Skip to main content

Legal Compliance Checklist

DSA, GDPR, COPPA, and CCPA compliance posture for nSelf-operated services and the ɳSentry status-page plugin.

Last reviewed: 2026-05-11


DSA (Digital Services Act) — EU Assessment

Is nSelf a DSA-regulated platform?

The DSA tiers its obligations by EU active user volume:

TierMonthly EU active usersObligations triggered
BasicAnyGDPR lawful basis, accessible ToS, take-down mechanism
Intermediary / HostingTransmits or stores user content at scaleTrusted Flaggers, annual transparency reports, notice-and-action
VLOP / VLOSE≥ 45 million in EUFull DSA obligations — algorithmic transparency, annual audit

nSelf current status: Sub-threshold. nSelf is a self-hosted infrastructure tool — closer to WordPress (the software) than to a social platform. DSA recital 27 excludes software distribution from the “intermediary service” definition unless the software transmits or stores content on behalf of end users toward third parties.

nself-status-page Plugin (ɳSentry)

QuestionAnswer
Does it store user-generated content?No — it displays automated service health metrics
Does it intermediate between users?No — read-only broadcast of infrastructure state
Does nSelf host the status pages?No — each operator self-hosts

Conclusion: The nself-status-page plugin does not independently trigger DSA platform obligations for nSelf. Self-hosted operators with large EU audiences should assess their own DSA position.


GDPR Summary

ServicenSelf roleLawful basisArt. 9 concern
cloud.nself.orgControllerContract (Art. 6(1)(b)) + Consent for telemetryNone
task.nself.orgControllerContract (Art. 6(1)(b))None
claw.nself.org (hosted)Processor (user-partitioned)Contract + Consent (AI opt-in)Zero-retention API mitigates health-info risk
ping.nself.orgController (telemetry)Consent — opt-in onlyNone
ɳFamily (self-hosted)Vendor; operator is controllern/aMedical, biometric, genetic — Art. 9(2)(a) consent gate implemented

COPPA (US — Children’s Privacy)

All nSelf-operated services gate signups for users under 13 (US) and under 16 (EU). The parental consent flow:

  1. Age field detected at signup
  2. If age < 13 (US) or age < 16 (EU/EEA): account set to consent_pending
  3. Verification email sent to parent/guardian
  4. Account activated only after verifiable parental consent
  5. Consent record stored in np_parental_consents (self-hosted: operator’s DB)

CCPA (California)

nSelf does not sell personal data. CCPA rights:

  • Right to know — Privacy Policy §2 enumerates all data collected
  • Right to delete — Account deletion cascade documented; 30-day grace period
  • Right to opt-out of sale — N/A (no sale)
  • Right to non-discrimination — Policy affirms no discrimination for exercising rights

Retention Summary

Data typeRetained forBasis
Account dataUntil deletion + 30 daysService continuity
Billing records7 yearsTax law
Art. 9 consent recordsRetained after revokeGDPR Art. 9(4) audit trail
Parental consent recordsRetained after account deleteCOPPA recordkeeping