Skip to main content

Legal Compliance Checklist

DSA, GDPR, COPPA, and CCPA compliance posture for nSelf-operated services and the ɳSentry status-page plugin.

Last reviewed: 2026-05-11


DSA (Digital Services Act), EU Assessment

Is nSelf a DSA-regulated platform?

The DSA tiers its obligations by EU active user volume:

Tier Monthly EU active users Obligations triggered
Basic Any GDPR lawful basis, accessible ToS, take-down mechanism
Intermediary / Hosting Transmits or stores user content at scale Trusted Flaggers, annual transparency reports, notice-and-action
VLOP / VLOSE ≥ 45 million in EU Full DSA obligations, algorithmic transparency, annual audit

nSelf current status: Sub-threshold. nSelf is a self-hosted infrastructure tool, closer to WordPress (the software) than to a social platform. DSA recital 27 excludes software distribution from the “intermediary service” definition unless the software transmits or stores content on behalf of end users toward third parties.

nself-status-page Plugin (ɳSentry)

Question Answer
Does it store user-generated content? No, it displays automated service health metrics
Does it intermediate between users? No, read-only broadcast of infrastructure state
Does nSelf host the status pages? No, each operator self-hosts

Conclusion: The nself-status-page plugin does not independently trigger DSA platform obligations for nSelf. Self-hosted operators with large EU audiences should assess their own DSA position.


GDPR Summary

Service nSelf role Lawful basis Art. 9 concern
cloud.nself.org Controller Contract (Art. 6(1)(b)) + Consent for telemetry None
task.nself.org Controller Contract (Art. 6(1)(b)) None
claw.nself.org (hosted) Processor (user-partitioned) Contract + Consent (AI opt-in) Zero-retention API mitigates health-info risk
ping.nself.org Controller (telemetry) Consent, opt-in only None
ɳFamily (self-hosted) Vendor; operator is controller n/a Medical, biometric, genetic, Art. 9(2)(a) consent gate implemented

COPPA (US, Children’s Privacy)

All nSelf-operated services gate signups for users under 13 (US) and under 16 (EU). The parental consent flow:

  1. Age field detected at signup
  2. If age < 13 (US) or age < 16 (EU/EEA): account set to consent_pending
  3. Verification email sent to parent/guardian
  4. Account activated only after verifiable parental consent
  5. Consent record stored in np_parental_consents (self-hosted: operator’s DB)

CCPA (California)

nSelf does not sell personal data. CCPA rights:

  • Right to know, Privacy Policy §2 enumerates all data collected
  • Right to delete, Account deletion cascade documented; 30-day grace period
  • Right to opt-out of sale, N/A (no sale)
  • Right to non-discrimination, Policy affirms no discrimination for exercising rights

Retention Summary

Data type Retained for Basis
Account data Until deletion + 30 days Service continuity
Billing records 7 years Tax law
Art. 9 consent records Retained after revoke GDPR Art. 9(4) audit trail
Parental consent records Retained after account delete COPPA recordkeeping