If you’re into WordPress, you’re probably familiar with Akismet: one of the most popular anti-spam plugins that comes pre-installed with every new WordPress installation. And while millions of users around the world trust Akismet to eliminate spam comments, there seems to be a major privacy issue that most users are unaware of. According to some reports, WordPress.org and Automattic are allegedly providing a spam protection solution that does not comply with international standards and privacy laws. So could using this plugin be a clear violation of the new European General Data Protection Regulation (GDPR)? Below, we’ll try to analyze whether this is the case and to what extent.

Anti-Spam Services and GDPR
Let's start from the beginning. To understand the problem with cloud-based antispam services, we first need to look at how they work. We'll take Akismet as a point of reference, keeping in mind that it's only part of the bigger picture.
Cloud-based services of this kind operate by maintaining databases of user-submitted comments on their servers. When a user submits a comment on a site that uses Akismet, their information is transferred to a third-party server, over which they no longer have control. The server processes and evaluates the comments, stores them in its database, and classifies them as spam or non-spam.
Collection of sensitive personal data
Each comment that is checked by Akismet contains a set of data which includes, among other things, the raw comment data, the names, the IP addresses and the users' email addresses. According to GDPR all of this constitutes personal data, or otherwise personally identifiable information (Personally Identifiable Information).
Although there is nothing shameful in evaluating this data for anti‑spam protection and security reasons, the problems start with sending the data to third‑party servers, the unclear way they are processed, and its ’ indefinite storage.
These servers are located in other countries and are governed by different laws. For example, Akismet’s main servers are located in the United States. Although the company seems to have expanded its datacenters to European countries, it does not seem to be able to guarantee in which country the data will be processed and under what conditions.
Furthermore, since there is no way to use the service without sending IP addresses and emails, this sensitive data that is necessarily collected by the company may be subject to incomplete data protection policies and incomplete user security mechanisms.
Simply put: The end user submitting the comment has no control over their data or privacy. Currently, there are no cloud-based anti-spam services that are fully GDPR compliant, including Akismet. These types of services could easily be used (or circumvented) to collect data that could be sold to data buyers and marketers. Many people suspect that this is already happening, especially after the Facebook scandal. Is Automattic/Akismet the next Facebook? Is Matt Mullenweg the next Mark Zuckerberg? We don't know. The unfortunate truth is that big companies don't have a habit of valuing user privacy, so users should start taking care of their own privacy.
Insecure transmission of comments via HTTP;
The problems affecting user privacy and security don't seem to end here. Another important security issue is that Akismet does not enforce the use of SSL/TLS (HTTPS) connections when sending data from websites that use it to the service's servers.
Let's take a look at the plugin code (in version: 4.0.7)
/* Try SSL first; if that fails, try without it and don't try it again for a while.*/ $ssl = $ssl_failed = false;
This means that if the HTTPS connection fails for some reason or the server is not properly configured, Akismet will not use HTTPS.
If this happens, it will be saved in the plugin settings, preventing the use of HTTPS for future connections.
// The request failed when using SSL but succeeded without it. Disable SSL for future requests.
if ( $ssl_failed ) { update_option( 'akismet_ssl_disabled', time() ); do_action( 'akismet_https_disabled' ); }In other words, the data transferred to Akismet’s servers will not even be encrypted, but will be sent in clear text and can easily be intercepted by attackers.
Of course, this contradicts another of the GDPR’s core principles, data protection by design, which means that secure practices must be used during coding, while data protection features must be built into the functionality from the start.
The only thing that is certain is that GDPR compliance requires much more than the use of secure connections. Even if Automattic / Akismet took better measures to strengthen its data protection policies, it would be very difficult to fully comply with the GDPR. It remains to be seen what the company’s next steps in this direction will be, as so far it seems unable to meet the requirements of the European regulation.
