Skip to content

Add the legal notice and the privacy policy, and ask the board for the two missing facts - #209

Open
DZPM wants to merge 7 commits into
editionfrom
work/association-identity
Open

DZPM wants to merge 7 commits into
editionfrom
work/association-identity

Conversation

@DZPM

@DZPM DZPM commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

The legal notice and the privacy policy that pybcn.org does not have, and the two facts only the Management Board can supply.

Why the site needs this

Spanish law 34/2002, LSSI-CE article 10, requires a site run by an association to publish its name, its address, an email, its entry in the register it is recorded in, and its tax number. The site publishes none of them. It also has no privacy policy, while it embeds Google Forms and a Google Calendar, serves from GitHub Pages, and links to Meetup and YouTube.

What this adds

Two pages. A legal notice at /pybcn_association/legal-notice/ and a privacy policy at /pybcn_association/privacy-policy/, both linked from the footer of every page.

A [params.association] table in config.toml, which the legal notice reads:

[params.association]
    legal_name = "Associació Python Barcelona"
    tax_id = "G67254045"
    address = ""
    registry = ""

The facts go in the configuration rather than in the text of the page, for two reasons. The association can correct one of them without anyone editing a page of legal prose, which is the kind of edit that goes wrong. And the gap stays visible instead of being quietly absent from a paragraph nobody rereads: an empty value prints a line that says so, and bin/check-content reports it on every run.

WARNING  config.toml: params.association.address is empty. It is the registered
         address, which LSSI-CE article 10 requires the legal notice to publish.
         Only the Management Board can fill it.

The check warns and does not fail. The site builds and serves without them, and an error would turn every pull request red for a reason no contributor could fix.

The dead cookie banner goes. cookieconsent.min.js and its CSS were loaded on every page for a banner that no longer appeared. The site sets no cookies, which is what the privacy policy now says.

What the board needs to provide

@mesejo, as Secretary, these two:

  1. The registered address of the association, the one on the statutes and on the entry in the register.
  2. The registration number in the Registre d'Associacions de la Generalitat de Catalunya, with its section, as it appears on the resolution.

Either answer here and I will commit them, or push the two lines onto this branch. Both are one edit to config.toml, nothing else.

Until they arrive the legal notice reads, in the page itself:

Registered address: not published yet. The Management Board has to supply it.

That is why this does not merge yet. A legal notice that leaves out the one section the law asks for does not do the job it exists for.

Worth the board's eye, not only the data

The pages are written in plain English by a volunteer, not by a lawyer. They describe what the site actually does: no analytics, no server of our own, no cookies, a static site on GitHub Pages, and a handful of third-party embeds named one by one. If anything in them is wrong about how the association works, this is the moment to say so.

Spanish law 34/2002, LSSI-CE article 10, requires a site run by an
association to publish its name, its address, an email, its entry in the
register it is recorded in, and its tax number. The legal notice page that
shows them is written and waiting; two of the five facts are missing and
no volunteer can supply them.

They go in config.toml, under [params.association], rather than in the
text of that page. Two reasons. The association can correct a fact without
anyone editing a page of legal prose, which is the kind of edit that goes
wrong. And the gap is visible: bin/check-content reports an empty one on
every run, instead of the fact being absent from a paragraph nobody
rereads.

Filled already: the legal name, and the tax number G67254045.

Empty, and only the Management Board can fill them: the registered
address, and the entry in the Registre d'Associacions de la Generalitat de
Catalunya.

The check warns and does not fail. The site builds and serves without
them, and an error would turn every pull request red for a reason no
contributor could fix. The gate is the legal notice page, which cannot be
published while they are empty: that page is the one place the law asks
for these, and a page that leaves them out does not do the job it exists
for.

Checked both ways: with the two keys empty the run ends 0 errors and 13
warnings, and with them filled, 11.
@DZPM
DZPM requested a review from a team as a code owner October 8, 2026 07:33
@DZPM DZPM self-assigned this Oct 8, 2026
@DZPM
DZPM requested review from ber2, mesejo and mrswats October 8, 2026 07:37
Comment thread config.toml
Comment on lines +51 to +52
address = ""
registry = ""

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please, provide this lines

DZPM added 6 commits October 8, 2026 10:39
The site identifies the association nowhere, which the LSSI-CE (article 10)
requires of any organisation that runs a website. This page gives the name,
the CIF, the contact mailbox, the terms of use and the applicable law.

The registered address and the registry number are not in the repository.
The page shows them as pending: it must not be published until they are
filled in.
The site publishes 138 people pages with a name, a photograph, a biography
and profile links, links Google Forms, embeds a Google Calendar, and sends
members to PayPal, with no privacy policy. GDPR articles 13 and 14 require
one.

The page names the controller, lists each kind of data the site involves
with its purpose and legal basis, names the third parties (Google, PayPal,
GitHub), states that the site sets no cookies and runs no analytics, and
gives one mailbox to exercise the rights of articles 15 to 22, including the
removal of a people page.

The registered address is not in the repository and shows as pending.
The footer is where a reader looks for them. The two pages are resolved
with site.GetPage, so a moved or renamed page fails the build instead of
leaving a dead link.
The partial was included only when cookie_consent_info_url was set, and the
site config never set it, so no page rendered the banner. The site sets no
cookie of its own, which the privacy policy now states. A banner that asks
consent for a cookie that does not exist would only mislead, so the partial
and the two vendored Osano assets go.
The banner was removed in the previous commit.
The legal notice held the five facts LSSI-CE article 10 asks for as text,
two of them a paragraph saying the association still had to supply them.
They come from [params.association] now, through a shortcode.

The association can correct a fact without a volunteer editing a page of
legal prose, which is the kind of edit that goes wrong. And an empty value
prints a line that says so rather than a missing bullet: a missing bullet
reads as a page that never claimed to carry the fact, where a line that
says it is missing is the page admitting it does not yet do its job.

Both states are checked in the build. With the two keys empty the page
reads "Registered address: not published yet. The Management Board has to
supply it." With them filled it reads the value.
@DZPM DZPM changed the title Hold who the association is in config, and ask the board for the two missing facts Add the legal notice and the privacy policy, and ask the board for the two missing facts Oct 8, 2026
@DZPM DZPM assigned mesejo and unassigned DZPM Oct 8, 2026
@DZPM
DZPM removed request for ber2 and mrswats October 8, 2026 09:05

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants