GDPR Compliance in Ghost Subscription Forms - We Need Your Voice

Hello Ghost Community,

I’d like to bring attention to a critical compliance issue that affects many of us using Ghost for our publications. This is a call for Ghost users who need to comply with GDPR to make themselves known so we can collectively demonstrate the importance of this matter to the Ghost team.

The Current Challenge:

Ghost’s current implementation of legal compliance in subscription forms appears insufficient for proper GDPR compliance:

  • The portal allows only one checkbox with a 115-character limit for legal text
  • This character limit is too restrictive (I had to trim mine to 114 characters despite having a short business name)
  • The subscription buttons in themes (like Source) don’t have these options at all

What GDPR Actually Requires:

Based on legal advice, proper GDPR compliance for email subscriptions typically requires three separate, unchecked boxes that users must actively check:

  1. ✓ I agree to the Privacy Policy (with link)
  2. ✓ I agree to the Terms of Service (with link)
  3. ✓ I agree to receive marketing emails from [business name]

Combining all of these into one checkbox = non-compliance.

Why This Matters:

  • GDPR applies based on where your users are located, not where your business is based
  • If your analytics show traffic from the UK/EU and you collect personal data, you need to comply
  • Non-compliance carries serious legal and financial risks
  • We shouldn’t have to hire developers to add custom code to make Ghost’s free themes legally compliant

We Need Your Support:

If you’re a Ghost user who needs to ensure GDPR compliance, please comment below and share:

  • Your location/jurisdiction
  • Your current compliance challenges
  • How this limitation affects your publication

Multiple users have raised this issue with Ghost support but received standard responses without implementation. We need to show this isn’t an isolated concern but a widespread requirement affecting many publishers.

Let’s gather our voices to help Ghost understand the seriousness of this situation. The more of us who speak up, the more likely we are to see the necessary changes implemented.

Thank you for taking the time to support proper GDPR compliance in Ghost.


Note: While the UK’s Data Use and Access Act 2025 comes into effect on June 19th with additional requirements, the core GDPR compliance issues discussed here have been relevant since 2018.

2 Likes

Thank you for opening a thread on this. That makes it easier to discuss.

That said, I am not a legal professional, but have looked quite a bit into GDPR as legal framework (as the little EU legislation nerd I am).

Where I’d disagree with you is the three check boxes. (All the information I rely on is from here: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng)

A privacy policy in general is not something people have to consent to. The policy is purely informational, see specifically Article 13 of the GDPR:

Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:

[…]

At no point is consent required. It is best practice to surface the privacy policy upon sign ups etc. to ensure that any data subject has a clear opportunity to read it. But GDPR itself does not require consent for a privacy policy.

Terms of Services are not governed by GDPR or privacy regulation at all. Legally speaking (again, not a professional) it’s a separate contract between the publisher and a user. It’s certainly desirable to have consent for them, but not as part of a privacy concern. Most newsletters wouldn’t even have spelled out ToS, in my eyes.

The only consent box I see as justified under GDPR is the marketing consent checkbox (based on GDPR’s Article 6(1)(a), with Article 4(11) defining what valid consent looks like (“freely given, specific, informed, unambiguous”) and Article 7(2) requiring it to be kept separate from other matters).

So, I am not saying this is not relevant. But I see it a bit more nuanced. Perhaps the right framing is a feature request (in Ideas) to optionally allow more check boxes?

3 Likes

My two ören can be summarised as “It’s complicated. Everyone has differing opinions on this subject. The approach I suppose that most companies take is based on risk assessment.”.

Here is what I’ve done to be as compliant as possible given the features of Ghost:

  1. Customise the CTA banner text so it reads “Sign up to receive our latest content by email and gain the power to comment. No spam. No cost. Unsubscribe anytime.”
  2. Enable the checkbox when signing up through the Portal
  3. Add the following text that is shown in relation to the checkbox: “By signing up, I agree to receive emails from PUBLICATION_NAME when new content is published. No spam. Unsubscribe anytime.”

It is a good enough solution to be decently in compliance with the GDPR regulation. Note that there are other laws and regulations that also are in effect in this use case. All the other finer details are described in separate pages for Terms & Conditions and Privacy.

It’s important to phrase the second half of the first sentence in bullet 3 above to reflect your newsletter. If you send a weekly roundup for example one could replace “when new content is published” with " on a weekly cadence".

To be super extra compliant, it would be nice to add how the email and name is used. One sentence per information and usage. Clearly demarcated from each other. That’s what my product team did when we owned a part of an online retailer website with 100s of millions of customers. No check boxes. Just very clear and simple explanation of what we did with each PII of the customer that they provided to the business in question. With a link to the privacy page. This was discussed and agreed upon with all national legal teams and the main legal representatives of the HQ.

To put this in context, I’ll link to the various state authorities that oversee these different laws and regulations in my country (Sweden) as member state of the EU. You should be able to translate to English using various tools in your respective browser.

1 Like

Likewise Jannis, I’m not a legal professional either, however I have this information on very good authority.

I do appreciate you engaging with this, and for all you do for your customers, me included.

What does puzzle me is that Ghost could quite easily add the ability to include additional checkboxes for their customers, and yours, particularly since the code for one checkbox already exists. Instead, here we are, eight+ years on. If Ghost has even a single customer based in the UK or EU, this is something they really should be supporting us on, rather than this forum farce.

I do however disagree with you on the three checkboxes, and I hope the detail below explains where I’m coming from.

Checkbox 1: The purpose of the Terms of Service is to protect the business - yes, this is not part of privacy requirements but it is part of protecting the business in general. For example, please see Specht v. Netscape Communications Corp., which provides that certain clauses of a Terms of Service may not be enforceable if the individual did not see the Terms of Service if it was buried elsewhere in the website. This demonstrates the fact that a checkbox to agree to a Terms of Service that is visible to an individual helps the businesses ensure that the individual actually saw those Terms and thus allows the business to enforce those Terms. The UK ICO has provided guidance stating that consent cannot be bundled with a Terms of Service, meaning that this would be a separate checkbox from any of the privacy-related checkboxes: Consent | ICO

Checkbox 2: The second checkbox would be stating that the individual agrees to receive email marketing. The EDPB guidelines state that consent must be granular “If you process data for multiple purposes, you should propose separate consents…” https://www.edpb.europa.eu/system/files/2026-04/edpb-summary-consent_en.pdf?.

Checkbox 3: This third checkbox would be agreeing to the Privacy Policy. This is specifically as part of the “informed” part of the consent requirement. For consent to be valid, the individual must be informed as to what you will be doing with their personal data - otherwise, consent is invalid. You can see that “informed” is part of the requirement here: Recital 32 - Conditions for Consent - General Data Protection Regulation (GDPR).

For consent to be informed, the individual must be provided with the following information (Art. 13 GDPR – Information to be provided where personal data are collected from the data subject - General Data Protection Regulation (GDPR)) and this information is present in the Privacy Policy. GDPR even states that this information must be provided when personal data is collected from the individual - so in this case, this would be when they submit their information to subscribe to the newsletter. The EDPB states this in their guidance as well: https://www.edpb.europa.eu/system/files/2026-04/edpb-summary-consent_en.pdf?. If the individual did not see the Privacy Policy (if it was not presented to them when they submitted their data), then they would not be informed as they would not have seen this information.

It does seem surprising that we’re navigating the nuances of well-established GDPR concepts when the simpler solution would be to give Ghost customers the flexibility to add as many checkboxes as they need, particularly given that the platform already has the capability to do so. The current limitation of a single checkbox capped at 115 characters really isn’t sufficient.

I note that even where you believe none of these checkboxes are strictly required, you also acknowledge that showing the Privacy Policy is best practice, that you would include a marketing checkbox, and that a Terms of Service checkbox is desirable. That’s actually a great deal of common ground between us. ;)

8 years after GDPR came into force, this really shouldn’t be a ‘feature request’ . It’s a matter of core platform legal compliance. I think we both know the answer to ‘What’s the worst that can happen?’ and it’s not a comfortable one.

All this said, I’m not content with the back and forth arguments this post will encourage. Ghost should be handling this. It should be on their time, not mine, or ours. And so given that I have two potential paths to follow to make this right, custom code being one, turning off the subscription model being another, I’ve said my piece. This is not the place. We are not the people. And so I plan on using my time more proactively in the pursuit of an income rather than an argument with an individual that I have much admiration and respect for. Ghost are very lucky to have you in their orbit.

My mental health doesn’t need this. If Ghost doesn’t care, why should I waste my time and breath. I’m done here.

3 Likes