Editors:
Version | Status | Writer | Editor | reviewer |
---|---|---|---|---|
v.01 | X | Mark Lizar - ; Summary of Intent | Mary Hodder | |
v.02 | X | Mark Lizar & Mary Hodder Stakeholder Analysis | John Wunderlich | |
v.03 | X | John & Mark: Summary of Compliance Contents | Mary Hodder | |
v.04 | Current | Spec Outline: Mark Lizar Respect Network Save Receipt to Cloud: Technical Walkthrough: Markus Sabadello Open Notice Website CR Demo: Mark Lizar | John Wunderlich Mary Hodder | |
v.05 | Next Edit |
Status
first draft in progressv,04 for a complete outline for v.05
(note: first v.1 should be a functional spec by example)
Action Items
- Former user (Deleted) insert walkthrough demo links)
- John Wunderlich edit the outline for draft 5the content and working, make less passive and more succinct, help make this the most simple bare bones but functional spec possible for first version.
- Mark Lizar (Unlicensed) Finish Compliance Scale description and compliance audit rules (needs a table)
- Mark Lizar (Unlicensed) needs a first read through edit after many changes
- Mark Lizar (Unlicensed) needs Open Notice Demo (in progress)
- Fix Formatting
- Mary Hodder edit draft
- needs Open Notice Demo (in progress)
- Former user (Deleted) Formatting review and update
- needs a flow chart (will talk to Renee)
...
Table Of Contents
Table of Contents outline true indent 10px
Related Documents:
- CISWG: Consent Requirements Map: (spreadsheet of laws/principles for receipt and data control R&D)
- Latest Consent Receipt Template
- Hackathon Video and Convergathon Hack Notes from July 12&13 2014 -->
- Scale of Compliance to measure the legal compliance of a consent receipt
...
Respect Network (RN) Technical Demo:
- Store a Consent Receipt in your RN personal cloud using XDI: http://amazon-respect-consent.herokuapp.com/
- List Consent Receipts in your RN personal cloud: http://open-notice.github.io/respect-network-receipts/
...
Specification by example (SBE) is a collaborative approach to defining requirements and business-oriented functional tests for software products based on capturing and illustrating requirements using realistic examples instead of abstract statements. It is applied in the context of agile software development methods, in particular behavior-driven development. This approach is particularly successful for managing requirements and functional tests on large-scale projects of significant domain and organisational complexity.[1] (https://en.wikipedia.org/wiki/Behavior-driven_development)
A key aspect of 'specification by example' is creating a single source of truth about required changes from all perspectives. This latest version specification with this document title is the single source of truth.
Objective
The aim of the specification is to produce a the minimum compliant capable consent receipt that directly links all required policies (open notices) to the consent receipt.
...
Field Name | Description | Purpose/Explanation | Reason Why This Field is Required | Cloud Receipt Capture & Sign: Format example in (XDI) Note: following lines all prepended with ([=]!:uuid:1111/[+]!:uuid:9999) |
---|---|---|---|---|
Data Subject | Name or pseudonym of the user at minimum, | Data Subject is primary party to consent | Is the consent contributor and primary party of the consent, (which is why this is the first field of the MVCR) if not signed by Data Subject then its use post consent may be limited. | Data Subject: Alice [=]!:uuid:1111 |
Address (and jurisdiction) of Data Controller | Name of the entity issuing the receipt | Should be the entity/organization that is in control of the personal data and is responsible for consent compliance. | Is the Data Controller and is the primary party responsible for administration of the consent | Data Controller: Amazon [+]!:uuid:9999 |
Purpose | The purposes for which the personal information is being collected. | this is a single purpose at minimum linked to the short purpose notice, or policy of purpose. | A purpose notice is a basic and common legal requirement and functionally a requirement of consent. | [#receipt]!:uuid:1234[<#purpose>]<@0>&/&/"We need to process your payment." [#receipt]!:uuid:1234[<#purpose>]<@1>&/&/"We need your data to prevent fraud." [#receipt]!:uuid:1234[<#purpose>]<@2>&/&/"We will advertise to you." |
Location of Consent | The location of the consent provision. from which the consent receipt originates.(For example the web page with the consent button. ) | This indicates the 'point of consent' - hopefully a button where the user clicked "I agree" or "I consent" (i.e. the biggest lie) Can be a URI, URL, URN, This can also be a physical space where surveillance legal notice requirements exist (EU) - Global Positioning System (GPS) |
| |
Sensitive Personal Data Flag (Y/N) | Flag to categorise the information collected as sensitive or not (Y/N) | Each jurisdiction has classifications of sensitive personal information: The generally include health, financial, Child Protection, Religious, Union categorisations | If Yes, then additional notice requirements are needed to confirm its compliance status. If No, then the consent is automatically compliant | |
Third Party Sharing | Flag whether data is shared with third parties. (Y/N) | If true, then compliance is dependent upon additional notice requirements not present in a MVCR. This can be addressed with the "Third Party Sharing" extension. | If Yes, then additional notice requirements are needed to confirm its compliance status. If No, then the consent is automatically compliant | |
Timestamp | When consent was obtained | To record when the user, either by implication or explicity, granted consent for the purposes described. | ||
Privacy Policy | The issuing entity's privacy policy (either inline copy, or reference to URI) | If not available, should provide a notice that it is missing | Is the minmum Policy (or short notice) Needed to create a consent receipt. | |
Operational Context Flag | Flag wether the Operational Requirements are present or not. (Y/N/Unknown) | For the presentation of consent there are contextual and prescriptive requirements in legislation, a check list of these elements is being crated in this draft below. | Consent has contextual compliance requirements for the notice to be sufficent. These depend on the location and format of the consent notices An organisation displays agreement (or not) to implement these OC requirements and this is reflected on the consent receipt. |
...
Notice Requirements Receipt Meets | Description | UK UK DPA 1998 | EU Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:31995L0046:EN:HTML | USA For Sharing Personal Sensitive Information with 3rd Parties | Canada | APEC | P3P | FTC FIPPS | OECD FIPPS |
---|---|---|---|---|---|---|---|---|---|
Contact of Data Controller (DC) | Legally required to provide contact details of the DC | X | X | ||||||
Address of Data Controller (DC) | Legally required to provide contact details of the DC | X | X | ||||||
Purpose(s) | Legally required to provide purpose for data control | X | X | ||||||
Third Party Legal Requirements Transparency | This is a flag to see if additional notice extensions are requirements to assess compliance | X | X | ||||||
Sensitive Personal Information Collection Transparency | This is a flag to see if additional notice extensions are requirements to assess compliance | X | X |
...
The MVCR has a base template v.1 that we have using to wireframe consent receipts: V.1
Latest Template Version
(******Template HERE***)
We have a template that we are using for the technical design of the consent receipthave created to guide the design and development of the MVCR, the GUI design is also out of scope of this specification versin. What is provided by default is a Consent Receipt Template that we are using for technical design.
Example 1: Open Notice Consent Receipt
(Example (in progress)
Open Notice Website - Consent Receipt - Technical Demo
- Provides a simple consent receipt to show compliant policy (in dev progress) http://on.smartspecies.com/receipt-example/
(Example (in progress) can be found at http://on.smartspecies.com/support-open-notice/
Image:ON-CR: Example
Example 2: Storing Receipt in Personal Data Store: Technical Walkthrough Example with Respect Network
Respect Network (RN) Technical Demo:
- Store a Consent Receipt in your RN personal cloud using XDI: http://amazon-respect-consent.herokuapp.com/
- List Consent Receipts in your RN personal cloud: http://open-notice.github.io/respect-network-receipts/
Amazon Respect Use Case: With the Respect Network and Open Notice
(Note: Amazon Respect is a Fictitious organisation used here only as an example)
(http://open-notice.github.io/consent-receipt/amazon-mock/signup.html)
Implementation of consent receipt which is signed & created by a DC and stored in a personal Cloud.
...
The compliance scale is based on the ICO table of compliance http://ico.org.uk/for_organisations/data_protection/working_with_the_ico/~/media/documents/library/Data_Protection/Detailed_specialist_guides/auditing_data_protection.pdf
Trusted Services Appendix
...