Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Use Case: Kantara v0.8 Implementation

Authors: Mark & Oliver

 

Log Of Activities

ActivitiesDateStatusNotes
Converted Api to Plugin Finished 
Updating JSON to v0.816/Jun/2016in progress 
Adding 2 conformance modes to this doc   

...

  1. Consent to Join WG
  2. Authority to consent on behalf of organsiation organisation (requires link to withdraw authority)
  3. Consent Preference - voting or non-voting (link to policy for changing voting status)
  4. Kantara PII Disclosure

...

 

To implement create a consent receipt the privacy policy needs to be reviewed to collect consent and policy components which should be a) reviewed by the Kantara organization b)

consent enhancement recommendations.  

 (or existing consent notice) was reviewed for collection, use and disclosure practices, and these were collected in order to implmenet a base consent receipt template for the Kantara WG GPA sign-up form. 

Review recommendations:

  • In the privacy policy there is a reference to an implied consent to transfer personal information across jurisdictional borders which is not compliant with current Privacy Shield practices
    • Recommend adding an explicit consent to the WPA form
  • Member data shared on WG WIKI in participation roster (link to participant roster)
  • All post to mailing list are captured in a public achieved (link to mailing list for m)

WG PI Sharing practices

  • Share IP with Google Analytics (non-identified data) (link to policy)

3. PII Sharing Practices

 

 

4. PI Sharing Practices

 

 

...

  • Disclosure 
    • Virtual
    • Emma Inc

 

5. Scopes

 

When reviewing the 3rd Party Sharing practices for both PII and PI, it became clear that there were some sharing.

...