60 likes | 76 Views
Explore the challenges and solutions related to attribute release in the GEANT Code of Conduct 2.0. Learn how to address data protection concerns and compliance requirements for Service Providers and IdPs. Stay updated on the latest guidelines and oversight mechanisms. Join the discussion on monitoring bodies and international cooperation.
E N D
GEANT Data protection Code of Conduct 2.0 REFEDS meeting 16 June 2019 Mikael Linden, mikael.linden@csc.fiCSC – IT Center for Science GN4-3 project
The attribute release problem Release my attributes to SP X, I need it to do my job! Home Organisation (HO): User(researcher) Sorry, to protect your privacy, we cannot release your attributes. Service Provider organisation Authenticates IdP SP X ? Attributes IdP admin
GEANT CoCo status and next steps • In February 2019, authorities (EDPB) published draft guidelines for codes of conduct • Effective oversight mechanisms • Monitoring body • GEANT Association and GEANT project now studying these • Then contact Dutch authorities for submission https://wiki.refeds.org/x/N4MY
Monitoring the GEANT CoCo New to everyone, out first approach: • Technical conformance • Can be fully automated • Behavioural conformance • Based on self-assessments • Complaints Who is proposed as the monitoring body? • for SPs in eduGAIN, GEANT Association? • for SPs in national federations, ??? SP SP SP SP SP SP SP SP SP SP SP IdP IdP IdP IdP IdP IdP IdP IdP IdP IdP IdP IdP IdP Participant Federation Participant Federation eduGAIN service Participant Federation Participant Federation
Other open issues • How do we call it (GEANT data protection code of conduct for federated IdM?) • Making international organisations confident to commit to it • Authorities have not published guidelines for CoCos for international transfers