-
Notifications
You must be signed in to change notification settings - Fork 38
beef up the infosec portion of our risk program #223
Comments
Europe has stronger data privacy laws. What are they? https://www.mywot.com/wiki/Personally_Identifiable_Information_(PII) |
#222 will be part of this. |
As will #214. |
Europe generally: http://ec.europa.eu/justice/data-protection/. |
http://ec.europa.eu/justice/data-protection/data-collection/index_en.htm |
What do we have to do here? We need to start storing bank accounts and identity numbers. We should look at the information we store and the risk associated with each, and adopt policies according to risk level. I'm thinking of three tiers:
|
At this point my hope is that we can:
|
With gratipay/gratipay.com#3504 (comment), I'm bumping this from the "Bring Back Payroll" milestone. |
Now that we're planning to store national identification numbers (gratipay/gratipay.com#3289 (comment)) as well as bank account numbers (#3377 downstream of #3366), we need a stronger infosec risk management program.
The text was updated successfully, but these errors were encountered: