Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Assess GDPR compliance for storing emails as part of incident reporting and OONI Run #869

Open
hellais opened this issue Aug 24, 2023 · 3 comments

Comments

@hellais
Copy link
Member

hellais commented Aug 24, 2023

Since we would like to know who created an incident for making it easier to verify and asses if it should be published or not (and not have random people from the internet create and publish them), we will store the email privately as part of the incident reporting platform.

We should have some lawyer give us feedback on what we should do in order to be compliant with GDPR.

@jbonisteel
Copy link

I have reached out to the Cyberlaw clinic at Harvard to see if they could help with this.

@jbonisteel
Copy link

Not a blocker for CIRP, but could be for OONI Run V2 - (mid-2024 timeline)

@hellais
Copy link
Member Author

hellais commented Feb 29, 2024

We have hired a lawyer for this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants