Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How to handle private information? #106

Open
Te-k opened this issue Apr 16, 2019 · 3 comments
Open

How to handle private information? #106

Te-k opened this issue Apr 16, 2019 · 3 comments

Comments

@Te-k
Copy link
Contributor

Te-k commented Apr 16, 2019

Is your feature request related to a problem? Please describe.

By design, pytition will have to deal with private information (names, emails, phone numbers etc.). How to deal with that ?

Describe the solution you'd like

I see two options :

  • Pytition does not allow the petition owner to have access to the full data. In that case, Pytition because the third party that owns the responsibility of having and keeping the data, and displaying the right number of signatures
  • Pytition allows the petition owner to fully download the data of the user that signed the petition (it is the case today), in that case the petition owner is responsible for the data.

I am not sure what is the best option, in both cases, we have to make sure that the policy is clear to the user. We should also check what GDPR is saying about all that.

Maybe having Framasoft involved in the discussion would help.

@fallen
Copy link
Member

fallen commented Apr 18, 2019

I think organizations (and also user who own petitions) should be able to print the list of signatories (with names and emails at least).
This is necessary when, at the end (or start) of a campaign you want to "give the petition" to a public representative (like a mayor or a deputy or such).

@fallen
Copy link
Member

fallen commented Dec 14, 2019

I also think it's fairly reasonable to give control of the data to both signing user and the petition owner.
I would like the hosting organization to not gain power over hosted organizations. So no data retention.
But indeed the policy should be very clear to user.
Even if I find it logical that the data you enter in a formular will be accessible by the organization which made the formular.

@fallen
Copy link
Member

fallen commented Jan 29, 2020

CNIL paper about RGPD: https://www.cnil.fr/fr/guide-rgpd-du-developpeur

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants