SlideShare une entreprise Scribd logo
1  sur  14
What GDPR compliancy means for
Open Badge Factory and Open Badge
Passport users
Eric Rousselle
About the EU General Data Protection
Regulation
• We’ve always been committed to protect personal data in all our
services
• EU General Data Protection Regulation (GDPR) is beneficial for
all parties as it sets clear rules for personal data protection
• GDPR brings transparency and therefore supports trust
• We’ve made necessary modifications to get OBF and OBP GDPR
compliant before May 25
• OBF and OBP will be updated on May 22 and 23
GDPR terminology
• Personal data is information relating to an identifiable living
individual
• Data subject means an individual who is the subject of
personal data
• Data controller means usually an organisation which
determines the purposes for which and the manner in which
any personal data are, or are to be, processed
• Data processor, means any person (usually organisation)
who processes the data on behalf of the data controller
What rights GDPR gives to individuals?
• a right of access to a copy their personal data
• a right to object to processing
• a right to have personal data rectified, blocked, erased or
destroyed or anonymised
• See the complete list:
https://ico.org.uk/for-organisations/guide-to-data-
protection/principle-6-rights/
Data protection principles
• Personal data shall be processed fairly and lawfully
• Personal data shall be processed in accordance with the rights
of data subjects
• Personal data shall not be transferred to a country or
territory outside the European Economic Area unless that
country or territory ensures an adequate level of protection
for the rights and freedoms of data subjects in relation to the
processing of personal data
• See: https://ico.org.uk/for-organisations/guide-to-data-protection/data-
protection-principles/
GDPR and Open Badge Factory
• data controller is a customer organisation using OBF to
create and issue badges
• data processor is the service provider (Discendum)
• OBF customer’s admin(s), registered users (creators and
issuers) are data subjects
• Badge recipients are also considered as data subjects
because their personal data is used to issue badges (email
address, name, surname, data submitted in badge
application forms)
How data subjects can access their personal data?
• OBF users (registered) can list their personal data in OBF and erase
their account and all their personal data if they wish to do so
• When receiving a badge, a badge recipient will get a link to check
(using their email address) what personal data is stored and processed
in OBF
• Badge recipient can request their personal data (name, surname,
email address, possibly also data submitted in badge request /
application forms) to be anonymised or erased
• Data subject’s requests have to be processed by the data controller
(customer) promptly (in a maximum delay of 40 calendar days)
• Data processor can not / will not anonymise or erase personal data on
behalf of the data controller (customer)
OBF documents
• DPA (Data Processing Agreement)
• This document is an annex, part of the agreement between the
Service provider and its Customer. The purpose of this Annex is to
agree on the privacy and data protection of the personal data of the
Customer in the services of the Service Provider.
• Terms and Conditions
• Privacy notice (annex of Terms and Conditions)
• Tells users what data is processed. On what legal basis and for what
purpose.
• These documents will be displayed to users when they log in to OBF (May
22). No agreement needs to be signed. Using OBF is considered as an
agreement.
Open Badge Passport and GDPR
• From GDPR point of view, OBP is a straightforward case
• The service provider is data controller and data processor
• OBP users are data subjects
• User creates their own account in OBP (accounts aren’t
created on their behalf)
• User brings their personal data to OBP
• User has access to their personal data
• User can delete all personal data and their account
• Service provider doesn’t delete data on behalf of the user
OBP documents
• Terms and Conditions
• Privacy notice (annex of Terms and Conditions)
Good to know
• Both OBF and OBP are hosted in an EU country (Finland)
• The cloud service provider of both OBF and OBP is GDPR compliant
• Aligning to GDPR is a requirement for all European companies
• OBF and OBP data is protected (firewalls, etc.) and backed up daily. Passwords
and network connections are encrypted
• OBF’s and OBP’s data processor (service provider) doesn’t transfer any data into
other services (except for back up purposes)
• When a customer issues badges in a Learning Management System using an OBF
plugin, some data is transferred between the systems
• Badges are usually hosted in OBF’s server, but in some cases customer can set up
their own Badge Record Storage to host their badges in their own server
OBF and OBP are “low risk services”
• Personal data stored and processed in both systems is not “sensitive
data”
• The amount of personal data used is small
• Open Badge is an earner centric concept, recipient can always decide
how to use and display their badges
• Badge earners have the right not to display and share their badges but it
is good to keep in mind that the Open Badges concept has been built to
recognise and communicate achievements, skills, competencies,
attitudes, etc. and therefore openness and sharing are in the core of the
concept!
Thank you!
eric.rousselle@discendum.com
@eric_rousselle

Contenu connexe

Similaire à OBF, OBP and GDPR

Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
Iron Mountain® Policy Center Solution Enterprise Edition
Iron Mountain® Policy Center Solution Enterprise EditionIron Mountain® Policy Center Solution Enterprise Edition
Iron Mountain® Policy Center Solution Enterprise EditionInfoGoTo
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudGurbir Singh
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
Binding corporate rules
Binding corporate rulesBinding corporate rules
Binding corporate rulesKjell Steffner
 
Why We Require GDPR?
Why We Require GDPR?Why We Require GDPR?
Why We Require GDPR?Jatin Kochhar
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxTimBee1
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxTimBee1
 
Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Andy Talbot
 
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Brian Miller, Solicitor
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy IntroductionNiclasGranqvist
 
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Ragnar Heil
 
Data protection within development
Data protection within developmentData protection within development
Data protection within developmentowaspsuffolk
 

Similaire à OBF, OBP and GDPR (20)

Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Iron Mountain® Policy Center Solution Enterprise Edition
Iron Mountain® Policy Center Solution Enterprise EditionIron Mountain® Policy Center Solution Enterprise Edition
Iron Mountain® Policy Center Solution Enterprise Edition
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the Cloud
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
GDPR
GDPRGDPR
GDPR
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
Binding corporate rules
Binding corporate rulesBinding corporate rules
Binding corporate rules
 
Why We Require GDPR?
Why We Require GDPR?Why We Require GDPR?
Why We Require GDPR?
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
 
Binding corporate rules
Binding corporate rulesBinding corporate rules
Binding corporate rules
 
Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)
 
GDPR- The Buck Stops Here
GDPR-  The Buck Stops HereGDPR-  The Buck Stops Here
GDPR- The Buck Stops Here
 
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
 
Operando @ Cyber camp 2015
Operando @ Cyber camp 2015Operando @ Cyber camp 2015
Operando @ Cyber camp 2015
 
Data protection within development
Data protection within developmentData protection within development
Data protection within development
 

Plus de Saarni Learning Oy

Discendum - Tehokasta osaamisen kehittämistä ja hallintaa verkossa
Discendum - Tehokasta osaamisen kehittämistä ja hallintaa verkossaDiscendum - Tehokasta osaamisen kehittämistä ja hallintaa verkossa
Discendum - Tehokasta osaamisen kehittämistä ja hallintaa verkossaSaarni Learning Oy
 
OBF Academy - case Opinlakeus Network
OBF Academy - case Opinlakeus NetworkOBF Academy - case Opinlakeus Network
OBF Academy - case Opinlakeus NetworkSaarni Learning Oy
 
OBF Academy - case SkillSafari
OBF Academy - case SkillSafariOBF Academy - case SkillSafari
OBF Academy - case SkillSafariSaarni Learning Oy
 
OBF Academy Mar. 20 2018 - Case: The Guides and Scouts of Finland
OBF Academy Mar. 20 2018 - Case: The Guides and Scouts of FinlandOBF Academy Mar. 20 2018 - Case: The Guides and Scouts of Finland
OBF Academy Mar. 20 2018 - Case: The Guides and Scouts of FinlandSaarni Learning Oy
 
Badge Finland kickoff 24.11.2017
Badge Finland kickoff 24.11.2017Badge Finland kickoff 24.11.2017
Badge Finland kickoff 24.11.2017Saarni Learning Oy
 
OBF Academy Nov. 6 2017: eCampusOnstario (part 2)
OBF Academy Nov. 6 2017: eCampusOnstario (part 2)OBF Academy Nov. 6 2017: eCampusOnstario (part 2)
OBF Academy Nov. 6 2017: eCampusOnstario (part 2)Saarni Learning Oy
 
OBF Academy Nov. 6 2017: eCampusOntario (Part 1)
OBF Academy Nov. 6 2017: eCampusOntario (Part 1)OBF Academy Nov. 6 2017: eCampusOntario (Part 1)
OBF Academy Nov. 6 2017: eCampusOntario (Part 1)Saarni Learning Oy
 
OBF Academy - Case Humanitarian Passport Initiative 25.9.2017
OBF Academy - Case Humanitarian Passport Initiative 25.9.2017 OBF Academy - Case Humanitarian Passport Initiative 25.9.2017
OBF Academy - Case Humanitarian Passport Initiative 25.9.2017 Saarni Learning Oy
 
OBF Academy - V2.0 and Multilingual Badges
OBF Academy - V2.0 and Multilingual BadgesOBF Academy - V2.0 and Multilingual Badges
OBF Academy - V2.0 and Multilingual BadgesSaarni Learning Oy
 
OBF Academy: Customer case - North Kirkwood Middle School
OBF Academy: Customer case - North Kirkwood Middle SchoolOBF Academy: Customer case - North Kirkwood Middle School
OBF Academy: Customer case - North Kirkwood Middle SchoolSaarni Learning Oy
 
OBF Academy: Unlock the potential of badge applications!
OBF Academy: Unlock the potential of badge applications!OBF Academy: Unlock the potential of badge applications!
OBF Academy: Unlock the potential of badge applications!Saarni Learning Oy
 
OBF Academy - Case "All Aboard!"
OBF Academy - Case "All Aboard!"OBF Academy - Case "All Aboard!"
OBF Academy - Case "All Aboard!"Saarni Learning Oy
 
Welcome to the Salava project final
Welcome to the Salava project finalWelcome to the Salava project final
Welcome to the Salava project finalSaarni Learning Oy
 
Open Badge Factory Academy - OBF ABC for Beginners
Open Badge Factory Academy - OBF ABC for BeginnersOpen Badge Factory Academy - OBF ABC for Beginners
Open Badge Factory Academy - OBF ABC for BeginnersSaarni Learning Oy
 

Plus de Saarni Learning Oy (20)

Discendum - Tehokasta osaamisen kehittämistä ja hallintaa verkossa
Discendum - Tehokasta osaamisen kehittämistä ja hallintaa verkossaDiscendum - Tehokasta osaamisen kehittämistä ja hallintaa verkossa
Discendum - Tehokasta osaamisen kehittämistä ja hallintaa verkossa
 
Discendum Oy - Esittely
Discendum Oy - EsittelyDiscendum Oy - Esittely
Discendum Oy - Esittely
 
OBF Academy - case Opinlakeus Network
OBF Academy - case Opinlakeus NetworkOBF Academy - case Opinlakeus Network
OBF Academy - case Opinlakeus Network
 
OBF Academy - case EHYT ry
OBF Academy - case EHYT ryOBF Academy - case EHYT ry
OBF Academy - case EHYT ry
 
OBF Academy - case SkillSafari
OBF Academy - case SkillSafariOBF Academy - case SkillSafari
OBF Academy - case SkillSafari
 
OBF et RGPD
OBF et RGPDOBF et RGPD
OBF et RGPD
 
Priima_WS_ITK2018
Priima_WS_ITK2018Priima_WS_ITK2018
Priima_WS_ITK2018
 
OBF Academy Mar. 20 2018 - Case: The Guides and Scouts of Finland
OBF Academy Mar. 20 2018 - Case: The Guides and Scouts of FinlandOBF Academy Mar. 20 2018 - Case: The Guides and Scouts of Finland
OBF Academy Mar. 20 2018 - Case: The Guides and Scouts of Finland
 
Badge Finland kickoff 24.11.2017
Badge Finland kickoff 24.11.2017Badge Finland kickoff 24.11.2017
Badge Finland kickoff 24.11.2017
 
OBF Academy Nov. 6 2017: eCampusOnstario (part 2)
OBF Academy Nov. 6 2017: eCampusOnstario (part 2)OBF Academy Nov. 6 2017: eCampusOnstario (part 2)
OBF Academy Nov. 6 2017: eCampusOnstario (part 2)
 
OBF Academy Nov. 6 2017: eCampusOntario (Part 1)
OBF Academy Nov. 6 2017: eCampusOntario (Part 1)OBF Academy Nov. 6 2017: eCampusOntario (Part 1)
OBF Academy Nov. 6 2017: eCampusOntario (Part 1)
 
OBF Academy - Case Humanitarian Passport Initiative 25.9.2017
OBF Academy - Case Humanitarian Passport Initiative 25.9.2017 OBF Academy - Case Humanitarian Passport Initiative 25.9.2017
OBF Academy - Case Humanitarian Passport Initiative 25.9.2017
 
OBF Academy - V2.0 and Multilingual Badges
OBF Academy - V2.0 and Multilingual BadgesOBF Academy - V2.0 and Multilingual Badges
OBF Academy - V2.0 and Multilingual Badges
 
OBF Academy 15.5.2017
OBF Academy 15.5.2017 OBF Academy 15.5.2017
OBF Academy 15.5.2017
 
Optima Connect - tiedote1
Optima Connect - tiedote1Optima Connect - tiedote1
Optima Connect - tiedote1
 
OBF Academy: Customer case - North Kirkwood Middle School
OBF Academy: Customer case - North Kirkwood Middle SchoolOBF Academy: Customer case - North Kirkwood Middle School
OBF Academy: Customer case - North Kirkwood Middle School
 
OBF Academy: Unlock the potential of badge applications!
OBF Academy: Unlock the potential of badge applications!OBF Academy: Unlock the potential of badge applications!
OBF Academy: Unlock the potential of badge applications!
 
OBF Academy - Case "All Aboard!"
OBF Academy - Case "All Aboard!"OBF Academy - Case "All Aboard!"
OBF Academy - Case "All Aboard!"
 
Welcome to the Salava project final
Welcome to the Salava project finalWelcome to the Salava project final
Welcome to the Salava project final
 
Open Badge Factory Academy - OBF ABC for Beginners
Open Badge Factory Academy - OBF ABC for BeginnersOpen Badge Factory Academy - OBF ABC for Beginners
Open Badge Factory Academy - OBF ABC for Beginners
 

Dernier

UI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptxUI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptxAndreas Kunz
 
Post Quantum Cryptography – The Impact on Identity
Post Quantum Cryptography – The Impact on IdentityPost Quantum Cryptography – The Impact on Identity
Post Quantum Cryptography – The Impact on Identityteam-WIBU
 
Xen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdfXen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdfStefano Stabellini
 
SpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at RuntimeSpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at Runtimeandrehoraa
 
英国UN学位证,北安普顿大学毕业证书1:1制作
英国UN学位证,北安普顿大学毕业证书1:1制作英国UN学位证,北安普顿大学毕业证书1:1制作
英国UN学位证,北安普顿大学毕业证书1:1制作qr0udbr0
 
Cyber security and its impact on E commerce
Cyber security and its impact on E commerceCyber security and its impact on E commerce
Cyber security and its impact on E commercemanigoyal112
 
VK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web DevelopmentVK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web Developmentvyaparkranti
 
Odoo 14 - eLearning Module In Odoo 14 Enterprise
Odoo 14 - eLearning Module In Odoo 14 EnterpriseOdoo 14 - eLearning Module In Odoo 14 Enterprise
Odoo 14 - eLearning Module In Odoo 14 Enterprisepreethippts
 
PREDICTING RIVER WATER QUALITY ppt presentation
PREDICTING  RIVER  WATER QUALITY  ppt presentationPREDICTING  RIVER  WATER QUALITY  ppt presentation
PREDICTING RIVER WATER QUALITY ppt presentationvaddepallysandeep122
 
Introduction Computer Science - Software Design.pdf
Introduction Computer Science - Software Design.pdfIntroduction Computer Science - Software Design.pdf
Introduction Computer Science - Software Design.pdfFerryKemperman
 
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...OnePlan Solutions
 
A healthy diet for your Java application Devoxx France.pdf
A healthy diet for your Java application Devoxx France.pdfA healthy diet for your Java application Devoxx France.pdf
A healthy diet for your Java application Devoxx France.pdfMarharyta Nedzelska
 
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanySuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanyChristoph Pohl
 
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...Angel Borroy López
 
Precise and Complete Requirements? An Elusive Goal
Precise and Complete Requirements? An Elusive GoalPrecise and Complete Requirements? An Elusive Goal
Precise and Complete Requirements? An Elusive GoalLionel Briand
 
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company OdishaBalasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odishasmiwainfosol
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsAhmed Mohamed
 
Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)Hr365.us smith
 
Salesforce Implementation Services PPT By ABSYZ
Salesforce Implementation Services PPT By ABSYZSalesforce Implementation Services PPT By ABSYZ
Salesforce Implementation Services PPT By ABSYZABSYZ Inc
 

Dernier (20)

UI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptxUI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptx
 
Post Quantum Cryptography – The Impact on Identity
Post Quantum Cryptography – The Impact on IdentityPost Quantum Cryptography – The Impact on Identity
Post Quantum Cryptography – The Impact on Identity
 
Xen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdfXen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdf
 
SpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at RuntimeSpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at Runtime
 
英国UN学位证,北安普顿大学毕业证书1:1制作
英国UN学位证,北安普顿大学毕业证书1:1制作英国UN学位证,北安普顿大学毕业证书1:1制作
英国UN学位证,北安普顿大学毕业证书1:1制作
 
Cyber security and its impact on E commerce
Cyber security and its impact on E commerceCyber security and its impact on E commerce
Cyber security and its impact on E commerce
 
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort ServiceHot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
 
VK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web DevelopmentVK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web Development
 
Odoo 14 - eLearning Module In Odoo 14 Enterprise
Odoo 14 - eLearning Module In Odoo 14 EnterpriseOdoo 14 - eLearning Module In Odoo 14 Enterprise
Odoo 14 - eLearning Module In Odoo 14 Enterprise
 
PREDICTING RIVER WATER QUALITY ppt presentation
PREDICTING  RIVER  WATER QUALITY  ppt presentationPREDICTING  RIVER  WATER QUALITY  ppt presentation
PREDICTING RIVER WATER QUALITY ppt presentation
 
Introduction Computer Science - Software Design.pdf
Introduction Computer Science - Software Design.pdfIntroduction Computer Science - Software Design.pdf
Introduction Computer Science - Software Design.pdf
 
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
 
A healthy diet for your Java application Devoxx France.pdf
A healthy diet for your Java application Devoxx France.pdfA healthy diet for your Java application Devoxx France.pdf
A healthy diet for your Java application Devoxx France.pdf
 
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanySuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
 
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
 
Precise and Complete Requirements? An Elusive Goal
Precise and Complete Requirements? An Elusive GoalPrecise and Complete Requirements? An Elusive Goal
Precise and Complete Requirements? An Elusive Goal
 
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company OdishaBalasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML Diagrams
 
Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)
 
Salesforce Implementation Services PPT By ABSYZ
Salesforce Implementation Services PPT By ABSYZSalesforce Implementation Services PPT By ABSYZ
Salesforce Implementation Services PPT By ABSYZ
 

OBF, OBP and GDPR

  • 1. What GDPR compliancy means for Open Badge Factory and Open Badge Passport users Eric Rousselle
  • 2. About the EU General Data Protection Regulation • We’ve always been committed to protect personal data in all our services • EU General Data Protection Regulation (GDPR) is beneficial for all parties as it sets clear rules for personal data protection • GDPR brings transparency and therefore supports trust • We’ve made necessary modifications to get OBF and OBP GDPR compliant before May 25 • OBF and OBP will be updated on May 22 and 23
  • 3. GDPR terminology • Personal data is information relating to an identifiable living individual • Data subject means an individual who is the subject of personal data • Data controller means usually an organisation which determines the purposes for which and the manner in which any personal data are, or are to be, processed • Data processor, means any person (usually organisation) who processes the data on behalf of the data controller
  • 4. What rights GDPR gives to individuals? • a right of access to a copy their personal data • a right to object to processing • a right to have personal data rectified, blocked, erased or destroyed or anonymised • See the complete list: https://ico.org.uk/for-organisations/guide-to-data- protection/principle-6-rights/
  • 5. Data protection principles • Personal data shall be processed fairly and lawfully • Personal data shall be processed in accordance with the rights of data subjects • Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data • See: https://ico.org.uk/for-organisations/guide-to-data-protection/data- protection-principles/
  • 6. GDPR and Open Badge Factory • data controller is a customer organisation using OBF to create and issue badges • data processor is the service provider (Discendum) • OBF customer’s admin(s), registered users (creators and issuers) are data subjects • Badge recipients are also considered as data subjects because their personal data is used to issue badges (email address, name, surname, data submitted in badge application forms)
  • 7. How data subjects can access their personal data? • OBF users (registered) can list their personal data in OBF and erase their account and all their personal data if they wish to do so • When receiving a badge, a badge recipient will get a link to check (using their email address) what personal data is stored and processed in OBF • Badge recipient can request their personal data (name, surname, email address, possibly also data submitted in badge request / application forms) to be anonymised or erased • Data subject’s requests have to be processed by the data controller (customer) promptly (in a maximum delay of 40 calendar days) • Data processor can not / will not anonymise or erase personal data on behalf of the data controller (customer)
  • 8. OBF documents • DPA (Data Processing Agreement) • This document is an annex, part of the agreement between the Service provider and its Customer. The purpose of this Annex is to agree on the privacy and data protection of the personal data of the Customer in the services of the Service Provider. • Terms and Conditions • Privacy notice (annex of Terms and Conditions) • Tells users what data is processed. On what legal basis and for what purpose. • These documents will be displayed to users when they log in to OBF (May 22). No agreement needs to be signed. Using OBF is considered as an agreement.
  • 10. • From GDPR point of view, OBP is a straightforward case • The service provider is data controller and data processor • OBP users are data subjects • User creates their own account in OBP (accounts aren’t created on their behalf) • User brings their personal data to OBP • User has access to their personal data • User can delete all personal data and their account • Service provider doesn’t delete data on behalf of the user
  • 11. OBP documents • Terms and Conditions • Privacy notice (annex of Terms and Conditions)
  • 12. Good to know • Both OBF and OBP are hosted in an EU country (Finland) • The cloud service provider of both OBF and OBP is GDPR compliant • Aligning to GDPR is a requirement for all European companies • OBF and OBP data is protected (firewalls, etc.) and backed up daily. Passwords and network connections are encrypted • OBF’s and OBP’s data processor (service provider) doesn’t transfer any data into other services (except for back up purposes) • When a customer issues badges in a Learning Management System using an OBF plugin, some data is transferred between the systems • Badges are usually hosted in OBF’s server, but in some cases customer can set up their own Badge Record Storage to host their badges in their own server
  • 13. OBF and OBP are “low risk services” • Personal data stored and processed in both systems is not “sensitive data” • The amount of personal data used is small • Open Badge is an earner centric concept, recipient can always decide how to use and display their badges • Badge earners have the right not to display and share their badges but it is good to keep in mind that the Open Badges concept has been built to recognise and communicate achievements, skills, competencies, attitudes, etc. and therefore openness and sharing are in the core of the concept!