Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove Personal Data of Contributors from Public Repository #125

Open
7 tasks
valerydluski opened this issue Apr 21, 2024 · 2 comments
Open
7 tasks

Remove Personal Data of Contributors from Public Repository #125

valerydluski opened this issue Apr 21, 2024 · 2 comments
Labels
blocked For task blocked other tasks

Comments

@valerydluski
Copy link

Description

The current practice of storing personal data of contributors, such as photos, in the public repository presents privacy concerns and violates general data protection principles. This issue outlines the steps needed to remove such data and suggests alternative secure storage solutions.

Objectives

  • Enhance Privacy: To protect the personal information of all contributors.
  • Comply with Data Protection Laws: To ensure our repository practices align with global data protection regulations.
  • Identify Secure Storage Alternatives: To provide secure and compliant alternatives for storing personal data.

Tasks

  1. Data Audit:

    • Identify all instances of personal data (e.g., photos, personal bios) in the repository.
    • Document where personal data is currently stored within the repository.
  2. Data Removal:

    • Remove all personal data of contributors from the repository.
    • Ensure backups and forks are also cleared of such data.
  3. Policy Update:

    • Update the repository's contribution guidelines to prohibit future uploads of personal data.
    • Implement a review process for future contributions to prevent similar issues.
  4. Research and Implement Alternative Storage Solutions:

    • Evaluate and select from the following alternatives for secure storage of personal data:
      • Private cloud storage solutions.
      • Internal databases with strict access controls.

Expected Outcome

Upon completion, the repository will no longer contain any personal data of contributors, thereby ensuring their privacy and aligning the project with best practices in data protection. Additionally, a secure and compliant alternative for storing personal data will be established.

Additional Notes

This task requires collaboration with the repository administrators and possibly legal advice to ensure compliance with data protection laws. A detailed timeline and responsibilities will be established following the initial audit phase.

@dzmitry-varabei
Copy link
Member

ChatGPT says that if implementation is difficult, we can get consent from contributors via a Google form. Example below:

Contributor Consent Form
Purpose: This form collects consent for displaying contributors' information on public platforms, like websites or repositories.

Contributor Information
Full Name: (Text Field)
Email Address: (Text Field)
Contributor Details
Photo: (File Upload Field)
Biography: (Text Area)
Consent for Public Display
Do you consent to the use of your name in public repositories or websites?
Yes
No
Do you consent to the use of your photo in public repositories or websites?
Yes
No
Do you consent to the use of your biography in public repositories or websites?
Yes
No
Additional Information
Data Retention Policy: Once information is published in public repositories or websites, it might not be completely removable.
Consent Withdrawal: If you withdraw consent, we will attempt to minimize exposure by removing or anonymizing the data where possible.

@natanchik natanchik added this to RS Site Jul 8, 2024
@natanchik natanchik moved this to Backlog in RS Site Jul 8, 2024
@ansivgit ansivgit moved this from Backlog to Todo in RS Site Feb 13, 2025
@ansivgit ansivgit added blocked For task blocked other tasks and removed high priority labels Feb 20, 2025
@ansivgit
Copy link
Collaborator

Blocked #732

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
blocked For task blocked other tasks
Projects
Status: Todo
Development

No branches or pull requests

3 participants