InteractiveAdvertisingBureau / GDPR-Transparency-and-Consent-Framework

Technical specifications for IAB Europe Transparency and Consent Framework that will help the digital advertising industry interpret and comply with EU rules on data protection and privacy - notably the General Data Protection Regulation (GDPR) that comes into effect on May 25, 2018.
868 stars 359 forks source link

Clarification on restrictions #244

Closed achimschloss closed 4 years ago

achimschloss commented 4 years ago

As discussed in https://github.com/InteractiveAdvertisingBureau/GDPR-Transparency-and-Consent-Framework/pull/220 - some more explicit description in the section "What are publisher restrictions?". Looking at the discussion it seem good to make it more explicit

@chrispaterson the TC Core String details description contains some language in the notes that restrictions should be respected even without flexibility, not sure I you'd want to change that given the code would not even allow them to be written just now

achimschloss commented 4 years ago

Adding here - the language around default legal basis is already present in the spec, but just in the annotated example global vendor list - seem even more reasonable to give this a bit more visibility. What missing here is that the default can only be changes via a restriction.

`

https://github.com/InteractiveAdvertisingBureau/GDPR-Transparency-and-Consent-Framework/blob/master/TCFv2/IAB%20Tech%20Lab%20-%20Consent%20string%20and%20vendor%20list%20formats%20v2.md#example-global-vendor-list-json-object

Facens commented 4 years ago

@asr-enid thanks, the changes look good to me. What about also adding to the CMP guidelines that CMPs can avoid sending redundant information, as per the gdoc here? https://docs.google.com/document/d/1yoYN-iD7wlLjPt1DyEYN8KFAyiO_yZGk_CWhiWOnqAI/edit?disco=AAAAG15TmLU&ts=5f720228&usp_dm=false I can review if you take the lead and add it, so we can get this moving forward quickly. Thanks!

achimschloss commented 4 years ago

@Facens - you mean within the general implementation guidelines? https://github.com/InteractiveAdvertisingBureau/GDPR-Transparency-and-Consent-Framework/blob/master/TCFv2/TCF-Implementation-Guidelines.md#cmp

Facens commented 4 years ago

@asr-enid Yes! This is what we've agreed on the latest group meeting.

achimschloss commented 4 years ago

Ok - will add something to this pull request (makes sense given its the same context), would like to get this closed

achimschloss commented 4 years ago

Added some language in the implementation guidelines to reflect in which cases restrictions are necessary. Added some language that this does not preclude encoding schemes that might deviate (as suggested by @chrispaterson ) from this because they might be more space efficient with the same results

achimschloss commented 4 years ago

@Facens - let me know what you think - I'd find it highly valuable to have both clarifications merged soon.

achimschloss commented 4 years ago

@alextcone I'm good - accepted the changes from @Facens and changed the language on purpose restrictions as well as leaving vendor bits undefined rather them setting them to 0 (last commit) as suggested

alextcone commented 4 years ago

@asr-enid & @Facens - I'm reviewing the latest now and hope to have this merged by tomorrow close of business on the East Coast of the US.

Facens commented 4 years ago

@asr-enid Take a look at my comments too, all minor tweaks in English, my bad for not creating a review and filing them as single comments, thought I could convert them but can't find a way. Lmk!

achimschloss commented 4 years ago

I think we are good now, also applied the editorial comments (all but one) in https://github.com/InteractiveAdvertisingBureau/GDPR-Transparency-and-Consent-Framework/pull/244/commits/30f1686167747549e624380110ecc1d4412ca91f - GH fortunately supports batching single review comments together

Facens commented 4 years ago

I think we're good! @alextcone FF to give it a final read and merge!