Open-Credentialing-Initiative / Digital-Wallet-Conformance-Criteria

Conformance Criteria for Digital Wallets | https://open-credentialing-initiative.github.io/Digital-Wallet-Conformance-Criteria/latest
https://open-credentialing-initiative.github.io/Digital-Wallet-Conformance-Criteria/latest
Apache License 2.0
1 stars 2 forks source link

NFR010 Archiving #13

Closed bluesteens closed 1 year ago

bluesteens commented 2 years ago

Steering summary: NFR requires wallets to keep transaction records for 6+ years. The duration of record-keeping should be dealt with in customer contracts. Suggest rewording to require capability of record storage & transfer without specifying the duration.


the criteria state,

The Wallet Provider SHALL keep detailed records of all VP generation and verification events as well as monitoring activities for a period of not less than six (6) years.

The duration of record-keeping should be dealt with in customer contracts. This requirement ignores the fact that contracts may end before 6 years are up. Does OCI require a wallet provider to keep records of ex-customers (for free)? Customers and providers should negotiate data retention and transfer in their service contract. Setting the duration is beyond the scope of OCI in my opinion. What OCI can ask for is that wallets are capable of relevant data logging.

I suggest to re-word the criteria section as follows:

The Wallet Provider SHALL be capable of keeping detailed records of all VP generation and verification events as well as monitoring activities. These detailed records constitute an audit trail to be used in the event of an investigation into credential-related activities of the credential holder.

It may be added that:

The Wallet Provider SHALL be capable of transferring such records to the user.

bluesteens commented 1 year ago

Triage:

Affected Parties (help determine Sunrise/Sunset):

Affected OCI Artifact

Change Category (Guides Steering Review)

- Steering/Industry Review

- Steering/Industry Notification

bluesteens commented 1 year ago

relates to issue https://github.com/Open-Credentialing-Initiative/Digital-Wallet-Conformance-Criteria/issues/43