bs227 / mywebclass-simulation

MIT License
0 stars 0 forks source link

 As a website owner, I want to implement GDPR requirements using Consent API and Javascript, so that I can comply with data protection regulations and protect user privacy #28

Open bs227 opened 1 year ago

navyarangu13 commented 1 year ago

Acceptance Criteria

  1. The website must include a Consent API and Javascript to implement GDPR requirements.
  2. The Consent API and Javascript must be properly integrated and functioning correctly on all relevant pages of the website.
  3. The user must be presented with a clear and concise message about the use of cookies and tracking technologies on the website, along with a link to the website's privacy policy.
  4. The user must be able to give and withdraw consent to the use of cookies and tracking technologies.
  5. If the user chooses to withdraw consent, the website must stop using cookies and tracking technologies.
  6. The website must not use cookies or tracking technologies for any purpose other than what the user has consented to.
  7. The website must provide a mechanism for users to request access to, correction of, or deletion of their personal data.
  8. Personal data must be securely stored and protected from unauthorized access, disclosure, and destruction.
  9. The website must display a cookie banner to users who have not yet given consent.
  10. The user enters incorrect data and is unable to give or withdraw consent.
  11. The website does not stop using cookies and tracking technologies after the user withdraws consent.
  12. The website uses cookies or tracking technologies for purposes other than what the user has consented to.

Story Points: 8

Estimation: 2-3 weeks

Resources: legal expertise, GDPR guidelines, Consent API and Javascript, testing resources.

Importance: High

Urgency: High