cds-snc / notification-planning

Project planning for GC Notify Team
5 stars 0 forks source link

Make a document that outlines where we collect IP addresses and for how long + AWS retention #946

Open sharlychan-cds opened 2 years ago

sharlychan-cds commented 2 years ago

Give your user story a simple, clear title

Description

We need to create a singular document that outlines when we log an IP address and how long we keep it on Notify. This is for the Privacy Analysis work we are doing.

As a client who uses notify, I need to be able to know what instances where we keep an IP address and for how long, so that I can be in compliance with my own department's policies.

Team to discuss adding: retention limits for AWS (e.g. SNS is 4 days). Might be worth doing this into an adr

Acceptance Criteria** (Definition of done)

Find instances in:

To be refined through discussion with the team

sharlychan-cds commented 2 years ago

Jimmy notes how we could also write an adr for AWS retention (these need to be double checked for accuracy):

YedidaZalik commented 1 year ago

@yaelberger-commits @mtoutloff I wonder if this card can be moved to done or does our privacy statement need more detail on this?

mtoutloff commented 1 year ago

@yaelberger-commits @YedidaZalik for now, I don't think we need to make changes to the privacy statement in relation to this issue. My understanding is that Sharly recommended we document IP addresses as part of the Privacy Analysis. There is some info on what we do with IP addresses already in the PA and it's almost final, so I don't know that we need to document it directly in the PA. What happens with IP addresses may come up as part of PTM scoping work, so perhaps we put this in the icebox for now?