linuxaudio / conference2018

Planning issue tracker for LAC2018
GNU General Public License v3.0
1 stars 0 forks source link

Be GDPR compliant #52

Closed dvzrv closed 6 years ago

dvzrv commented 6 years ago

I know, I know, the timing couldn't be better, but:

A processor of personal data must clearly disclose any data collection, declare the lawful basis and purpose for data processing, how long data is being retained, and if it is being shared with any third-parties or outside of the EU. Users have the right to request a portable copy of the data collected by a processor in a common format, and the right to have their data erased under certain circumstances. Public authorities, and businesses whose core activities centre around regular or systematic processing of personal data, are required to employ a data protection officer (DPO), who is responsible for managing compliance with the GDPR. Businesses must report any data breaches within 72 hours if they have an adverse effect on user privacy.

source: https://en.wikipedia.org/wiki/General_Data_Protection_Regulation

We need to inform each participant and each presenter about the intended streaming (and have opt-outs for media.ccc.de or youtube.com) and the usage of their metadata (on the website and the aformentioned platforms).

As I have no clue about the whole thing, I'll ask bengoshi (from c-base) about it.

ri0t commented 6 years ago

live.linuxaudio.org has its own ToS which might/should even be GDPR compliant. The participant registration is another potential minor issue.

dvzrv commented 6 years ago

This is not really what this issue is about, but maybe your live system is somehow also affected by this. I'm explicitely referring to streaming here.

I think we will have to a) mention all of this on the website (as streaming potentially also affects visitors!) and b) write to all presenters and ask for their permission to stream their presentation.

dvzrv commented 6 years ago

Got referred to use this: https://datenschutz-generator.de/, which I will use for the website. We need to formulate something similar to be sent to all presenters.

dvzrv commented 6 years ago

Added all presenters and artists to a mailing list. The privacy statement is in place on the website, but not actively linked anywhere yet. Later I'll write a post and send an e-mail to all affected people regarding the privacy statement, streaming and licensing.

dvzrv commented 6 years ago

Sent out e-mail to all presenters informing about privacy statement and licensing model for streaming and video uploads to platforms (CC BY-NC-SA 4.0) such as media.ccc.de and youtube.com.

dvzrv commented 6 years ago

the agreement only needs to be printed about 50 times now and setup at the bar.