maproulette / maproulette3

MapRoulette, the micro-tasking tool for OpenStreetMap
https://maproulette.org
MIT License
120 stars 32 forks source link

GDPR compliance #137

Open mvexel opened 6 years ago

mvexel commented 6 years ago

We need to ensure that MapRoulette complies with the new European regulations regarding personal information.

GDPR may apply to us if we collect any personal information about citizens in the EU. The regulations may apply to MapRoulette even if we think they won't.

I'll research and follow up.

mgcuthbert commented 6 years ago

The only potentially personal user information that we may collect is the users location. And this is something that is collected from OpenStreetMap and not directly from us. Otherwise the only reference we have to the user is their OSM id and their OSM username. So if collecting their location falls under the regulations, we can easily remove that.

mvexel commented 6 years ago

Resources I'm working through:

@mgcuthbert are we retaining web server logs indefinitely currently?

mvexel commented 6 years ago

I started writing a diary post on how we deal with privacy and PII that should clarify things for users. I am planning to post this on the OSM diary site.

Here is the draft. @nrotstan @mgcuthbert could you check for factual correctness and completeness? And make any suggestions for additional things to cover?

nrotstan commented 6 years ago

Here are a few thoughts that pop into my head:

mvexel commented 4 years ago

Keeping this open as something to monitor and for the user community to voice concerns around GDPR and MapRoulette.

mvexel commented 1 month ago

Checking in on this ticket. I'm going to keep this open since it's something that may still come up but we won't pro-actively pursue this.