w3c-ccg / vc-ed-use-cases

https://w3c-ccg.github.io/vc-ed-use-cases/
Other
9 stars 3 forks source link

Clause 5.11.3 #18

Open David-Chadwick opened 1 year ago

David-Chadwick commented 1 year ago

Clause 5.11.3 states "Because of GDPR, Laura’s training certificate credential continues to be verifiable even though the her account and data has been removed from the training platform."

Is this realistic? Won't the trainer keep a permanent record of all the certificates it has issued? This might not be an online record, but it should certainly be in its audit trail. Otherwise what happens when the VC crypto is broken or otherwise fails or expires? How can the trainer know if the training certificate is valid or not? How can the trainer issue a fresh VC? How can the trainer revoke the VC is fraud is subsequently detected?

Suggest change to "Because of GDPR, Laura’s training certificate credential continues to be verifiable even though the her account and data has been removed from the online training platform. Note. The trainer will still keep a record of all the training certificates it has issued during their valid lifetime."