[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[EP-tech] GDPR and the "Request a copy" buttonn



Another issue is that this form passes data to your academics. They can't do anything else with that data... ie. add people to a mailing list or whatever.

On 15/02/2019 10:22, John Salter via Eprints-tech wrote:
Hi,
A standard install of EPrints will retain the requests made. Look in the 'request' table.

There is also some data stored in the history dataset - when someone (e.g. the author) responds to a request:
https://github.com/eprints/eprints/blob/3.3/perl_lib/EPrints/Plugin/Screen/Request/Respond.pm#L199-L217<https://emea01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Feprints%2Feprints%2Fblob%2F3.3%2Fperl_lib%2FEPrints%2FPlugin%2FScreen%2FRequest%2FRespond.pm%23L199-L217&data=01%7C01%7C%7C909eda7d3d044d64038b08d6933325a8%7C4a5378f929f44d3ebe89669d03ada9d8%7C1&sdata=7b6%2B56E9xTIr6bg0mu256A29Z4NBXNbBj%2FEiIHyoLqs%3D&reserved=0>

If you look in the history table for rows with 'action' set to 'accept_request', 'oa_request' or 'reject_request', you can see what information is stored. It includes the reason for rejection - which may have data in it that you need to consider in relation to GDPR.

I'm currently pondering what to do with this data.
Retaining statistics about items that have been requested is useful - but the details of who made the requests should be removed according to GDPR regulations.
I may end up setting the details in the Request dataset to a standard (e.g. 'removed-for-gdpr at example.com<mailto:removed-for-gdpr at example.com>' for the email address), or we may store counts of what items were requested and when.

The IRStats package can process the requests data too - so removing the entries entirely will mean if you regenerate the stats from scratch, your historic usage data will change.

Cheers,
John


From: eprints-tech-bounces at ecs.soton.ac.uk<mailto:eprints-tech-bounces at ecs.soton.ac.uk> [mailto:eprints-tech-bounces at ecs.soton.ac.uk] On Behalf Of Siminson ,Nicola Jane via Eprints-tech
Sent: 15 February 2019 08:55
To: Laszlo Csirmaz <laci at degas.ceu.hu><mailto:laci at degas.ceu.hu>; eprints-tech at ecs.soton.ac.uk<mailto:eprints-tech at ecs.soton.ac.uk>
Subject: Re: [EP-tech] GDPR and the "Request a copy" buttonn

Hello Laszlo,
Many thanks for your interesting reply. In terms of the data not being kept, I note that https://wiki.eprints.org/w/GDPR<https://emea01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.eprints.org%2Fw%2FGDPR&data=01%7C01%7C%7C909eda7d3d044d64038b08d6933325a8%7C4a5378f929f44d3ebe89669d03ada9d8%7C1&sdata=xqOmbwcjVDKqVFYps8TDponwL1Zj0q1%2FUn%2BdlrCfgcQ%3D&reserved=0> states:
Request a copy Dataset
This collects an email address and a reason for requesting the document. Without intervention this can be stored indefinitely.
Have you therefore set your own instance of EPrints not to store the data - or how do you monitor when the requested paper has been forwarded or rejected?

With thanks and best wishes,

Nicola

Nicola Siminson | Institutional Repository and Records Manager
The Glasgow School of Art | 167 Renfrew Street | Glasgow | G3 6RQ | Tel: 0141 566 1417 | Email: n.siminson at gsa.ac.uk<mailto:n.siminson at gsa.ac.uk> | www.gsa.ac.uk<https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.gsa.ac.uk&data=01%7C01%7C%7C909eda7d3d044d64038b08d6933325a8%7C4a5378f929f44d3ebe89669d03ada9d8%7C1&sdata=4hwlTJWQ2xJEr%2F0DkoHFfL60DnvNv4qlwc0mjXOBj%2BQ%3D&reserved=0>

-----Original Message-----
From: Laszlo Csirmaz [mailto:laci at degas.ceu.hu]
Sent: 14 February 2019 21:20
To: eprints-tech at ecs.soton.ac.uk<mailto:eprints-tech at ecs.soton.ac.uk>; Siminson ,Nicola Jane <N.Siminson at gsa.ac.uk<mailto:N.Siminson at gsa.ac.uk>>
Subject: Re: [EP-tech] GDPR and the "Request a copy" buttonn

Dear Nicola,

according to my understanding, GDPR is relevant only if you KEEP the data.
In this case the data is not kept, only during the time it is necessary to forward the requested paper (or reject it). In this case GDPR is not relevant and gives no legally binding obligations.

Hope this helps.
Best,

Laszlo
Laszlo Csirmaz,
CEU

> Hello,
> I think there was some mention of GDPR on this list last year, but I'm
> struggling to see how to actually search the list archive (https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fmailman.ecs.soton.ac.uk%2Fpipermail%2Feprints-tech%2F&amp;data=02%7C01%7CN.Siminson%40gsa.ac.uk%7C3788272b77964417749c08d692c21c54%7C67f9795821514513bd2170cde632768b%7C0%7C1%7C636857759744238597&amp;sdata=CaUxyW%2FaE4uDQrH7mmjJ6J8w6D5FF%2BO6CuTWXd1yxl8%3D&amp;reserved=0<https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fmailman.ecs.soton.ac.uk%2Fpipermail%2Feprints-tech%2F&data=01%7C01%7C%7C909eda7d3d044d64038b08d6933325a8%7C4a5378f929f44d3ebe89669d03ada9d8%7C1&sdata=guN0wTtdfxUdPkNWxC%2B%2FEH0pEn5ka4iYA%2FhJcowZZNc%3D&reserved=0>). I  know also that this was a topic at the EPrints user group meeting within the Repository Fringe event in Edinburgh last summer - but I'm not aware of any further information emerging from that session either.
> And finally - I am familiar with this page and its contents - but
> there are still quite a lot of items marked as "TO DO", including the
> section "Request a copy Dataset":
> https://emea01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwik
> i.eprints.org%2Fw%2FGDPR&amp;data=02%7C01%7CN.Siminson%40gsa.ac.uk%7C3
> 788272b77964417749c08d692c21c54%7C67f9795821514513bd2170cde632768b%7C0
> %7C0%7C636857759744238597&amp;sdata=DrD643XyYvQyiBfeE%2FGCv4cP9Sa432bu
> KIfxgzTqk04%3D&amp;reserved=0
>
> My question is this: Would anyone on this list be willing to share with me what they consider the legal basis to be for processing personal data which is received when a user selects the "Request a copy" button, and fills in their contact details etc.? I realise that each institution makes a decision on which of the 6 legal bases it chooses for each of its processing activities - so I'm interested (on or off-list!) to know what colleagues think, and / or what you have stated in your privacy notices!
>
> With many thanks in advance for considering my request   :-)
>
> Best wishes,
>
> Nicola
>
> Nicola Siminson
> Institutional Repository and Records Manager The Glasgow School of Art
> n.siminson at gsa.ac.uk<mailto:n.siminson at gsa.ac.uk<mailto:n.siminson at gsa.ac.uk%3cmailto:n.siminson at gsa.ac.uk>>
>
> *** Options:
> https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fmail
> man.ecs.soton.ac.uk%2Fmailman%2Flistinfo%2Feprints-tech&amp;data=02%7C
> 01%7CN.Siminson%40gsa.ac.uk%7C3788272b77964417749c08d692c21c54%7C67f97
> 95821514513bd2170cde632768b%7C0%7C1%7C636857759744238597&amp;sdata=NyR
> %2B9LToHNz%2FB12bvROtDHg1zAjmYIbdyfJaqridA8g%3D&amp;reserved=0
> *** Archive:
> https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.
> eprints.org%2Ftech.php%2F&amp;data=02%7C01%7CN.Siminson%40gsa.ac.uk%7C
> 3788272b77964417749c08d692c21c54%7C67f9795821514513bd2170cde632768b%7C
> 0%7C1%7C636857759744238597&amp;sdata=L9s50oSaPUxvkQHyqiebPhVD6CPpZmqFE
> uuky1jlEqQ%3D&amp;reserved=0
> *** EPrints community wiki:
> https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwiki
> .eprints.org%2F&amp;data=02%7C01%7CN.Siminson%40gsa.ac.uk%7C3788272b77
> 964417749c08d692c21c54%7C67f9795821514513bd2170cde632768b%7C0%7C1%7C63
> 6857759744238597&amp;sdata=%2BmU3mYVaOy0Ymmpo5so0ulBieN3u0LsX89KZoITZ8
> Wg%3D&amp;reserved=0
> *** EPrints developers Forum:
> https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fforu
> m.eprints.org%2F&amp;data=02%7C01%7CN.Siminson%40gsa.ac.uk%7C3788272b7
> 7964417749c08d692c21c54%7C67f9795821514513bd2170cde632768b%7C0%7C1%7C6
> 36857759744248611&amp;sdata=hlbD%2FmNF0MDL017JGhlAQ0%2F7oOfn6tHIaTot8s
> gK4rY%3D&amp;reserved=0




*** Options: http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech
*** Archive: http://www.eprints.org/tech.php/<https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.eprints.org%2Ftech.php%2F&data=01%7C01%7C%7C909eda7d3d044d64038b08d6933325a8%7C4a5378f929f44d3ebe89669d03ada9d8%7C1&sdata=OGoxHm1g2OZEB4tMIClqjrmBjUbdzmpLkaE8peMiRN4%3D&reserved=0>
*** EPrints community wiki: http://wiki.eprints.org/<https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwiki.eprints.org%2F&data=01%7C01%7C%7C909eda7d3d044d64038b08d6933325a8%7C4a5378f929f44d3ebe89669d03ada9d8%7C1&sdata=epTKGnQXWOBdMqicPPNUI8o34aQEshz0IEG%2BNPPoMDA%3D&reserved=0>
*** EPrints developers Forum: http://forum.eprints.org/<https://emea01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fforum.eprints.org%2F&data=01%7C01%7C%7C909eda7d3d044d64038b08d6933325a8%7C4a5378f929f44d3ebe89669d03ada9d8%7C1&sdata=HHn0Ktw3VQCWZzv0zSaEmKof3YJKRd4AF7uT6DDixWI%3D&reserved=0>


--
Christopher Gutteridge <totl at soton.ac.uk><mailto:totl at soton.ac.uk>
You should read our team blog at http://blog.soton.ac.uk/webteam/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ecs.soton.ac.uk/pipermail/eprints-tech/attachments/20190215/c8d2bc0e/attachment-0001.html