Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 351045 - www site needs a privacy policy
Summary: www site needs a privacy policy
Status: IN_PROGRESS
Alias: None
Product: Websites
Classification: Unclassified
Component: [OLD] Social Contract (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Infrastructure
URL: https://wiki.gentoo.org/wiki/Foundati...
Whiteboard:
Keywords:
Depends on:
Blocks: 613938 613940 613942
  Show dependency tree
 
Reported: 2011-01-07 19:29 UTC by Robin Johnson
Modified: 2020-03-26 11:27 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2011-01-07 19:29:29 UTC
This may seem a bit odd, but I was asked if Gentoo had a privacy policy in general. We've got one for the mailing lists, but not for anything else.

I think we need one for Bugzilla at the least, but also a broad one to cover the rest of our sites (primarily for weblogs that contain user IPs).

The Fedora privacy policy is maybe a good one to base it off:
http://fedoraproject.org/wiki/Legal/PrivacyPolicy
Comment 1 Matt Summers (RETIRED) gentoo-dev 2011-01-07 20:45:17 UTC
For www.g.o (i.e. weblogs) we could use something like http://www.sfconservancy.org/privacy-policy/
Its nice and simple.

The Fedora version would need to be tailored a bit, most likely, and I think it might provide a nice starting point for an "authenticated user" privacy policy. Regardless, I have contacted the Foundation attorney for assistance.
Comment 2 nm (RETIRED) gentoo-dev 2011-01-07 23:36:06 UTC
Nothing the GDP can do anything about. Reassigning to infra@ for the time being -- I or another member can put it in /main/en/ and link it once it's done. (We could use a public www@ address for this kind of bug, if there's anyone on the team besides me that is.)

GDP members, feel free to CC yourselves on this bug if you feel like helping out with the policy wording, or something. :)
Comment 3 Alec Warner (RETIRED) archtester gentoo-dev Security 2011-01-08 04:43:46 UTC
I am still on www; but I watch all infra-bugs as well ;)
Comment 4 Alex Legler (RETIRED) archtester gentoo-dev Security 2012-02-13 19:43:23 UTC
(In reply to comment #1)
> The Fedora version would need to be tailored a bit, most likely, and I think it
> might provide a nice starting point for an "authenticated user" privacy policy.
> Regardless, I have contacted the Foundation attorney for assistance.

Any updates here?
Comment 5 Sven Vermeulen (RETIRED) gentoo-dev 2013-12-29 17:41:07 UTC
I don't mind taking a stab at creating a privacy policy.

Personally, I'd like to have it clear which information is kept for what service. I can make a draft with what I assume is kept, and have it then proof-read by infra to see if my assumptions stick.
Comment 6 Alex Legler (RETIRED) archtester gentoo-dev Security 2014-08-19 15:18:00 UTC
https://wiki.gentoo.org/wiki/User:A3li/Privacy_Policy_Draft

Adapted from the Fedora policy, minus lots of the 'raffle/giveaway' and partner stuff we don't do. Comments or edits welcome.
Comment 7 Sven Vermeulen (RETIRED) gentoo-dev 2014-08-30 12:33:31 UTC
Alex, thanks for taking this up.

The only comment I have is about the "Our Commitment to Data Security". It mentions the use of SSL(/TLS) but not about password protection. Considering that leaked password databases are a, well, humiliating PR nightmare if found out that the database was not properly protected (and the passwords not properly hashed and salted and what not)... would it make sense to mention this as well?
Comment 8 Alex Legler (RETIRED) archtester gentoo-dev Security 2014-10-24 11:53:14 UTC
(In reply to Sven Vermeulen from comment #7)
> Alex, thanks for taking this up.
> 
> The only comment I have is about the "Our Commitment to Data Security". It
> mentions the use of SSL(/TLS) but not about password protection. Considering
> that leaked password databases are a, well, humiliating PR nightmare if
> found out that the database was not properly protected (and the passwords
> not properly hashed and salted and what not)... would it make sense to
> mention this as well?

I added a sentence about that. No text will make us look any better in the even this happens though.
Comment 9 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2015-06-21 21:58:10 UTC
swift:
I've added a few bits so it's correct to the best of my knowledge now (mostly that LDAP has birthdays). Do you want to give it one last review, then infra will post it as needed?
Comment 10 Sven Vermeulen (RETIRED) gentoo-dev 2016-05-15 18:59:59 UTC
Ah, I missed this one. Yes, looks good!
Comment 11 Alex Legler (RETIRED) archtester gentoo-dev Security 2016-08-15 10:36:46 UTC
(In reply to Sven Vermeulen from comment #10)
> Ah, I missed this one. Yes, looks good!

Is this the official confirmation from trustees@ that this is our official privacy policy now?
Comment 12 Sven Vermeulen (RETIRED) gentoo-dev 2016-08-16 15:44:19 UTC
No, not yet. I've added it to the agenda for the coming trustees meeting (for September as August is our AGM).

https://wiki.gentoo.org/wiki/Foundation:Meetings/2016/09

I will mail the trustees after the AGM when the new trustees take place.
Comment 13 David Abbott (RETIRED) gentoo-dev 2016-08-25 08:14:31 UTC
Looks good, thanks everyone.
Comment 14 Roy Bamford gentoo-dev 2016-08-25 17:34:33 UTC
Do we have a COPPA option everywhere?
The forums does, I couldn't find it on the Wiki.

Do we need a few words aimed at users based in the EU to the effect that their personal data may be held and processed outside of the EU?

We mention IRC but we don't operate our own IRC network, so this privacy policy does not apply.  Should we point to the freenode privacy policy?

The statement of a policy and its implementation are two different things. It looks like a good comprehensive document.
Comment 15 Sven Vermeulen (RETIRED) gentoo-dev 2016-09-18 20:00:32 UTC
Privacy policy slightly adjusted [1] and approved on Gentoo Foundation trustees meeting, dd 2016/09/18

[1] https://wiki.gentoo.org/index.php?title=User%3AA3li%2FPrivacy_Policy_Draft&type=revision&diff=544754&oldid=327638
Comment 16 Sven Vermeulen (RETIRED) gentoo-dev 2016-09-18 20:11:21 UTC
Also added paragraph regarding non-coverage (cfr trustee meeting). Forgot to mention that in previous comment.

https://wiki.gentoo.org/index.php?title=User%3AA3li%2FPrivacy_Policy_Draft&type=revision&diff=544756&oldid=544754
Comment 17 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2016-09-18 21:50:17 UTC
a3li:
The edit as of 2016/Sep/18 20:09 UTC is the final version now. Where do you want to put it on the main website?
Comment 18 Alex Legler (RETIRED) archtester gentoo-dev Security 2016-09-19 12:38:41 UTC
(In reply to Robin Johnson from comment #17)
> a3li:
> The edit as of 2016/Sep/18 20:09 UTC is the final version now. Where do you
> want to put it on the main website?

Something like https://gentoo.org/legal/privacy-policy.html that can be linked to from sign-up forms and/or page footers?
Comment 19 Matthew Marchese Gentoo Infrastructure gentoo-dev 2017-03-01 16:36:57 UTC
I've been commissioned by the Trustees to move this page...starting work now.
Comment 20 Matthew Marchese Gentoo Infrastructure gentoo-dev 2017-03-01 16:47:23 UTC
For the record, this privacy policy was approved at this Trustee meeting: https://projects.gentoo.org/foundation/2016/meeting-20160918-log.txt

I have, for now, moved the draft to the Foundation namespace: https://wiki.gentoo.org/wiki/Foundation:Privacy_Policy
Comment 21 Matthew Marchese Gentoo Infrastructure gentoo-dev 2017-03-01 16:57:26 UTC
I have removed the Work in Progress (WIP) template and have made minor punctuation improvements (capitalization and added an oxford comma). Not sure if changes such at these constitute a re-approval. I did NOT bump the "last amended" date near the bottom of the document but can do so if requested. Not sure it's needed since I add or remove any content, but I guess that may be considered relative.

Please review: https://wiki.gentoo.org/wiki/Foundation:Privacy_Policy
Comment 22 Matthew Marchese Gentoo Infrastructure gentoo-dev 2017-03-01 17:14:09 UTC
For the wiki, redirecting this page: https://wiki.gentoo.org/wiki/Gentoo_Wiki:Privacy_policy to https://wiki.gentoo.org/wiki/Foundation:Privacy_Policy
Comment 23 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2017-03-26 22:24:05 UTC
The privacy policy is live, and there are separate bugs now to add it to all sites.
Comment 24 alex writer 2020-03-26 11:27:34 UTC
> The only comment I have is about the "Our Commitment to Data Security". It
> mentions the use of SSL(/TLS) but not about password protection. Considering
> that leaked password databases are a https://mathcool.games/, well, humiliating PR nightmare if
> found out that the database was not properly protected (and the passwords
> not properly hashed and salted and what not)... would it make sense to
> mention this as well?