Launchpad needs a privacy policy

Bug #62702 reported by Matthew Paul Thomas
10
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
Medium
Joey Stanford

Bug Description

There should be a central page describing what we do with people's names, e-mail addresses, other contact details, and any other information they provide. (For example, how come ShipIt knows my name when I've never been there before?)

Changed in launchpad:
status: Unconfirmed → Confirmed
Revision history for this message
Francis J. Lacoste (flacoste) wrote :

It is also common for a privacy policy to explain the use of cookies by the web site and other information that are collected and for what purpose.

Changed in launchpad:
assignee: nobody → jjs
Revision history for this message
Joey Stanford (joey) wrote :

Basic plan of attack on this one is to review that material that we've already accomplished in the act of signing the EU Data Protection Act, review standard privacy policy templates such as can be found at the BBB, and also to ensure we implement this both as a regular html page but also as P3P XML (preferably in APPEL). Need to investigate if the compact P3P is worth doing vs full. P3P would be simple apache header response change on our servers which would push out an extra line of metadata and the compact version would be a potentially simple change to add an html metadata string on each served page.

Revision history for this message
Matthew Paul Thomas (mpt) wrote :

I suggest that before you put effort into producing a P3P policy, you investigate whether anyone would actually use it. P3P is not supported in Firefox (it was implemented for Mozilla, then removed), nor in Konqueror, Opera, Epiphany, or Safari, and it has only very limited support in Internet Explorer. It tends to be useless for Web users both because it is very complex and because it is reliant on the honesty of Web developers. I think just a human-readable policy would be fine.

Revision history for this message
Joey Stanford (joey) wrote :

I've received some material about the EU Data Protection Act including what Canonical has registered. There are some missing pieces that I think Steve A can fill me in on. I'm trying to find time on our calendars to chat about this.

Revision history for this message
Joey Stanford (joey) wrote :

Due to workload Steve had asked that I push this out a few weeks until we have more time to go through the EU DPA laws.

Revision history for this message
Joey Stanford (joey) wrote :

I have yet to work with Steve but used a privacy policy text generator to create a Safe Harbour compliant initial draft. This draft will need to be edited and then, when done, I'd like to convert it to P3P and enable Launchpad to be P3P compliant.

https://launchpad.canonical.com/JoeyStanford/privacy

Joey Stanford (joey)
Changed in launchpad:
importance: Undecided → Medium
status: Confirmed → In Progress
Revision history for this message
Joey Stanford (joey) wrote :

Had a chat with Steve today. He made the call that we should not do P3P at this time.

Revision history for this message
Joey Stanford (joey) wrote :

Good progress. Under review.

Revision history for this message
Joey Stanford (joey) wrote :

Reviewed by Steve with hefty changes. This now lives at https://launchpad.canonical.com/JoeyStanford/privacyanddataretention

Revision history for this message
Joey Stanford (joey) wrote :

I've received a highly edited draft back from legal along with a general statement and have posted those to the wiki page we are using to build this document.

Revision history for this message
Joey Stanford (joey) wrote :
Revision history for this message
Joey Stanford (joey) wrote :

Final draft under review

Revision history for this message
Joey Stanford (joey) wrote :

approved by kiko for release

Changed in launchpad:
status: In Progress → Fix Committed
Revision history for this message
Joey Stanford (joey) wrote :

This has been deployed to https://help.launchpad.net/Legal

Changed in launchpad:
status: Fix Committed → Fix Released
Revision history for this message
Joey Stanford (joey) wrote :

FYI, I've moved the WIP page to

https://launchpad.canonical.com/privacyanddataretention

in order to keep the relevant history.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Related questions

Remote bug watches

Bug watches keep track of this bug in other bug trackers.