Closed (fixed)
Project:
SAML SSO - Service Provider
Version:
3.0.7
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
15 Sep 2023 at 06:55 UTC
Updated:
21 Feb 2024 at 07:34 UTC
Jump to comment: Most recent
Comments
Comment #2
avpadernoAssuming it is acceptable to send information to an external site, the project page should inform people installing and using the module which data is sent, to whom, and why. No data must be sent without information. Preferably, the same information should be given in a page rendered from the module; the module setting page would be fine too.
Eventually, there should be an option to avoid that data is sent.
Editing the project page and changing the module code are task for the project queue. Bear in mind it is not acceptable to send data without informing people or without their consens.
Comment #3
avpadernoComment #4
gisleFor a site that provides services to users located in Europe, it is illegal for a website to do this without prior informed consent from the user. The GDPR (the EU legal framework for data protection) imposes some very huge fines on the site's data controller (usually the site's owner) for doing this.
Without disclosure or opt-out, this behaviour also amounts to a supply-chain attack on any site where the module is installed.
Comment #5
kolhatkarrahul commented@apaderno, @gisle
We understand your concern and will take the necessary steps to get this changed. We currently have 2 options. One, as rightly pointed by @apaderno, would be declaration of whatever data that would be sent, will be shown to the user asking for their consent, with an option to skip the transmission. And two, deprecate the transfer of email + domain data back to our servers.
We will ensure the fix in place and the latest release will go out within the next 48 hours with the fix implemented.
Comment #6
gisleHere is a reference to the provisions of the GDPR you must address if you want the module to comply with the GDPR:
Please take into account that the first item ("Information to be provided") is a very detailed requirement, and the requirements go well beyond a declaration of whatever data that would be sent.
As for the last two items ("transfers" of personal data to a location outside of outside of the EEA and UK, and the "right to erasure"), those requirements has so far not been addressed in this issue. I suspect that it may be very hard for you to satisfy those. Not exporting these personal data in the first place may be the easiest solution.
FYI, anyone using this module in Europe in its current state risks paying a fine, for example, see: European supervisory authority issues €8.15m fine for international data transfer and processing failings
Comment #7
arsh244 commentedhi @apaderno @gisle, we have made the required changes in the 3.0.6 version of the module.
We have handled this in the module in the following manner:
1) Informing the people of what data will be sent if they choose to submit the feedback during uninstallation on that same form itself.
2) We have also added the option to avoid sending any data via the skip feedback option.
Let us know in case any further changes are required.
Comment #8
gisleDid you read my comment #6?
In it, I tried to provide some guidance about what was required to make your module comply with privacy laws in Europe, but you choose to ignore it. Here is another attempt to provide guidance. It relieves you of the burden of following links to the actual legal framework, at the expense of you having to trust my interpretation, instead of working directly with original texts.
When requesting information from the data subject, article 13 requires that the following information is provided:
Version 3.0.6 of the module provides none of this information, still does not comply with European law, and a lot of further work is necessary to rectify this.
The GDPR (Recital 32) also says:
I.e. the blank opt-out checkbox that you provide does not constitute valid consent.
A typical situation that will result in a fine is to conduct marketing communications to customers without valid consent, which sounds a lot like what you actually want to do here, deceptively described as facilitating that "our Drupal experts can reach out to you and provide you with proper assistance".
If you're not familiar with European data protection laws, but still want to collect personal data from users located in Europe, you need to hire legal experts that can guide you in this endeavour, or your company will risk incurring huge fines for breaking European data protection laws.
Comment #9
arsh244 commentedHi @gisle, my intention was not to ignore your comment or any of your insights on the issue at hand. I also appreciate you providing the relevant links and detailed information on the subject.
I will go through all the provided information(links as well as the detailed text) in order to get a better understanding. But before that, I will make the required changes to eradicate the complete feedback process from the module so that there is no export of the data during the entire process.
Comment #10
shashank_thigale commentedThis feedback form was removed from the 3.0.7 version