I hate to be party pooper, and respect the effort the company has made to create the module, but the SAML SP 2.0 Single Sign On (SSO) - SAML Service Provider (miniorange_saml) module sends private data (admin email + site domain) during the uninstall process to third party provider.

Uninstall hook:
https://git.drupalcode.org/project/miniorange_saml/-/blob/3.0.x/minioran...

Information which is send to third party:
https://git.drupalcode.org/project/miniorange_saml/-/blob/3.0.x/src/Util...

Third party provider where the data is sent:
https://git.drupalcode.org/project/miniorange_saml/-/blob/3.0.x/src/Mini...

Comments

sokru created an issue. See original summary.

avpaderno’s picture

Project: Drupal.org site moderators » SAML SSO - Service Provider
Version: » 3.0.5
Component: Policy » Code

Assuming it is acceptable to send information to an external site, the project page should inform people installing and using the module which data is sent, to whom, and why. No data must be sent without information. Preferably, the same information should be given in a page rendered from the module; the module setting page would be fine too.
Eventually, there should be an option to avoid that data is sent.

Editing the project page and changing the module code are task for the project queue. Bear in mind it is not acceptable to send data without informing people or without their consens.

avpaderno’s picture

Title: Privacy issues with miniorange_saml contrib module » The module sent information to an external site without informing the people who are using it
gisle’s picture

For a site that provides services to users located in Europe, it is illegal for a website to do this without prior informed consent from the user. The GDPR (the EU legal framework for data protection) imposes some very huge fines on the site's data controller (usually the site's owner) for doing this.

Without disclosure or opt-out, this behaviour also amounts to a supply-chain attack on any site where the module is installed.

kolhatkarrahul’s picture

@apaderno, @gisle

We understand your concern and will take the necessary steps to get this changed. We currently have 2 options. One, as rightly pointed by @apaderno, would be declaration of whatever data that would be sent, will be shown to the user asking for their consent, with an option to skip the transmission. And two, deprecate the transfer of email + domain data back to our servers.

We will ensure the fix in place and the latest release will go out within the next 48 hours with the fix implemented.

gisle’s picture

Here is a reference to the provisions of the GDPR you must address if you want the module to comply with the GDPR:

  1. Information to be provided where personal data are collected from the data subject
  2. Conditions for Consent
  3. Transfers on the basis of an adequacy decision
  4. Right to erasure

Please take into account that the first item ("Information to be provided") is a very detailed requirement, and the requirements go well beyond a declaration of whatever data that would be sent.

As for the last two items ("transfers" of personal data to a location outside of outside of the EEA and UK, and the "right to erasure"), those requirements has so far not been addressed in this issue. I suspect that it may be very hard for you to satisfy those. Not exporting these personal data in the first place may be the easiest solution.

FYI, anyone using this module in Europe in its current state risks paying a fine, for example, see: European supervisory authority issues €8.15m fine for international data transfer and processing failings

arsh244’s picture

Status: Active » Fixed

hi @apaderno @gisle, we have made the required changes in the 3.0.6 version of the module.

We have handled this in the module in the following manner:
1) Informing the people of what data will be sent if they choose to submit the feedback during uninstallation on that same form itself.
2) We have also added the option to avoid sending any data via the skip feedback option.

Let us know in case any further changes are required.

gisle’s picture

Title: The module sent information to an external site without informing the people who are using it » The module send information to an external site without informing the people who are using it
Version: 3.0.5 » 3.0.6
Status: Fixed » Needs work

Did you read my comment #6?

In it, I tried to provide some guidance about what was required to make your module comply with privacy laws in Europe, but you choose to ignore it. Here is another attempt to provide guidance. It relieves you of the burden of following links to the actual legal framework, at the expense of you having to trust my interpretation, instead of working directly with original texts.

When requesting information from the data subject, article 13 requires that the following information is provided:

  • the identity and the contact details of the controller and, where applicable, of the controller’s representative; the contact details of the data protection officer
  • the legal basis for the processing;
  • the legitimate interests pursued by the controller or by a third party;
  • the recipients or categories of recipients of the personal data, if any;
  • the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of an adequacy decision by the Commission, with reference to the appropriate or suitable safeguards and the means by which to obtain a copy of them or where they have been made available.
  • the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;
  • the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;
  • the existence of the right to withdraw consent at any time;
  • the right to lodge a complaint with a supervisory authority;
  • meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

Version 3.0.6 of the module provides none of this information, still does not comply with European law, and a lot of further work is necessary to rectify this.

The GDPR (Recital 32) also says:

  • Silence, pre-ticked boxes or inactivity should not therefore constitute consent.

I.e. the blank opt-out checkbox that you provide does not constitute valid consent.

A typical situation that will result in a fine is to conduct marketing communications to customers without valid consent, which sounds a lot like what you actually want to do here, deceptively described as facilitating that "our Drupal experts can reach out to you and provide you with proper assistance".

If you're not familiar with European data protection laws, but still want to collect personal data from users located in Europe, you need to hire legal experts that can guide you in this endeavour, or your company will risk incurring huge fines for breaking European data protection laws.

arsh244’s picture

Hi @gisle, my intention was not to ignore your comment or any of your insights on the issue at hand. I also appreciate you providing the relevant links and detailed information on the subject.

I will go through all the provided information(links as well as the detailed text) in order to get a better understanding. But before that, I will make the required changes to eradicate the complete feedback process from the module so that there is no export of the data during the entire process.

shashank_thigale’s picture

Version: 3.0.6 » 3.0.7
Status: Needs work » Fixed

This feedback form was removed from the 3.0.7 version

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.