Tech:Data Processing Inventory

From Meta
Jump to navigation Jump to search

At the Board meeting of October 23, 2020 a data processing inventory was suggested. This page is a draft.

Data processors[edit | edit source]

Processor Website Jurisdiction Data processing agreement Purpose Data
DigitalOcean, LLC https://www.digitalocean.com/ United States https://www.digitalocean.com/legal/data-processing-agreement/ Hosting infrastructure Usernames, real names, email addresses, IP addresses, (private) wiki content, passwords, optional user information, other usage information
OVH https://www.ovh.co.uk/ France https://www.ovh.co.uk/support/termsofservice/Data%20Processing%20Agreement_UK.pdf Hosting infrastructure Usernames, real names, email addresses, IP addresses, (private) wiki content, passwords, optional user information, other usage information
RamNode LLC https://ramnode.com/ United States https://www.ramnode.com/gdpr-dpa.pdf Hosting infrastructure Usernames, real names, email addresses, IP addresses, (private) wiki content, passwords, optional user information, other usage information

Data processing[edit | edit source]

Data type Subjects Legal basis Retention date Processors
IP address Editors, readers Anonymous editors: consent
CheckUser (registered editor): legitimate interests
Anonymous editing: indefinite (attribution mandatory by licensing)
CheckUser (registered editor): up to 90 days
DigitalOcean, OVH, RamNode
Usernames Registered editors Consent (account may not be required[1]) Indefinite (until account has been renamed or deleted by user or per GDPR request[2]) DigitalOcean, OVH, RamNode
Password Registered users Legitimate interests (account security) Indefinite (until changed or removed by user or per GDPR request) DigitalOcean, OVH, RamNode
Email address Registered users Consent (not required upon registration), legitimate interests (account security / password reset) Indefinite (until removed or changed by user or per GDPR request) DigitalOcean, OVH, RamNode
Optional user information (e.g. a user page, real name) Editors Consent Indefinite (until edited or removed by user or per GDPR request) DigitalOcean, OVH, RamNode
Access logs / analytics
IP address Editors, readers Legitimate interests Up to 90 days DigitalOcean, OVH, RamNode
Timestamp of request Editors, readers Legitimate interests Up to 90 days DigitalOcean, OVH, RamNode
User agent Editors, readers Legitimate interests Up to 90 days DigitalOcean, OVH, RamNode
URL Editors, readers Legitimate interests Up to 90 days DigitalOcean, OVH, RamNode
Referer Editors, readers Legitimate interests Up to 90 days DigitalOcean, OVH, RamNode
Legenda
  • Anonymous: user without an account
  • Registered: user with an account
  • Editors: anonymous or registered users, editing wiki content[3]
  • Readers: anonymous or registered users, reading wiki content
  1. Communities may require registration prior to reading and editing, but Miraheze Limited commits to information access without prior registration.
  2. Due to attribution requirements by licensing, user accounts will not be erased, but accounts will be renamed to apply pseudonymisation.
  3. All editors are readers, but not all readers are editors.