Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GDPR compliance #2571

Open
idleberg opened this issue Apr 26, 2021 · 2 comments
Open

GDPR compliance #2571

idleberg opened this issue Apr 26, 2021 · 2 comments

Comments

@idleberg
Copy link

idleberg commented Apr 26, 2021

This plugin is not GDPR-compliant and the same might be true for other privacy regulations, e.g. the CCPA. I will continue to use the GDPR as an umbrella term for similar regulations.

At the time of this writing, the authors assume that consent is given through the consent for GitHub's metric package. This is problematic in many ways. Let's take a look at these simple definitions:

  1. Consent must be freely given
  2. Consent must be specific
  3. Consent must be informed
  4. Consent must be unambiguous

I think these definitions are easy enough to understand for non-lawyers and it should be clear that all of these are violated. When accepted, each of these definitions is fulfilled between GitHub and the user. However, GitHub cannot be made liable for everyone else jumping the train – they don't know anything about what your code does, why would they vouch for it? Also, GitHub sends user data to its own servers, while this package sends it to a different party: Google Analytics.

Here's a simple example to illustrate the problem: A user installs Atom on January 1st, on the first startup he accepts the privacy policy between him/her and GitHub Inc. Nine months later, the user installs atom-beautify. GitHub's policy is specific to the data collection of the metrics package, the user is uninformed about the data collection of atom-beautify — because GitHub's privacy policy is unambiguous that it applies to the collection by the metrics package.

It should be enough, if this package pops up a notification with "Accept" / "Reject" buttons and a link to your privacy policy. Or better, replicate the consent page used by the metrics package. However, since I'm not a lawyer, you might want to read about this online. There are plenty of free resources that provide guidance, including here on GitHub.

@Glavin001
Copy link
Owner

Hi @idleberg , thank you for reaching out!

Atom-Beautify is currently using core.telemetryConsent as requested by GitHub team member almost 5 years ago in #1179

I see your points on how this can be improved and would be happy to accept a Pull Request improving this area.

To help you or others write such a Pull Request, here are links to applicable code which would be useful:

Thanks for your interest and supporting this open source project!

@Sloter88
Copy link

Situs Judi Togel Terpercaya Dan Terlengkap 2022 GASKEN88

DAFTAR
[ klik DISINI](https://tinyurl.com/gaston88
)

Bandar Togel Terpercaya Padakali ini kami akan membahas sebuah bandar togel terpercaya dan terbaik di indonesia yang menurut kami terbaik dan terbesar di asia karena dengan semua bandar togel terpercaya yang akan kami bahas kali ini adalah Bandar Togel Hadiah 4d 10 Juta terbesar di indonesia dengan semua reputasi yang kami rekomendasikan adalah salah satu situs togel online terpercaya yang terbaik di indonesia.
Bandar Togel Hadiah Terbesar yang terpercaya di indonesia adalah salah satu situs dan agen togel terpercaya yang terbesar di indonesia dengan semua bandar togel terpercaya yang kami rkeomendasikan ini sudah memiliki pasaran togel lengkap di indonesia untuk kami rekomendasikan untuk togelers setia yang bermain di situs togel online terpercaya.
Dengan Mendaftar bandar togel terpercaya yang kami rekomendasikan tentusaja anda sudah bisa menikmati semua permainan togel online dan pasaran togel paling lengkap di indonesia karena dengan semua situs yang kami rekomendasikan tentunya sangat aman dan terpercaya anda bermain di situs yang admin berikan di atas karena sudah aman terpercaya.
Togel Terpercaya adlah salah satu agen togel online terbaik di indonesia yang sudah memiliki reputasi bandar togel terbaik di indonesia dengan semua fasilitas yang diberikan bandar togel terpercaya satu ini adalah salah satu yang terbesar di indonesia jadi kami sangat merekomendasikannya utnuk anda bermain di situs yang akan kami berikan terbaik di indonesaia ini.
Bandar Togel Terpercaya Dan Terbaik Di Indonesia

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants