Bug#900552: Bug #900552: Add privacy policy to the Debian website

Laura Arjona Reina <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <ad2a4427-cde2-c819-171c-767f9cb3160c__671.880428171967$1532736081$gmane$org@debian.org>
Hello all

Sorry for the delay in dealing with this.

I have created the merge request

https://salsa.debian.org/webmaster-team/webwml/merge_requests/10

with what I think it's ready to be published:

* The document /english/legal/privacy.wml (Section of LDAP
updated-expanded, as per conversation with the team at
[email protected])

* Updated /english/legal/index.wml to link to the new document

* Updated the footer in homepage and other pages to include "Legal Info"
and "Data Privacy" in the "About" section.

I'm attaching a diff, with these changes (the same that are included in
the merge request), and the result of a local build of
/legal/index.en.html and /legal/privacy.en.html files.

If there are not objections, I will merge this in 2-3 days.

I will keep this bug open, though (and the branch in the salsa repo),
because the suggestions mentioned in

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900552#10
and
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900552#30

remain (but not so hurry, I guess).

Thanks!

-- 
Laura Arjona Reina
https://wiki.debian.org/LauraArjona
index.en.html (text/html, 7.8 KB)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html lang="en">
<head>
  <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  <title>Debian -- Legal issues </title>
  <link rel="author" href="mailto:[email protected]">
  <meta name="Generator" content="WML 2.0.12 (16-Apr-2008)">
  <meta name="Modified" content="2018-07-28 00:59:26">
  <meta name="viewport" content="width=device-width">
  <meta name="mobileoptimized" content="300">
  <meta name="HandheldFriendly" content="true">
<link href="../debian.css" rel="stylesheet" type="text/css">
  <link href="../debian-en.css" rel="stylesheet" type="text/css" media="all">
<link rel="search" type="application/opensearchdescription+xml" title="Debian website search" href="../search.en.xml">
</head>
<body>
<div id="header">
   <div id="upperheader">
   <div id="logo">
  <a href="../" title="Debian Home"><img src="../Pics/openlogo-50.png" alt="Debian" width="50" height="61"></a>
  </div> <!-- end logo -->
	<div id="searchbox">
		<form name="p" method="get" action="https://search.debian.org/cgi-bin/omega">
		<p>
<input type="hidden" name="DB" value="en">
			<input name="P" value="" size="27">
			<input type="submit" value="Search">
		</p>
		</form>
	</div>   <!-- end sitetools -->
 </div> <!-- end upperheader -->
<!--UdmComment-->
<div id="navbar">
<p class="hidecss"><a href="#content">Skip Quicknav</a></p>
<ul>
   <li><a href="../intro/about">About Debian</a></li>
   <li><a href="../distrib/">Getting Debian</a></li>
   <li><a href="../support">Support</a></li>
   <li><a href="../devel/">Developers' Corner</a></li>
</ul>
</div> <!-- end navbar -->
<p id="breadcrumbs">
Legal issues</p>
</div> <!-- end header -->
<!--/UdmComment-->
<div id="content">
<h1>Legal issues</h1>
<p>This section of the Debian web site is for legal issues.</p>
<h2>Legal information</h2>
<ul>
  <li><a href="licenses/">License summaries</a></li>
  <li><a href="../trademark">Trademarks</a></li>
  <li><a href="privacy">Privacy policy</a></li>
  <li><a href="patent">Patent policy</a></li>
  <li><a href="cryptoinmain">Crypto in main</a>
    <ul>
      <li><a href="notificationforarchive">Initial notification for the archive</a></li>
      <li><a href="notificationfornewpackages">Notification for new packages</a></li>
    </ul>
  </li>
  <li><a href="anssi">Cryptographic export/import attestation</a></li>
</ul>
<h2>Mailing list</h2>
<p>The mailing list for Debian legal matters is
<a href="mailto:[email protected]">[email protected]</a>.
To subscribe, send a message with the word "subscribe" as the subject to
<a href="mailto:[email protected]">[email protected]</a>, or use the
<a href="https://lists.debian.org/debian-legal/">mailing list
subscription</a> web page. The list is archived at
<a href="https://lists.debian.org/debian-legal/">the list archives</a>.
<div class="clr"></div>
</div> <!-- end content -->
<div id="footer">
<hr class="hidecss">
<p>Back to the <a href="../">Debian Project homepage</a>.</p>
<hr>
<!--UdmComment-->
<div id="pageLang">
<div id="langSelector">
This page is also available in the following languages:
<div id="langContainer">
 <a href="index.bg.html" title="Bulgarian" hreflang="bg" lang="bg" rel="alternate">&#1041;&#1098;&#1083;&#1075;&#1072;&#1088;&#1089;&#1082;&#1080;&nbsp;(B&#601;lgarski)</a>
 <a href="index.da.html" title="Danish" hreflang="da" lang="da" rel="alternate">dansk</a>
 <a href="index.de.html" title="German" hreflang="de" lang="de" rel="alternate">Deutsch</a>
 <a href="index.es.html" title="Spanish" hreflang="es" lang="es" rel="alternate">espa&ntilde;ol</a>
 <a href="index.fr.html" title="French" hreflang="fr" lang="fr" rel="alternate">fran&ccedil;ais</a>
 <a href="index.it.html" title="Italian" hreflang="it" lang="it" rel="alternate">Italiano</a>
 <a href="index.ja.html" title="Japanese" hreflang="ja" lang="ja" rel="alternate">&#26085;&#26412;&#35486;&nbsp;(Nihongo)</a>
 <a href="index.pt.html" title="Portuguese" hreflang="pt" lang="pt" rel="alternate">Portugu&ecirc;s</a>
 <a href="index.ru.html" title="Russian" hreflang="ru" lang="ru" rel="alternate">&#1056;&#1091;&#1089;&#1089;&#1082;&#1080;&#1081;&nbsp;(Russkij)</a>
 <a href="index.sv.html" title="Swedish" hreflang="sv" lang="sv" rel="alternate">svenska</a>
</div>
How to set <a href="../intro/cn">the default document language</a>
</div></div><!--/UdmComment-->
<hr>
<div id="footermap">
<!--UdmComment-->
<p><strong><a href="/">Home</a></strong></p>
    <ul id="footermap-cola">
		<li><a href="../intro/about">About</a>
		  <ul>
		  <li><a href="../social_contract">Social Contract</a></li>
		  <li><a href="../code_of_conduct">Code of Conduct</a></li>
		  <li><a href="../intro/free">Free Software</a></li>
		  <li><a href="../partners/">Partners</a></li>
		  <li><a href="../donations">Donations</a></li>
          <li><a href="../legal">Legal Info</a></li>
          <li><a href="../legal/privacy">Data Privacy</a></li>
		  <li><a href="../contact">Contact Us</a></li>
		  </ul>
		</li>
        <li><a href="../intro/help">Help Debian</a></li>
    </ul>
	<ul id="footermap-colb">
			<li><a href="../distrib/">Getting Debian</a>
			  <ul>
			  <li><a href="../distrib/netinst">Network install</a></li>
			  <li><a href="../CD/">CD/USB ISO images</a></li>
			  <li><a href="../CD/vendors/">CD vendors</a></li>
			  <li><a href="../distrib/pre-installed">Pre-installed</a></li>
			  </ul>
			</li>
            <li><a href="../blends/">Pure Blends</a></li>
			<li><a href="../distrib/packages">Debian Packages</a></li>
			<li><a href="../devel/">Developers' Corner</a></li>
	</ul>
	<ul id="footermap-colc">
		<li><a href="../News/">News</a>
		  <ul>
		  <li><a href="../News/weekly/">Project News</a></li>
		  <li><a href="../events/">Events</a></li>
		  </ul>
		</li>
    <li><a href="../doc/">Documentation</a>
      <ul>
      <li><a href="../releases/">Release Info</a></li>
      <li><a href="../releases/stable/installmanual">Installation manual</a></li>
      <li><a href="../doc/books">Debian Books</a></li>
      <li><a href="https://wiki.debian.org/">Debian Wiki</a></li>
      </ul>
    </li>
   </ul>
   <ul id="footermap-cold">
    <li><a href="../support">Support</a>
	  <ul>
			  <li><a href="../international/">Debian International</a></li>
			  <li><a href="../security/">Security Information</a></li>
			  <li><a href="../Bugs/">Bug reports</a></li>
			  <li><a href="../MailingLists/">Mailing Lists</a></li>
			  <li><a href="https://lists.debian.org/">Mailing List Archives</a></li>
			  <li><a href="../ports/">Ports/Architectures</a></li>
      </ul>
    </li>
</ul>
<ul id="footermap-cole">
  <li><a href="../misc/">Miscellaneous</a></li>
  <li><a href="../sitemap">Site map</a></li>
  <li><a href="https://search.debian.org/">Search</a></li>
  <li><a href="https://bits.debian.org">The Debian Blog</a></li>
  <li><a href="https://identi.ca/debian"><img src="../Pics/identica.png"
  alt="follow debian on identi.ca!" width="80" height="15"></a></li>
  <li><a href="https://planet.debian.org"><img src="../Pics/planet.png"
  alt="follow debian on planet.debian.org!" width="80" height="15"></a></li>
</ul>
<!--/UdmComment-->
</div> <!-- end footermap -->
<div id="fineprint">
  <p>To report a problem with the web site, please e-mail our publicly archived mailing list <a href="mailto:[email protected]">[email protected]</a> in English. For other contact information, see the Debian <a href="../contact">contact page</a>. Web site source code is <a href="https://salsa.debian.org/webmaster-team/webwml">available</a>.</p>
<p>
Last Modified: Fri, Jul 27 22:57:57 UTC 2018
  <br>
  Copyright &copy; 1997-2018
 <a href="https://www.spi-inc.org/">SPI</a> and others; See <a href="../license" rel="copyright">license terms</a><br>
  Debian is a registered <a href="../trademark">trademark</a> of Software in the Public Interest, Inc.
</p>
</div>
</div> <!-- end footer -->
</body>
</html>
privacy.en.html (text/html, 18.9 KB)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html lang="en">
<head>
  <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  <title>Debian -- Privacy Policy </title>
  <link rel="author" href="mailto:[email protected]">
  <meta name="Generator" content="WML 2.0.12 (16-Apr-2008)">
  <meta name="Modified" content="2018-07-28 00:59:25">
  <meta name="viewport" content="width=device-width">
  <meta name="mobileoptimized" content="300">
  <meta name="HandheldFriendly" content="true">
<link href="../debian.css" rel="stylesheet" type="text/css">
  <link href="../debian-en.css" rel="stylesheet" type="text/css" media="all">
<link rel="search" type="application/opensearchdescription+xml" title="Debian website search" href="../search.en.xml">
</head>
<body>
<div id="header">
   <div id="upperheader">
   <div id="logo">
  <a href="../" title="Debian Home"><img src="../Pics/openlogo-50.png" alt="Debian" width="50" height="61"></a>
  </div> <!-- end logo -->
	<div id="searchbox">
		<form name="p" method="get" action="https://search.debian.org/cgi-bin/omega">
		<p>
<input type="hidden" name="DB" value="en">
			<input name="P" value="" size="27">
			<input type="submit" value="Search">
		</p>
		</form>
	</div>   <!-- end sitetools -->
 </div> <!-- end upperheader -->
<!--UdmComment-->
<div id="navbar">
<p class="hidecss"><a href="#content">Skip Quicknav</a></p>
<ul>
   <li><a href="../intro/about">About Debian</a></li>
   <li><a href="../distrib/">Getting Debian</a></li>
   <li><a href="../support">Support</a></li>
   <li><a href="../devel/">Developers' Corner</a></li>
</ul>
</div> <!-- end navbar -->
<p id="breadcrumbs"><a href="./">Legal issues</a>
 &#x2F;
Privacy Policy</p>
</div> <!-- end header -->
<!--/UdmComment-->
<div id="content">
<h1>Privacy Policy</h1>
<p>The <a href="https://www.debian.org/">Debian Project</a> is a volunteer
association of individuals who have made common cause to create a free
operating system, referred to as Debian. </p>
<p>There is no requirement for anyone who
wishes to use Debian to provide the project with any personal information; it
is freely downloadable without registration or other form of identification
from both official mirrors run by the project and numerous third parties.</p>
<p>Various other aspects of interacting with the Debian Project will, however,
involve the collection of personal information. This is primarily in the form
of names and email addresses in emails received by the project; all Debian
mailing lists are publicly archived, as are all interactions with the bug
tracking system. This is in keeping with our <a
href="https://www.debian.org/social_contract">Social Contract</a>, in
particular our statement that we will give back to the free software community
(#2), and that we will not hide our problems (#3). We do not perform further
processing on any of the information we hold, but there are instances where it
is automatically shared with third parties (such as emails to lists, or
interactions with the bug tracking system).</p>
<p>The list below categorises the various services run by the project, the
information used by those services and the reasons it is required.</p>
<p>Please note that hosts and services under the <strong>debian.net</strong>
domain are not part of the official Debian project;
they are run by individuals who have an association with the project rather
than the project themselves.
Questions about exactly what data those services hold should be directed
at the service owners rather than the Debian Project itself.</p>
<h2>Contributors (<a href="https://contributors.debian.org/">contributors.debian.org</a>)</h2>
<p>The Debian Contributors site provides an aggregation of data about where
someone has contributed to the Debian Project, whether that's through filing a
bug report, making an upload to the archive, posting to a mailing list or
various other interactions with the Project. It receives its information from
the services in question (details about an identifier such as login name and
time of last contribution) and provides a single reference point to see where
the Project is storing information about an individual.</p>
<h2>The Archive (<a href="https://ftp.debian.org/debian/">ftp.debian.org</a>)</h2>
<p>The primary distribution method of Debian is via its public archive network.
The archive consists of all of the binary packages and their associated source
code, which will include personal information in the form of names and email
addresses stored as part of changelogs, copyright information, and general
documentation. The majority of this information is provided via the upstream
software authors distributed source code, with Debian adding additional
information to track authorship and copyright to ensure that licenses are being
correctly documents and the Debian Free Software Guidelines adhered to.</p>
<h2>Bug Tracking System (<a href="https://bugs.debian.org/">bugs.debian.org</a>)</h2>
<p>The bug tracking system is interacted with via email, and stores all emails
received in relation to a bug as part of that bug's history. In order that the
project can effectively deal with issues found in the distribution, and to
enable users to see details about those issues and whether a fix or workaround
is available, the entirety of the bug tracking system is openly accessible.
Therefore any information, including names and email addresses as part of email
headers, sent to the BTS will be archived and publicly available.</p>
<h2>DebConf (<a href="https://www.debconf.org/">debconf.org</a>)</h2>
<p>The DebConf registration structure stores the details of conference
attendees. These are required to determine eligibility to bursaries, association
to the project, and to contact attendees with appropriate details. They may
also be shared with suppliers to the conference, e.g. attendees staying in the
conference provided accommodation will have their name and attendance date
shared with the accommodation provider.</p>
<h2>Developers LDAP (<a href="https://db.debian.org">db.debian.org</a>)</h2>
<p>Project contributors (developers and others with guest accounts) who
have account access to machines within the Debian infrastructure have
their details stored within the project's LDAP infrastructure. This
primarily stores name, username and authentication information. However
it also has the optional facility for contributors to provide additional
information such as gender, instant messaging (IRC/XMPP), country and
address or phone details, and a message if they are on vacation.
</p>
<p>
Name, username and some of the voluntarily provided details
are freely available via the web interface or LDAP search. Additional
details are only shared with other individuals who have account access
to the Debian infrastructure and is intended to provide a centralised
location for project members to exchange such contact information. It is
not explicitly collected at any point and can always be removed by
logging into the db.debian.org web interface or sending signed email to
the email interface. See <a href="https://db.debian.org/">https://db.debian.org/</a> and
<a href="https://db.debian.org/doc-general.html">https://db.debian.org/doc-general.html</a> for more details.
</p>
<h2>Gitlab (<a href="https://salsa.debian.org/">salsa.debian.org</a>)</h2>
<p>salsa.debian.org provides an instance of the <a
href="https://about.gitlab.com/">GitLab</a> DevOps lifecycle management tool.
It is primarily used by the Project to allow Project contributors to host
software repositories using Git and encourage collaboration between
contributors. As a result it requires various pieces of personal information to
manage accounts. For Project members this is tied to the central Debian LDAP
system, but guests may also register for an account and will have to provide
name and email details in order to facilitate the setup and use of that
account.</p>
<p>Due to the technical nature of git contributions to the git repositories
held on salsa will contain the name and email address recorded within those git
commits. The chained nature of the git system means that any modification to
these commit details once they are incorporated into the repository is
extremely disruptive and in some cases (such as when signed commits are in use)
impossible.</p>
<h2>Gobby (<a href="https://gobby.debian.org/">gobby.debian.org</a>)</h2>
<p>Gobby is a collaborative online text editor, which tracks contributions and
changes against connected users. No authentication is required to connect to
the system and users may choose any username they wish. However while no
attempt is made by the service to track who owns usernames it should be
understand that it may prove possible to map usernames back to individuals
based upon common use of that username or the content they post to a
collaborative document within the system.</p>
<h2>Mailing Lists (<a href="https://lists.debian.org/">lists.debian.org</a>)</h2>
<p>Mailing lists are the primary communication mechanism of the Debian Project.
Almost all of the mailing lists related to the project are open, and thus
available for anyone to read and/or post to. All lists are also archived; for
public lists this means in a web accessible manner. This fulfils the project
commitment to transparency, and aids with helping our users and developers
understand what is happening in the project, or understand the historical
reasons for certain aspects of the project. Due to the nature of email these
archives will therefore potentially hold personal information, such as names
and email addresses.</p>
<h2>New Members site (<a href="https://nm.debian.org/">nm.debian.org</a>)</h2>
<p>Contributors to the Debian Project who wish to formalise their involvement
may choose to apply to the New Members process. This allows them to gain the
ability to upload their own packages (via Debian Maintainership) or to become
full voting members of the Project with account rights (Debian Developers, in
uploading and non-uploading variants). As part of this process various personal
details are collected, starting with name, email address and
encryption/signature key details. Full Project applications also involve the
applicant engaging with an Application Manager who will undertake an email
conversation to ensure the New Member understands the principles behind Debian
and has the appropriate skills to interact with the Project infrastructure.
This email conversation is archived and available to the applicant and
Application Managers via the nm.debian.org interface. Additionally details of
outstanding applicants are publicly visible on the site, allowing anyone to see
the state of New Member processing within the Project to ensure an appropriate
level of transparency.</p>
<h2>Popularity Contest (<a href="https://popcon.debian.org/">popcon.debian.org</a>)</h2>
<p>"popcon" tracks which packages are installed on a Debian system, to enable
the gathering of statistics about which packages are widely used and which are
no longer in use. It uses the optional "popularity-contest" package to collect
this information, requiring explicit opt-in to do so. This provides useful
guidance about where to devote developer resources, for example when migrating
to newer library versions and having to spend effort on porting older
applications. Each popcon instance generates a random 128 bit unique ID which
is used to track submissions from the same host. No attempt is made to map this
to an individual about submissions are made via email or HTTP and it is thus
possible for personal information to leak in the form of the IP address used
for access or email headers. This information is only available to the Debian
System Administrators and popcon admins; all such meta-data is removed before
submissions are made accessible to the project as a whole. However users should
be aware that unique signatures of packages (such as locally created packages
or packages with very low install counts) may make machines deducible as
belonging to particular individuals.</p>
<p>Raw submissions are stored for 24 hours, to allow replaying in the event of
issues with the processing mechanisms. Anonymized submissions are kept for at
most 20 days. Summary reports, which contain no personally identifiable
information, are kept indefinitely.</p>
<h2>snapshot (<a href="http://snapshot.debian.org/">snapshot.debian.org</a>)</h2>
<p>The snapshot archive provides a historical view of the Debian archive
(ftp.debian.org above), allowing access to old packages based on dates and
version numbers. It carries no additional information over the main archive
(and can thus contain personal information in the form of names + email address
within changelogs, copyright statements and other documentation), but can
contain packages that are no longer part of shipping Debian releases. This
provides a useful resource to developers and users when tracking down
regressions in software packages, or providing a specific environment to run a
particular application.</p>
<h2>Votes (<a href="https://vote.debian.org/">vote.debian.org</a>)</h2>
<p>The vote tracking system (devotee) tracks the status of ongoing General
Resolutions and the results of previous votes. In the majority of cases this
means that once the voting period is over details of who voted (usernames +
name mapping) and how they voted becomes publicly visible. Only Project
members are valid voters for the purposes of devotee, and only valid votes are
tracked by the system.</p>
<h2>Wiki (<a href="https://wiki.debian.org/">wiki.debian.org</a>)</h2>
<p>The Debian Wiki provides a support and documentation resource for the
Project which is editable by everyone. As part of that contributions are
tracked over time and associated with user accounts on the wiki; each
modification to a page is tracked to allow for errant edits to be reverted and
updated information to be easily examined. This tracking provides details of
the user responsible for the change, which can be used to prevent abuse by
blocking abusive users or IP addresses from making edits. User accounts also
allow users to subscribe to pages to watch for changes, or see details of
changes throughout the entire wiki since they last checked. In general user
accounts are named after the name of the user, but no validation is performed
of the account names and a user may choose any free account name. An email
address is required for the purposes of providing a mechanism for account
password reset, and notifying the user of any changes on pages they are
subscribed to.</p>
<h2>Echelon</h2>
<p>Echelon is a system used by the Project to track member activity; in
particular it watches the mailing list and archive infrastructures, looking for
posts and uploads to record that a Debian member is active. Only the most
recent activity is stored, in the member's LDAP record. It is thus limited to
only tracking details of individuals who have accounts within the Debian
infrastructure. This information is used when determining if a project member
is inactive or missing and thus that there might be an operational requirement
to lock their account or otherwise reduce their access permissions to ensure
Debian systems are kept secure.</p>
<h2>Service related logging</h2>
<p>In addition to the explicitly listed services above the Debian
infrastructure logs details about system accesses for the purposes of ensuring
service availability and reliability, and to enable debugging and diagnosis of
issues when they arise. This logging includes details of mails sent/received
through Debian infrastructure, web page access requests sent to Debian
infrastructure, and login information for Debian systems (such as SSH logins to
project machines). None of this information is used for any purposes other than
operational requirements and it is only stored for 15 days in the case of web
server logs, 10 days in the case of mail log and 4 weeks in the case of
authentication/ssh logs.</p>
<div class="clr"></div>
</div> <!-- end content -->
<div id="footer">
<hr class="hidecss">
<p>Back to the <a href="../">Debian Project homepage</a>.</p>
<hr>
<div id="footermap">
<!--UdmComment-->
<p><strong><a href="/">Home</a></strong></p>
    <ul id="footermap-cola">
		<li><a href="../intro/about">About</a>
		  <ul>
		  <li><a href="../social_contract">Social Contract</a></li>
		  <li><a href="../code_of_conduct">Code of Conduct</a></li>
		  <li><a href="../intro/free">Free Software</a></li>
		  <li><a href="../partners/">Partners</a></li>
		  <li><a href="../donations">Donations</a></li>
          <li><a href="../legal">Legal Info</a></li>
          <li><a href="../legal/privacy">Data Privacy</a></li>
		  <li><a href="../contact">Contact Us</a></li>
		  </ul>
		</li>
        <li><a href="../intro/help">Help Debian</a></li>
    </ul>
	<ul id="footermap-colb">
			<li><a href="../distrib/">Getting Debian</a>
			  <ul>
			  <li><a href="../distrib/netinst">Network install</a></li>
			  <li><a href="../CD/">CD/USB ISO images</a></li>
			  <li><a href="../CD/vendors/">CD vendors</a></li>
			  <li><a href="../distrib/pre-installed">Pre-installed</a></li>
			  </ul>
			</li>
            <li><a href="../blends/">Pure Blends</a></li>
			<li><a href="../distrib/packages">Debian Packages</a></li>
			<li><a href="../devel/">Developers' Corner</a></li>
	</ul>
	<ul id="footermap-colc">
		<li><a href="../News/">News</a>
		  <ul>
		  <li><a href="../News/weekly/">Project News</a></li>
		  <li><a href="../events/">Events</a></li>
		  </ul>
		</li>
    <li><a href="../doc/">Documentation</a>
      <ul>
      <li><a href="../releases/">Release Info</a></li>
      <li><a href="../releases/stable/installmanual">Installation manual</a></li>
      <li><a href="../doc/books">Debian Books</a></li>
      <li><a href="https://wiki.debian.org/">Debian Wiki</a></li>
      </ul>
    </li>
   </ul>
   <ul id="footermap-cold">
    <li><a href="../support">Support</a>
	  <ul>
			  <li><a href="../international/">Debian International</a></li>
			  <li><a href="../security/">Security Information</a></li>
			  <li><a href="../Bugs/">Bug reports</a></li>
			  <li><a href="../MailingLists/">Mailing Lists</a></li>
			  <li><a href="https://lists.debian.org/">Mailing List Archives</a></li>
			  <li><a href="../ports/">Ports/Architectures</a></li>
      </ul>
    </li>
</ul>
<ul id="footermap-cole">
  <li><a href="../misc/">Miscellaneous</a></li>
  <li><a href="../sitemap">Site map</a></li>
  <li><a href="https://search.debian.org/">Search</a></li>
  <li><a href="https://bits.debian.org">The Debian Blog</a></li>
  <li><a href="https://identi.ca/debian"><img src="../Pics/identica.png"
  alt="follow debian on identi.ca!" width="80" height="15"></a></li>
  <li><a href="https://planet.debian.org"><img src="../Pics/planet.png"
  alt="follow debian on planet.debian.org!" width="80" height="15"></a></li>
</ul>
<!--/UdmComment-->
</div> <!-- end footermap -->
<div id="fineprint">
<p>
Last Modified: Fri, Jul 27 22:57:58 UTC 2018
  <br>
  Copyright &copy; 1997-2018
 <a href="https://www.spi-inc.org/">SPI</a> and others; See <a href="../license" rel="copyright">license terms</a><br>
  Debian is a registered <a href="../trademark">trademark</a> of Software in the Public Interest, Inc.
</p>
</div>
</div> <!-- end footer -->
</body>
</html>
bug900552-privacypolicy.diff (text/x-patch, 17.4 KB)
diff --git a/english/legal/index.wml b/english/legal/index.wml
index e38404dff29..960501eebb0 100644
--- a/english/legal/index.wml
+++ b/english/legal/index.wml
@@ -3,11 +3,13 @@
 # TODO: a better introduction!
 <p>This section of the Debian web site is for legal issues.</p>
 
-<h2>Current things</h2>
+<h2>Legal information</h2>
 
 <ul>
   <li><a href="licenses/">License summaries</a></li>
   <li><a href="$(HOME)/trademark">Trademarks</a></li>
+  <li><a href="privacy">Privacy policy</a></li>
+  <li><a href="patent">Patent policy</a></li>
   <li><a href="cryptoinmain">Crypto in main</a>
     <ul>
       <li><a href="notificationforarchive">Initial notification for the archive</a></li>
@@ -15,7 +17,6 @@
     </ul>
   </li>
   <li><a href="anssi">Cryptographic export/import attestation</a></li>
-  <li><a href="patent">Patent policy</a></li>
 </ul>
 
 <h2>Mailing list</h2>
diff --git a/english/legal/privacy.wml b/english/legal/privacy.wml
new file mode 100644
index 00000000000..9cfa7e42ff3
--- /dev/null
+++ b/english/legal/privacy.wml
@@ -0,0 +1,247 @@
+#use wml::debian::template title="Privacy Policy" NOCOMMENTS="yes"
+
+## Translators may want to add a note stating that the translation 
+## is only informative and has no legal value, and people
+## should look at the original English for that. 
+## Some languages have already put such a note in the
+## translations of /trademark and /license, for example.
+
+<p>The <a href="https://www.debian.org/">Debian Project</a> is a volunteer
+association of individuals who have made common cause to create a free
+operating system, referred to as Debian. </p>
+
+<p>There is no requirement for anyone who
+wishes to use Debian to provide the project with any personal information; it
+is freely downloadable without registration or other form of identification
+from both official mirrors run by the project and numerous third parties.</p>
+
+<p>Various other aspects of interacting with the Debian Project will, however,
+involve the collection of personal information. This is primarily in the form
+of names and email addresses in emails received by the project; all Debian
+mailing lists are publicly archived, as are all interactions with the bug
+tracking system. This is in keeping with our <a
+href="https://www.debian.org/social_contract">Social Contract</a>, in
+particular our statement that we will give back to the free software community
+(#2), and that we will not hide our problems (#3). We do not perform further
+processing on any of the information we hold, but there are instances where it
+is automatically shared with third parties (such as emails to lists, or
+interactions with the bug tracking system).</p>
+
+<p>The list below categorises the various services run by the project, the
+information used by those services and the reasons it is required.</p>
+
+<p>Please note that hosts and services under the <strong>debian.net</strong> 
+domain are not part of the official Debian project; 
+they are run by individuals who have an association with the project rather 
+than the project themselves. 
+Questions about exactly what data those services hold should be directed 
+at the service owners rather than the Debian Project itself.</p>
+
+<h2>Contributors (<a href="https://contributors.debian.org/">contributors.debian.org</a>)</h2>
+
+<p>The Debian Contributors site provides an aggregation of data about where
+someone has contributed to the Debian Project, whether that's through filing a
+bug report, making an upload to the archive, posting to a mailing list or
+various other interactions with the Project. It receives its information from
+the services in question (details about an identifier such as login name and
+time of last contribution) and provides a single reference point to see where
+the Project is storing information about an individual.</p>
+
+<h2>The Archive (<a href="https://ftp.debian.org/debian/">ftp.debian.org</a>)</h2>
+
+<p>The primary distribution method of Debian is via its public archive network.
+The archive consists of all of the binary packages and their associated source
+code, which will include personal information in the form of names and email
+addresses stored as part of changelogs, copyright information, and general
+documentation. The majority of this information is provided via the upstream
+software authors distributed source code, with Debian adding additional
+information to track authorship and copyright to ensure that licenses are being
+correctly documents and the Debian Free Software Guidelines adhered to.</p>
+
+<h2>Bug Tracking System (<a href="https://bugs.debian.org/">bugs.debian.org</a>)</h2>
+
+<p>The bug tracking system is interacted with via email, and stores all emails
+received in relation to a bug as part of that bug's history. In order that the
+project can effectively deal with issues found in the distribution, and to
+enable users to see details about those issues and whether a fix or workaround
+is available, the entirety of the bug tracking system is openly accessible.
+Therefore any information, including names and email addresses as part of email
+headers, sent to the BTS will be archived and publicly available.</p>
+
+<h2>DebConf (<a href="https://www.debconf.org/">debconf.org</a>)</h2>
+
+<p>The DebConf registration structure stores the details of conference
+attendees. These are required to determine eligibility to bursaries, association
+to the project, and to contact attendees with appropriate details. They may
+also be shared with suppliers to the conference, e.g. attendees staying in the
+conference provided accommodation will have their name and attendance date
+shared with the accommodation provider.</p>
+
+<h2>Developers LDAP (<a href="https://db.debian.org">db.debian.org</a>)</h2>
+
+<p>Project contributors (developers and others with guest accounts) who
+have account access to machines within the Debian infrastructure have
+their details stored within the project's LDAP infrastructure. This
+primarily stores name, username and authentication information. However
+it also has the optional facility for contributors to provide additional
+information such as gender, instant messaging (IRC/XMPP), country and
+address or phone details, and a message if they are on vacation.
+</p>
+
+<p>
+Name, username and some of the voluntarily provided details
+are freely available via the web interface or LDAP search. Additional
+details are only shared with other individuals who have account access
+to the Debian infrastructure and is intended to provide a centralised
+location for project members to exchange such contact information. It is
+not explicitly collected at any point and can always be removed by
+logging into the db.debian.org web interface or sending signed email to
+the email interface. See <a href="https://db.debian.org/">https://db.debian.org/</a> and
+<a href="https://db.debian.org/doc-general.html">https://db.debian.org/doc-general.html</a> for more details.
+</p>
+
+<h2>Gitlab (<a href="https://salsa.debian.org/">salsa.debian.org</a>)</h2>
+
+<p>salsa.debian.org provides an instance of the <a
+href="https://about.gitlab.com/">GitLab</a> DevOps lifecycle management tool.
+It is primarily used by the Project to allow Project contributors to host
+software repositories using Git and encourage collaboration between
+contributors. As a result it requires various pieces of personal information to
+manage accounts. For Project members this is tied to the central Debian LDAP
+system, but guests may also register for an account and will have to provide
+name and email details in order to facilitate the setup and use of that
+account.</p>
+
+<p>Due to the technical nature of git contributions to the git repositories
+held on salsa will contain the name and email address recorded within those git
+commits. The chained nature of the git system means that any modification to
+these commit details once they are incorporated into the repository is
+extremely disruptive and in some cases (such as when signed commits are in use)
+impossible.</p>
+
+<h2>Gobby (<a href="https://gobby.debian.org/">gobby.debian.org</a>)</h2>
+
+<p>Gobby is a collaborative online text editor, which tracks contributions and
+changes against connected users. No authentication is required to connect to
+the system and users may choose any username they wish. However while no
+attempt is made by the service to track who owns usernames it should be
+understand that it may prove possible to map usernames back to individuals
+based upon common use of that username or the content they post to a
+collaborative document within the system.</p>
+
+<h2>Mailing Lists (<a href="https://lists.debian.org/">lists.debian.org</a>)</h2>
+
+<p>Mailing lists are the primary communication mechanism of the Debian Project.
+Almost all of the mailing lists related to the project are open, and thus
+available for anyone to read and/or post to. All lists are also archived; for
+public lists this means in a web accessible manner. This fulfils the project
+commitment to transparency, and aids with helping our users and developers
+understand what is happening in the project, or understand the historical
+reasons for certain aspects of the project. Due to the nature of email these
+archives will therefore potentially hold personal information, such as names
+and email addresses.</p>
+
+<h2>New Members site (<a href="https://nm.debian.org/">nm.debian.org</a>)</h2>
+
+<p>Contributors to the Debian Project who wish to formalise their involvement
+may choose to apply to the New Members process. This allows them to gain the
+ability to upload their own packages (via Debian Maintainership) or to become
+full voting members of the Project with account rights (Debian Developers, in
+uploading and non-uploading variants). As part of this process various personal
+details are collected, starting with name, email address and
+encryption/signature key details. Full Project applications also involve the
+applicant engaging with an Application Manager who will undertake an email
+conversation to ensure the New Member understands the principles behind Debian
+and has the appropriate skills to interact with the Project infrastructure.
+This email conversation is archived and available to the applicant and
+Application Managers via the nm.debian.org interface. Additionally details of
+outstanding applicants are publicly visible on the site, allowing anyone to see
+the state of New Member processing within the Project to ensure an appropriate
+level of transparency.</p>
+
+<h2>Popularity Contest (<a href="https://popcon.debian.org/">popcon.debian.org</a>)</h2>
+
+<p>"popcon" tracks which packages are installed on a Debian system, to enable
+the gathering of statistics about which packages are widely used and which are
+no longer in use. It uses the optional "popularity-contest" package to collect
+this information, requiring explicit opt-in to do so. This provides useful
+guidance about where to devote developer resources, for example when migrating
+to newer library versions and having to spend effort on porting older
+applications. Each popcon instance generates a random 128 bit unique ID which
+is used to track submissions from the same host. No attempt is made to map this
+to an individual about submissions are made via email or HTTP and it is thus
+possible for personal information to leak in the form of the IP address used
+for access or email headers. This information is only available to the Debian
+System Administrators and popcon admins; all such meta-data is removed before
+submissions are made accessible to the project as a whole. However users should
+be aware that unique signatures of packages (such as locally created packages
+or packages with very low install counts) may make machines deducible as
+belonging to particular individuals.</p>
+
+<p>Raw submissions are stored for 24 hours, to allow replaying in the event of
+issues with the processing mechanisms. Anonymized submissions are kept for at
+most 20 days. Summary reports, which contain no personally identifiable
+information, are kept indefinitely.</p>
+
+<h2>snapshot (<a href="http://snapshot.debian.org/">snapshot.debian.org</a>)</h2>
+
+<p>The snapshot archive provides a historical view of the Debian archive
+(ftp.debian.org above), allowing access to old packages based on dates and
+version numbers. It carries no additional information over the main archive
+(and can thus contain personal information in the form of names + email address
+within changelogs, copyright statements and other documentation), but can
+contain packages that are no longer part of shipping Debian releases. This
+provides a useful resource to developers and users when tracking down
+regressions in software packages, or providing a specific environment to run a
+particular application.</p>
+
+<h2>Votes (<a href="https://vote.debian.org/">vote.debian.org</a>)</h2>
+
+<p>The vote tracking system (devotee) tracks the status of ongoing General
+Resolutions and the results of previous votes. In the majority of cases this
+means that once the voting period is over details of who voted (usernames +
+name mapping) and how they voted becomes publicly visible. Only Project
+members are valid voters for the purposes of devotee, and only valid votes are
+tracked by the system.</p>
+
+<h2>Wiki (<a href="https://wiki.debian.org/">wiki.debian.org</a>)</h2>
+
+<p>The Debian Wiki provides a support and documentation resource for the
+Project which is editable by everyone. As part of that contributions are
+tracked over time and associated with user accounts on the wiki; each
+modification to a page is tracked to allow for errant edits to be reverted and
+updated information to be easily examined. This tracking provides details of
+the user responsible for the change, which can be used to prevent abuse by
+blocking abusive users or IP addresses from making edits. User accounts also
+allow users to subscribe to pages to watch for changes, or see details of
+changes throughout the entire wiki since they last checked. In general user
+accounts are named after the name of the user, but no validation is performed
+of the account names and a user may choose any free account name. An email
+address is required for the purposes of providing a mechanism for account
+password reset, and notifying the user of any changes on pages they are
+subscribed to.</p>
+
+<h2>Echelon</h2>
+
+<p>Echelon is a system used by the Project to track member activity; in
+particular it watches the mailing list and archive infrastructures, looking for
+posts and uploads to record that a Debian member is active. Only the most
+recent activity is stored, in the member's LDAP record. It is thus limited to
+only tracking details of individuals who have accounts within the Debian
+infrastructure. This information is used when determining if a project member
+is inactive or missing and thus that there might be an operational requirement
+to lock their account or otherwise reduce their access permissions to ensure
+Debian systems are kept secure.</p>
+
+<h2>Service related logging</h2>
+
+<p>In addition to the explicitly listed services above the Debian
+infrastructure logs details about system accesses for the purposes of ensuring
+service availability and reliability, and to enable debugging and diagnosis of
+issues when they arise. This logging includes details of mails sent/received
+through Debian infrastructure, web page access requests sent to Debian
+infrastructure, and login information for Debian systems (such as SSH logins to
+project machines). None of this information is used for any purposes other than
+operational requirements and it is only stored for 15 days in the case of web
+server logs, 10 days in the case of mail log and 4 weeks in the case of
+authentication/ssh logs.</p>
diff --git a/english/template/debian/common_translation.wml b/english/template/debian/common_translation.wml
index cf6e7ca6726..83cab8b4f56 100644
--- a/english/template/debian/common_translation.wml
+++ b/english/template/debian/common_translation.wml
@@ -33,6 +33,12 @@
 <define-tag contactus whitespace=delete>
   <gettext>Contact Us</gettext>
 </define-tag>
+<define-tag legalinfo whitespace=delete>
+  <gettext>Legal Info</gettext>
+</define-tag>
+<define-tag dataprivacy whitespace=delete>
+  <gettext>Data Privacy</gettext>
+</define-tag>
 <define-tag donations whitespace=delete>
   <gettext>Donations</gettext>
 </define-tag>
diff --git a/english/template/debian/footer.wml b/english/template/debian/footer.wml
index 56ab9e449d1..1104147c2ca 100644
--- a/english/template/debian/footer.wml
+++ b/english/template/debian/footer.wml
@@ -31,6 +31,8 @@
 		  <li><a href="$(HOME)/intro/free"><freesoftware/></a></li>
 		  <li><a href="$(HOME)/partners/"><partners/></a></li>
 		  <li><a href="$(HOME)/donations"><donations/></a></li>
+          <li><a href="$(HOME)/legal"><legalinfo/></a></li>
+          <li><a href="$(HOME)/legal/privacy"><dataprivacy/></a></li>
 		  <li><a href="$(HOME)/contact"><contactus/></a></li>
 		  </ul>
 		</li>
diff --git a/english/template/debian/mainpage.wml b/english/template/debian/mainpage.wml
index a76a17b6cfe..da3f39518f7 100644
--- a/english/template/debian/mainpage.wml
+++ b/english/template/debian/mainpage.wml
@@ -38,6 +38,8 @@
       <li><a href="$(HOME)/intro/free"><freesoftware/></a></li>
       <li><a href="$(HOME)/partners/"><partners/></a></li>
       <li><a href="$(HOME)/donations"><donations/></a></li>
+      <li><a href="$(HOME)/legal"><legalinfo/></a></li>
+      <li><a href="$(HOME)/legal/privacy"><dataprivacy/></a></li>
       <li><a href="$(HOME)/contact"><contactus/></a></li>
     </ul>
   </li>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.