[Lvfs-announce] New GDPR account compliance requirements

Richard Hughes <[email protected]> Sun, 10 May 2020 21:14:20 +0100
Newsgroups dev.linux.lists.lvfs-announce
Message-ID <CAD2FfiGT5V86EBS5_mz603X0_OTYnNhcaQ0dcYp2hBznUsP+8g@mail.gmail.com>
Hi all,

Users with an LVFS account will now have to log in at least once per
year to keep their account active. If this affects you then a
notification will be sent via email on Monday. If you have not used
the LVFS in the last year you will need to log into the LVFS within
the next 6 weeks to keep your account from being automatically
disabled. If you have used the LVFS within the last year no action is
required.

We've made this small change on the LVFS primarily for GDPR compliance
reasons, but also because it makes the LVFS more secure by not having
accounts left active for users long moved to other companies. User
names and display names can also be considered "PII" and we can't
store them indefinitely without consequence. Disabled users cannot
login and will have their display name set to "Disabled User" but they
are *not* removed from the database, and any firmware uploaded by them
is also *not* deleted. Disabled user accounts can be re-enabled by the
LVFS administrator, or a new user can just be created with the
original user email address by a vendor manager.

As a reminder, as a vendor manager on the LVFS it is your
responsibility to disable users when people leave the group
responsible for uploading firmware. When users leave your company it
should be part of standard procedure to also deactivate their LVFS
account if you are also not using Azure AD for LVFS login.

Any questions welcome off list, thanks.

Richard.