[Lvfs-announce] New GDPR account compliance requirements
Richard Hughes <[email protected]> Sun, 10 May 2020 21:14:20 +0100
| Newsgroups | dev.linux.lists.lvfs-announce |
|---|---|
| Message-ID | <CAD2FfiGT5V86EBS5_mz603X0_OTYnNhcaQ0dcYp2hBznUsP+8g@mail.gmail.com> |
Hi all, Users with an LVFS account will now have to log in at least once per year to keep their account active. If this affects you then a notification will be sent via email on Monday. If you have not used the LVFS in the last year you will need to log into the LVFS within the next 6 weeks to keep your account from being automatically disabled. If you have used the LVFS within the last year no action is required. We've made this small change on the LVFS primarily for GDPR compliance reasons, but also because it makes the LVFS more secure by not having accounts left active for users long moved to other companies. User names and display names can also be considered "PII" and we can't store them indefinitely without consequence. Disabled users cannot login and will have their display name set to "Disabled User" but they are *not* removed from the database, and any firmware uploaded by them is also *not* deleted. Disabled user accounts can be re-enabled by the LVFS administrator, or a new user can just be created with the original user email address by a vendor manager. As a reminder, as a vendor manager on the LVFS it is your responsibility to disable users when people leave the group responsible for uploading firmware. When users leave your company it should be part of standard procedure to also deactivate their LVFS account if you are also not using Azure AD for LVFS login. Any questions welcome off list, thanks. Richard.