University IdP Terms and Conditions: Difference between revisions

From RavenWiki
Jump to navigationJump to search
(Revised in line with changes to the Attribute Release Policy)
(Revised in line with the SMT's recent decision. Still not quite right...)
Line 1: Line 1:
{{shib-project}}
{{shib-project}}


: ''This is a draft (as at 2007-07-09) of the 'Terms and Conditions' that will be displayed to each user the first time they use the Shibboleth service and at least annually thereafter. As well as generally keeping users informed, it provides a critical element in the service's compliance with the Data Protection Act.''
: ''This is a draft (as at 2007-07-20) of the 'Terms and Conditions' that will be displayed to each user the first time they use the Shibboleth service and at least annually thereafter. As well as generally keeping users informed, it provides a critical element in the service's compliance with the Data Protection Act.''


----
----
Line 7: Line 7:
'''The site that you wish to access requires that Raven releases some information about you. Before accessing this site, or any others operating in the same way, you must read this document and confirm that you accept having your information processed and released in this way. The information released may be used by the site for various purposes - you should consult its privacy policy for further details.'''  
'''The site that you wish to access requires that Raven releases some information about you. Before accessing this site, or any others operating in the same way, you must read this document and confirm that you accept having your information processed and released in this way. The information released may be used by the site for various purposes - you should consult its privacy policy for further details.'''  


For sites that are operated by organisations other than the University (for example other Universities, commercial database providers, etc.), only 'anonymous' information from which the site can not establish your real-world identity will be released wherever possible. In many cases this will include only your status within the University ('member', 'staff', 'student', etc.) and an 'Anonymous Identifier' which is unique to you and the particular site you are visiting.
For sites that are operated by organisations other than the University (for example other Universities, commercial database providers, etc.) Raven will by default release your identity (in the form of an eduPersonPrincipleName), your status within the University ('member', 'staff', 'student', etc.) and an 'Anonymous Identifier' which is unique to you and the particular site you are visiting. In some cases Raven may release additional information, but only when this is necessary to allow you to access to the particular resource.


For some sites it is necessary for Raven to release additional information from which you could be identified. This only happens when release of the data is required for access to the particular resource. Release of such information to sites outside the University is only allowed where there is adequate levels of protection for the data. You should be aware that some of these sites could be in parts of the world with limited data protection legislation.
For sites that are operated by the University, additional information derived from lookup may be released if those sites could obtain the same information directly from lookup, but only subject to your choice of suppression.


Each time you access a new site that works this way you will be told what information will be released and asked to approve this release. You can always withhold you approval but this may prevent you from accessing the site. If you wish to do this but access to the site is necessary for your employment or studies you should seek advice, perhaps from your manager, supervisor, lecturer, tutor or director of studies.
When you access a site that works this way for the first time you will be told what information will be released and asked to approve this release. You can always withhold you approval but this may prevent you from accessing the site. If you wish to do this but access to the site is necessary for your employment or studies you should seek advice, perhaps from your manager, supervisor, lecturer, tutor or director of studies.


Even where only 'anonymous' information is released, Raven maintains logs from which your real-world identity can be established. This information may be used to investigate misuse of Raven or services accessed through it, or for fault finding. Your identity, when established in this way, will not be divulged to third parties except as required by law.
You should be aware that any site, operated by the University or otherwise, may be located outside the European Economic Area.


Some sites may invite or require you to provide additional information about yourself, over and above that provided by Raven. Such requests, and the site's subsequent use of this information, are outside the University's control and you must use your own judgement about how to respond. The site should inform you at the time of collection of the purposes for which the data is required.
Whatever information is released, Raven maintains logs from which your real-world identity can be established. This information may be used to investigate misuse of Raven or services accessed through it, or for fault finding. Your identity, when established in this way, will not be divulged to third parties except as required by law.
 
Some sites may themselves invite or require you to provide additional information about yourself, over and above that provided by Raven. Such requests, and the site's subsequent use of this information, are outside the University's control and you must use your own judgement about how to respond. The site should inform you at the time of collection of the purposes for which the data is required.


This service is often used to grant you access to resources provided to the University by third parties. You must familiarise yourself with the terms and conditions under which such resources are available and abide by them. In extreme cases, misuse of resources controlled by Raven may result in the suspension of your Raven account.
This service is often used to grant you access to resources provided to the University by third parties. You must familiarise yourself with the terms and conditions under which such resources are available and abide by them. In extreme cases, misuse of resources controlled by Raven may result in the suspension of your Raven account.

Revision as of 16:21, 20 July 2007

ShibbolethLogoColorSmall.png
WARNING: This page is retained as a historical record but is out-of-date and is not being maintained.

This was a working document belonging to the Computing Service's Shibboleth Development Project. This project is complete (Raven now supports Shibboleth) and this document only remains for historical and reference purposes. Be aware that it is not being maintained and may be misleading if read out of context.
This is a draft (as at 2007-07-20) of the 'Terms and Conditions' that will be displayed to each user the first time they use the Shibboleth service and at least annually thereafter. As well as generally keeping users informed, it provides a critical element in the service's compliance with the Data Protection Act.

The site that you wish to access requires that Raven releases some information about you. Before accessing this site, or any others operating in the same way, you must read this document and confirm that you accept having your information processed and released in this way. The information released may be used by the site for various purposes - you should consult its privacy policy for further details.

For sites that are operated by organisations other than the University (for example other Universities, commercial database providers, etc.) Raven will by default release your identity (in the form of an eduPersonPrincipleName), your status within the University ('member', 'staff', 'student', etc.) and an 'Anonymous Identifier' which is unique to you and the particular site you are visiting. In some cases Raven may release additional information, but only when this is necessary to allow you to access to the particular resource.

For sites that are operated by the University, additional information derived from lookup may be released if those sites could obtain the same information directly from lookup, but only subject to your choice of suppression.

When you access a site that works this way for the first time you will be told what information will be released and asked to approve this release. You can always withhold you approval but this may prevent you from accessing the site. If you wish to do this but access to the site is necessary for your employment or studies you should seek advice, perhaps from your manager, supervisor, lecturer, tutor or director of studies.

You should be aware that any site, operated by the University or otherwise, may be located outside the European Economic Area.

Whatever information is released, Raven maintains logs from which your real-world identity can be established. This information may be used to investigate misuse of Raven or services accessed through it, or for fault finding. Your identity, when established in this way, will not be divulged to third parties except as required by law.

Some sites may themselves invite or require you to provide additional information about yourself, over and above that provided by Raven. Such requests, and the site's subsequent use of this information, are outside the University's control and you must use your own judgement about how to respond. The site should inform you at the time of collection of the purposes for which the data is required.

This service is often used to grant you access to resources provided to the University by third parties. You must familiarise yourself with the terms and conditions under which such resources are available and abide by them. In extreme cases, misuse of resources controlled by Raven may result in the suspension of your Raven account.

You will be asked to re-confirm your understanding of this document and the process that it describes annually and whenever this document changes. The current version of this document can be consulted at any time at <insert URL here>.

General questions about this service should be emailed to help-desk@ucs.cam.ac.uk. The processing of personal data by this service is subject to the UK Data Protection Act 1998. The 'Data Controller' for the processing of such data is the University of Cambridge (contact The University Data Protection Officer, The Old Schools, Trinity Lane, Cambridge CB2 1TN; Email: data.protection@admin.cam.ac.uk).