University IdP Terms and Conditions

From RavenWiki
Revision as of 17:10, 26 June 2007 by jw35 (talk | contribs) (First cut)
Jump to navigationJump to search
ShibbolethLogoColorSmall.png
WARNING: This page is retained as a historical record but is out-of-date and is not being maintained.

This was a working document belonging to the Computing Service's Shibboleth Development Project. This project is complete (Raven now supports Shibboleth) and this document only remains for historical and reference purposes. Be aware that it is not being maintained and may be misleading if read out of context.
This is a draft of the 'Terms and Conditions' that will be displayed to each user the first time they use the Shibboleth service and at least annually thereafter. As well as generally keeping users informed, it provides a critical element in the services compliance with the Data Protection Act.

The site that you wish to access requires that Raven provides some additional information about you. Before accessing this site, or any others operating in the same way, you must read this document and confirm that you understand it by selecting the 'Confirm' button below.

For sites within the University, Raven normally uses your CRSid to identify you. This is inappropriate for sites that are not operated by the University and for these (and also for some University ones) Raven provides one or more items of information about you. This information may be used by the site both to control access and to customise your browsing experience.

For sites which are not operated by the University, wherever possible only 'anonymous' information from which your real-world identity can not be derived is released. In many cases this includes only your status within the University ('member', 'staff', 'student', etc.) and an 'Anonymous Identifier' which is unique to you and the site being visited.

For some non-University sites it is necessary for Raven to release information from which you can be identified. This only happens when release of the data is required for access to the particular resource. Release of such information only happens under a contract or other arrangements which provides what the University considers to be adequate levels of protection for the data concerned, but you should be aware that some of these sites may be in parts of the world with limited data protection legislation.

The first time you access a new site in this way you will be told what information will be released to it and asked to approve this release. You always have the option of preventing release by withholding you approval. This will prevent you from accessing the site - if necessary you should seek advice, perhaps from your supervisor, lecturer, Tutor or Director of Studies, to establish how you can obtain the information you require without disclosing personal information about yourself.

The processing of personal data by this service is subject to the UK Data Protection Act 1998. The 'Data Controller' for the processing of such data is the University of Cambridge (contact the University Data Protection Officer, 10 Peas Hill, Cambridge CB2 3PN, tel. 01223 339888, fax 01223 331200, E-mail: data.protection@admin.cam.ac.uk). General questions about this service should be emailed to raven-support@ucs.cam.ac.uk.

This service is often used to grant you access to resources provided to the University by third parties. You must familiarise yourself with the terms and conditions under which such resources are available and abide by them. In extreme cases, misuse of resources controlled by Raven may result in the suspension of your Raven account.

You will be asked to re-confirm your understanding of this document and the process that it describes annually and whenever this document changes. The current version of this document can be consulted at any time at <insert URL here>.