[WG-InfoSharing] Removing Subject ID Field from receipt fields

Mark Lizar - OCG m.lizar at openconsentgroup.com
Thu Mar 10 18:53:16 CST 2016


Hello CISWG, 

I have added a new issue to Github for discussion.  Another one of those long outstanding issues about how to present and transfer PII in the receipt.  This is relative to the specification review of the table fields.  

The issue #23 <https://github.com/KantaraInitiative/CISWG/issues/23> is a suggestion to remove the subject id field from the consent receipt field so that the consent receipt fields don't contain PII, but, instead, attached is the receipt payload with all of the data entered by the consent grantee.
The benefit would be that the receipt fields themselves don't contain PII, thus are less sensitive themselves, with the PII entered into  the receipt delivered in the receipt payload. The payload of PII data would be provisioned to the consent grantee, but not displayed on the website, via the consent receipt as to protect privacy and be privacy by design.

All thoughts welcome, especially on how to specify this in the specification (if it should be specified). 

Best, 

Mark 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://kantarainitiative.org/pipermail/wg-infosharing/attachments/20160311/dcb5a56b/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3591 bytes
Desc: not available
URL: <http://kantarainitiative.org/pipermail/wg-infosharing/attachments/20160311/dcb5a56b/attachment.p7s>


More information about the WG-InfoSharing mailing list