Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Swedish

Beskrivning av Sunets Crowd-inloggningstjänst

Inloggningstjänsten Crowd hanterar inloggning i Sunets Wiki, Jira och Jira Service Desk för användare som behöver komma åt inloggningsskyddad information i dessa tjänster. Du ska endast logga in om du är verksam vid Sunet eller samverkar med Sunet och har blivit ombedd att logga in.

Hantering av personuppgifter

Överföring av personuppgifter

Vid inloggning överförs personuppgifter från den identitetsutfärdare du har loggat in med till Sunets inloggningstjänst Crowd för att ge dig som användare tillgång till inloggningsskyddad information i Sunets tjänster Wiki, Jira och Jira Service Desk. I samband med inloggning begärs ett antal personuppgifter för att identifiera dig som användare samt att inloggningen ska vara tekniskt möjlig.

Följande personuppgifter begärs av inloggningstjänsten:

PersonuppgifterSyfteTeknisk representation
Unik teknisk identifierareIdentifiera dig som användare i tjänsten så att du får åtkomst enligt de rättigheter du blivit tilldelade.

eduPersonPrincipalName

FörnamnIdentifiera dig för övriga användare i tjänsterna.givenName
EfternamnIdentifiera dig för övriga användare i tjänsterna.sn
E-postadressKontaktuppgift som används om administratören av tjänsten behöver komma i kontakt med dig.mail


Förutom direkta personuppgifter överförs även tekniskt indirekta personuppgifter såsom vilken organisation du tillhör och vilken identitetsutfärdare som har använts vid inloggningen. Dessa uppgifter används ej av inloggningstjänsten mer än för tekniska loggar.

Övrig behandling av personuppgifter i tjänsten

Inloggningstjänsten sparar tekniska loggar för felsökning och säkerhetsrelaterade incidenter. Dessa tekniska loggar innehåller information om alla inloggningar som görs i deltjänsterna inkl. överförda personuppgifter.

Sunets Wiki sparar vem som har skapat, uppdaterat och tagit bort wikisidor. Sunets Jira och Jira Service Desk sparar vem som har arbetat med ett visst ärende via en händelselog per ärende.

Överföring av personuppgifter till tredje part

Inga personuppgifter överförs till tredje part.

Rättslig grund

Personuppgifter hanteras baserat på den rättsliga grunden allmänt intresse. Personuppgifterna måste överföras för att ge användare åtkomst till inloggningsskyddad information som behövs för sitt arbete vid Sunet eller i samverkan med Sunet.

Rätt till registerutdrag, rättelse och radering av personuppgifter

Personuppgifter sparade i inloggningstjänsten rättas automatiskt baserat på personuppgifterna som överförs från din identitetsutfärdare i samband inloggningen.

För att radera dina personuppgifter i inloggningstjänsten tag kontakt med SUNET NOC.

För registerutdrag kontakta personuppgiftsansvarig.

Rensning av personuppgifter

Personuppgifter rensas manuellt när de inte längre används inloggningstjänsten eller anslutna tjänster.

Personuppgiftsansvarig

Personuppgiftsansvarig för behandlingen av personuppgifter är Vetenskapsrådet i Sverige. Har du frågor om hur personuppgifter hanteras inom tjänsten tag kontakt med SUNET NOC.

Kontaktuppgifter till Vetenskapsrådets dataskyddsombud finns på https://www.vr.se/behandling-av-personuppgifter.html.

GÉANT Data Protection Code of Conduct

Denna tjänst följer det internationella ramverket GÉANT Data Protection Code of Conduct (http://www.geant.net/uri/dataprotection-code-of-conduct/v1) för överföring av personuppgifter från identitetsutfärdare till tjänsten. Ramverket är avsett för tjänster i Sverige, EU och EES som används inom forskning och högre utbildning.


English

Description

of SWAMID Entity Category Release Check

SWAMID Entity Category Release Check is a suite of test services for system administrators of identity providers registered in SWAMID..

The test services determine if the identity provider follows SWAMID Best Current Practice for Entity Category Attribute Release.

The purpose of the test services are to evaluate which attributes are released by the identity provider depending on entity categories and requested attributes in the metadata of the respective test service.

SWAMID Entity Category Release Check contains the following test services:

of Sunet Crowd Identity Management

The Crowd Identity Management service handles login in Sunets Wiki, Jira and Jira Service Desk for users who need to access login-protected information in these services.You should only log in if you work at Sunet or collaborate with Sunet and have been asked to log in.

  • SWAMID Entity Category Release Check - EC verification
  • SWAMID Entity Category Release Check - No EC
  • SWAMID Entity Category Release Check - REFEDS R and S
  • SWAMID Entity Category Release Check - GÉANT CoCo part 1
  • SWAMID Entity Category Release Check - GÉANT CoCo part 2
  • SWAMID Entity Category Release Check - GÉANT CoCo part 3

Processing of personal data

Transfer of personal data

Personal data are transferred from the identity provider (your login service) to the test services to ensure that the identity provider complies with the SWAMID Best Current Practice for Entity Category Attribute Release. When logging in to the respective test service, a unique subset of personal data are requested from the list below personal information is transferred from the identity provider you are testing. Each test service stores the set of attributes that have been transferred from the identity provider to the service in order to be able to give a summarised result after the test suite has been completed. The attribute values, that contains personal data, are not storedhave logged in with to Sunet's identity management service Crowd to give you as a user access to login-protected information in Sunet's services Wiki, Jira and Jira Service Desk.At tme of login, a number of personal data is requested to identify you as a user and give you access to service.

When logging in to these test services, the following personal data are requested from the identity provider you use:

cn
displayName
givenName
sn
Personal dataPurposeTechnical representation
Unique identifiersTo verify that the attributes are released by the identity provider and to display the values to the user performing the tests

eduPersonPrincipalName
eduPersonTargetedID
eduPersonUniqueID

Personal Identity NumberTo verify that the attributes are released by the identity provider and to display the values to the user performing the testsnorEduPersonNIN
personalIdentityNumber
Researcher and contributor identifierTo verify that the attribute is released by the identity provider and to display the value to the user performing the testseduPersonOrcid
identifierIdentify you as a user of the service so that you have access according to the rights you have been granted.

eduPersonPrincipalName

ForenameIdentify yourself to other users in the services.givenName
SurnameIdentify yourself to other users in the services.givenNameNameTo verify that the attributes are released by the identity provider and to display the values to the user performing the tests
E-mail addressTo verify that the attribute is released by the identity provider and to display the value to the user performing the testsmail
Date of birthTo verify that the attribute is released by the identity provider and to display the value to the user performing the testsschacDateOfBirth
Assurance levelTo verify that the attribute is released by the identity provider and to display the value to the user performing the testseduPersonAssurance
Organisational dataTo verify that the attributes are released by the identity provider and to display the values to the user performing the testseduPersonAffiliation
eduPersonScopedAffiliation


In addition to direct personal data, indirect personal data are also transferred, such as which organisation the user belongs to and which identity provider that has been used when logging in. In combination with the above personal data, these can be used to uniquely identify a person This information is not used by the login service more than for technical logs.

Other processing of personal data within the service

All test services store The identity management service saves technical logs for debugging purposes troubleshooting and security related incidents.These technical logs contain information regarding about all authentications made to the test services and the personal data transferredlogins made incl.transferred personal data.

Sunets Wiki saves who has created, updated and deleted wiki pages.Sunets Jira and Jira Service Desk save who has worked on a particular case via an event log per case.

Transfer of personal data to third parties

No personal data are transferred to third parties.

Lawful basis

Personal data are processed is handled based on the lawful basis of public interest.  Personal The personal data must be transferred in order for system administrators of identity providers to be+ able to verify that personal data is transferred in accordance with the recommendations of SWAMIDto give users access to login-protected information needed for their work at Sunet or in collaboration with Sunet.

Right of access, right of rectification and right of erasure of personal data

Personal data saved in the identity management service is automatically corrected based on the personal data transferred from your identity issuer in connection with the login.

To delete your personal information in the identity management service, contact SUNET NOCNo personal data are stored in the service except in technical logs for debugging purposes and security related incidents.

For access and erasure of your personal data, contact the Personal data controller.

Purging of personal data

No personal data are stored in the service except in technical logs. The technical logs are automatically purged within a week.Personal data is manually purged when it is no longer used by the identity management service or connected services.

Personal data controller

Personal data controller for the processing of personal data is The Swedish Research Council, Sweden. If you have questions about how personal data are processed within the service, please contact operations@swamid.se SUNET NOC.

Contact information for The Swedish Research Council's data protection officer can be found at https://www.vr.se/behandling-av-personuppgifter.html.

GÉANT Data Protection Code of Conduct

This service complies with the international framework GÉANT Data Protection Code of Conduct (http://www.geant.net/uri/dataprotection-code-of-conduct/v1) for the transfer of personal data from identity providers to the service. This framework is intended for services in Sweden, the EU and the EEA that are used in research and higher education.

...