You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

Identity Providers don't send attributes to Service Providers without any good reason. Sweden is a member of the European Union and within the union there are strict rules on storing, transfer and process personal data. All attributes in the attribute release is to consider as personal data and therefore Identity Providers are careful.

The best way for a Service Provider to get the needed attributes is to request to the registering federation, i.e. SWAMID, to add entity categories to their metadata. For more information about entity categories please see Entity Categories for Service Providers.

To further more enhance the possibility to get attributes the Service Provider should write and publish an informational document about the Service Provider and a privacy policy the defines how the Service Provider stores and processes personal data, please see Service Provider Metadata Extensions for Login and Discovery User Interface (MDUI) for further information.

If some Identity Providers still doesn't release enough required attributes to the Service Provider you should inform the users what required attributes are missing in the release from their Identity Providers.

  • No labels