EPrints Technical Mailing List Archive

See the EPrints wiki for instructions on how to join this mailing list and related information.

Message: #07704


< Previous (by date) | Next (by date) > | < Previous (in thread) | Next (in thread) > | Messages - Most Recent First | Threads - Most Recent First

Re: [EP-tech] GDPR and the "Request a copy" buttonn


Another issue is that this form passes data to your academics. They can't do anything else with that data... ie. add people to a mailing list or whatever.

On 15/02/2019 10:22, John Salter via Eprints-tech wrote:

Hi,

A standard install of EPrints will retain the requests made. Look in the 'request' table.

 

There is also some data stored in the history dataset - when someone (e.g. the author) responds to a request:

https://github.com/eprints/eprints/blob/3.3/perl_lib/EPrints/Plugin/Screen/Request/Respond.pm#L199-L217

 

If you look in the history table for rows with 'action' set to 'accept_request', 'oa_request' or 'reject_request', you can see what information is stored. It includes the reason for rejection - which may have data in it that you need to consider in relation to GDPR.

 

I'm currently pondering what to do with this data.

Retaining statistics about items that have been requested is useful - but the details of who made the requests should be removed according to GDPR regulations.

I may end up setting the details in the Request dataset to a standard (e.g. 'removed-for-gdpr@example.com' for the email address), or we may store counts of what items were requested and when.

 

The IRStats package can process the requests data too - so removing the entries entirely will mean if you regenerate the stats from scratch, your historic usage data will change.

 

Cheers,

John

 

 

From: eprints-tech-bounces@ecs.soton.ac.uk [mailto:eprints-tech-bounces@ecs.soton.ac.uk] On Behalf Of Siminson ,Nicola Jane via Eprints-tech
Sent: 15 February 2019 08:55
To: Laszlo Csirmaz <laci@degas.ceu.hu>; eprints-tech@ecs.soton.ac.uk
Subject: Re: [EP-tech] GDPR and the "Request a copy" buttonn

 

Hello Laszlo,

Many thanks for your interesting reply. In terms of the data not being kept, I note that https://wiki.eprints.org/w/GDPR states:

Request a copy Dataset

This collects an email address and a reason for requesting the document. Without intervention this can be stored indefinitely.

Have you therefore set your own instance of EPrints not to store the data - or how do you monitor when the requested paper has been forwarded or rejected?

 

With thanks and best wishes,

 

Nicola

 

Nicola Siminson | Institutional Repository and Records Manager

The Glasgow School of Art | 167 Renfrew Street | Glasgow | G3 6RQ | Tel: 0141 566 1417 | Email: n.siminson@gsa.ac.uk | www.gsa.ac.uk

 

-----Original Message-----
From: Laszlo Csirmaz [mailto:laci@degas.ceu.hu]
Sent: 14 February 2019 21:20
To: eprints-tech@ecs.soton.ac.uk; Siminson ,Nicola Jane <N.Siminson@gsa.ac.uk>
Subject: Re: [EP-tech] GDPR and the "Request a copy" buttonn

 

Dear Nicola,

 

according to my understanding, GDPR is relevant only if you KEEP the data.

In this case the data is not kept, only during the time it is necessary to forward the requested paper (or reject it). In this case GDPR is not relevant and gives no legally binding obligations.

 

Hope this helps.

Best,

 

Laszlo

Laszlo Csirmaz,

CEU

 

> Hello,

> I think there was some mention of GDPR on this list last year, but I'm

> And finally - I am familiar with this page and its contents - but

> there are still quite a lot of items marked as "TO DO", including the

> section "Request a copy Dataset":

> i.eprints.org%2Fw%2FGDPR&amp;data="">

> 788272b77964417749c08d692c21c54%7C67f9795821514513bd2170cde632768b%7C0

> %7C0%7C636857759744238597&amp;sdata=DrD643XyYvQyiBfeE%2FGCv4cP9Sa432bu

> KIfxgzTqk04%3D&amp;reserved=0

>

> My question is this: Would anyone on this list be willing to share with me what they consider the legal basis to be for processing personal data which is received when a user selects the "Request a copy" button, and fills in their contact details etc.? I realise that each institution makes a decision on which of the 6 legal bases it chooses for each of its processing activities - so I'm interested (on or off-list!) to know what colleagues think, and / or what you have stated in your privacy notices!

>

> With many thanks in advance for considering my request   :-)

>

> Best wishes,

>

> Nicola

>

> Nicola Siminson

> Institutional Repository and Records Manager The Glasgow School of Art

>

> *** Options:

> man.ecs.soton.ac.uk%2Fmailman%2Flistinfo%2Feprints-tech&amp;data="">

> 01%7CN.Siminson%40gsa.ac.uk%7C3788272b77964417749c08d692c21c54%7C67f97

> 95821514513bd2170cde632768b%7C0%7C1%7C636857759744238597&amp;sdata=NyR

> %2B9LToHNz%2FB12bvROtDHg1zAjmYIbdyfJaqridA8g%3D&amp;reserved=0

> *** Archive:

> eprints.org%2Ftech.php%2F&amp;data="">

> 3788272b77964417749c08d692c21c54%7C67f9795821514513bd2170cde632768b%7C

> 0%7C1%7C636857759744238597&amp;sdata=L9s50oSaPUxvkQHyqiebPhVD6CPpZmqFE

> uuky1jlEqQ%3D&amp;reserved=0

> *** EPrints community wiki:

> .eprints.org%2F&amp;data="">

> 964417749c08d692c21c54%7C67f9795821514513bd2170cde632768b%7C0%7C1%7C63

> 6857759744238597&amp;sdata=%2BmU3mYVaOy0Ymmpo5so0ulBieN3u0LsX89KZoITZ8

> Wg%3D&amp;reserved=0

> *** EPrints developers Forum:

> m.eprints.org%2F&amp;data="">

> 7964417749c08d692c21c54%7C67f9795821514513bd2170cde632768b%7C0%7C1%7C6

> 36857759744248611&amp;sdata=hlbD%2FmNF0MDL017JGhlAQ0%2F7oOfn6tHIaTot8s

> gK4rY%3D&amp;reserved=0

 


*** Options: http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech
*** Archive: http://www.eprints.org/tech.php/
*** EPrints community wiki: http://wiki.eprints.org/
*** EPrints developers Forum: http://forum.eprints.org/
-- 
Christopher Gutteridge <totl@soton.ac.uk> 
You should read our team blog at http://blog.soton.ac.uk/webteam/