Networks ∙ Services ∙ People Nicole Harris, GÉANT GN4 Project Update “SA5”, or Identity Stuff Internet2 Technology Exchange 2015.

Slides:



Advertisements
Similar presentations
PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
Advertisements

Data Protection & Privacy in the Information Age COMNET – Legal Frameworks for ICTs Malta 2013 Dr Antonio Ghio Dr Jeanine Rizzo.
Federated Identity Management for Researchers – A quick overview from GÉANT BoF TNC May 2014 Dublin.
Innovation through participation GÉANT Data Protection Code of Conduct (DP CoC) FIM for research collaboration workshop Mikael Linden,
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Innovation through participation Attributes Release Working Group European data protection directive REFEDS meeting 22th Apr, 2012
Updates Licia Florio, TERENA REFEDS Meeting 5 Sept 2012.
EduGAIN – Are we there yet? Lukas Hämmerle (ghost writer, Brook Schofield) FIM4R, Helsinki – 2 October 2013.
Innovation through participation eduGAIN federation operator training eduGAIN policy eduGAIN training in Vienna Oct 2011
REFEDS RESEARCH AND EDUCATION (R&S) ENTITY CATEGORY NICOLE HARRIS.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
LexisNexis Confidential EU Privacy Framework Michael Lamb LexisNexis Risk Solutions Vice President and Lead Counsel: Regulatory, Privacy & Policy May 19,
Innovation through participation Interfederation through eduGAIN - steps and challenges eduGAIN interfederation service Federated Identity Systems.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
The ReFEDS/GÉANT Code of Conduct (CoC) An Approach to Compliance with the EU Data Protection Directive Steve Carmody April 23, 2012.
Updates Licia Florio, TERENA REFEDS Meeting 5 Sept 2012.
Identity Federation Policy Marina Vermezović, AMRES Federated Identity Technology Workshop Sofia, Bulgaria, 20. Jun 2014.
Networks ∙ Services ∙ People Mandeep Saini TF-MSP, Espoo, Finland Service Delivery and Adoption 10 th Sep 2015 Task Leader, GN4-1 SA7 T3.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
WHOIS data The EU legal principles ICANN - GNSO meeting 2 March 2004 George Papapavlou, European Commission ICANN - GNSO meeting 2 March 2004 George Papapavlou,
INTRODUCTION: THE FIRST TRY InCommon eduGAIN Policy and Community Working Group.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Networks ∙ Services ∙ People 1 European Workshop on Trust and Identity Date: 30 November – 3 December 2015 Location: Vienna, Austria Organisers:
Authentication and Authorisation for Research and Collaboration Michał Jankowski, Maciej Brzeźniak AARC General Meeting, Milan.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Networks ∙ Services ∙ People Daniela Pöhn REFEDS EWTI, Vienna IdPs and Federations Service Aspects of Assurance SA5T1.
Understanding deployment issues on the Supply Chain Ann Harding, SWITCH, Nicole Harris, TERENA Cambridge July 2014.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
Networks ∙ Services ∙ People eduGAIN Townhall Meeting Nicole Harris (or updating the eduGAIN policy suite) “Unicorns can be sued in Wales”
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Networks ∙ Services ∙ People Marina Adomeit FIM4R meeting Virtual Organisation Platform as a Service VOPaaS Nov 30, 2015, Austria Task Leader,
Networks ∙ Services ∙ People Ann Harding eduGAIN Town Hall eduGAIN in the GÉANT Project Activity Leader GÉANT Trust and Identity.
Networks ∙ Services ∙ People Ann Harding GÉANT Symposium, Vienna Users Session A3 Trust and Identity March GÉANT Activity Leader Trust.
Networks ∙ Services ∙ People Ann Harding + Marina Adomeit GÉANT Symposium 2016 What’s changed, what stays the same? Project future - services.
Networks ∙ Services ∙ People Mandeep Saini TNC15, Porto, Portugal Virtual organisation Authorisation Management Practices in Research and.
Networks ∙ Services ∙ People Licia Florio TNC, Lisbon Consuming identities across e- Infrastructures 16 June 2015 PDO GÈANT.
Authentication and Authorisation for Research and Collaboration Heiko Hütter, Martin Haase, Peter Gietz, David Groep AARC 3 rd.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC CORBEL Workshop The AARC Project Paris, 31 May.
Designing Identity Federation Policy, the right way Marina Vermezović, Academic Network of Serbia TNC2013 conference 4 May 2013.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC f-2-f Meeting One Year of AARC Utrecht, 24 May.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
Networks ∙ Services ∙ People Marina Adomeit TNC16 Conference, Prague Towards a platform for supporting collaboration GÉANT VOPaaS
Networks ∙ Services ∙ People TNC 2016, Prague Alice Through the Looking Glass Science DMZ goes above the network 13 June
Authentication and Authorisation for Research and Collaboration AARC/CORBEL Workshop for Life Sciences AAI AARC Draft Blueprint.
Networks ∙ Services ∙ People Ann Harding Networkshop 44, Manchester Thinking globally, acting locally Trust and Identity in the GÉANT project.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Networks ∙ Services ∙ People Mandeep Saini AARC/CORBEL Workshop Collaborative Organisation Platform as a Service June 1, 2016, Paris Product.
Networks ∙ Services ∙ People Marina Adomeit JRA3 kick off SA2 in GN July, Zürich SA2 Activity leader.
Authentication and Authorisation for Research and Collaboration Licia Florio IGTF Meeting The AARC Project Amsterdam, 8 September.
Innovation through participation Data Protection Code of Conduct (DP CoC) TNC2013 conference, 4 June 2013 Mikael Linden, CSC – IT Center for Science
Cross-sector and user-centric AAI
TrustTech - Task Overview (GN4-2 JRA3-T3)
eduTEAMS platform for collaboration Niels Van Dijk
GÉANT 4-2 JRA3 T1 Something with Federations and Campus VC
GÉANT 4-2 JRA3 T1 and T2 Federations and Campus (CaFe) e-Infrastructures and Service Providers (RASP) Daniela Pöhn JRA3 T1 LRZ/DFN-AAI Technology Exchange.
Transfers of personal data
EU Reference Centres for Animal Welfare
General Data Protection Regulation
Relocation CARNIVAL come one…come all
The activity of Art. 29. Working Party György Halmos
REFEDS Report: Fall 2017 Nicole Harris Internet2 Technology Exchange
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Legal Basis: CRITERIA FOR MAKING DATA PROCESSING LEGITIMATE
Why are we processing data
Baseline Expectations for Trust in Federation
Presentation transcript:

Networks ∙ Services ∙ People Nicole Harris, GÉANT GN4 Project Update “SA5”, or Identity Stuff Internet2 Technology Exchange 2015 Sunday 4th October 2015

Networks ∙ Services ∙ People Nicole Harris, GÉANT Harmonisation Rhys Smith, JISC Non Web Brook Schofield, GÉANT eduGAIN Marina Vermezovic, AMRES Federation as a Service Niels van Dijk, Surfnet VOPaaS & InAcademia Lukas Hämmerle, SWITCH Enabling Users Mandeep Saini, GÉANT Assoc. GÉANT AAI Miroslav Milinovic, CARnet/SRCE eduroam Who’s who?

Networks ∙ Services ∙ People Harmonisation Entity Categories CoCo Federation Practices Assurance Business Case Interoperability Non web MoonshotECP eduGAIN eduGAIN technical development, inc. portal Federation development InAcademia Federation as a Service VO Platform as a Service Enabling Users PilotsConsultancy SP registration simplification The eduGAIN family in GN4 Service Development (SA5) New TaskNew Subtask/work area

Networks ∙ Services ∙ People Support the rollout of “Research and Scholarship” and “Code of Conduct” categories. Support the creation of “Affiliation” and “Academia” categories. Entity Categories Continue development of non EU / EEA Code of Conduct. Ensure compliancy with changing Data Protection legislations. Work with WP29. Code of Conduct Establish common Metadata Registration Practice Statement. Support non-SAML profiles in eduGAIN. Make recommendations on metadata publication processes. Federation Practices Cost-benefit analysis for campuses adopting assurance profiles. Scoping of step-up assurance service options. Assurance Business Case Complete STORK-eduGAIN interoperability pilot and eIDAS scoping. Define service requirements for FedLab offering. Interoperability Service Development (SA5) Trust and Identity Harmonisation New Subtask/work area

Networks ∙ Services ∙ People Research and Scholarship 5 DateIdPsSPsFederations 10 September DFN, CESNET, SWITCHaai, UK, SWAMID, Aconet, InCommon, Feide. (8) 03 October DFN, CESNET, PIONER.Id, SWITCHaai, UK, SWAMID, Aconet, InCommon, Feide, SurfConext, IDEM. (11)

Networks ∙ Services ∙ People CONSENTThe data subject has unambiguously given his consent. CONTRACTUALProcessing is necessary for the performance of a contract to which the data subject is party. LEGAL OBLIGATIONProcessing is necessary for compliance with a legal obligation to which the data controller is subject. VITAL INTERESTProcessing is necessary in order to protect the vital interests of the data subject. PUBLIC INTERESTProcessing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller or in a third party to whom the data are disclosed. LEGITIMATE INTERESTS Processing is necessary for the purposes of the legitimate interests pursued by the controller or by the third party or parties to whom the data are disclosed.

Networks ∙ Services ∙ People What do the important people say? Article29 Working Party: "The current text of Article 7(f) of the Directive is open ended. This flexible wording leaves much room for interpretation and has sometimes as experience has shown led to lack of predictability and lack of legal certainty. However, if used in the right context, and with the application of the right criteria, as set out in this Opinion, Article 7(f) has an essential role to play as a legal ground for legitimate data processing.” 7(f) = legitimate interests

Networks ∙ Services ∙ People What do the important people say? Article29 Working Party: "...an appropriate assessment of the balance under Article 7(f), often with an opportunity to opt-out of the processing, may in other cases be a valid alternative to inappropriate use of, for instance, the ground of 'consent' or 'necessity for the performance of a contract'. Considered in this way, Article 7(f) presents complementary safeguards - which require appropriate measures - compared to the other pre-determined grounds.” PERFORM A BALANCE TEST

Networks ∙ Services ∙ People SAFGUARDSTRANSPARENCY IMPACT MANAGEMENT LEGITIMATE REASONS BALANCE CASE BY CASE

Networks ∙ Services ∙ People 7-STEP PLAN Check that Legitimate Interests is the best approach. STEP ONE Qualify the legitimacy of the request – lawful, clearly articulated, real need. STEP TWO Determine whether the processing is necessary to achieve the goal. STEP THREE

Networks ∙ Services ∙ People 7-STEP PLAN Balance the data controller’s needs against the interests of the subjects. STEP FOUR Identity safeguards you can put in place (tech design etc). STEP FIVE Demonstrate (publish) compliancy. STEP SIX Allow the user to opt-out. STEP SEVEN

Networks ∙ Services ∙ People Where? Harmonisation

Networks ∙ Services ∙ People The “Academia” conversation - hopefully Leif will arrive. Paper on the value proposition for statistics and next steps proposal. Paper on how to make edugain technology neutral. Push for entity category adoption. Business case on assurance for IdPs. Metdata Registration Practice Statement for eduGAIN. (publication?) What will you see? 13

Networks ∙ Services ∙ People The eduGAIN context Growth & Maturity eduGAIN Members Joining eduGAIN Other federations

Networks ∙ Services ∙ People Trust and Identity Harmonisation Relationships Harmonisation Entity Categories Code of Conduct Federation Practices Assurance Business Case Interoperability REFEDS AARC Non Web eduGAIN Enabling Users

Networks ∙ Services ∙ People AARC & Enabling Users Requirements Specific Anchored in real use cases Training REFEDS Pre-existing design work Profiles Experiences Harmonisation Develop business case (P1) Costing Supply chain Pilot (P2) eduGAIN Incorporate (P2, P3) In depth – Assurance REFEDS/GÉANT/AARC working together Don’t reinvent wheels – do try to really use them

Networks ∙ Services ∙ People Advanced CAMP sessions. Security Incident and Assurance in FIM: Monday 11:20am. Moonshot: Tuesday 2:25pm. VAMPIRE (GÉANT VO): Tuesday 3pm. VO Platform as a Service: Tuesday 3.25pm. Lightning Talk on InAcademia: Tuesday 3pm. SA5 at TechX 17

Networks ∙ Services ∙ People Thank you Networks ∙ Services ∙ People This work is part of a project that has applied for funding from the European Union’s Horizon 2020 research and innovation programme under Grant Agreement No (GN4-1). 18 Questions?