Identity Provider Direzione Consortium GARR
Service Name | Identity Provider Direzione Consortium GARR |
Service Description | Federated Authentication Service Direzione Consortium GARR for GARR staff only. |
Data Processor Entitled Referee |
Consortium GARR - Via dei Tizii, 6 - 00185 ROMA, IT
Consortium GARR is entitled for user's personal data processing provided by the service, according to art.24 of GDPR 2016/679, and entitled to protect user's personal data privacy and for the communication of the informations related to articles 13 and 14 of GDPR 2016/679 . |
Data Processing Entitled Manager (GDPR 2016/679 Art. 4) |
Consortium GARR Director, Dr. Federico Ruggieri Contacts: info@garr.it |
Data Protection Entitled Manager (GDPR Sez.4 Art. 37) | Not applicabile |
Jurisdiction and control authority |
IT-IT According to art. 79 GDPR 2016/679 user who suspect his/her rights have been violated due to personal data processing can write to italian general data protection authority: Italian Personal Data Protection Authority: Garante per la Protezione dei Dati Personali How to file a complaint with the data protection authority: http://www.garanteprivacy.it/home/diritti/come-agire-per-tutelare-i-nostri-dati-personali |
Processed Personal Data and Law references basis for the processing |
Consortium GARR ensure user's personal data processing is fully compliant to GDPR 2016/679. |
personal data processing policy usage |
User personal data collected (during service registration and service use) are necessary to authenticate him/her, granting access to network services he/she requested. Due to SAML-federated authentication protocol proper nature, user's credentials (username/password) are never sent to 3rd party (both Resource Providers or others Identity Providers). However end user's attributes identitying him/her,accordingly to SAML protocol, could be sent to Resource Providers, with user's explicit consent, to grant him/her access to the resource he/she requested. Subscribing this service end user give his/her consent to Consortium GARR to treat his/her data according to EU GDPR 2016/679 and further modifications. Service logs, containing user's personal data, are collected only to verify service right availability, operation and security according to italian laws. According to GDPR 2016/679 art.2 section d and art.23, in case of user account violation/compromission user will be notified of it and, if requested by police control authorities, logs could be be given to them for further investigations. |
3rd parties data transfer |
Consortium GARR Direzione Identity Provider Direzione sends user's attributes to Resource Providers he/she wants to access to following principle of minimization. User's personal data are transferred only when user requests access to the 3rd party Resource Provider and only to access to that 3rd party service. Such resources are:
Third parties outside EAA:
|
How to access to, correct, delete personal data and oppose to their processing. |
Contact the above mentioned Data Processors. |
How to revoke user consent |
The only collected data with user consent are preferences about the transmission of attributes to third parties. Data are gathered online at the time of first access to resources, and can be deleted, with the outcome of eliminating consent to their transmission, starting over the login procedure and checking the "Clear prior granting of permission for release of your information to this service" box. |
Data portability |
User can request to data processor his/her data portability related to digital identities, including credentials and consent information. These will be provided according to Art. 20 of GDPR 2016/679 . If requested to data processor, data portability will be provided free of charge at the end of service. |
>Data Processing Timelife |
User's personal data are kept for the whole duration of the user's service request access. Service logs are stored according to italian privacy and security laws for 6 months, and if necessary and requested by police for crime investigations related to user's service usage for further 6 months. At the end of such period (6 months if not requested by security public authorities for cime investigatin) service logs are permanently deleted. |