Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • The European level authentication proxy infrastructure,
  • The eduroam database, 
  • The eduroam Configuration Assistant Tool (CAT),
  • The eduroam Managed IdP Service,
  • The eduroam F-ticks traffic measurement – a portal with technical information about the service,
  • monitor.eduroam.org,
  • The eduroam wiki and
  • The eduroam website.

eduroam was designed for minimal disclosure of end users personal data following the requirement that user must be authenticated by his/hers her IdP. The design of the system provides and favours the end user anonymization, i.e., the possibility to hide the end user’s identity from any third parties, including providers of eduroam network access (SPs). eduroam technical foundations have a built-in support for end user privacy throughout the authentication process. For all intermediate services, like routing of authentication requests and F-ticks (log format for distributed federations), the service is designed to know *nothing* about the actual identity of an end user, while still maintaining log traces which allow for resolving security incidents, debugging, monitoring and usage statistics.

...

  • When you roam and visit other countries, or as a user of the eduroam Managed IdP service, the European proxy servers will receive and log the following data: your realm (denoting your institution and federation) and MAC addresses. We can also receive your username if  you have not chosen to anonymise this data (eduroam Managed IdP always uses opaque usernames). When you roam to another institution within your home country we the European proxy servers don’t receive any data because the European proxy servers they are not included in that process.  The service has a legitimate interest in processing this information.
  • When you roam and visit other countries or other institutions within your federation we may also process for monitoring, measuring and reporting services, in addition to the data mentioned above, the data about visited country, visited institution and authentication outcome. The service has a legitimate interest in processing this information.
  • As part of supporting activities we maintain several public web sites (e.g. web of CAT service) where  we collect normal web server logs, i.e. timestamp of access, IP address which requested the page, the page being requested, the HTML result code, etc. The data collected is for the purpose of troubleshooting and debugging potential problems of with eduroam web servers and therefore the service has a legitimate interest in processing this information.
  • The eduroam Operational Team maintains a database where we collect data related to NROs, IdPS and SPs to enable supporting services and improve incident response and user support. The data is provided by the NROs based on the eduroam Policy.
  • To ensure proper functioning of the eduroam Configuration Assistant Tool (CAT) we and of the eduroam Managed IdP service we collect the identifers and e-mail addresses of the NRO and IdP admins responsible for the configurations that will be used be the end users. The service has a legitimate interest in processing this information.
  • The eduroam Managed IdP system also stores pseudonyms of end users (as instructed by the IdP administator) and the second-level pseudonyms of the actual access credentials as derived from those original pseudonyms.

Who Do We Share Data With?

...

You also have the right to ask what personal data we hold about you, and to complain to the Supervisory Authority (Autoriteit Persoonsgegevens at https://autoriteitpersoonsgegevens.nl) about our data processing activities if you feel your data is not being managed as described here.

Contact Information

Data Controller and ContactData Protection Officer

GÉANT Association
Hoekenrode 3
1102 BR
Amsterdam – Zuidoost
Netherlands
Telephone number: +31 20 530 4488
email: gdpr@geant.org

JurisdictionNetherlands

Dutch Data Protection Authority
Autoriteit Persoonsgegevens
Postbus 93374 2509 AJ DEN HAAG.
Telephone number: (+31) – (0)70 – 888 85 00.