eduGAIN Attribute Release Check is a suite of test services for system administrators of identity providers registered in the eduGAIN Participant Federations.
The test services determine if an identity provider releases attributes according to the relevant Entity Category defined by REFEDS.
The purpose of the test services are to evaluate which attributes are released by the identity provider depending on entity categories and requested attributes in the metadata of the respective test service.
The eduGAIN Rellease Check contains the following test services:
Personal data are transferred from the identity provider (your login service) to the test services to ensure that the identity provider complies with the relevant Entity Category defined by REFEDS. When logging in to the respective test service, a unique subset of personal data are requested from the list below from the identity provider you are testing. Each test service stores the set of attributes that have been transferred from the identity provider to the service in order to be able to give a summarised result after the test suite has been completed. The attribute values, that contains personal data, are not stored.
When logging in to these test services, the following personal data are requested from the identity provider you use:
| Unique identifiers | To verify that the attributes are released by the identity provider and to display the values to the user performing the tests. Please note that SAML NameIDs might be transmitted by the Identity Provider, but they are not requested and they will not be processed nor stored. | subject-id |
| Researcher and contributor identifier | To verify that the attribute is released by the identity provider and to display the value to the user performing the tests | eduPersonOrcid |
| Name | To verify that the attributes are released by the identity provider and to display the values to the user performing the tests | cn displayName givenName sn |
| E-mail address | To verify that the attribute is released by the identity provider and to display the value to the user performing the tests | mailLocalAddress |
| Affiliation | To verify that the attribute is released by the identity provider and to display the value to the user performing the tests | eduPersonAffiliation eduPersonScopedAffiliation |
| Assurance level | To verify that the attribute is released by the identity provider and to display the value to the user performing the tests | eduPersonAssurance |
| Organisational data | To verify that the attributes are released by the identity provider and to display the values to the user performing the tests | schacHomeOrganization |
In addition to direct personal data, indirect personal data are also transferred, such as which organisation the user belongs to and which identity provider that has been used when logging in. In combination with the above personal data, these can be used to uniquely identify a person.
All test services store technical logs for debugging purposes and security related incidents. These technical logs contain information regarding all authentications made to the test services and the personal data transferred.
No personal data are transferred to third parties.
Personal data are processed on the basis of public interest. Personal data must be transferred in order for system administrators of identity providers to be+ able to verify that personal data is transferred in accordance with the recommendations of relevant REFEDS's Entity Categories.
No personal data are stored in the service except in technical logs for debugging purposes and security related incidents.
For access and erasure of your personal data, contact the Personal data controller.
No personal data are stored in the service except in technical logs. The technical logs are automatically purged within a week.
Personal data controller for the processing of personal data is the GÉANT Association, Hoekenrode 3 1102 BR Amsterdam – Zuidoost Netherlands, Telephone number: +31 20 530 4488, email: gdpr@geant.org.
This service complies with the international framework REFEDS Data Protection Code of Conduct (https://refeds.org/category/code-of-conduct) for the transfer of personal data from identity providers to the service. This framework is intended for services in Sweden, the EU and the EEA that are used in research and higher education.