git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Is git compliant with GDPR?

From
Ddemerphq <demerphq@gmail.com>
Date
Jul 3, 2020, 06:22 UTC
Message-ID
<CANgJU+XM2Y-Dp5odRfSecqYeZQ+Ft0okvB6RNUs=hyAdJDJ-gw@mail.gmail.com>
In-Reply-To
<03df01d6508f$873cc320$95b64960$@nexbridge.com>
On Thu, 2 Jul 2020 at 18:42, Randall S. Becker <rsbecker@nexbridge.com> wrote:
> I am not speaking for the Git Foundation here, nor am I a lawyer; However, to use some practices from some of my customers who have this concern, the team members are directed to use tokenized names and email addresses that can be resolved by their security teams during an audit. Obviously the team members recognize the tokens so they know who is making what change. This means that externally, any names/emails that might get pushed upstream are non-identifying.

I think this is a really good point. I think git could make itself much more GDPR friendly by having some support for this type of idea built in.

Not sure how it could work, maybe some kind of object that can be deleted after the fact which maps an identifier used for the author with name and email. If that name and email change the object can be updated, and if there is a need to "forget" the author, the object can be deleted. The object would not be shared on clone, so it would stay private to the repo that held it.

I guess you can argue that this isnt git's problem. But at a corporate level, it will be seen as git's fault regardless if it cause a big disruption. It could/would also be a reason that european companies might decide not to use git.

cheers, Yves

-- 
perl -Mre=debug -e "/just|another|perl|hacker/"
Previous: Randall S. BeckerNext: Randall S. Becker
Message 4 of 10 in “Is git compliant with GDPR?”
  1. Jakub TrzebiatowskiJul 2, 2020
  2. Jason PyeronJul 2, 2020
  3. Randall S. BeckerJul 2, 2020
  4. demerphqJul 3, 2020
  5. Randall S. BeckerJul 3, 2020
  6. Jakub TrzebiatowskiJul 2, 2020
  7. Jason PyeronJul 2, 2020
  8. Paul SmithJul 2, 2020
  9. Jason PyeronJul 2, 2020
  10. demerphqJul 3, 2020

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.