Crowd Privacy Policy

Description of Sunet Crowd Identity Management

The Crowd Identity Management service handles login in Sunets Wiki, Jira and Jira Service Desk for users who need to access login-protected information in these services. You should only log in if you work at Sunet or collaborate with Sunet and have been asked to log in.

Processing of personal data

Transfer of personal data

When logging in, personal information is transferred from the identity provider you have logged in with to Sunet's identity management service Crowd to give you as a user access to login-protected information in Sunet's services Wiki, Jira and Jira Service Desk. At tme of login, a number of personal data is requested to identify you as a user and give you access to service.

When logging in, the following personal data are requested from the identity provider you use:

Personal dataPurposeTechnical representation
Unique identifierIdentify you as a user of the service so that you have access according to the rights you have been granted.

eduPersonPrincipalName

ForenameIdentify yourself to other users in the services.givenName
SurnameIdentify yourself to other users in the services.givenName
E-mail addressTo verify that the attribute is released by the identity provider and to display the value to the user performing the testsmail

In addition to direct personal data, indirect personal data are also transferred, such as which organisation the user belongs to and which identity provider that has been used when logging in. This information is not used by the login service more than for technical logs.

Other processing of personal data within the service

The identity management service saves technical logs for troubleshooting and security related incidents. These technical logs contain information about all logins made incl. transferred personal data.

Sunets Wiki saves who has created, updated and deleted wiki pages. Sunets Jira and Jira Service Desk save who has worked on a particular case via an event log per case.

Transfer of personal data to third parties

No personal data are transferred to third parties.

Lawful basis

Personal data is handled based on the lawful basis of public interest. The personal data must be transferred to give users access to login-protected information needed for their work at Sunet or in collaboration with Sunet.

Right of access, right of rectification and right of erasure of personal data

Personal data saved in the identity management service is automatically corrected based on the personal data transferred from your identity issuer in connection with the login.

To delete your personal information in the identity management service, contact SUNET NOC.

For access your personal data, contact the Personal data controller.

Purging of personal data

Personal data is manually purged when it is no longer used by the identity management service or connected services.

Personal data controller

Personal data controller for the processing of personal data is The Swedish Research Council, Sweden. If you have questions about how personal data are processed within the service, please contact SUNET NOC.

Contact information for The Swedish Research Council's data protection officer can be found at https://www.vr.se/behandling-av-personuppgifter.html.

GÉANT Data Protection Code of Conduct

This service complies with the international framework GÉANT Data Protection Code of Conduct (http://www.geant.net/uri/dataprotection-code-of-conduct/v1) for the transfer of personal data from identity providers to the service. This framework is intended for services in Sweden, the EU and the EEA that are used in research and higher education.




  • No labels