You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 19 Next »

Description of SWAMID Entity Category Release Check

SWAMID Entity Category Release Check is a suite of test services for system administrators of identity providers registered in SWAMID..

The test services determine if the identity provider follows SWAMID Best Current Practice for Entity Category Attribute Release.

The purpose of the test services are to evaluate which attributes are released by the identity provider depending on entity categories and requested attributes in the metadata of the respective test service.

SWAMID Entity Category Release Check contains the following test services:

  • SWAMID Entity Category Release Check - EC verification
  • SWAMID Entity Category Release Check - No EC
  • SWAMID Entity Category Release Check - REFEDS R and S
  • SWAMID Entity Category Release Check - GÉANT CoCo part 1
  • SWAMID Entity Category Release Check - GÉANT CoCo part 2
  • SWAMID Entity Category Release Check - GÉANT CoCo part 3

Processing of personal data

Transfer of personal data

Personal data are transferred from the identity provider (your login service) to the test services to ensure that the identity provider complies with the SWAMID Best Current Practice for Entity Category Attribute Release. When logging in to the respective test service, a unique subset of personal data is requested from the list below from the identity provider you are testing. Each test service stores the set of attributes that have been transferred from the identity provider to the service in order to be able to give a summarised result after the test suite has been completed. The attribute values, that contains personal data, are not stored.

When logging in to these test services, the following personal data are requested from the identity provider you use:

Personal dataPurposeTechnical representation
Unique identifiersTo verify that the attribute is released by the identity provider and to display the values to the user performing the tests

eduPersonPrincipalName
eduPersonTargetedID
eduPersonUniqueID

Personal Identity NumberTo verify that the attributes is released by the identity provider and to display the values to the user performing the testsnorEduPersonNIN
personalIdentityNumber
Researcher and contributor identifierTo verify that the attribute is released by the identity provider and to display the value to the user performing the testseduPersonOrcid
NameTo verify that the attributes is released by the identity provider and to display the values to the user performing the testscn
displayName
givenName
sn
E-mail addressTo verify that the attribute is released by the identity provider and to display the value to the user performing the testsmail
Date of birthTo verify that the attribute is released by the identity provider and to display the value to the user performing the testsschacDateOfBirth
Assurance levelTo verify that the attribute is released by the identity provider and to display the value to the user performing the testseduPersonAssurance
Organisational dataTo verify that the attributes is released by the identity provider and to display the values to the user performing the testseduPersonAffiliation
eduPersonScopedAffiliation

In addition to direct personal data, indirect personal data is also transferred, such as which organisation the user belongs to and which identity provider that has been used when logging in. In combination with the above personal data, these can be used to uniquely identify a person.

Other processing of personal data within the service

All test services store technical logs for debugging purposes and security related incidents. These technical logs contain information regarding all authentications made to the test services and the personal data transferred.

Transfer of personal data to third parties

No personal data is transferred to third parties.

Lawful basis

Personal data is processed on the basis of public interest. Personal data must be transferred in order for system administrators of identity providers to be+ able to verify that personal data is transferred in accordance with the recommendations of SWAMID.

Right of access, right of rectification and right of erasure of personal data

No personal data are stored in the service except in technical logs for debugging purposes and security related incidents.

For access and erasure of your personal data, contact the Personal data controller.

Purging of personal data

No personal data is stored in the service except in technical logs. The technical logs are automatically purged within a week.

Personal data controller

Personal data controller for the processing of personal data is The Swedish Research Council, Sweden. If you have questions about how personal data is used and handled within the service, please contact operations@swamid.se.

Contact information for The Swedish Research Council's data protection officer can be found at https://www.vr.se/behandling-av-personuppgifter.html.

GÉANT Data Protection Code of Conduct

This service complies with the international framework GÉANT Data Protection Code of Conduct (http://www.geant.net/uri/dataprotection-code-of-conduct/v1) for the transfer of personal data from identity providers to the service. This framework is intended for services in Sweden, the EU and the EEA that are used in research and higher education.




  • No labels