<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div>
<div>Nicely written set of thoughts. We are looking at this. I have been meaning to get with Susan Blair in UF privacy. We have some current policy and practice to cover this area of risk. In our case I want to be sure turning on consent does not weaken
or cause a risk not intended by the tactical changes in the consent page. The policy, practice and tool must complement each other for a solution that manages risks well and defensibly.</div>
<div><br>
</div>
<div>I will pursue this soon and see what IAM and privacy legal can come up with.</div>
<div><br>
</div>
<div>+1 on this topic. </div>
<div><br>
</div>
<div>Warren</div>
<div><br>
</div>
<div><font style="color:#333333"><i>Sent from my Verizon Wireless 4G LTE DROID</i></font></div>
</div>
<div class="elided-text">On Dec 2, 2015 3:05 PM, Steven Carmody <steven_carmody@brown.edu> wrote:<br type="attribution">
<blockquote class="quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div><font size="2"><span style="font-size:10pt"></span></font>
<div>Hi,<br>
<br>
I see that sites (including mine) are starting to experiment with User <br>
Consent to Attribute release -- I'd be interested in hearing what people <br>
are thinking about how to approach the question of when to present the <br>
browser user with the Consent screens... some thoughts and examples ..<br>
<br>
-- always present the Consent screen to every student who has opt'ed out <br>
under FERPA. This rule overrides all of the others.<br>
<br>
-- we have contracts with a number of commercial SPs (eg Canvas, the LMS <br>
people; Workday; etc). We want to suppress consent in these cases. Do we <br>
add each one to a blacklist ? Or does it make better sense to TAG them <br>
in some way, and use the TAG value to suppress ?<br>
<br>
-- R&S. Always release the standard R&S bundle to R&S SPs ? Or always <br>
present the Consent screens, and let individuals decide what to release?<br>
<br>
-- should we TAG ALL (or most) of the local SPs, and release all the <br>
required attributes, and bypass Consent ? "we trust ourselves".<br>
<br>
-- are there other well known and easily identifiable Categories of <br>
sites that we should try to implement ?<br>
<br>
-- should we provide users with an out-of-band management console where <br>
they could specify some "global rules" to control how Consent works for <br>
them ? (eg Always/Never ask for my Consent, and presumably some <br>
in-between possibilities.) Presumably this would also include a <br>
mechanism to revoke Consent.<br>
<br>
Thanks for your thoughts !<br>
<br>
<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</div>
</blockquote>
</div>
</body>
</html>