NDA: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
 
(4 intermediate revisions by 3 users not shown)
Line 3: Line 3:
==== What is a Confidentiality Agreement: ====
==== What is a Confidentiality Agreement: ====


A Confidentiality Agreement (or NDA) is a legal agreement between volunteers and Mozilla that will allow us to share confidential information with contributors that we don’t, or aren’t yet ready to share with the general public. For example, NDA’d Mozillians have access to the videos on Air Mozilla, which are closed to the public because they contain confidential information.  
A Confidentiality Agreement (or NDA) is a legal agreement between volunteers and Mozilla that will allow us to share confidential information with contributors that we don’t, or aren’t yet ready to share with the general public. For example, NDA’d Mozillians have access to the videos on Air Mozilla, which are closed to the public because they contain confidential information.


In order for the NDA group to grow and succeed it requires everyone who enters it to make a commitment to share the trust conferred by admission into this group.  
In order for the NDA group to grow and succeed, it requires everyone who enters it to make a commitment to share the trust conferred by admission into this group.


'''You can view the full text of the NDA [https://drive.google.com/file/d/0B-IbEs3PKNPKVzlqWGQ0bWRkcTQ/view?usp=sharing here].'''
'''You can view the full text of the NDA [https://drive.google.com/file/d/1xAMu3CYiWpzYLbQW8_9qrFQbcvbH1by0/view?usp=sharing].'''
 
Contributors can also request that information shared with you under the NDA be made public through this form [http://mzl.la/reclassify mzl.la/reclassify].


NOTE: This NDA process is exclusively for volunteer Mozillians. To NDA a contractor, vendor, intern, or anyone else Mozilla has a business relationship with, please file [http://sso.mozilla.com/casa a casa ticket].
NOTE: This NDA process is exclusively for volunteer Mozillians. To NDA a contractor, vendor, intern, or anyone else Mozilla has a business relationship with, please file [http://sso.mozilla.com/casa a casa ticket].
Line 19: Line 17:


You will:
You will:
* a) only share the Confidential Information if the person disclosing the information tells you
 
* that it can be shared,
* a) only share the Confidential Information if the person disclosing the information tells you that it can be shared,
* b) only share the Confidential Information with the specific group or individuals Mozilla
* b) only share the Confidential Information with the specific group or individuals Mozilla authorizes you to share with; and
* authorizes you to share with; and
* c) use appropriate judgment and access restrictions to prevent unauthorized disclosure.
* c) use appropriate judgment and access restrictions to prevent unauthorized disclosure.


Line 29: Line 26:
==== What do I need to get an NDA? ====
==== What do I need to get an NDA? ====


In addition to a staff member who can vouch for your contributions and ability to maintain the parameters of the NDA (the details of which are blow) you will need to have the following:  
In addition to a staff member who can vouch for your contributions and ability to maintain the parameters of the NDA (the details of which are below) you will need to have the following:  


* A [https://mozillians.org/en-US/ Mozillians.org profile]
* A profile on [https://people.mozilla.org/ people.mozilla.org] platform
* Setup [[IAM/Frequently_asked_questions#Q:_How_can_I_set_up_two-factor_authentication_.282FA.29_for_my_github_account.2C_using_an_app_on_my_phone_.28Android.2FiOS.2FBlackberry.29.3F|multifactor authentication]] on their profile


==== How long does an NDA last: ====
==== How long does an NDA last: ====  


NDA’s expire after one year, in order to make sure that those on the list are regularly active. One year from the acceptance date, inviters will have the opportunity to re-invite volunteers to the NDA group. You can request to leave the NDA group at any time. Please note that your obligations continue for as long as the information remains confidential, even if the NDA ends. Only when the information is publicly announced or made publicly available by Mozilla (or
NDA’s expire after one year, in order to make sure that those on the list are regularly active. One year from the acceptance date, inviters will have the opportunity to re-invite volunteers to the NDA group. You can request to leave the NDA group at any time. Please note that your obligations continue for as long as the information remains confidential, even if the NDA ends. Only when the information is publicly announced or made publicly available by Mozilla (or its partner) is the information no longer considered Confidential Information. If you’re unsure, ask the persons who provided you with the Confidential Information or email Mozilla’s Legal Team.
its partner) is the information no longer considered Confidential Information. If you’re unsure, ask the persons who provided you with the Confidential Information or email Mozilla’s Legal Team.


==== What happens once I get my invitation: ====  
==== What happens once I get my invitation: ====  
Your invitation will arrive to the email associated with your Mozillians profile. Once you receive your invitation, please read and think carefully about the NDA before you agree to its terms and if you have any questions please do not hesitate to reach out to your inviter!
Your invitation will arrive to the email associated with your People.mozilla.org profile. Once you receive your invitation, please read and think carefully about the NDA before you agree to its terms and if you have any questions please do not hesitate to reach out to your inviter!
 
'''Note that you will need to have [[IAM/Frequently_asked_questions#Q:_How_can_I_set_up_two-factor_authentication_.282FA.29_for_my_github_account.2C_using_an_app_on_my_phone_.28Android.2FiOS.2FBlackberry.29.3F|Multi-Factor Authentication]] set-up on your Mozillians profile in order to receive your NDA invitation. Instructions for how to set it up can be found [[IAM/Frequently_asked_questions#Q:_How_can_I_set_up_two-factor_authentication_.282FA.29_for_my_github_account.2C_using_an_app_on_my_phone_.28Android.2FiOS.2FBlackberry.29.3F|Multi-Factor Authentication|here]].'''


Once you have received and accepted the terms of the NDA you will:  
Once you have received and accepted the terms of the NDA you will:
* Automatically be added to the NDA Group on Mozillians
* Automatically be added to the NDA Group on People.mozilla.org
* You will have access to the [https://discourse.mozilla-community.org/c/mozillians/nda NDA-restricted discourse category], a safe space for internal conversations (staff and nda volunteers).
* You will be added to the nda@mozilla.com mail group that will allow you to receive internal confidential emails with updates pertaining to Mozilla.
* You will also automatically have access to view NDA-restricted [https://air.mozilla.org/ Air Mozilla] and you will be able to access the #moco channel on IRC from the Air Mozilla page.
* You will also automatically have access to view NDA-restricted [https://air.mozilla.org/ Air Mozilla] and you will be able to access the #moco channel on IRC from the Air Mozilla page.
* You will receive internal confidential emails with updates pertaining to Mozilla.
* You may also have additional confidential information shared with you personally, so please be aware or check with the disclosure before you re-share any information.
* You may also have additional confidential information shared with you personally, so please be aware or check with the disclosure before you re-share any information.
* You may now be invited to additional access groups such as Slack, based on the tools you need to contribute effectively.
* You may now be invited to additional access groups such as Slack, based on the tools you need to contribute effectively.


==== Leaving the NDA group: ====  
==== Leaving the NDA group: ====  
If you would like to stop receiving confidential information at any time, or can no longer contribute your time as a volunteer, before the end of your one year period you can ask your inviter to remove you from the group or email legal-notices@mozilla.com to end your NDA. Inviters can also remove contributors from the NDA group at any time if that contributor is no longer actively contributing to Mozilla, or if there is a violation of trust or the [https://www.mozilla.org/en-US/about/governance/policies/participation/ Community Participation Guidelines].
If you would like to stop receiving confidential information at any time, or can no longer contribute your time as a volunteer, before the end of your one-year period you can ask your inviter to remove you from the group or email legal-notices@mozilla.com to end your NDA. Inviters can also remove contributors from the NDA group at any time if that contributor is no longer actively contributing to Mozilla, or if there is a violation of trust or the [https://www.mozilla.org/en-US/about/governance/policies/participation/ Community Participation Guidelines].


== Who Can Get an NDA ==  
== Who Can Get an NDA ==  


They are distributed by invitation to volunteer individuals who are deeply involved with Mozilla and are trusted by the administrators of a Mozilla Community. Reps, L10N, Security and SUMO each have their own procedure for assessing activity and distributing NDA’s (vendors, contractors, and anyone else Mozilla has a business relationship with should file a [https://sso.mozilla.com/casa a CASA ticket] instead). Staff can also nominate contributors to receive an NDA if they believe that a contributor who is actively contributing to Mozilla, they know or have worked with, whose capacity to contribute would be improved by receiving information or having access to Mozilla tools that are not public, and whose capacity to keep the parameters of the NDA are not in doubt.
They are distributed by invitation to volunteer individuals who are deeply involved with Mozilla and are trusted by the administrators of a Mozilla Community. Different communities (SUMO, L10N, MDN, Mozfest and Security) have their own procedure for assessing activity and distributing NDAs. If you belong to any of those communities, contact your community manager to get more info on the process. Staff can also nominate contributors to receive an NDA if they believe that a contributor who is actively contributing to Mozilla, they know or have worked with, whose capacity to contribute would be improved by receiving information or having access to Mozilla tools that are not public, and whose capacity to keep the parameters of the NDA are not in doubt.
 
Here is the information for each of these groups.
 
===== Reps =====
All active Reps are under NDA and receive invitations as part of entry into the program. [https://mozillians.org/en-US/u/nukeador/ Reps Staff] access activity each year for the purposes of renewal. You can read more about how to become a Rep [https://reps.mozilla.org/ here].
 
===== SUMO =====
[https://support.mozilla.org/en-US/kb/meet-team/ SUMO admins] determine activity and send invitations to active SUMO members. You can [https://support.mozilla.org/en-US/get-involved read more about how to become a member of SUMO here]. The Mozilla Support Community requires an NDA for product updates and support related communications and participation in the Social Support program that answers brand questions. Check out how to get involved at https://support.mozilla.com and Support. If you have participated for a while or would benefit from a more involved please send a request for an NDA with this form: bit.ly/2Ihl1Rh
 
===== L10N =====
You can read more about how to get involved with localization (L10N) [https://wiki.mozilla.org/L10n:Contribute in this page]. If you're an active localizer and want to know more about NDA, please get in touch directly with [https://wiki.mozilla.org/L10n:Mozilla_Team l10n drivers].
 
===== Tech Speakers =====
All active Mozilla Tech Speakers are invited to sign Mozilla’s NDA (Non-Disclosure Agreement). This will give you access to timely information about future product plans, releases, organizational announcements, and confidential Mozilla meetings. You can learn more about the Tech Speakers program [https://wiki.mozilla.org/TechSpeakers/ here].
 
===== Security Contributors =====
Non-Staff working as part of the Bugzilla Security Group will be invited to join the NDA group.
 
===== Research Contributors =====
Non-Staff contributing to Research organization projects such as Rust, Servo, WebVR/WebAR, Daala, and Deep Speech may contact larsberg.
 
===== Add-ons Contributors =====
There are many ways to [[Add-ons/Contribute|contribute]] to Mozilla's [[Add-ons|add-ons projects]]. If you are an active contributor and want to learn more about NDA, please contact [https://mozillians.org/en-US/u/caitmuenster Caitlin Neiman].
 
===== Mozilla Community Web Services =====
Active MCWS volunteers will be invited to sign Mozilla’s NDA in order to provision and administer some of the Mozilla-hosted web services open to our communities.
 
===== All Hands Contributors =====
Volunteers invited by a staff member to attend an All Hands will be invited to sign an NDA. An NDA will be required to participate in some parts of the All Hands. Invitations will be sent shortly before the event, and volunteers will be removed from the NDA group after the All Hands if they are not also covered by one of the long-term contribution areas (above).  


--
--
Line 95: Line 58:
Staff should only NDA people who: "Are actively contributing to Mozilla, who you know or have worked with in the past, whose capacity to contribute would be improved by receiving information or having access to Mozilla tools that are not public, and whose capacity to keep the parameters of the NDA you do not doubt.  
Staff should only NDA people who: "Are actively contributing to Mozilla, who you know or have worked with in the past, whose capacity to contribute would be improved by receiving information or having access to Mozilla tools that are not public, and whose capacity to keep the parameters of the NDA you do not doubt.  


 
Please note that contributors must have a people.mozilla.org account to be added to the NDA Group. Former staff will require an additional screening by the people partner team before an NDA will be granted.  
Please note that contributors must have a Mozillians.org account and multi-factor authentication to be added to the NDA Group. Former staff will require an additional screening by the people partner team before an NDA will be granted.  


Staff: Please note that you will accountable for your invitee and you will have to renew their NDA at the end of one year. In order to accommodate for changes in position or employment you must also list a “back-up” inviter who will assume responsibility for your contributors should you leave the organization.
Staff: Please note that you will accountable for your invitee and you will have to renew their NDA at the end of one year. In order to accommodate for changes in position or employment you must also list a “back-up” inviter who will assume responsibility for your contributors should you leave the organization.

Latest revision as of 15:43, 10 April 2025

Confidentiality Agreement FAQ

What is a Confidentiality Agreement:

A Confidentiality Agreement (or NDA) is a legal agreement between volunteers and Mozilla that will allow us to share confidential information with contributors that we don’t, or aren’t yet ready to share with the general public. For example, NDA’d Mozillians have access to the videos on Air Mozilla, which are closed to the public because they contain confidential information.

In order for the NDA group to grow and succeed, it requires everyone who enters it to make a commitment to share the trust conferred by admission into this group.

You can view the full text of the NDA [1].

NOTE: This NDA process is exclusively for volunteer Mozillians. To NDA a contractor, vendor, intern, or anyone else Mozilla has a business relationship with, please file a casa ticket.

What are your obligations under the NDA

  • You will only use Confidential Information to perform your Activities on behalf of Mozilla.
  • You will not publicly disclose or share the Confidential Information with any other persons, except with other Mozilla employees or other volunteers under an NDA with Mozilla as noted below.

You will:

  • a) only share the Confidential Information if the person disclosing the information tells you that it can be shared,
  • b) only share the Confidential Information with the specific group or individuals Mozilla authorizes you to share with; and
  • c) use appropriate judgment and access restrictions to prevent unauthorized disclosure.

By signing an NDA, in addition to agreeing to comply with the terms of the NDA (above) you are agreeing to respect and adhere to Mozilla’s Community Participation Guidelines (“CPG”). Violation of these guidelines can result in you being removed from the NDA group, either temporarily or in perpetuity.

What do I need to get an NDA?

In addition to a staff member who can vouch for your contributions and ability to maintain the parameters of the NDA (the details of which are below) you will need to have the following:

How long does an NDA last:

NDA’s expire after one year, in order to make sure that those on the list are regularly active. One year from the acceptance date, inviters will have the opportunity to re-invite volunteers to the NDA group. You can request to leave the NDA group at any time. Please note that your obligations continue for as long as the information remains confidential, even if the NDA ends. Only when the information is publicly announced or made publicly available by Mozilla (or its partner) is the information no longer considered Confidential Information. If you’re unsure, ask the persons who provided you with the Confidential Information or email Mozilla’s Legal Team.

What happens once I get my invitation:

Your invitation will arrive to the email associated with your People.mozilla.org profile. Once you receive your invitation, please read and think carefully about the NDA before you agree to its terms and if you have any questions please do not hesitate to reach out to your inviter!

Once you have received and accepted the terms of the NDA you will:

  • Automatically be added to the NDA Group on People.mozilla.org
  • You will be added to the nda@mozilla.com mail group that will allow you to receive internal confidential emails with updates pertaining to Mozilla.
  • You will also automatically have access to view NDA-restricted Air Mozilla and you will be able to access the #moco channel on IRC from the Air Mozilla page.
  • You may also have additional confidential information shared with you personally, so please be aware or check with the disclosure before you re-share any information.
  • You may now be invited to additional access groups such as Slack, based on the tools you need to contribute effectively.

Leaving the NDA group:

If you would like to stop receiving confidential information at any time, or can no longer contribute your time as a volunteer, before the end of your one-year period you can ask your inviter to remove you from the group or email legal-notices@mozilla.com to end your NDA. Inviters can also remove contributors from the NDA group at any time if that contributor is no longer actively contributing to Mozilla, or if there is a violation of trust or the Community Participation Guidelines.

Who Can Get an NDA

They are distributed by invitation to volunteer individuals who are deeply involved with Mozilla and are trusted by the administrators of a Mozilla Community. Different communities (SUMO, L10N, MDN, Mozfest and Security) have their own procedure for assessing activity and distributing NDAs. If you belong to any of those communities, contact your community manager to get more info on the process. Staff can also nominate contributors to receive an NDA if they believe that a contributor who is actively contributing to Mozilla, they know or have worked with, whose capacity to contribute would be improved by receiving information or having access to Mozilla tools that are not public, and whose capacity to keep the parameters of the NDA are not in doubt.

--

Staff Vouching

In order to receive an NDA, if you are not in any of these groups, you must be invited by a staff member. Staff members can vouch for contributors using this form.

Staff should only NDA people who: "Are actively contributing to Mozilla, who you know or have worked with in the past, whose capacity to contribute would be improved by receiving information or having access to Mozilla tools that are not public, and whose capacity to keep the parameters of the NDA you do not doubt.

Please note that contributors must have a people.mozilla.org account to be added to the NDA Group. Former staff will require an additional screening by the people partner team before an NDA will be granted.

Staff: Please note that you will accountable for your invitee and you will have to renew their NDA at the end of one year. In order to accommodate for changes in position or employment you must also list a “back-up” inviter who will assume responsibility for your contributors should you leave the organization.