Data Safety: Difference between revisions

2,291 bytes added ,  16 February 2012
Line 80: Line 80:
== Special Cases: Accelerated Data Safety Approval ==
== Special Cases: Accelerated Data Safety Approval ==


'''Experimental and Research Activities'''
Data Safety approval related to the following areas is dependent on the circumstances for each project. Approvals may require additional consideration and/or may be granted as an exception to the usual conditions in the following two areas.
'''Engagement and Marketing Activities'''
 
* Experimental and Research Activities
* Engagement and Marketing Activities
 
<b>Experimental and Research Activities</b>
 
For experimental research-related activities, teams can forgo approval if systems with access to user data run on the upcoming Petri system, and require opt-in by users. The following requirements must also apply:
* No sensitive personal data is collected or used
* There is a limited and defined data retention period
* Notice is sent to users prior to a full product release
* User data is not combined / cross-referenced / triangulated with other user data from other research or experimental systems
 
Project Petri is a 1-year experiment in providing an Infrastructure-as-a-Service offering to make it easy for Mozilla teams with new ideas for web apps to try them quickly, with minimal impact on IT/Ops, and with an on-ramp to making web apps that are better/safer/faster/more maintainable if the ideas they're testing prove to be useful. For more info, see https://wiki.mozilla.org/Petri
 
<b>Engagement and Marketing Activities</b>
 
Engagement-sponsored marketing activities, projects and campaigns that entail the collection, use and retention of personal data are held to the same privacy and data principles as our products and services. Mozilla's Engagement team has dedicated privacy professionals, Privacy Friends and legal contributors who review and support all of its activities in alignment with Mozilla's principles.
 
Day-to-day marketing tasks do not require a Data Safety Consultation, including data handling practices associated with our newsletters, online surveys, advertising, social media and contests. However, Engagement is required to bring an engagement or marketing activity in for a consultation under three circumstances:
 
# Proposed engagement activity connects to and/or utilizes user data from one of Mozilla's products, services or related features
# Proposed activity leads to the creation of a standalone product that generates new sources of user data
# Proposed campaign contemplates linking and/or utilizing user data from non-Mozilla, externally-created data sources


== Scheduling a Consultation ==
== Scheduling a Consultation ==
Confirmed users
152

edits