Privacy SIG WOLFCon Presentation

Privacy SIG WOLFCon Presentation

  • Introductions

    • AJ Henryson

    • Sharon Markus

    • Whitney Christopher

    • Amelia Sutton

  • Privacy SIG Background

    • The purpose of the Privacy SIG.

    • Privacy SIG Past and Present

    • We Want You

      • We want members, including European members who are familiar with GDPR

      • Can ask people to give us their organization privacy policies and ask them to share any of their local work being done and joining the SIG to implement those changes more widely.

      • Meeting cadence is currently once per month on Fridays at 11am.

  • State of privacy of FOLIO as a whole

  • Current Work

    • Whitney’s PPD form work.

    • AJ’s work with values that may require anonymization and other privacy topics.

    • Sharon will talk about her work with MetaDB and scripting related to privacy.

      • MetaDB Privacy SIG merger into the Privacy SIG.

      • MetaDB 1.4 to discuss what additional features are available in this version.

    • Amelia will share some of the local fixes being done at UMass

      • Reviewed our data retention policies which boil down to “once there isn’t a business need for the data, we should be anonymizing it”

      • Removing unneeded data from feed coming from IT

      • Bulk changes to records to remove unused sensitive info, primarily contact information

      • Bulk deleting expired users with no fees/fines, no requests, and fully anonymized loans.

        • Problem: No way to anonymize loans after a user has been deleted - loan anonymization endpoint only accepts user UUIDs, not loan UUIDs

        • Problem: “Actual Cost” fee/fine records cannot be anonymized.

    • Amelia can talk about their work with request anonymization.

      • At the 5C, anonymizing circulation data is our current priority for patron privacy

      • Especially critical for protecting the academic freedom of professors/students researching topics being heavily scrutinized by the current administration

      • Some staffing issues during development.

    • Local overrides to FOLIO privacy concerns.

    • Can we standardize these best practices across FOLIO in some way?

    • The important of the visibility of your privacy policies.