Privacy laws

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
10 messages Options
Reply | Threaded
Open this post in threaded view
|

Privacy laws

harry mead
Hi everyone,

Does anyone know the privacy laws (im based in the UK) regarding the personal information that is handled and stored on apache ofbiz, and if so the best way to go about it.

Thanks in advance

Sent from my iPhone
Reply | Threaded
Open this post in threaded view
|

Re: Privacy laws

Pierre Smits
Hi Harry,

As far as I can tell, we don't have any information on hand regarding the
applicable laws that are applied to personal information stored in OFBiz.

Are you questioning this in relation to GDPR compliance?

Best regards,

Pierre Smits

ORRTIZ.COM <http://www.orrtiz.com>
OFBiz based solutions & services

OEM - The OFBiz Extensions Marketplace1
http://oem.ofbizci.net/oci-2/
1 not affiliated to (and not endorsed by) the OFBiz project

On Mon, Nov 20, 2017 at 1:22 PM, harry mead <[hidden email]>
wrote:

> Hi everyone,
>
> Does anyone know the privacy laws (im based in the UK) regarding the
> personal information that is handled and stored on apache ofbiz, and if so
> the best way to go about it.
>
> Thanks in advance
>
> Sent from my iPhone
Reply | Threaded
Open this post in threaded view
|

Re: Privacy laws

Heidi Dehaes - Olagos
In reply to this post by harry mead
Hi Harry, Pierre,

About privacy laws, it depends if the data in ofbiz is stored on a hosting
server in Europe or in the United States for example. If the data is stored
in Europe, the privacy law of Europe is there.

Eric

Olagos bvba
Heidi Dehaes
Kerkstraat 34
2570 Duffel
Belgium
Tel. :     015/31 53 04
GSM :    0485/22 35 80
E-mail : [hidden email]
http://www.olagos.eu
http://www.olagos.com
http://www.olagos.be
http://www.olagos.nl



2017-11-20 13:22 GMT+01:00 harry mead <[hidden email]>:

> Hi everyone,
>
> Does anyone know the privacy laws (im based in the UK) regarding the
> personal information that is handled and stored on apache ofbiz, and if so
> the best way to go about it.
>
> Thanks in advance
>
> Sent from my iPhone
Reply | Threaded
Open this post in threaded view
|

Re: Privacy laws

Heidi Dehaes - Olagos
In reply to this post by harry mead
Hello Harry,

It is for Europe Regulation 45/2001 until now or from anywhere in 2018 it
is GDPR law (search in Google).

As long as you stay in the European Union :-)

Eric

Olagos bvba
Heidi Dehaes
Kerkstraat 34
2570 Duffel
Belgium
Tel. :     015/31 53 04
GSM :    0485/22 35 80
E-mail : [hidden email]
http://www.olagos.eu
http://www.olagos.com
http://www.olagos.be
http://www.olagos.nl



2017-11-20 13:22 GMT+01:00 harry mead <[hidden email]>:

> Hi everyone,
>
> Does anyone know the privacy laws (im based in the UK) regarding the
> personal information that is handled and stored on apache ofbiz, and if so
> the best way to go about it.
>
> Thanks in advance
>
> Sent from my iPhone
Reply | Threaded
Open this post in threaded view
|

Re: Privacy laws

Pierre Smits
In reply to this post by Heidi Dehaes - Olagos
Hey Eric,

Long time no see... ;)

Yes, the law of the country of residence of the datacenter of the service
provider may be applicable too.

As for 'European Law' that all depends on the moment of ratification of
that law by the member state. The GDPR regulation seems to be ratified by
all, but the UK may (given their plan to BREXIT) have something else in
mind.

The GDPR (General Data Protection Regulation) is to come in effect on May
25th, 2018. And companies must be ready by then (regardless of systems
used), or they may be subject to hefty fines.

Best regards,

Pierre Smits

ORRTIZ.COM <http://www.orrtiz.com>
OFBiz based solutions & services

OEM - The OFBiz Extensions Marketplace1
http://oem.ofbizci.net/oci-2/
1 not affiliated to (and not endorsed by) the OFBiz project

On Mon, Nov 20, 2017 at 2:00 PM, Heidi Dehaes - Olagos <
[hidden email]> wrote:

> Hi Harry, Pierre,
>
> About privacy laws, it depends if the data in ofbiz is stored on a hosting
> server in Europe or in the United States for example. If the data is stored
> in Europe, the privacy law of Europe is there.
>
> Eric
>
> Olagos bvba
> Heidi Dehaes
> Kerkstraat 34
> 2570 Duffel
> Belgium
> Tel. :     015/31 53 04
> GSM :    0485/22 35 80
> E-mail : [hidden email]
> http://www.olagos.eu
> http://www.olagos.com
> http://www.olagos.be
> http://www.olagos.nl
>
>
>
> 2017-11-20 13:22 GMT+01:00 harry mead <[hidden email]>:
>
> > Hi everyone,
> >
> > Does anyone know the privacy laws (im based in the UK) regarding the
> > personal information that is handled and stored on apache ofbiz, and if
> so
> > the best way to go about it.
> >
> > Thanks in advance
> >
> > Sent from my iPhone
>
Reply | Threaded
Open this post in threaded view
|

Re: Privacy laws

hzzg6y
In reply to this post by harry mead
Dear All,

     I have unsubscribed to [hidden email]  however still I am
getting lot of mails. Please can you remove me from this distribution
list...

Rgds,
Rupa

On Mon, Nov 20, 2017 at 5:52 PM, harry mead <[hidden email]>
wrote:

> Hi everyone,
>
> Does anyone know the privacy laws (im based in the UK) regarding the
> personal information that is handled and stored on apache ofbiz, and if so
> the best way to go about it.
>
> Thanks in advance
>
> Sent from my iPhone
Reply | Threaded
Open this post in threaded view
|

Re: Privacy laws

harry mead
In reply to this post by Pierre Smits
HI Pierre,


Thanks for the quick response,


Yes this is in relation to GDPR compliance.


Currently it is going to all be based in the UK, then expanded.

is all the data automatically encrypted on Apache ofBiz, or is there a process to ensure that we have fulfilled all of the GDPR requirements and the law.


Many thanks,


Harry

________________________________
From: Pierre Smits <[hidden email]>
Sent: 20 November 2017 12:57
To: [hidden email]
Subject: Re: Privacy laws

Hi Harry,

As far as I can tell, we don't have any information on hand regarding the
applicable laws that are applied to personal information stored in OFBiz.

Are you questioning this in relation to GDPR compliance?

Best regards,

Pierre Smits

ORRTIZ.COM <http://www.orrtiz.com>
OFBiz based solutions & services

OEM - The OFBiz Extensions Marketplace1
http://oem.ofbizci.net/oci-2/
Promotions: OEM Store<http://oem.ofbizci.net/oci-2/>
oem.ofbizci.net
This site has been created by Pierre Smits, an Apache OFBiz Contributor. Apache, the Apache feather logo, Apache OFBiz, OFBiz and the Apache OFBiz logo are ...



1 not affiliated to (and not endorsed by) the OFBiz project

On Mon, Nov 20, 2017 at 1:22 PM, harry mead <[hidden email]>
wrote:

> Hi everyone,
>
> Does anyone know the privacy laws (im based in the UK) regarding the
> personal information that is handled and stored on apache ofbiz, and if so
> the best way to go about it.
>
> Thanks in advance
>
> Sent from my iPhone
Reply | Threaded
Open this post in threaded view
|

Re: Privacy laws

Pierre Smits
Hi Harry,

Thank you for the prompt reply.

With your answer I can state: nothing of the sort is available OOTB.

Best regards,

Pierre Smits

ORRTIZ.COM <http://www.orrtiz.com>
OFBiz based solutions & services

OEM - The OFBiz Extensions Marketplace1
http://oem.ofbizci.net/oci-2/
1 not affiliated to (and not endorsed by) the OFBiz project

On Mon, Nov 20, 2017 at 3:51 PM, harry mead <[hidden email]>
wrote:

> HI Pierre,
>
>
> Thanks for the quick response,
>
>
> Yes this is in relation to GDPR compliance.
>
>
> Currently it is going to all be based in the UK, then expanded.
>
> is all the data automatically encrypted on Apache ofBiz, or is there a
> process to ensure that we have fulfilled all of the GDPR requirements and
> the law.
>
>
> Many thanks,
>
>
> Harry
>
> ________________________________
> From: Pierre Smits <[hidden email]>
> Sent: 20 November 2017 12:57
> To: [hidden email]
> Subject: Re: Privacy laws
>
> Hi Harry,
>
> As far as I can tell, we don't have any information on hand regarding the
> applicable laws that are applied to personal information stored in OFBiz.
>
> Are you questioning this in relation to GDPR compliance?
>
> Best regards,
>
> Pierre Smits
>
> ORRTIZ.COM <http://www.orrtiz.com>
> OFBiz based solutions & services
>
> OEM - The OFBiz Extensions Marketplace1
> http://oem.ofbizci.net/oci-2/
> Promotions: OEM Store<http://oem.ofbizci.net/oci-2/>
> oem.ofbizci.net
> This site has been created by Pierre Smits, an Apache OFBiz Contributor.
> Apache, the Apache feather logo, Apache OFBiz, OFBiz and the Apache OFBiz
> logo are ...
>
>
>
> 1 not affiliated to (and not endorsed by) the OFBiz project
>
> On Mon, Nov 20, 2017 at 1:22 PM, harry mead <[hidden email]>
> wrote:
>
> > Hi everyone,
> >
> > Does anyone know the privacy laws (im based in the UK) regarding the
> > personal information that is handled and stored on apache ofbiz, and if
> so
> > the best way to go about it.
> >
> > Thanks in advance
> >
> > Sent from my iPhone
>
Reply | Threaded
Open this post in threaded view
|

Re: Privacy laws

Paul Foxworthy
In reply to this post by harry mead
Hi Harry,

On 21 November 2017 at 01:51, harry mead <[hidden email]> wrote:


> is all the data automatically encrypted on Apache ofBiz, or is there a
> process to ensure that we have fulfilled all of the GDPR requirements and
> the law.
>

"automatically encrypted" applies to several different facets of an
application. For example, you would use TLS to encrypt data in transit from
a browser.

One security risk is that someone with basic file read permissions can dump
the contents of a data file used by a DBMS with software other than the
DBMS, and extract sensitive information like credit card numbers. Some
databases have the option of transparently encrypting all data "at rest",
sometimes known as Transparent Data Encryption (TDE), which eliminates that
risk. It's "transparent" in the sense that the data is encrypted while at
rest in a data file, without you doing anything different in your
application or your queries. TDE will add some processing overhead and will
mean your data does not compress well.

MariaDB can do this (
https://mariadb.com/kb/en/library/data-at-rest-encryption/), as can Oracle
and Microsoft SQL Server. I'm no Postgres expert, but from what I've seen I
think you need to call encryption functions as you store data, so it's not
transparent.

Cheers

Paul Foxworthy

--
Coherent Software Australia Pty Ltd
PO Box 2773
Cheltenham Vic 3192
Australia

Phone: +61 3 9585 6788
Web: http://www.coherentsoftware.com.au/
Email: [hidden email]
--
Coherent Software Australia Pty Ltd
http://www.coherentsoftware.com.au/

Bonsai ERP, the all-inclusive ERP system
http://www.bonsaierp.com.au/
Reply | Threaded
Open this post in threaded view
|

Re: Privacy laws

Jacques Le Roux
Administrator
Le 21/11/2017 à 04:02, Paul Foxworthy a écrit :

> Hi Harry,
>
> On 21 November 2017 at 01:51, harry mead <[hidden email]> wrote:
>
>
>> is all the data automatically encrypted on Apache ofBiz, or is there a
>> process to ensure that we have fulfilled all of the GDPR requirements and
>> the law.
>>
> "automatically encrypted" applies to several different facets of an
> application. For example, you would use TLS to encrypt data in transit from
> a browser.
>
> One security risk is that someone with basic file read permissions can dump
> the contents of a data file used by a DBMS with software other than the
> DBMS, and extract sensitive information like credit card numbers. Some
> databases have the option of transparently encrypting all data "at rest",
> sometimes known as Transparent Data Encryption (TDE), which eliminates that
> risk. It's "transparent" in the sense that the data is encrypted while at
> rest in a data file, without you doing anything different in your
> application or your queries. TDE will add some processing overhead and will
> mean your data does not compress well.
>
> MariaDB can do this (
> https://mariadb.com/kb/en/library/data-at-rest-encryption/), as can Oracle
> and Microsoft SQL Server. I'm no Postgres expert, but from what I've seen I
> think you need to call encryption functions as you store data, so it's not
> transparent.
>
> Cheers
>
> Paul Foxworthy
>
Also you can encrypt data using encrypt="true" for a field

Have a look at
     <entity entity-name="CreditCard"
and
     <field name="cardNumber" type="credit-card-number" encrypt="true"></field>

HTH

Jacques