GDPR and OpenMRS?

I couldn’t answer this topic before, but thanks so much for doing it :slight_smile:

Burke raised the ticket to add the user agreement to ID a long time ago: Log in with Atlassian account If someone is willing to change ID dashboard, please let me know.

So.

We don’t have a lot of personal data with OpenMRS ID, I suppose we are sensible people :smiley: We have username, emails, full name. We do maintain any historical data on changes. We do not aggregate, generate metrics. Avatars come from gravatar. We do not store IPs or anything. We do not have gender, preferences, address or country.

We know that Atlassian apps will store the last time the person logged in.

Helpdesk is a little bit tricky, not sure if anything there could be considered PII.

Exception is Atlas. Atlas is submitted via OpenMRS module I believe most of the time, but we have a lot of public PII there. The data is sort of stored forever, the only way to delete is to hack our way on the database and delete it. Not only that, the endpoint to recover all data is a public endpoint…

So, deleting an OpenMRS ID should* be easy, it’s exactly the same screen we add ldap groups. But it won’t delete the data from any atlassian product: you’ll see the username only, not sure if that’s enough. In talk you can see everything just as before, but I believe we should have the option to anonymize the user if that’s what we want.

*should, because formage sometimes doesn’t find a user that exists… but we should fix it soon.

It could be either in the internal wiki or confluence, both should be fine.

cc @dkayiwa

1 Like