-
-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Harvesting user email addresses without any form of consent is against GDPR regulation #17
Comments
Thanks for your comment! From the readme in this very repo, perhaps you missed this important note:
We never get the actual email address until the user actually consents to that by installing the SponsorLink app. |
@kzu a SHA256 of the email is not sufficient for GDPR compliance:
|
This is completely incorrect, and not GDPR compliant. It's not GDPR compliant due to the paragraph linked by @iamdavidfrancis. It's trivially exploitable, since you could
Since you don't use any salt when hashing, this is privacy-unsecure basically by design. Even if this was somehow legal from the standpoint of GDPR, it's so obviously and blatantly unethical that I can't even believe we need to have this discussion. |
The SponsorLink addin is sending user email addresses without any consent to a cloud API. When used inside a corporate environment is is unacceptable. Next to this its also against EU GDPR regulations and probably most corporate environments.
Developers won't use their private github account to do contributions to the corporate git repository, so the sponsorlink will never work for them either
The text was updated successfully, but these errors were encountered: