The SEAL Project is a European Project with GRANT AGREEMENT UNDER THE CONNECTING EUROPE FACILITY (CEF) - TELECOMMUNICATIONS SECTOR,

What data do we collect?

  • The SEAL Service will temporarily collect personal data upon behalf of the user where they request to collect data from any of the following sources:
    • eIDAS[1]
    • eduGAIN[2]
    • ICAO[3] compliant ePassport and national Identity Cards
    • User´s own Personal Data Store (PDS) residing on his local device or cloud storage (current support for Google Drive and Microsoft One Drive)
    • User´s Self-sovereign Identity (SSI) Wallet

The data collected from eIDAS relates to their national eIDs, specifically:

    • Mandatory identity attributes:
      • A uniqueness identifier      
      • Current family name           
      • Current first name(s)          
      • Date of birth 
    • Optional attributes may additionally be provided:
      • Gender          
      • Name and family name at Birth    
      • Place of birth
      • Address        
      • Current address      

The data collected from eduGAIN relates to the commonly supported attributes by HEI IdPs:

The data collected from ePassports and national eIDs:

  • DocumentCode
  • IssuingState
  • DocumentNumber
  • DateOfExpiry
  • GivenName
  • Surname
  • Nationality
  • DateOfBirth
  • Sex
  • PlaceOfBirth
  • FaceImage

How do we collect your data?

  • SEAL facilitates users to collect their data through the following means:
    • Through request from the SEAL Web or Mobile Dashboard to manage their identity information with the following functions:
      • importing / authenticating identities (eduGAIN, eIDAS, ePassport),
      • linking two identities and giving them a matching level of assurance based on either manual or automatic KYC processes,
      • deriving new identifiers based on an authenticated identity (eduGAIN or eIDAS),
      • Issue imported, linked and derived identities as Verifiable Credentials to the users´ SSI Wallets.
    • The personal identity data is requested from a Service Provider (SP) such as a university student service upon behalf of a user´s request. The SP redirects the user to the SEAL Service which then redirects the user to identify themselves by any of the following means:
      • eIDAS authentication
      • eduGAIN authentication
      • Retrieval of personal identity information from the user´s PDS
      • Retrieval of personal identity information from the user´s SSI Wallet
      • The user is able to see and control all information collected at any moment and choose to only send limited attribute data or cancel any query of their data.
    • The personal identity data can also be requested from the VC Issuer directly via Web Browser to issue the VCs to a user´s SSI Wallet from the following sources:
      • eIDAS authentication
      • eduGAIN authentication
      • SEAL Linking service once the identities above have been retrieved

How will we use your data?

  • The personal data collected by the SEAL service is returned to the user, or SP as instructed by the user. There is no further use of personal data by the service and the user´s data is deleted when the session is terminated.
  • The service can generate non-personal data for managing the service e.g. number of users accessing the service.

How do we store your data?

  • No personal data is stored in SEAL. It is only temporarily collected to provide a user´s personal identity data to the user for their identity management client or to a requesting SP as instructed by the user.
  • The SEAL Service also supports manual and automatic KYC linking of a user´s identities when requested by the user. The data is temporarily stored in the KYC linking repository until the user retrieves it.

What are your data protection rights?

  • You have the right to:
    • request further information on how your personal data is processed.
    • raise an objection about how your personal data is processed
  • For your information, we follow the Data Protection Code of Conduct[4].

Please contact us as per the contact indicated if you have and request or issue to raise.

Cookies

  • No cookies are employed by the SEAL Service.

Changes to our privacy policy

  • There may be future updates to this privacy policy, in which case the “last updated” date at the foot of the page will also change accordingly.
  • Any updates to this privacy policy will apply to the processing of your data immediately.

How to contact us?

  • If you have any query or concern about this privacy notice or processing of your personal data, please contact us here:

https://project-seal.eu/form/contact

Other affiliates:

The SEAL Service for providing the authentication and the identification of the user, SEAL partners with “GRNET” (National Infrastructures for Research and Technology). “GRNET” is providing the eIDAS service along with the technical guidance. More detailed information about the provision of services by "GRNET", the Privacy Policy thereof, is available on https://eid-proxy.aai.grnet.gr/static/privacy-policy.pdf. Furthermore, it should be noted that “GRNET” shall act as the sub-processor for the technical logs of the activity of the users on behalf of each Project in compliance with the provisions of law on personal data, and shall not be responsible for the lawfulness of the collection, the processing and the legal basis thereof, the purpose, nor for notifying the data subjects and for satisfying the rights thereof.

Rights of data subjects:

As regards the data processed in the context of providing the SEAL Service the Connecting Europe Facility (CEF) -acts as the processor- takes all necessary action, pursuant to the terms of this Privacy Policy, both during the collection as well as in every subsequent stage of processing of SEAL Service “users” personal data, so that every "user" who may has any query or concern about this privacy notice or processing can contact us in the form mentioned hereinabove.

However, please notice that the organization or institution that has required the user to use the SEAL Service as a means to gather and/or verify their identity credentials is acting as the Data Controller and is responsible for the collection, the processing and the legal basis thereof, of the personal data that SEAL collects.

To exercise any of the - as laid out in applicable legislation on the protection of personal data – rights, namely: Access, Rectification, Erasure, Restriction of Processing, data Portability rights, the “user” may contact his/hers affiliated organization or institution.

Recourse/Complaint:

In the event that any SEAL Service “user” request is not satisfied by the affiliated organization or institution, the "user" may at any time address to/ file recourse with the Competent Supervisory Authority of its residence.

 

[1] https://ec.europa.eu/digital-single-market/en/trust-services-and-eid

[2] https://edugain.org/

[3] https://www.icao.int/Pages/default.aspx

[4] https://wiki.geant.org/display/eduGAIN/Data+Protection+Code+of+Conduct+Cookbook