澄清Auth0 Cookie的数据过程

发布于 2025-02-14 01:47:11 字数 503 浏览 3 评论 0原文

我在这里发布一个问题,但甚至可能的建议已经很好。

为了遵守GDPR,法律部门现在要求我们澄清我们使用的Cookie的数据处理。对于每个cookie,我们需要澄清:

  • IT处理的数据处理是什么
  • 数据处理涉及服务器(例如已发送到服务器),或者只是在本地
  • 与其他信息合并以决定Cookie是否正在处理个人数据。

在我们在网站上拥有的cookie中,有第三方cookie由Auth0 Custom域设置,它们是:

现在,我们很难满足请求,因为从我们所知道的以及从Auth0上找到的文档中网站,我们要寻找的信息不可用。

请帮助我们如何找到我们要求的信息。

I'm posting a question here but may be even advice is already good.

To be complied with the GDPR, we are now requested by legal department to clarify the data processing for the cookies we use. For each cookie, we need to clarify:

  • What data it process
  • Does that data processing involve a server (like sent to the server) or just proceeded locally
  • Combine with other information to decide if the cookie is processing personal data or not.

Among the cookies we are having on our website, there are 3rd party cookies set by auth0 custom domain, they are:
enter image description here

Now it's really hard for us to fulfill the request because from what we know and from the document we found on auth0 website, the information we're looking for is not available.

Please help to give advice on how should we find the information we're requested.

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(1

烟酒忠诚 2025-02-21 01:47:11

您会在此处找到一些信息: https://auth0.com/文档/管理用户/cookie/authentication-api-cookies 。另外,我建议您直接与Auth0联系,因为它们是您的“处理器”,并有义务(根据GDPR第28条)为您提供所需的信息。除非您可以阅读JavaScript,否则您需要向Auth0询问每个Cookie的目的。

第二个问题的答案取决于您的实施。如果这些是第三方Cookie(由Auth0设置),则它们始终涉及第三方服务器。这意味着当使用这些cookie时,始终处理个人数据(IP地址)。

一旦获得有关每个cookie目的的信息(为什么要设置它们),您将获得第三个问题的答案。

另外,您的法律团队可能想知道这些服务器的位置(最终用户获取这些cookie)。随着IP地址和其他流量数据的处理,它可能涉及转移到第三个国家(这是GDPR变得非常复杂的地方)。

You'll find some information here: https://auth0.com/docs/manage-users/cookies/authentication-api-cookies. Also I'd advice you to contact Auth0 directly as they are your "processor" and obliged (under the GDPR article 28) to provide you with the information you need. Unless you can read javascript, you need to ask Auth0 for the purpose(s) of each cookie.

The answer for your 2nd question depends on your implementation. If those are 3rd party cookies (set by Auth0), then they always involve a 3rd party server. This means that personal data (IP addresses) are always processed when those cookies are used.

You will get the answer for your 3rd question once you get information on the purposes of each cookie (why they are being set).

Also your legal team would probably want to know the location of those servers (where end users fetch those cookies). As IP-addresses and other traffic data are being processed, it might involve transfers to 3rd countries (and this is where the GDPR gets really complicated).

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文