From ea7ff9c978db760add67d7c2ec4ca450c5bddf88 Mon Sep 17 00:00:00 2001 From: Ronald Tse Date: Thu, 20 Aug 2026 14:39:17 +0800 Subject: [PATCH] Answer the data-protection review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A data-protection-officer review of the draft raised seven concerns about personal data in public, append-only transparency structures; all are answered, six normatively: - Log content minimization (new requirement with test): log leaves, proofs, and tree heads carry no directly identifying personal data; named-identity binding lives in access-controlled registers, with revocation and key rotation as the withdrawal mechanism. - Rectification: the log records issuance, not truth — corrections flow through superseding attestations and re-issuance, never edits (guidance on append-only structure and retention). - Data minimization: co-signature signer identity in public artifacts and passports is normatively a key fingerprint or pseudonym. - Linkability: schemes attesting individuals use rotating or purpose-bound keys or privacy-preserving credentials. - Storage limitation: retention bounded by purpose with scheme-defined deletion criteria for logs and ceremony transcripts. - Cross-border transfer: the deployment manifest documents mirror jurisdiction and transfer basis; schemes processing personal data define a privacy policy with lawful basis and information duties. The registry is now 118 requirements and 118 tests; the new audit gate passes. --- presentations/signatif-intro.pptx | Bin 456006 -> 456006 bytes sources/data/08-artifact-format-rc.yaml | 7 ++++++- sources/data/13-transparency-cc.yaml | 12 ++++++++++++ sources/data/13-transparency-rc.yaml | 15 +++++++++++++++ sources/data/17-ceremony-rc.yaml | 2 ++ sources/data/18-manifest-rc.yaml | 2 ++ sources/data/19-governance-rc.yaml | 2 ++ 7 files changed, 39 insertions(+), 1 deletion(-) diff --git a/presentations/signatif-intro.pptx b/presentations/signatif-intro.pptx index afeb3bd8861411dd99ff95164cc3910b6aeb86cb..3d2b8bfaaf96d54ee5e451e7582f55973935ec35 100644 GIT binary patch delta 2172 zcmY+Edoe}Cs1fzi&{h>TD)?$FG?b|kjfw?QGb)^QSVp|TOa%%9gCG=%GhDz!zeMNr2{i(@)UoqufWS_olXt zIt!GdTNa>{)mJEGZM%Cp&6ZJOk5UN^MntTZE%ICd)EOTF>S575C*RegMs6rR;by#Q z?(yKQled55Rcq#(#{?X%VLju#i804zZ~e+W$WtL&5`v)}lNH-dUIl4ICAG4pK?^_Lvc0Nc=6<6?lI@*EZ>JoYBbL+#TS&zAID_zLU+jU zdMa;{lxS3<;2~w_znoyppt_o<A?qB+jSTuFqkIwH-QCmAt5N`yx$tpA}Wt_pCm*D_vqUAf3(rrNrrcK(hHHUfEvq zhv8MqK#*#!lvR1jSs>M_Bls%GfS~^Q*lXXZ0H_-5rH3MIS6im_>(!HM5D?-1no+ueRmyoy4 zP^ewO(bmn|eCEjad)DV)DAkBt~Q7RexbA<^1OUUFwyzbhnb4JSTPQ z_4L`jI^Hr*(hX+1reycrxE4>Auwa^SX48!fZ)$pI&`>-prO7R)@M+efWTT+^(ui zH@o1ZR~Om++d!jJ-uGPH(=4+|iCY`nQ?i(jy!Hq(E!?hr=MCz`rfubRj~?lf>*nJP zI1l{nMn00gVn6YZUl(iSgwv%YQu^=hX4CK zAqIA?v7N>-J867%HZmd@2fN^a6cGr7;+zP$Kv6FOK2T^)U>gfq7K{muc{MHH#`FZR zhT!H&MLT5@vn$rv+EbYAF{MZ|m+kH~ww)NGzZWagP0RLwYwX}@jLw{1rO_eC65tA( z43}WrVktOeL~{n%z_{zoDo92O<@UtznUpMsDLa7zwfa&hLFO{`fufeZJ>&&hMP_%=>#Lr96{Tw0%5P zNpled(Li#d^b52tR8+BFo}8M9y#G(VV6K%?2>E>3+gx8;;t z;uPB|4X3PEK;?EhdhZ2t?;;At_KuwUNQgZgkqahZYfnSrygqkcfJ%aiAPdm>{mXw^jo|Ecc_%Y%rfMj{_bWicS>Q48WG`+2GWaWsZ8w zu>5z)MDg?#psN&YRs;itL@+xI3@Y7Rkqz+u2j#Y~4q~I_eT!ep>(J0&9prNtgg~gF*dpU_XD@%rOE90r-1|OtVYt;M z{UpF<6v>_ptZNqVXzS0W8iyzUm=MyE6I0n#chfqrt)5!b{DvE0WL|G@OWiM0YJRJi zUh>+Noh$rYD{>t#^nF}|`o#LpXGQF$R>oZ1cPn5_PoB6nv6N;@rB*%oBkRzH6A?b| z4bs*9F1}(Fir1g7br}*0ng1p%dweYLdy$S*a$T+?q|IyWmkn%}zghj;ez!*QZPBSF zt^-xn7Gpi+S?^g%6*fJ%fBJZJ+OZ_MKRM;6dpop#zEeoTC&}HHaNzb#Fyjxvy=k|r1>hHXw1gC3}5mh(K z;3Q3wLrCM>Iiq)DA|@8Bv}beI9=`iBvAc_YDI;B_kmfREmo?0t2oi~cbr~M{oy{3e zzBF23L4)e0WYcr%4#p&Aupsv-y-afTg_9{C(IaOyvGm;an(iFTjkm}Y6nEZ1%w7jD zH)jMTR3v(^>KA)QmQLh{C)6=x{SB_Aa!HrDuCB-0SA<$FB|j2=vDS^v>*}jU#x{C6 z>hEUhct450!g8DIoLzO%7EG8pq^E}dnc>$Ot>U5L&nXw{xyCc;?_V6zO5T>Oqdj&c zC8)$E$$lu}_aH;N$a<9*i6JhFte(3Ic#Dkw${60YshC6d3%%*W7#xi%=r2BAXHz`7 z^U$l(U+vn{=$FZ*i$`kRtIIBGEGWsiane0QQr>JdX9v?`^y`5c@9w_fM@OUi*emQX z3qjEFhk$~5$(28l8)9Gz|F!(Gw_q-O9{6>QpbowmXu(I|1V6=rkH7&6ssyZqB1{5k zP;ez+0~AsT*b2p(7J@l5DT-PMX1IkY==ce2gK+#O;19*ePk;`EO)Ch1;z}#Qyza#M z{@hAbwQp0l)7l8TX@>3IPT2A7%5?vvy{bdmzTQF54KwUborE3RIZfl;Ql--l1x=O` zV9gBMsf)0qyQXKOpdDRcJsi-Y8|;80rW-gzQQi$aq0sFiHs(7iI6VX->c_Ux-vd@b zaA~iy9otLTMKf&uKEmG8r%Y!~+I2H*dl^B8%9QD6llI6A+rOWnS^d*AJ_Ka|Y=li7 y7$CNlr{qvj?LlAz;~NL3K?<6V*;7v^+Av5g5i3GLZRJEth@42tl@ql`G4Vf~yp(SM diff --git a/sources/data/08-artifact-format-rc.yaml b/sources/data/08-artifact-format-rc.yaml index b398680..592e793 100644 --- a/sources/data/08-artifact-format-rc.yaml +++ b/sources/data/08-artifact-format-rc.yaml @@ -36,7 +36,10 @@ groups: identifier_fragment: signer-identification statement: A signature wrapper shall reference or embed the signer's public key or end certificate, enabling the verifier to locate the key and its delegation - chain. + chain. In publicly presentable artifacts and passports, the signer identity of a + co-signature block shall be a key fingerprint or pseudonym; named-identity + binding shall be held in an access-controlled register by the responsible + authority. guidance: - "Signer identifiers are URIs (<>)." @@ -88,6 +91,8 @@ groups: algorithm and parameters, dimension tag, and signature over the canonical payload. guidance: - The dimension tag identifies the trust dimension this co-signature attests. + - "Schemes whose attesting subjects are individuals should use rotating or purpose-bound operator keys, or privacy-preserving credentials, to limit cross-artifact linkability." + - name: Co-signature independent verification identifier_fragment: cosignature-independent-verification diff --git a/sources/data/13-transparency-cc.yaml b/sources/data/13-transparency-cc.yaml index d994623..fd8ffd8 100644 --- a/sources/data/13-transparency-cc.yaml +++ b/sources/data/13-transparency-cc.yaml @@ -82,6 +82,18 @@ groups: is validated independently. type: Conformance + - name: Log content minimization test + identifier_fragment: log-content-minimization + targets: + - /req/transparency/log-content-minimization + purpose: Verify log structures carry no directly identifying personal data and that + named-identity binding sits in access-controlled registers. + method: Inspect serialized log leaves, inclusion proofs, and tree heads for names, + identifiers, or linkable personal data; verify only digests and tags appear. + Attempt to resolve a signer from a public artifact without the authority register + and confirm the register is access-controlled. + type: Conformance + - name: Log retention test identifier_fragment: log-retention targets: diff --git a/sources/data/13-transparency-rc.yaml b/sources/data/13-transparency-rc.yaml index aeb5461..7c54194 100644 --- a/sources/data/13-transparency-rc.yaml +++ b/sources/data/13-transparency-rc.yaml @@ -21,6 +21,8 @@ groups: - Domain separation prevents second-preimage attacks. RFC 6962 uses 0x00 prefix for leaves and 0x01 prefix for internal nodes. - The Merkle tree semantics follow RFC 6962. + - "Append-only history records that attestations were issued, not that their content remains accurate; rectification flows through supersession and the revocation propagation of clause 11." + - name: Inclusion proof format identifier_fragment: inclusion-proof @@ -75,6 +77,17 @@ groups: - Each inclusion proof is validated independently. - No single log operator controls the record. + - name: Log content minimization + identifier_fragment: log-content-minimization + statement: Log leaves, inclusion proofs, and tree heads shall contain no directly + identifying personal data; personal data referenced by an artifact shall be held in + access-controlled registers by the responsible authority, with revocation and key + rotation serving as the mechanism for withdrawal of validity. + guidance: + - "The log records issuance, not truth: corrections are made by superseding + attestations and re-issuance, never by editing history." + + - name: Log retention identifier_fragment: log-retention statement: A recognized transparency log shall retain its append-only history, and its @@ -82,6 +95,8 @@ groups: plus grace periods that the deployment serves. guidance: - Retention obligations transfer with log succession per the scheme's governance. + - "Retention is bounded by purpose: the scheme's retention policy defines deletion and suppression criteria once the served validity period ends." + - name: Consistency proofs identifier_fragment: consistency-proofs diff --git a/sources/data/17-ceremony-rc.yaml b/sources/data/17-ceremony-rc.yaml index e2cc57a..f79575a 100644 --- a/sources/data/17-ceremony-rc.yaml +++ b/sources/data/17-ceremony-rc.yaml @@ -36,6 +36,8 @@ groups: transcript custody shall transfer to a successor or escrow designated by the scheme's governance. guidance: + - "Transcript retention follows the scheme's retention policy, which defines deletion and suppression criteria for personal data of key holders once the served period ends." + - name: Transcript transparency log cross-reference identifier_fragment: transcript-log-cross-reference diff --git a/sources/data/18-manifest-rc.yaml b/sources/data/18-manifest-rc.yaml index 9c0ad67..c5ff45f 100644 --- a/sources/data/18-manifest-rc.yaml +++ b/sources/data/18-manifest-rc.yaml @@ -43,6 +43,8 @@ groups: mirrors with their endpoints and public keys, and the multi-log attestation policy parameters if applicable. guidance: + - "The manifest documents the jurisdictional scope of log operators and mirrors and the basis for any cross-border transfer of personal data." + - name: Manifest validation — acyclic graph identifier_fragment: manifest-validation-acyclic diff --git a/sources/data/19-governance-rc.yaml b/sources/data/19-governance-rc.yaml index 8310ee5..663f066 100644 --- a/sources/data/19-governance-rc.yaml +++ b/sources/data/19-governance-rc.yaml @@ -30,6 +30,8 @@ groups: guidance: - ISO/IEC 27001, WebTrust for CAs, and ETSI EN 319 411 are recognized ISMS frameworks. - Audit attestations shall be published. + - "Schemes processing personal data define a privacy policy covering lawful basis, information duties to attesting subjects, and the retention schedule." + - name: Issuing authority organizational assurance identifier_fragment: issuing-authority-assurance