Data Collection: Difference between revisions

Jump to navigation Jump to search
no edit summary
(→‎Step 1: Submit Request: Matrix -> Element)
No edit summary
Line 116: Line 116:
:  It also includes any data from different categories that, when combined, can identify a person, device, household or account.  For example:  Category 1 log data combined with Category 3 saved URLs.  
:  It also includes any data from different categories that, when combined, can identify a person, device, household or account.  For example:  Category 1 log data combined with Category 3 saved URLs.  


: Additional examples are:  voice audio commands (including a voice audio file), speech-to-text or text-to-speech (including transcripts), biometric data, demographic information, and precise location data associated with a persistent identifier, individual or small population cohorts.  This is location inferred or determined from mechanisms other than IP such as wi-fi access poinits, Bluetooth beacons, cell phone towers or provided directly to us, such as in a survey or a profile.  
: Additional examples are:  voice audio commands (including a voice audio file), speech-to-text or text-to-speech (including transcripts), biometric data, demographic information, and precise location data associated with a persistent identifier, individual or small population cohorts.  This is location inferred or determined from mechanisms other than IP such as wi-fi access points, Bluetooth beacons, cell phone towers or provided directly to us, such as in a survey or a profile.  
:   
:   


== Eligibility for Default on Data Collection ==
== Eligibility for Default on Data Collection ==
* Categories 1 & 2 (Technical & Interaction data)
** Pre-Release & Release: Data may default on, provided the data is exclusively in these categories (it cannot be in any other category).  In Release, an opt-out must be available for most types of Technical and Interaction data.  Teams may limit data collection to pre-release populations if appropriate for testing/validation, cost reduction, or risk mitigation.


* Category 3 (Web activity data)
At installation, Mozilla’s products and services include one or more preferences and settingsThese preferences and settings typically belong to a data collection statea status that describes whether data collection occurs by default or not.
** Pre-Release: May be eligible for default on data collection, provided there is an opt-out.
** Release: Default off.
*** On a case-by-case basis collections may be eligible to be "default on" if mitigations are identified. Mitigations may include UX changes that make users aware of additional risk, technical mechanisms that remove the risk, or a risk assessment done of a case-by-case basis that determines the risk is limited.
   
* Category 4 (Highly Sensitive data)
** Pre-Release: Default off.  May be eligible for opt-in data collection by specific users, provided there is (i) advance user notice (ii) consent and (iii) an opt-out.
** Release: Default off. May be eligible for opt-in data collection by specific users, provided there is (i) advance user notice (ii) consent and (iii) an opt-out.


{| class="wikitable"
|-
! State !! What it Means
|-
| Default ON || Data may be collected automatically. 
Users must have a way to turn off data collection. Learn how to opt out of data collection in Firefox.
|-
| Default OFF || Data may be collected,  but only if a user takes an clear, express action to opt-in to the collection.  This can be through a configuration option, a prompt or an update through an account profile. 
Users must have a way to turn off data collection.
|}
“'''Release'''” means products that are not experimental. These include Firefox, Pocket, Lockwise, Monitor, and others.
“'''Pre-release'''” means experimental products. They are typically identified by the words “Beta,” “Nightly,” “Preview,” “Reference Browser,” or “Developer Edition” in the name of the product.
{| class="wikitable"
|-
! Category 1 “Technical data”
|-
|  ''Release & Pre-Release'' - eligible for Default ON.
|}
{| class="wikitable"
|-
! Category 2  “Interaction data”
|-
|  ''Release & Pre-Release'' - eligible for Default ON.
|}
{| class="wikitable"
|-
! Category 3 “Stored Content and Communications”
|-
| ''Release'':  Default OFF.  Default ON requires prior Trust approval.
 
''Pre-Release'': Default ON eligible
On a case-by-case basis collections may be eligible to be "Default ON"  if mitigations are identified. Mitigations may include UX changes that make users aware of additional risk, technical mechanisms that remove the risk, or a risk assessment done of a case-by-case basis that determines the risk is limited.
|}
{| class="wikitable"
|-
! Category 4 “Highly Sensitive or Clearly identifiable personal data”
|-
| ''Release & Pre-Release'': Default OFF
Any collection requires prior Trust approval and (i) advance user notice (ii) consent and (iii) an opt-out.
|}
= Other Practices =
= Other Practices =


39

edits

Navigation menu