General Data Protection Regulation

Contents
  1. What is the GDPR?
  2. How does BOINCstats respect the GDPR?
  3. Access to data
  4. Rectification of data
  5. Erasure of data
  6. Statistics data
  7. Statistics export consent

1: What is the GDPR?

The General Data Protection Regulation (EU) 2016/679 (GDPR) is a regulation in EU law on data protection and privacy for all individual citizens of the European Union (EU) and the European Economic Area (EEA). It also addresses the transfer of personal data outside the EU and EEA areas. The GDPR aims primarily to give control to individuals over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU. Superseding the Data Protection Directive 95/46/EC, the regulation contains provisions and requirements pertaining to the processing of personal data of individuals (formally called data subjects in the GDPR) inside the EEA, and applies to any enterprise established in the EEA or—regardless of its location and the data subjects' citizenship—that is processing the personal information of data subjects inside the EEA.

More information can be found on Wikipedia.

2: How does BOINCstats respect the GDPR?

BOINCstats aims to fully comply with the GDPR withing the limitations of the nature of the data provided by third parties and processed by BOINCstats.

3: Access to data

The GDPR requires that users can request insight in their data stored by BOINCstats. Users can request this by emailing the webmaster.

4: Rectification of data

All data entered by a user can also be edited by a user. There is no need to ask the website administrator to do so.

5: Erasure of data

A user can delete his own account from the account page.

By deleting the account the following data is irreversible removed:
  • Host preferences
  • Host projects
  • Hosts
  • Host group preferences
  • Host group projects
  • Host groups
  • Task log
  • Task settings
  • Tasks
  • Account preferences
  • User profile
  • Profile and avatar image
  • Profile ratings
  • Project ratings
  • Public profiles messages, send and received
  • Forum signature
  • Stats targets
  • Team create information
  • Team founder data
  • Account data
  • BOINCstats settings
  • All email addresses, current and past
  • Account projects
  • Work preferences
  • Forum logs
  • Forum preferences
  • Forum subscriptions
  • Profile friends
  • Received private messages
  • Private message outbox

The following data is not removed but instead anonymized:
  • Forum threads and posts. They are part of a public discussion.
  • Private messages in the inbox of other users. These are owned by the receiving user, just like email.

The following data is not removed:
  • All statistics data. They do not originate from BOINCstats. See below how to anonymize or delete these.
  • Stored IP addresses. They may be needed when abuse is suspected. They will be automatically removed when the logs expire.
  • Fixed CPID in retired projects.

6: Statistics data

All data in the statistics does not originate from BOINCstats. This data is generated by the BOINC projects and subsequently imported by BOINCstats. Erasure at BOINCstats does not delete this data as with the next import it will be added again.
There are several options to delete this data and get it removed from BOINCstats:
  • When the project is based in the EU it should also comply with the GDPR. In the account settings at the project you'll find an option to revoke the consent to export your data to BOINC statistics aggregation web sites. By revoking consent your data will no longer be exported and will be removed from BOINCstats with the next import from the project. See below for a list of projects which have the consent option.
  • When the project does not offer the consent option you can anonymize the data by changing all relevant data. Every project has an option to anonymize hosts so that they are not linked to your account anymore.
  • When anonymization is not good enough you can ask the project administrator to delete your data. The procedure on how to do this is different for every project. A good starting point is the forum.

Currently the BOINC project server software does not provided an API to delete your account data by using an account manager (BAM!).

The exported data does not contain any data which can be linked directly to a person. It does not contain the email address used to create the account at the project. Therefor it is difficult to determine or to proof which data belongs to an actual person. Usernames are generally not enough proof since there are many persons with the same name. In order to avoid deleting someone elses data (especially the history) requests to delete this data directly from the BOINCstats database will not be honored. Please follow the procedures outlined above to get your data removed.

7: Statistics export consent

The following projects require you to consent to exporting your statistics to stats sites. If you do not do so your data will be removed from the export and in accordance with the GDPR all your data from these projects will be removed from BOINCstats as well. This data can't be recovered!
You need to consent before they enforce the setting in the export!
  • Albert@home
  • Climate Prediction
  • Einstein@Home
  • LHC@Home
  • LHCathome-dev
  • NumberFields@home
  • VGTU
  • Universe@Home
  • World Community Grid
  • WUProp@Home


Project owners: Please let me know in time when you add this setting so I can add your project to this list!