{"id":1981,"date":"2018-05-24T09:56:51","date_gmt":"2018-05-24T08:56:51","guid":{"rendered":"http:\/\/blog.mozilla.org\/press-uk\/?p=1981"},"modified":"2018-05-24T09:57:18","modified_gmt":"2018-05-24T08:57:18","slug":"the-general-data-protection-regulation-firefox","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/press-uk\/2018\/05\/24\/the-general-data-protection-regulation-firefox\/","title":{"rendered":"The General Data Protection Regulation and Firefox"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">We are only a day away from May 25th, when the European General Data Protection Regulation (GDPR) will go into full effect. Since we were founded, Mozilla has <\/span><a href=\"https:\/\/blog.mozilla.org\/netpolicy\/2016\/05\/25\/the-countdown-is-on-24-months-to-gdpr-compliance\/\"><span style=\"font-weight: 400;\">always stood for<\/span><\/a><span style=\"font-weight: 400;\"> and practised a set of <\/span><a href=\"https:\/\/www.mozilla.org\/en-US\/privacy\/principles\/\"><span style=\"font-weight: 400;\">data privacy principles<\/span><\/a><span style=\"font-weight: 400;\"> that are at the heart of privacy laws like the GDPR. And we have applied those principles, not just to Europe, but to all our users worldwide. \u00a0We feel like the rest of the world is catching up to where we have been all along.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">GDPR has implications for many different parts of Mozilla. Rather than give you a laundry list of GDPR stuff, in this post, we want to focus specifically on Firefox and drill down specifically into how we think about privacy-by-design and data protection impact assessments within our browser product. <\/span><\/p>\n<h3><strong>Privacy By People Who Care About Privacy<\/strong><\/h3>\n<p><span style=\"font-weight: 400;\">Firefox, the web browser that runs on your device, is your gateway to the internet. Your browser will manage a lot of information about the websites you visit, but that information stays on your device. Mozilla, the company that makes Firefox, doesn\u2019t collect it unless you give us permission.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Mozilla does collect a <\/span><a href=\"https:\/\/telemetry.mozilla.org\/\"><span style=\"font-weight: 400;\">set of data<\/span><\/a><span style=\"font-weight: 400;\"> that helps us to understand how people use Firefox. We\u2019ve purposely designed our data collection with privacy protections in mind. So while the browser knows so much about you, Mozilla still knows very little.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Building a browser that is so powerful yet still respectful of our users takes a lot of effort. At Mozilla, we have teams of privacy and security engineers who are responsible for building a trustworthy browser. More than that, we have a workforce and a volunteer community that takes Mozilla\u2019s responsibility to protect you seriously and personally. This responsibility cuts across all areas of Mozilla, including our security engineers, platform and data engineers, data scientists, product managers, marketing managers and so on. We basically have an army of people who have your back. <\/span><\/p>\n<h3><span style=\"font-weight: 400;\">Rather than <\/span><i><span style=\"font-weight: 400;\">Privacy By Design<\/span><\/i><span style=\"font-weight: 400;\">, we do <\/span><i><span style=\"font-weight: 400;\">Privacy By People Who Care About Privacy. <\/span><\/i><\/h3>\n<p><span style=\"font-weight: 400;\">It is important to keep this in mind when we think about the GDPR\u2019s privacy-by-design requirements. Regardless of any regulatory requirement, including GDPR, if an organisation and its people aren\u2019t rooted in a commitment to privacy, any privacy-by-design process will fail. \u00a0It is our people\u2019s commitment to the <\/span><a href=\"https:\/\/www.mozilla.org\/en-US\/about\/manifesto\/\"><span style=\"font-weight: 400;\">Mozilla mission<\/span><\/a><span style=\"font-weight: 400;\"> that undergirds our design processes and serves as the most important backstop for protecting our users. <\/span><\/p>\n<h3><strong>Our Process<\/strong><\/h3>\n<p><span style=\"font-weight: 400;\">Okay, enough throat clearing. At Mozilla, we do have plenty of design processes to identify and deeply engage on privacy risks; code reviews, security and privacy reviews, intensive product and infrastructure audits, and public forums for anyone to contribute concerns and solutions. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Our Firefox data collection review process is the cornerstone of our effort to meaningfully practice privacy-by-design and assess privacy impacts to our users. We believe it is consistent with the GDPR\u2019s requirements for privacy impact assessments. Mozilla has had this process in place for several years and revamped it in 2017. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Here are a few key pieces of that process:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Before we look at any privacy risk, we need to know there is a valid analytic basis for the data collection. That is why our review process starts with a few simple questions about why Mozilla needs to collect the data, how much data is necessary, and what specific measurements will be taken. Mozilla employees who propose additional data collection must first answer these questions on our <\/span><a href=\"https:\/\/github.com\/mozilla\/data-review\/blob\/master\/request.md\"><span style=\"font-weight: 400;\">review form<\/span><\/a><span style=\"font-weight: 400;\">. <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Second, our Data Stewards &#8211; designated individuals on our Firefox team &#8211; will <\/span><a href=\"https:\/\/github.com\/mozilla\/data-review\/blob\/master\/review.md\"><span style=\"font-weight: 400;\">review<\/span><\/a><span style=\"font-weight: 400;\"> the answers, ensure there is public documentation for data collection, and make sure users can turn data collection on and off. \u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Third, we categorise data collection by different levels of privacy risk, which you can find in more detail <\/span><a href=\"https:\/\/wiki.mozilla.org\/Firefox\/Data_Collection\"><span style=\"font-weight: 400;\">here<\/span><\/a><span style=\"font-weight: 400;\">. The data category for the proposed collection must be identified as part of the review. For proposals to collect data in higher risk categories, the data collection must be default off.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Complex data collection requests, such as those to collect more sensitive data or those that call for a new data collection mechanism, will escalate from our Data Stewards to our Trust and Legal teams. Further privacy, policy, or legal analysis will then be done to assess privacy impact and identify appropriate mitigations.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">The results of this review process, as well as in-depth descriptions of our data categories and the <\/span><a href=\"https:\/\/wiki.mozilla.org\/Firefox\/Data_Collection\"><span style=\"font-weight: 400;\">process<\/span><\/a><span style=\"font-weight: 400;\"> itself, can be found publicly on the web. And you can find the full documentation for Firefox data collection <\/span><a href=\"https:\/\/firefox-source-docs.mozilla.org\/toolkit\/components\/telemetry\/telemetry\/index.html\"><span style=\"font-weight: 400;\">here<\/span><\/a><span style=\"font-weight: 400;\">. <\/span><\/p>\n<h3><strong>But Wait, There\u2019s More!<\/strong><\/h3>\n<p><span style=\"font-weight: 400;\">This process is just one of the many tools we have to protect and empower the people who use our products. \u00a0Last year, we completely rewrote our <\/span><a href=\"https:\/\/www.mozilla.org\/en-US\/privacy\/firefox\/\"><span style=\"font-weight: 400;\">privacy notice<\/span><\/a><span style=\"font-weight: 400;\"> to provide clear, simple language about the browser. The notice includes links directly to our Firefox privacy settings page, so users can turn off data collection if they read something on the notice they don\u2019t like. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">We redesigned those privacy settings to make them easier to use (check out about:preferences#privacy in the Firefox Browser). This page serves as a one-stop shop for anyone looking to take control of their privacy in Firefox. And we revamped Firefox onboarding by showing new users the Firefox privacy notice right on the second tab the very first time they use the browser. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">It\u2019s easier today than ever before to take control of your privacy in the Firefox browser. As you can see, limited data, transparency, choice &#8211; all GDPR principles &#8211; are deeply embedded in how all of us at Mozilla think about and design privacy for you. <\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We are only a day away from May 25th, when the European General Data Protection Regulation (GDPR) will go into full effect. Since we were founded, Mozilla has always stood &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/press-uk\/2018\/05\/24\/the-general-data-protection-regulation-firefox\/\">Read more<\/a><\/p>\n","protected":false},"author":493,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[121],"tags":[],"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/press-uk\/wp-json\/wp\/v2\/posts\/1981"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/press-uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/press-uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/press-uk\/wp-json\/wp\/v2\/users\/493"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/press-uk\/wp-json\/wp\/v2\/comments?post=1981"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/press-uk\/wp-json\/wp\/v2\/posts\/1981\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/press-uk\/wp-json\/wp\/v2\/media?parent=1981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/press-uk\/wp-json\/wp\/v2\/categories?post=1981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/press-uk\/wp-json\/wp\/v2\/tags?post=1981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}