APIFamilyproposal_Identity&Consent.md

April 26, 2024 ยท View on GitHub

FieldDescription
API family nameIdentity and Consent Management
API family ownerTelefonica
API family summaryHigh level description
Operator (NaaS) platform implementing CAMARA APIs should be built with a privacy-by-default approach to fully comply with data protection regulations like the GDPR regulation in Europe, which emphasises on user's privacy. These regulations note that some CAMARA APIs may require user consent to be accessed. This forces the operators to provide means and appropriate solutions to capture, store and manage this consent through its lifecycle. Otherwise, the scoped CAMARA APIs cannot be rolled out in production networks.
Building such a solution also means bringing in scope the identity of the end user and/or the subscriber (as both could be different) and making sure that end user experience of using the API is not compromised while doing so.

Input params
N/A

Output params
N/A

Notifications
N/A

Notes
APIs around managing consent are expected to be contributed in this subproject. Certain concepts from this subproject will be contributed to the Commonalities WG.
Technical viabilityN/A
Commercial viabilityThere is no a direct commercial expectation from this API family -- it is an enabler instead. Identity and Consent Management API family includes one or more APIs which will allow other CAMARA APIs to be commercialized, provided those CAMARA APIs require user consent to be accessed as per in-scope data protection regulations.
YAML code available?N/A
Validated in lab/productive environments?No
Validated with real customers?No

Validated with operators?No