Full text
2nd CRAFT-OA Summer School for Journal Editors - GDPR Dulip Withanage Technische Informationsbibliothek (TIB) 24. June 2025 2nd CRAFT-OA Summer School for Journal Editors - GDPR 1 / 18
Contents 1GDPR introduction 2GDPR Issues in OJS 3.3 3OJS/OMP/OPS 3.5 Invitation model 4Conclusion 2nd CRAFT-OA Summer School for Journal Editors - GDPR 2 / 18
Introduction to GDPR GDPR is a comprehensive data protection law that has been in effect since 2018 in the EU. It gives individuals control over their personal data and harmonizes data protection laws across the EU. Non-compliance can lead to fines up to 20 million euros ?. 2nd CRAFT-OA Summer School for Journal Editors - GDPR GDPR introduction 3 / 18
Definition of Personal Data under GDPR General Data Protection Regulation (GDPR) personal data means: “Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person” (?). 2nd CRAFT-OA Summer School for Journal Editors - GDPR Definition of Personal Data under GDPR 4 / 18
Core GDPR Principles Lawfulness, Fairness, and Transparency , through Consent. Purpose Limitation Data Minimization Accuracy Storage Limitation Integrity and Confidentiality Accountability 2nd CRAFT-OA Summer School for Journal Editors - GDPR Definition of Personal Data under GDPR 5 / 18
Implementing GDPR in Software Development Requirements Analysis: Identify personal data and data flows. Design Systems: consent mechanisms, Secure storage, encryption Development: Consent management, user rights support. Testing: Security audits, penetration testing. 2nd CRAFT-OA Summer School for Journal Editors - GDPR Definition of Personal Data under GDPR 6 / 18
Key Features for GDPR Compliance Explicit, auditable consent management. User rights support: access, correction, deletion, portability. Data encryption and access controls. Privacy by design and default. 2nd CRAFT-OA Summer School for Journal Editors - GDPR Definition of Personal Data under GDPR 7 / 18
Summary Table Principle/Feature Implementation Example Lawfulness & Transparency Clear privacy policies and consent forms Purpose Limitation Data collected only for specified functions Data Minimization Collect only essential data Accuracy User data correction tools Storage Limitation Automate dduplicate data deletion Integrity & Confidentiality Encryption, access controls Accountability Documentation and audit trails Consent Management Consent dashboards, opt-in/out User Rights Self-service data access and deletion 2nd CRAFT-OA Summer School for Journal Editors - GDPR Definition of Personal Data under GDPR 8 / 18
GDPR Issues in OJS 3.3 Editorial Workflow Key Challenges: Authors must provide personal data at submission. Journal managers can create/edit/delete/merge users (without consent) Journal managers can search for users in other journals by email Editors, reviewers, and others access personal data in workflow. Users do not have automated means to request deletion of personal data Authors may need means to access, edit, or request deletion of their data. Only declined submissions can be deleted for erasure requests. Submission and document libraries store potentially sensitive files from multiple journals. Editorial actions and communications are logged (a gray area / merge tool is not enough). Privacy policy must describe data handling at each workflow stage. 2nd CRAFT-OA Summer School for Journal Editors - GDPR GDPR Issues in OJS 3.3 9 / 18
Development Summary OJS GDPR compatible by Design OJS Core development Addresses community feedback and improves user management workflows. Ensures compliance with GDPR and other privacy regulations. Establishes a robust foundation for future enhancements in OJS. needs an email server by design Used general references ? ? Used transaltion tools ? 2nd CRAFT-OA Summer School for Journal Editors - GDPR Conclusion 16 / 18
Invitation Window 2nd CRAFT-OA Summer School for Journal Editors - GDPR Conclusion 17 / 18
References 2nd CRAFT-OA Summer School for Journal Editors - GDPR Conclusion 18 / 18