Re: [security-services] SAML deployments that use consent step?

From
Josh Howlett <>
Date
2009-11-11T22:09:53+00:00
ID
Thread
Re: [security-services] SAML deployments that use consent step?
I previously wrote that:
> There is certainly a place for consent, but it needs to be used  
> judiciously. It is certainly not (in the EU context, at least) the  
> silver bullet or "best practice" that proponents of "user centric"  
> approaches sometimes suggest.

One of my colleagues who specialises in DP law (and understands this  
stuff, unlike me) informed me today that the UK Information  
Commissioner's Office (the body charged with "upholding information  
rights in the public interest") has issued a statement to the effect  
that consent should be considered the cause-of-last-resort for  
releasing PII.

josh.