Skip to content

Conversation

jogu
Copy link
Contributor

@jogu jogu commented Oct 9, 2025

This bulks out the privacy considerations section a bit as it was looking pretty empty.

The same language is used as we used for a similar sentence about security considerations, as added in #296

This bulks out the privacy considerations section a bit as it was looking
pretty empty.

The same language is used as we used for a similar sentence about security
considerations.

# Privacy Considerations

Note that privacy considerations for OpenID for Verifiable Credential Issuance are defined in Section 15 of [@!OIDF.OID4VCI] and for OpenID for Verifiable Presentations in Section 15 (for redirect based flows) or Section A.6 (for DC API) of [@!OIDF.OID4VP].
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Note that privacy considerations for OpenID for Verifiable Credential Issuance are defined in Section 15 of [@!OIDF.OID4VCI] and for OpenID for Verifiable Presentations in Section 15 (for redirect based flows) or Section A.6 (for DC API) of [@!OIDF.OID4VP].
Privacy considerations for OpenID for Verifiable Credential Issuance are defined in Section 15 of [@!OIDF.OID4VCI] and for OpenID for Verifiable Presentations in Section 15 (for redirect based flows) or Section A.6 (for DC API) of [@!OIDF.OID4VP].
They MUST be followed where applicable.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think if we're changing the language here we should probably change it for security considerations too unless there's a reason for them to differ?

"MUST be followed where applicable" it kind of like a SHOULD, and at least the VCI privacy considerations already have SHOULDs (which are already normative when following HIAP) - I'm not sure what the aim of adding normative text here is?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed on today's WG call; consensus to keep the same form as we used for security considerations and as is currently used in this PR, i.e. that we're not trying to change the normative status of the existing privacy considerations.

@Sakurann Sakurann added this to the 1.0 Final milestone Oct 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants