Trust negotiation II: Client-side decisions.


  • Match server's access control and privacy policies against user's privacy preferences.
  • This happens in the client's reasoner module.
  • Principle of data minimization: Provide as little personal information as possible.

Privacy preferences

1. Social security number is only given out for social security purposes.
2. Copies of the passport must be deleted after 7 days.
3. Information about the (anonymous) driver's license credential must be deleted after 8 days.
4. We insist that personal information only be processed at facilities certified by Trusty Security Services.