Board Meeting Minutes - Data Privacy Introducing The ASF’s New Logo Read Now Toggle navigation Community Contributor Getting Started Becoming a Committer Code of Conduct Community Resources Community Over Code Events Projects Projects Incubator Projects Projects Directory M…
Board Meeting Minutes - Data Privacy Introducing The ASF’s New Logo Read Now Toggle navigation Community Contributor Getting Started Becoming a Committer Code of Conduct Community Resources Community Over Code Events Projects Projects Incubator Projects Projects Directory Mailing Lists Report a Vulnerability The Apache Attic Downloads Distributions Releases Learn Blog How the ASF Works The Apache Way Legal & Trademark Licenses Glossary FAQ Resources & Tools Developer Information Wiki Issues Slack Self Serve Portal Infrastructure Infrastructure Status Infrastructure Statistics Whimsy Brand Guidelines Project Logos About About Our Sponsors Corporate Sponsorship Individual Supporters Leadership Members Diversity & Inclusion Newsroom Contact Sponsor Search Board Meetings and Calendar, 2015 - Present Data Privacy This was extracted (@ 2026-07-15 23:10) from a list of minutes which have been approved by the Board. Please Note The Board typically approves the minutes of the previous meeting at the beginning of every Board meeting; therefore, the list below does not normally contain details from the minutes of the most recent Board meeting. ASF Members may have access to a private draft of these still-unapproved minutes. WARNING: these pages may omit some original contents of the minutes. This is due to changes in the layout of the source minutes over the years. Fixes are being worked on. 17 Jun 2026 [Christian Grobmeier] ¶ # General There are no issues that need urgent attention. ## Privacy Committee The _privacy committee_ is a group of volunteers actively working for more privacy towards the ASF. Committee members have become more active in supporting projects for a few weeks. ## Privacy complaints / Removal requests We have received multiple requests directed at VP-Privacy. The number of private complaints is generally rising, and the requests usually look valid, not automated. ## Drafting an AI recommendation I have been drafting a recommendation on the use of AI from a privacy perspective. Although I have already progressed far, I haven't yet completed it. This draft will be sent to the privacy@ list for further feedback and discussion first. Several questions came up in the past weeks, asking for clarification. # Open tasks I am currently reviewing the accuracy of our documentation. For that reason, I have not added any more open tasks. 20 May 2026 [Christian Grobmeier] ¶ A report was expected, but not received 15 Apr 2026 [Christian Grobmeier] ¶ A report was expected, but not received 18 Mar 2026 [Christian Grobmeier] ¶ A report was expected, but not received 18 Feb 2026 [Christian Grobmeier] ¶ A report was expected, but not received 21 Jan 2026 [Christian Grobmeier] ¶ # General There are no issues that need urgent attention. The last Data Privacy Report was in July 2025 and this report is for the period since the last report. ## Privacy Committee The _privacy committee_ are volunteers actively working for more privacy within the ASF. There are four members of the Privacy committee. ## Privacy complaints / Removal requests We received 2 requests since the last report in July 2025. ## Data Privacy Policies There are seven Data Privacy policies listed on the policies page: https://privacy.apache.org/policies/ The website policy was ratified by the board in January 2023 and the other six policies are all in DRAFT form. ### Telemetry Usage in Downloaded/Installed Software No work has been done on this since the last report. The Airflow PMC asked the Board about their Telemetry usage in their Board Report in September 2025 and received positive feedback. The current policy is still in DRAFT format: https://privacy.apache.org/policies/privacy-products-policy-medium.html ## Matomo The ASF started hosting its own Matomo instance in March 2022 to provide analytics for project websites that respected user's privacy: https://analytics.apache.org/ In November 2025 the handover of the Matomo instance and VM to the Infrastructure team was completed. The Privacy team appreciates all the work Infra has done to achieve this and the fact that Infra is now supporting Matomo. https://issues.apache.org/jira/browse/INFRA-26367 Currently, 78 Matomo _Tracking Codes_ have been issued, 9 since the last report in July 2025. There are 9 Matomo sites that don't receive traffic at this point. ## Content Security Policy (CSP) We continue to receive queries from projects about permissable modification of the Content Security Policy for their websites. ## Analytics Usage Campaign The _Privacy Committee_ receives a monthly report of ASF websites that utilise external trackers/analytics that are not permitted by the _Privacy Policy_. The number of websites using proscribed analytics on the monthly report has reduced from 103 to 3 in the last 12 months (-97%). # Open tasks - Provide guidelines for advertising user mailing lists - Create a list of WordPress sites - Create a list of domains that are allowed to connect because a DPA is covering it (improved Whimsy support) - Better documentation about DPAs - Add "canned responses" and instructions on how to run the privacy office to the website - Investigate TAC for data privacy and develop a targeted version for the committee - Clarify status of "donate.apache.org" - Clarify status of "status.apache.org" 17 Dec 2025 [Christian Grobmeier] ¶ A report was expected, but not received 19 Nov 2025 [Christian Grobmeier] ¶ A report was expected, but not received 15 Oct 2025 [Christian Grobmeier] ¶ A report was expected, but not received 24 Sep 2025 [Christian Grobmeier] ¶ A report was expected, but not received 20 Aug 2025 [Christian Grobmeier] ¶ A report was expected, but not received 16 Jul 2025 [Christian Grobmeier] ¶ # General There are no issues that need urgent attention. ## Privacy Committee The _privacy committee_ are volunteers actively working for more privacy within the ASF. There are four members of the Privacy committee. ## Privacy complaints / Removal requests We received 7 requests since the last report in March 2025, three of which came in directly to vp-privacy. ## Data Privacy Policies There are seven Data Privacy policies listed on the policies page: https://privacy.apache.org/policies/ The website policy was ratified by the board in January 2023 and the other six policies are all in DRAFT form. ### Telemetry Usage in Downloaded/Installed Software At the end of 2024 the Apache Airflow project initiated a discussion about the collection of telemetry data in installed Airflow instances. As a result of that discussion a DRAFT policy was developed: https://privacy.apache.org/policies/privacy-products-policy-medium.html Airflow recently revived that discussion seeking clarity on what the ASF policy is for their use-case and the committee is working with them on this with the aim of having a ratified policy that they can comply with. ## Matomo The ASF started hosting its own Matomo instance in March 2022 to provide analytics for project websites that respected user's privacy: https://analytics.apache.org/ Currently, 69 Matomo _Tracking Codes_ have been issued, 11 since the start of 2025. There are 7 Matomo sites that don't receive traffic at this point. Seven projects that were not using the Matomo tracking code generated for them were contacted in March to remind them that they were available for their use. This resulted in one projected starting to use Matomo. #### Responsibility for the Matomo VM Infra will take over the responsibility for the Matomo VM. The current progress is tracked here: https://issues.apache.org/jira/browse/INFRA-26367 ## New services A request to be able to use "dynamic images" from pepy.tech was received and the process to consider whether we want to sign a DPA with that Org is being considered. ## Content Security Policy The Infrastructure team implemented a _Content Security Policy_ (CSP) at the start of March 2025 which prevents project websites from using trackers or loading resources which are not permitted by the ASF Privacy Policy. Quite a few projects have issues to fix due to external resources that are now blocked by the CSP. There have been discussions around some external usage and whether they could be permitted under the Privacy Policy (e.g. sign a DPA) or provide a technical solution that would make usage compliant. ## Analytics Usage Campaign The _Privacy Committee_ receives a monthly report of ASF websites that utilise external trackers/analytics that are not permitted by the _Privacy Policy_. From December 2023 to January 2025, the number of ASF websites using proscribed analytics had reduced from 113 to 103 (-9%). In January 2025 the _Privacy Committee_ started a campaign to encourage projects to remove those analytics. The number of websites using proscribed analytics on the monthly report has now reduced to 9 (-91% since January 2025). # Open tasks - Provide guidelines for advertising user mailing lists - Create a list of WordPress sites - Create a list of domains that are allowed to connect because a DPA is covering it (improved Whimsy support) - Better documentation about DPAs - Add "canned responses" and instructions on how to run the privacy office to the website - Investigate TAC for data privacy and develop a targeted version for the committee - Clarify responsibility for the Matomo VM https://lists.apache.org/thread/6c7dn3ot494pxdlfxfn1pngbcpzj5g08 https://issues.apache.org/jira/browse/INFRA-25432 - Clarify status of "donate.apache.org" - Clarify status of "status.apache.org" 18 Jun 2025 [Christian Grobmeier] ¶ Nothing to report this month. 21 May 2025 [Christian Grobmeier] ¶ A report was expected, but not received 16 Apr 2025 [Christian Grobmeier] ¶ A report was expected, but not received 19 Mar 2025 [Christian Grobmeier] ¶ # General There are no issues that need urgent attention. ## Privacy Committee The _privacy committee_ are volunteers actively working for more privacy towards the ASF. Committee members have become more active supporting projects for a few weeks. ## Privacy complaints / Removal requests We received 4 requests since the start of 2025. Several others came in directly to vp-privacy. ## Matomo The ASF started hosting its own Matomo instance in March 2022 to provide analytics for project websites that respected user's privacy: https://analytics.apache.org/ Currently, 67 Matomo _Tracking Codes_ have been issued, 9 since the start of 2025. There are 9 Matomo sites that don't receive traffic at this point. #### Responsibility for the Matomo VM Infra will take over the responsibility for the Matomo VM. The current progress is tracked here: https://issues.apache.org/jira/browse/INFRA-26367 ## New services Project websites can embed Kapa.AI for an improved documentation experience. While a DPA is on file, ASF projects need to turn on the "explicit consent" option provided by Kapa.AI. ## Content Security Policy The Infrastructure team implemented a _Content Security Policy_ (CSP) at the start of March 2025 which prevents project websites from using trackers or loading resources which are not permitted by the ASF Privacy Policy. Quite a few projects have issues to fix due to external resources that are now blocked by the CSP. There have been discussions around some external usage and whether they could be permitted under the Privacy Policy (e.g. sign a DPA) or provide a technical solution that would make usage compliant. ## Analytics Usage Campaign The _Privacy Committee_ receives a monthly report of ASF websites that utilise external trackers/analytics that are not permitted by the _Privacy Policy_. From December 2023 to January 2025, the number of ASF websites using proscribed analytics had reduced from 113 to 103 (-9%). In January 2025 the _Privacy Committee_ started a campaign to encourage projects to remove those analytics. Issue Tickets were created for 87 projects which included PRs/patches for 67. Over the last two months, the number of websites using p…