Federation - Privacy Risk Assessment for RPs Sharing a Pairwise Pseudonymous Identifier, v1.0

A federation member that shares pairwise pseudonymous identifiers, because of a specific mission need, must thoroughly document the risk of this sharing within their privacy risk assessment.

Assessment Step

1
Sharing Identifier Risks (SharingIdentifierRisks)
Does the federation member that shares pseudonymous identifiers properly document the risks of this sharing within their privacy risk assessments?
Artifact
A1
Provide evidence (e.g., policies, federation rules, privacy risk assessments) that the federation member is aware of the risks associated with shared identifiers.

Conformance Criteria (1)

C1
Normally, the pair-wise identifiers SHALL only be known by and used by one pair of endpoints (e.g., IdP-RP). However, an IdP MAY generate the same identifier for a subscriber at multiple RPs at the request of those RPs, provided: (1) Those RPs have a demonstrable relationship that justifies an operational need for the correlation, such as a shared security domain or shared legal ownership; and (2) All RPs sharing an identifier consent to being correlated in such a manner. The RPs SHALL conduct a privacy risk assessment to consider the privacy risks associated with requesting a common identifier.
Citation
NIST SP 800-63C
Section 6.3.2