Re: [webauthn] Cross-origin credential creation in iframes (#1656)

These are not my concerns, Natalie - they are the law in the EU and California - at least, this is what I've paid attention to so far. :-)  I know there are many more privacy laws all over the world - here are 2 sites that are helpful in tracking them: in the [US](https://iapp.org/resources/article/us-state-privacy-legislation-tracker/), and [globally](https://www.dlapiperdataprotection.com/).

Article 7 of GDPR and Section 999.305 of CCPA speak to an RP's responsibilities regarding disclosure to, and consent from the Consumer. WRT the mechanics and compliance with the entire law, you should really be speaking to your lawyer(s) about this.

-- 
GitHub Notification of comment by arshadnoor
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1656#issuecomment-893394338 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 5 August 2021 11:47:44 UTC