13. Privacy Considerations
This specification suggests status values to denote contact and registrant information that has been marked as private and/or has been removed or obscured. See Section 10.2.2 for the complete list of status values. The following status codes SHOULD be used to describe data elements of a response when appropriate:
-
private -- The object is not to be shared in query responses, unless the user is authorized to view this information.
-
removed -- Data elements within the object have been collected but have been omitted from the response. This option can be used to prevent unauthorized access to associated object instances without the need to mark them as private.
-
obscured -- Data elements within the object have been collected, but the response value has been altered so that values are not easily discernible. A value changed from "1212" to "XXXX" is an example of obscured data. This option may reveal privacy sensitive information and should only be used when data sensitivity does not require a more protective option like "private" or "removed".
See Appendix A.1 for an example of applying those values to contacts and registrants.