Talk:Ombuds commission
Add topic| We welcome speakers of all languages in this discussion. Please comment here in any language you wish; staff or other volunteers will translate your comments to English if possible. |
| This page is for discussions related to the Ombuds commission page and about the Commission itself.
Please remember to:
For older conversations you can see the archive index. SpBot archives all sections tagged with {{Section resolved|1=~~~~}} after 3 days or sections whose most recent comment is older than 60 days. |
SpBot archives all sections tagged with {{Section resolved|1=~~~~}} after 3 days and sections whose most recent comment is older than 60 days.
|
Applicability of the 2025 advice on CU data sharing to a proposed ArbCom–CheckUser framework on zhwiki
[edit]Dear members of the Ombuds Commission,
I am an editor on Chinese Wikipedia, writing in my personal capacity. Our community is holding a Request for Comment on adjustments to our arbitration mechanism (zh:WP:RFC/ARB2026, comment period ending 12 July 2026 AoE). I have participated in the discussion and have been preparing participant summaries for the eventual closer; this inquiry conveys compliance questions raised by multiple participants that remain unresolved. It does not represent the community, the RfC initiator, or any official body.
One of the proposals under discussion is a standing collaboration framework between our Arbitration Committee and local CheckUsers. Under this framework, arbitrators would not hold CheckUser permissions themselves; instead, the Committee would submit check requests to local CheckUsers through a non-public channel, and CheckUsers would report findings back. Some arbitrators may have signed the ANPDP (Access to Nonpublic Personal Data Policy); others, due to residence in regions the Foundation has assessed as high-risk, cannot sign it and would receive only redacted technical conclusions.
During the discussion, participants raised the Commission's 2025 advice to CheckUsers and the 2026 statement on disclosure of CU data, which indicate that CU data should only be shared with users holding the same permissions. I would be grateful for your guidance on the following:
- Does the principle that CU data may only be shared with holders of the same permission admit any exception where the recipient (a) has signed the ANPDP, and (b) has been explicitly authorized by local community consensus to receive case-relevant findings in an arbitration context?
- If such an exception is possible, what would constitute valid "authorization" — is a local RfC consensus sufficient, or is confirmation from the Foundation (e.g. Legal or Trust & Safety) also required?
- If no exception is possible, is it compliant for CheckUsers to provide the Arbitration Committee with redacted technical conclusions only (e.g. "accounts A and B are technically related"), without disclosing underlying IP or user-agent data?
The discussion currently leans toward making the framework's entry into force conditional on compliance being confirmed, so your guidance will be directly relevant to how the closer and the community frame the final outcome. A link to this thread will be provided on the RfC page for community reference. Thank you for your time. Taiwania Justo (talk) 05:00, 4 July 2026 (UTC)
- Related discussions: U4C and T&S. Taiwania Justo (talk) 05:46, 4 July 2026 (UTC)
- Dear Taiwania Justo,
- I can confirm that the Ombuds Commission has noted you request. However, we will have to discuss this internally before providing answers to your questions. We will reach out to you once this is done. --Ameisenigel (talk) 06:40, 7 July 2026 (UTC)
