Conformità
Answers to common questions about data protection, sustainability, and accessibility for organizations using KDE software
Il software KDE è normalmente distribuito come applicazione desktop locale piuttosto che come servizio ospitato. Per questo motivo, molte delle domande sulla conformità che le organizzazioni pongono in genere ai fornitori di software, come le richieste di un accordo sul trattamento dei dati (DPA), un elenco dei subappaltatori o un questionario sulla sicurezza relativo all'hosting dei dati, non si applicano allo stesso modo come farebbero con un prodotto SaaS. Questa pagina spiega il motivo e cosa possiamo offrire in alternativa.
Le applicazioni desktop non hanno alcuna relazione con il processore.
Applicazioni come Okular, Kate, Krita, digiKam, e la maggioranza dell'altro software KDE, sono eseguite interamente nel dispositivo in cui sono installate. Esse non presentano un lato server, non chiamano il telefono di casa e non inviamo alcun documento o file in una parte qualsiasi della rete. Le operazioni di apertura, modifica, visualizzazione e stampa avvengono tutte localmente.
Poiché nessuno in KDE o nel progetto attinente al software non vede né gestisce i tuoi dati, non esiste alcuna relazione col processore in ottica RGPD (Regolamento generale sulla protezione dei dati, regolamento UE n. 2016/679). La tua organizzazione resta l'unica e la sola tenutaria dei tuoi dati in qualsiasi momento, come quando si una qualsiasi altro strumento locale offline. Questo implica anche che:
- non esiste alcun DPA (accordo di trattamento dei dati) da firmare, perché non vi è alcuna attività di elaborazione dati da parte di KDE da coprire;
- non esiste alcun elenco di subappaltatori da fornire, in quanto non vi sono terze parti coinvolte nella catena;
- il solo accesso di rete che si verifica è quello eseguito da te, come l'apertura di un file remoto o un URL. È una tua azione personale, non qualcosa che il software esegue per tuo conto.
Se il processo di acquisizione della tua organizzazione richiede la documentazione di ciò per i tuoi archivi, saremo lieti di fornirti una breve dichiarazione scritta a tal fine, anziché un accordo firmato. Contatta il Board di KDE e.V. per richiederne una.
Il codice sorgente è pubblico e verificabile
Tutto il software KDE è libero e open source, e lo sviluppo avviene in chiaro su invent.kde.org. Se il tuo processo di revisione trae vantaggio dall'ispezionare direttamente il codice, per esempio per confermare l'assenza di chiamate di rete, esso è disponibile per la lettura o la verifica.
Vulnerability reporting and disclosure
Security issues in KDE software can be reported to security@kde.org. Issues with KDE's own infrastructure (such as GitLab or Bugzilla) rather than with a specific application should go to sysadmin@kde.org instead.
Reports are handled according to the KDE Security Policy: the security team verifies the issue and works with the affected project's maintainers on a fix. Where an immediate public alert isn't necessary, the team instead coordinates a private advance-notice period with Linux distributors and other downstream packagers, so they can prepare updated packages before the fix and a public advisory are published at the same time. A CVE is requested for confirmed issues.
Every published advisory is listed on the KDE Security Advisories page, with a public record going back to 1998, so you can review KDE's actual disclosure track record and timelines directly rather than relying on our word for it. KDE does not currently run a bug bounty program.
Long-term support (LTS) releases
Plasma normally releases on a four-month cadence, with each stable release receiving six subsequent bugfix updates released over the next six months. Periodically, one release is additionally designated a “Long-Term Support” (LTS) release, receiving bug fixes and security updates for a longer period of time; typically 2-3 years.
Plasma 6.6 is the current LTS release, supported until approximately August 2029. This is the result of a commercial partnership between KDE Patrons Kubuntu Focus and Techpaladin Software, who fund continuous maintenance of Plasma 6.6, KDE Frameworks, and Gear applications, plus dedicated continuous-integration infrastructure to validate the software on an ongoing basis. See the initiative announcement for details, and get in contact with them if you'd like to join the initiative or sponsor LTS work in your own organization.
The work lands upstream, and while the initiative is anchored to Kubuntu 26.04 LTS, any distribution or organization is free to build and ship Plasma 6.6 LTS itself.
For the exact schedule, including future LTS designations as they're decided, see the Plasma 6 release schedule on the KDE Community wiki.
La telemetria, se presente, è opt-in (con consenso)
Some applications include optional, disabled-by-default telemetry that a user can choose to enable. Where this exists, only anonymous details about the software and device are ever transmitted, never document or file content, and it’s covered by our Privacy Policy. See the Telemetry Policy for details on what individual applications collect when this is turned on.
Online services are a different case
A small number of things KDE operates are genuine online services rather than local software, such as the KDE Bug Tracking System, the Discussion Forum, and KDE Identity. These do collect and process some personal information (such as an email address for account registration) in order to function. If your compliance question concerns one of these services specifically, see the KDE.org Privacy Policy for details of what each service collects and how it’s handled.
Sostenibilità
Software has an environmental footprint, and it’s increasingly common for organizations to ask about this as part of their own procurement or ESG requirements. As Free and Open Source Software, KDE applications are generally designed to run efficiently across a wide range of hardware, including older machines, which helps extend the useful life of existing devices rather than forcing new purchases to keep up with each release.
Okular was the first computer program in the world to receive Germany’s Blue Angel eco-label, recognizing it against criteria for sustainable software design such as resource efficiency, portability, and avoidance of forced obsolescence. This work is part of a broader, ongoing initiative: see eco.kde.org for more on our approach to energy-efficient software, related research, and which other projects have applied similar principles.
If your organization needs specific figures (energy consumption benchmarks, etc.) for a particular application, this varies project by project, so contact that application’s team to see what’s available.
Accessibilità
KDE aims for its software to be usable by people who rely on assistive technology, including screen readers, switch devices, and other alternative input methods. Plasma and most KDE applications are built on Qt, which provides accessibility APIs (AT-SPI on Linux, and equivalents on Windows and macOS) that our software integrates with to expose its interface to assistive tools, and contributors maintain Human Interface Guidelines covering accessible design.
Accessibility work in KDE is ongoing and carried out project by project rather than centrally certified, so we don’t currently maintain a formal conformance report (such as a VPAT against WCAG or EN 301 549) covering our applications, and a full accessibility audit only exists for a few of them. If your organization needs this kind of documentation for procurement purposes, for instance under the European Accessibility Act, let us know which application it’s for and we can put you in touch with that project’s maintainers to discuss what’s feasible. Background on our ongoing accessibility efforts is available on the Accessibility page of the KDE Community wiki.
This is also an area where we could use help: accessibility audits take real expertise and time that our volunteer maintainers often can’t spare, so if your organization has accessibility professionals able to contribute an audit for a KDE application, even informally, we’d very much appreciate it. Get in touch via the Accessibility page linked above, or with the application’s team directly.
If you or your users have hit a specific accessibility barrier in a KDE application, please report it as a bug so it can be fixed like any other issue.
Domande?
If none of the above answers your question, or you need something further for your own paperwork, please reach out. For questions about a specific application’s behavior, contact that application’s team. For anything relating to KDE e.V., the non-profit that represents the KDE Community in legal matters, get in touch with the Board.
If your organization needs paid support, custom development, or professional services (including help with the kind of audits mentioned above), the KDE e.V. Trusted IT Consulting Firms are a good place to start: an independently vetted list of firms with a track record in the KDE community.