Skip to content

Compliance

Answers to common questions about data protection, sustainability, and accessibility for organizations using KDE software

KDE Software is generally distributed as a local desktop application rather than as a hosted service. Because of this, many of the compliance questions organizations typically ask of software vendors, such as requests for a Data Processing Agreement (DPA), a subprocessor list, or a security questionnaire about data hosting, do not apply in the way they would to a SaaS product. This page explains why, and what we can offer instead.

Desktop applications have no processor relationship

Applications like Okular, Kate, Krita, digiKam, and most other KDE software run entirely on the device where they’re installed. They don’t have a server side, don’t phone home, and don’t send your document or file content anywhere over the network. Opening, editing, viewing, and printing all happen locally.

Because no one at KDE or in the relevant project ever sees or handles your data, there’s no processor relationship in the GDPR sense. Your organization remains the sole controller of your data at all times, just as it would using any other local, offline tool. This also means:

  • There’s no DPA to sign, because there’s no data processing activity by KDE to cover.
  • There’s no subprocessor list to provide, because there’s no third party anywhere in the chain.
  • The only network access that occurs is one you initiate yourself, such as opening a remote file or URL. That’s your own action, not something the software does on your behalf.

If your procurement process requires documentation of this for your records, we’re happy to provide a short written statement to that effect rather than a signed agreement. Contact the KDE e.V. Board to request one.

The source code is public and auditable

All KDE software is Free and Open Source, with development happening in the open on invent.kde.org. If your review process benefits from inspecting the code directly, for example to confirm the absence of network calls, it’s available for anyone to read or audit.

Telemetry, if present, is opt-in

Some applications include optional, disabled-by-default telemetry that a user can choose to enable. Where this exists, only anonymous details about the software and device are ever transmitted, never document or file content, and it’s covered by our Privacy Policy. See the Telemetry Policy for details on what individual applications collect when this is turned on.

Online services are a different case

A small number of things KDE operates are genuine online services rather than local software, such as the KDE Bug Tracking System, the Discussion Forum, and KDE Identity. These do collect and process some personal information (such as an email address for account registration) in order to function. If your compliance question concerns one of these services specifically, see the KDE.org Privacy Policy for details of what each service collects and how it’s handled.

Sustainability

Software has an environmental footprint, and it’s increasingly common for organizations to ask about this as part of their own procurement or ESG requirements. As Free and Open Source Software, KDE applications are generally designed to run efficiently across a wide range of hardware, including older machines, which helps extend the useful life of existing devices rather than forcing new purchases to keep up with each release.

Okular was the first computer program in the world to receive Germany’s Blue Angel eco-label, recognizing it against criteria for sustainable software design such as resource efficiency, portability, and avoidance of forced obsolescence. This work is part of a broader, ongoing initiative: see eco.kde.org for more on our approach to energy-efficient software, related research, and which other projects have applied similar principles.

If your organization needs specific figures (energy consumption benchmarks, etc.) for a particular application, this varies project by project, so contact that application’s team to see what’s available.

Accessibility

KDE aims for its software to be usable by people who rely on assistive technology, including screen readers, switch devices, and other alternative input methods. Plasma and most KDE applications are built on Qt, which provides accessibility APIs (AT-SPI on Linux, and equivalents on Windows and macOS) that our software integrates with to expose its interface to assistive tools, and contributors maintain Human Interface Guidelines covering accessible design.

Accessibility work in KDE is ongoing and carried out project by project rather than centrally certified, so we don’t currently maintain a formal conformance report (such as a VPAT against WCAG or EN 301 549) covering our applications, and a full accessibility audit only exists for a few of them. If your organization needs this kind of documentation for procurement purposes, for instance under the European Accessibility Act, let us know which application it’s for and we can put you in touch with that project’s maintainers to discuss what’s feasible. Background on our ongoing accessibility efforts is available on the Accessibility page of the KDE Community wiki.

This is also an area where we could use help: accessibility audits take real expertise and time that our volunteer maintainers often can’t spare, so if your organization has accessibility professionals able to contribute an audit for a KDE application, even informally, we’d very much appreciate it. Get in touch via the Accessibility page linked above, or with the application’s team directly.

If you or your users have hit a specific accessibility barrier in a KDE application, please report it as a bug so it can be fixed like any other issue.

Questions?

If none of the above answers your question, or you need something further for your own paperwork, please reach out. For questions about a specific application’s behavior, contact that application’s team. For anything relating to KDE e.V., the non-profit that represents the KDE Community in legal matters, get in touch with the Board.

If your organization needs paid support, custom development, or professional services (including help with the kind of audits mentioned above), the KDE e.V. Trusted IT Consulting Firms are a good place to start: an independently vetted list of firms with a track record in the KDE community.