İçeriğe atla

Uyum

Veri güvenliği, sürdürülebilirlik ve KDE yazılımlarını kullanan organizasyonlar için erişilebilirlik hakkındaki sıkça sorulan sorulara yanıtlar

KDE Software is generally distributed as a local desktop application rather than as a hosted service. Because of this, many of the compliance questions organizations typically ask of software vendors, such as requests for a Data Processing Agreement (DPA), a subprocessor list, or a security questionnaire about data hosting, do not apply in the way they would to a SaaS product. This page explains why, and what we can offer instead.

Desktop applications have no processor relationship

Applications like Okular, Kate, Krita, digiKam, and most other KDE software run entirely on the device where they’re installed. They don’t have a server side, don’t phone home, and don’t send your document or file content anywhere over the network. Opening, editing, viewing, and printing all happen locally.

Because no one at KDE or in the relevant project ever sees or handles your data, there’s no processor relationship in the GDPR sense. Your organization remains the sole controller of your data at all times, just as it would using any other local, offline tool. This also means:

  • There’s no DPA to sign, because there’s no data processing activity by KDE to cover.
  • There’s no subprocessor list to provide, because there’s no third party anywhere in the chain.
  • The only network access that occurs is one you initiate yourself, such as opening a remote file or URL. That’s your own action, not something the software does on your behalf.

If your procurement process requires documentation of this for your records, we’re happy to provide a short written statement to that effect rather than a signed agreement. Contact the KDE e.V. Board to request one.

The source code is public and auditable

All KDE software is Free and Open Source, with development happening in the open on invent.kde.org. If your review process benefits from inspecting the code directly, for example to confirm the absence of network calls, it’s available for anyone to read or audit.

Vulnerability reporting and disclosure

Security issues in KDE software can be reported to security@kde.org. Issues with KDE's own infrastructure (such as GitLab or Bugzilla) rather than with a specific application should go to sysadmin@kde.org instead.

Reports are handled according to the KDE Security Policy: the security team verifies the issue and works with the affected project's maintainers on a fix. Where an immediate public alert isn't necessary, the team instead coordinates a private advance-notice period with Linux distributors and other downstream packagers, so they can prepare updated packages before the fix and a public advisory are published at the same time. A CVE is requested for confirmed issues.

Every published advisory is listed on the KDE Security Advisories page, with a public record going back to 1998, so you can review KDE's actual disclosure track record and timelines directly rather than relying on our word for it. KDE does not currently run a bug bounty program.

Long-term support (LTS) releases

Plasma normally releases on a four-month cadence, with each stable release receiving six subsequent bugfix updates released over the next six months. Periodically, one release is additionally designated a “Long-Term Support” (LTS) release, receiving bug fixes and security updates for a longer period of time; typically 2-3 years.

Plasma 6.6 is the current LTS release, supported until approximately August 2029. This is the result of a commercial partnership between KDE Patrons Kubuntu Focus and Techpaladin Software, who fund continuous maintenance of Plasma 6.6, KDE Frameworks, and Gear applications, plus dedicated continuous-integration infrastructure to validate the software on an ongoing basis. See the initiative announcement for details, and get in contact with them if you'd like to join the initiative or sponsor LTS work in your own organization.

The work lands upstream, and while the initiative is anchored to Kubuntu 26.04 LTS, any distribution or organization is free to build and ship Plasma 6.6 LTS itself.

For the exact schedule, including future LTS designations as they're decided, see the Plasma 6 release schedule on the KDE Community wiki.

Telemetry, if present, is opt-in

Some applications include optional, disabled-by-default telemetry that a user can choose to enable. Where this exists, only anonymous details about the software and device are ever transmitted, never document or file content, and it’s covered by our Privacy Policy. See the Telemetry Policy for details on what individual applications collect when this is turned on.

Online services are a different case

A small number of things KDE operates are genuine online services rather than local software, such as the KDE Bug Tracking System, the Discussion Forum, and KDE Identity. These do collect and process some personal information (such as an email address for account registration) in order to function. If your compliance question concerns one of these services specifically, see the KDE.org Privacy Policy for details of what each service collects and how it’s handled.

Sustainability

Software has an environmental footprint, and it’s increasingly common for organizations to ask about this as part of their own procurement or ESG requirements. As Free and Open Source Software, KDE applications are generally designed to run efficiently across a wide range of hardware, including older machines, which helps extend the useful life of existing devices rather than forcing new purchases to keep up with each release.

Okular was the first computer program in the world to receive Germany’s Blue Angel eco-label, recognizing it against criteria for sustainable software design such as resource efficiency, portability, and avoidance of forced obsolescence. This work is part of a broader, ongoing initiative: see eco.kde.org for more on our approach to energy-efficient software, related research, and which other projects have applied similar principles.

If your organization needs specific figures (energy consumption benchmarks, etc.) for a particular application, this varies project by project, so contact that application’s team to see what’s available.

Accessibility

KDE aims for its software to be usable by people who rely on assistive technology, including screen readers, switch devices, and other alternative input methods. Plasma and most KDE applications are built on Qt, which provides accessibility APIs (AT-SPI on Linux, and equivalents on Windows and macOS) that our software integrates with to expose its interface to assistive tools, and contributors maintain Human Interface Guidelines covering accessible design.

Accessibility work in KDE is ongoing and carried out project by project rather than centrally certified, so we don’t currently maintain a formal conformance report (such as a VPAT against WCAG or EN 301 549) covering our applications, and a full accessibility audit only exists for a few of them. If your organization needs this kind of documentation for procurement purposes, for instance under the European Accessibility Act, let us know which application it’s for and we can put you in touch with that project’s maintainers to discuss what’s feasible. Background on our ongoing accessibility efforts is available on the Accessibility page of the KDE Community wiki.

This is also an area where we could use help: accessibility audits take real expertise and time that our volunteer maintainers often can’t spare, so if your organization has accessibility professionals able to contribute an audit for a KDE application, even informally, we’d very much appreciate it. Get in touch via the Accessibility page linked above, or with the application’s team directly.

If you or your users have hit a specific accessibility barrier in a KDE application, please report it as a bug so it can be fixed like any other issue.

Questions?

If none of the above answers your question, or you need something further for your own paperwork, please reach out. For questions about a specific application’s behavior, contact that application’s team. For anything relating to KDE e.V., the non-profit that represents the KDE Community in legal matters, get in touch with the Board.

If your organization needs paid support, custom development, or professional services (including help with the kind of audits mentioned above), the KDE e.V. Trusted IT Consulting Firms are a good place to start: an independently vetted list of firms with a track record in the KDE community.