//Instructions //
# Define the problem or opportunity (WHAT).
# Outline the importance of addressing the problem or opportunity (WHY).
= WHAT?
**In one sentence, what is the problem or opportunity?**
The absence of a clear policy on the use of third-party resources in Wikimedia projects creates security and privacy risks for Wikimedia users, while exposing the Foundation to financial and reputational damage.
**What does the future look like if this is achieved? **
- Security and Privacy risks associated with the use of third-party resources is considerably lowered
- Should third-party resources prove necessary, users allowing them are sufficiently educated about their risk and have consented to it
- A culture of security and privacy is increasingly promoted across across the Wikimedia ecosystem, especially among technical contributors
- The Foundation avoids reputational damage ([[ https://commons.wikimedia.org/wiki/Commons:Village_pump/Proposals/Archive/2021/02#Use_of_off-wiki_surveys_using_third-party_tools | example ]]), privacy violations, and financial loss due to misuse of third-party resources
**What happens if we do nothing?**
- There is continued confusion about the handling of third-party resources in Wikimedia projects (eg: T230124)
- Unmitigated security and privacy risks related to third-party resources are exploited, leading to violation of user's privacy and platform integrity
- Users face real-life safety consequences because ill-intended third parties stood with between their data and the Wikimedia platform.
- Foundation’s reputation is damaged if a user’s privacy or security is compromised as a result of its platform not policing the use of third party resources
= WHY?
**Identify the value(s) this problem/opportunity provides. Add links to relevant OKRs. **
//Rank values in order of importance and be explicit about who this benefits and where the value is.//
**User Value/Organization Value AND Objective it supports and How**
# Clear guidelines on how Wikimedia users should treat third-party resources
# Baseline for discussion and mitigation of issues related to third-party resources
# Raise awareness among contributors and Foundation staff on privacy and security best practice
**Why are you bringing this decision to the Technical Forum?**
//What about the scope of this problem led you and your team to seek input across departments/organizations?//
- The use of third-party resources impacts thousands of users across Wikimedia projects (Cf. T275754, T65598)
- Any change to it will involve collaborating with various stakeholders, both within the Foundation and outside.
- This issue needs broader visibility so as to gather valuable feedback