On Thu, Jan 14, 2016 at 12:52 PM, Stas Malyshev <smalyshev@wikimedia.org> wrote:

> How easy is it to encode/include PII in a valid SPARQL query? Hmmm.

Well, theoretically you can just type your home address into query form
GUI and send it, but I don't think anybody does that :) At least not often.

But that wouldn't be valid SPARQL, so a validator could be used to filter out a lot of junk.

You should also refer to the Discovery data access guidelines Oliver has been working on. (On the Office wiki, so they are WMF internal at the moment.)