- edited description
- Type: Editorial
- Subclause(s): 5.2.2.1
- Comments: The abbreviation “PII” seems to be first used here in this document “6. should not return sensitive PII in the ID Token in the authorization response, but if it needs to, then it should encrypt the ID Token”
- Proposed Change: Either rephrase “PII” to “Personally Identifiable Information (PII)” or “Personally Identifiable Information”.
- WG Accept / Reject: Partially accepted. Add PII to clause 4.