Skip to content

Personal Data Protection

Introduction

To comply with the GDPR directive on the protection of personal data, CCH Tagetik can run checks on the protection of personal data present in dataset fields. In particular, at the workspace level, it is possible to run checks on the status (protected/unprotected) of personal data and potentially run data processing to encrypt data.

For a field to be included in personal data protection checks and processing, it must have the Personal field protection option enabled in its properties. Only users with function 0004095 - Personal Data Protection enabled in their own role can enable this option and run checking operations.

Note: users who do not have this function enabled will see the personal data protection options in grey, but they cannot change them.

Personal data encoding

If the personal data protection option is active on the dataset field, the system encodes the field data on every save and decodes it to display it in the interface and in forms. All encoding and decoding activities run on the fields are recorded in the audit log files.

Note: the encoding and decoding of personal data can be overridden by the workspace settings.

Actions on personal data contained in the workspace

The following actions can be performed on personal data individually, but never simultaneously:

Action Description
Data protection check Checks that the data on all reporting layer partitions ($ - Reporting Layer type), for datasets containing data or dimensions for which personal data protection is active, are properly encrypted. Can return the following results: - Data protection check never executed: the data encryption must be checked, applied or removed. - All your personal data are properly protected. - Your personal data are not properly protected: no data for which protection is active are encrypted. - Your personal data are not protected: some data for which protection is active are not encrypted.
Apply Data Protection Identifies the data on all reporting layer partitions ($ - Reporting Layer type) for which personal data protection is active and encrypts them, if not yet properly encrypted.
Remove Data Protection Identifies the data on all reporting layer partitions ($ - Reporting Layer type) for which personal data protection is active and removes the encryption if they are already encrypted.

IMPORTANT: to run these actions, the workspace must be offline, but the relative datasets must be online.

Particular features of personal data protection

  • The personal data protection option is only available for the text fields of a dataset.
  • If the dataset is offline, or online but has no partitions, the personal data protection option can only be enabled. If the dataset contains partitions and is online, then the option is visible but cannot be changed.
  • Neither default values nor dictionaries can be used on fields for which personal data protection is active.
  • A label (Personal data tracking label) can be associated with dataset fields for which sensitive data protection is active. These labels have a maximum length of 50 characters, only accept ISO LATIN characters and cannot be reserved key words or labels already in use in the dataset. If left empty, these fields take the value of the label. Labels are tracked in the audit log files.