Personal Data Management
Decide the erasure and anonymisation requests clients raise about their own data, and keep the cookie decisions visitors made as proof.
Reaching the Screen
Open Clients in the menu and choose Personal Data Management: {admin}/users/gdpr
The menu entry carries a counter for the requests still waiting on a decision, so a new one is visible without opening the page.
The page holds two tabs and each has its own address: {admin}/users/gdpr?gdprSection=requests and {admin}/users/gdpr?gdprSection=consent
What Is on the Screen
Two tabs, two separate records. They share the page and nothing else: each keeps its own list, its own filters and its own settings window.
Data requests
A note above the list repeats what is at stake: approving a request cannot be undone, because the data is either deleted outright or stripped of identity.
The list itself carries five columns:
Above the list sit the status and type filters, a search box, a Configuration button that opens the settings for the whole feature, and an Apply to Selected box whose only action is deleting the ticked rows, whatever their status.
The request window
Opening a request shows the account behind it before anything else: who the client is, when the request came in, which type it is, how many active and how many inactive services the account holds, and how many invoices it has. Active Service counts active and suspended services together, Inactive Service covers every remaining status, and the invoice figure is the lifetime count rather than the unpaid one, so all of it is context and not a bill. Each of the three numbers links through to the matching list on the client record.
What comes below depends on the state of the request:
Choosing a decision type opens the section that belongs to it. Request Denied opens a reason box with the reasons you saved earlier. Anonymization of Data offers two mutually exclusive options and a blacklist tick. Destroy Data offers the single option that deletes the account.
Cookie consent
A band above the list states the current position: with record keeping on it reports the retention period, and with it off it says so plainly, because an empty list there means "nothing is being recorded", not "no one consented". The cookie notice keeps running either way and no optional cookie is written before consent.
Each row is one decision:
The filters above the list narrow by decision and by date range, the search box matches the address and the browser string, and Record Settings opens the switch and the retention period.
Fields
The decision form inside a pending request:
Configuration, on the Data Requests tab:
Record Settings, on the Cookie Consent tab:
Tasks
Approve a request
- Open the request with View from its row menu and read the account behind it: services, invoices and the mark on the type column.
- In Process Data Request, choose Anonymization of Data or Destroy Data.
- Pick the option that appears underneath, and tick Send Notification if the client should be told.
- Save. The row's status becomes Approved, the date it was processed appears under the badge, and the request drops below the pending ones.
Deny a request
- Open the request and choose Request Denied.
- Write the reason, or take one from Select saved reason...; the save icon beside it keeps the current text for next time.
- Tick Send Notification where the client should hear the reason.
- Save. The status becomes Denied and the reason stays on the request.
Require the data processing agreement
- Open Configuration on the Data Requests tab and turn Status on.
- Turn Authorization Requirement on and choose the Agreement Page clients must accept.
- Save Changes. From then on a client who has not accepted is sent to the Personal Data tab of their account until they do.
Keep consent records
- Switch to Cookie Consent and open Record Settings.
- Turn Keep consent records on; the retention row appears with it.
- Set Retention in days and save. The band above the list turns informational and states the period, and decisions taken from then on land in the list.
Things to Watch
A processed request cannot be reopened, and the data it acted on does not come back. Permanently Delete All Data is the heaviest of the three: it removes the client record itself, along with everything attached to it. Read the services and invoices on the request before you decide, not after.
The save button opens as soon as a type is chosen, but what actually happens comes from the option beneath it. Choosing Anonymization of Data without ticking one of its two options marks the request approved and changes no data at all. Pick the option before saving.
A client can withdraw a request they raised while it is still pending, and that lands in this list as Denied with no reason. If the request window shows no Reason for Denial card at all, nobody refused it: the client changed their mind. The Denied by line still reads Admin in that case, so it is not the field to check.
Required Privileges
The page belongs to USERS_GDPR. Without it the menu entry is not shown and the address returns access denied. Every action on the page follows the same privilege: opening a request, processing it, deleting one, the bulk delete, the configuration window and the consent record settings. Deleting more than one request at once also asks for your own password.
Related Articles
Merci pour votre retour !
Notre équipe d'assistance est disponible 24h/24 pour tout ce que vous ne trouvez pas ci-dessus.