Personal Data Management

90 vues Markdown

Decide the erasure and anonymisation requests clients raise about their own data, and keep the cookie decisions visitors made as proof.

Reaching the Screen

Open Clients in the menu and choose Personal Data Management: {admin}/users/gdpr

The menu entry carries a counter for the requests still waiting on a decision, so a new one is visible without opening the page.

The page holds two tabs and each has its own address: {admin}/users/gdpr?gdprSection=requests and {admin}/users/gdpr?gdprSection=consent

What Is on the Screen

Two tabs, two separate records. They share the page and nothing else: each keeps its own list, its own filters and its own settings window.

Data Requests Erasure and anonymisation requests clients raised from their own account, waiting for you to decide.
Cookie Consent A record of every cookie decision a visitor made, filled only while record keeping is switched on.

Data requests

A note above the list repeats what is at stake: approving a request cannot be undone, because the data is either deleted outright or stripped of identity.

The list itself carries five columns:

Client Who asked, with a link through to the client record.
Request Type Delete Data or Anonymization of Data, whichever the client chose. A red mark next to it means the account still has services or unpaid invoices; hovering it gives the counts.
Request Date When the client raised it.
Process Status Pending Approval, Approved or Denied. A decided request also shows the date it was processed under the badge. Pending ones sort to the top.
Row menu View opens the request. Delete is offered in the row menu only for pending and denied requests; an approved one cannot be deleted from the row menu, but Apply to Selected still removes it from the list.

Above the list sit the status and type filters, a search box, a Configuration button that opens the settings for the whole feature, and an Apply to Selected box whose only action is deleting the ticked rows, whatever their status.

The request window

Opening a request shows the account behind it before anything else: who the client is, when the request came in, which type it is, how many active and how many inactive services the account holds, and how many invoices it has. Active Service counts active and suspended services together, Inactive Service covers every remaining status, and the invoice figure is the lifetime count rather than the unpaid one, so all of it is context and not a bill. Each of the three numbers links through to the matching list on the client record.

What comes below depends on the state of the request:

Still pending A Process Data Request card where the decision is made, plus a Send Notification card. The save button stays closed until a decision type is chosen.
Approved Read only: who approved it, which actions were applied, and the date. Nothing can be changed from here.
Denied Read only: who denied it and when, and the reason if one was written.

Choosing a decision type opens the section that belongs to it. Request Denied opens a reason box with the reasons you saved earlier. Anonymization of Data offers two mutually exclusive options and a blacklist tick. Destroy Data offers the single option that deletes the account.

A band above the list states the current position: with record keeping on it reports the retention period, and with it off it says so plainly, because an empty list there means "nothing is being recorded", not "no one consented". The cookie notice keeps running either way and no optional cookie is written before consent.

Each row is one decision:

Date When the decision was taken.
Decision Accepted All, Rejected All or Partial, read from the optional categories only.
Categories Every category the record covers, ticked or crossed. Essential is always on because it cannot be switched off.
Source The address and browser behind the decision. A decision taken while signed in also names the client; a guest decision has only its address.
Receipt The code that also sits in the visitor's own cookie. A disputed consent is checked by matching the two; hovering shows it in full.
Version Which version of the category set the visitor answered. Changing the categories raises the version and asks everyone again.

The filters above the list narrow by decision and by date range, the search box matches the address and the browser string, and Record Settings opens the switch and the retention period.

Fields

The decision form inside a pending request:

Process Data Request Required. The decision itself: Request Denied, Anonymization of Data or Destroy Data. The save button opens only once one is chosen.
Select saved reason... Optional, denial only. Picking one fills the reason box. The buttons beside it save the text you wrote for later use, or remove a saved one.
Reason/Explanation Optional, denial only. Kept on the request and shown when it is reopened; it is also what the client sees if a notification is sent.
Block Client Access One of the two anonymisation options. The account stays intact but sign in and password reset stop working.
Anonymize Data The other anonymisation option. Identifying details are masked with asterisks while the account and its history stay in place.
Add to Blacklist Optional. Prevents an account being created again with the same details.
Permanently Delete All Data The only option under Destroy Data. The client record and everything attached to it is deleted for good.
Send Notification Off by default. Ticked, the client is told the outcome; the wording comes from the notification templates, and approval and denial use different ones.

Configuration, on the Data Requests tab:

Status Turns the whole feature on. With it off the Personal Data tab does not appear in the client's account, so no new request can reach this list.
Authorization Requirement Off by default, and it only bites while Status is on. A client who has not accepted the agreement is held on the Personal Data tab: every other page of their panel sends them back there.
Agreement Page The agreement clients accept. The list holds the active agreement pages; leaving it unselected means the requirement has no text to point at.

Record Settings, on the Cookie Consent tab:

Keep consent records On by default. Each decision is stored with its date, address, browser and receipt. The record is personal data in its own right, so keep it because you carry the burden of proof, not out of habit.
Retention Between 1 and 3650 days, 395 by default. Records older than this are deleted automatically. Consent itself lapses after 365 days; thirteen months is the retention ceiling allowed for the record (CNIL), not the lifetime of the consent, so a longer window keeps proof of something that no longer holds.

Tasks

Approve a request

  1. Open the request with View from its row menu and read the account behind it: services, invoices and the mark on the type column.
  2. In Process Data Request, choose Anonymization of Data or Destroy Data.
  3. Pick the option that appears underneath, and tick Send Notification if the client should be told.
  4. Save. The row's status becomes Approved, the date it was processed appears under the badge, and the request drops below the pending ones.

Deny a request

  1. Open the request and choose Request Denied.
  2. Write the reason, or take one from Select saved reason...; the save icon beside it keeps the current text for next time.
  3. Tick Send Notification where the client should hear the reason.
  4. Save. The status becomes Denied and the reason stays on the request.
  1. Open Configuration on the Data Requests tab and turn Status on.
  2. Turn Authorization Requirement on and choose the Agreement Page clients must accept.
  3. Save Changes. From then on a client who has not accepted is sent to the Personal Data tab of their account until they do.
  1. Switch to Cookie Consent and open Record Settings.
  2. Turn Keep consent records on; the retention row appears with it.
  3. Set Retention in days and save. The band above the list turns informational and states the period, and decisions taken from then on land in the list.

Things to Watch

Approving cannot be undone

A processed request cannot be reopened, and the data it acted on does not come back. Permanently Delete All Data is the heaviest of the three: it removes the client record itself, along with everything attached to it. Read the services and invoices on the request before you decide, not after.

The decision type alone does nothing

The save button opens as soon as a type is chosen, but what actually happens comes from the option beneath it. Choosing Anonymization of Data without ticking one of its two options marks the request approved and changes no data at all. Pick the option before saving.

Denied without a reason usually means withdrawn

A client can withdraw a request they raised while it is still pending, and that lands in this list as Denied with no reason. If the request window shows no Reason for Denial card at all, nobody refused it: the client changed their mind. The Denied by line still reads Admin in that case, so it is not the field to check.

Required Privileges

The page belongs to USERS_GDPR. Without it the menu entry is not shown and the address returns access denied. Every action on the page follows the same privilege: opening a request, processing it, deleting one, the bulk delete, the configuration window and the consent record settings. Deleting more than one request at once also asks for your own password.

Cet article vous a-t-il été utile ?

Merci pour votre retour !

Besoin d'aide supplémentaire ?

Notre équipe d'assistance est disponible 24h/24 pour tout ce que vous ne trouvez pas ci-dessus.