Redacting identified personal data

Plan requirement

Subscription Any plan
Access Admin

Removing one person's data from across your tickets. What the tooling does, and the part that stays manual.

Work through it

  1. Verify the request and who is making it.
  2. Find the person's user record.
  3. List their tickets, and tickets where they appear without being the requester.
  4. Redact or delete according to what you decided.
  5. Record what you did.

The hard part is finding it all

Their own tickets are easy. What is harder: tickets where they were CC'd, tickets raised by a colleague that mention them, attachments containing their details, and messages where they used a different address.

A search on one email address finds the obvious cases and gives false confidence about the rest.

Check for other addresses

People write in from work and from home, and from an old address before they changed it. Look at the user record for alternates before concluding you have found everything.

Redact rather than delete, usually

Deleting the user removes the record and can leave tickets that no longer make sense. Redacting removes the personal data and keeps the history, which is normally the better outcome for both obligations.

Decide what you must keep

Some records must be retained for tax, contractual or legal reasons. Work out the scope before starting, because the removal itself cannot be reversed.

Write it down

Who asked, when, how you verified them, what you removed, what you kept and why. That record is the evidence if the request is ever questioned.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.