CARL Source
GDPR consent
GDPR > GDPR consent

CARL Source allows, according to the rules of GDPR, to consent (or otherwise) to the anonymization of certain personal data (e.g. phone numbers, addresses, contacts).

If the user consents to the anonymization of such data, an anonymization date is automatically calculated for it, based on the retention period defined in the dictionary.

If the user refuses this consent, the data is automatically set to "Inactive". It is therefore no longer usable in the application.

The standard scope of consent includes the following functions:

The "GDPR" checkbox on theattributes of objects is used to indicate which data will be taken into account in the anonymization mechanism.

Only objects in the dictionary with the "GDPR" checkbox checked are taken into account for GDPR; it is then essential to specify a data retention period.

A setting on the User form lets you define the data anonymization consent mode:

However, users can access the consent at any time via the "Access to GTU" menu to change their choice.

 

Data can be anonymized:

During anonymization, two types of jobs are performed:

  1. Deletion of data not essential for database consistency. This anonymization thus involves purging contact and address information (phone, e-mail, address, etc.).
  2. Changing of data so as not to lose the database history (and the consistency check by the physical model). This anonymization involves changing the attribute value.

For further information on data anonymization jobs, see the next page.

Only the administrator can do this (profile right: System -> Global -> Manage consent) to accept or refuse consent for the following functions:

... however, the administrator can never avoid the user's consent.