Responsible data management
Many states have laws in place to protect personal data. In the EU, protection of this data is addressed by the General Data Protection Regulation (GDPR). This regulation aims to ensure several rights, under which a person’s right that their data is stored for reasonable retention periods only (Art. 5e GDPR). TOPdesk software comes with anonymization features and we recommend the following best practices in order for your organization to meet the demand of the GDPR. Want to learn more about the GDPR before coming up with data retention procedures for your organization? Head over to My TOPdesk.
Put an anonymization procedure in place for employees who left your organization
Use the person and operator anonymization to have TOPdesk anonymize personal information in cards after a custom archive period.
Have personal data removed from person and operator cards
Set up a custom anonymization period for archived person and operator cards separately. Configure TOPdesk to anonymize or delete data for each linked card type.
Note
To set up the automated anonymization, go to Functional Settings > Responsible data management > Personal data protection > Anonymize persons / operators / delete data in closed cards .
Have content deleted from old cards
To protect data of users who are still active in your organization, have TOPdesk delete card content when it is no longer relevant. After a period you choose, the Delete data in closed cards feature deletes the following information from closed cards: request, action, and brief description. Caller-related information will be left as-is, except in the case of unregistered caller data which is removed. When you have person-based anonymizations in place, these won't be interfered with during this process.
Note
To set up this anonymization, go to Functional Settings > Responsible data management > Personal data protection > Delete data in closed cards.
Have attachments regularly deleted
Do users upload attachments in TOPdesk that contain personal information? Then you will need to delete these files regularly. Use the File maintenance functionality to clean up attachments. The feature allows you to determine for each process how long you want to keep attached files.
Note
To have attachments automatically deleted, go to Functional Settings > Responsible data management > File maintenance.
Limit the lifetime of your TOPdesk database backups
As a SaaS customer, you’re off the hook here. In its procedures for data handling and retention, TOPdesk has taken the GDPR requirements into account.
When you’re an on-premises customer, TOPdesk advises that you include a time limit in your backup rotation. For instructions, please refer to the documentation of your backup system vendor.