eStealth Profiles

February 18, 2022

What is a Profile?

eStealth’s profiles are configuration files that describe everything related to data protection and privacy in a single place. They are the result of your initial analysis and assessment phase.

Contents

Puposes

GDPR requires that all sensitive data is only ever stored and/or processed for a clearly defined purpose. The profile defines which purposes exist and which data attributes are covered by which purpose. Each definition includes a technical identifier, expiration rules, and localized labels and descriptions for display in the self-service portal and in reports.

Attributes

Each sensitive data attribute needs to be declared in the profile. This tells the vault which attributes to allow into the vault, and how to process them. Each definition includes technical field identifier, data validation rules, data access rules, normalization rules, and localized labels and descriptions for display in the self-service portal and in reports.

Roles

eStealth enforces role-based access control. Every access to data is authorized and processed within the context of a role. The profile defines which roles exist, for which purposes a role may access data, and which attributes a role may read and/or write. It also defines whether some attributes must be masked when read by a particular role. Of course, the role definition also include a technical identifier, and localized labels and descriptions for display in the self-service portal and in reports.

Retention Rules

Sometimes data needs to be stored for legal reasons. Through the definition of retention rules, eSealth’s archival process can ensure that this data is kept archived when a particular token or dataset is deleted. Every retention rule also includes localized labels and descriptions for display in the self-service portal and in reports.