February 18, 2022
What is a Profile?
eStealth’s profiles are configuration files that describe everything related to data protection and privacy in a single place. They are the result of your initial analysis and assessment phase.
Contents
Puposes
GDPR requires that all sensitive data is only ever stored and/or processed for a clearly defined purpose. The profile defines which purposes exist and which data attributes are covered by which purpose. Each definition includes a technical identifier, expiration rules, and localized labels and descriptions for display in the self-service portal and in reports.
Attributes
Each sensitive data attribute needs to be declared in the profile. This tells the vault which attributes to allow into the vault, and how to process them. Each definition includes technical field identifier, data validation rules, data access rules, normalization rules, and localized labels and descriptions for display in the self-service portal and in reports.
Roles
eStealth enforces role-based access control. Every access to data is authorized and processed within the context of a role. The profile defines which roles exist, for which purposes a role may access data, and which attributes a role may read and/or write. It also defines whether some attributes must be masked when read by a particular role. Of course, the role definition also include a technical identifier, and localized labels and descriptions for display in the self-service portal and in reports.
Retention Rules
Sometimes data needs to be stored for legal reasons. Through the definition of retention rules, eSealth’s archival process can ensure that this data is kept archived when a particular token or dataset is deleted. Every retention rule also includes localized labels and descriptions for display in the self-service portal and in reports.