Okay
  Public Ticket #3634198
Function GDPR
Closed

Comments

  • Leon Zhang started the conversation

    Issue Overview: In the current implementation of Amelia's employee panel, there is unrestricted access to view all email addresses of registered attendees. This access is granted to all employees, including contractors such as freelance teachers. This poses a significant privacy concern, particularly in light of GDPR regulations and our internal safeguarding policies.

    Context: Our application’s employee panel is used by various types of employees, including full-time staff and contractors. Specifically, freelance teachers who are hired to conduct sessions at events also have access to this panel. However, they do not need, nor should they have access to the attendees' personal email addresses, which may include young learners.

    Problem Statement: The visibility of attendees' email addresses to contractors is in violation of GDPR and our safeguarding commitments to protect student privacy. For instance, a freelance teacher scheduled to teach a session can currently view all email addresses of the students registered for the event, which is unnecessary for their role and breaches privacy standards.

    Required Action: We need a system update that restricts access to sensitive information such as email addresses based on the role and necessity. Only employees who require this information for their job functions should have access to it.

    Suggested Solutions:

    1. Implement role-based access controls (RBAC) in the employee panel to differentiate access rights between full-time employees and contractors.
    2. Ensure that email addresses are hidden by default and only visible to those with explicit permissions to view them.

    Urgency and Impact: This issue requires prompt attention as it poses a compliance risk with GDPR and a potential breach of trust with our attendees. 

    Thank you for your attention to this urgent matter. Please update us on the estimated time for this issue to be addressed or if further information is needed to proceed with a solution.

  •  1,564
    Marko replied

    Hello there,

    Thank you for reaching out to us.

    Unfortunately, currently, this feature is not built-in in Amelia. But we will forward your suggestion to the appropriate sector but we can not make any promises that will be implemented or not in the future. 

    Should you have any further inquiries, we kindly request that you open separate tickets for each question and we will gladly help you there.

    We wish you all the best and hope you have a wonderful day ahead. 


    Kind Regards, 

    Marko Davidovic
    [email protected]

    Rate my support

    wpDataTables: FAQ | Facebook | Twitter | InstagramFront-end and back-end demo | Docs

    Amelia: FAQ | Facebook | Twitter | InstagramAmelia demo sites | Docs | Discord Community

    You can try wpDataTables add-ons before purchasing on these sandbox sites:

    Powerful Filters | Gravity Forms Integration for wpDataTables | Formidable Forms Integration for wpDataTables | Master-Detail Tables