Privacy Settings


Secure the personal information of your users when they leave the organization by configuring privacy settings in ServiceDesk Plus Cloud. Privacy guidelines, such as the General Data Protection Regulations, require businesses to protect their user's personal data from potential misuse. That is when a user leaves the organization any data that could be used in isolation or in conjunction with other data to accurately identify the person must be completely deleted from the application.

GDPR protects all types of personally identifiable information (PII)/electronic Protected Health Information (ePHI), including the user's name, social security number, insurance details, or racial or ethnic data.

To enable privacy settings in the application, go to Setup  >> Users & Settings >> Privacy Settings and click Enable privacy settings.

 

 

When you enable privacy settings in ServiceDesk Plus Cloud, you can anonymize (user names and email IDs) and erase all personally identifiable information (PII)/electronic Protected Health Information (ePHI). To do that you'll need to first identify the PII/ePHI fields. Then, you'll need to anonymize and erase the data from the application. 

Identifying the PII/ePHI

By default, all data collected in system fields such as name, email, SMS mail ID, phone, and mobile are considered PII/ePHI. Data collected in the Requests, Requesters, and Technicians Additional Fields (shown below) and Resource Info within Service Category must be explicitly marked as PII/ePHI. 

 

 

Resource Info PII/ePHI Marking

 

Anonymizing and Erasing PII/ePHI

When the PII/ePHI fields are explicitly marked within the application, all of them, in addition to system fields, will be displayed under Setup >> Privacy Settings >> PII/ePHI Fields.

When a user exits the organization, user data in the Mobile Number and Phone Number fields (listed on this page) will be deleted by default.

As for email IDs and all other PII/ePHI fields enable them under Setup >> Privacy Settings >> PII/ePHI Fields.

 

 

Then, go to Setup >> Privacy Settings >> Anonymize

On this page will be listed all the deleted usernames with their email IDs. Select each one to anonymized individually. You can provide a random name/text in place of the username, whereas the email IDs will be automatically anonymized in the anon_<userID>@<domainname>.com format. 

 

 

Select the usernames and click Anonymize to provide random text for the names.

 

 

Viewing PII/ePHI Log

The PII/ePHI Log functions as a historical record of all activities around the PII/ePHI fields across the application. Each log on this page contains information on the PII/ePHI field's module, sub-module, the action, and when exactly it occurred.

You can export the log files in CSV and XLS file formats.