Guidelines for GDPR readiness
Protecting your data can help you comply with the General Data Protection Regulation (GDPR). GDPR establishes a regulatory framework for processing personal data. Use the following sections to help you prepare for GDPR readiness.
Use the following sections to help you prepare for GDPR readiness. Each section provides information about aspects of IBM® Cloud Pak for Business Automation as a Service you can consider to help your organization with GDPR readiness. What you need to do for GDPR readiness in practice depends on the capabilities installed on your subscription.
The IBM Support team installed and configured IBM Cloud Pak for Business Automation as a Service on your subscription in compliance with various laws and regulations, including the GDPR adopted by the European Union in May 2018. You are responsible for ensuring that applications and solutions you develop and run on your subscription also meet data privacy requirements. Obtain the advice of competent legal counsel as to the identification and interpretation of any relevant laws and regulations that might affect your business. Take the resulting actions to comply with such laws and regulations.
IBM does not provide legal, accounting, or auditing advice, or represent or warrant that its services and products ensure compliance with any law or regulation. The responsibility to ensure that an IBM product is compliant with laws and regulations is on the company that purchases the product. Always consider how protected your data is and whether it is ready for GDPR. For more information, see the GDPR
page on the IBM website.
Event emitters
- The BPM event emitter (
bpmnandbawadvjobs) selects data per field to be part of the event. Choose the fields according to your needs and to data sensitivity. - The Case event emitter provides data from Case events.
- The ODM emitter emits events based on inputs to the decisions, outputs from the decisions, and technical data about the rule execution.
- The Content event emitter captures Content events so that Kafka can process document metadata.
Data deletion
Article 17 of the GDPR states that data subjects have the right to request that their personal data be removed from the systems of controllers and processors, without undue delay. Implement appropriate controls and tools to satisfy this right.
IBM Cloud Pak for Business Automation as a Service does not require any special method for data deletion, providing that it is secure.
- Data stored in the IBM Cloud Pak for Business Automation as a Service platform
- The only PII data that's stored by the IBM Cloud Pak for Business Automation as a Service platform is a user's name and email address. This data is required so that the user can access the subscription. If the user no longer requires access, your account administrator is responsible for removing the user's PII.
- Data stored by customer-built solutions
- Build your solutions to include a mechanism for completely removing PII from the solution if requested to do so by a data subject.
Responding to requests from individuals
- Basic personal data, such as names, usernames, and passwords.
- Technically identifiable personal information, such as IP addresses and hostnames to which user activity might potentially be linked.
- Personal data that might be stored in text.
This data is key for efficient operation of an automated system. IBM Cloud Pak for Business Automation as a Service platform logs can contain technically identifiable PII that is required to run the service and meet contractual requirements. These logs are kept as long as required. When the logs are no longer required, the IBM Support team properly discards them.
- Delete data.
- Correct data.
- Modify data.
- Extract specific data for export to another system.
- Restrict the use of data within the overall system.