WebSphere Automation considerations for GDPR readiness

This document is intended to help you understand how WebSphere Automation can assist you to comply with your requirements under the European Union (EU) General Data Protection Regulation (GDPR). It provides information about features of WebSphere Automation that you can configure and aspects of the product's use that you should consider to help your organization with your GDPR readiness. This information is not exhaustive as there are many ways that clients can choose to configure features and to use the product by itself and with third-party applications and systems.

Clients are responsible for ensuring their own compliance with various laws and regulations, including the European Union General Data Protection Regulation. Clients are solely responsible for obtaining advice of competent legal counsel as to the identification and interpretation of any relevant laws and regulations that may affect the clients' business and any actions the clients may need to take to comply with such laws and regulations.

The products, services, and other capabilities described herein are not suitable for all client situations and might have restricted availability. IBM® does not provide legal, accounting, or auditing advice or represent or warrant that its services or products will ensure that clients are in compliance with any law or regulation.

Table of Contents

  1. GDPR overview
  2. Product configuration - considerations for GDPR Readiness
  3. Data life cycle
  4. Data collection
  5. Data storage
  6. Data access
  7. Data deletion
  8. Data processing
  9. Data processing
  10. Responding to data subject rights

GDPR overview

The General Data Protection Regulation has been adopted by the European Union ("EU") and applies from May 25, 2018.

Why is GDPR important?

GDPR establishes a stronger data protection regulatory framework for processing of personal data of individuals. GDPR brings:

  • New and enhanced rights for individuals
  • Widened definition of personal data
  • New obligations for processors
  • Potential for significant financial penalties for non-compliance
  • Compulsory data breach notification

Read more about GDPR:

Product configuration - considerations for GDPR Readiness

The following sections provide considerations for configuring WebSphere Automation to help your organization with GDPR readiness.

The GDPR legislation requires that personal data is strictly controlled and that the integrity of the data is maintained. This requires the data to be secured against loss through system failure and also through unauthorized access or by theft of computer equipment or storage media.

Data life cycle

GDPR requires that personal data is:
  • Processed lawfully, fairly, and in a transparent manner in relation to individuals.
  • Collected for specified, explicit, and legitimate purposes.
  • Adequate, relevant, and limited to what is necessary.
  • Accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that inaccurate personal data is erased or rectified without delay.
  • Kept in a forma that permits identification of the data subject for no longer than necessary.

What are the lawful bases for processing?

The lawful bases for processing are set out in Article 6 of the GDPR. At least one of these lawful bases must apply whenever you process personal data:
  1. Consent: The individual has given clear consent for you to process their personal data for a specific purpose.
  2. Contract: The processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.
  3. Legal obligation: The processing is necessary for you to comply with the law (not including contractual obligations).
  4. Vital interests: The processing is necessary to protect someone's life.
  5. Public task: The processing is necessary for you to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law.
  6. Legitimate interests: The processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual's personal data which overrides those legitimate interests. (This cannot apply if you are a public authority processing data to perform your official tasks.)

Explicit requirements:

  1. Ensure the appropriate consent is in place - contract, service, explicit Data Subject consent
  2. Understand where the data resides in the application/solution
  3. Ensure the data is secured through:
    • Encryption
    • Access control
    • Additional controls
  4. Ensure the retention period of this data is clearly defined
  5. Ensure the data is deleted at the end of the retention period
  6. Ensure all the Data Subject rights can be fulfilled:
    • Higher standards for privacy policies and statements and for obtaining consent
    • Easier access to personal data by a data subject
    • Enhanced right to request the erasure of their personal data
    • Right to transfer personal data to another organization (portability)
    • Right to object to processing now explicitly includes profiling

Product considerations

GDPR requires that personal data are processed in accordance with the following data principles. This section lists those data principles and explains in what way WebSphere Automation might be subject to the GDPR regulation itself and how WebSphere Automation can help to monitor that business processes respect GDPR.

  • Lawfulness,fairness and transparency: processed lawfully, fairly and in a transparent manner in relation to individuals;
    • WebSphere Automation may store GDPR related data. Refer to the following sections to understand what needs to be done to be GDPR compliant when using WebSphere Automation.
  • Purpose limitation:collected for specified, explicit and legitimate purposes;
    • The customer needs to define according to business processes to comply with this principle.
  • Data minimization:adequate, relevant, and limited to what is necessary;
    • The customer needs to define according to business processes to comply with this principle.
  • Accuracy: accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that inaccurate personal data are erased or rectified without delay;
    • The customer needs to define according to business processes to comply with this principle.
    • In addition, WebSphere Automation might also store GDPR related data. Refer to the following sections to understand what needs to be done to be GDPR compliant when using WebSphere Automation.
  • Storage limitation: kept in a form that permits identification of the data subject for nolonger than necessary;
    • The customer needs to define according to business processes to comply with this principle. However, WebSphere Automation can help customers to monitor that existing business process are respected. Refer to the following sections to understand what needs to be done to be GDPR compliant when using WebSphere Automation.
    • In addition, WebSphere Automation might also store GDPR related data. Refer to the following sections to understand what needs to be done to be GDPR compliant when using WebSphere Automation.
  • Integrity and confidentiality: processed in a manner that ensures appropriate security of the data, including protection against unauthorized or unlawful processing and against loss, destruction, or damage.
    • WebSphere Automation might store GDPR related data. Refer to the following sections to understand what needs to be done to be GDPR compliant when using WebSphere Automation.

Product configuration to support data handling requirements

The GDPR requires that personal data are strictly controlled, and that the integrity of the data is maintained. This requires the data to be secured against loss through system failure and also through unauthorized access or via theft of computer equipment or storage media.

For data at rest, WebSphere Automation encrypts the data in the database.

Data in motion between WebSphere Automation and the user client systems are always encrypted by default using TLS based encryption. However, it is strongly recommended to provide a customer owned certificate for encryption during the WebSphere Automation setup. In addition, data in motion being transferred within the WebSphere Automation system (i.e. between different WebSphere Automation components, so-called "containers") is encrypted. See Setting up WebSphere Automation for a complete, step-by-step description on how to set up WebSphere Automation for production environments.

Data collection

WebSphere Automation is a product that provides our customers with the ability to access unstructured data through metadata and full-text indexes in place across a variety of data sources. You can specify the data to be accessed based on your business requirements; this data might or might not include personal data for your clients and employees.

WebSphere Automation uses encryption for both transmission of data over the network (data in motion) as well as storage of sampled data on disk (data at rest).

The following explicit requirements need to be considered with respect to the different types of data being stored or collected by WebSphere Automation:

Types of data collected
User account information

WebSphere Automation can be set up with local users for test or demonstration purposes. In that case, the following user information is encrypted and stored in a secure vault: password, given name and surname, email address. In addition, WebSphere Automation can be configured for LDAP authentication for production use. In that case, WebSphere Automation stores the username and the LDAP group membership information in a relational database; passwords of LDAP users are not stored.

Access credentials for the configured data sources are also encrypted and stored in the credential vault.

WebSphere Automation is a browser-based application and utilizes HTTPS as the connection mechanism to the application server, assuming the product is set up correctly for production use. WebSphere Automation does not require the IP address to establish the connection, but the IP address might be logged to web server log files.

Notification recipient informatio
WebSphere Automation can be provided with a list of one or more email addresses for email notifications to be sent. WebSphere Automation stores and encrypts collected email addresses.
Log information

For debugging purposes, the IBM StoredIQ InstScan support team might need to collect customer log files. The log files are designed not to contain personally identifiable information, when possible, but they might contain information like IP addresses or names of sampled files. The IBM StoredIQ InstScan support team uses ECuRep for customer data management. ECuRep archives the PMR or case data when the PMR is closed. Logs exist for as long as the pods in Red Hat OpenShift exist.

Personal data used for online contact with IBM

You can submit online comments, feedback, or requests to IBM about WebSphere Automation subjects in a variety of ways, primarily:

  • Public comments area on pages of WebSphere Automation documentation in IBM Documentation
  • Data on how you use the product may be collected if you give your consent within the tool. You can request the deletion of that data.

It is your responsibility to make sure that no personal data are provided in any public spaces or groups. Typically, only the client's name and email address are used to enable personal replies for the subject of the contact, and this use of personal data conforms to the IBM Online Privacy Statement (https://www.ibm.com/privacy/us/en/).

Data storage

The following data storage mechanisms are used by WebSphere Automation, which users might want to consider when assessing their GDPR readiness.

  • Storage of account data

    WebSphere Automation stores the service account credentials used to connect to data sources.

  • Storage of client data

    WebSphere Automation accesses unstructured data. You decide what is stored in the data sources that are accessed by WebSphere Automation. WebSphere Automation creates previews of the accessed documents as needed. The generated preview files are automatically deleted after a few minutes. In addition, reports are created by WebSphere Automation which contain data detected in the sampled documents. The reports can be deleted by request of the user.

    WebSphere Automation collects, stores, and analyzes data during health investigations. When you configure health-specific storage, encrypt the filesystem where investigations are stored to protect sensitive information about your servers.

Data access

WebSphere Automation has four defined roles as described in the IBM documentation for user roles and privileges.

The roles WebSphere Automation Health, WebSphere Automation Security, WebSphere Automation Viewer, and WebSphere Automation Administrator have access based on their permissions to data in the database. The WebSphere Automation Viewer and WebSphere Automation Administrator roles have permissions to personal data or other sensitive information.

Data deletion

Right to Erasure
Article 17 of the GDPR states that data subjects have the right to have their personal data removed from the systems of controllers and processors - without undue delay - under a set of circumstances.
Data deletion characteristics
  • Local account information deletion

    This information can be deleted in WebSphere Automation, for example, when a person leaves your company or to satisfy the right to erasure. All accounts which include production environment LDAP integration, local demo and test user accounts must be deleted manually. It is the responsibility of the client to maintain the list of users.

  • Client data deletion

    Client data deletion is the responsibility of the client based on their configuration of WebSphere Automation. A client with the role of WebSphere Automation Administrator has the privilege of data deletion.

  • Notification recipient information

    If clients have configured notifications within WebSphere Automation, it is the responsibility of the client to delete email addresses from the recipient list. A client with the role of WebSphere Automation Administrator has the privilege of data deletion.

Data monitoring

WebSphere Automation logs the following audit events.
Login, logout, session, authentication
  • Success or failure when a user logs in
  • Record when users log out
  • Success or failure of token authentication
  • Failure when invoking any privileged action
User management
  • Authorize a user for access to the platform
  • Remove access to the platform for user
  • Make changes in a user's profile, including name and email address
  • Grant a specific privilege to a user on the platform
  • Revoke a platform privilege from a user

Data processing

Types of data processed include:

Notification recipient information
If clients have configured notifications within WebSphere Automation, it is the responsibility of the client to maintain the recipient list of email addresses.

Responding to data subject rights

Using the facilities summarized in this document, WebSphere Automation enables an end user to restrict usage of any technical data within the platform that is considered personal data.

Under GDPR, users have rights to access, modify, and restrict processing. Refer to other sections of this document to control the following:

The WebSphere Automation Viewer and Administrator roles have permissions to personal data or other sensitive information.
  • Right to access
    • WebSphere Automation Administrators can use WebSphere Automation features to provide individuals access to their data.
    • WebSphere Automation Administrators can use WebSphere Automation features to provide information about what data WebSphere Automation holds about the individual.
  • Right to modify
    • WebSphere Automation Administrators can use WebSphere Automation features to modify or correct an individual's data for them.
  • Right to restrict processing
    • WebSphere Automation can use WebSphere Automation features to stop processing an individual's data.