GDPR
GDPR
overview
Article
06/29/2022
19 minutes to read
6 contributors
Note
Before utilizing any product features in support of your GDPR compliance efforts,
please ensure that you have applied all of the related hotfixes.
The GDPR gives EU citizens specific data subject rights (DSRs) that let them perform
the following actions:
The GDPR defines personal data in the following way in article 4 of the
regulation (organizations do not have personal data):
For finance and operations apps, Microsoft acts as a processor. As a data processor,
finance and operations provides processes and features that help you comply with
your GDPR obligations as a data controller.
The following illustration shows the flow of data from your customer to the
application database, and the roles that you and Microsoft play in that process. For
each application, the controller is the tenant administrator, and Microsoft is the
processor. In this scenario, the data is sent to the processor (Microsoft), who then
processes the data by storing it, retrieving it, sorting it, and so on.
When a data subject chooses to submit a DSR, the data subject makes the request to
the controller. Data subjects won't approach Microsoft to exercise their rights for
data that your business has collected. As the processor, Microsoft assists the
controller by providing features, or just by making sure that the actions are possible.
In other words, the controller accepts and responds to a DSR request, and the
processor assists with or enables the compliance request. The following table
outlines some of the roles and responsibilities that are relevant.
Properly identify the person and role (is the person an employee, a
customer, a vendor?) by using information that the data subject gave
you as part of their request. This information might be a name, an
employee ID or customer number, or another identifier.
Record the date and time of the request. (You have 30 days to complete
the request.)
Affirm that the DSR request is proper and valid. You will need to work
with your legal counsel to determine what is valid. For example, you
must make sure that compliance with a DSR request doesn't conflict with
any other legal obligations that you have.
Verify that you have the information that is related to the request.
The following table lists several reasons why personal data modification or deletion is
restricted in certain scenarios.
Reason Comment
Financial, tax, generally accepted A party can't be deleted, but the party's name can be
accounting principles (GAAP) updated.
Financial, tax, GAAP A current worker's data can't be deleted, but the
worker's name can be updated.
GAAP Posted or completed transactions can't be modified.
Right to view
Use the Person search report to find and collect personal data. To access
this report, from the navigation pane, select Modules > System
administration > Inquiries > Person search report.
Extend the Person search report by authoring a new entity or extending
an existing entity.
Use search and filter features to find specific personal data and export
that data by using the Microsoft Office Export functionality or print that
information to a .pdf using browser extensions.
Use provided documentation to identify data tables that contain data
that the controller has identified as personal data.
Author a custom form that locates and exports personal data.
Author an external portal or website that allows an authenticated
customer to see their personal data.
The Person search report might help you discover personal data that is subject to a
DSR request. If the report doesn't include the information that you're looking for,
check the Microsoft Dynamics Lifecycle Services (LCS) site for possible hotfixes that
include the information. You can also extend the report yourself by creating
additional entities, or extending the provided entities.
If the Person search report doesn't contain all the information that the data subject is
requesting, you can extend it by using tools that Microsoft has provided. For
information about how to extend the Person search report, see Extend the Person
search report.
Right to correct* **
Use the Person search report to find and collect personal data.
Extend the Person search report by authoring a new entity or extending
an existing entity.
Use search and filter features to find specific personal data.
Author a custom form that locates personal data.
Author an external portal or website that allows an authenticated
customer to correct their personal data.
When data is located, use in-product features to correct the data where the product
offers the ability to do so.
*You might find that some data that qualifies as personal data can't be modified
directly. Typically, this data is part of a financial transaction or other business data
that is kept "as is" for compliance with financial laws (for example, tax laws),
prevention of fraud (such as security audit trail), or compliance with industry
certifications.
** GDPR is not a law exclusive of all other laws. As an enterprise resource planning
system, finance and operations doesn't allow for modification of certain business or
transactional data, and will not endorse nor provide functionality for the modification
of business data that is necessary for compliance with other laws or certifications.
Finance and operations will not provide support for modifications/customizations or
other actions that result in the corruption of referential or business data integrity.
Right to be forgotten*
Delete or otherwise erase personal data where the product enables that
action directly.
Anonymize the personal data where the product enables that action
directly.
Author a customization to erase/modify the personal data.
* GDPR is not a law exclusive of all other laws. As an enterprise resource planning
system, finance and operations does not allow for deletion of certain business or
transactional data, and will not endorse nor provide functionality for the deletion of
business data that is necessary for compliance with other laws or certifications.
Finance and operations will not provide support for modifications/customizations or
other actions that result in the corruption of referential or business data integrity.
Right to port
The Person search report might help you discover personal data that is subject to a
DSR request. If the report doesn't include the information that you're looking for,
check the LCS site for possible hotfixes that include the information. You can also
extend the report yourself by creating additional entities.
If the Person search report doesn't contain all the information that the data subject is
requesting, you can extend it by using tools that Microsoft has provided. For
information about how to extend the Person search report, see Extend the Person
search report.
The controller may, at their sole discretion choose to redact certain types of
information that may fall outside of the scope of data that must be returned to the
data subject as defined within the GDPR.
Right to restrict
An organization might decide to take the following action in response to a DSR
request to restrict optional data processing:
* GDPR is not a law exclusive of all other laws. As an enterprise resource planning
system, finance and operations does not allow for restricted processing of certain
business or transactional data, and will not endorse nor provide functionality for the
restriction of processing of business data that is necessary for compliance with other
laws or certifications. Finance and operations will not provide support for
modifications/customizations or other actions that result in the corruption of
referential or business data integrity.
Controller considerations
Controllers can use the following information to complete DSR requests.
System inventory
Roles that are associated with party records are referred to as party roles. There are
several party roles, and they can be assigned to both party types (person and
organization):
The right to view and port: It's all about the party
When a data subject approaches the controller to request a copy of their personal
data, the controller might choose to use the Global address book information to
locate the data that describes the person. As noted in the illustration earlier in this
article, a person is a type of party that plays a role.
Note
The Person search report is available for Finance, Supply Chain Managament,
Commerce, and Human Resources. Currently the report does not support Microsoft
Dynamics AX 2012.
When a data subject approaches the controller to request a copy of their personal
data, the controller might choose to use the Global address book information to
locate the data that describes the person. As noted in the illustration earlier in this
article, a person is a type of party that plays a role.
Some organizations conduct their activities only through business-to-business
relationships and will have modest DSR obligations. By contrast, other organizations
conduct their activities through business-to-customer relationships. These
organization might choose to use the Global address book and its associative data
relationship to write custom reports, custom forms, custom queries, and custom data
export features by using the extensibility and customization capabilities and Open in
Excel experiences to serve the specific needs of the kinds of data that their business
collects from their customers.
The following table lists several reasons why data modifications might be restricted.
Reason Comment
Audit Data must be preserved for compliance and auditing.
Calculated Data that has been calculated can be changed only by
changing the data that is included in the calculation.
Financial, tax, generally accepted Posted transactions can't be modified or deleted.
accounting principles (GAAP)
Import log Data must be preserved for compliance and auditing.
You should expect data requests to come to your company. You can categorize the
people who request data into one or, in some cases, more than one relationship with
your company:
Customers
Vendors
Workers
Users
Warehouse workers
Truck drivers
Prospects
Contacts
Applicants
Competitors
Personal data might also be contained in other roles that aren't listed here. Pages
used to enter, view or edit personal data have been provided in worksheets for most
roles in the preceding list. You can view or download the spreadsheets from
the Reference documents for finding and managing personal data page on Customer
Source.
Detailed inventory
As you use finance and operations apps, you might find that you generate or collect
large amounts of data that resides in multiple data stores. To help you make sense of
where your data resides, we've introduced a data marker for each piece of data in
our data stores. This marker is called "Asset Classification," and it can be used to
identify or track personal data. Any data that you collect has been described as
"customer content." Some customer content might contain personal data, and some
customer content might contain business data. You can choose to treat all customer
content as personal data, or you can change the classification yourself, so that you
can identify and track any data that you feel is considered "Personal Data." Although
Microsoft has a supplied a set of default classifications, you're free to use any
classification or identifiers that you choose.
Age Gating: Preventing minors from using the
service
Overview
Microsoft mandates that all users of Microsoft software where personal data is
collected must use a Microsoft account (MSA) or Microsoft Azure Active Directory
(Azure AD) account for authentication. Additionally, those accounts must be
configured to enable minors who use the software or service to affirm parental
consent for the service to use their personal data.
As the tenant admin of the service, you will be required to set up Azure AD Age
Gating and/or MSA age gating.
Any user who isn't configured by using Azure Age Gating will be restricted from
using the service, even if the user isn't a minor. Age Gating must be configured.
We will restrict access to our software and systems by using a sign-in age gate.
The GDPR specifies that systems must stop processing a minor's personal data if that
minor doesn't have parental consent. Note that consent can be given and then
withdrawn. Therefore, a user might have access to the system one day but not the
next.
In the About box, you will find links to the Microsoft user rights documentation, and
to the Microsoft privacy and cookies documentation. You can also add a link to your
organization's privacy statement.
On the System parameters page, system administrator can add links to the
organization's user rights and privacy notices. You can add a valid URL for one or
both notice types.
When you've completed your entries in the system parameters, the link to your
organization's privacy notice will appear in the About box, as show in the following
illustration.