GDPR compliance functions
ASAPIO Integration Add-on supports features to help customers/users comply with GDPR regulations, in the following areas:
- Right to information
- Right of deletion
- Right to data migration
In general, there are two scenarios where customer data, including personally identifiable data of individuals, might be stored within ASAPIO Integration Add-on:
- ASAPIO Integration Add-on configuration or customizing, e.g. SAP user id, that created a configuration set.
- In header or payload of messages or transmission logs created by ASAPIO Integration Add-on, based on customers individual configuration. Example: supplier contact data, employee data records, etc.
No data is transferred or stored at ASAPIO servers or premises. Customer is solely responsible where data is stored.
Right to information / Where does ASAPIO store customer data?
ASAPIO Integration Addon – Core
Type of Data | Storage | Description |
---|---|---|
Usernames | Addon specific tables:
SAP Standard:
|
Various places store usernames of
|
Customer or
Sensitive Data |
Longtext table in SAP: STXH | Tracing of payloads/messages is stored when tracing is activated.
Depending on the customer configuration this can include sensitive data. |
ASAPIO Integration Addon – Fieldglass
Type of Data | Storage | Description |
---|---|---|
Usernames | Fieldglass specific tables:
SAP standard tables:
|
Various places store usernames of
Changes to the Fieldglass tables by Admin users are recorded |
Right of deletion / How can ASAPIO stored data be deleted?
Storage | How to delete | Description |
---|---|---|
ASAPIO Logs: /ASADEV/A_AMRLOG
ASAPIO Traces: STXH |
Report: /ASADEV/ACI_AMRLOG_DELETE
|
This report can be used to periodically delete the Log and Trace entries. |
ASAPIO Table: /ASADEV/DYN_VIEW | No deletion report.
|
Contains the Payload Design configuration.
Payload Designs can be deleted if no longer needed in transaction /ASADEV/DESIGN |
Fieldglass specific tables:
|
No deletion report. | Reference tables for the Fieldglass integration. Entries should not be deleted. Typically only contain technical interface users. |
SAP Standard:
|
SAP mechanisms exist to delete data from these places. |
Right to data migration / How can ASAPIO stored data be downloaded or transferred?