Table of Contents

GDPR

This document explains how GDPR actions currently work in InsightEngine from an operational perspective.

What Is In Place

Right of Access (Data Export)

Users can request and download a copy of their personal data from Settings.

Current export includes:

Outcome:

Right to Erasure (User Account Deletion)

Registered users can delete their own account from Settings after password confirmation.

When this happens:

Outcome:

Participant Erasure (Organization Admin Action)

Organization owners and super admins can anonymize a participant record.

When this happens:

Outcome:

Analytics tracking is consent-gated.

Behavior:

Outcome:

Audit and Accountability

GDPR-relevant actions are auditable.

Recorded events include:

Outcome:

Data Retention Position

Current approach uses anonymisation for erasure flows instead of full historical destruction in all cases.

Rationale:

Operational Notes for Handover