GDPR data retention in S/4HANA: implementation of the Qintesi solution for data anonymization in public utilities

Challenge

A leading company in the Mobility and Public Services sector, currently migrating to SAP S/4HANA, needed to ensure full compliance with EU Regulation 2016/679 (GDPR), particularly in relation to the right to be forgotten and the protection of the personal data of its customers and suppliers. The previous features used for data anonymization would no longer be supported in the new S/4HANA environment. The challenge was to implement a smart and simple solution that would allow the anonymization of personal data throughout the SAP supply chain (including development and testing), in accordance with the customer’s anonymization process, without negatively impacting the integrity and consistency of accounting and service data, and without requiring additional licensing costs and system activities.

Solution

The solution adopted consists of implementing the GDPR Cockpit, a custom tool developed in ABAP (both SAP Ecc and S/4HANA) by Qintesi, which can be extended in SAP Fiori\BTP and has already been successfully implemented for other large account customers. The tool is designed as an accelerator for the implementation of the anonymization process, with the aim of minimizing the impact on services and the integrity of accounting data and centralizing the basic functions for performing masking, scrambling, deleting, anonymization, etc.

The Cockpit consists of a “Core” component for basic functionality and a “Context” component for customer-specific contextualization, such as Data Lineage, Anonymization Drivers, masking rules, etc.

The basic process in a production environment can be divided into five main macro-phases:

  1. Identification of subjects to be anonymized: an extractor selects “candidates for oblivion” (personal data of customers/suppliers who are natural persons, business partners) based on retention requirements such as the absence of transactions in SAP in the last 9 years.
  2. Confirmation by the user (Owner): the user views the extracted list and can confirm or remove subjects, for example in the event of a dispute.
  3. Anonymization run execution: the tool applies the rules directly to the database, using an encryption algorithm of your choice (AES with a 256-bit key by default). After the run, the data is no longer readable and fields containing personal data are masked, for example with “XXX,” or encrypted.
  4. Final user verification with reports available for audit purposes.
  5. Rollback: in the event of errors, data can be restored, provided that the encryption keys have not been permanently deleted. The rollback window has been set at one year, after which the deletion of keys is irreversible, guaranteeing the right to be forgotten without deleting transactional data and compromising accounting consistency.

This methodology has therefore enabled compliance with the GDPR to be achieved while maintaining the integrity of transactional data for historical and accounting purposes.

In the lower environments, Development and Quality, the tool has been used to anonymize personal data across the entire database using the scrumbling technique, with no possibility of rollback.

Results

Quote

Qintesi's GDPR Cockpit solution has efficiently resolved the issue of anonymizing personal data in the S/4HANA environment. It has ensured full compliance with the right to be forgotten through a native SAP process that is streamlined, auditable, and has no impact on accounting integrity, delivering benefits in terms of compliance and operational autonomy. A quick, easily implementable result that is fully compliant with regulations.
Michele Valentini
Executive Head of Unit Development & Integration

Le informazioni contenute in questo documento sono di proprietà.
Copyright © 2014 Qintesi S.p.A. Tutti i diritti riservati.

Ricevi la nostra newsletter

Compila il form qui di seguito con i tuoi dati per rimanere sempre aggiornato sulle novità e gli eventi di Qintesi.

Subscribe to our newsletter

Fill out the form below with your details to stay up to date on Qintesi news and events.

Come realizzare un profitto sostenibile

Approfondisci i trend e le linee guida per un’impresa sostenibile