Zum Hauptinhalt springen

Compliance & Data Protection

The Compliance section covers GDPR/DSGVO data protection obligations and the compliance monitoring tools available to compliance officers.

Compliance Dashboard

The compliance dashboard shows your club's real-time regulatory status. See Dashboard for details on the 9-panel overview.

Audit Log

The audit log records every data-changing action taken by any staff member.

To access the audit log:

  1. Go to Compliance → Audit Log.
  2. Use the filters to narrow by date, table, event type, or actor.

The audit log is immutable — no one can modify or delete entries. It covers changes to 12 critical tables including members, roles, dispensing events, and compliance records.

Breach Incidents

Use the Breach Incidents module to manage GDPR data breaches (Art. 33 GDPR).

Key deadlines

DeadlineAction required
T+8hInternal management notification (automatic alert)
T+72hReport to supervisory authority (Art. 33 GDPR)
T+30 daysNotify affected individuals if required (Art. 34 GDPR)

To register a breach:

  1. Go to Compliance → Breach Incidents.
  2. Click Report Breach.
  3. Fill in: discovery date/time, description, data categories affected, estimated number of individuals.
  4. Save.

CANNEVO tracks both the T+8h and T+72h clocks automatically, with escalation alerts as deadlines approach.

DSAR Requests

Data Subject Access Requests (DSARs) must be handled within 30 days of receipt.

Request types

TypeGDPR ArticleAction
AccessArt. 15Generate data export for the member
ErasureArt. 17Check what can be deleted vs. legally required to retain
PortabilityArt. 20Generate machine-readable export
RestrictionArt. 18Flag record for processing restriction

To register a DSAR:

  1. Go to Compliance → DSARs.
  2. Click New Request.
  3. Select request type and enter member details.
  4. Save — the 30-day deadline is set automatically.

Deadline extension: In complex cases, the deadline can be extended by 60 days. Click Extend Deadline and provide a justification.

Members with open DSARs

Members with an open DSAR are automatically excluded from retention archival until the request is resolved. This prevents data being deleted while a data access request is pending.

Break-Glass Access

Support staff from CANNEVO may occasionally need temporary elevated access to diagnose issues. This is managed via the break-glass access system:

  • Maximum duration: 2 hours
  • Requires explicit approval from a tenant_admin user
  • All actions during break-glass access are fully audited
  • Access is automatically revoked when the grant expires

To review break-glass grants:

  1. Go to Compliance → Break-Glass (or Settings → Security).
  2. Approve or revoke pending grants.
  3. View the audit trail for any completed break-glass sessions.

Data Protection Configuration

Go to Settings → Config to:

  • View and accept the Data Processing Agreement (DPA)
  • Check DPA acceptance status
  • View your sub-processor list