Managing Access to Personal Data
Introduction
System Administrators can grant or revoke personal data-related permissions on the Edit group permissions page to ensure compliance with personal data protection regulations.
Personal Data-Related Group Permissions
The following table lists and describes the personal data-related group permissions.
Permission
Description
Accounts - Administer
Enables users to administer all account data settings. If the Accounts - Administer is granted, all Account - View... user group permissions are automatically selected and cannot be revoked:
Account - View Address
Account - View Company
Account - View Phone
Account - View Email Address
Account - View Skills
Account - View Username
Account - View Presence
Account - View Time Settings
If the Accounts - Administer is revoked, all Account - View... permissions remain selected and must be managed individually.
Account - View Address
Enables users to view the following field values in all accounts:
Address
Zip/Postal Code
City
State/Province
Country
Account - View Company
Enables users to view the Company field value in all accounts.
Account - View Phone
Enables users to view the following field values in all accounts:
Phone Number
Mobile/IP Voice
Account - View Email Address
Enables users to view the following field values in all accounts:
Email
Language
Account - View Skills
Enables users to view the Skills field value in all accounts.
Account - View Username
Enables users to view the User Name field value in all accounts.
Account - View Presence
Enables users to view the following field values in all accounts:
Registered
Last Login
Status
Account - View Time Settings
Enables users to view the following field values in all accounts:
Date Format
Time Zone
Users can see their own personal data regardless of the permissions granted.
New Personal Data-Related Group Permissions
Out of the above listed group level permissions, the Account - View Username, Account - View Presence and the Account - View Time Settings permissions have newly been introduced to refine the handling of personal data.
* 
The Account - View Username, Account - View Presence and Account - View Time Settings permissions are automatically granted to existing user groups during the upgrade. System Administrators can revoke any personal data-related group permission manually, if needed.
The personal data-related permissions must be managed manually when creating new user groups.
Account - View Username
The Account - View Username permission sets the visibility of the User Names of other users to the members of a user group.
The following table details how the User Names are displayed with and without the Account - View Username permission.
Permission
If Granted
If Revoked
Account - View Username
The User Names of other users are displayed to the members of the user group
In the Personal Details section on the Account page.
As user account links in Member type of fields, widgets and comments.
In a tooltip when hovering over the avatars of other users.
On the Members list on page Members of the project.
On the Release Dashboard page.
The User Names of other users are masked with asterisks on the user interface from the members of the user group
In the Personal Details section on the Account page where the First Name and the Last Name of other users are available and displayed.
The user account links are displayed in the form of First Name and Last Name in Member type of fields, widgets and comments.
Neither the User Name, nor the First Name and Last Name are displayed in tooltip when hovering over the avatars of other users.
On the Members page of the project, users can only see their own User Names. The User Names of other users are masked with asterisks.
* 
Regardless of whether the Account - View Username permission is granted or not, the First Names and Last Names of other users are always displayed on the account details popups when hovering over user account links.
If the Account - View Username permission is revoked, the First Name and the Last Name of other users are displayed on the user interface by default. To modify the default setting, see the"login" application configuration.
Account - View Presence
The Account - View Presence permission sets the visibility of presence information of other users to the members of a user group.
The following table details how the presence information of other users is displayed with and without the Account - View Presence permission.
Permission
If Granted
If Revoked
Account - View Presence
The Last Login, Registered and the Status field details of other users are displayed in the Personal Details section on the Account page to the members of the user group.
On the Members list on page Members of the project,
The user account links of other, logged-in users are displayed in italics while the user account links of logged-out users are displayed in normal font style. The user account links of inactivated users appear with strikethrough formatting.
Green status indicator are displayed next to the user account links of the logged-in users.
In tracker items, on the Choose Roles and Members overlay, no status indicators are displayed next to the user account links in column Account. The account links of the logged-in users are displayed in italics, and those of the logged-out users are displayed in normal font style.
Users see their own user account link in italics.
On Release Dashboard and in Release planner , the green status indicators are displayed next to the user account links of the logged-in users. The user account links of both the logged-in and logged-out users are displayed in normal font style.
On the account details popup, the Presence and Last Activity at fields are displayed.
The Last Login and the Registered field details of other users are masked with asterisks, while the Status field is not displayed in the Personal Details section on the Account page.
In the User Profile wiki widget, the Last Login, Registered and the Status field details of other users are masked with asterisks to the members of the user group.
All user account links are displayed in normal font style on the Members page of the project, on the Choose Roles and Members overlay, on Release Dashboard and in Release planner regardless of whether the users are logged-in or not.
No status indicators are displayed next to the user account links of users who are logged-in
On the Members list on page Members of the project.
On Release Dashboard and in Release planner.
On the account details popup, the Presence and Last Activity at fields are not displayed.
Account - View Time Settings
The Account - View Time Settings permission sets the visibility of Time Zone and Date Format information of other users to the members of a user group.
The following table details how the Time Zone and Date Format information of other users is displayed with and without the Account - View Time Settings permission.
Permission
If Granted
If Revoked
Account - View Time Settings
The values of the Time Zone and Date Format fields of other users are visible to the members of a user group
In the Personal Details section on the Account page.
In the User Profile wiki widget.
The values of the Time Zone and Date Format fields of other users are masked with asterisks to the members of a user group
In the Personal Details section on the Account page
In the User Profile wiki widget.
Account - View Email Address and Accounts - Administer Permissions
The already existing Account - View Email Address and the Accounts - Administer permissions have been updated to manage and protect personal data.
Account - View Email Address
The Account - View Email Address permission sets the visibility of Language and Email field values as well as the visibility of the avatars of other users to the members of a user group.
The following table details how the Language and Email field values as well as the visibility of the avatars of other users are displayed with and without the Account - View Email Address permission.
Permission
If Granted
If Revoked
Account - View Email Address
The Language and Email field values of other users are displayed
In the Personal Details section on the Account page.
In the User Profile wiki widget.
The avatars of other users are displayed
In the Personal Details section on the Account page.
In the User Profile wiki widget.
In the Activity Stream widget.
The Language and Email field values of other users are masked with asterisks
In the Personal Details section on the Account page.
In the User Profile wiki widget.
The avatars of other users are replaced by the anonymous avatar
In the Personal Details section on the Account page.
In the User Profile wiki widget.
In the Activity Stream widget.
Accounts - Administer
The Accounts - Administer permission has been updated for the more efficient management and protection of personal data.
The following table details how the Accounts - Administer permission interworks with the personal data protection-related permissions.
Permission
If Granted
If Revoked
Accounts - Administer
The following permissions in the user group are automatically selected and cannot be revoked:
Account - View Address
Account - View Company
Account - View Phone
Account - View Email Address
Account - View Skills
Account - View Username
Account - View Presence
Account - View Time Settings
The Edit Account option is available when visiting the account page of other users.
All fields and field values on the Edit Account page are visible, the values can be modified, and the changes can be saved.
The following permissions in the user group can be managed manually:
Account - View Address
Account - View Company
Account - View Phone
Account - View Email Address
Account - View Skills
Account - View Username
Account - View Presence
Account - View Time Settings
The Edit Account option is not available when visiting the account page of other users.
* 
When upgrading Codebeamer, all existing user group permissions are updated. If the Accounts - Administer permission is granted, all the Account - View... permissions are granted automatically.
Handling Personal Data in Microsoft Office Exports
The following tables demonstrate how personal data is displayed in the exported Microsoft Office files.
Microsoft Office Word
Permissions
If Granted
If Revoked
Account - View Username
If the "${account}" parameter is defined in the "login": "accountLink" Application Configuration, and the Account - View Username permission is granted to the exporting user, the User Names of other users are displayed in the exported Word documents in the same format as on the user interface when exporting tracker items, Wiki pages with mentioned users and Wiki dashboards.
The personal data of other users is always exported according to the "login": "accountLink" Application Configuration setup, regardless of whether the round trip option is available or not.
If the "${account}" parameter is defined in the "login": "accountLink" Application Configuration, and the Account - View Username permission is revoked from the exporting user, the First Names and Last Names of other users are displayed in the exported Word documents instead of the User Names when exporting tracker items, Wiki pages with mentioned users and Wiki dashboards to Microsoft Word, mirroring their display on the user interface.
If additional parameters for which the exporting user has permissions are defined in the "login": "accountLink" Application Configuration, and consequently appear in the exported Word documents, the User Names of other users are masked with asterisks.
Account - View Email Address
If the "${email}" parameter is defined in the "login": "accountLink" Application Configuration, and the Account - View Email Address permission is granted to the exporting user, the email addresses of other users are displayed in the exported Word documents in the same format as on the user interface when exporting tracker items, Wiki pages with mentioned users and Wiki dashboards.
When hovering over the User Names of other users in the exported Word documents, their email addresses are displayed in the tooltip that appears.
* 
If the Account - View Presence permission is granted to the exporting user, the Last Login details of other users are displayed in the tooltip that appears.
If the "${email}" parameter is defined in the "login": "accountLink" Application Configuration, and the Account - View Email Address permission is revoked from the exporting user, the email addresses of other users are masked with asterisks in the exported Word documents when exporting tracker items, Wiki pages with mentioned users and Wiki dashboards to Microsoft Word, mirroring their display on the user interface.
When hovering over other users in the exported Word documents, their email addresses are masked with asterisks in the tooltip that appears.
* 
If the Account - View Presence permission is revoked from the exporting user, the Last Login details of other users are not displayed in the tooltip that appears.
Microsoft Office Excel
Permission
If Granted
If Revoked
Account - View Username
If round trip export is available, for instance, in case of tracker items, always the User Names of other users are exported, regardless of the "login": "accountLink" Application Configuration setup.
If round trip export is not available, for example, in case of the Members or Reports page, the personal data of other users is exported and displayed according to the "login": "accountLink" Application Configuration setup.
If the Account - View Username permission is revoked from the exporting user, the First Names and Last Names of other users are displayed in the files when exporting tracker items and project members to Microsoft Excel.
If Round trip export is available, but the Account - View Username is revoked, the First Names and the Last Names of other users are exported.
Account - View Email Address
If the Account - View Email Address permission is granted to the exporting user, the email addresses are exported when exporting project members to Microsoft Excel.
If the Account - View Email Address permission is revoked from the exporting user, the email addresses are masked with asterisks in the files when exporting project members to Microsoft Excel.
Microsoft Office Project
Permission
If Granted
If Revoked
Account - View Username
If the Account - View Username permission is granted to the exporting user, the User Names of other users are displayed in the files when exporting tracker items to Microsoft Office Project.
If the Account - View Username permission is revoked from the exporting user, the First Names and Last Names of other users are displayed in the files when exporting tracker items to Microsoft Office Project.
Account - View Email Address
If the Account - View Email Address permission is granted to the exporting user, the email addresses of other users are exported to Microsoft Office Project.
If the Account - View Email Address permission is revoked from the exporting user, the email addresses of other users are not exported to Microsoft Office Project.
Handling Personal Data in Notifications Emails
Personal data included in notification emails sent to involved users is displayed according to the recipient user's personal data permission settings.
Users do not have access to any personal data in notification emails for which they do not have permission in the UI.
For example, if the recipient does not have Account - View Username permission, the User Names of other users are either masked with asterisks or replaced with their First Names and Last Names in the email, depending on the recipient’s permissions and the "accountLink" configuration.
Handling Personal Data in Swagger User API Endpoints
The Account - View... group permission settings affect the operation of the User API endpoints. For details, see Swagger V3 User API.
Was this helpful?