CodamAIDocs
Topicdone

Data protection and retention

Which personal data the audit contains and how long revisions are kept.

Variants
data about the acting persondata in the object contentafter the object is deletedretention without expirywho may read the history

What this is about

Auditing keeps every change, with the content of the object and with details about the person who made the change. Both can be personal data, meaning information that can be linked to a human being. The rules of data protection apply to it, for example the GDPR.

CDMS provides the recording. How long the data may stay and who may see it is up to your project.

Where personal data lives

flowchart LR
    subgraph DB["Tenant database"]
      R[("revinfo<br/>user_id · username<br/>ip_address · user_agent<br/>acting_user_id · acting_username")]
      A[("person_AUD<br/>every old state:<br/>name, email, address …")]
      T[("person<br/>only the current state")]
    end
    subgraph FS["File storage"]
      V["&lt;fileId&gt;.&lt;identifier&gt;<br/>old file contents"]
    end
    R --- A
WhatWhereVisible through the API?
user namerevinfo.usernameyes, revisionMeta.username
IP addressrevinfo.ip_addressyes, revisionMeta.ip
browser or programrevinfo.user_agentyes, revisionMeta.useragent
user IDrevinfo.user_idno, only in the database
acting person after a user switchrevinfo.acting_username, revinfo.acting_user_idname yes, revisionMeta.actingUsername; ID only in the database
every old state of the object<table>_AUDyes, revision in the history
old file contentsversions in the file storageonly through a rollback

Where the values come from is explained in What a revision records.

Two kinds of data

Personal data in the history
About the acting person
in every revision
  • name and ID from the token
  • IP address and user agent of the request
  • created for every audited model, even for purely technical data
  • shows who worked when
In the content of the object
depends on the model
  • everything that is in the object, for example name, email, address, notes
  • including values that were changed or emptied later
  • including file contents for file models
  • depends on what you model

How long revisions stay

CDMS deletes no revision. There is no endpoint that deletes, shortens or anonymizes revisions, and no built-in retention period.

What happens to revisions over time

When: PUT, PATCH, upload, rollback

The old state stays as a revision. So emptying a field does not remove the old value from CDMS, it is still in the older revision.

When: DELETE, directly or through a cascade

The row disappears, the history stays complete. The DEL revision itself is empty except the id, but every revision before it contains the content.

Result: See What remains after a delete.

When: audited file model

Old contents stay as long as the record exists. When the record is deleted, the content and all versions are removed, the history of the record stays.

Result: See File versions.

When: The model is set to not audited.

New changes are no longer recorded. The existing revisions stay in the database.

Deleting or anonymizing revisions is therefore a task at database level, outside the CDMS API. Because every tenant has its own database with its own revinfo, such an intervention always affects only one tenant.

Who may read the history

The history of an object can be read by whoever has the read role and the history role of the model – and who would have been allowed to read the object itself. The row filters that run along when reading and searching, for example the owner filter, apply here too. For a deleted object, its last state before the deletion counts. See Reading the history.

That limits who sees the personal data in the history, but it does not lift the warning above: whoever may read an object sees all its old states as well, with the history role.

What your project has to watch out for

Should this model be audited?
Proof or rollback needed?contains personal data?Recommendation
no–do not audit
yesnoaudit. Personal data is still created through name and IP address of the acting person.
yesyesaudit, but decide on retention, read permissions and how to handle deletion requests first

Pitfalls

What comes next

Sources in the code and the knowledge base
  • CDMS/cdms-persistence-database – auditing/AuditRevisionEntity (revinfo: user_id, username, ip_address, user_agent, acting_user_id, acting_username), AuditRevisionListener, AuditHistoryReader (no deleting/shortening of revisions; store_data_at_delete not set); docs/adr/ADR-019 (Envers append-only)
  • CDMS/cdms-system-layer – AbstractLayer.queryHistory (read and history role, assertHistoryVisible)
  • CDMS/cdms-localfs-storage – retainCurrentContent (versions without cleanup, ADR-018)
  • CIAS/cias-authentication – JwtSessionFilter (IP, user agent), TokenParser (userId, userName)
  • documentation/50-auditierung/01-auditing-und-historie.md (section data protection)
Search