FAQ - Baseline GDPR Toolbox
On this page, we have compiled the most common questions for the Baseline GDPR Toolbox. You are of course always welcome to contact us at gdprtoolbox@itm8.com if you do not find the answer to your question below.
Please note that your company may have selected some other settings on the Baseline GDPR Toolbox than the FAQ below describes.
What is GDPR?
When was the GDPR enforced?
On May 25th 2018, the EU Personal Data Regulation called the General Data Protection Regulation (GDPR) became effective throughout the EU. Companies, public authorities and organizations processing personal data must now comply with the new regulation.
Why GDPR?
The purpose of the GDPR is first and foremost to create security around personal data. The GDPR requires organizations to protect personal data through organizational administrative and technical measures, and this protection must be documented.
Are you in doubt about how to deal with the GDPR?
Our best recommendation is to contact your immediate manager.
Baseline GDPR Toolbox
What is Baseline GDPR Toolbox? add
It is an solution that ensures that GDPR data in emails and files are identified and handled. The solution automatically scans GDPR data for the individual employee and makes it easy and clear to handle GDPR data.
How often does the Baseline GDPR Toolbox scan? add
The solution is constantly scanning for new GDPR data.
Users receive a new notification email every month, but it is always possible to use the link in the notification email to go in and get the current image.
Important information about who should not be scanned add
Some people should not be scanned for GDPR data:
- Union Representative - It is not allowed to scan emails for a union representative unless you have the person's written permission. Therefore, you must either have it or fail to select a trust representative for scanning .
- Leave, maternity leave or long-term sick leave - You must be aware that users on leave, maternity leave or long-term sick leave do not look at the notification reports that are sent out. This means that they can potentially have their GDPR emails deleted without having assessed them*. Therefore, they may not need to be marked for scanning or removed from the scan list. You can change your decision by add/remove to AD group or notifying gdprtoolbox@itm8.com
Note: Your company chooses whether Automatic Deletion of GDPR related mails / documents should be activated.
What criteria does the Baseline GDPR Toolbox scan for? add
The solution scans according to a wide range of criteria. The criteria are composed on the basis of the Danish Data Protection Agency's guidelines for what GDPR-related content is:
- Sensitive information
- Health information
- Trade union membership
- Ethnic and religious beliefs
- Sexual orientation
- General information
- PII-pictures (Personal Identifiable Information)
- Travel information
- Confidential information
- CPR & +20 European countries national ID
- Danish driver's license & +20 European countries Danish Passport & +20 European countries
- Written warnings
- Annual accounts
- Salary / Loans
- Application / Job offer / CV
- Commissions / Bonus Agreements
- Termination
- Criminal offenses
- Criminal record
- Offenses, fines, convictions
Insight Search add
Insight search on defined person (name / civil registration number) can be done via the team behind Baseline GDPR Toolbox
For help with this, write an e-mail to gdprtoolbox@itm8.com.
The established procedure for this is subsequently followed in collaboration with your contact person responsible for GDPR Toolbox.
Notification e-mail
What is a notification email? add
Every month, a notification email is sent out to users.
The link to the notification report in the mail is the same from time to time, so it is always possible to use that link to get in and check its current status.
You can save it in your browser and use it every time you go in and check your GDPR status. Also in the middle of the month.
You can also share it with your colleagues in the organization. It is your AD login that determines what you get access to.
Notification email is sent for each data source scanned. They have the following subject line in email:
- Baseline GDPR Toolbox rapport (for Mail + SharedMail + OneDrive)
- SharePoint – Baseline GDPR Toolbox rapport
- FileShare – Baseline GDPR Toolbox rapport (for Professionel-customers)
Can we reissue notification reports to individuals? add
Baseline GDPR Toolbox cannot issue new notification reports with links to individuals.
We can send out a new notification report to everyone in the company
otherwise he / she has to wait for the next automatic broadcast on the 7th of next month
But you can share your link with your colleague. It is your AD login that determines what you can see in the notification report.
Where does notification email come from? add
Every month we send out notification emails to those users who have potentially GDPR sensitive emails.
It is important to note where mail is sent from, as hackers can also send emails out to fish for data.
If you receive a notification email from Baseline GDPR Toolbox, then the header should look like this:
From: gdprtoolbox@itm8.com
Sent: Jan 1, 2024 4:03 pm
To: XXXXXXXXX
Subject: Baseline GDPR Toolbox report
You receive mails from gdprtoolbox@itm8.com
Why send an internal email to everyone before the first notification email is sent out? add
Notification email contains a link that leads to a web page with the notification report, where you can see all the emails that potentially contain GDPR data.
This notification email comes from the Baseline GDPR Toolbox.
It is important to inform all users before the first broadcast that an email is coming from the Baseline GDPR Toolbox and that it is ok.
Users are warned again and again (and with good reason) that they do not click on a link in an email from an unknown sender.
There is a risk that users will delete notification emails, because "they have learned that".
Therefore, an internal email must be sent out so that users are informed that the notification email is in order.
When will I receive an e-mail notification? add
Notification is sent out when the company has decided to get started. The e-mail will then be sent out once a month.
Experience shows that the period just around the 1st in a month creates a lot of pressure for both customers and suppliers.
There are time registrations, month-ends and invoicing, so there does not have to be a notification email that you have to correlate to.
Therefore, we move the sending out of the monthly mail to the 7th of the month.
It is always possible to use the link in an old email to access GDPR portal, but the broadcast of mails takes place on the 7th of the month.
Who will receive the notification e-mail? add
Notification e-mail will be received by each user in their personal mailbox. Notification email contains information about Mail, OneDrive and shared mailboxes, if you are responsible for such. Sharepoint folders that are included in GDPR scanning will also receive notification emails for these.
Best practice is to only send emails to the people who have potentially GDPR sensitive data. Therefore, emails are only sent to users who have potentially GDPR sensitive data.
If you get a notification email and think your notification report is empty, check if you have data in DeleteNow, Private or Dispensation tabs. There may still be GDPR data in these tabs.
What does a notification e-mail contain? add
Each notification e-mail contains a link to the Baseline GDPR Toolbox server, where it is possible to see which documents potentially contain GDPR data for the individual user.
It can be shared between colleagues, as the link is the same. It is your AD login that determines what you can see in GDPR Toolbox.
Link and notification e-mail are the same from time to time, so it can be saved in favourites, so you can always check your GDPR data without having to wait for the next notification e-mail.
Notifcation report
How do I access the notification report? add
Access to the notification report can be obtained via the link in the notification email.
You get access to your Notification Report using your regular AD login.
When you click on the link in your Notification Email, a browser with a login page opens.
You must select "Sign in with Office 365" and enter your AD login information.
Note: It is NOT possible to log in by pressing Advanced Login.
When does data appear in the Notification Report? add
Data must be at least 3 months old and contain one or more GDPR words to appear in the notification report.
Why do I get a notification email when my list is empty when I access it? add
Best practice is to only send emails to the people who have potentially GDPR sensitive data. Therefore, emails are only sent to users who have potentially GDPR sensitive data.
If you get a notification email and think your notification report is empty, check if you have items in the Delete Now, Private or Dispensation tabs. There may still be GDPR data in these tabs
Synchronization folder in Outlook add
Occasionally, GDPR sensitive emails appear in notification reports placed in synchronization folders.
That folder can be difficult to find in Outlook, so here is help to find folders:
Tap the 3 dots below mail folders in Outlook:
Select "Folders" / "Folders"
It is now possible to view synchronization logs with other mail folders
It is removed again by pressing the mail folder again.
Mails that are down here are mails that for one reason or another failed while syncing Outlook.
They can usually be deleted without further inspection.
How does a notification report work? add
The individual user has the following options for handling GDPR data
- Marking as "Misclassified" on datasets (mail and documents) that are still not related to GDPR data. The dataset marked "Misclassified" will not appear in the future notification report.
- Marking as "Private" on datasets (emails and documents) that are related to the user as a private person. The dataset marked "Private" will continue to appear in the future notification report in a tab in top of notification report..
- Marking as "Dispensation" on the dataset (mail and documents) on which there is a need to continue to keep the information. The dataset marked "Dispensation" will continue to appear in the future notification report in a tab in top of notification report.
- Marking as "Delete" on the dataset (mail and documents) that must be deleted now (the deletion takes place by a run that is made within a day).
If you are in doubt about how the remaining GDPR-related elements should be handled after handling, reach out to the company's GDPR contact person.
The data set marked with "Misclassified", "Private" and "Dispensation" is still displayed in the report via the customer portal. See more under the item: Reporting / Customer portal
Automatic deletion of mails and documents and age of mails add
NOTE: Customer-specific configuration of the following may be agreed differently for your company.
Your company chooses whether Automatic Deletion of GDPR related mails / documents should be activated.
When an email / document has appeared in a notification email for 2½ months (3 times) because it contains GDPR data, it is deleted automatically if the user has not responded with a tagging. (Dispensation, Misclassified, Private, Delete-Now)
This means that an email is a minimum of 5½ months.
It only appears in a notification report when it is 3 months old.
When a customer is put into operation, there may be some old data that needs to be handled and it is not certain that everything has been processed to the start date.
Therefore, "Automatic Deletion" will not be initiated until we are sure that all "backlog" has been processed and the customer has had a reasonable time to check old mails.
When the Baseline GDPR Toolbo automatically initiates deletion, the age of the email applies. Mail must be older than 3 + 2½ = 5½ month.
Notification report overview add
When you click on the link in your notification email, you will be asked to log in with your site AD username.
Once you have done that, the notification report opens (Here a danish version):
The notification report is divided into 4 parts:
- Tabs
- Purpose text
- Search field and filtering and quantity information
- Handling of GDPR elements
See the next 3 sections on handling the individual sections.
Tabs add
At the top of the notification mail are different tabs:
- Data set – These are all potential GDPR elements that have not yet been processed. This is where your work should take place
- Deleted – All the emails you have deleted, but which have not been deleted in your mailbox yet. This is done once a day, so you have time to regret
- Private – All the items you have marked Private are in this list.
- Dispensation – All the items you have marked as Dispensation are in this list and will remain there until you finish working with them and remove the “Dispensation” mark. They are then moved to the dataset page and can be processed like all other GDPR data elements.
If you think you have handled all your GDPR data and therefore should not have an email with reminders, look in Private and Dispensation. There may be data that still has GDPR content.
Private data can be viewed by clicking on the Private tab:
Dispensation data can be viewed by clicking on the Dispensation tab:
Purpose text add
The text provides a quick description of what data has been found and what can be done about it.
It is possible to use "Show more" to display the entire text
Search field and filtering and quantity information add
You can search your GDPR elements by typing in the search field and pressing return.
If you press the 3 horizontal filter lines with bubbles on them, the filter section unfolds:
You can select and deselect filters by clicking on them and fold the filter in by pressing 3 horizontal filter lines again.
On the right you will see information about
- Number of GDPR elements you have put in your trash, but they are not deleted in Outlook yet.
- Number of GDPR elements displayed on current page
- Number of GDPR elements you have in total
Search field and filtering and quantity information add
The lower part of the Notification Report contains all the GDPR elements found for a given mailbox/folder/Site.
In the example shown, there is only GDPR data in Mail. If there are GDPR elements in OneDrive or shared mailboxes for which the user is responsible, then there will be more items in the folder structure.
The notification report for a mailbox is displayed here, but there may also be additional Folder items for OneDrive and Shared mailboxes for which you are responsible:
The placement of your GDPR-related items can be displayed via the presented folder structure in the left menu.
The folder structure presents the folder structure that you have, for example, in your Outlook "Inbox".
Thereby, you can handle the GDPR handling based on the folder structure.
It is possible to get a preview of the individual dataset if you press '+'.
Then the individual dataset is unfolded and you can see why it was marked as GDPR.
Afterwards you can close it again by pressing '-'
Each individual piece of data can be marked with
- Dispensation
- Misclassified
- Private
To mark, click on the 3 vertical dots to the right of the element.
This gives you the opportunity to mark which type you want.
You can also mark several elements and handle them several at a time
A 'taskbar' opens at the bottom of the page, where you can choose an action:
If you click on the 3 vertical dots, you can check whether all selected elements should be marked as Misclassified, Private or Dispensation.
Onboarding guide and start-up
What options does the user have in the Baseline GDPR Toolbox? add
The individual user has the following options for handling GDPR data:
- Marking as "Misclassified" on datasets (e-mail and documents) that are not related to GDPR data anyway. The dataset marked "Misclassified" will not appear in the future notification report
- Marking as "Private" on the dataset (email and documents) that is related to the user as a private person. The dataset marked with "Private" will continue to appear in the future notification report in a tab at the top of the report.
- Marking as "Dispensation" on the dataset (e-mail and documents), after which there is a need to continue to keep the information.The dataset marked with "Dispensation" will continue to appear in the future notification report in a tab at the top of the report.
- Marking as "Delete now" on the dataset (e-mail and documents) that must be deleted now (the deletion takes place by a run that is made within 24 hours).
What is being scanned by the Baseline GDPR Toolbox? add
Baseline GDPR Toolbox basically scans the Microsoft 365 applications Exchange (mails and attachments), OneDrive and SharePoint and Teams sites (SharePoint sites).
Exchange Online Archive:
The Exchange Online Archive in Microsoft 365 is NOT scanned by default.
Feel free to contact gdprtoolbox@itm8.com for info about this.
If the Baseline GDPR Toolbox Professional version is used, onpremise file share is also scanned.
What is NOT going to be scanned with Baseline GDPR Toolbox? add
- E-mails and documents that have been omitted by the company (eg HR folders)
- Folders named "Private" in Outlook and OneDrive *1
- "Deleted record" in Outlook. We recommend instead that a delete policy should be created on the folder *1
- Meeting invitation in outlook *2
*1 Private and deleted mail will not be scanned per default, but it is possible to opt for scanning of this data as well
*2 When a meeting invitation is deleted, it can give a "reply" to the sender.
This often confuses the sender – especially if it is an old meeting invitation or from an external sender.
When and how is scanning executed? add
The solution scans 24/7 and the solution scans in "lumps" on different users and on the different data sources.
The solution does this to accommodate as many users as possible; i.e. that as many users as possible can start handling GDPR-related data as quickly as possible.
It is therefore not a question of the solution scanning a user "completely" before the solution moves on to the next user.
When a user is "finished", GDPR Toolbox still continues to control this person's data volume.
- Old emails may have been deleted in Outlook
- New emails arrive (older than 3 months)
- The scanning algorithms change *
* GDPRToolbox is continuously updated and improved with regard to scanning algorithms.
GDPR legislation is changing and fine-tuning to avoid false positives is constantly being done.
For example, 'Corona' was a Spanish girl's name in 2019, where it is now a health information.
PREVIEW option in onboarding add
Baseline GDPR Toolbox allows you to make 1 or 2 PREVIEW reports.
A PREVIEW report means that 5 to 6 selected employees get a PREVIEW notification report before everyone else and they therefore have the opportunity to test and get to know the system before it is sent out to everyone in the organization.
Only the PREVIEW notification report for Mail is sent.
It is important when the 5-6 people are selected that you choose people who can be thought to have GDPR data, as the solution only sends out if there IS GDPR data found on the individual user.
The 5-6 people are selected in connection with onboarding procedures, so that they can be started before everyone else and thus be longer in the scanning process.
How is the user advised by the Baseline GDPR Toolbox? add
The individual user receives an e-mail with a link to the Baseline GDPR Toolbox. Via the link, the individual user gets access to GDPR data related to the user's e-mails and documents.
Notification e-mails are sent once a month, but the link works all the time and the content is updated regularly. Therefore, the individual user does not have to wait until next month to review GDPR data.
Notification e-mails are sent separately for Exchange (mails), SharePoint OneDrive and FileShare (Baseline GDPR Toolbox Professional).
How do you count users in Baseline GDPR Toolbox? add
One Office 365 account counts as one Baseline GDPR Toolbox account.
Both personal and shared mailboxes count as one user each in the Baseline GDPR Toolbox solution and also cover scanning oneDrive belonging to the individual account.
SharePoint is scanned regardless of the number of accounts.
We do a count of the number of accounts in each month and this forms the basis for the settlement of the Baseline GDPR Toolbox.
How do you ensure the best and fastest possible processing of support cases? add
Our support team can be contacted here: gdprtoolbox@itm8.com
If it is a specific email we would like to know:
- To
- From
- Subject field (if you have it - or as much as possible)
- Date and time
It makes it easier for us to support you!
How to add and remove users from Baseline GDPR Toolbox scanning add
We handle scanning of users using an Entra AD (Former Azure Active Directory) group.
This means off-/onboarding of users happens by adjusting content in the Entra AD group.
If you are in doubt about which Entra AD group we use for your company, please write to
Note: However, it is necessary to handle on-prem solutions (Exchange servers and file scanning) and OnlineArchive scanning by adding/removing email addresses from the GDPR Toolbox manually.
Deletion of users in Office 365 add
When a user is deleted in Office 365, the user is removed from AAD groups.
This means that the user is removed from the Baseline GDPR Toolbox and all scanning of this user's data is removed.
Difference between Private Folder and Private Tag add
Private folder in Outlook
Datasets (documents and emails) that are located in the Private folder in Outlook or OneDrive are not included in the Notification report and are not included in the Baseline GDPR Toolbox reporting.
Note:
It is your company's decision whether data placed in Private folders in Outlook or OneDrive should be included in the Notification report or not.
"Private" marked with a tag in the notification report
Elements marked with "Private" will be excluded from the main list in Notification report, but will be shown in tab marked Privat and included in the Baseline GDPR Toolbox reporting
GDPR elements in Mailbox and OneDrive add
When a Mailbox / OneDrive folder is scanned, the notification email is sent to the owner of this Mailbox / OneDrive and it is the owner who can use the link to the notification report and process any. GDPR items on the list.
GDPR elements in Shared Mailbox add
When a shared mailbox is scanned, the notification mail is sent to the shared mailbox.
It is not possible to just log in with your own AD login, as the link is connected to the shared mailbox email address.
It is possible to set up one person responsible for handling shared mailboxes.
Write to gdprtoolbox@itm8.com for more information
GDPR elements in SharePoint add
It is possible to define the responsible for handling GDPR elements on existing SharePoint sites - this is done in the Baseline GDPR Toolbox onboarding procedure, where it is also possible to specify which sites may need to be omitted.
A 'Custodian Report' is sent to the GDPR Toolbox contact person or a person appointed by the GDPR Toolbox contact person.
In this special Custodian Report, it is possible to appoint someone responsible for the various SharePoint sites.
The person in charge of a SharePoint Site receives the notification email and can use the link to the notification report and process GDPR items on the list.
When new SharePoint sites are created in Microsoft 365, the notification email will by default be sent to the owner of the individual SharePoint Site and the owner can use the link to the notification report and process GDPR elements in the list. If it is not the right recipient, it is possible to change the owner using the custodian report.
If an owner of the individual SharePoint site has not been added to Microsoft 365, the site will be without an owner - an overview of owners of SharePoint sites can be seen via the Baseline GDPR Toolbox reporting on the customer portal.
Determination of responsible person in SharePoint takes place at Site level.
The Exchange/Outlook distribution list, so that more users can handle the GDPR elements on SharePoint sites, can be made.
This is not part of the Baseline GDPR Toolbox and is the responsibility of the Customer.
GDPR elements in FileShare (Baseline GDPR Toolbox Professional version) add
In connection with the launch of the Baseline GDPR Toolbox, it is possible to define the person responsible for handling GDPR elements on existing Fileshare folders - this is done via the Baseline GDPR Toolbox Professional onboarding procedure, where it is also possible to specify which folders need to be omitted.
A 'Custodian Report' is sent to the GDPR Toolbox contact person or person appointed by the GDPR Toolbox contact person.
In this special Custodian Report, it is possible to appoint someone responsible for the various folders.
The person responsible receives the notification email and can use the link to the notification report and process GDPR items on the list.
When new Fileshare folders are created in Microsoft 365, the notification email will by default be sent to the owner of the individual FileShare and the owner can use the link to the notification report and process GDPR elements in the list. If it is not the right recipient, it is possible to change the owner using a custodian report.
If an owner of the individual file folder has not been applied in Microsoft 365, the folder will be without an owner - an overview of owners of file folders can be seen via the Baseline GDPR Toolbox Professional reporting on the customer portal.
Determination of the person responsible for file folders takes place at folder level.
Exchange / Outlook distribution list so that more users can handle the GDPR elements on file folders can be created.
This is not part of the Baseline GDPR Toolbox and is the responsibility of the Customer.
Reporting / customer portal
What can you see in management overview / reporting? add
In connection with scanning of all users' data, access is opened for reporting on the company's GDPR status, which takes place via Customer portal. It is possible to get an overview of the company's GDPR data (without access to specific GDPR data) and the distribution of the different types of GDPR data.
Distribution of the various found GDPR data:
- Distribution by types
- Distribution over time
- Distribution by users (e-mail addresses)
- Distribution over datasets marked with "Misclassified", "Private" and "Dispensation"
What can NOT be seen in management overview / reporting? add
It is NOT possible to see the specific datasets, only the type and number and their distribution by user and sources.
How do I access the customer portal? add
User access to Cherwell Customer Portal
If you have access to the Cherwell Customer Portal, you must use this link
First, the contract that contains the GDPRToolbox is selected. There may be several contracts to choose from, although there is only one in the example shown. If you are in doubt which contract, write to us and ask.
To access the report, select ”Compliance” and then "Baseline GDPR Toolbox".
User access to the Ivanti customer portal
If you have access to the Ivanti Customer Portal, you must use this link:
When entering, you must choose a contract:
You can then select the Baseline report and view customer statistics
Your contact person gets a login to the portal.
More users can access, send an e-mail to gdprtoolbox@itm8.com and ask for access to more users.
SharePoint Sites have the same name add
Baseline GDPR Toolbox provides via the customer portal an overview of which SharePoint sites are inclusive and exclusive in the GDPR management.
If multiple SharePoint sites are created with the same name in Microsoft 365, then the respective SharePoint sites will also be with the same name in the Baseline GDPR Toolbox reporting.
Baseline GDPR Toolbox reporting provides an overview of who is responsible for GDPR management on the individual SharePoint sites.
Did you not find an answer to your question?
We are always ready to help you.
Contact your regular serviceprovider either by e-mail or phone.
Alternatively, you are welcome to write an email to gdprtoolbox@itm8.com