Exclude fields from an export: sensitive data and GDPR
By default, an export removes two families of fields: fields marked GDPR and eight field types. This applies to FTP / SFTP and Metabase exports. Both families arrive ticked in a single list, Fields to exclude. Untick a field to keep it. This guide explains the logic of these settings, the special cases and how to check the file.
Are you in the configuration window of a transfer? The step by step of the Exported fields section is in the article of your export. FTP / SFTP: chapter 5.6 Choose the exported fields (FTP / SFTP). Metabase: chapter 2.1 Choose the exported fields (Metabase). This guide explains the logic behind these settings. It is for the workspace owner and administrators. The screenshots show the interface in English.
A field stays out of the file for one of two reasons. It is marked GDPR / confidential, or its type is not exported by default. The Fields to exclude list brings both together, with the reason for each field.
1.1 Fields marked GDPR / confidential
Two settings work together. The GDPR / confidential marking in the table says which fields hold personal data. The Exclude fields marked GDPR / confidential checkbox in the export says whether these fields go into the file. One without the other protects nothing.
1
Mark the fields with the GDPR / confidential marking option
Field menu → GDPR / confidential marking → Sensitive. Linked table columns and Link to another table columns inherit the marking, formulas do not. Details: GDPR / confidential marking: mark a field.
2
Keep the Exclude fields marked GDPR / confidential checkbox ticked in the export
Exported fields section → Exclude fields marked GDPR / confidential, ticked by default. Every sensitive field is removed from the file, including those marked later.
3
Check the file with Test config
Test config shows the fields that will really be sent.
Without GDPR / confidential marking in the table, the export checkbox excludes nothing. Without a ticked checkbox in the export, the marking removes nothing from the file.
1.2 The eight field types not exported by default
Eight field types are not exported by default: their value is hard to read in a flat file. The Exclude non-exportable field types by default checkbox ticks them, and the linked table columns that read one of them. To export one anyway, untick it in the Fields to exclude list. An attachment kept this way goes out as a link.
Comments
History
URL
Attachment
Email
Phone
Smart text
External form
Email, Phone and URL: excluded by their type, not protected under the GDPR. They leave the file because of their format, not because they hold personal data. This exclusion stops as soon as the field types checkbox or the field is unticked, with no warning. An email typed into a text field is not excluded at all. Judging whether a field holds personal data remains your responsibility. If it does, mark it Sensitive → GDPR / confidential marking: mark a field.
1.3 What GDPR / confidential marking does not do
It does not hide the field in the application
Every member who could see the field still sees it. Marking only drives the content of exported files.
It does not change your existing exports
An export created before the marking keeps its settings. Open it and tick the checkbox to apply it.
2. What do the two checkboxes of the Exported fields section do?
The section holds two checkboxes and the Fields to exclude list. Each checkbox ticks a whole group of fields in the list at once. The list decides everything: a ticked field does not go out, an unticked field does.
Exclude fields marked GDPR / confidential
Ticks every sensitive field: marked in the table, or inherited. The checkbox is recalculated at every run. A field marked later is excluded without touching the export.
Exclude non-exportable field types by default
Ticks the fields whose value is hard to read in a flat file: comments, attachments, history. The full list is in chapter 1.2.
2.1 The four combinations of the two checkboxes
Setting
What goes into the file
No checkbox
Every field of the view, including GDPR fields and field types not exported by default.
GDPR checkbox only
Everything except sensitive fields.
Non-exportable types checkbox only
Everything except these types. GDPR fields go out, and a warning points it out.
Both checkboxes
Only fields that are neither sensitive nor of a type not exported by default.
Each row of the table matches a real situation. Here is what happens in each one.
No checkbox: the file holds everything
This is the state of an export created before this release. Name, email, comments, attachments: everything goes into the file. A GDPR fields message shows in the section if fields are marked in the table.
GDPR checkbox only: personal data stays with you
Fields marked Sensitive and those that inherit from them are removed. Comments or attachments still go out, in a form that is hard to read in a flat file. Suitable when the recipient needs everything except personal data.
Non-exportable types checkbox only: the file is clean, but not compliant
Comments, history, attachments and the other types of the list are removed. GDPR-marked fields still go out. The GDPR fields message stays on screen, and every run is logged.
Both checkboxes: the recommended and default setting
Only useful fields without personal data go out. The GDPR fields message disappears. A field marked later is excluded at the next run, without reopening the export.
2.2 What happens if you untick the GDPR checkbox?
By default, the Exclude fields marked GDPR / confidential checkbox is ticked: this message does not show. It appears if the checkbox is unticked and marked fields go into the export. The screenshot below shows the two places where it appears.
1. At the top of the section: exclude or keep
The message lists the marked fields that go into the export. Click Exclude fields marked GDPR / confidential to remove them. Click Keep them in the export to keep them.
2. Under the Fields to exclude list: a reminder
If you keep these fields, a second message lists them again. Every run of the export is then logged.
3. When you save: a confirmation
An Export of GDPR / confidential fields window lists the marked fields that go out. Save anyway confirms. Cancel takes you back to the section.
The step by step when this message appears → chapter 6.
3. Tick the GDPR checkbox or pick the fields one by one: which is better?
Keep the Exclude fields marked GDPR / confidential checkbox ticked for anything related to GDPR. It follows the marking changes in the table. A field-by-field selection in the Fields to exclude list is a snapshot of the day you made it.
Setting
A sensitive field is added the following month
GDPR checkbox ticked
It is excluded automatically. Nothing to do.
Checkbox unticked, fields ticked by hand
It goes into the file. The list only knows the fields ticked that day.
Keep field-by-field selection for a file that is too wide, to remove fields unrelated to GDPR.
4. How do you keep a GDPR-marked field in the exported file?
Your choice in the Fields to exclude list always wins, over the two checkboxes and over chained exclusion.
1
Open the Fields to exclude list
Each field shows its reason: Marked GDPR / confidential, Inherited GDPR / confidential or Non-exportable type.
2
Untick the field to keep
It goes back into the file. Every other field stays excluded.
3
Test, then save
Test config confirms the field is back among the exported fields.
Example: an export to Metabase must contain the customer email. Keep the GDPR checkbox ticked, then untick only Customer email. The other sensitive fields stay excluded.
5. Why does an unmarked field disappear from the exported file?
Fields derived from an excluded field are excluded too. The exclusion follows the chain all the way, from one table to another. Removed data does not reappear under another name.
Linked table column
Follows the exclusion. A linked table column that reads it follows it too.
Link to another table column
Follows the exclusion of the field on the other side of the relation.
Formula
Does not follow: a formula has no Inherited state. Mark it Sensitive by hand if it copies personal data.
5.1 Chained exclusion example: Customers and Orders tables
The Email field of the Customers table is marked Sensitive and excluded. Here is what happens in the Orders table.
Field
Result
Customers: Email
Excluded: marked GDPR / confidential in the table.
Stays in the file: formula that reads Customer email. Excluded only if you mark it Sensitive.
Orders: Total (excl. VAT)
Stays in the file: formula that reads Quantity and Unit price.
Formulas do not inherit the marking. This is a product choice: a formula only offers Sensitive and Not sensitive. It is Not sensitive by default, even if it reads a sensitive field. It does not appear in the Fields to exclude list and goes into the file. Mark as Sensitive, by hand, every formula that copies personal data. Example: a label that joins name and email. A formula that does not reproduce the data, such as initials or a TRUE / FALSE, can stay exported.
6. What should you do when the GDPR fields warning appears in the export?
A warning lists the GDPR fields that still go into the file. It appears, for example, when a field was marked after the export was created.
1
Read the list of the fields concerned
These are the sensitive fields the export still sends.
2
Choose one of the two buttons Exclude fields marked GDPR / confidential ticks the checkbox of the same name. The fields are excluded and the warning disappears. Keep them in the export keeps the fields knowingly. A reminder stays below the list and every run is logged.
3
Confirm when you save
A confirmation window lists again the GDPR fields that still go out. Confirm to save, or cancel to go back to the list.
7. How do you check the file with Test config before scheduling the export?
Test config applies the same logic as a real export: the two checkboxes, unticked fields, chained exclusion.
1
Click Test config
TimeTonic prepares the file with your settings, without sending it.
2
Check the fields shown
They are the ones that will be sent. An excluded field is missing from the header, it is not exported empty.
3
Save Save or Save and close. As long as a change is not saved, the Close button becomes Cancel and closes without keeping anything.
Export to Metabase: removing a field changes the shape of the table. Any Metabase question or dashboard that used that field stops working. Refresh the schema in the Metabase admin, then fix the affected questions.
An encrypted field kept in the export comes out as an asterisk: its value is never written in clear.
8. Three practical cases of GDPR / confidential marking and export
An HR table sent to the payroll provider
Last name, First name, Personal e-mail and Social security number are marked Sensitive. The weekly export ticks the GDPR checkbox. The file only holds Department and Cost centre. A Personal phone field added later is excluded from the next run.
A formula that would leak a name
The Full label formula joins Last name and Contract number. Last name is marked Sensitive. The formula stays Not sensitive and is not excluded. Mark it Sensitive by hand: the GDPR checkbox then excludes it like the others.
A dashboard that needs the email
The Orders table export ticks the GDPR checkbox. Customer email is unticked in the list. It goes into the file. Customer contact stays excluded, and so does Invoice label, marked by hand.
9. Frequently asked questions on GDPR / confidential marking and exports
Should I mark an Email field that is already excluded by default?
Yes, if it holds personal data. Email, Phone and URL are excluded for their format, not under the GDPR. This exclusion disappears if the field types checkbox or the field is unticked, with no warning. Marked Sensitive, the field is excluded under the GDPR, and the GDPR fields warning appears if it goes back into the export.
My old export excludes nothing. Is that normal?
Yes. Exports created before this feature keep their settings: no checkbox ticked, no field ticked. Nothing changes without your action. Open the export, tick the Exclude fields marked GDPR / confidential checkbox, then save. The sensitive fields are removed from the next run onwards.
A field I wanted to keep has disappeared. Why?
It reads an excluded field. Chained exclusion removed it. A linked table column or a Link to another table column always follows its source field. Untick it in the Fields to exclude list to keep it: your choice wins over the checkboxes and over the chain.
My Metabase dashboard no longer works. Why?
Excluded fields are no longer sent. Removing a field changes the shape of the table on the Metabase side. Any question or dashboard that read it stops working. Refresh the schema in the Metabase admin, then fix the questions that used those fields.
More fields than expected were excluded. Why?
A linked table could not be read while the export was prepared. Its linked table columns and Link to another table columns are then treated as sensitive, as a precaution. The run log reports it. Run the export again once the table is reachable: the fields come back by themselves.
Does marking hide the field in the application?
No. Every member sees it as before. Marking only drives the content of exported files. To hide data from some members, use an encrypted field or restrict access to the field by view. Both of these settings combine with the marking.
Does the manual CSV export follow these settings?
Partly. You can exclude fields one by one when you download. The two checkboxes do not exist there, so marked fields are not removed automatically. Check the whole list carefully before you confirm, especially for a table that holds personal data.
Go further
Mark a field as personal data
The three states, inheritance and who can change it.