GDPR / confidential marking flags the columns that hold personal data, so you can exclude them from your exports. It hides nothing in the application. This article covers the GDPR / confidential marking option, its states and the logic behind them.
1. Where is the GDPR / confidential marking option?
The option sits in the menu of each column. It also exists in the column configuration window, with the same result. Only the workspace owner and administrators can change it. For an ordinary member, the option is read-only.
1
Open the column menu
Click the header of the column you want to mark.
2
Choose GDPR / confidential marking
A submenu lists the states available for this column type.
3
Select a state
Sensitive or Not sensitive. Three types also offer Inherited: mirror column, Link to another table, single-select fed by another table. The setting is saved immediately.
Once the column is marked Sensitive, a shield icon appears in its header. It lets you spot the sensitive columns of a view at a glance.
1.1 How do you mark several columns at once?
The Organize fields window sets the marking of the whole table in one place.
1
Open the table menu
Click the ⋮ button to the right of the tabs.
2
Choose Organize fields
The window lists the fields of the table, one row per field.
3
Set the GDPR / confidential column
It shows the state of each field. The GDPR / confidential filter, at the top of the window, shows only the marked fields.
4
Click Save
The markings apply to the whole table.
1.2 What does the GDPR / confidential column of Organize fields show?
Two displays live side by side in this column. A checkbox for fields with two states. Three icons for fields that also offer Inherited. Only the encrypted field comes already ticked: it is Sensitive as soon as it is created.
What you see
Field type
Meaning
Action
Empty checkbox
Plain column: text, number, date, single-select, formula
Not sensitive. The field goes into exports.
Tick the box to mark it Sensitive.
Ticked checkbox
Plain column or formula, ticked by hand
Sensitive. The field is excluded from exports that tick the GDPR checkbox.
Untick the box to go back to Not sensitive.
Ticked from creation
Encrypted field
Sensitive by default. The field is excluded from exports that tick the GDPR checkbox.
No action needed: the marking is automatic.
Three icons
Mirror column, Link to another table column, single-select fed by another table
The blue icon is the current state.
Click an icon to change the state.
The three icons, from left to right:
Icon
State
What it means
Chain link
Inherited
Sensitivity comes from the columns the field reads. It is the default state of a mirror column or a Link to another table column.
Shield with padlock
Sensitive
Explicit marking. The field is excluded from GDPR exports, whatever its sources read.
Crossed shield
Not sensitive
The field goes into exports, even if the column it reads is Sensitive. Choose this state when the field shows no personal data.
Example: in the Customers table, Contact, Email and Phone are ticked. In the Orders table, the Customer email mirror column shows the chain link in blue: it is Inherited.
2. What do the Sensitive, Not sensitive and Inherited states mean?
Every column has a default state, based on its type. You do not have to go through your current tables.
Plain column: Not sensitive
Text, number, date, checkbox, single-select. Two possible states: Sensitive or Not sensitive.
Formula: Not sensitive
Two possible states: Sensitive or Not sensitive. A formula never inherits from the columns it reads.
Mirror column, Link to another table column, single-select fed by another table: Inherited
It takes the sensitivity of the columns it reads. Three possible states.
Encrypted column: Sensitive
An administrator can set it to Not sensitive.
Example: the Invoice label formula joins the order number, the customer company and the contact's email. It is Not sensitive by default, as in the screenshot. Because it copies an email, set it to Sensitive.
You only change this setting for columns that hold personal data.
State
Meaning
Default for
Inherited
Sensitivity is deduced from the columns this one reads. Nothing to set: it is computed automatically.
Mirror columns, Link to another table columns, single-selects fed by another table. Never formulas.
Sensitive
Explicit decision: the column holds personal data. It is excluded from exports that tick the GDPR checkbox.
Encrypted columns. An administrator can set them to Not sensitive.
Not sensitive
The column does not hold personal data: it goes into exports. On a mirror column, this choice wins: it is exported, even if the column it reads is Sensitive.
Plain columns and formulas.
Only three types offer Inherited: mirror column, Link to another table column, single-select fed by another table. A plain column or a formula only offers Sensitive and Not sensitive. The marking follows the column when you duplicate it, or when you duplicate the table.
3. What is the logic behind GDPR / confidential marking?
Marking is a label attached to the column, like its name or its type. It hides nothing. A Sensitive column stays visible to every member who could see it. They read, filter and edit it.
Marking does one thing only: it decides what leaves TimeTonic in an export. It applies to the whole column, to every member and to every export of the table.
A label, not a mask
To hide a column from some members, use encryption or view rights, not marking.
A property of the column
That is why only the owner and administrators can change it. It is not a personal preference.
A decision made in each export
Marking prepares the list of fields to exclude. The export chooses to exclude or keep them.
4. How does a column inherit sensitivity from another one?
A column set to Inherited is sensitive as soon as at least one of the columns it reads is. TimeTonic follows the chain from one table to another. A mirror of a sensitive column is sensitive. A mirror of that mirror is too. Nobody needs to open its settings.
Mirror column
Inherits from the target column and, if it is itself a mirror, from the next one, and so on.
Link to another table column
Inherits from the column on the other side of the relation.
Single-select fed by another table
Inherits from the source column in the other table.
Formula
Does not inherit: its menu does not offer Inherited. Mark it Sensitive by hand if it copies personal data.
4.1 Use case: which columns to mark in two linked tables?
Take two linked tables: Customers and Orders. You want to export Orders without personal data. Follow these four steps to spot the columns to mark.
1
Mark personal data at its source
Open the Customers table. Spot the columns that identify a person: Contact, Email, Phone. Mark them Sensitive.
2
Let inheritance handle mirror columns
In Orders, the Customer email mirror column reads the Email column. It becomes Sensitive on its own. In Organize fields, its chain link is blue.
3
Review each formula
A formula never follows the columns it reads. Invoice label copies the customer's email: mark it Sensitive by hand. Total (excl. VAT) computes an amount: leave it Not sensitive.
4
Check in the export
The Exclude fields marked GDPR / confidential checkbox is ticked by default (chapter 5). The Fields to exclude list must show Customer email and Invoice label.
Result, with the GDPR checkbox ticked in the export:
Column
Type
Your action
In the export
Customers: Email
Plain column
Mark Sensitive
Excluded
Orders: Customer email
Mirror column
None: it inherits
Excluded, by inheritance
Orders: Invoice label
Formula that copies the email
Mark Sensitive by hand
Excluded
Orders: Total (excl. VAT)
Formula that computes an amount
None
Exported
Formulas do not inherit the marking. A formula offers two states: Sensitive and Not sensitive. It is Not sensitive by default, even if it reads a sensitive column. So it goes into the exported file. Mark as Sensitive, by hand, every formula that copies personal data. Example: a label that joins name and email. A formula that does not reproduce the data, such as initials or a TRUE / FALSE, can stay exported.
4.2 Take a column out of inheritance
Set it to Not sensitive. It no longer follows the column it reads: it goes into exports. Columns that read it in turn do not become sensitive because of it. The Sensitive choice also fixes the state: the column stays sensitive, even if its source changes.
A legitimate case: a mirror column of a column marked out of caution. Its value is not personal, such as a department code.
5. How do I exclude marked columns from my exports?
In a new export, marked columns are excluded by default. You can change this choice in each export.
1
Open an export
An existing export, or a new one, in the FTP / SFTP transfers or the Metabase export.
2
Go to the Exported fields section
It sits in the configuration window of the export.
3
Check the Exclude fields marked GDPR / confidential checkbox
It is ticked by default. The Fields to exclude list ticks the marked columns, with their reason. Untick it only to include these fields again.
Marked columns no longer go out, including those marked later. An export created before the marking is not changed: open it to tick the checkbox. Mark first the formulas that copy personal data.
6. Frequently asked questions on GDPR / confidential marking
I marked the column in my table, but it is still visible to a member. Is that normal?
Yes. GDPR / confidential marking only drives exports. It changes nothing in what members see in the application. They read, filter and edit the column as before. To hide data from some members, use an encrypted field. Marking only decides which columns go into an exported file, and nothing else.
I cannot change the marking. Why?
Only the workspace owner and administrators can change the marking. It is a property of the column, not a personal preference. For an ordinary member, the GDPR / confidential marking option is read-only. Ask an administrator to mark the column for you, or to give you that role in the workspace.
The Inherited option is not offered on my column. Why?
Your column is a plain column or a formula. Only three types offer Inherited: mirror column, Link to another table column, single-select fed by another table. A plain column or a formula only offers Sensitive and Not sensitive. Choose Sensitive if it holds or copies personal data, so that exports can exclude it.
My formula reads a sensitive column but is not excluded. Is that a bug?
No. A formula does not inherit the marking: this is a product choice. It stays Not sensitive until you mark it. Mark it Sensitive by hand if it copies personal data, such as a label that joins name and email. The GDPR checkbox of the export then excludes it like the other columns.
Go further
Choose the exported fields (FTP / SFTP)
Chapter 5.6: tick the GDPR checkbox in the export window.