GDPR / confidential marking flags the fields that hold personal data, so you can exclude them from your exports. It hides nothing in the application. This article covers the GDPR / confidential marking option, its states and the logic behind them.
1. Where is the GDPR / confidential marking option?
The option sits in the menu of each field. It also exists in the field configuration window, with the same result. Only the workspace owner and administrators can change it. For an ordinary member, the option is read-only.
1
Open the field menu
Click the header of the field you want to mark.
2
Choose GDPR / confidential marking
A submenu lists the states available for this field type.
3
Select a state
Sensitive or Not sensitive. Four types also offer Inherited: linked table column, Link to another table column and two selects. These selects, single or conditional, are fed by another table. The setting is saved immediately.
Once the field is marked Sensitive, a shield icon appears in its header. It lets you spot the sensitive fields of a view at a glance.
1.1 How do you mark several fields at once?
The Organize fields window sets the marking of the whole table in one place.
1
Open the table menu
Click the ⋮ button to the right of the tabs.
2
Choose Organize fields
The window lists the fields of the table, one row per field.
3
Set the GDPR / confidential column
It shows the state of each field. The GDPR / confidential filter, at the top of the window, shows only the marked fields.
4
Click Save
The markings apply to the whole table.
1.2 What does the GDPR / confidential column of Organize fields show?
Two displays live side by side in this column. A checkbox for fields with two states. Three icons for fields that also offer Inherited. Only the encrypted field comes already ticked: it is Sensitive as soon as it is created.
What you see
Field type
Meaning
Action
Empty checkbox
Plain field: text, number, date, single-select, formula
Not sensitive. The field goes into exports.
Tick the box to mark it Sensitive.
Ticked checkbox
Plain field or formula, ticked by hand
Sensitive. The field is excluded from exports that tick the GDPR checkbox.
Untick the box to go back to Not sensitive.
Ticked from creation
Encrypted field
Sensitive by default. The field is excluded from exports that tick the GDPR checkbox.
No action needed: the marking is automatic.
Three icons
Linked table column, Link to another table column, single or conditional select fed by another table
The blue icon is the current state.
Click an icon to change the state.
The three icons, from left to right:
Icon
State
What it means
Chain link
Inherited
Sensitivity comes from the fields this field reads. It is the default state of a linked table column or a Link to another table column.
Shield with padlock
Sensitive
Explicit marking. The field is excluded from GDPR exports, whatever its sources read.
Crossed shield
Not sensitive
The field goes into exports, even if the field it reads is Sensitive. Choose this state when the field shows no personal data.
Example: in the Customers table, Contact, Email and Phone are ticked. In the Orders table, the Customer email linked table column shows the chain link in blue: it is Inherited.
2. What do the Sensitive, Not sensitive and Inherited states mean?
Every field has a default state, based on its type. You do not have to go through your current tables.
Plain field: Not sensitive
Text, number, date, checkbox, single-select. Two possible states: Sensitive or Not sensitive.
Formula: Not sensitive
Two possible states: Sensitive or Not sensitive. A formula never inherits from the fields it reads.
Linked table column, Link to another table column, single or conditional select fed by another table: Inherited
It takes the sensitivity of the fields it reads. Three possible states.
Encrypted field: Sensitive
An administrator can set it to Not sensitive.
Example: the Invoice label formula joins the order number, the customer company and the contact's email. It is Not sensitive by default, as in the screenshot. Because it copies an email, set it to Sensitive.
You only change this setting for fields that hold personal data.
State
Meaning
Default for
Inherited
Sensitivity is deduced from the fields this one reads. Nothing to set: it is computed automatically.
Linked table columns, Link to another table columns, single or conditional selects fed by another table. Never formulas.
Sensitive
Explicit decision: the field holds personal data. It is excluded from exports that tick the GDPR checkbox.
Encrypted fields. An administrator can set them to Not sensitive.
Not sensitive
The field does not hold personal data: it goes into exports. On a linked table column, this choice wins: it is exported, even if the field it reads is Sensitive.
Plain fields and formulas.
Only four types offer Inherited: linked table column, Link to another table column and two selects. These selects, single or conditional, are fed by another table. A plain field or a formula only offers Sensitive and Not sensitive. The marking follows the field when you duplicate it, or when you duplicate the table.
3. What is the logic behind GDPR / confidential marking?
Marking is a label attached to the field, like its name or its type. It hides nothing. A Sensitive field stays visible to every member who could see it. They read, filter and edit it.
Marking does one thing only: it decides what leaves TimeTonic in an export. It applies to the whole field, to every member and to every export of the table.
A label, not a mask
To hide a field from some members, use encryption or view rights, not marking.
A property of the field
That is why only the owner and administrators can change it. It is not a personal preference.
A decision made in each export
Marking prepares the list of fields to exclude. The export chooses to exclude or keep them.
It is up to you to judge which fields are personal. TimeTonic does not detect personal data: marking is a manual decision. Email, Phone and URL are excluded by default for their format, not for the GDPR. Mark Sensitive any field that holds personal data, whatever its type. A name typed into a text field is only excluded if it is marked.
4. How does a field inherit sensitivity from another one?
A field set to Inherited is sensitive as soon as at least one of the fields it reads is. TimeTonic follows the chain from one table to another. A linked table column that reads a sensitive field is sensitive. A linked table column that reads that column is too. Nobody needs to open its settings.
Linked table column
Inherits from the target field and, if that field is itself a linked table column, from the next one, and so on.
Link to another table column
Inherits from the field on the other side of the relation.
Single-select fed by another table
Inherits from the source field in the other table.
Conditional select fed by another table
Inherits from the source field in the other table.
Formula
Does not inherit: its menu does not offer Inherited. Mark it Sensitive by hand if it copies personal data.
4.1 Use case: which fields to mark in two linked tables?
Take two linked tables: Customers and Orders. You want to export Orders without personal data. Follow these four steps to spot the fields to mark.
1
Mark personal data at its source
Open the Customers table. Spot the fields that identify a person: Contact, Email, Phone. Mark them Sensitive.
2
Let inheritance handle linked table columns
In Orders, the Customer email linked table column reads the Email field. It becomes Sensitive on its own. In Organize fields, its chain link is blue.
3
Review each formula
A formula never follows the fields it reads. Invoice label copies the customer's email: mark it Sensitive by hand. Total (excl. VAT) computes an amount: leave it Not sensitive.
4
Check in the export
The Exclude fields marked GDPR / confidential checkbox is ticked by default (chapter 5). The Fields to exclude list must show Customer email and Invoice label.
Result, with the GDPR checkbox ticked in the export:
Field
Type
Your action
In the export
Customers: Email
Plain field
Mark Sensitive
Excluded
Orders: Customer email
Linked table column
None: it inherits
Excluded, by inheritance
Orders: Invoice label
Formula that copies the email
Mark Sensitive by hand
Excluded
Orders: Total (excl. VAT)
Formula that computes an amount
None
Exported
Formulas do not inherit the marking. A formula offers two states: Sensitive and Not sensitive. It is Not sensitive by default, even if it reads a sensitive field. So it goes into the exported file. Mark as Sensitive, by hand, every formula that copies personal data. Example: a label that joins name and email. A formula that does not reproduce the data, such as initials or a TRUE / FALSE, can stay exported.
4.2 Take a field out of inheritance
Set it to Not sensitive. It no longer follows the field it reads: it goes into exports. Fields that read it in turn do not become sensitive because of it. The Sensitive choice also fixes the state: the field stays sensitive, even if its source changes.
A legitimate case: a linked table column that reads a field marked out of caution. Its value is not personal, such as a department code.
5. How do I exclude marked fields from my exports?
In a new export, marked fields are excluded by default. You can change this choice in each export.
1
Open an export
An existing export, or a new one, in the FTP / SFTP transfers or the Metabase export.
2
Go to the Exported fields section
It sits in the configuration window of the export.
3
Check the Exclude fields marked GDPR / confidential checkbox
It is ticked by default. The Fields to exclude list ticks the marked fields, with their reason. Untick it only to include these fields again.
Marked fields no longer go out, including those marked later. An export created before the marking is not changed: open it to tick the checkbox. Mark first the formulas that copy personal data.
6. Frequently asked questions on GDPR / confidential marking
Should I mark an Email field that is already excluded by default?
Yes, if it holds personal data. Email, Phone and URL are excluded for their format, not under the GDPR. This exclusion disappears if the field types checkbox or the field is unticked, with no warning. Marked Sensitive, the field is excluded under the GDPR, and the GDPR fields warning appears if it goes back into the export.
I marked the field in my table, but it is still visible to a member. Is that normal?
Yes. GDPR / confidential marking only drives exports. It changes nothing in what members see in the application. They read, filter and edit the field as before. To hide data from some members, use an encrypted field. Marking only decides which fields go into an exported file, and nothing else.
I cannot change the marking. Why?
Only the workspace owner and administrators can change the marking. It is a property of the field, not a personal preference. For an ordinary member, the GDPR / confidential marking option is read-only. Ask an administrator to mark the field for you, or to give you that role in the workspace.
The Inherited option is not offered on my field. Why?
Your field is a plain field or a formula. Only four types offer Inherited: linked table column, Link to another table column and two selects. These selects, single or conditional, are fed by another table. A plain field or a formula only offers Sensitive and Not sensitive. Choose Sensitive if it holds or copies personal data, so that exports can exclude it.
My formula reads a sensitive field but is not excluded. Is that a bug?
No. A formula does not inherit the marking: this is a product choice. It stays Not sensitive until you mark it. Mark it Sensitive by hand if it copies personal data, such as a label that joins name and email. The GDPR checkbox of the export then excludes it like the other fields.
Go further
Choose the exported fields (FTP / SFTP)
Chapter 5.6: tick the GDPR checkbox in the export window.