SAP Knowledge Base Article - Public

2978918 - Configurable Sensitive Personal Data Fields for Read Audit [2H 2020]

Symptom

  • The Read Audit feature will be enhanced in b2011 release so that you can configure fields in different modules as sensitive for read access logging.
  • You now also have an overview of all allowable sensitive personal data fields and the current quota usage.

Environment

SAP SuccessFactors HXM Suite

Resolution

Pre-Requisites:

Ensure that Read Access Logging is enabled. To enable Read Access Logging

  1. Go to Admin Center
  2. Select Manage Audit Configuration 
  3. Go to Read Audit
  4. Select the Read Access Logging option.

Steps:

Scenario 1:

  1. Access a candidate or applicant's data as an internal user (Recruiting operator).
  2. As an HR Admin or DPO, run a Read Audit report using the Person Search option. Select Activity as Read By User or Data Operator and specify the operator who read a candidate or applicant's data.
  3. Fields from candidate profile and job application templates marked as sensitive="true" are read logged with all other parameters available in the report. Examples of the parameters include, Read By User (ID) and Subject User (ID).

Scenario 2:

  1. As an internal candidate, log on to the internal career site and select View My Candidate Profile.
  2.  As an HR Admin or DPO, run a Read Audit report using the Person Search option. Select Activity as Read By User or Data Operator and specify the internal candidate who read his/her own data.
  3. Fields from candidate profile and job application templates marked as sensitive="true" are read logged with all other parameters available in the report. Examples of the parameters include, Read By User (ID) and Subject User (ID).

Scenario 3:

  1. As an external candidate, log on to the external career site and select View My Candidate Profile.
  2. As an HR Admin or DPO, run a Read Audit report using the External Candidate Search option.
  3. Fields from candidate profile and job application templates marked as sensitive="true" are read logged with all other parameters available in the report. Examples of the parameters include, Read By User (ID) and Subject User (ID).

Note: Sensitive personal data is a small subset of all the personal data stored in the system. Not all personal data, nor all personally identifiable information, is necessarily sensitive. Read auditing is only available for small number of fields that we've identified as sensitive.

For further information please check out the Whats New Viewer [2H 2020] which also contains a link to the demo video

The Help Portal Guide for Change Audit can be found here Help Guide - Configuring Read Audit

See Also

Whats New Viewer [2H 2020]

Help Guide - Configuring Read Audit

2618848 - Enabling Change Audit Feature

2789153 - How to schedule Change Audit Report and access it

2744431 - How to Create Change Audit Reports and What Reports are Available - SuccessFactors

Keywords

PLA-12582 ,  Read-Access Logging, RAL, Change Audit, Reports,  , KBA , LOD-SF-PLT-RAL , Read Access Logs , How To

Product

SAP SuccessFactors HCM suite all versions