SAP Knowledge Base Article - Public

3714953 - Is it possible to restrict access to purge preview report based on legal entity in SuccessFactors?

Symptom

  • A user who has Additional Access Control based on a DRTM-enabled Country/Region is able to download purge preview reports for all users belonging to that country/region, including users outside the user’s Department or Legal Entity target population.
  • Users can download DRTM purge preview reports that include users outside their assigned target population. 
  • DRTM purge preview reports display users from multiple Legal Entities even though the user has restricted target population access.
  • Access to DRTM purge preview reports is broader than expected and not limited by Department or Legal Entity.
  • Issue with restricting access to purge preview report based on Legal Entity (LE).

Environment

SAP SuccessFactors HCM Suite

Cause

This behavior is working as designed.
Access to DRTM purge preview reports is controlled only at the DRTM-enabled country/region level. Legal Entity– or Department-based restrictions and target population filtering are not supported for downloading or viewing already generated purge preview reports.

Resolution

At this time, it is not possible to restrict purge preview report visibility or content by Legal Entity or target population. Access control is enforced only at the country level for DRTM purge reports.

Permission Behavior Clarification

1. Additional Access Control Based on DRTM-enabled Country/Region Permission

  • Purpose: Controls whether a user can download a purge preview report based on country only.

  • Target Population: Not applicable

  • Behavior:

    • If at least one to-be-purged user in the preview report belongs to the same DRTM-enabled country/region:

      • A user without this permission will see the Download Preview Report link greyed out.

      • A user with this permission can download the entire report.

  • Limitation:

    • This permission does not filter report content by Department or Legal Entity.

    • If the report contains users from multiple Legal Entities within the same DRTM-enabled country/region, the full report is downloadable.

2. Manage and Approve DRTM Purge Requests Permission 

  • Purpose: Controls whether the Approve and Decline buttons are clickable.

  • Target Population:  Not applicable

  • Behavior:

    • Does not restrict visibility of purge report data.

    • Does not validate target population for the to-be-purged users.

3. Manage User Permission (with Target Population)

  • Purpose: Controls which users can be selected and included when a purge request is launched.

  • Target Population: Applicable

  • Behavior:

    • Applies only to the purge request launcher.

    • Filters which users are included in the purge request at creation/scheduling time.

    • Does not restrict access to a purge preview report.

  • Important Note:

See Also

Enhancements to Data Retention Management | SAP Help Portal

Keywords

restricting access, purge preview report, legal entity, target population, GDPR implications, approver permissions, data retention management, country-level restriction, SAP SuccessFactors, DRTM permissions, permission groups, access control, Additional Access Control Based on DRTM-enabled Country/Region, Manage and Approve DRTM Purge Requests, Manage User , KBA , LOD-SF-PLT-DRM , Data Retention Management , How To

Product

SAP SuccessFactors HCM Suite all versions