Datenmaske
ART. 15 DSGVO · ACCESS REQUEST

The painful step
in the access workflow.

DSAR software manages the request and finds the data. Redacting third-party data from the document file — the step that eats hours of legal review — mostly remains manual and error-prone. That is exactly where Datenmaske comes in.

The workflow is available in the dashboard (sign-in required). Status v1 — cross-document balancing UI and ZIP export to follow.

THE GAP

Workflow tools do not redact document contents.

Established DSR suites (OneTrust, Securiti, DataGrail) manage the request, search databases, automate the response — but at the document content (personnel file as PDF, email attachments, scanned files) their capabilities end. OneTrust, for example, limits redaction to unstructured text and HTML according to its own FAQ.

DACH GDPR tools (Robin Data, Cortina, FTAPI) cover workflow, ROPA and data transfer — but not genuine content-stream redaction. Datenmaske closes exactly this gap: the MuPDF module in the DSAR workflow.

WORKFLOW

Where Datenmaske sits

01

Receive access request

Former employees, customers, creditors request Art. 15 access. Deadline: one month (Art. 12 Abs. 3 DSGVO).

02

Assemble documents

Emails, personnel file, tickets, contracts — everything concerning the person. The file must be redacted before it goes out.

03

Redact third-party data

The painful step: names of other employees, customers, witnesses, whistleblowers must be removed — balancing test under Art. 15 Abs. 4 i. V. m. ErwG 63.

04

Release + log

Transmit the redacted PDF and document in the redaction log what was removed — Art. 5 Abs. 2 Accountability.

Datenmaske engages at step 3 — the balancing test under Art. 15 Abs. 4 i. V. m. Erwägungsgrund 63 remains a legal, human judgement; but the detection, preview and irreversible removal of the marked passages is carried out machine-traceably.

HONESTY

What Datenmaske replaces — and what it does not.

  • Replaces: manual redaction in Adobe, Excel-table fiddling, black-box overlays with recoverable text.
  • Does not replace: a DSR workflow suite. Request intake, identity verification, datastore discovery stay with OneTrust, Robin Data & Co.
  • Does not replace: the legal case-by-case decision of whether a specific third-party data point must be redacted. Datenmaske makes suggestions; approval lies with the user.
DATENMASKE

Access requests in hours, not weeks.