MagikINFO is compliant with the GDPR
The General Data Protection Regulation, known as the GDPR, has been in force across the European Union since 25 May 2018. It's an EU-wide regulation that harmonises the protection of personal data across all member states.
The regulation is aimed above all at companies that handle the personal data of their employees, partners or customers. In practice, that means putting in place processes for handling personal data in line with the regulation, reviewing information systems for compliance, and introducing measures to control and secure that data.
So where does MagikINFO stand when it comes to the GDPR? From our perspective, the topic splits into two parts:
- Bringing MagikINFO itself into compliance with the regulation
- MagikINFO as a tool that helps you address specific areas of GDPR compliance
Bringing MagikINFO into compliance with the regulation
The GDPR places requirements on how information systems handle personal data correctly. We can talk about this mainly in terms of three areas.
Secure access to personal data
Access to personal data in MagikINFO can be restricted to selected users, secured behind a login, and managed so that each employee has authorised access only to the personal data they actually need for their job — whether that's the asset team needing records including handover reports, or the helpdesk team accessing the data of a user requesting a service or reporting an incident.
All data is held in an MS SQL database, secured with username-and-password or Windows authentication. Audit and monitoring output files imported into the database are encrypted with a secure, unique key.

Monitoring access to personal data
Every login to MagikINFO is logged, so it's always possible to check which user accessed the system and when. That logging can also be applied directly to the records that contain personal data — in particular the user records, where logging can be enabled for any edit, deletion or creation of a record.
Anonymising personal data (the right to erasure)
The data subject — in this case, an employee — can exercise what's known as the right to erasure. In an employment context, this typically applies once the purpose of processing has lapsed (the employment relationship has ended), in cases of unlawful processing, or where the subject raises a legitimate objection to processing.
In those cases, an employer should delete or anonymise the personal data so that it can no longer be linked to a specific person. MagikINFO supports deleting records, as well as bulk anonymisation of data for users who have already been removed from the records.
MagikINFO as a tool for specific GDPR areas
Proactive security
The MagikMONITOR module includes mechanisms for blocking unwanted user activity. You can set the security level for USB flash drive connections — allowed, blocked, or authorised drives only from an approved list. Where flash drives are allowed, you can also track which files get copied onto them.
Access to selected websites, mail servers and other services can also be blocked (blocking all protocols for a given domain). Running selected programs can be blocked too.
Print monitoring lets you check whether documents containing personal data are being printed in ways that go against your processes for handling that data.

Standardisation and security
Auditing stations and servers gives an administrator information that matters a great deal from a data security standpoint. Your environment's security depends, among other things, on installed operating system updates, current versions of installed applications, security software (antivirus, firewall), and confirming that no unauthorised (potentially dangerous) applications are installed. The MagikAUDIT module also includes remote distribution, which lets you install, update or uninstall unwanted applications in bulk.
Visibility into documents on computers
When it comes to data containing personal information, the main problem is usually unstructured data — the various documents scattered across computers throughout an organisation. MagikINFO can offer not just an overview of all the documents found on computers, but visibility into individual access to those documents too. That helps you check and put measures in place to keep the volume of unstructured data under control.

Visibility into information system usage
Access to information systems is one of the core parts of protecting personal data. The MagikMONITOR module helps you quickly and easily find out who worked with which information systems containing personal data, and when — so you can check whether your access processes for those applications are actually being followed.