X-ERP Help

GDPR

Use roles, data minimization, purpose limitation and documented processing so that personal data in X-ERP is only effective for as long and as widely as necessary.

Data protection is not reflected in a banner, but in a thousand small decisions: Who sees this partner contact? Why is this field saved? When does its purpose end?

Translate a set of rules into a safe process

The GDPR principles include, but are not limited to, legality, purpose limitation, data minimization, accuracy, storage limitation, integrity and accountability. X-ERP supports processes and rights; the company defines the purpose, legal basis and deadline.

This is how X-ERP works in the process

  1. Record processing activities, purposes, categories, recipients, legal basis and deadlines.
  2. Reduce fields and permissions to the extent necessary.
  3. Separate roles and audit sensitive exports, portals, attachments and logs.
  4. Define information, correction, restriction, deletion and objection as responsible processes.
  5. Monitor deadlines and document decisions and technical implementation.

Check before submitting or shipping

  • Every processing has a purpose and owner.
  • Roles only show necessary personal data.
  • Deletion/blocking decision takes retention into account.
  • Information and incident response are practiced.

Limits and obligation to check

  • “We might need this” doesn’t replace a purpose.
  • Production copies remain indefinitely as test systems.
  • Logs contain full payloads or session data.

This is what you take with you

In X-ERP, data protection becomes a lived process quality that creates trust and enables evidence.

Further information / source

Related topics

  1. For country specialists – National requirements and special features › GoBD
  2. For country specialists – National requirements and special features › INTRASTAT declaration

Frequently asked questions

**What is data minimization?**

Only process personal data that is appropriate and necessary for the specified purpose.

**Can I just delete?**

Not across the board. Check data subject rights, legal basis, storage and technical dependencies; if necessary, block or anonymize.