PII is tagged at the schema, masked by default, and de-pseudonymized only with dual approval.
TENSOR treats personal data as a first-class concern — not an afterthought. Field-level classification, a masking layer, k-anonymity, and Works Council integration for organizations under BetrVG.
Capabilities
PII is classified at the schema layer — every field that holds personal data is tagged with its PII class. This drives masking, retention, and export behavior automatically.
A masking layer sits between the data store and the UI. Pseudonymized fields show masked values by default; original data is accessible only through a controlled de-pseudonymization flow.
Aggregated results suppress any bucket below a k-anonymity threshold — 5 by default, configurable from 3 to 50 — to prevent re-identification through small-group inference. A free-text scrubber replaces directory names with pseudonyms in comment and email text.
Accessing unmasked PII requires dual approval — two authorized individuals must confirm. The request, approval, and access are logged on a separate PII-access audit channel. Each request carries a written reason and scope, and the grant is time-bounded — 24 hours by default, seven days at most — reverting automatically when it expires.
Where a Works Council (Betriebsrat) exists, every de-pseudonymization grant is disclosed to a designated council member in an audit view after a seven-day delay, and the council's own landing page shows aggregates only — never individual records — meeting BetrVG co-determination requirements.
Data subjects can receive a structured, machine-readable export of their personal data. Export covers all PII-tagged fields across the tenant.
GDPR FAQ
Informational only — not legal advice. Consult qualified counsel for regulatory obligations specific to your organization.
See pseudonymization and the Works Council workflow in action.
30 minutes. We'll demonstrate PII masking, dual-approval, and the BetrVG flow.