Skip to main content
GDPR & BetrVG — Data protection and co-determination

PII is tagged at the schema, masked by default, and de-pseudonymized only with dual approval.

TENSOR treats personal data as a first-class concern — not an afterthought. Field-level classification, a masking layer, k-anonymity, and Works Council integration for organizations under BetrVG.

What the regulation requires → what TENSOR produces

Capabilities

GDPR
Art. 5(1)(c)Field-level PII tagging

PII is classified at the schema layer — every field that holds personal data is tagged with its PII class. This drives masking, retention, and export behavior automatically.

GDPR
Art. 4(5)Pseudonymization with masking layer

A masking layer sits between the data store and the UI. Pseudonymized fields show masked values by default; original data is accessible only through a controlled de-pseudonymization flow.

GDPR
Art. 25k-Anonymity enforcement

Aggregated results suppress any bucket below a k-anonymity threshold — 5 by default, configurable from 3 to 50 — to prevent re-identification through small-group inference. A free-text scrubber replaces directory names with pseudonyms in comment and email text.

GDPR
Art. 5(1)(f)Dual-approval de-pseudonymization

Accessing unmasked PII requires dual approval — two authorized individuals must confirm. The request, approval, and access are logged on a separate PII-access audit channel. Each request carries a written reason and scope, and the grant is time-bounded — 24 hours by default, seven days at most — reverting automatically when it expires.

BetrVG
§ 87(1)(6)BetrVG Works Council workflow

Where a Works Council (Betriebsrat) exists, every de-pseudonymization grant is disclosed to a designated council member in an audit view after a seven-day delay, and the council's own landing page shows aggregates only — never individual records — meeting BetrVG co-determination requirements.

GDPR
Art. 20GDPR Art. 20 data export

Data subjects can receive a structured, machine-readable export of their personal data. Export covers all PII-tagged fields across the tenant.

Common questions

GDPR FAQ

Fields are tagged by PII class: direct identifiers (name, email), indirect identifiers (employee ID, IP address), sensitive data (health, biometric), and non-PII. Classification drives masking depth and retention rules.
When BetrVG mode is on, a de-pseudonymization still requires two compliance approvers; each granted access is then disclosed to a designated Works Council member in an audit view after a seven-day delay. The council's view is aggregate-only — oversight and request context, never a live window into the data.
Yes. The dual-approval de-pseudonymization works independently of BetrVG. The Works Council step is an additional layer enabled per tenant when co-determination applies.
The platform manages PII handling and access controls. Consent management (collecting and tracking data-subject consent) is outside the current scope — integrate with your consent management platform via the webhook adapter.

Informational only — not legal advice. Consult qualified counsel for regulatory obligations specific to your organization.

See pseudonymization and the Works Council workflow in action.

30 minutes. We'll demonstrate PII masking, dual-approval, and the BetrVG flow.