Skip to content

Project and task data is kept forever, with no retention period #667

Description

@rubenvdlinde

Planninq sets no retention period on any of its schemas. Projects, tasks and time entries keep the names of the people on them for as long as the instance lives.

This is a code reading of planninq development at f936e09 and openregister development at d611a36, from the planninq timetabling competitor scan (#665, matrix row plt-retention-anonymise).

The competitors

The planninq matrix rates Zermelo unknown, Untis partial, Xedule yes and TimeEdit partial:

What planninq has

  • lib/Settings/planninq_register.json declares seven schemas. None carries an archival or retention block: a search for archival and retention in the file finds nothing.
  • The schemas hold personal data: task.assignedTo, task.reporter, task.watchers, project.owner, project.members, plannedTimeEntry.user.

What the platform offers

  • openregister deletes rows past their retention for a schema that declares x-openregister-archival, in an hourly sweep (lib/BackgroundJob/ArchivalRetentionTask.php, class docblock).
  • openregister can pseudonymise one data subject's fields on request (openspec/specs/gdpr-data-subject-rights/spec.md:82, :102-103).
  • Neither anonymises data automatically after a period.

How I searched

A search of planninq src/, lib/ and appinfo/ for anonymi|retention|bewaartermijn|archival, a read of the register, and a read of openregister's retention job and data subject spec.

Live check

Confirm the live task schema has no archival block, and that no job removes or anonymises a task closed years ago.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

triageAwaiting triage

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions