Skip to content

Data protection overview & DPA

The Data protection module controls which version of project and session data may be used. It combines a binding tenant policy, the protection level of each project or session, and an auditable workflow for changes and recovery.

When the module is disabled for a tenant, the shield menu and privacy administration are hidden. Disabling it never turns protected data back into original data.

The platform operator enables the module per tenant. If Data protection is not visible for your organization, contact your StoryVault representative.

In StoryVault, DPA is the tenant-specific Data protection capability (data_protection_admin). It allows an assigned person to plan, approve, monitor, and — where still possible — reverse privacy operations.

The capability applies only to the selected tenant membership. Administrators do not receive it automatically. A platform super admin can inspect safe error and recovery metadata, but cannot re-identify content or restore originals without a DPA assignment in that tenant.

  1. Open Admin → Users and select the person.
  2. Confirm that the person has an active membership in the correct tenant.
  3. Enable Data protection on that tenant membership and save.
  4. Switch to that tenant before opening the shield menu or privacy administration.

If no active DPA is assigned, manual privacy operations remain disabled and administrators receive a link to the user administration. Automatic operations that only increase protection may continue.

The Data protection administration page contains the active tenant policy, operation status, legal holds, recovery material, and the tenant-scoped access log.

SettingEffect
Policy templateSupplies a comprehensible starting configuration.
Tenant data access limitMost exposed variant the tenant may use, such as original or permanently anonymized.
Original media handlingStore originals, quarantine them, or delete them after a retention period.
Retention daysTime during which protected originals remain recoverable. Empty means no fixed deadline.
Automatically apply to importsNew uploads, imports, and bot sessions are moved to the tenant’s required level.
Export / share original mediaAvailable only while the tenant policy permits original data.

Available templates are Standard, Strict privacy, Remove identifying data by default, and Permanently anonymized workspace. Always review the individual settings before activating a new policy version.

A legal hold prevents changes and automatic deletion for a selected project or session. It does not expose original data or grant additional access. While a hold is active, anonymization and destruction of pseudonym mappings are blocked.