Workspace GDPR
IdeaScale GDPR compliance
Path: Workspace Homepage >> Navigation Panel >> Settings >> Security >> GDPR
| What is Workspace GDPR? |
|---|
| Workspace GDPR is the set of tools, policies, and administrative options IdeaScale provides to help customers understand and comply with the General Data Protection Regulation (GDPR) when handling the personal data of European Union individuals. |
The General Data Protection Regulation (GDPR) is a legal framework that sets guidelines for the collection and processing of personal data belonging to individuals within the European Union (EU). It strengthens and standardizes user data privacy across EU nations and places obligations on any organization that handles EU citizens' personal data, regardless of where that organization is located. IdeaScale supports GDPR compliance through its security infrastructure, international data transfer safeguards, GDPR Data Processing Addendums, data management tools, and ongoing privacy monitoring.
Role Permissions
- Workspace Administrator: Reviews and accepts the GDPR Data Processing Addendum (DPA), and deletes or restricts a member's personal data using the Forget, Ban, and Hide tools available through Workspace Member Management.
TABLE OF CONTENTS
SecurityPrivacy Shield
GDPR Data Processing Addendums
Data Deletion, Portability, and Management
Privacy Monitoring and Review
Exceptions
Frequently Asked Questions
Security
Protecting customer information and user privacy is a priority for IdeaScale. IdeaScale uses data centers that undergo annual SOC and/or ISO 27001 third-party audits, and applies the NIST 800-53 security matrix to guide its policies, procedures, and controls. These procedures include an incident notification plan that allows IdeaScale to meet GDPR notification timelines.
Privacy Shield
To comply with EU data protection laws governing international data transfer mechanisms, IdeaScale self-certifies under the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield frameworks. These frameworks establish a way for companies to meet data protection requirements when transferring personal data from the European Union and Switzerland to the United States.
GDPR Data Processing Addendums
IdeaScale offers customers a GDPR Data Processing Addendum (DPA) to meet the privacy and security requirements of organizations operating in the EU. The Workspace Administrator can review and accept the DPA by navigating to Settings >> Security >> GDPR. Within this panel, the DPA can be reviewed and accepted, and additional contact details can be provided if desired.
Data Deletion, Portability, and Management
IdeaScale provides tools that allow customers to meet their users' rights under the GDPR, covering deletion, portability, and management of personal data.
Deletion
Using the Forget, Ban, and Hide tools, IdeaScale allows customers to respond to a user's request to delete or change personal information, such as a name or email address, or to restrict data processing. These tools support the "right to be forgotten" and other obligations under the GDPR.
To delete a member's personal data:
- Navigate to Workspace Member Management >> Members.
- Select the checkbox appearing before the email address of the member who submitted the request to be forgotten.
- Under the Action tab, select Delete Member.
- In the pop-up window, select one of the following:
- Delete Member: Deletes the selected member's personal data but retains their ideas and comments.
- Delete Member(s) and their Contributions: Deletes the selected member's personal data, ideas, and comments.
Note: Both deletion options are irreversible. See Exceptions below for related data retention timelines.
Portability
The Community Administrator can honor a member's request to export their personal data using IdeaScale's export tools by navigating to Community Settings >> Data >> Export Data >> Member Data. Data can be exported in Excel or CSV format.
Help Article for Export Member Data (https://help.ideascale.com/community-export-member-data)
Management
Administrators can review the types of personal data being collected through the administrative settings panel. (TO BE VERIFIED — whether this review capability is scoped to the Workspace Administrator, the Community Administrator, or both.)
Note: IdeaScale's support staff can be contacted for further assistance with any of the data deletion, portability, or management tools described above.
Privacy Monitoring and Review
IdeaScale's security team continuously monitors the IdeaScale system for vulnerabilities and issues that could compromise personal data. The team also reviews notices and alerts from regulatory bodies and makes adjustments when required. IdeaScale additionally engages third-party privacy professionals to review its policies and procedures, using their input to improve and update its privacy practices and help IdeaScale customers maintain GDPR compliance.
Exceptions
- Contract Termination: Upon conclusion of a contract, the customer has 30 days to export data from the application before removal begins. After 90 days from contract conclusion, all backups of the data are also removed.
Frequently Asked Questions
What is the GDPR Data Processing Addendum (DPA)?
The DPA is a document IdeaScale offers to customers to meet the privacy and security requirements of organizations operating in the EU. It can be reviewed and accepted by the Workspace Administrator from Settings >> Security >> GDPR.
Which tools can be used to delete a member's personal data?
The Forget, Ban, and Hide tools allow a member's personal data to be deleted or changed, or their data processing to be restricted, in response to a "right to be forgotten" request.
Is deleting a member's personal data reversible?
No. Both the Delete Member and Delete Member(s) and their Contributions options are irreversible once confirmed.
How is a member's data exported to fulfill a portability request?
Personal data can be exported in Excel or CSV format by navigating to Community Settings >> Data >> Export Data >> Member Data.
What happens to data after a contract with IdeaScale ends?
The customer has 30 days after contract conclusion to export its data before removal begins. All backups of the data are removed after 90 days.
Related Articles
- Help Article for Export Member Data
- Help Article for Workspace Security
- Help Article for Access Control
- Help Article for Workspace Member Management
Last Updated: August 17, 2026
