Library · Travel & housing – master data in detail

DAT-130 · Carry out offboarding and personal data deletion plan

Ends processing for an individual person as soon as their purpose no longer applies, cleanly separating documents subject to tax retention…

Travel & housing · master data

Overview

Who it's for

Coordination, assistance, office

Trigger

Person status changes to “left” (contract end, reassignment, termination) or a deletion deadline stored in the deadline calendar has been reached.

You get

Ends processing for an individual person as soon as their purpose no longer applies, cleanly separating documents subject to tax retention requirements from data that must be deleted.

Status: Concept – not built yet

Ends processing for an individual person as soon as their purpose no longer applies, cleanly separating documents subject to tax retention requirements from data that must be deleted.

Trigger: Person status changes to “left” (contract end, reassignment, termination) or a deletion deadline stored in the deadline calendar has been reached.

1Check open cases:billing, claims,damage case,complianceTHK2Separate dataclasses intoretention-requiredandPBH3Revoke systemaccess andpermissionsITA4Delete datasubject todeletionrequirements,5Request deletionfrom externalrecipients anddocument theTHK6Generate deletionlog and have itcountersigned by`DSB`THK / DSB7Reset remainingdeadlines forretention-requiredrecords and hand

Rule (automatable) Judgment (human decides)

Decision rules

  • R1 IF an open billing, claim, or damage case exists THEN no deletion, but blocking of the record from operational access while it is retained for the open purpose.
  • R2 IF a date is part of a booking receipt or billing document THEN the tax retention requirement applies and no deletion is allowed; deadline and start of deadline ⚠️[VERIFY — source: § 147 para. 3 and 4 AO, check reduction through the Fourth Bureaucracy Relief Act at time of application].
  • R3 IF it is D4 THEN deletion after {{PASSDATEN_LÖSCHFRIST_TAGE}} regardless of project status, because there is no reason for retention.
  • R4 IF it is D5 or D6 THEN deletion after {{LÖSCHFRIST_NICHT_STEUERRELEVANT_TAGE}} or immediately upon revocation per DAT-080 rule R4.
  • R5 IF data was transmitted to HOT, RDL, TXI, or MWV THEN send a deletion request per Art. 28 para. 3 lit. g GDPR and archive the response; if no response is received, send a reminder after 30 days and hand the case over to DSB.
  • R6 IF the person is employed again in a follow-up production THEN no reuse of the old data, but new collection per DAT-020, because the purpose limitation is project-specific; excepted are framework data for which a separate basis exists (coordination with CLS-060).

Common pitfalls

1. Deletion is implemented as “set record to inactive” → data remains fully present and is still accessible via reports. 2. The entire person profile is deleted because the project ends, even though travel expense receipts are attached to it → proof is missing in the tax audit. 3. Hotel and travel service providers keep rooming lists and name lists, no one requests deletion → data remains permanently with third parties. 4. Deletion deadline is calculated from project end instead of the legally relevant start of the deadline → either deleted too early or years too late.

Impact M × effort M → Later; however, deadline monitoring alone is Do-first and should be prioritized with the deadline calendar. · HITL · RACI **R** THK · **A** PL · **C** DSB, PBH, STB for retention questions · **I** ITA, HL · Manual effort: Estimate: 10–20 min. per person as a rule; 60–120 min. per case with external recipients and open items

Request this workflow

Request this workflow See all workflows