Privacy Masking
Use Privacy Masking to help protect user privacy by masking user information. You can select which fields to mask. Masked fields show anonymous data. You can unmask and see the original data by entering the Data Mask Key that you specify in the administrator profile.
When Privacy Masking is enabled in an administrator profile, the configured fields will be masked for those administrators. These administrators will have a See Original Data button in the banner, which they can use to unmask data when appropriate if they have the configured data mask key.
Privacy Masking and GDPR
Privacy masking can be used to support compliance to the General Data Protection Regulation (GDPR). An Admin Profile can be created that masks all fields that may contain personal data relevant to the definitions of GDPR. The administrators assigned this profile can view the fields to perform their work in FortiAnalyzer, but the data will be anonymized. The anonymized data is different for each administrator and the anonymization is changed at each login to prevent opportunity for identification. When the anonymized data is required for processing, the administrator can use a data mask key to unmask the data. Only the selected data is unmasked, leaving all other masked data anonymized.
To turn privacy masking on:
- In System Settings > Admin Profiles, create or edit a profile.
- In the Privacy Masking section, set the toggle to ON
- In the Masked Data Fields section, select the fields you want to mask.
The fields you select are masked in all modules that display those fields.
- In the Data Mask Key field, type the key that will allow users to unmask the data.
- In the Data Unmasked Time field, type the number of days the data is unmasked.
You can enter a number between 0-365. Logs that are older than the number of days appear masked.
To see the original, unmasked data:
-
In any list showing masked data, click See Original Data in the banner and select Screen Picker or Manual Input.
-
If you select Screen Picker, click a masked field in the current pane.
The Unmask Protected Data dialog displays with the field you clicked already entered.
If you select Manual Input, enter the Masked Text.
- Enter the Data Mask Key that was set up in the administrator profile and click OK.