GDPR Request Compliance in Jamf School

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Jamf is committed to complying with the EU General Data Protection Regulation (GDPR) and helping our customers comply with "right of access" and "right to be forgotten" requests related to GDPR. Here we provide information about the remediation process that customers can use in their environments if they receive GDPR-related requests from end users.

Jamf School stores data in a database for short-term and long-term access. The data storage retention period is 30 days for logs and database backups. Device data is kept for as long as the device is enrolled. There are two options for removing a device or user:
  • Soft-deleteThe record of the device or user is kept in the Trash and the record still exists in the database.
  • Hard-deleteThe device or user is deleted from the Trash and the record is permanently removed from the database.
Note:

Customers who use data forwarding to forward specific data to third-party vendors should review their data forwarding and retention policy in the third-party vendor solution to ensure that they adhere to GDPR guidelines for privacy.

Personal data may be stored in the following sections of Jamf School:
  • DevicesLocation where all the devices in a Jamf School environment can be managed.
  • OrganizationLocation where all administrator data and audit logging is found.
  • UsersLocation where all users can be managed by a Jamf School administrator.