Jamf is committed to complying with the EU General Data Protection Regulation (GDPR) and helping our customers comply with "right of access" and "right to be forgotten" requests related to GDPR. Here we provide information about the remediation process that customers can use in their environments if they receive GDPR-related requests from end users.
Jamf School stores data in a database for short-term and long-term access. The data storage retention period is 30 days for logs and database backups. Device data is kept for as long as the device is enrolled. There are two options for removing a device or user:
- Soft-delete —The record of the device or user is kept in the Trash and the record still exists in the database.
- Hard-delete —The device or user is deleted from the Trash and the record is permanently removed from the database.
Note:
Customers who use data forwarding to forward specific data to third-party vendors should review their data forwarding and retention policy in the third-party vendor solution to ensure that they adhere to GDPR guidelines for privacy.
Personal data may be stored in the following sections of Jamf School:
- Devices —Location where all the devices in a Jamf School environment can be managed.
- Organization —Location where all administrator data and audit logging is found.
- Users —Location where all users can be managed by a Jamf School administrator.