May 2019 saw one year since the enforcement of the General Data Protection Regulation (GDPR). Compliance is an ongoing concern, and the field in which Tiro Partners operates – specialist technology recruitment – is particularly sensitive due to the sheer amount of personal information within their workflows.
Last year we worked with Tiro to prepare for GDPR, and one measure was to create a SharePoint site where their consultants must save all files containing personal data that has not entered into a contract. Tiro has a retention policy of 12 months for such data, and so we have been busy writing a bot that automatically crawls the SharePoint site and cleans all expired data – saving a huge amount of time if this were to be done manually.
The bot runs daily and its activity is fully logged. Expired files are deleted and cannot be accessed, but retain a 30 day recovery window in the event of an error having been made. The bot is written in a combination of PowerApps and Visual Basic .NET, using a JSON instruction set, and Microsoft Flow to trigger and monitor its scheduled routine.
