Permission to block subjects
So far anyone with the change_subject
permission is allowed to block a subject in the "additional info" tab.
However, blocking a subject is quite a radical thing to do. It is claiming that the subject has behaved so badly that we have sufficient reason to keep their data even against their will (Art. 6.1.f GDPR).
I therefore made some changes:
- In order to block a subject you need the special permission
block_subject
. Principal subject managers have it by default. - Blocking subjects is only possible in subject management, not in recruitment/execution. This is similar to GDPR export and deletion.
- Blocking subjects has been moved out of the "additional info" tab into its own tab. (This greatly simplified the other two changes.)