Skip to content

Permission to block subjects

Bengfort requested to merge block-perm into main

So far anyone with the change_subject permission is allowed to block a subject in the "additional info" tab.

However, blocking a subject is quite a radical thing to do. It is claiming that the subject has behaved so badly that we have sufficient reason to keep their data even against their will (Art. 6.1.f GDPR).

I therefore made some changes:

  • In order to block a subject you need the special permission block_subject. Principal subject managers have it by default.
  • Blocking subjects is only possible in subject management, not in recruitment/execution. This is similar to GDPR export and deletion.
  • Blocking subjects has been moved out of the "additional info" tab into its own tab. (This greatly simplified the other two changes.)
Edited by Bengfort

Merge request reports