Background documentationAuthorization Concept for the Destruction of Data in HR

 

In data privacy terms, HR data is almost always personal data that is subject to data privacy regulations. The general authorization concept for Human Resources enables you to regulate access to personal data. In addition to the regulated access to personal data, the authorization concept for the destruction of personal data plays a particularly important role in data privacy.

Features

The authorization concept for data privacy is based on the general authorization checks for Human Resources and archiving.

When destroying data, you use write and delete programs that communicate with the logical database PNPCE. The PNPCE logical database performs the standard authorization checks for all infotype data records that are requested by the report using the INFOTYPES statement.

For detailed information, see the documentation for the program SAPDBPNPCE for the logical database PNPCE.

Furthermore, you can use the report-specific authorization check HR: Reporting (authorization object P_ABAP) to override the authorization for the write programs and the delete programs for personal data, irrespective of the infotype authorization. You can thus grant a user authorization to destroy HR master data without also granting this user other authorizations for personal data.

Since the write programs and delete programs refer to archiving objects, they are also subject to the authorization concept for archiving. For more information, see User Authorization Checks in archiving.

You can control write and delete authorizations separately, independently of the authorization checks mentioned.