ABCDEFG
1
FireServiceRota Data Usage and Storage overview
2
Data attributeDescription / MeaningExample ValuePurpose/UsageSystem containingVisible to users' colleaguesPrivacy / security risk
3
IdId of the user entity (unique)2294336Uniquely identify a user and a key to related data records.Web applicationYesNone
4
External IdentifiersThe external user ID used to login to a system external to FSRVRT1000Used as a foreign key to exchange data with external HR systemsWeb applicationNoNone
5
First NameFirst name of userJanHuman readable identification of the userWeb applicationYesLow
6
Last NameLast name of userDe VriesHuman readable identification of the userWeb applicationYesLow
7
PasswordA secret code only the user knows. Our company cannot read the value as it is stored in an encrypted format.1LoveTheFireService!AuthenticationWeb applicationNoHigh, encrypted
9
Profile pictureOptimal picture the user can upload himself:)Help quick visual identification of who you are communicating withWeb applicationYesMedium
10
Personnel NumberPersonnel number of user often a reference to the contract a user has with the employer123123Set personnel number in user's profileWeb applicationOnly managers (supervisor and owner)Medium
11
Membership periodsPeriods detailing when a person was actively involved in a team, station, cluster or region within the customer's organisation.1960-02-08T11:00:00.000Z - 1960-03-08T11:00:00.000Z - Make the user a member of the right station and facilitate data access rights.Web applicationYesLow
12
AddressThe home or work addresses of the user.Stationsweg 1
1111 AB AMSTERDAM
Show users on a map around the stationWeb applicationYesMedium
13
RankRank a user is employed withCrew CommanderPayroll export rules
Internal station hierarchy information
Web applicationYesLow
14
SkillsPrimary skillOfficer in Charge, DriverEvaluate appliance crewing level and warn for crewing deficienciesWeb applicationYesLow
15
Email addressesEmail address, including the primary that acts as a login to the systemjan@devries.nlTransactional email *only*, such as login, lost password recovery, service and support, and non-urgent (Prio2) message between usersWeb applicationYesHigh, secondary emails encrypted. Primary emails todo.
16
Phone numbersHome, work, mobile or 'in case of emergency' phone numbers020-1234567Shared with colleagues to serve as group phonebook
Send priority 1 urgent messages such as backup alerts
Caller Id recognition to facilitate booking on/off by calling a phone number
Web applicationYesHigh, encrypted
17
GPS dataMobile device configured to share its location in real time. 41°24'12.2"N 2°10'26.5"E. Only applicable if user double opted-in. Can be switched off just as easy as it is to switch on. Is auto-deleted after 24 hours.
Allow geofencing warnings when user is on-call and too far away.
Allow showing user location when responding to an incident.
Web applicationNoHigh, encrypted
18
Availability and shifts dataThe moments a user is on-call available and/or has a shift. Can include reasons why the person is available (comments) or unavailable (leave, sickness)1960-02-08T11:00:00.000Z - 1960-02-08T15:00:00.000Z: available
1960-03-08T11:00:00.000Z - 1960-03-08T15:00:00.000Z: unavailable, comment: work
Evaluate appliance crewing level and warn for crewing deficiencies.
Facilitate contractual compliance and payroll integration.
Web applicationYesMedium
19
Attendance to activitiesThe moments a user is attending activities such as incidents or trainings.1960-02-08T11:00:00.000Z - 1960-02-08T15:00:00.000Z: attend incident ABC123 as commanderFacilitate payroll integration, planning of trainings and logging of incident reports.Web applicationYesMedium
20
Incident notesIncidents notes provided by command & control centre software should not, but may sometimes contain sensitive information. The victim is suspected to have condition XYZThe incident notes inform attending firefighters at the time of the incident, but lose their value shortly after. We therefore remove incident notes from the incident record after 1 hour.Web applicationNoHigh
21
ContractsA collection of rules that apply to a group of users, indicating working targets, leave allowance and checks/balances.
Contracts apply to users for a certain period (can be open-ended)
1920 hours per yearFacilitate business rules enforcement, contractual compliance reportingWeb applicationOnly managers (supervisor and owner)Medium
22
MessagesMessages between (groups of) users, or announcements and pollsAre you joining the team BBQ next Sunday?Facilitate communication internallyWeb applicationLimitedMedium
23
Support requestsUser support questions and answers to these questions. May contain name, email and phone number. How do I reset my password?Help our usersZendeskNoLow
24
Database backupsAll data stored in the 'Web application' system111010111000101010111010101110000Fully encrypted file containing a real-time copy of all data we have.
Only readable by our company technical employees.
Amazon S3NoHigh, encrypted
25
PayrollA list of coded line items describing the number of occurances and hours of attendance and work. 1 incident attendance on incident [incident reference] from [start_time] to [end_time] for [user name] having role [role number] coded as [element code] against cost centre [cost centre] on date [date]Create an overview of payable activities of firefighters. This overview can be sent to payroll systems for further processing. FireServiceRota describes activities but does NOT calculate actual payments. The output provided would generally NOT have a currency sign. Web applicationOnly managers (supervisor and owner)Medium
26
IP addressThe address of the computer on the internet.192.168.2.1Only accessible for FSR admins for auditing purposes. Helps detect and analyse suspicious user transactions and login activity. Web applicationNoMedium
27
Browser user agentThe type of internet browser accessing the system.
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
Only accessible for FSR admins for auditing and debugging purposes.Web applicationNoLow
28
Mobile and alerting devicesThe smartphone apps and/or smart pagers connected to a useriOS primary alerting app version ABC
Swissphone pager with serial number DEF
Sending/receiving messages
Debugging and auditing
Web applicationNoLow
29
30
31
32
33
34
35
36
37
38
39
40