-
Bug
-
Resolution: Fixed
-
Minor
-
3.4.2, 3.5, 3.6
-
MOODLE_34_STABLE, MOODLE_35_STABLE, MOODLE_36_STABLE
-
MOODLE_35_STABLE
-
MDL-62544-master -
-
Privacy Sprint 1
If the contactdataprotectionofficer config option is disabled, users are not allowed to make subject access requests (SARs) on their own. However, neither are admins: If I click on "New request" in admin/tool/dataprivacy/datarequests.php, the next page will throw a notice: "Please contact the Data Protection Officer as described in the privacy policy."
Expected behaviour
As an administrator or DPO I am allowed to create SARs on behalf of a user, even if site config prohibits this for regular users.
Otherwise, administrators and DPOs will be unable to comply with SARs that will be received via other channels.