Skip to main content

Creating a Quote

GDPR in Practice

Written by Petr Pech

In this chapter, we will walk through an example of how to proceed when creating a quote for your customers.

Personal Data in the Case of a Quote

For a quote, the personal data processing period can vary significantly. It may be just a matter of months, or in some cases years. This depends primarily on whether the customer accepted the quote or not.

If the quote was not accepted, the processing period will be considerably shorter — it may be just a matter of months. Of course, if you use the data for purposes such as statistics, the personal data processing period may be longer (however, you must be able to justify retaining the personal data — it will most likely be necessary to remove personal data such as email address, etc., and retain only data such as city, postal code, etc.).

If the quote was accepted, the personal data processing period is naturally much longer, primarily because the quote gives rise to additional purposes within the company (invoices, etc.), which by definition allow for the processing of this data. For example, in the case of an invoice for a VAT payer, the personal data processing period is 10 years.


Creating a Purpose Definition

Now let's look at our example of creating a purpose definition required for generating a quote.

First, you need to create a purpose definition.

  • In the Data Occurrences tab, fill in the agenda Issued Quotes and the agenda fields Email, address (city, company name, postal code, street).

  • Validity begins "Automatically from the start of the record's validity", meaning the purpose is created each time a quote becomes active.

  • The validity period of the purpose for a quote can be set to, for example, 6 months. If you produce statistical outputs, this does not entitle you to retain contact details such as an email address — you will need to create a separate purpose for retaining only the essential data (name, city, etc.).

  • The legal basis in the case of an issued quote is "Legitimate Interest".

  • Filling in additional information such as Data Access, Post-expiry Procedure, etc. is not mandatory, but we recommend including it in case you need to demonstrate compliance before the personal data protection authority.

Purposes can subsequently be looked up in the GDPR -> Purposes register. Here, as in most registers in Flexi, filtering is available (by company, by purpose definition, etc.).

Did this answer your question?