GDPR Compliance – What’s the Big Deal?
The General Data Protection Regulation (GDPR) requires organizations handling EU personal data to implement strict safeguards. Articles 5, 25, and 32 emphasize data minimization, privacy-by-design, and robust monitoring and logging to ensure accountability and transparency.
This article examines NetSuite’s native GDPR-related capabilities, highlights gaps (particularly around audit logging of sensitive data access), and provides recommended controls to help organizations stay compliant.
Native GDPR Compliance Features in NetSuite
NetSuite includes a number of features designed to help organizations comply with GDPR requirements:
Data Masking / Field-Level Security via Permissions:
- NetSuite provides granular field-level security that allows administrators to strictly control access to highly sensitive personal data. Viewing certain fields—such as Employee Social Security Numbers, unencrypted credit card information, or unencrypted bank account numbers—requires explicit permissions to be assigned to a user. By default, these fields are hidden or masked unless a user has been deliberately granted access. For example, payroll administrators may be permitted to view full SSNs, while other HR roles see only the last four digits. In addition to native fields, organizations often store sensitive information in custom records (e.g., medical details, government ID numbers, or other PII data necessary for their operations). NetSuite allows administrators to restrict which roles and users can access those custom records, ensuring that only designated personnel can view or update the data.
Example of Data Obfuscation for Social Security Numbers:

- Right-to-Erasure (Record and Field Deletion):
NetSuite provides routines to anonymize or delete personal records when a subject invokes their “Right to Be Forgotten.” Users simply need the Delete access level to the specific record that needs to be deleted. In practice, this often involves deleting records, purging identifiers, or replacing PII fields with placeholder text to preserve transactional integrity.
Employee Record Deletion Example:

Audit-Log Question: PII Access in NetSuite
A critical GDPR question is: Does NetSuite capture who has viewed or exported sensitive personal data (PII)?
- What Exists:
NetSuite provides detailed System Notes and Login Audit Trail features, which capture changes to records, login activity, and transaction events. However, these logs primarily focus on new records or updates to records.
- What’s Missing:
By default, NetSuite does not provide detailed audit trails of who has simply viewed or queried sensitive data fields (e.g., SSN, bank account, or ID numbers). If a user with access permissions runs a saved search or opens a customer record, the action may not be logged at a field-level granularity. Though we haven’t seen this in any ERP system to this point, and our intention is certainly not to make NetSuite look bad as they have extremely robust audit logging capabilities, it would one day be awesome to see NetSuite provide the ability to audit what users and roles have viewed highly sensitive data.
Risk if Logs Are Absent
If NetSuite does not provide full audit trails for sensitive data access:
- Regulatory Exposure: Organizations may be unable to demonstrate to regulators that personal data access was properly controlled, violating GDPR’s accountability principle.
- Undetected Privacy Breaches: Unauthorized users could access, copy, or export sensitive PII without detection, increasing risks of identity theft, reputational damage, or fines.
- Investigation Limitations: In the event of a suspected breach, the organization cannot reliably trace who accessed which PII, when, and how often.
Controls & Recommendations
To mitigate the above risks, organizations should strengthen privacy controls in NetSuite:
- Restrict Sensitive Data Permissions: Assign access to PII fields only to roles that actually have a business need to enter or view such data.
- Schedule Privacy-Access Reviews: During your quarterly access review process, ensure you are evaluating what users and roles can access sensitive fields and confirm that access is appropriate.
- Implement Efficient Deletion / Anonymization Processes: Establish documented routines for promptly handling GDPR “Right to Be Forgotten” requests by deleting or anonymizing records.
Final Thoughts
While NetSuite provides useful features for data masking and right-to-erasure, its audit logging over viewing sensitive data remains limited. Organizations attempting to obtain GDPR Compliance in NetSuite must implement access controls over sensitive data and closely follow customer and employee requests to have their data forgotten to ensure compliance with GDPR’s accountability and transparency obligations.