In this article
The Limit Display of Personal Data setting reduces or restricts personally identifiable information (PII) shown in the DNSFilter dashboard and exports. It controls how user and device details display across the application, including logs, reporting, exports, and synchronization tools.
Stricter privacy modes reduce the visibility of user and device identifiers and disable the collection of certain Roaming Client fields that may contain PII.
Only users with Admin permissions or higher update this setting.
Important considerations
Review internal compliance requirements before selecting a privacy level to ensure operational needs and privacy expectations are aligned.
- Privacy settings affect dashboard visibility and exported data
- Stricter privacy levels limit forensic detail in logs and reporting
- Sync tools and user-based policy assignments are hidden but still applied when user identifiers are hidden
Privacy levels and data visibility
The following table describes each privacy level.
| Privacy level | What it displays |
|---|---|
| Standard (default) | Displays all available user and device details.
|
| Device-Only | Redacts user-specific details while preserving limited device context.
This mode supports device-level monitoring without exposing user identity details. |
| Maximum Privacy | Removes personal identifiers from display and exports.
This mode provides the strictest privacy posture within the dashboard. |
Limit Display of Personal Data controls
To set the privacy level:
- From the DNSFilter dashboard, navigate to Organization and select Settings (from the MSP dashboard, navigate to MSP and select Settings).
- Locate Limit Display of Personal Data.
- Select the desired privacy level.
- Select Save.
Changes apply Organization-wide and affect subsequent dashboard views and exports. Existing data is not retroactively hidden.
Multi-tenant (MSP) dashboard and Organization controls
Privacy controls are managed at both the MSP dashboard level and the Organization level. MSP admins also control whether client Organization admins can adjust privacy settings independently.
MSP dashboard level
The privacy setting configured at the MSP dashboard level acts as the default for all managed Organizations. MSP admins can:
- Apply the same privacy setting to all Organizations
- Bulk update multiple Organizations
- View and manage overrides
Organization-level override
An individual MSP Organization can override the MSP-level privacy setting. When overridden:
- The selected privacy level updates for that Organization
- The change is recorded in the Organization Overrides grid in the MSP dashboard
Overrides can be applied from within the individual Organization or from the MSP dashboard for one or multiple Organizations.
To edit an existing override, select Edit (the pencil) in the Actions column. To edit multiple overrides at once, select the Organizations, select Edit, and then select an option in the Bulk Edit drawer.
Restrict client admin access to privacy settings
MSP admins control whether client Organization admins can adjust privacy settings from their dashboard. The toggle is enabled by default.
- On (default). Client admins can view and adjust privacy settings for their Organization.
- Off. Client admins cannot access or adjust privacy settings. The section is hidden from the client Organization dashboard, and MSP admins retain full visibility and control.
Limit display of personal data FAQs
How does this feature affect GDPR compliance?
Your organization's compliance with GDPR is determined solely by your own legal counsel and your own internal requirements. This feature is designed to enhance certain privacy features of the DNSFilter service.
Can this feature be turned on and off again?
Yes. After the option is disabled, each Roaming Client must check in with the DNSFilter dashboard before Client Name and Username data is available again.
Limit display of personal data troubleshooting
If Limit Display of Personal Data was enabled before entering a Friendly Name for each Roaming Client, it can be difficult to differentiate between devices in the DNSFilter dashboard.
To identify Roaming Clients after the data has been redacted, compare the ID of the Roaming Client in the dashboard with the Client ID of the device. Obtain the Client ID of the device using one of the following methods:
Command line or terminal window
Run the following command, which will return the client_id of the Roaming Client:
nslookup -type=txt debug.dnsfilter.comWindows Registry
Look up the agent on the local device:
HKEY_LOCAL_MACHINE\SOFTWARE\DNSAgent\Agent\ClientIdFor Windows Roaming Client version 3.0.0 and higher, the ClientId is located in the appsettings.json file under C:\Program Data\DNSFilter, Inc\Settings
macOS Library Application file
Look up the agent on the local device:
Standard agent:
cat /Library/Application\ Support/DNSFilter\ Agent/daemon.reg Legacy Whitelabel agent:
cat /Library/Application\ Support/DNS\ Agent/daemon.reg
Comments
0 comments
Please sign in to leave a comment.