Protect the Windows device
- Use individual Windows accounts and strong sign-in controls.
- Enable device encryption where appropriate.
- Keep Windows and the app updated.
- Restrict administrative access and unattended sessions.
- Plan secure disposal or reassignment of old devices.
Review source authorisation
- Connect only organisations and portals the user is authorised to access.
- Review the provider consent and permissions.
- Remove connections when a client or employee relationship ends.
- Revoke provider access through provider settings where supported.
Separate export folders and clients
Use a dedicated stable folder for each workspace, source and connection. Apply folder permissions and do not mix client files merely because a BI model can technically read them. A combined report should have an explicit purpose, model and authorisation.
Control backups, retention and deletion
Know whether local folders are copied into Windows backup, a shared drive or a synchronisation service. Set a retention period, remove obsolete exports and verify that deletion covers backup copies where policy requires it.
Keep support diagnostics proportionate
Start with version, source, timestamp, status and a non-sensitive error. Inspect diagnostic ZIP files and screenshots before sending them. Never paste provider tokens, authorisation codes or raw customer data into a routine support form.
Treat BI cloud publishing as a new data transfer
Datplan may prepare files locally, but publishing them through Power BI, Tableau, Qlik, email or shared storage introduces another processor and access model. Review the destination's permissions, retention and access controls before publishing or sharing the files.
Frequently asked questions
Is local reporting automatically more secure than cloud reporting?
No. It changes the risk and control model. Local storage can reduce external processing but makes device access, backups, folders, exports and user behaviour especially important.
Should client data share one export folder?
No. Keep each client, workspace, source and connection in a separate stable folder unless your reporting model intentionally combines them and the access has been approved.
What should a finance team check before publishing to a BI cloud service?
Check the data classification, lawful purpose, permissions, destination region and contract, user access, refresh route, retention, sharing controls and the BI provider’s terms.