Hi all,

I'd like to open discussion on SIP-230: an opt-in download reason for
CSV/XLSX exports. Deployments that hold personal data often need to
record why a file was exported, not just who/what/when — Korea's
PIPA safeguards standard and GDPR/HIPAA-style audits ask the same
"purpose of processing" question.

Behind a new feature flag (REQUIRE_DOWNLOAD_REASON, default False),
the UI prompts for a short reason before CSV/XLSX export (Explore,
dashboard charts, dashboard-wide Excel, SQL Lab), the backend rejects
export requests without one, and the reason rides along in the
existing Action Log entry — no new table. Scheduled reports supply
their own reason automatically. Flag off, nothing changes.

SIP:
https://www.google.com/url?q=https://github.com/apache/superset/issues/44512&source=gmail&ust=1790996007510000&sa=E
Reference PR:
https://www.google.com/url?q=https://github.com/apache/superset/pull/44499&source=gmail&ust=1790996007510000&sa=E

Would love to hear your thoughts.

Thanks,
Seunggabi (seunggabi)

Reply via email to