Skip to content

Implement privacy inventory, consent evidence, rights, retention, and deletion replay #64

Description

@alexeygrigorev

Parent epic: #8

Normative spec: 07 — Privacy baseline
Decision dependency: #23

Scope

Create approved data inventory/processing records and versioned notices; separate privacy acknowledgement and marketing consent; implement account and accountless access/export/correction/deletion-or-anonymization/restriction workflows; idempotent retention jobs across registrations, learners, submissions/reviews/attendance/certificates/email/audit/log projections; processor/cache/search/export propagation; deletion tombstones for restored backups; Studio/admin API request handling/audit; and minors/public-recording policy enforcement.

Non-goals

Do not load production personal data before #23 approval, infer consent, promise backup mutation outside approved tombstone process, or expose third-party learner/reviewer data in an export.

Acceptance criteria

  • Field-level purpose/basis/controller/processor/region/retention/right inventory reflects Decision: Approve privacy ownership, retention, and minors policy #23 approval.
  • Versioned notice/consent evidence is immutable, unbundled, and migrates only with provenance.
  • Accountless and account export/correction/deletion/anonymization include all owned data while protecting others and required educational/audit integrity.
  • Retention jobs are dry-run/idempotent/bounded/audited and propagate to projections/caches/providers/exports.
  • Restored-backup tombstone replay prevents resurrected use/sends.
  • PII is masked by default and rights operations have scoped Studio/API parity.

Test scenarios

  1. Export/correct/delete active/past/accountless/multi-cohort/event registrant with shared peer-review or certificate relations.
  2. Each retention boundary, retry/crash/resume, legal hold/suppression exception, missing consent evidence, and processor failure.
  3. Restore pre-deletion backup, replay tombstones, rebuild search/cache, reconcile provider state, and prove no old outbox send.

Playwright

Submit/view representative privacy request and staff handling with identity/PII permission checks; verify notices/unbundled consent/error states at desktop/mobile and capture redacted screenshots.

Dependencies

Depends on #23, #31#33, and relevant domain models. Blocks production import/cutover.

Metadata

Metadata

Assignees

No one assigned

    Labels

    P0Must-have or release-blockingdata-migrationArea: data-migrationoperationsArea: operationssecurityArea: security

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions