Parent epic: #8
Normative spec: 07 — Privacy baseline
Decision dependency: #23
Scope
Create approved data inventory/processing records and versioned notices; separate privacy acknowledgement and marketing consent; implement account and accountless access/export/correction/deletion-or-anonymization/restriction workflows; idempotent retention jobs across registrations, learners, submissions/reviews/attendance/certificates/email/audit/log projections; processor/cache/search/export propagation; deletion tombstones for restored backups; Studio/admin API request handling/audit; and minors/public-recording policy enforcement.
Non-goals
Do not load production personal data before #23 approval, infer consent, promise backup mutation outside approved tombstone process, or expose third-party learner/reviewer data in an export.
Acceptance criteria
Test scenarios
- Export/correct/delete active/past/accountless/multi-cohort/event registrant with shared peer-review or certificate relations.
- Each retention boundary, retry/crash/resume, legal hold/suppression exception, missing consent evidence, and processor failure.
- Restore pre-deletion backup, replay tombstones, rebuild search/cache, reconcile provider state, and prove no old outbox send.
Playwright
Submit/view representative privacy request and staff handling with identity/PII permission checks; verify notices/unbundled consent/error states at desktop/mobile and capture redacted screenshots.
Dependencies
Depends on #23, #31–#33, and relevant domain models. Blocks production import/cutover.
Parent epic: #8
Normative spec: 07 — Privacy baseline
Decision dependency: #23
Scope
Create approved data inventory/processing records and versioned notices; separate privacy acknowledgement and marketing consent; implement account and accountless access/export/correction/deletion-or-anonymization/restriction workflows; idempotent retention jobs across registrations, learners, submissions/reviews/attendance/certificates/email/audit/log projections; processor/cache/search/export propagation; deletion tombstones for restored backups; Studio/admin API request handling/audit; and minors/public-recording policy enforcement.
Non-goals
Do not load production personal data before #23 approval, infer consent, promise backup mutation outside approved tombstone process, or expose third-party learner/reviewer data in an export.
Acceptance criteria
Test scenarios
Playwright
Submit/view representative privacy request and staff handling with identity/PII permission checks; verify notices/unbundled consent/error states at desktop/mobile and capture redacted screenshots.
Dependencies
Depends on #23, #31–#33, and relevant domain models. Blocks production import/cutover.