Skip to main content
Petanque Life

Compliance & Legal

F21.13 10 features

At a glance

The compliance and legal console: GDPR request tracker with SLA timers and one-click execution, legal-document publisher with diff viewer and re-acceptance campaigns, security-posture snapshot, DPIA register, public subprocessor list with change notifications, breach-notification workflow under GDPR Article 33, retention-policy overview, and a read-only GDPR snapshot for support.

How it works

Compliance & Legal centralises every regulatory artefact a federation auditor or DPO might ask for. The GDPR request tracker enumerates user access, export, and erasure requests with deadlines, assignee, and status; an SLA timer surfaces on the dashboard `Attention` panel as deadlines approach. `Execute request` triggers the GDPR service endpoints, packages the output, and stores it for the requester to download. The legal-document publisher builds on the existing PL-T094 infrastructure for ToS, DPA, Privacy Policy, and SLA, with a side-by-side diff viewer between versions.

Re-acceptance campaigns mark a version as requiring fresh consent and track acceptance rate per tenant so legal can prove who has accepted what. Security posture renders a snapshot of CIS benchmarks, SBOM age, and penetration-test findings — the place an SOC2 auditor lands first. The DPIA register logs Data Protection Impact Assessments per feature; a flag highlights features that need DPIA review.

The subprocessor list publishes to `/legal/subprocessors`, keeps a public changelog, and notifies tenants on change so the contractual obligation to inform of subprocessor changes is automated rather than manual. The breach-notification workflow activates when a SEV1 incident is tagged with personal-data impact: a guided workflow drives the operator through the GDPR Article 33 72-hour notification, capturing the supervisory authority recipient, the affected categories, and the remediation steps. Retention policy overview enumerates every collection with its configured TTL versus its observed age and flags anomalies (a collection holding rows older than its policy is a compliance breach in waiting).

Finally, the GDPR snapshot at `GET /sys/users/{id}/gdpr-snapshot` aggregates 13 categories (identity, profiles, tenant memberships, licenses, payments sent and received, matches, tournaments, communications, audit-on-user, linked OAuth, sessions summary, consent history) with sensitive payloads redacted (password hashes, session fingerprints, M2M secrets). It is an internal support tool — explicitly not a replacement for the formal Article 15 export — and is downloadable as JSON. Every read and download is audited as `sys.user.gdpr_snapshot.{read,download}`.

Key capabilities

  • GDPR request tracker with deadlines, assignee, and SLA timers
  • One-click execute for access/export/erasure with packaged output
  • Legal-document publisher with diff viewer and re-acceptance campaigns
  • Security posture: CIS benchmarks, SBOM age, pen-test findings
  • DPIA register flagging features that need impact assessment
  • Public subprocessor list with changelog and tenant notifications
  • Breach-notification workflow guiding GDPR Article 33 72-hour reporting
  • Retention-policy overview comparing configured TTL vs observed age
  • Read-only GDPR snapshot (13 categories, redacted) for support — not the formal Article 15 export

In practice

A user emails a GDPR Article 15 access request. The DPO opens the GDPR request tracker, creates a record with a 30-day deadline, assigns to herself, and clicks `Execute`. The GDPR service produces a packaged JSON; she downloads, reviews, and emails the requester a signed link.

A week later a SEV1 incident is tagged personal-data-impact: the breach-notification workflow opens, asks for affected categories and remediation steps, and pre-fills a draft for the supervisory authority within the 72-hour window. Separately a support operator opens the GDPR snapshot for a different user to answer a `what data do you have on me` ticket; the snapshot covers all 13 categories without exposing password hashes, and the read is audited.

Features in this subsystem

10
ID Status Features
F21.13.01 Shipped GDPR request tracker — user access / export / erasure requests with deadlines, assignee, status. ✅ PL-T133 | 🔁 Go-backend + sys-UI 742fe3db.m-4 (D-GDPR m-4 t-4): cross-tenant-intaget är byggt rent i Go/Postgres — POST|GET /v1/sys/gdpr, GET|PATCH /v1/sys/gdpr/{id} bakom capability sys.gdpr.manage (både sys_support och sys_security). Ärendenummer GR-…, FSM received → validated → in_progress → completed|rejected prövad i transaktionen, 30-dagarsfrist (art. 12(3)) med append-only förlängning ≤ 2 mån och sla_state härlett vid varje läsning. Flera berörda förbund per ärende (gdpr_request_tenant är omfattningens sanning). Yta: /efterlevnad/dsar + /efterlevnad/dsar/{id}.
F21.13.02 Shipped Execute request — triggers gdpr service endpoints and packages output. SLA timer on dashboard. ✅ PL-T133 | 🔁 Go-backend + sys-UI 742fe3db.m-4 (D-GDPR m-4 t-4): exekveringen är byggd och idempotent: POST /v1/sys/gdpr/{id}/execute konsumerar m-2:s exportpipeline respektive m-3:s raderingspipeline (aldrig auto-beviljad) och skapar EN artefakt per förbund i det förbundets kontext; omtag ger samma id:n, omtag på ett stängt ärende ⇒ 409 gdpr_already_completed. dry_run=true visar planen och skriver ingenting. POST …/delivery-link (fresh auth) utfärdar den kortlivade signerade länken. SLA-klockan drivs av jobbet gdpr_sla_tick.
F21.13.03 Shipped Legal document publisher — ToS, DPA, Privacy Policy, SLA. Builds on PL-T094 infrastructure. Diff viewer between versions. ✅ PL-T133
F21.13.04 Shipped Re-acceptance campaigns — mark a version as requiring re-accept, track acceptance rate per tenant. ✅ PL-T133
F21.13.05 Shipped Security posture — snapshot of CIS benchmarks, SBOM age, penetration test findings. ✅ PL-T133
F21.13.06 Shipped DPIA register — log DPIAs per feature; dashboard flags features needing review. ✅ PL-T133 | 🔁 Go-backend + sys-UI 742fe3db.m-4 (D-GDPR m-4 t-4): DPIA-registret är byggt: GET|POST /v1/sys/compliance/dpia, GET|PUT /v1/sys/compliance/dpia/{id}. overdue beräknas VID LÄSNING, godkännande kräver sys.security.operate + ifylld art. 35(7)-kärna (422 dpia_assessment_incomplete) och sätter review_by = +12 mån. Ingen auto-approve-väg finns. Yta: /efterlevnad/dpia.
F21.13.07 Shipped Subprocessor list — public /legal/subprocessors page, changelog, tenant notification on change. ✅ PL-T133
F21.13.08 Shipped Breach notification workflow — SEV1 incident + personal data impact → guided notification workflow under GDPR Article 33 (72 h). ✅ PL-T133 | 🔁 Go-backend + sys-UI 742fe3db.m-4 (D-GDPR m-4 t-4): Art. 33/34-anmälan är byggd: POST /v1/admin/incidents/{id}/notify-gdpr (sys.security.operate + fresh auth) med attesterad personal_data_impact (422 dpia_impact_not_set), mottagarupplösning mot RIKTIG data, dry_run → utkast utan skrivning och dry_run=false → EN immutabel, hash-kedjad rad i gdpr_notification_log (5 års retention). "Utfärdad och förseglad" — inte "levererad": plattformen har ingen notiskanal. Läsning via GET /v1/sys/compliance/breach-notifications. Yta: /efterlevnad/incidenter.
F21.13.09 Shipped Retention policy overview — per collection, configured TTL vs observed age, flags anomalies. ✅ PL-T133
F21.13.10 Shipped GDPR snapshot (read-only) — GET /sys/users/{id}/gdpr-snapshot aggregates 13 categories (identity, profiles, tenant memberships, licenses, payments sent/received, matches, tournaments, communications, audit-on-user, linked OAuth, sessions summary, consent history) with sensitive payloads redacted (password hashes, session fingerprints, M2M secrets). Internal support tool — not a replacement for the formal Article 15 export (F21.13.02). Downloadable JSON, audited as sys.user.gdpr_snapshot.{read,download}. ✅ PL-T148 | 🔁 Go-backend + sys-UI 742fe3db.m-2 (D-GDPR m-2 t-3): rena rutterna GET /v1/sys/users/{id}/gdpr-snapshot (+ /download) bakom capability sys.support.lookup. 13 kategorier i låst ordning (egen JSON-marshaler — encoding/json skulle annars sortera nycklarna alfabetiskt), var och en bunden till RIKTIGA tabeller (oidc_identity_link, ett AGGREGAT över refresh_token_family/auth_audit_event, newsletter_sent_mail, audit_log riktad mot personen utan diff, refunds+referee_payout, …). Degraderar per kategori (en trasig kategori ⇒ tom + error, de övriga tolv orörda — medvetet spegelvänt mot exportens fail-hard; bevisas med sömmen PL_GDPR_SNAPSHOT_FAIL_CATEGORY). Redigering i två lager: uppräknade kolumner i SQL (allowlist) + en rekursiv nyckelfiltrering som stryker password_hash/secret_data/otp_seed/jti/credential_id/recovery_code/token-hashar. Svaret bär is_dsar_response: false + canonical_art15_channel: "/v1/me/data-export" — snapshoten är aldrig ett DSAR-svar. Två skilda audit-actions (…read / …download) plus en data_access_audit-rad i varje förbund personen tillhör, så den registrerade ser läsningen i sin egen Art. 15-vy. Ingen listnings-/sökrutt för identiteter (anti-uppräkning; user-directory ägs av D-SYS). sys-UI: NAV-posten "GDPR-snapshot" → uppslag på identitets-UUID → /anvandare/{id}/gdpr-snapshot med 13 kategorikort, "Fel"-badge i ORD för en degraderad kategori, nedladdning och den permanenta callouten om att detta inte är ett DSAR-svar. Bevisat mot körande stack av tools/gate/dgdpr-m2-admin-e2e.mjs. Se specs/api/endpoints/sys-users-gdpr-snapshot.md + specs/sys/views/users-gdpr-snapshot.md.