Browse docs

GDPR / Privacy Compliance

Purpose: Define data handling, consent, and retention rules for personal data in the project. Read when: Adding any feature that collects, stores, processes, or shares user-identifiable data. Skip when: Working on infrastructure or internal-only features with no PII. Read next: Engineering rules for logging (PII redaction) and security architecture.

Nav: Docs Index

Personal Data Inventory

(empty — populate when first PII is collected)

Lawful Basis

For each data type above, specify lawful basis (consent / contract / legitimate interest / legal obligation).

Retention Rules

  • Define maximum retention period per data type
  • Define automated deletion policy
  • Define user-initiated deletion (right to erasure) flow
  • How is consent obtained? (signup checkbox, cookie banner, etc.)
  • How is consent recorded? (timestamp, version of terms agreed to)
  • How is consent withdrawn?

Data Subject Rights

Provide a path for users to:

  • Access their data (export)
  • Rectify their data (edit)
  • Erase their data (account deletion)
  • Object to processing
  • Port their data (machine-readable export)

Data Processor Inventory

(empty — populate as integrations are added)

Breach Response

  • Detection: monitoring + alerting
  • Containment: rotate credentials, isolate affected systems
  • Notification: notify regulator within 72 hours, notify affected users without undue delay
  • Documentation: log incident in governance/archive/