Skip to content

GDPR: add personal-data breach evidence and incident export for vpay #148

Description

@stephane-segning

Context

A GDPR breach assessment must be based on facts that can be reconstructed quickly. Relevant requirements include Arts. 32–34, including the 72-hour supervisory-authority notification window where Art. 33 applies.

This story is product evidence plumbing, not the legal incident-response policy itself.

Scope

Ensure vpay can reconstruct the scope of a suspected personal-data incident: affected tenant/merchant, records, data categories, actors/credentials, time window, relevant security events and external deliveries.

Provide an operator workflow that exports the evidence needed by the incident lead without exposing unrelated tenants.

Acceptance

  • Security-relevant access/change events needed to investigate privacy incidents are retained and queryable.
  • Operator can bound an incident by tenant, subject/record identifiers and time window.
  • Export includes relevant authentication/audit/webhook evidence with timestamps and identifiers.
  • Cross-tenant information is excluded by default and tested.
  • Evidence export itself is authorised and audit logged.
  • Runbook maps the product evidence to the organisation's breach-response process, explicitly leaving risk/notification decisions to the responsible human role.
  • A tabletop/test scenario proves evidence can be collected from a representative compromised-credential incident.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions