Context
vsms already has retention mechanisms, but GDPR readiness requires a demonstrable path from retention policy to concrete recipient-data erasure or pseudonymisation. Relevant requirements include Art. 5(1)(e), Art. 17 and Art. 25.
Scope
Define and enforce retention behaviour for recipient MSISDNs, derived operator/country data, delivery receipts, webhook delivery records and other privacy-relevant metadata.
The implementation must distinguish data that can be deleted from data that must remain for operational/security/accounting reasons, and preserve integrity without keeping a directly identifying MSISDN where it is no longer needed.
Acceptance
Context
vsms already has retention mechanisms, but GDPR readiness requires a demonstrable path from retention policy to concrete recipient-data erasure or pseudonymisation. Relevant requirements include Art. 5(1)(e), Art. 17 and Art. 25.
Scope
Define and enforce retention behaviour for recipient MSISDNs, derived operator/country data, delivery receipts, webhook delivery records and other privacy-relevant metadata.
The implementation must distinguish data that can be deleted from data that must remain for operational/security/accounting reasons, and preserve integrity without keeping a directly identifying MSISDN where it is no longer needed.
Acceptance