Context
Telemetry and retry infrastructure can become an uncontrolled duplicate store for recipient identifiers and message content. Relevant GDPR principles include Art. 5(1)(c), Art. 25 and Art. 32.
Scope
Audit vsms logging, tracing, metrics, alert payloads, provider error handling, webhook request journals and admin-console diagnostics for MSISDNs, message bodies, OTPs and other personal data.
Establish central redaction/pseudonymisation rules and safe operator identifiers rather than relying on individual call sites.
Acceptance
Context
Telemetry and retry infrastructure can become an uncontrolled duplicate store for recipient identifiers and message content. Relevant GDPR principles include Art. 5(1)(c), Art. 25 and Art. 32.
Scope
Audit vsms logging, tracing, metrics, alert payloads, provider error handling, webhook request journals and admin-console diagnostics for MSISDNs, message bodies, OTPs and other personal data.
Establish central redaction/pseudonymisation rules and safe operator identifiers rather than relying on individual call sites.
Acceptance