Context
A suspected personal-data incident involving SMS content, recipient numbers or application credentials has to be scoped from evidence quickly. Relevant GDPR requirements include Arts. 32–34, including the 72-hour supervisory-authority notification window where Art. 33 applies.
This issue provides product evidence; it does not automate the legal decision whether an incident is notifiable.
Scope
Ensure vsms can reconstruct the affected app/tenant, recipient/message records, data categories, provider submissions, authentication events, webhook deliveries and time window for a suspected privacy incident.
Provide an operator-only export suitable for the incident-response process.
Acceptance
Context
A suspected personal-data incident involving SMS content, recipient numbers or application credentials has to be scoped from evidence quickly. Relevant GDPR requirements include Arts. 32–34, including the 72-hour supervisory-authority notification window where Art. 33 applies.
This issue provides product evidence; it does not automate the legal decision whether an incident is notifiable.
Scope
Ensure vsms can reconstruct the affected app/tenant, recipient/message records, data categories, provider submissions, authentication events, webhook deliveries and time window for a suspected privacy incident.
Provide an operator-only export suitable for the incident-response process.
Acceptance