Skip to content

GDPR: add personal-data breach evidence and incident export for vsms #376

Description

@stephane-segning

Context

A suspected personal-data incident involving SMS content, recipient numbers or application credentials has to be scoped from evidence quickly. Relevant GDPR requirements include Arts. 32–34, including the 72-hour supervisory-authority notification window where Art. 33 applies.

This issue provides product evidence; it does not automate the legal decision whether an incident is notifiable.

Scope

Ensure vsms can reconstruct the affected app/tenant, recipient/message records, data categories, provider submissions, authentication events, webhook deliveries and time window for a suspected privacy incident.

Provide an operator-only export suitable for the incident-response process.

Acceptance

  • Security/privacy-relevant access and change events needed for investigation are queryable.
  • Incident evidence can be bounded by app/tenant, message/recipient identifiers and time window.
  • Export includes relevant provider, delivery, webhook and authentication evidence with timestamps.
  • Unrelated tenant/app data is excluded by default and tested.
  • Evidence export itself is authenticated, authorised and audit logged.
  • Runbook maps product evidence to the organisation's breach-response process.
  • A tabletop/test scenario demonstrates evidence collection for a compromised application credential or unintended message-content exposure.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions