feat(records): add governed DSAR coverage

This commit is contained in:
2026-08-21 02:31:10 +02:00
parent e9d2827581
commit 38f203a906
5 changed files with 1794 additions and 0 deletions
+19
View File
@@ -54,6 +54,25 @@ Restricted object grants remain a separate governed slice. A target-tested
archive adapter and any destructive effect remain deliberately unimplemented;
approved destruction is only a pending lifecycle state.
## Data-subject requests
Records publishes `privacy.dsar.records`. A record-subject search must include
an exact record, revision, item, volume, chronology, hold, disposition,
transfer-package, or authoritative source-module reference. A canonical
account, identity, or membership match identifies staff accountability
activity only; creating, filing, reviewing, or transferring an eAkte does not
make that staff member the subject of its contents.
The provider exports bounded record identity, revision, filing, chronology,
hold, disposition, and transfer lifecycle metadata. It excludes source
content, record snapshots and search text, opaque institutional contexts and
payloads, digests, replay keys, launch URLs, approval identifiers, archive
manifests and receipts, and unrelated records. Exact source content remains in
the source owner's DSAR provider. Record revisions and lifecycle evidence are
immutable retention evidence; the current record fact receives a
non-executable manual-review action. Actual correction, closure, appraisal,
hold, disposition, or transfer must use the governed eAkte lifecycle.
## First Implementation Slice
Complete restricted access and one target-tested archive provider without