[Privacy] Add governed Records DSAR coverage #9

Closed
opened 2026-08-21 02:23:37 +02:00 by zemion · 1 comment
Owner

Goal

Implement the Records portion of GovOPlaN/govoplan#47 without weakening eAkte retention, holds, disposition, or archive evidence.

Acceptance criteria

  • Resolve exact-tenant record, revision, item, volume, chronology, hold, disposition, transfer-package, and authoritative source references.
  • Treat canonical account/identity/membership matches as operator accountability attribution, not record-subject ownership.
  • Export bounded, minimized metadata without snapshots, search text, opaque contexts, payloads, hashes, replay keys, archive receipts/manifests, launch URLs, or source content.
  • Retain immutable record evidence and route current-record/privacy consequences to non-executable manual review.
  • Fail closed for missing/conflicting direct selectors, enforce tenant isolation, and cap results.
  • Register and document privacy.dsar.records, with provider/workflow and manifest tests.
## Goal Implement the Records portion of GovOPlaN/govoplan#47 without weakening eAkte retention, holds, disposition, or archive evidence. ## Acceptance criteria - Resolve exact-tenant record, revision, item, volume, chronology, hold, disposition, transfer-package, and authoritative source references. - Treat canonical account/identity/membership matches as operator accountability attribution, not record-subject ownership. - Export bounded, minimized metadata without snapshots, search text, opaque contexts, payloads, hashes, replay keys, archive receipts/manifests, launch URLs, or source content. - Retain immutable record evidence and route current-record/privacy consequences to non-executable manual review. - Fail closed for missing/conflicting direct selectors, enforce tenant isolation, and cap results. - Register and document `privacy.dsar.records`, with provider/workflow and manifest tests.
Author
Owner

Implemented and pushed in 38f203a. The provider covers explicit eAkte/source linkages and staff accountability without treating staff activity as record-subject ownership. It exports minimized lifecycle evidence, excludes content/snapshots/search/context/payload/hash/replay/archive secrets, retains immutable evidence, and routes current facts to non-executable review. Verification: 22 Records tests, Ruff, manifest registry, and the complete workspace gate passed.

Implemented and pushed in `38f203a`. The provider covers explicit eAkte/source linkages and staff accountability without treating staff activity as record-subject ownership. It exports minimized lifecycle evidence, excludes content/snapshots/search/context/payload/hash/replay/archive secrets, retains immutable evidence, and routes current facts to non-executable review. Verification: 22 Records tests, Ruff, manifest registry, and the complete workspace gate passed.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-records#9