Skip to content

Privacy Runbooks (M7)

The operational layer for GDPR/CCPA obligations: a maintained data inventory (what personal data exists, where, why) and the DSAR workflow (how a data subject's access/deletion request gets fulfilled on the clock, with evidence).

Contents

Runbook Use it for
DSAR Workflow Fulfilling a data-subject access/deletion/portability request end to end — GDPR 30-day / CCPA 45-day clocks.
DSAR record template The per-request evidence record committed to compliance/dsar/.

See also

  • Data inventory (RoPA)compliance/data-inventory/, the register the DSAR workflow walks; gate: validate.py.
  • M4 Purview — data discovery/classification that reconciles against the register. M5 DLP — stops personal data leaving via M365. M6 enforces residency; M1/M2/M3 enforce encryption/TLS.
  • The data-leak IR runbook — a DSAR is a request; an exposure is an incident. If a DSAR uncovers an exposure, open the incident path immediately.