Privacy Runbooks (M7)¶
The operational layer for GDPR/CCPA obligations: a maintained data inventory (what personal data exists, where, why) and the DSAR workflow (how a data subject's access/deletion request gets fulfilled on the clock, with evidence).
Contents¶
| Runbook | Use it for |
|---|---|
| DSAR Workflow | Fulfilling a data-subject access/deletion/portability request end to end — GDPR 30-day / CCPA 45-day clocks. |
| DSAR record template | The per-request evidence record committed to compliance/dsar/. |
See also¶
- Data inventory (RoPA) —
compliance/data-inventory/, the register the DSAR workflow walks; gate:validate.py. - M4 Purview — data discovery/classification that reconciles against the register. M5 DLP — stops personal data leaving via M365. M6 enforces residency; M1/M2/M3 enforce encryption/TLS.
- The data-leak IR runbook — a DSAR is a request; an exposure is an incident. If a DSAR uncovers an exposure, open the incident path immediately.