Spec: personal-data catalog, compliance role, Overview and Data inventory #81

Merged
jcoffey-dev merged 2 commits from spec/personal-data-catalog into main 2026-09-28 13:05:02 +00:00
Owner

Phase 1 of the GDPR auditor foundation: docs/spec/features/personal-data-catalog.md. Investigation and design only; nothing is built until this is approved.

  • Source map of personal data (content, fork records, transport and reports, telemetry and logs, sign-in and network defence, spam and AI, external stores), each with categories, whose data, controlling settings, retention bound, location, scope, writing code and default.
  • Ten findings, among them: webhooks ignore levels and at defaults receive raw SMTP input; log files are never deleted; automatic bans never expire; some fork records outlive the account.
  • Sidecar catalog format, CI check, strip-report extension, inbuxa:DataInventory and inbuxa:InventorySnapshot, a Compliance Officer role, and the Compliance navigation.
  • Default profile with seven proposed new-install changes (none made), contradictions with the docs, and seven open questions.
Phase 1 of the GDPR auditor foundation: `docs/spec/features/personal-data-catalog.md`. Investigation and design only; nothing is built until this is approved. - Source map of personal data (content, fork records, transport and reports, telemetry and logs, sign-in and network defence, spam and AI, external stores), each with categories, whose data, controlling settings, retention bound, location, scope, writing code and default. - Ten findings, among them: webhooks ignore levels and at defaults receive raw SMTP input; log files are never deleted; automatic bans never expire; some fork records outlive the account. - Sidecar catalog format, CI check, strip-report extension, `inbuxa:DataInventory` and `inbuxa:InventorySnapshot`, a Compliance Officer role, and the Compliance navigation. - Default profile with seven proposed new-install changes (none made), contradictions with the docs, and seven open questions.
jcoffey-dev added 1 commit 2026-09-28 08:37:02 +00:00
Spec: personal-data catalog, compliance role, Overview and Data inventory
ci / fork-checks (pull_request) Successful in 50s
ci / build (pull_request) Successful in 11m33s
35cf3f405f
Phase 1 of the GDPR auditor foundation: the investigation and the
design, committed before anything is built (SPEC.md §3 rule 3).

It maps every place the server stores or sends personal data found
in the code at de275ba, each with its categories, whose data it is,
the settings that control it, what bounds its retention, where it
lives, whether it leaves the host, its scope and the code that writes
it, and the default in a new install. It proposes a sidecar catalog
(resources/privacy/catalog.toml), since the schema and registry code
are upstream's generated output with no generator here; a CI check
modeled on name-check.py; a strip-report section; a read-only
inventory method with dated snapshots; a Compliance Officer role; and
the Compliance navigation with Overview and Data inventory.

Findings worth reading on their own: webhooks ignore levels and, at
their defaults, receive every event including raw SMTP input; log
files are never deleted; automatic bans never expire; some of the
fork's records outlive the account; spam training keeps whole
messages for 180 days; traces are on in a new install; the spam
filter sends IPs, domains, hashed addresses and body digests to
third-party services by default.

Proposed default changes (new installs only) and seven open questions
are for John to decide. No default is changed.
jcoffey-dev added 1 commit 2026-09-28 12:57:28 +00:00
Spec: record John's answers to the personal-data catalog questions
ci / fork-checks (pull_request) Successful in 15s
ci / build (pull_request) Successful in 7m25s
a588a8aa7d
The sidecar catalog; the Compliance Officer places and releases holds;
the Tenant Compliance Officer is built now; shortening audit retention
is recorded and surfaced, not gated on a second person; all seven
new-install defaults, in Phase 3; the webhook finding fixed now as a
bug; snapshots kept as long as the audit log.
jcoffey-dev merged commit 85ea0c80e9 into main 2026-09-28 13:05:02 +00:00
jcoffey-dev deleted branch spec/personal-data-catalog 2026-09-28 13:05:02 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: inbuxa/inbuxa-server#81