Files
agentic-dev/docs/work/epics/dsr-consent-and-cookie-banner/_epic.md

2.1 KiB
Raw Blame History

id, prd, title, type, status, features, created, updated
id prd title type status features created updated
dsr-consent-and-cookie-banner docs/work/prds/dsr-consent-and-cookie-banner.prd.md DSR + consent abstraction + cookie consent banner — Epic B of ADR-025 epic in-progress
core-shared
core-consent
core-dsr
core-ui
core-eslint
core-testing
core-api
auth
2026-05-19T12:00:00Z 2026-05-19T11:54:41.015Z

Goal

Ship the user-rights surface end-to-end: DSR endpoints that walk Epic A's PII tags to export/delete/rectify/restrict any subject's data, per-use-case consent gates with audit-logged proof, and a compliant cookie consent banner with EU-prominence defaults.

Why

Epic A delivered declarative PII inventory + retention + sub-processors. Epic B closes the remaining gaps: GDPR Arts. 1518 + 20 DSR endpoints, Art. 7 demonstrable consent with structural lint enforcement, and a CNIL-compliant cookie consent banner that downstream consumers can drop in without forking legal-compliance logic.

Stories