Curated, product-agnostic snapshot of the post-story-04 tree: demo content deleted, auth-only reference feature, web-next shell, all gates green. Product-specific docs, ADRs 027-029, PRDs/epics/archive, editor library traces, and product naming are curated out; generic template repairs (coverage provider devDeps, root test:coverage script, live lint fixes, root-only release-please) are kept. See TEMPLATE.md for provenance, curation list, and usage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
34 lines
1.5 KiB
Markdown
34 lines
1.5 KiB
Markdown
# @repo/core-dsr
|
||
|
||
Optional core package providing GDPR Data Subject Rights (DSR) interfaces and implementations. Scaffold via `pnpm turbo gen core-package dsr`.
|
||
|
||
## Structure
|
||
|
||
```
|
||
src/
|
||
data-export.interface.ts # IDataExport — exportSubjectData
|
||
data-delete.interface.ts # IDataDelete — deleteSubjectData
|
||
data-rectify.interface.ts # IDataRectify — updateSubjectField
|
||
processing-restriction.interface.ts # IProcessingRestriction — setRestriction, isRestricted
|
||
dsr-types.ts # UserDataBundle, DeletionCertificate, DSR value types
|
||
contexts/
|
||
user-data.jsonld # schema.org JSON-LD @context
|
||
index.ts # Barrel export
|
||
```
|
||
|
||
## Design
|
||
|
||
Four interfaces map directly to GDPR Articles 15–18 + 20:
|
||
|
||
- `IDataExport` (Art. 15/20) — export a subject's data as `UserDataBundle`
|
||
- `IDataDelete` (Art. 17) — soft-delete or cascade-hard-delete subject data; returns `DeletionCertificate`
|
||
- `IDataRectify` (Art. 16) — update a specific field for a subject
|
||
- `IProcessingRestriction` (Art. 18) — toggle and read the processing restriction flag
|
||
|
||
Implementations walk `custom.pii`-tagged fields and `custom.subject`-linked collections. Row semantics:
|
||
|
||
- `kind: "self" | "owner"` → directly owned by the subject (export full; delete hard or soft)
|
||
- `kind: "reference"` → references the subject from another entity (export redacted; redact link on delete)
|
||
|
||
See `docs/architecture/agent-first-workflow-and-conformance.md` for the DI conventions.
|