Make the site GDPR-compliant with a plugin of its own #297
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#297
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Postulo keeps a lot of personal data on a person's behalf -- contacts and their phone numbers,
addresses, documents, CVs, letters, everything a capture brings in. On a self-hosted instance the
operator is the controller for everything in the database, and where the instance is in the EU, or
holds data of EU data subjects, GDPR applies to it. The site currently has no built-in way to meet
any of that: nothing in the repository names the regulation yet, and this is the issue that changes
that.
The account holder's own rights are already met -- the account archive carries every row and file
the account owns, and account deletion removes them. What is missing is the rest: the data the site
keeps about other people, and the duties that sit with the instance itself.
The shape
A plugin of the internal kind -- one that ships in the box, in the company of the other feature
plugins (several phone numbers, several email addresses, employer structure) -- declared as a
FeaturePlugin, registered underpostulo.features, with its own manifest and its own locale, andimporting nothing but
postulo.plugins.api. As with every feature, it is switched on and off, andit governs what the site offers and uses, not what the database holds.
What it offers
holds on one person -- rows, documents, files, and every plugin's own rows -- with the archive's
discipline: what a plugin owns and cannot answer for is named as
not_carriedrather thansilently dropped. This is the answer to "what do you have on me?".
documents and files, and each plugin's own rows for them -- the same guarantee the uninstall
machinery already demands of a plugin before it may go. Off never deletes; this does, and it says
what it deleted.
would touch before anything is deleted.
receives it. Much of this is already derivable -- every installed plugin, and every notifier,
outbox, store and sync, is a purpose or a recipient in its own right -- so the page is drawn from
the registry and the connections, not from a second list to keep in sync.
Not in scope (yet)
The account holder's own data stays with the archive and the account deletion that already exist.
The operator's legal bases and the legal opinion are the operator's, not the plugin's.
Done when
src/postulo/plugins/, with its manifest and locale, and isfound by the registry like every other.
tests/test_plugin_surface.pypasses: it imports the surface only, and owns its catalogues.retention dry run deletes nothing.