Agentic AI Atlasby a5c.ai
OverviewWikiGraphFor AgentsEdgesSearchWorkspace
/
GitHubDocsDiscord
i.2Wiki
Agentic AI Atlas · Data Privacy Compliance (Library)
library/data-privacy-compliancea5c.ai
Search the atlas/
Wiki · linked records

Article and nearby pages

I.Current articlepp. 1 - 1
accessibility (Library)Aerospace Engineering Specialization (Library)AI Agents and Conversational AI Specialization (Library)Algorithms and Optimization Specialization (Library)Arts and Culture Specialization (Library)ATDD/TDD Methodology (Library)
II.Documented nodesrefs · 1
specialization:data-privacy-compliance
I.
Wiki article

library/data-privacy-compliance

Reading · 8 min

Data Privacy Compliance (Library) reference

Privacy operations lifecycle for DSAR (data-subject access request), erasure, and DPIA work: intake and identity verification, kip-reconciled data mapping, parallel multi-system retrieval, exemption analysis with mandatory legal bases, policy-gated deletion and disclosure, and deadline-audited closure — all inside statutory clocks. This specialization complements security-compliance and supersedes nothing.

Page nodewiki/library/data-privacy-compliance.mdNearby pages · 135Documents · 1

Continue reading

Nearby pages in the same section.

accessibility (Library)Aerospace Engineering Specialization (Library)AI Agents and Conversational AI Specialization (Library)Algorithms and Optimization Specialization (Library)Arts and Culture Specialization (Library)ATDD/TDD Methodology (Library)authoring (Library)AutoMaker (Library)Automotive Engineering Specialization (Library)Backend Development (Library)BDD/Specification by Example (Library)Bioinformatics and Genomics Specialization (Library)Biomedical Engineering Specialization (Library)BMAD Method (Library)business/ (folded) (Library)Business Analysis and Consulting (Library)Business Strategy and Operations (Library)Business Strategy Specialization (Library)CC10X Methodology (Library)CCPM - Claude Code PM Methodology (Library)Chemical Engineering Specialization (Library)Civil Engineering Specialization (Library)ClaudeKit Methodology (Library)Cleanroom Software Engineering (Library)CLI and MCP Development Specialization (Library)Code Migration and Modernization Specialization (Library)COG Second Brain (Library)collaboration (Library)common-utilities (Library)Communication specialization (Library)Composition: Aerospace Flight Control (Waterfall + V-Model + Cleanroom + inline Formal Verification) (Library)Composition: Legacy Modernization (Event Storming + DDD + FDD + Strangler Fig + RUP) (Library)Composition: Open Source Data-Validation Framework (TDD + BDD + Kanban + XP + Continuous Deployment) (Library)Composition: Regulated Greenfield (V-Model + DDD + Cleanroom + Waterfall) (Library)Composition: SaaS Analytics Dashboard (JTBD + Impact Mapping + Spec-Kit + Kanban + XP) (Library)Composition: Smart Product Recommendations (DDD + Hypothesis-Driven Development + BDD + Kanban) (Library)Composition: Startup MVP (Shape Up + Example Mapping + TDD + Scrum) (Library)Computer Science Specialization (Library)Cryptography and Blockchain Development Specialization (Library)Customer Experience and Support Specialization (Library)customer-support (Library)Data Engineering, Analytics, and BI Specialization (Library)Data Science and Machine Learning Specialization (Library)Intelligence, Decision Support and Decision Making (Library)Desktop Product Development Specialization (Library)developer-relations (Library)DevOps, SRE, and Platform Engineering Specialization (Library)Digital Marketing and Content Strategy Specialization (Library)Domain-Driven Design (DDD) Methodology (Library)Double Diamond Methodology (Library)Education and Learning Specialization (Library)Electrical Engineering Specialization (Library)Embedded Systems Engineering Specialization (Library)Entrepreneurship and Startup Processes (Library)Environmental Engineering Specialization (Library)Event Storming (Library)Everything Claude Code Methodology (Library)Example Mapping Methodology (Library)Extreme Programming (XP) (Library)Feature-Driven Development (FDD) (Library)Finance, Accounting, and Economics Specialization (Library)FPGA Programming and Hardware Description Specialization (Library)Game Product Development Specialization (Library)Gas Town Methodology (Library)GPU Programming and Parallel Computing (Library)GSD-Adapted Workflows for Babysitter SDK (Library)Healthcare and Medical Management Specialization (Library)Human Resources and People Operations Specialization (Library)Humanities and Anthropology Specialization (Library)Hypothesis-Driven Development (Library)Impact Mapping Methodology (Library)Incident Management (Library)Industrial Engineering Specialization (Library)internationalization (Library)Jobs to Be Done (JTBD) Methodology (Library)Kanban (Library)Knowledge Management (Library)Legal and Compliance Specialization (Library)Logistics and Operations Specialization (Library)Maestro App Factory (Library)Marketing and Brand Management Specialization (Library)Materials Science Specialization (Library)Mathematics Specialization (Library)Mechanical Engineering Specialization (Library)media (Library)Meta Specialization - Process, Skill, and Agent Creation (Library)Metaswarm Methodology (Library)MLOps (Library)Mobile Product Development Specialization (Library)Nanotechnology Specialization (Library)Network Programming and Protocols Specialization (Library)Observability specialization (Library)Enhanced Ontology-Driven Development (ODD) Methodology (Library)Operations Management Specialization (Library)Performance Optimization and Profiling Specialization (Library)Philosophy and Theology Specialization (Library)Physics Specialization (Library)Pilot Shell Methodology for Babysitter SDK (Library)Planning with Files (Library)Procurement — business domain specialization (Library)Product Management and Product Strategy Specialization (Library)Production contract (Library)Programming Languages and Compilers Development Specialization (Library)Project Management and Leadership Specialization (Library)Public Relations and Communications Specialization (Library)QA, Testing, and Test Automation (Library)Quantum Computing Specialization (Library)Release Engineering (Library)Research Specialization (Library)Robotics and Simulation Engineering Specialization (Library)RPIKit Methodology (Library)Ruflo Methodology (Library)RUP (Rational Unified Process) (Library)Sales and Business Development Specialization (Library)Scientific Discovery and Problem Solving Specialization (Library)Scrum (Library)SDK, Platform, and Systems Development (Library)Security, Compliance, and Risk Management Specialization (Library)Security Research and Vulnerability Analysis Specialization (Library)Shape Up (Library)Shared (Cross-Domain Assets) (Library)Social Sciences Specialization (Library)Software Architecture and Design Patterns Specialization (Library)sourcing/ (folded) (Library)Spec Kit Methodology (Library)Spiral Model (Library)Superpowers Extended Methodology (Library)Supply Chain Management Specialization (Library)Technical Documentation Specialization (Library)Travel (Curated-Dataset + SQL-Tool Pattern) (Library)UX/UI Design and User Experience Specialization (Library)V-Model Methodology (Library)Venture Capital and Investment Due Diligence Specialization (Library)Waterfall Methodology (Library)Web Product Development Specialization (Library)

Documented graph nodes

Records linked directly from this page’s Page node.

specialization:data-privacy-compliance

Data Privacy Compliance

Privacy operations lifecycle for DSAR (data-subject access request), erasure, and DPIA work: intake and identity verification, kip-reconciled data mapping, parallel multi-system retrieval, exemption analysis with mandatory legal bases, policy-gated deletion and disclosure, and deadline-audited closure — all inside statutory clocks. This specialization **complements** security-compliance and supersedes nothing.

Use it when a data-subject request arrives (access, erasure, rectification, portability), when an erasure demands verified deletion across systems, or when a request surfaces new high-risk processing that needs a DPIA signed off.

Statutory clocks

Clocks are **frozen consts, not inputs** — there is deliberately no override knob. A statute is not configurable.

ClockDurationLegal basisStarts from
dsar30 daysGDPR Art 12(3) / CCPA 1798.130**RECEIPT** (request.receivedAt), not verification
breach72 hoursGDPR Art 33(1)breach-indicator detection at intake

The DSAR clock is started by the **orchestrator** the moment the process runs — before classification finishes, because the statute does not wait. If intake reports non-empty breachIndicators, a second 72-hour ledger clock opens and the run records a composition directive to run specializations/domains/business/legal/data-breach-response **by name** — this process never absorbs regulator notification.

Deadline-escalation map

Zone computed by deadlineZone(nowMs, clockStartMs, deadlineMs) from the remaining/total ratio: **comfortable** > 0.5, **warning** > 0.25, **critical** > 0, **breached** <= 0. Throws on non-finite inputs or a deadline at/before the clock start — no fallback zone.

DEADLINE_ESCALATION (verbatim — the frozen const is the implementation):

Actioncomfortablewarningcriticalbreached
data-deletiondpodpoprivacy-counselprivacy-counsel
disclosure-responsedpodpoprivacy-counselprivacy-counsel
dpia-signoffprivacy-counselprivacy-counselprivacy-counselprivacy-counsel

dpia-signoff is not clock-driven; its row is kept total so lookups never miss. Lookups go through deadlineExpert(actionId, zone), which **throws** on unknown actions and unknown zones — the exact analog of incident-lifecycle routingExpert(); no default expert exists.

Policy-gated actions

Convention: **breakpointId = actionId**, expert from deadlineExpert(actionId, currentZone()), tags ['policy-gated','privacy','dsar'|'dpia', <zone>], strategy single, **never auto-approved** (no autoApproveAfterN, no presentAlwaysApprove). Any harness-level auto-approval is surfaced by recordGate() into the always-present autoApprovals[] output — fail-closed provenance, nothing auto-approves silently.

actionIdWhat it gatesRaised in
data-deletionIrreversible deletion of personal dataP6, erasure branch only; one bounded re-plan round; second rejection halts with nothing deleted
disclosure-responseSending the disclosure package **or denial letter** to the data subjectP10, both outcomes; one bounded revise-and-re-gate round; unapproved -> withheld, fail closed
dpia-signoffApproving the privacy impact assessmentP9, only when dpiaRequired or inputs.dpiaContext

Non-policy breakpoints: dpc.identity-verification.unverified (P2, only on failed verification — genuinely blocking) and the combinator-owned dpc.dsar-completeness.gate-escalation (only on gate exhaustion).

Lifecycle walkthrough (P0–P11)

  • **P0 — kip recall** (kind data-privacy): data-map/system-of-record facts and DSAR precedents for the subject + jurisdiction, threaded into intake and the data-map refresh.
  • **P1 — DSAR intake + clock start**: orchestrator starts the 30-day clock from request.receivedAt; assertRequestType validates the classification; non-dsar exits early before verification or any gate; breach indicators open the 72-hour clock + composition directive.
  • **P2 — identity verification (fail-closed)**: failed verification raises the unverified breakpoint; rejected -> run refused with **closure audit still executed** (a refusal is still deadline-audited); approved -> recorded as an identity bypass that forces success:false.
  • **P3 — data-map refresh**: kip-recalled map reconciled against the live inventory (seeded from data-mapping-inventory.js discovery/classification/system-inventory slices). **Zero mapped systems throws** — there is no fallback system list.
  • **P4 — parallel multi-system retrieval**: one dpc.system-retrieval task per mapped system via ctx.parallel.all; the orchestrator diffs results against the map to compute allSystemsSearched (ground truth for the coverage critic).
  • **P5 — exemption analysis + branch assembly**: every withheld item must cite instrument + article + rationale (uncited withholding is schema-invalid). Access/rectification/portability -> disclosure package compiled (an all-withheld outcome compiles a **denial letter** riding the same schema and gates); erasure -> deletion plan whose every action carries the exact verificationQuery the gate later executes.
  • **P6 — data-deletion gate** (erasure only): never auto-approves; one re-plan round; second rejection returns with **nothing deleted** — the executor has no other invocation site.
  • **P7 — deletion execution**: only inside the approved === true branch; per-system outcomes reported honestly, ledgered by the orchestrator.
  • **P8 — adversarial completeness-and-exemption gate** (dpc.dsar-completeness): coverage-critic + exemption-critic, plus deletion-verification-critic on erasure, which **executes every verificationQuery** and requires zero records back. Nothing leaves until this gate passes (or the owner accepts via escalation).
  • **P9 — dpia-signoff gate** (conditional): DPIA drafted to artifactsDir, signed off by privacy-counsel at every zone; rejection blocks closure success only when the DPIA need came from the request's own processing.
  • **P10 — disclosure-response gate -> delivery**: both disclosure and denial ride the same gate; approved -> the package is delivered **verbatim** with a concrete messageRef; unapproved after one revise round -> withheld, recorded, fail closed.
  • **P11 — deadline-audited closure + kip assert**: dpc.closure-audit executes the deadline arithmetic against the orchestrator ledger; kip assert writes updated data-map facts, the DSAR precedent, and deletion outcomes.

Composition seeds

  • `domains/business/legal/data-mapping-inventory.js` — **folded slice** (composition, NOT supersedes): discovery/classification/system-inventory folded into dpc.data-map-refresh.
  • `domains/business/legal/data-breach-response.js` — **composed by name** when breachIndicators fire the 72-hour clock; regulator notification stays in that process.

Module table — `dsar-lifecycle.js` exports

ExportKindPurpose
process(inputs, ctx)orchestratorThe DSAR lifecycle, phases P0–P11
STATUTORY_CLOCKSfrozen const30-day DSAR / 72-hour breach clocks with legal bases
REQUEST_TYPESfrozen const['access','erasure','rectification','portability']
IDENTITY_VERIFICATION_METHODSfrozen constAllowed verification methods
DEADLINE_ZONESfrozen const['comfortable','warning','critical','breached']
DEADLINE_ESCALATIONfrozen constPer-zone expert routing (lookup via deadlineExpert)
deadlineExpert(actionId, zone)helperEscalation lookup — **throws** on unknown action/zone (no fallback expert)
deadlineZone(nowMs, clockStartMs, deadlineMs)helperZone computation — **throws** on non-finite inputs or deadline <= start
assertRequestType(value, source)helper**Throws** on unknown request types; 'non-dsar' passes as a classification outcome
dsarIntakeTaskagent taskdpc.dsar-intake — classification, dsarId mint, breach indicators
identityVerificationTaskagent taskdpc.identity-verification — executed checks, fail-closed
dataMapRefreshTaskagent taskdpc.data-map-refresh — kip-reconciled inventory
systemRetrievalTaskagent taskdpc.system-retrieval — per-system fan-out unit
exemptionAnalysisTaskagent taskdpc.exemption-analysis — per-item legal bases
responseCompilationTaskagent taskdpc.response-compilation — draft only, denial included
deletionPlanTaskagent taskdpc.deletion-plan — plan only, verificationQuery per action
deletionExecutionTaskagent taskdpc.deletion-execution — only after its gate approves
dpiaDraftTaskagent taskdpc.dpia-draft — DPIA markdown
responseDeliveryTaskagent taskdpc.response-delivery — only after its gate approves
closureAuditTaskagent taskdpc.closure-audit — executed deadline arithmetic

Gate combinators (routedBreakpoint, adversarialGate, kipRecall, kipAssert) are imported from `../common-utilities/routed-gate-combinators.js`, not redefined.

Inputs / outputs reference

**Inputs**: request { receivedAt (ISO, REQUIRED — starts the statutory clock), channel, subject { name, email, identifiers? }, rawText }, requestTypeOverride?, jurisdiction ('gdpr'|'ccpa'|string, REQUIRED), dpiaContext?, maxFixAttempts? (default 2), kipEnabled? (default true), kipDir? (default .a5c/kip), kipModel? (default sonnet), artifactsDir?. Missing request.receivedAt/subject **throws** — the process refuses to guess when a statutory clock started.

**Outputs**: success, dsarId, requestType, identityVerified, clock { startedAt, deadlineAt, zoneAtClosure, breached, ledger[] }, dataMap { systems, discrepancies, dpiaRequired }, retrieval { perSystem[], allSystemsSearched }, withheld[], deletion { plan, executed, verified } | null, disclosure { sent, deliveredAt, messageRef } | null, dpia { required, path, signedOff } | null, completenessGate { passed, attempts, escalated, issues }, autoApprovals[] (ALWAYS present — fail-closed provenance), kipFactsAsserted, slaBreaches[], artifacts[], metadata { processId, runId, clockLedger, breakpointsHit }.

Hard rules

  • **No fallbacks**: assertRequestType, deadlineZone, and deadlineExpert all throw on unknown values; an empty data map throws; missing request.receivedAt throws. There is no default expert, zone, request type, or system list anywhere.
  • **Fail-closed gates**: deletion and disclosure never execute via any ungated path. dpc.deletion-execution and dpc.response-delivery are invoked only inside the approved === true branches of their gates; no retry, recovery, or closure path calls them otherwise.
  • **Style-A agent-only**: every task is kind: 'agent' (zero kind: 'shell'), with per-effect io paths and labels, and every evidence-carrying output schema declares evidence { type: 'array', minItems: 1 }.
  • **Orchestrator-owned clock ledger**: the ledger is accumulated in the orchestrator, never inside agents, so the deadline auditor and gate critics diff against ground truth the agents cannot rewrite.

Validation

ESM import check from the repo root (resolves the ../common-utilities import and @a5c-ai/babysitter-sdk):

bash
node --input-type=module -e "await import('./library/specializations/data-privacy-compliance/dsar-lifecycle.js')"

Then confirm the exported consts are frozen and the lookups throw:

bash
node --input-type=module -e "
const m = await import('./library/specializations/data-privacy-compliance/dsar-lifecycle.js');
if (!Object.isFrozen(m.STATUTORY_CLOCKS) || !Object.isFrozen(m.DEADLINE_ESCALATION)) throw new Error('consts not frozen');
try { m.deadlineExpert('data-deletion', 'nope'); throw new Error('should have thrown'); } catch (e) { if (!/unknown deadline zone/.test(e.message)) throw e; }
try { m.assertRequestType('bogus', 'test'); throw new Error('should have thrown'); } catch (e) { if (!/Unknown requestType/.test(e.message)) throw e; }
console.log('ok');
"

Trail

Wiki

Library

Data Privacy Compliance (Library)

Continue reading

accessibility (Library)
Aerospace Engineering Specialization (Library)
AI Agents and Conversational AI Specialization (Library)
Algorithms and Optimization Specialization (Library)
Arts and Culture Specialization (Library)
ATDD/TDD Methodology (Library)
authoring (Library)
AutoMaker (Library)

Page record

Open node ledger

wiki/library/data-privacy-compliance.md

Documents

specialization:data-privacy-compliance