Skip to content

[M0-D01 follow-up] Define the Privacy personal-information lifecycle backlog #349

Description

@smiggleworth

Note

Follow-up discovery issue created 2026-09-22 when M0-D01 #58 closed with Privacy in scope for the first engagement.

Decision needed

The Privacy category (P-series criteria) needs a personal-information lifecycle the current backlog does not model: notice, choice and consent, collection, use/retention/disposal, access, disclosure to third parties, quality, and monitoring and enforcement. Define that backlog before the product claims Privacy support.

Questions to answer

  • Inventory which Privacy criteria need product records beyond the existing control, evidence, information-asset, and data-flow model.
  • Define the minimum personal-information entities and relationships (for example personal-information category, processing purpose, notice version, consent or lawful basis, data-subject request) as additions to the canonical entity model.
  • Decide which of those are governed records versus referenced source-system facts.
  • Draft the resulting stories with milestone and priority.

Rule until this closes

A boundary may select privacy, but no readiness, package, or export may state that the product supports the Privacy category's lifecycle requirements. Privacy criteria can still be mapped to ordinary controls.

Involve

Product owner, compliance lead, privacy or legal owner, readiness advisor.

Done when

  • The decision, rationale, owner, and date are recorded in this issue.
  • The Privacy lifecycle stories exist and the canonical model additions are proposed.
  • The Type I package story reflects the rule above.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:productProduct definition and experiencepriority:P1Important after the critical path is usabletype:discoveryProduct or domain decision required before implementation

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions