Add privacy policy page - #65
Conversation
Add OSBR privacy policy covering authentication, data handling, third-party services, and user rights. Update sidebar config to include the new page under Policies. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…ness, and user decisions Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Split into 4 pages: summary, company practices, PDPA compliance, systems - Separate WHAT (company) from HOW (systems) for service user data - Frame client data handling as governed by engagement agreements - Remove false DNT compliance claim - Set handbook GA4 retention to 2 months (verified default) - Confirm 30-day auth log retention (Cloud Logging default) - Soften over-commitments: manage gaps, don't fill them - Update VitePress sidebar with nested navigation Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Reduce outstanding lawyer review scope by researching and addressing items that can be resolved with public legal sources: - privacy-pdpa.md §8: cite the 2013 Class of Data Users Order and 2016 Amendment by P.U.(A) reference; confirm OSBR does not fall within any designated class. - privacy-pdpa.md §9: new Data Protection Officer section with PDPA Amendment Act 2024 thresholds (20,000 / 10,000 / systematic monitoring); note OSBR does not meet thresholds. - privacy-pdpa.md §10: new Data Breach Notification section with the 72-hour statutory timeline and 2-year register requirement. - privacy-company.md §6-3: add retention statement for meeting recordings where they occur. - privacy-company.md §8-9: split sensitive personal data into a dedicated section covering all five Section 4 categories (including biometric data added by the 2024 Amendment); move general exclusions into §9. - privacy-policy.md §8: add data portability right under the PDPA Amendment Act 2024. - privacy-policy.md §11: update breach notification language to reference the statutory timeframe and link to the PDPA page.
3 items: - Add 7-day data subject notification timeline (§10), clarifying that the countdown starts from notification to the Commissioner. - Add [Act A1727] full citation on first substantive reference to the Personal Data Protection (Amendment) Act 2024 (§9). - Add breach register record retention row to the §5 retention table (at least 2 years from notification to the Commissioner).
|
Reviewed 2026-07-03 12:49 JST. This PR appears to fully satisfy the acceptance criteria of #64 — no scope gap found:
The implementation looks complete and ready to close/merge. Before merging, the author checklist still needs attention: the Self Review and Evidence checkboxes in the PR body are unchecked and section 5 (Evidence) is empty — worth attaching a screenshot of the rendered pages / passing build to satisfy the repo's review-request checklist. 🤖 auto-posted by sn0wm1ku/ghDuty · co-authored by Claude (claude-opus-4-8) |
|
Closing as duplicated by #91, which shipped the dedicated Privacy Policy page (grounded on Malaysia's PDPA 2010 + 2024 amendment, with Japan's APPI and the EU/US baseline layered on) together with the engineering-side Data Protection standard. 🤖 Posted by Claude Code |
1. Target
2. Specification / Test Plan
(Text here)
3. Additional Instructions / Notes for Shipping (optional)
N/A
4. Check before Review Request
5. Evidence
(Attach here before request review)