Skip to content

Answer the data-protection review - #32

Merged
ronaldtse merged 1 commit into
mainfrom
fix/dpo-review
Aug 20, 2026
Merged

ronaldtse merged 1 commit into
mainfrom
fix/dpo-review

Conversation

@ronaldtse

Copy link
Copy Markdown
Contributor

Answer the data-protection review

A data-protection-officer review of the draft raised seven concerns
about personal data in public, append-only transparency structures;
all are answered, six normatively:

  • Log content minimization (new requirement with test): log leaves,
    proofs, and tree heads carry no directly identifying personal data;
    named-identity binding lives in access-controlled registers, with
    revocation and key rotation as the withdrawal mechanism.
  • Rectification: the log records issuance, not truth — corrections
    flow through superseding attestations and re-issuance, never edits
    (guidance on append-only structure and retention).
  • Data minimization: co-signature signer identity in public artifacts
    and passports is normatively a key fingerprint or pseudonym.
  • Linkability: schemes attesting individuals use rotating or
    purpose-bound keys or privacy-preserving credentials.
  • Storage limitation: retention bounded by purpose with scheme-defined
    deletion criteria for logs and ceremony transcripts.
  • Cross-border transfer: the deployment manifest documents mirror
    jurisdiction and transfer basis; schemes processing personal data
    define a privacy policy with lawful basis and information duties.

The registry is now 118 requirements and 118 tests; the new audit
gate passes.

A data-protection-officer review of the draft raised seven concerns
about personal data in public, append-only transparency structures;
all are answered, six normatively:

- Log content minimization (new requirement with test): log leaves,
  proofs, and tree heads carry no directly identifying personal data;
  named-identity binding lives in access-controlled registers, with
  revocation and key rotation as the withdrawal mechanism.
- Rectification: the log records issuance, not truth — corrections
  flow through superseding attestations and re-issuance, never edits
  (guidance on append-only structure and retention).
- Data minimization: co-signature signer identity in public artifacts
  and passports is normatively a key fingerprint or pseudonym.
- Linkability: schemes attesting individuals use rotating or
  purpose-bound keys or privacy-preserving credentials.
- Storage limitation: retention bounded by purpose with scheme-defined
  deletion criteria for logs and ceremony transcripts.
- Cross-border transfer: the deployment manifest documents mirror
  jurisdiction and transfer basis; schemes processing personal data
  define a privacy policy with lawful basis and information duties.

The registry is now 118 requirements and 118 tests; the new audit
gate passes.
@ronaldtse
ronaldtse merged commit 03ee29c into main Aug 20, 2026
3 checks passed
@ronaldtse
ronaldtse deleted the fix/dpo-review branch August 20, 2026 06:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant