Files
magnus919_agent-skills/privacy-engineering/templates/data-lifecycle-record.md
T
Magnus HedemarkGitHubusername <username>factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
6f429a91b1 feat(privacy-engineering): add privacy-engineering skill (#202) (#225)
Add privacy-engineering skill that translates privacy principles and legal
requirements into verifiable engineering artifacts: data-lifecycle records,
privacy acceptance criteria, data-flow and access maps, retention/deletion
verification plans, and privacy change reviews.

Covers seven privacy dimensions (purpose, lifecycle/retention, access,
deletion, tenant/isolation, residency, consent) as structured concerns.
Addresses agent traces (LLM conversation logs, tool-call history) and
product analytics telemetry with privacy-specific guidance. Routes legal
interpretation to legal-strategy and security implementation to
secure-software-engineering.

Includes:
- SKILL.md with Loading Guide, file map, and routing boundaries
- README.md with 5 required sections
- references/discovery-brief.md comparing 10 adjacent skills
- 5 templates for expected artifacts
- evals/evals.json with 6 cases covering all mandatory scenarios
- Updated root README catalog, skill-triggers, and generated catalogs

Co-authored-by: username <username>
Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
2026-08-02 18:42:49 -04:00

2.3 KiB

Data-Lifecycle Record

Template for tracing each data category from collection through deletion across all stores, caches, backups, replicas, logs, and derived datasets.

System / feature context

Field Value
System / feature name
Data categories in scope
Regulatory / policy drivers
Record owner
Last updated

Data categories and classification

Data category Classification Examples Sensitivity rationale
Public / Internal / Confidential / Restricted (PII)

Purpose declaration

Data category Purpose Legal basis (if applicable) Purpose review cadence

Full lifecycle trace

For each data category, trace through every stage. A lifecycle that ends at "primary database" is incomplete.

Lifecycle stage Location / store Retention at this stage Access at this stage Deletion mechanism Deletion verified?
Collection N/A N/A N/A
Processing
Primary storage
Caches
Replicas (read)
Backups
Logs
Analytics / derived
Archives
Third-party / subprocessor

Deletion cascade

Trigger event Data categories affected Cascade order SLA per store Verification method
Account closure
Retention expiry
Consent revocation
Deletion request (DSAR)

Retention clock

Data category Retention period Clock start trigger Clock stop trigger Rationale

Access map

Data category Role / system Access type (read/write/delete) Access condition Access logged?

Residency

Data category Residency constraint Current region(s) Compliance evidence
Consent state Data collected Retention behavior Deletion behavior
Pre-consent
Post-consent
Post-revocation

Gaps and follow-up

Gap Severity Owner Due date Closure evidence