The system's framework, proven. No solutions.md before submitting.
Exercise 1 — The legal bases
- Classify each datum of YOUR TicketFlow with its legal basis (contract/consent/legitimate interest/legal obligation): email, optional phone, purchase history, login IP, the analytics cookie, the org's profile photo. The map's table with the basis column.
- The revocable consent: implement the opt-in's evidence: date + version of the accepted text (§4's "they said yes to THIS version") + the revocation with audit. Test: consent → revoke → marketing stops touching them (the flag or the filter? decide and document).
- The money's exception: the user requests total erasure: what gets deleted and what gets ANONYMIZED (the ticket's email? the ledger?)? Implement 23's extended flow: the profile's deletion + the history's anonymization preserving the invoicing. The test: the later export contains NO PII but 08's ledger still balances.
Exercise 2 — The Art. 30 map
- Complete the map (§2) for YOUR system: each table of 00b with datum/where/purpose/basis/retention/access. The unclassified tables: 45's log (PII? basis?)? 38's cache with profile?
- PII in the log and in the cache: verify (45/38) that the log carries identifiers and the profile's cache has per-user purge: the compliance test: a grep/scan of the cache keys and the sample logs WITHOUT email/phone patterns. Implement the guard.
- The document:
docs/compliance/mapa-datos.md(48) with the full table + the quarterly review date + the owner. The doc the DPO reads first.
Exercise 3 — The SOC 2 evidences
- The system's reports: write the 3 evidence queries (§3): the access report (who escalated permissions this quarter?), the secrets report (when did they rotate and who?), the changes report (which PRs reached prod without review? — does 41's pipeline allow it? verify). Each one as a repo query/script.
- The change chain: the control's test: try (in lab) to reach prod without a PR (direct push? 43's kubectl?): what blocks it (branch protection? the pipeline?)? Document the change controls with their evidence.
- The honest gap: which §3 control do you NOT have (the DR drill? the quarterly access review?)? Create the issue with owner/date (49) — the documented gap is a control on its way; the hidden one is the auditor's finding.
Exercise 4 — The audit log and the breach
- The auditor's queries (§4): implement them as scripts/admin endpoint (with 21's role): "who saw/exported user X's data?", "who changed event Y's price?", "who downloaded the export this month?". Each query with its test (33: the right admin runs it, the other gets 403).
- Retention as a job (31): the automatic purge of the audit log >12 months (cold) and of revoked marketing data. The test with FakeClock: the expiring datum gets purged with its audit row ("purged by retention").
- The breach runbook (72 h): write
docs/compliance/runbook-brecha.md: the typical chronology (detect/scope/contain/notify/learn) with each step's commands (46's alerts, 47's protocol, the notification's template) and the thresholds of who gets notified (regulator? affected? the documented decision).
Exercise 5 — The internal DPO
- Compliance's linter: the test failing if a free-text field (a new CharField/email?) enters a map table without basis/retention annotation (the model's Meta with
data_classification = {...}?). Implement the schema guard. - Retention and export as a system: 31's jobs (exercise 4's purge) + 23's export + the audit of each execution: the "internal DPO" in an ASCII diagram of the automatic compliance processes with their evidences.
- The module's close: TicketFlow's compliance checklist (the 10 items: legal bases, map, retention, rights, breach, evidences...) with each one's real status (/pending/issue). The self-assessment document the auditor (or 57) asks for.
Submit
Paste the map with legal bases, the 3 SOC 2 evidences, the breach runbook and the final checklist. Next: Lesson 57 — Capstone project.