Module 12 · Enterprise level (capstone)

Lesson 56 — Compliance

GDPR, audit logs and SOC 2 / ISO 27001 at a glance.

Published
In this lesson
  1. Exercise 1 — The legal bases
  2. Exercise 2 — The Art. 30 map
  3. Exercise 3 — The SOC 2 evidences
  4. Exercise 4 — The audit log and the breach
  5. Exercise 5 — The internal DPO
  6. Submit

The system's framework, proven. No solutions.md before submitting.

  1. Classify each datum of YOUR TicketFlow with its legal basis (contract/consent/legitimate interest/legal obligation): email, optional phone, purchase history, login IP, the analytics cookie, the org's profile photo. The map's table with the basis column.
  2. The revocable consent: implement the opt-in's evidence: date + version of the accepted text (§4's "they said yes to THIS version") + the revocation with audit. Test: consent → revoke → marketing stops touching them (the flag or the filter? decide and document).
  3. The money's exception: the user requests total erasure: what gets deleted and what gets ANONYMIZED (the ticket's email? the ledger?)? Implement 23's extended flow: the profile's deletion + the history's anonymization preserving the invoicing. The test: the later export contains NO PII but 08's ledger still balances.

Exercise 2 — The Art. 30 map

  1. Complete the map (§2) for YOUR system: each table of 00b with datum/where/purpose/basis/retention/access. The unclassified tables: 45's log (PII? basis?)? 38's cache with profile?
  2. PII in the log and in the cache: verify (45/38) that the log carries identifiers and the profile's cache has per-user purge: the compliance test: a grep/scan of the cache keys and the sample logs WITHOUT email/phone patterns. Implement the guard.
  3. The document: docs/compliance/mapa-datos.md (48) with the full table + the quarterly review date + the owner. The doc the DPO reads first.

Exercise 3 — The SOC 2 evidences

  1. The system's reports: write the 3 evidence queries (§3): the access report (who escalated permissions this quarter?), the secrets report (when did they rotate and who?), the changes report (which PRs reached prod without review? — does 41's pipeline allow it? verify). Each one as a repo query/script.
  2. The change chain: the control's test: try (in lab) to reach prod without a PR (direct push? 43's kubectl?): what blocks it (branch protection? the pipeline?)? Document the change controls with their evidence.
  3. The honest gap: which §3 control do you NOT have (the DR drill? the quarterly access review?)? Create the issue with owner/date (49) — the documented gap is a control on its way; the hidden one is the auditor's finding.

Exercise 4 — The audit log and the breach

  1. The auditor's queries (§4): implement them as scripts/admin endpoint (with 21's role): "who saw/exported user X's data?", "who changed event Y's price?", "who downloaded the export this month?". Each query with its test (33: the right admin runs it, the other gets 403).
  2. Retention as a job (31): the automatic purge of the audit log >12 months (cold) and of revoked marketing data. The test with FakeClock: the expiring datum gets purged with its audit row ("purged by retention").
  3. The breach runbook (72 h): write docs/compliance/runbook-brecha.md: the typical chronology (detect/scope/contain/notify/learn) with each step's commands (46's alerts, 47's protocol, the notification's template) and the thresholds of who gets notified (regulator? affected? the documented decision).

Exercise 5 — The internal DPO

  1. Compliance's linter: the test failing if a free-text field (a new CharField/email?) enters a map table without basis/retention annotation (the model's Meta with data_classification = {...}?). Implement the schema guard.
  2. Retention and export as a system: 31's jobs (exercise 4's purge) + 23's export + the audit of each execution: the "internal DPO" in an ASCII diagram of the automatic compliance processes with their evidences.
  3. The module's close: TicketFlow's compliance checklist (the 10 items: legal bases, map, retention, rights, breach, evidences...) with each one's real status (/pending/issue). The self-assessment document the auditor (or 57) asks for.

Submit

Paste the map with legal bases, the 3 SOC 2 evidences, the breach runbook and the final checklist. Next: Lesson 57 — Capstone project.