Skip to Content
User guideWorked examplesGDPR complianceOverview

GDPR compliance

The GDPR data-subject rights obligations — export an account’s personal data, erase it on a confirmed request, cancel a request that has not been confirmed — written as requirements. It is regulation-driven rather than feature-driven, so most of the set is non-functional, and the load is carried by the constraints and business rules rather than by the three features. It stops at requirements: no design stage was run for it.

Nothing here was written or corrected by hand. The pages are generated from the committed set under docs/requirements/examples/gdpr/, so what you read is the artifact rather than a description of one.

  • Requirements — 21 atomic artifacts: 3 functional requirements, 15 non-functional requirements, 1 constraint and 2 business rules.
  • Definition of done — projected from every stage above, and owned by none of them.
Last updated on