Skip to Content
User guideWorked examplesGDPR complianceDefinition of done

Definition of Done

  • Project / feature: GDPR Data Export & Account Deletion
  • Generated: 2026-09-18
  • Derived from: requirements ✓ · design — · qa —

A work item is Done only when every gate below is satisfied.

PR Checklist

Everything below needs a person. CI-enforced gates are not listed — a passing build is their evidence.

  • NFR-012 — Tamper-evident audit logging of export and deletion events: evidence recorded (inspection).
  • NFR-014 — Extensibility of statutory retention categories: evidence recorded (analysis).
  • NFR-016 — Safe deployment and rollback without corrupting in-flight requests: evidence recorded (demonstration).
  • NFR-017 — Statutory-retention compliance of pseudonymised records post-erasure: evidence recorded (inspection).
  • Documentation updated for FR-001, FR-002, FR-003.

Functional Acceptance Gates

One gate per functional requirement. The linked file holds the authoritative acceptance criteria; they are referenced here, never duplicated.

  • FR-001 — Export personal data as machine-readable archive (must) [verification: test] All acceptance-criteria scenarios in the source file pass. Fit criterion: 100% of export requests produce a downloadable archive within 30 days of submission; a field-level audit of each generated archive against the catalogued data map confirms 0 omitted fields, checked across a sample of test accounts spanning every data store in scope. Source: .sdlc/requirements/functional/FR-001-export-personal-data-as-machine-readable-archive.md

  • FR-002 — Erase account and personal data on confirmed deletion request (must) [verification: test] All acceptance-criteria scenarios in the source file pass. Fit criterion: For 100% of confirmed deletion requests sampled in acceptance testing, a data audit conducted on or before day 30 after confirmation finds 0 personal-data records for the account outside the documented statutory-retention set, and 100% of authentication attempts against the deleted account fail. Source: .sdlc/requirements/functional/FR-002-erase-account-and-personal-data-on-confirmed-deletion-request.md

  • FR-003 — Cancel unconfirmed account deletion request within 24-hour window (must) [verification: test] All acceptance-criteria scenarios in the source file pass. Fit criterion: 100% of deletion requests left unconfirmed for 24 hours are automatically cancelled with 0 mutations to account state or personal data; 0 accounts are deleted without a corresponding recorded re-authentication event within the 24-hour window. Source: .sdlc/requirements/functional/FR-003-cancel-unconfirmed-account-deletion-request-within-24-hour-window.md

NFR Fitness Gates

The quality attribute scenario’s response measure is the pass/fail oracle for each gate below.

  • NFR-001 — Export data completeness across all catalogued data stores (must) [verification: test] Response measure: A field-level audit finds 0 omissions across 100% of data stores, sampled quarterly and on every export-pipeline release. Scenario: Submits a data export request. on Export generation subsystem. under Normal operation, spanning every data store in the already-catalogued data map.. Source: .sdlc/requirements/non-functional/NFR-001-export-data-completeness-across-all-catalogued-data-stores.md

  • NFR-002 — Erasure completeness excluding statutory-retention records (must) [verification: test] Response measure: A data audit finds 0 personal-data records outside the documented statutory-retention set; 100% of authentication attempts against the deleted account fail. Scenario: Confirms a deletion request via re-authentication. on Erasure processing subsystem across all catalogued personal-data stores. under Normal operation, after the erasure process completes.. Source: .sdlc/requirements/non-functional/NFR-002-erasure-completeness-excluding-statutory-retention-records.md

  • NFR-003 — Export generation time under normal load (must) [verification: test] Response measure: p95 turnaround <= 72 hours; 100% of exports available within the 30-day statutory ceiling, measured over a rolling 30-day window. Scenario: Submits a request to export their personal data. on Export generation service and the durable object store holding generated archives (D-1). under Normal operating load, export-worker utilisation <= 80%.. Source: .sdlc/requirements/non-functional/NFR-003-export-generation-time-under-normal-load.md

  • NFR-005 — Export archive format interoperability (should) [verification: test] Response measure: 100% of archives validate against the published schema via automated validation and open successfully in standard tooling during verification testing. Scenario: Downloads and opens the export archive. on Export archive format and its published specification. under Normal operation, using common third-party tooling (archive utilities, JSON/CSV parsers).. Source: .sdlc/requirements/non-functional/NFR-005-export-archive-format-interoperability.md

  • NFR-006 — User error protection for irreversible account deletion (must) [verification: test] Response measure: 100% of deletion initiations require the distinct acknowledgment step; 0 deletion requests are queued without both the acknowledgment and the re-authentication event recorded. Scenario: Initiates account deletion. on Deletion request UI/flow. under Normal operation, self-service deletion flow.. Source: .sdlc/requirements/non-functional/NFR-006-user-error-protection-for-irreversible-account-deletion.md

  • NFR-007 — Accessibility of export and deletion self-service flows (should) [verification: test] Response measure: 0 critical violations, verified by automated scan plus manual screen-reader and keyboard-only walkthrough. Scenario: Navigates the export or deletion self-service flow, including the re-authentication step-up and the irreversibility-acknowledgment step. on Export and deletion self-service UI flow. under Normal operation, any supported assistive technology.. Source: .sdlc/requirements/non-functional/NFR-007-accessibility-of-export-and-deletion-self-service-flows.md

  • NFR-008 — Availability of the GDPR self-service portal (should) [verification: test] Response measure: >= 99.9% monthly availability, measured via uptime monitoring over a rolling monthly window. Scenario: Attempts to submit an export or deletion request. on Export and deletion request-submission API endpoints. under Normal operation, any hour (self-service, no business-hours restriction implied by the brief).. Source: .sdlc/requirements/non-functional/NFR-008-availability-of-the-gdpr-self-service-portal.md

  • NFR-009 — Fault tolerance and recovery of export generation (should) [verification: test] Response measure: >= 99% of transient failures resolved within 3 retry attempts; 100% of affected requests still complete within the 30-day ceiling, verified via fault-injection testing. Scenario: One or more source stores fail to respond during archive assembly. on Export generation pipeline. under Normal operation, no sustained outage.. Source: .sdlc/requirements/non-functional/NFR-009-fault-tolerance-and-recovery-of-export-generation.md

  • NFR-010 — Confidentiality of exported personal-data archives (must) [verification: test] Response measure: 100% of archives encrypted at rest (assumed AES-256 or equivalent); links expire within an assumed 72-hour window; 0 unauthorized retrievals across access-control and penetration testing. Scenario: Attempts to access or intercept the export archive or its download link. on Export archive and its download link. under Normal operation, archive at rest in the durable object store and in transit during download.. Source: .sdlc/requirements/non-functional/NFR-010-confidentiality-of-exported-personal-data-archives.md

  • NFR-011 — Deletion requires fresh re-authentication and auto-cancels if unconfirmed (must) [verification: test] Response measure: 0 accounts deleted without a recorded re-authentication event in the prior 24 hours; 100% of unconfirmed requests auto-cancelled with no data mutation. Scenario: A deletion request is submitted, with or without a subsequent step-up re-authentication event. on Deletion confirmation flow and its integration with the existing identity provider’s step-up re-authentication capability. under Normal operation, within or beyond the 24-hour confirmation window.. Source: .sdlc/requirements/non-functional/NFR-011-deletion-requires-fresh-re-authentication-and-auto-cancels-if-unconfirmed.md

  • NFR-012 — Tamper-evident audit logging of export and deletion events (must) [verification: inspection] Response measure: 100% of lifecycle events captured with actor, timestamp, and outcome; entries are immutable/tamper-evident; no automated deletion occurs absent a defined retention policy (open question Q-3); verified via log-integrity inspection and a sample compliance audit. Scenario: A request is created, confirmed, cancelled, or completed. on Audit logging subsystem for export/deletion events. under Normal operation.. Source: .sdlc/requirements/non-functional/NFR-012-tamper-evident-audit-logging-of-export-and-deletion-events.md

  • NFR-014 — Extensibility of statutory retention categories (should) [verification: analysis] Response measure: The addition is achievable via configuration/data rather than core deletion-logic changes, verified via mechanism analysis. Scenario: Identifies a new regulated record type (beyond financial/tax) that must override erasure. on Retention-override / pseudonymisation-and-isolation mechanism. under Normal operation, outside of an active deletion incident.. Source: .sdlc/requirements/non-functional/NFR-014-extensibility-of-statutory-retention-categories.md

  • NFR-015 — Monitoring and alerting on requests approaching the statutory deadline (should) [verification: test] Response measure: 100% of requests within an assumed 5-day margin of the ceiling trigger an alert, verified via test; 0 silent breaches. Scenario: An export or deletion request is still open as it nears the 30-day statutory ceiling. on Monitoring/alerting pipeline over export and deletion request state. under Normal operation.. Source: .sdlc/requirements/non-functional/NFR-015-monitoring-and-alerting-on-requests-approaching-the-statutory-deadline.md

  • NFR-016 — Safe deployment and rollback without corrupting in-flight requests (could) [verification: demonstration] Response measure: 0 jobs left in an inconsistent state, verified via a deployment/rollback demonstration under simulated in-flight load. Scenario: A deployment or rollback occurs while export/deletion jobs are in-flight. on Export generation and erasure processing pipelines and their deployment mechanism. under Normal release activity.. Source: .sdlc/requirements/non-functional/NFR-016-safe-deployment-and-rollback-without-corrupting-in-flight-requests.md

  • NFR-017 — Statutory-retention compliance of pseudonymised records post-erasure (must) [verification: inspection] Response measure: 100% of retained records are pseudonymised and isolated; a compliance audit finds 0 exceptions against the documented retention rules. Scenario: An account with financial/tax records under mandated retention is erased. on Retention-isolation and pseudonymisation mechanism. under Normal operation.. Source: .sdlc/requirements/non-functional/NFR-017-statutory-retention-compliance-of-pseudonymised-records-post-erasure.md

Documentation Requirements

  • Public-facing behaviour of every must functional requirement is documented: FR-001, FR-002, FR-003.
  • Operational NFRs have runbook or configuration notes: NFR-010 (Security), NFR-011 (Security), NFR-012 (Security), NFR-008 (Reliability), NFR-009 (Reliability), NFR-015 (Extension), NFR-016 (Extension), NFR-017 (Extension).
  • Every implemented artifact carries status: implemented (or verified) and a populated traces_to.code.

Deployment / Operational Readiness

  • Security NFR gates pass before release: NFR-010, NFR-011, NFR-012.
  • Reliability targets are met or have an accepted waiver: NFR-008, NFR-009.
  • Observability is in place for the response measures asserted above.
  • Constraints and business rules hold in the deployed configuration: BR-001, BR-002, CON-001.

Generated from the artifact sets under .sdlc/. Change the source artifact and regenerate; do not edit this file.

Last updated on