Pet360 Internal Intelligence Layer

The Bible/Security/PII & Privacy

PII Protection & Privacy

PII identification, crypto-shredding, and data subject rights per Canon Doctrine 5.

CANON DOCTRINE 5: PII MUTABILITY

PII envelope is immutable. Payload MUST support crypto-shredding or externalization. "Forget" renders PII unreadable while preserving audit narrative.

PII Field Classification

EntityPII Fields
Personfirst_name, last_name, email, phone, address, ssn_last4
DonorAll person fields + payment_method_token
StaffAll person fields + employee_id
Medicaltreatment_notes (if contains person info)

Crypto-Shredding Flow

STEP 1: Erasure Request

pii.erasure.requested

{ person_id, reason, requestor, legal_basis }

โ†“

STEP 2: Key Destruction

DELETE FROM pii_keys WHERE person_id = ?

(Encryption key permanently destroyed)

โ†“

STEP 3: Verification

pii.erasure.completed

{ person_id, erased_at, verified_by_audit }

โ†“

RESULT: Audit trail preserved, PII unrecoverable

"Adoption completed by [REDACTED] on 2025-03-15"

"Donation of $100 received from [REDACTED] on 2025-06-20"

Data Subject Rights

RightImplementationResponse Time
AccessExport personal data as JSON/PDF30 days
RectificationCorrection event with audit trail30 days
ErasureCrypto-shredding (key destruction)30 days
PortabilityStandard export format30 days
RestrictionProcessing hold flagImmediate
ObjectMarketing opt-outImmediate

Privacy by Design (Canon ยง10)

Prohibited
  • Behavioral ad targeting
  • Donor data resale or enrichment
  • Audience profiling beyond consent
  • Marketing surveillance features
  • Retargeting
Required
  • Anonymous donations supported
  • Campaign โ‰  consent for messaging
  • Explicit consent for marketing
  • Data minimization
  • Purpose limitation