Files
accounted/.compliance/Data_Classification_Handling.md
T
Mattsson 072aedeaf9 Fix/supp ag fb (#1023)
* fix: prevent credit notes from entering payment flow

* fix: persist and display customer personal numbers

* feat: configure automatic invoice reminder days

* fix: issue credit notes through send flow

* chore: add repository agent guidance

* feat(mcp): route tools across user companies

* fix(articles): delete unused register entries

* feat(invoices): improve issued invoice actions

* feat(supplier-invoices): retain uploaded source documents

* docs: record implementation decisions

* feat: enhance customer personal number handling and validation

- Updated CustomerForm to allow personal numbers in the format of "********-1234" for individual customers.
- Added validation to ensure personal numbers are only accepted for individual customers in CreateCustomerSchema.
- Implemented masking and encryption for personal numbers to enhance data protection.
- Introduced new utility functions for masking and encrypting personal numbers.
- Added database migration to enforce unique constraints on credit note relationships and prevent duplicate entries.
- Enhanced error handling and logging for credit note issuance and invoice processing.
- Updated tests to cover new credit note creation guards and personal number handling.

* test: enhance list companies test with supabase query mocks
2026-07-15 15:53:15 +02:00

1.1 KiB

Data Classification and Handling

Restricted data

Swedish personal identity numbers are Restricted personal data. They are not an Article 9 special category by themselves, but their stable government identifier role requires heightened protection.

Controls:

  • Customer personal numbers are accepted only for individual customers.
  • Values are encrypted with AES-256-GCM before database storage.
  • API and UI output exposes only the last four digits.
  • Writes require an authenticated company member with write permission.
  • RLS and explicit company_id filters enforce tenant isolation.
  • There is no endpoint that returns the full value.
  • Logs and audit event payloads must never contain the full value.

Internal business data

Article master records are Internal business data. An unused article may be deleted because issued invoice lines, archived invoice PDFs, journal entries, and audit events retain the accounting evidence independently. Any article that is referenced by an invoice line is protected by the application check and the database foreign key.