Files
accounted/.compliance/dsar_runbook.md
T
Mattsson 072aedeaf9 Fix/supp ag fb (#1023)
* fix: prevent credit notes from entering payment flow

* fix: persist and display customer personal numbers

* feat: configure automatic invoice reminder days

* fix: issue credit notes through send flow

* chore: add repository agent guidance

* feat(mcp): route tools across user companies

* fix(articles): delete unused register entries

* feat(invoices): improve issued invoice actions

* feat(supplier-invoices): retain uploaded source documents

* docs: record implementation decisions

* feat: enhance customer personal number handling and validation

- Updated CustomerForm to allow personal numbers in the format of "********-1234" for individual customers.
- Added validation to ensure personal numbers are only accepted for individual customers in CreateCustomerSchema.
- Implemented masking and encryption for personal numbers to enhance data protection.
- Introduced new utility functions for masking and encrypting personal numbers.
- Added database migration to enforce unique constraints on credit note relationships and prevent duplicate entries.
- Enhanced error handling and logging for credit note issuance and invoice processing.
- Updated tests to cover new credit note creation guards and personal number handling.

* test: enhance list companies test with supabase query mocks
2026-07-15 15:53:15 +02:00

1.2 KiB

Data Subject Rights Runbook

Customer identity data

For access, correction, restriction, portability, or erasure requests, first verify the requester and the tenant relationship. Search the company-scoped customer record and any retained accounting documents. Customer master data may be corrected or erased when no legal retention duty applies. Accounting records and issued invoice documents remain retained for the statutory period; document the Article 17(3)(b) exception in the response.

Full personal numbers are never returned through the ordinary customer API. Exports and support evidence must use the masked value unless a separately approved identity-verification procedure requires otherwise.

Article master data

Article master records are not personal data and have no independent retention duty. The delete endpoint allows deletion only when no invoice item references the article. Issued invoice lines contain frozen descriptions, accounts, VAT values, and amounts, while archived PDFs and journal records remain immutable. This preserves the verification chain and the seven-year accounting retention period even when an unused article master row is deleted.