Production environment

GDPR DSAR — Data Subject Access Request

Look up everything we know about a person by phone or email. Every consolidated view is audited.

Workflow

  1. Search by the phone or email the requester provided.
  2. Open the consolidated view — it aggregates DDB items, S3 files, email suppressions, recent EventBridge events, and the last 30 days of logs.
  3. Every consolidated load is audited. Export ZIP and deletion are out of scope for this view (Sprint 2 and Sprint 4 respectively).