| name | privacy-reviewer |
| description | Review PII handling, encryption, and GDPR/CCPA compliance in Rails applications. |
| allowed-tools | Read Grep Glob Bash |
Privacy Compliance Review
Review PII identification, encryption, data deletion, and regulatory compliance.
PII Identification Checklist
| Category | Examples | Treatment |
|---|
| Direct identifiers | Name, email, phone, SSN | Encrypt at rest |
| Indirect identifiers | IP address, device ID | Hash or encrypt |
| Location data | GPS, address, zip code | Encrypt, retention limits |
| Financial | Card numbers, bank accounts | PCI compliance required |
| Health | Medical records, conditions | HIPAA compliance required |
| Behavioral | Browsing history, preferences | Consent required |
Encryption for Sensitive Fields
class User < ApplicationRecord
encrypts :ssn
encrypts :date_of_birth
encrypts :medical_notes, deterministic: false
end
Right to Deletion (GDPR Article 17)
user.destroy
def anonymize!
transaction do
update!(
email: "deleted_#{id}@anonymized.local",
name: "Deleted User",
phone: nil,
address: nil,
deleted_at: Time.current
)
orders.update_all(
customer_name: "Anonymized",
shipping_address: nil
)
end
end
Data Retention
class PiiRetentionJob < ApplicationJob
def perform
User.where("last_activity_at < ?", 3.years.ago)
.find_each(&:anonymize!)
AuditLog.where("created_at < ?", 7.years.ago).delete_all
end
end
Audit Trails
class PiiAccessLog < ApplicationRecord
belongs_to :user
belongs_to :accessed_by, class_name: 'User'
end
def ssn
PiiAccessLog.create!(user: self, accessed_by: Current.user, field_accessed: 'ssn')
super
end
Consent Management
class UserConsent < ApplicationRecord
belongs_to :user
end
def can_send_marketing?(user)
user.consents.active.exists?(consent_type: 'marketing')
end
Data Export (GDPR Article 20)
def export_personal_data
{
profile: attributes.slice('name', 'email', 'phone'),
orders: orders.map(&:export_data),
activity: activity_logs.map(&:export_data),
exported_at: Time.current.iso8601
}.to_json
end
Review Checklist
Output Format
## Privacy Review: [PASS/WARN/FAIL]
### Unencrypted PII
- [model.field]: [PII type, should be encrypted]
### Deletion Compliance
- [issue]: [hard deletes without anonymization option]
### Missing Audit Trails
- [model]: [PII accessed without logging]
### Consent Gaps
- [feature]: [processes data without consent check]
### Recommendations
1. [Prioritized fixes]