pii, personal data, data leak | PII detection scan | PII inventory + classification | reference/pii-detection.md |
gdpr, ccpa, privacy law, compliance | Regulation compliance audit | Gap analysis + remediation plan | reference/privacy-regulations.md |
consent, opt-in, opt-out, cookie | Consent management implementation | Consent flow patterns | reference/implementation-patterns.md |
data flow, data map, lineage | Data flow mapping | Visual data flow + risk points | reference/pii-detection.md |
dsar, right to delete, data export | DSAR automation | DSAR handler code | reference/implementation-patterns.md |
retention, data lifecycle | Retention policy enforcement | TTL/cron patterns | reference/implementation-patterns.md |
logging, observability, audit | Privacy-safe logging | PII redaction middleware | reference/implementation-patterns.md |
anonymize, pseudonymize, mask | Data de-identification | Transform functions | reference/implementation-patterns.md |
dpia, impact assessment | DPIA facilitation | Risk assessment document | reference/privacy-regulations.md |
llm, ai privacy, embedding, rag | AI/LLM privacy risk assessment | PII sanitization plan + differential privacy guidance | reference/implementation-patterns.md |
admt, automated decision | CCPA ADMT compliance | Pre-use notice + opt-out + appeal flow | reference/privacy-regulations.md |
eu ai act, fria, high-risk ai | EU AI Act FRIA + GDPR DPIA dual assessment | FRIA report + DPIA + data governance plan | reference/privacy-regulations.md |
gpc, opt-out signal, universal opt-out | GPC / universal opt-out signal compliance | Signal detection + visible acknowledgment + honor flow | reference/implementation-patterns.md |
hipaa, ephi, health data | HIPAA Security Rule compliance | Encryption + MFA + audit controls | reference/privacy-regulations.md |
privacy manifest, PrivacyInfo.xcprivacy, Required Reasons API, ITMS-91056 | App Store Privacy Manifest audit (host + SDK) | Manifest review verdict + SDK replacement recommendations | reference/privacy-regulations.md |
data safety, play console privacy, ANDROID_ID | Google Play Data Safety form audit | Form completeness + runtime-vs-declaration diff | reference/privacy-regulations.md |
5.1.2(i), app store AI consent, third-party AI disclosure | 5.1.2(i) AI consent UI design | Consent ledger spec + per-provider UI + on-device fallback | reference/privacy-regulations.md |
EAA, EN 301 549, mobile accessibility privacy | EAA / WCAG 2.1 AA mobile conformance | Accessibility-as-privacy audit | reference/privacy-regulations.md |
| unclear privacy request | PII detection scan | PII inventory + next steps | reference/pii-detection.md |