Skip to main content

Notification Compliance

Business Purpose

Identify source-backed controls and unresolved governance decisions for personal communication data.

Actors

Employees, privacy owners, security reviewers, tenant administrators, auditors, support teams and service owners.

Business Flow

Events can create recipient directory records, rendered message content, recipient addresses, delivery errors, attempts, audit stages and processed-event evidence. Employees read records through an authenticated legacy controller. The extracted service expects queries to apply tenant scope explicitly because its context does not use a global tenant filter.

Responsibilities

Data controllers define purpose, lawful handling, retention and user-rights procedures. Service owners enforce authentication, authorization and tenant scoping. Content owners minimize personal data. Support protects message content and errors during investigation.

Business Rules

The legacy inbox requires authentication and scopes records to the active signed-in user. Legacy template changes require role and tenant checks. Audit and attempt records are append-oriented. These controls do not establish a complete compliance program.

Integrations

Compliance spans event producers, recipient data, channel providers, notification storage, portal access and operational telemetry. Provider contracts and deployment controls are outside the reviewed source boundary.

Limitations

No source-backed retention purge, archival, erasure workflow, consent UI, content redaction, field-level encryption, legal hold or data export was found. Extracted-service authentication and endpoint policies are not evident. Public documentation cannot confirm compliance with a named law or standard.

Requires Confirmation

Confirm data classifications, lawful basis, retention schedules, tenant isolation tests, access policies, encryption, provider agreements, cross-border processing, user-rights workflows, audit access and security incident procedures.

Source References

  • microservices/src/notification-service/Domain/NotificationEntities.cs
  • microservices/src/notification-service/Infrastructure/NotificationDbContext.cs
  • microservices/src/notification-service/Program.cs
  • microservices/src/notification-service/Api/NotificationEndpoints.cs
  • Controllers/NotificationsController.cs
  • Controllers/NotificationTemplatesController.cs

See Also

Keywords

Privacy, tenant isolation, access, audit, retention, personal data.

Revision Information

Draft; reviewed 2026-07-21; next quarterly review 2026-10-21.