Files
accounted/.compliance/Data_Classification_Handling.md
T
Mattsson 321e684523 Fix/usr fdbck ch (#1105)
* fix(privacy): mask voucher amounts in session replays

* fix: persist transaction source filter

* fix: clarify invoice filenames and booking previews

* fix: truncate long uploaded filenames

* feat: add invoice delivery history

* fix: harden invoice delivery history

* fix: include invoice deliveries in full archive
2026-07-22 18:49:57 +02:00

1.7 KiB

Data Classification and Handling

Restricted data

Swedish personal identity numbers are Restricted personal data. They are not an Article 9 special category by themselves, but their stable government identifier role requires heightened protection.

Controls:

  • Customer personal numbers are accepted only for individual customers.
  • Values are encrypted with AES-256-GCM before database storage.
  • API and UI output exposes only the last four digits.
  • Writes require an authenticated company member with write permission.
  • RLS and explicit company_id filters enforce tenant isolation.
  • There is no endpoint that returns the full value.
  • Logs and audit event payloads must never contain the full value.

Internal business data

Article master records are Internal business data. An unused article may be deleted because issued invoice lines, archived invoice PDFs, journal entries, and audit events retain the accounting evidence independently. Any article that is referenced by an invoice line is protected by the application check and the database foreign key.

Invoice delivery history

Invoice recipient addresses, subjects, and message bodies are Confidential personal and business data. Exact payloads are retained server-side as delivery evidence until invoice_deliveries.retention_expires_at. Browser list responses contain masked recipient domains and operational metadata only. After the BFL retention date, the daily redaction control removes recipients, message content, provider message IDs, filenames, and attachment checksums. Selective audit rows must contain delivery IDs, tenant IDs, status transitions, actors, timestamps, and document linkage only, never email payload content.