Fit and capacity
Trace confirms the request environment is suitable and that responsible delivery capacity exists.
Proposed operating model · In validation
Trace is developing a managed sequence for mapping sources, coordinating approved retrieval, structuring evidence and exposing exceptions. The workflow stops where authorised privacy judgement begins.
Maturity boundary
Trace is pre-launch. There is no generally available production case platform, live connector catalogue, handling service or confirmed reviewer network. Any paid work begins only after fit, capacity, scope, roles, security and data handling are agreed in writing.
Before preparation
A waitlist form or email does not begin case processing. The proposed operating sequence starts only inside an accepted, written scope.
Trace confirms the request environment is suitable and that responsible delivery capacity exists.
Systems, identifiers, retrieval paths, exclusions and known limitations are documented.
The controller, privacy decision owner and Trace preparation boundary are explicit.
Required legal, security, transfer, retention and deletion conditions are satisfied first.
The proposed workflow
The record should let the next authorised person see what happened, what was searched, what could not be resolved and which decision is now required.
The request type, intake route, identity state, controller context and open questions enter one case record.
An authorised person confirms the operating scope and decides whether identity evidence is sufficient.
Only agreed sources and customer-approved retrieval paths are used. The method and identifier travel with each result.
Available records are arranged with the source inventory, search context and known collection limits.
Missing coverage, conflicting identifiers, third-party data and decision questions remain explicit.
The evidence manifest, exception notes, draft structure and activity record meet the human decision boundary.
Source mapping
The proposed source map connects each system to the identifiers, owner, approved retrieval method and known limit. It is designed to prevent a result from becoming detached from how it was produced.
Review source-mapping readinessNo one-click connector claim
Proposed deliverable
The exact records would depend on the request, written scope and available sources. These labels describe the intended evidence-pack structure.
Request type, identity state, agreed scope and unresolved questions.
Sources checked, identifiers used, retrieval methods, records found and known gaps.
Available fictional or approved records arranged by source for authorised inspection.
A structured starting point for the authorised privacy professional—not autonomous legal advice.
Third-party information, retention questions, uncertainty and missing-source warnings.
Timestamped operational actions and decision hand-offs without an immutable-log claim.
Clear ownership
Disclosure, redaction, retention, exemptions, erasure, correction, legal advice and final wording remain outside automated preparation.
Proposed operating role
Decision boundary
Two clocks
An accepted engagement would define its sources, milestones and outputs in writing. This is not a public response-time guarantee.
Controllers generally must act without undue delay and within one month. Circumstances may permit an extension; one month is not simply a fixed 30-day count.
Read the official EDPB timing explanation, European Commission request guidance and GDPR Article 12. Trace does not calculate a legally binding deadline on this page.
Test readiness first
The proposed Readiness Sprint maps up to three systems and rehearses one synthetic request. No live request data, checkout or production-access promise.