Methodology · Version 0.1

A fast case is only useful when its evidence boundary is visible.

This methodology defines the proposed acceptance gate, pack clock, source record, review boundary and quality checks for Trace’s early-access concierge model. It is a design and operating standard under validation—not proof of current capacity or legal advice.

Working definitions

Start with language a buyer can audit.

What is Trace?
An early-stage managed privacy-operations product thesis focused first on preparing GDPR data-request cases for authorised human review.
What is a DSAR?
A common operational term for a data subject access request. Trace may also need to frame other rights requests, but the customer remains responsible for the legal classification and response.
What is a review-ready pack?
A scoped case summary, source inventory, available evidence, response draft, exception notes and activity record with open decisions made explicit.
What happens within 24 hours?
For a case Trace has accepted under agreed conditions, the proposed target is preparation of that pack—not final legal closure, disclosure, correction or erasure.
Who responds to the person?
The controller or its authorised representative. Trace does not assume that authority merely by preparing operational material.
Does Trace make legal decisions?
No autonomous legal-decision claim is made. Identity, exceptions, third-party rights, retention and final communication require authorised human judgement.

Official context: European Commission guidance on handling rights requests and GDPR Article 15. This page summarises an operating method, not the law.

01

Authority

The applicant can identify the controller and a person authorised to instruct and approve the case.

02

Request frame

The right being exercised, receipt context, known date and immediate urgency are understandable enough to scope.

03

Identity path

The customer owns an appropriate verification decision and can state the current verification status.

04

Source boundary

Likely systems, requester identifiers, owners and material gaps can be named.

05

Access path

A controlled export, customer-run retrieval or narrow access route can be agreed before data transfer.

06

Review boundary

Disclosure, redaction, retention, correction, erasure and final wording have an authorised decision owner.

07

Capacity

Trace can actually perform the agreed concierge work and any promised review within the proposed period.

08

Terms

Scope, price, data handling, retention, deletion, cancellation and responsibility are accepted in writing.

The pack clock

What starts it, what stops it and what it measures.

The 24-hour statement is a proposed service-level target that needs real operating capacity before it can be offered. It is not the GDPR response period.

T+00:00

Target starts after accepted intake

  • Written case scope accepted
  • Instructions and decision owner recorded
  • Agreed evidence path available
  • Any required data-processing terms active
  • Trace capacity explicitly confirmed
T+24:00 · Proposed target

Pack reaches the review boundary

  • Available evidence organised
  • Source and gap inventory prepared
  • Response structure drafted
  • Exceptions and uncertainties flagged
  • Case queued for authorised judgement
The target does not mean
Identity is always verifiedEvery source is reachableEvery exception is resolvedErasure is executedThe response is deliveredThe legal case is closed

The general legal timing requirement is separate. See GDPR Article 12 and the EDPB explanation of the one-month period.

01

Source

The system, dataset, export or repository that was checked.

02

Owner

The customer role able to validate access and explain the source.

03

Identifier

The requester key used for lookup and its known matching limits.

04

Method

Export, query, API retrieval, manifest search or manual evidence import.

05

Time

When collection occurred and which case event records it.

06

Result

Records found, no records found, access failure or inconclusive search.

07

Transformation

Normalisation, deduplication or packaging applied after retrieval.

08

Gap

An unqueried source, missing identifier, incomplete export or unresolved ambiguity.

Proposed case sequence

Transform the format. Preserve the uncertainty.

The sequence aims to reduce coordination without laundering incomplete evidence into false certainty.

  1. 01 / FRAME

    Record request facts and open questions

    Preserve original receipt context, request wording, identity state, controller instructions and timing assumptions.

    Human-confirmed input
  2. 02 / MAP

    Set the source boundary

    Name expected sources, owners, requester identifiers, access methods and exclusions before retrieval begins.

    Concierge setup
  3. 03 / COLLECT

    Retrieve or import agreed evidence

    Use the accepted path, record failures and resist expanding access merely because it is convenient.

    Controlled execution
  4. 04 / NORMALISE

    Organise without rewriting the facts

    Structure records by source, deduplicate where justified and preserve original evidence alongside transformations.

    Trace prepares
  5. 05 / FLAG

    Expose gaps and decision points

    Mark missing systems, weak identifier matches, third-party information, retention questions and inconsistent results.

    No silent assumptions
  6. 06 / DRAFT

    Prepare the review material

    Assemble the source inventory, evidence package, response structure, action list and event record.

    Pack target
  7. 07 / DECIDE

    Authorised people approve or escalate

    Record the decision owner, rationale and next action. No automatic disclosure or erasure is inferred.

    Human boundary
  8. 08 / CLOSE

    Deliver, retain and remove access as agreed

    Only after approval: use the accepted delivery path, update the activity record and apply retention and revocation instructions.

    Customer authority
01

Scope integrity

Every file and draft statement can be traced to an agreed source or a clearly labelled customer instruction.

Required
02

Completeness honesty

A pack never calls itself complete merely because every reachable source returned a result. Known unknowns stay visible.

Required
03

Identity visibility

The verification state is present without Trace implying a universal or autonomous identity decision.

Required
04

Decision separation

Recommendations, factual observations and customer decisions are distinguishable in the case.

Required
05

Delivery readiness

File structure, access, recipient, expiry and delivery method are checked before an approved transfer.

Required
06

Retention closure

Credentials, working copies and final case materials have agreed revocation and deletion instructions.

Required

Claim methodology

Product language advances only when evidence does.

The same discipline applied to a case should apply to Trace itself.

LIVE

Implemented and currently usable, with an owner and evidence that supports the public wording.

CONCIERGE

Delivered through a defined human-operated process when scope and capacity are expressly accepted.

PROTOTYPE

An illustrative interface, artefact or workflow used to test understanding—not customer proof.

PLANNED

A prioritised direction that has not reached a generally usable state and has no guaranteed date.

UNDER REVIEW

A claim or control requiring technical, security, operational or professional review before publication.

UNVERIFIED

No sufficient evidence is available. The statement must not be presented as fact.

A controlled first request

A pilot should test the method, not just the headline.

Apply with operating context and system names. If Trace can accept the work, the case scope and evidence method should be explicit before any data moves.