Authority
The applicant can identify the controller and a person authorised to instruct and approve the case.
Methodology · Version 0.1
This methodology defines the proposed acceptance gate, source record, review boundary, exception handling and quality checks. It is an operating standard under validation—not proof of production capacity or legal advice.
Working definitions
Official context: European Commission guidance on handling rights requests and GDPR Article 15. This page summarises an operating method, not the law.
The applicant can identify the controller and a person authorised to instruct and approve the case.
The right being exercised, receipt context, known date and immediate urgency are understandable enough to scope.
The customer owns an appropriate verification decision and can state the current verification status.
Likely systems, requester identifiers, owners and material gaps can be named.
A controlled export, customer-run retrieval or narrow access route can be agreed before data transfer.
Disclosure, redaction, retention, correction, erasure and final wording have an authorised decision owner.
Trace can perform the agreed Readiness Sprint work without implying production case handling or reviewer capacity.
Scope, price, data handling, retention, deletion, cancellation and responsibility are accepted in writing.
The Sprint boundary
The Readiness Sprint is a proposed mapping and synthetic-rehearsal engagement. It is not a service-level promise or the GDPR response period.
The general legal timing requirement is separate. See GDPR Article 12 and the EDPB explanation of the one-month period.
The system, dataset, export or repository that was checked.
The customer role able to validate access and explain the source.
The requester key used for lookup and its known matching limits.
Export, query, API retrieval, manifest search or manual evidence import.
When collection occurred and which case event records it.
Records found, no records found, access failure or inconclusive search.
Normalisation, deduplication or packaging applied after retrieval.
An unqueried source, missing identifier, incomplete export or unresolved ambiguity.
Proposed case sequence
The sequence aims to reduce coordination without laundering incomplete evidence into false certainty.
Preserve original receipt context, request wording, identity state, controller instructions and timing assumptions.
Name expected sources, owners, requester identifiers, access methods and exclusions before retrieval begins.
Use the accepted path, record failures and resist expanding access merely because it is convenient.
Structure records by source, deduplicate where justified and preserve original evidence alongside transformations.
Mark missing systems, weak identifier matches, third-party information, retention questions and inconsistent results.
Assemble the source inventory, evidence package, response structure, action list and event record.
Record the decision owner, rationale and next action. No automatic disclosure or erasure is inferred.
Only after approval: use the accepted delivery path, update the activity record and apply retention and revocation instructions.
Every file and draft statement can be traced to an agreed source or a clearly labelled customer instruction.
A pack never calls itself complete merely because every reachable source returned a result. Known unknowns stay visible.
The verification state is present without Trace implying a universal or autonomous identity decision.
Recommendations, factual observations and customer decisions are distinguishable in the case.
File structure, access, recipient, expiry and delivery method are checked before an approved transfer.
Credentials, working copies and final case materials have agreed revocation and deletion instructions.
Claim methodology
The same discipline applied to a case should apply to Trace itself.
Implemented and currently usable, with an owner and evidence that supports the public wording.
Delivered through a defined human-operated process when scope and capacity are expressly accepted.
An illustrative interface, artefact or workflow used to test understanding—not customer proof.
A prioritised direction that has not reached a generally usable state and has no guaranteed date.
A claim or control requiring technical, security, operational or professional review before publication.
No sufficient evidence is available. The statement must not be presented as fact.
Sources
The case method is Trace’s proposed operational model. Legal statements are grounded in primary EU materials.
Founding design partners
The proposed Readiness Sprint maps up to three systems and rehearses the evidence method without accepting live request data through this website.