Owner: Ayisha (Compliance) · Department: Compliance · Status: Live · Version: 1.0
Effective Date: 2026-06-13 · Last Reviewed: 2026-06-13 · Next Review Date: 2026-09-13
Source of Truth: this page · Maturity: 4 (Operational)
Drives the PII/DSAR SOP and DSAR Execution playbook. Primary regime for HempDash customers: Texas TDPSA (Texas Data Privacy & Security Act).
| Right | What the customer asks | Backend support | Statutory deadline |
|---|---|---|---|
| Access / Know | "What do you have on me?" | DataExportRequest (export) |
45 days (TDPSA), +45 extension |
| Delete | "Delete my data" | AccountDeletionRequest (tracks deleted/anonymized/retained) |
45 days |
| Portability | "Give me my data" | DataExportRequest |
45 days |
| Correct | "Fix my data" | manual via account | 45 days |
| Opt-out | "Stop selling/sharing" | consent flags (GDPRConsent/CCPAPreference) |
as soon as practicable |
CURRENT-STATE note: deletion preserves required legal/fraud/order records (append-only tables, RESTRICT FKs) but does not revoke the customer's compliance seal (no seal-revoke-on-deletion path exists yet — backend-truth audit §24.15). Flag for the Seal Revocation playbook.
Reference index · SOPs · Playbooks · Home