Consent & Privacy Service · View 11 of 22 · Data
Decisions
- The ledger, the audit store and the per-subject keys are irreplaceable: RPO 0, committed to a regional quorum before a capture is acknowledged.
- Projections, snapshots and enforcement caches are deliberately disposable. That is what turns a corrupt projection or a bad decision deploy into a rebuild rather than an incident with no exit.
- Losing a per-subject key is indistinguishable from erasing that subject. The key store is therefore in the irreplaceable row and backed up with the ledger, not with the projections.
Assumptions
- RPO 0 for ledger, audit and keys; RPO 60 s for derived projections; RTO 10 minutes for a region's decision path, 60 minutes for its full projection rebuild.
- Ledger 40 TB over 7 years after compression; hot for recent entries, archive beyond, retrievable inside the regulator-response window rather than instantly.
Risks
- The identity index is marked re-derivable "slowly", which is optimistic: re-deriving it depends on forty systems still holding the linkage they held when it was built. Treat it as closer to irreplaceable than the row suggests.
- A 20× replay rate is an assumption, not a measurement. The whole 60-minute RTO rests on it, so it is one of the three things the prototype must falsify.