Home›Telecom›Non-Functional Architecture›Compliance & Data Governance← NFR overview
Non-functional architecture
Reference Architecture

Compliance & Data Governance

Compliance & Data Governance: PII Compliance · GDPR · Data Classification · Audit Trail · Retention Policies.

Compliance & Data Governance
PII Compliance · GDPR · Data Classification · Audit Trail · Retention Policies
PII & Data Protection
GDPR · Data Minimisation · Pseudonymisation · Right to Erasure
Data Classification4-tier: Public · Internal · Confidential · Restricted (PII/PCI). Classification applied at field level — not document level. Drives encryption, access control and retention rules.
PII HandlingPII fields (name, address, MSISDN, IMEI, NIN) encrypted at field level with service-specific encryption keys. PII never logged. PII masked in non-production environments. PII map maintained per service.
Data MinimisationServices collect only the PII fields they are authorised to process. No data hoarding — PII not replicated to services that do not require it. Enforced via API contract reviews.
Right to ErasureErasure request triggers a propagated deletion event across all services holding subscriber PII. Services must confirm deletion within SLA (72 h). Audit trail of deletion is retained (without the PII).
PseudonymisationAnalytics and reporting pipelines use pseudonymised subscriber IDs — not real MSISDN or account IDs. Mapping table held in restricted access vault accessible only to authorised data teams.
Audit TrailImmutable audit log of every read and write on PII fields. Log entries: who accessed, what data, from which service, when. Audit logs stored in tamper-evident write-once storage. Retained 7 years.
GDPR Field Encryption Data Minimisation Right to Erasure Pseudonymisation Immutable Audit Log
Data Retention & Lifecycle
Retention Policies · Automated Purge · Archival · Legal Hold
Data TypeHot RetentionArchivePurge
Subscriber PIIActive + 6 months post-churn6–13 months cold13 months (unless legal hold)
Call Records (CDR)6 months6–24 months24 months (regulatory minimum)
Invoice & Billing2 years2–7 years cold7 years (financial regulation)
Order History2 years2–5 years5 years
Audit Logs90 days90 days – 7 years7 years (never auto-purge)
Application Logs30 days30–90 days90 days
Non-Functional Requirements — Summary Reference
NFR CategoryRequirementTarget / StandardStatus
AvailabilityPlatform availability SLO99.99% (≈ minutes per year)Mandatory
LatencyAPI P99 latency (tier-1 services)< Sub-second P99Mandatory
ThroughputCDR processing rateVery High — stream processing sustainedMandatory
RTORevenue-critical service recovery<Minutes (Tier 0 — near-zero)Mandatory
RPOMaximum data loss windowNear-zero (Tier 0 — synchronous replication)Mandatory
SecurityEncryption in transitTLS 1.3+ on external traffic, mTLS on all inter-service communicationMandatory
SecurityEncryption at restAES-256-GCM all data storesMandatory
IdentityAuthentication protocolOAuth 2.0 / OIDC + Workload Identity Standard workload identityMandatory
PII ComplianceGDPR — Right to Erasure SLAConfirmed deletion within the regulatory SLA windowMandatory
ResilienceCircuit breaker on all external callsError rate >50% in 10 s window triggers openMandatory
IdempotencyAll financial mutation endpointsIdempotency key + 24 h dedup storeMandatory
ScalabilityHPA on all stateless servicesCPU target 60%, scale within a short cool-down windowMandatory
Anti-AffinityPod distributionRequired: no two replicas on same node; Preferred: spread across AZsMandatory
Technical DebtSprint debt remediation allocationMinimum 20% per sprintRecommended
ObservabilityDistributed tracing coverage100% of requests carry traceId; 10% sampledMandatory
CI/CD SecuritySAST + SCA in every pipelineCritical/High CVEs block mergeMandatory
Non-functional architecturePrevious: Observability & CI/CD→