Data Classification4-tier: Public · Internal · Confidential · Restricted (PII/PCI). Classification applied at field level — not document level. Drives encryption, access control and retention rules.
PII HandlingPII fields (name, address, MSISDN, IMEI, NIN) encrypted at field level with service-specific encryption keys. PII never logged. PII masked in non-production environments. PII map maintained per service.
Data MinimisationServices collect only the PII fields they are authorised to process. No data hoarding — PII not replicated to services that do not require it. Enforced via API contract reviews.
Right to ErasureErasure request triggers a propagated deletion event across all services holding subscriber PII. Services must confirm deletion within SLA (72 h). Audit trail of deletion is retained (without the PII).
PseudonymisationAnalytics and reporting pipelines use pseudonymised subscriber IDs — not real MSISDN or account IDs. Mapping table held in restricted access vault accessible only to authorised data teams.
Audit TrailImmutable audit log of every read and write on PII fields. Log entries: who accessed, what data, from which service, when. Audit logs stored in tamper-evident write-once storage. Retained 7 years.
GDPR
Field Encryption
Data Minimisation
Right to Erasure
Pseudonymisation
Immutable Audit Log