Skip to content

M9-13 Regulatory & Industry Compliance — UKDIATF, CCPA, SOC2, UK Staffing Data Retention

Milestone: M9 — Hardening and Compliance SOW Reference: NFR3 Requirement Clarity: 🟡 These are named requirements in NFR3, but each is a compliance-alignment exercise rather than a single buildable feature — the SOW itself only says "compatibility and compliance... as the regulation evolves" for UKDIATF, with no further specification of what compliance activity is expected during this SOW. Dev Status: ❌ Not started — none of the four items below have any dedicated work recorded anywhere in the codebase or docs

Corroborating evidence: M9-00's security audit (dated 2026-04-15) independently flagged three of these four as unresolved at the time — "S7 UKDIATF compliance: ⚠️ Unknown, need legal review," "S9 UK staffing industry data retention: ❌ Missing," "S11 CCPA, SOC2 compliance: ⚠️ Partial, framework in place." This confirms these aren't newly-invented concerns — they were already open questions four months ago and, as far as this review found, still are.

Overview

Four distinct compliance requirements named in NFR3 that haven't been individually addressed: 1. UKDIATF — compatibility and compliance with the UK Digital Identity and Attributes Trust Framework, "as the regulation evolves." 2. CCPA — compliance with the California Consumer Privacy Act (alongside GDPR). 3. SOC2 — compliance with SOC2 for data protection and user privacy. 4. UK staffing industry data retention regulations — compliance with sector-specific retention rules, distinct from the general GDPR retention work in M9-01.

Tasks

  • Confirm with Curo what concrete UKDIATF compliance activity is expected within this SOW (it's an evolving framework, not a fixed checklist)
  • Confirm whether CCPA is genuinely applicable (it's a California, not UK, regulation — worth checking why it's named in a UK staffing-sector platform's requirements before scoping work against it)
  • Confirm what SOC2 compliance would require here — a SOC2 report/certification is normally an organisational audit process (Curo's or NeuralRays'), not a platform feature; clarify what NeuralRays is actually expected to build vs. what's an organisational responsibility
  • Research UK staffing industry-specific data retention rules and confirm they're reflected in the retention periods used by retention-policy.service.ts

Dependencies

Acceptance Criteria

Not explicitly defined in Appendix 3 beyond the bare NFR3 statements — worth getting concrete acceptance criteria agreed for each of the four items above.

Existing Reference Material

None.

Blockers & Risks

  • Needs decision: all four items need scope clarification before they can be estimated or built — none are further specified anywhere in the SOW beyond the single NFR3 line each.