Skip to content
Draft
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/processing-activities-kebab.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@transcend-io/cli': minor
'@transcend-io/sdk': minor
---

Complete processing-activities RoPA pull/push with kebab-case transcend.yml keys (e.g. `retention-type`, `data-subject-types`, `processing-sub-purposes`), skip empty `processing-activities: []` on push, and soft-warn unresolved `team-names`.
7 changes: 4 additions & 3 deletions packages/cli/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2472,7 +2472,7 @@ The API key permissions for this command vary based on the `resources` argument:
| `enrichers` | `enrichers` | The Privacy Request enricher configurations. | View Identity Verification Settings | [DSR Automation -> Identifiers](https://app.transcend.io/privacy-requests/identifiers) |
| `dataFlows` | `data-flows` | Consent Manager Data Flow definitions. | View Data Flows | [Consent Management -> Data Flows](https://app.transcend.io/consent-manager/data-flows/approved) |
| `businessEntities` | `business-entities` | The business entities in the Data Inventory. | View Data Inventory | [Data Inventory -> Business Entities](https://app.transcend.io/data-map/data-inventory/business-entities) |
| `processingActivities` | `processing-activities` | The processing activities in the Data Inventory. | View Data Inventory | [Data Inventory -> Processing Activities](https://app.transcend.io/data-map/data-inventory/processing-activities) |
| `processingActivities` | `processing-activities` | The processing activities in the Data Inventory (RoPA). Empty `processing-activities: []` does not request Manage Data Map scopes. | View Data Inventory | [Data Inventory -> Processing Activities](https://app.transcend.io/data-map/data-inventory/processing-activities) |
| `actions` | `actions` | The privacy request action settings. | View Data Subject Request Settings | [DSR Automation -> Request Settings -> Data Actions](https://app.transcend.io/privacy-requests/settings/data-actions) |
| `dataSubjects` | `data-subjects` | The privacy request data subject settings. | View Data Subject Request Settings | [DSR Automation -> Request Settings -> Data Subjects](https://app.transcend.io/privacy-requests/settings/data-subjects) |
| `identifiers` | `identifiers` | The privacy request identifier configurations. | View Identity Verification Settings | [DSR Automation -> Identifiers](https://app.transcend.io/privacy-requests/identifiers) |
Expand Down Expand Up @@ -2674,7 +2674,8 @@ FLAGS

#### Scopes

The API key permissions for this command vary based on the resources declared as top-level keys in your [`transcend.yml`](#transcendyml) file:
The API key permissions for this command vary based on the resources declared as top-level keys in your [`transcend.yml`](#transcendyml) file.
Empty arrays (e.g. `processing-activities: []`) do **not** request scopes for that resource.

| Resource | Key in `transcend.yml` | Description | Scopes | Link |
| ----------------------- | ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
Expand All @@ -2685,7 +2686,7 @@ The API key permissions for this command vary based on the resources declared as
| `enrichers` | `enrichers` | The Privacy Request enricher configurations. | Manage Request Identity Verification | [DSR Automation -> Identifiers](https://app.transcend.io/privacy-requests/identifiers) |
| `dataFlows` | `data-flows` | Consent Manager Data Flow definitions. | Manage Data Flows | [Consent Management -> Data Flows](https://app.transcend.io/consent-manager/data-flows/approved) |
| `businessEntities` | `business-entities` | The business entities in the Data Inventory. | Manage Data Inventory | [Data Inventory -> Business Entities](https://app.transcend.io/data-map/data-inventory/business-entities) |
| `processingActivities` | `processing-activities` | The processing activities in the Data Inventory. | Manage Data Map | [Data Inventory -> Processing Activities](https://app.transcend.io/data-map/data-inventory/processing-activities) |
| `processingActivities` | `processing-activities` | The processing activities in the Data Inventory (RoPA). Empty `processing-activities: []` does not request Manage Data Map scopes. | Manage Data Map | [Data Inventory -> Processing Activities](https://app.transcend.io/data-map/data-inventory/processing-activities) |
| `actions` | `actions` | The privacy request action settings. | Manage Data Subject Request Settings | [DSR Automation -> Request Settings -> Data Actions](https://app.transcend.io/privacy-requests/settings/data-actions) |
| `dataSubjects` | `data-subjects` | The privacy request data subject settings. | Manage Data Subject Request Settings | [DSR Automation -> Request Settings -> Data Subjects](https://app.transcend.io/privacy-requests/settings/data-subjects) |
| `identifiers` | `identifiers` | The privacy request identifier configurations. | Manage Request Identity Verification | [DSR Automation -> Identifiers](https://app.transcend.io/privacy-requests/identifiers) |
Expand Down
91 changes: 61 additions & 30 deletions packages/cli/examples/processing-activities.yml
Original file line number Diff line number Diff line change
@@ -1,84 +1,115 @@
# Processing activities (RoPA) for Data Inventory.
# Admin UI: https://app.transcend.io/data-map/data-inventory/processing-activities
#
# Pull:
# transcend inventory pull --auth="$TRANSCEND_API_KEY" --resources=processingActivities
# Push:
# transcend inventory push --auth="$TRANSCEND_API_KEY" --resources=processingActivities
processing-activities:
# TWDC CCTV RoPA acceptance fixture — round-trips via pull/push
- title: CCTV — Disney Italia Theme Park Entrances
description: On-premise CCTV surveillance…
controllerships: [CONTROLLER]
retention-type: LIMITED
data-protection-impact-assessment-status: MISSING
data-subject-types: [customer, employee]
team-names: [Security Operations]
processing-sub-purposes:
- purpose: OPERATION_SECURITY
- purpose: ESSENTIAL
data-sub-categories:
- category: OTHER
name: Security-Physical
- category: CONTACT
name: Image
storage-regions:
- country: IT
transfer-regions:
- country: EU

- title: Chatbot AI
description: >-
A product that allows employees to chat with an informational AI Chatbot
that provides information
securityMeasureDetails: Data is transmitted with end-to-end encryption
security-measure-details: Data is transmitted with end-to-end encryption
controllerships:
- CONTROLLER
retentionType: UNSPECIFIED
dataProtectionImpactAssessmentStatus: MISSING
dataSiloTitles:
retention-type: UNSPECIFIED
data-protection-impact-assessment-status: MISSING
data-silo-titles:
- Algolia
- Aircall
dataSubjectTypes:
data-subject-types:
- employee
teamNames:
team-names:
- Product
ownerEmails:
owner-emails:
- alice@acme.com
processingSubPurposes:
processing-sub-purposes:
- purpose: ESSENTIAL
dataSubCategories:
data-sub-categories:
- category: CONTACT
name: Email
- category: ONLINE_ACTIVITY
name: Interaction Events
saaSCategories:
saas-categories:
- Artificial Intelligence

- title: Marketing Analytics
description: Data around how our website is used
controllerships:
- PROCESSOR
retentionType: UNSPECIFIED
dataProtectionImpactAssessmentStatus: MISSING
retention-type: UNSPECIFIED
data-protection-impact-assessment-status: MISSING
attributes:
- key: Source of Data
values:
- Online Tracking Technologies
- Social Media Integrations
dataSiloTitles:
data-silo-titles:
- Adobe Experience Platform
- AdRoll
teamNames:
team-names:
- Marketing
ownerEmails:
owner-emails:
- bill@acme.com
processingSubPurposes:
processing-sub-purposes:
- purpose: ANALYTICS
- purpose: MARKETING

- title: Onboarding
description: >-
The process of onboarding new hires through a number of interactive
lessons, both sync and async
retentionType: UNSPECIFIED
dataProtectionImpactAssessmentLink: https://example.com
dataProtectionImpactAssessmentStatus: LINK
dataSiloTitles:
retention-type: UNSPECIFIED
data-protection-impact-assessment-link: https://example.com
data-protection-impact-assessment-status: LINK
data-silo-titles:
- Adobe Analytics
- ADP
ownerEmails:
owner-emails:
- charlie@acme.com
processingSubPurposes:
processing-sub-purposes:
- purpose: HR

- title: Recruiting
description: >-
Our recruitment pipeline includes the use of several different tools and
processes to find, vet, and hire candidates
storageRegions:
storage-regions:
- country: US
transferRegions:
transfer-regions:
- country: US
countrySubDivision: US-NJ
retentionType: STATED_PERIOD
retentionPeriod: 90
dataProtectionImpactAssessmentStatus: MISSING
dataSiloTitles:
retention-type: STATED_PERIOD
retention-period: 90
data-protection-impact-assessment-status: MISSING
data-silo-titles:
- Adobe
ownerEmails:
owner-emails:
- delilah@acme.com
- eric@acme.com
processingSubPurposes:
processing-sub-purposes:
- purpose: HR
name: Recruiting
- purpose: HR
28 changes: 14 additions & 14 deletions packages/cli/schema/transcend-yml-schema-latest.json
Original file line number Diff line number Diff line change
Expand Up @@ -43395,7 +43395,7 @@
"description": {
"type": "string"
},
"securityMeasureDetails": {
"security-measure-details": {
"type": "string"
},
"controllerships": {
Expand All @@ -43405,7 +43405,7 @@
"enum": ["CONTROLLER", "PROCESSOR", "JOINT_CONTROLLER"]
}
},
"storageRegions": {
"storage-regions": {
"type": "array",
"items": {
"type": "object",
Expand Down Expand Up @@ -48806,7 +48806,7 @@
}
}
},
"transferRegions": {
"transfer-regions": {
"type": "array",
"items": {
"type": "object",
Expand Down Expand Up @@ -54207,17 +54207,17 @@
}
}
},
"retentionType": {
"retention-type": {
"type": "string",
"enum": ["STATED_PERIOD", "LIMITED", "INDEFINITE", "OTHER", "UNSPECIFIED"]
},
"retentionPeriod": {
"retention-period": {
"type": "number"
},
"dataProtectionImpactAssessmentLink": {
"data-protection-impact-assessment-link": {
"type": "string"
},
"dataProtectionImpactAssessmentStatus": {
"data-protection-impact-assessment-status": {
"type": "string",
"enum": ["LINK", "NOT_REQUIRED", "MISSING"]
},
Expand All @@ -54239,31 +54239,31 @@
}
}
},
"dataSiloTitles": {
"data-silo-titles": {
"type": "array",
"items": {
"type": "string"
}
},
"dataSubjectTypes": {
"data-subject-types": {
"type": "array",
"items": {
"type": "string"
}
},
"teamNames": {
"team-names": {
"type": "array",
"items": {
"type": "string"
}
},
"ownerEmails": {
"owner-emails": {
"type": "array",
"items": {
"type": "string"
}
},
"processingSubPurposes": {
"processing-sub-purposes": {
"type": "array",
"items": {
"allOf": [
Expand Down Expand Up @@ -54302,7 +54302,7 @@
]
}
},
"dataSubCategories": {
"data-sub-categories": {
"type": "array",
"items": {
"allOf": [
Expand Down Expand Up @@ -54345,7 +54345,7 @@
]
}
},
"saaSCategories": {
"saas-categories": {
"type": "array",
"items": {
"type": "string"
Expand Down
Loading
Loading