{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","download":{"releaseId":"sha256:8cdb4bef046dcc89c6dae94f58d685e3496d3500624d64450b593428709c9768","slug":"reg-personal-data-quality-deidentification","url":"/assets/agent_workflow-reg-personal-data-quality-deidentification-0bb15cbf.1c7db0bd064df86d.json"},"kind":"record","record":{"attributes":{"department":"privacy","domain":"reg","lineOfDefense":"operate"},"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=reg-personal-data-quality-deidentification","description":"Personal Data Quality & De-identification runs as a recurring operate cycle attached to the existing Control for personal-data quality & de-identification (framework gdpr/hipaa/ccpa/nist-800-53, domain data_protection_privacy): each period is a workflow instance that enriches that Control's operating record — never a new Control. The cycle consumes the data map / RoPA, the data-quality ruleset and retention schedule (Policy items), the individual correction-request queue, the disclosure log and the recipient/processor Vendor register, and the de-identification policy; it checks PII accuracy, relevance, timeliness, and completeness, corrects or deletes failing records and notifies downstream recipients under GDPR Art. 19, adjudicates individual correction requests within statutory deadlines, and de-identifies datasets that do not require full identifiers. It produces the exception register (exception Issue items), the corrected-and-deleted set, the recipient correction/deletion notices, and the de-identification and residual-risk reports; systemic findings hand off to the internal privacy backlog as Issue items. This is a terminal operate cycle — the archived, regulator-ready cycle record is the deliverable, not a handoff package for a named downstream workflow.","details":{"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=reg-personal-data-quality-deidentification","capabilities":[],"controls":["UC-DATA-07","UC-DATA-12"],"domains":["reg"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:8cdb4bef046dcc89c6dae94f58d685e3496d3500624d64450b593428709c9768","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:reg-personal-data-quality-deidentification","standards":["gdpr","ccpa","hipaa","nist-800-53"],"teams":["privacy"]},"download":{"releaseId":"sha256:8cdb4bef046dcc89c6dae94f58d685e3496d3500624d64450b593428709c9768"},"history":{"digest":"788d2820e0eab1b3c4bf71170ac83bc413e18cbce302e2f3cd6e3800154baf4b","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-10-04T21:48:26Z","updatedRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4"},"id":"wf:R10","mapUrl":"https://evidenceflows.com/?v=1&node=wf%3AR10","slug":"reg-personal-data-quality-deidentification","sourceIds":["aiuc-1","ccpa","hipaa","iso-27001","nist-800-53","soc2"],"sourceUrl":null,"title":"Personal Data Quality & De-identification","type":"workflow"},"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:0059f91f380a53e6d32b3a6fba91ea68eaa30bd7f98e807c5ab6d096b6d51c86","properties":{},"sourceDetailPath":"/data/v1/records/wf-r10-bc8bf886.json","sourceId":"wf:R10","targetDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","targetId":"uc:UC-DATA-12","type":"operates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:24223814b0af26a6a7bffe54a7395610ea8a9465ebc55bba9c3ada3d2a550911","properties":{},"sourceDetailPath":"/data/v1/records/wf-r10-bc8bf886.json","sourceId":"wf:R10","targetDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","targetId":"uc:UC-DATA-07","type":"operates"}],"schemaVersion":1}
