Masterplan Optimiser

General audience · data protection

How MP-OPT supports GDPR and Swiss FADP work

MP-OPT supplies technical controls and accountable workflows that a controller can use in a GDPR/FADP programme. It does not certify a deployment, choose its legal basis, validate its contracts or make it automatically compliant.

Deployment-specific responsibility: every installation has its own controller and generated notice. Provider, country, transfer, feature and retention facts come from that controller's reviewed publication—not from the software maintainer or a generic example.

Engineering support

Data minimisation

Operational field categories, explicit public/authenticated audiences, unsupported sensitive-data guidance and deliberate publication boundaries.

Transparency

Deployment-generated privacy, rights, retention, processor and permitted-data notices based on facts published by that deployment.

Access control

Passkeys, scoped roles, bounded sessions, reauthentication and event-level authorisation enforced by the Server.

Retention and erasure

Controller-selected periods, scheduled review, user and whole-event deletion cases, Desktop work orders, snapshot resolution and external-copy confirmation.

Security and resilience

Protected secrets, signed releases, TLS, encrypted recovery snapshots, optional two-node HA and guarded restore workflows.

Accountability

Separate controller, processor, root and instance trust domains; append-only signed evidence; portable chain verification.

Layered security stack

No single control is treated as sufficient; each layer limits or detects a different failure.

Protected sourceReviews, Code Owners and qualified CI
Signed deliveryTags, checksums, manifests, SBOMs and Sigstore
Runtime boundaryTLS, Caddy, unprivileged containers and protected secrets
IdentityPasskeys, roles, sessions, CSRF and reauthentication
Data controlsAudience rules, retention, deletion and encrypted recovery
ResilienceHA fencing, peer verification and independent snapshots
EvidenceDomain signatures and append-only chain verification

Deletion proceeds on parallel accountable tracks

A case completes only after every applicable track has evidence or an explicit bounded resolution.

Server

Purge live data; record HA peer confirmation

Desktop

Delete event/person data; resolve local exports

Recovery

Create clean replacement; remove only pre-purge local snapshots

External copies

Operator confirms copies outside controlled systems

Evidence

Verify every required digest before root closure

Evidence sealing and portable verification

The exported ZIP carries the chain, public keys and verification result; private keys never belong in it.

  1. 1

    Canonical record

    Bounded facts and receipt digests

  2. 2

    Domain signature

    Controller, processor, root action or instance seal as applicable

  3. 3

    Chain link

    Previous digest and current record digest

  4. 4

    Evidence repository

    Append-only archive or guarded private mirror

  5. 5

    Portable ZIP

    Records, public keys and verification report

  6. 6

    Offline verifier

    Checks every signature, link and required artifact

What root and controller must do

  1. 01Determine which laws apply, who the controller is, the purposes and lawful bases or Swiss justification, and whether a DPIA or other assessment is needed.
  2. 02Declare the real controller, privacy contact, processors, providers, countries, transfers, enabled features and retention periods. MP-OPT does not infer them.
  3. 03Review provider contracts, SMTP and infrastructure processing, Cloudflare configuration, host/CDN/network logging and any international-transfer safeguards.
  4. 04Publish and keep the deployment notices current. SMTP, HA, retention, provider or purpose changes can make a new immutable governance version necessary.
  5. 05Limit event data to necessary operational information, handle rights requests and incidents, and ensure organisers understand the permitted-data boundary.
  6. 06Maintain recovery custody, test restoration, inventory workstation exports and external copies, and resolve those copies during deletion workflows.
  7. 07Treat signatures as proof of exact statements and chain integrity—not proof that an undeclared device, provider or physical copy was deleted.

Primary legal texts and implementation guides

The GDPR places responsibility and accountability on the controller and requires appropriate technical and organisational measures, including data protection by design and by default. The Swiss FADP likewise governs processing by private persons and federal bodies. Applicability and the appropriate measures depend on the real deployment and should be assessed by the controller or qualified counsel.