# 1. Regulatory Compliance — Test Cases

User Type: **Super Administrator**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: regulatory_compliance.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature,
  expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 1.1 GDPR (Europe) | Compliance: the compliance (the compliance, the rule, the data, the date) | TC-SA-22-01-001 |
| 1.1 GDPR (Europe) | Rule: the rule (the rule of the GDPR, the requirement, the date) | TC-SA-22-01-002 |
| 1.1 GDPR (Europe) | Data: the data (the data of the users, the type, the date) | TC-SA-22-01-003 |
| 1.1 GDPR (Europe) | Consent: the consent (the consent of the user, the date, the scope) | TC-SA-22-01-004 |
| 1.1 GDPR (Europe) | Compliance status: the status (the compliant, the non-compliant) | TC-SA-22-01-005 |
| 1.1 GDPR (Europe) | Compliance count: the count (the count of the rules by status) | TC-SA-22-01-006 |
| 1.1 GDPR (Europe) | Compliance view: the view (the compliances, the rules, the data, the dates) | TC-SA-22-01-007 |
| 1.1 GDPR (Europe) | Audit logging of the GDPR compliance | TC-SA-22-01-008 |
| 1.1 GDPR (Europe) | Rule: the compliance is the adherence (the compliance, the rule, the data, the date); the compliance is the conformity | TC-SA-22-01-001 |
| 1.1 GDPR (Europe) | Rule: the rule is the requirement (the rule of the GDPR, the requirement, the date); the rule is the law | TC-SA-22-01-002 |
| 1.1 GDPR (Europe) | Rule: the data is the subject (the data of the users, the type, the date); the data is the personal data | TC-SA-22-01-003 |
| 1.1 GDPR (Europe) | Rule: the consent is the permission (the consent of the user, the date, the scope); the consent is the agreement | TC-SA-22-01-004 |
| 1.1 GDPR (Europe) | Rule: the GDPR is compliant (the compliances, the rules, the data, the dates); the adherence is managed | TC-SA-22-01-007 |
| 1.1 GDPR (Europe) | Rule: GDPR compliance is audit-logged with the compliance, rule, and timestamp | TC-SA-22-01-008 |
| 1.2 POPIA (South Africa) | Compliance: the compliance (the compliance, the rule, the data, the date) | TC-SA-22-01-009 |
| 1.2 POPIA (South Africa) | Rule: the rule (the rule of the POPIA, the requirement, the date) | TC-SA-22-01-010 |
| 1.2 POPIA (South Africa) | Data: the data (the data of the users, the type, the date) | TC-SA-22-01-011 |
| 1.2 POPIA (South Africa) | Consent: the consent (the consent of the user, the date, the scope) | TC-SA-22-01-012 |
| 1.2 POPIA (South Africa) | Compliance status: the status (the compliant, the non-compliant) | TC-SA-22-01-013 |
| 1.2 POPIA (South Africa) | Compliance count: the count (the count of the rules by status) | TC-SA-22-01-014 |
| 1.2 POPIA (South Africa) | Compliance view: the view (the compliances, the rules, the data, the dates) | TC-SA-22-01-015 |
| 1.2 POPIA (South Africa) | Audit logging of the POPIA compliance | TC-SA-22-01-016 |
| 1.2 POPIA (South Africa) | Rule: the compliance is the adherence (the compliance, the rule, the data, the date); the compliance is the conformity | TC-SA-22-01-009 |
| 1.2 POPIA (South Africa) | Rule: the rule is the requirement (the rule of the POPIA, the requirement, the date); the rule is the law | TC-SA-22-01-010 |
| 1.2 POPIA (South Africa) | Rule: the data is the subject (the data of the users, the type, the date); the data is the personal data | TC-SA-22-01-011 |
| 1.2 POPIA (South Africa) | Rule: the consent is the permission (the consent of the user, the date, the scope); the consent is the agreement | TC-SA-22-01-012 |
| 1.2 POPIA (South Africa) | Rule: the POPIA is compliant (the compliances, the rules, the data, the dates); the adherence is managed | TC-SA-22-01-015 |
| 1.2 POPIA (South Africa) | Rule: POPIA compliance is audit-logged with the compliance, rule, and timestamp | TC-SA-22-01-016 |
| 1.3 COPPA (Children's Online Privacy) | Compliance: the compliance (the compliance, the rule, the child, the date) | TC-SA-22-01-017 |
| 1.3 COPPA (Children's Online Privacy) | Rule: the rule (the rule of the COPPA, the requirement, the date) | TC-SA-22-01-018 |
| 1.3 COPPA (Children's Online Privacy) | Child: the child (the child, the age, the date) | TC-SA-22-01-019 |
| 1.3 COPPA (Children's Online Privacy) | Parental consent: the consent (the consent of the parent, the date, the scope) | TC-SA-22-01-020 |
| 1.3 COPPA (Children's Online Privacy) | Compliance status: the status (the compliant, the non-compliant) | TC-SA-22-01-021 |
| 1.3 COPPA (Children's Online Privacy) | Compliance count: the count (the count of the rules by status) | TC-SA-22-01-022 |
| 1.3 COPPA (Children's Online Privacy) | Compliance view: the view (the compliances, the rules, the children, the dates) | TC-SA-22-01-023 |
| 1.3 COPPA (Children's Online Privacy) | Audit logging of the COPPA compliance | TC-SA-22-01-024 |
| 1.3 COPPA (Children's Online Privacy) | Rule: the compliance is the adherence (the compliance, the rule, the child, the date); the compliance is the conformity | TC-SA-22-01-017 |
| 1.3 COPPA (Children's Online Privacy) | Rule: the rule is the requirement (the rule of the COPPA, the requirement, the date); the rule is the law | TC-SA-22-01-018 |
| 1.3 COPPA (Children's Online Privacy) | Rule: the child is the minor (the child, the age, the date); the child is the protected user | TC-SA-22-01-019 |
| 1.3 COPPA (Children's Online Privacy) | Rule: the parental consent is the permission (the consent of the parent, the date, the scope); the consent is the agreement | TC-SA-22-01-020 |
| 1.3 COPPA (Children's Online Privacy) | Rule: the COPPA is compliant (the compliances, the rules, the children, the dates); the adherence is managed | TC-SA-22-01-023 |
| 1.3 COPPA (Children's Online Privacy) | Rule: COPPA compliance is audit-logged with the compliance, rule, and timestamp | TC-SA-22-01-024 |
| 1.4 FERPA (Educational Records) | Compliance: the compliance (the compliance, the rule, the record, the date) | TC-SA-22-01-025 |
| 1.4 FERPA (Educational Records) | Rule: the rule (the rule of the FERPA, the requirement, the date) | TC-SA-22-01-026 |
| 1.4 FERPA (Educational Records) | Record: the record (the record of the student, the type, the date) | TC-SA-22-01-027 |
| 1.4 FERPA (Educational Records) | Access: the access (the access to the record, the role, the date) | TC-SA-22-01-028 |
| 1.4 FERPA (Educational Records) | Compliance status: the status (the compliant, the non-compliant) | TC-SA-22-01-029 |
| 1.4 FERPA (Educational Records) | Compliance count: the count (the count of the rules by status) | TC-SA-22-01-030 |
| 1.4 FERPA (Educational Records) | Compliance view: the view (the compliances, the rules, the records, the dates) | TC-SA-22-01-031 |
| 1.4 FERPA (Educational Records) | Audit logging of the FERPA compliance | TC-SA-22-01-032 |
| 1.4 FERPA (Educational Records) | Rule: the compliance is the adherence (the compliance, the rule, the record, the date); the compliance is the conformity | TC-SA-22-01-025 |
| 1.4 FERPA (Educational Records) | Rule: the rule is the requirement (the rule of the FERPA, the requirement, the date); the rule is the law | TC-SA-22-01-026 |
| 1.4 FERPA (Educational Records) | Rule: the record is the educational record (the record of the student, the type, the date); the record is the data | TC-SA-22-01-027 |
| 1.4 FERPA (Educational Records) | Rule: the access is the permission (the access to the record, the role, the date); the access is the control | TC-SA-22-01-028 |
| 1.4 FERPA (Educational Records) | Rule: the FERPA is compliant (the compliances, the rules, the records, the dates); the adherence is managed | TC-SA-22-01-031 |
| 1.4 FERPA (Educational Records) | Rule: FERPA compliance is audit-logged with the compliance, rule, and timestamp | TC-SA-22-01-032 |

## 1.1 GDPR (Europe)

### TC-SA-22-01-001 — Compliance: the compliance (the compliance, the rule, the data, the date); the compliance is the conformity
**Type:** Positive
**Covers:** 1.1 → Compliance: the compliance (the compliance, the rule, the data, the date); Rule: the compliance is the adherence (the compliance, the rule, the data, the date); the compliance is the conformity
**Preconditions:** Super Admin is logged in; European users with personal data exist.
**Steps:**
1. Open Data Protection & Compliance → Regulatory Compliance → GDPR (Europe).
2. Comply with the GDPR: the compliance (the compliance, the rule, the data, the date) — verify the compliance is the adherence.
3. Verify the compliance shows the rule, the data, and the date.
4. Verify the compliance applies only to European users' data.
**Expected Result:** The GDPR compliance is recorded — the compliance, the rule, the data, and the date are the conformity.
**Priority:** Critical

### TC-SA-22-01-002 — Rule: the rule (the rule of the GDPR, the requirement, the date); the rule is the law
**Type:** Positive
**Covers:** 1.1 → Rule: the rule (the rule of the GDPR, the requirement, the date); Rule: the rule is the requirement (the rule of the GDPR, the requirement, the date); the rule is the law
**Preconditions:** GDPR rules are defined in the compliance register.
**Steps:**
1. Select the rule: the rule (the rule of the GDPR, the requirement, the date) — verify the rule is the requirement.
2. Verify the rule shows the requirement and the date.
3. Verify each rule maps to a documented GDPR obligation.
**Expected Result:** The rule is selected — the rule of the GDPR, the requirement, and the date are the law.
**Priority:** High

### TC-SA-22-01-003 — Data: the data (the data of the users, the type, the date); the data is the personal data
**Type:** Positive
**Covers:** 1.1 → Data: the data (the data of the users, the type, the date); Rule: the data is the subject (the data of the users, the type, the date); the data is the personal data
**Preconditions:** European users' personal data of multiple types exists.
**Steps:**
1. Select the data: the data (the data of the users, the type, the date) — verify the data is the subject.
2. Verify the data shows the type and the date.
3. Verify only personal data of European users is in scope.
**Expected Result:** The data is selected — the data of the users, the type, and the date are the personal data.
**Priority:** High

### TC-SA-22-01-004 — Consent: the consent (the consent of the user, the date, the scope); the consent is the agreement
**Type:** Edge
**Covers:** 1.1 → Consent: the consent (the consent of the user, the date, the scope); Rule: the consent is the permission (the consent of the user, the date, the scope); the consent is the agreement
**Preconditions:** European users exist; a user who has NOT given consent (no-consent edge) is also prepared.
**Steps:**
1. Set the consent: the consent (the consent of the user, the date, the scope) — verify the consent is the permission.
2. Verify the consent shows the date and the scope.
3. Attempt to process the no-consent user's personal data — verify the system blocks the processing (no consent = no processing); no data is touched.
**Expected Result:** The consent is set — the consent of the user, the date, and the scope are the agreement; processing without consent is blocked.
**Priority:** High

### TC-SA-22-01-005 — Compliance status: the status (the compliant, the non-compliant); the status is the state
**Type:** Positive
**Covers:** 1.1 → Compliance status: the status (the compliant, the non-compliant)
**Preconditions:** GDPR rules with compliant and non-compliant statuses exist.
**Steps:**
1. View the compliance status: the status (the compliant, the non-compliant) — verify the compliance status is the state.
2. Verify a rule shows compliant when its requirement is met.
3. Introduce a gap (e.g., missing consent record) — verify the rule flips to non-compliant immediately.
**Expected Result:** The compliance status is shown — the compliant and the non-compliant are the state; gaps are reflected immediately.
**Priority:** High

### TC-SA-22-01-006 — Compliance count: the count (the count of the rules by status); the count is the measure
**Type:** Positive
**Covers:** 1.1 → Compliance count: the count (the count of the rules by status)
**Preconditions:** Multiple GDPR rules with mixed statuses exist.
**Steps:**
1. View the compliance count: the count (the count of the rules by status) — verify the count is the measure.
2. Verify the count per status matches the actual number of rules in that status.
3. Verify the total equals the sum of the per-status counts.
**Expected Result:** The compliance count is shown — the count of the rules by status is the measure.
**Priority:** High

### TC-SA-22-01-007 — Compliance view: the view (the compliances, the rules, the data, the dates); the adherence is managed
**Type:** Positive
**Covers:** 1.1 → Compliance view: the view (the compliances, the rules, the data, the dates); Rule: the GDPR is compliant (the compliances, the rules, the data, the dates); the adherence is managed
**Preconditions:** Multiple GDPR compliance entries exist.
**Steps:**
1. View the compliances: the view (the compliances, the rules, the data, the dates) — verify the GDPR is compliant.
2. Verify each entry shows the rule, the data, and the date.
3. Verify the adherence is managed (view, remediate gaps, re-check).
**Expected Result:** The compliances are viewed — the compliances, the rules, the data, and the dates are visible; the adherence is managed.
**Priority:** High

### TC-SA-22-01-008 — GDPR compliance is audit-logged with the compliance, rule, and timestamp
**Type:** Positive
**Covers:** 1.1 → Audit logging of the GDPR compliance; Rule: GDPR compliance is audit-logged with the compliance, rule, and timestamp
**Preconditions:** Super Admin has recorded a GDPR compliance action.
**Steps:**
1. Open the audit trail and filter by "GDPR compliance".
2. Verify entries show the compliance, the rule, and the timestamp.
**Expected Result:** The GDPR compliance is audit-logged with the compliance, rule, and timestamp.
**Priority:** Critical

## 1.2 POPIA (South Africa)

### TC-SA-22-01-009 — Compliance: the compliance (the compliance, the rule, the data, the date); the compliance is the conformity
**Type:** Positive
**Covers:** 1.2 → Compliance: the compliance (the compliance, the rule, the data, the date); Rule: the compliance is the adherence (the compliance, the rule, the data, the date); the compliance is the conformity
**Preconditions:** Super Admin is logged in; South African users with personal data exist.
**Steps:**
1. Open Data Protection & Compliance → Regulatory Compliance → POPIA (South Africa).
2. Comply with the POPIA: the compliance (the compliance, the rule, the data, the date) — verify the compliance is the adherence.
3. Verify the compliance shows the rule, the data, and the date.
4. Verify the compliance applies only to South African users' data.
**Expected Result:** The POPIA compliance is recorded — the compliance, the rule, the data, and the date are the conformity.
**Priority:** Critical

### TC-SA-22-01-010 — Rule: the rule (the rule of the POPIA, the requirement, the date); the rule is the law
**Type:** Positive
**Covers:** 1.2 → Rule: the rule (the rule of the POPIA, the requirement, the date); Rule: the rule is the requirement (the rule of the POPIA, the requirement, the date); the rule is the law
**Preconditions:** POPIA rules are defined in the compliance register.
**Steps:**
1. Select the rule: the rule (the rule of the POPIA, the requirement, the date) — verify the rule is the requirement.
2. Verify the rule shows the requirement and the date.
3. Verify each rule maps to a documented POPIA obligation.
**Expected Result:** The rule is selected — the rule of the POPIA, the requirement, and the date are the law.
**Priority:** High

### TC-SA-22-01-011 — Data: the data (the data of the users, the type, the date); the data is the personal data
**Type:** Positive
**Covers:** 1.2 → Data: the data (the data of the users, the type, the date); Rule: the data is the subject (the data of the users, the type, the date); the data is the personal data
**Preconditions:** South African users' personal data of multiple types exists.
**Steps:**
1. Select the data: the data (the data of the users, the type, the date) — verify the data is the subject.
2. Verify the data shows the type and the date.
3. Verify only personal data of South African users is in scope.
**Expected Result:** The data is selected — the data of the users, the type, and the date are the personal data.
**Priority:** High

### TC-SA-22-01-012 — Consent: the consent (the consent of the user, the date, the scope); the consent is the agreement
**Type:** Edge
**Covers:** 1.2 → Consent: the consent (the consent of the user, the date, the scope); Rule: the consent is the permission (the consent of the user, the date, the scope); the consent is the agreement
**Preconditions:** South African users exist; a user who has NOT given consent (no-consent edge) is also prepared.
**Steps:**
1. Set the consent: the consent (the consent of the user, the date, the scope) — verify the consent is the permission.
2. Verify the consent shows the date and the scope.
3. Attempt to process the no-consent user's personal data — verify the system blocks the processing (no consent = no processing); no data is touched.
**Expected Result:** The consent is set — the consent of the user, the date, and the scope are the agreement; processing without consent is blocked.
**Priority:** High

### TC-SA-22-01-013 — Compliance status: the status (the compliant, the non-compliant); the status is the state
**Type:** Positive
**Covers:** 1.2 → Compliance status: the status (the compliant, the non-compliant)
**Preconditions:** POPIA rules with compliant and non-compliant statuses exist.
**Steps:**
1. View the compliance status: the status (the compliant, the non-compliant) — verify the compliance status is the state.
2. Verify a rule shows compliant when its requirement is met.
3. Introduce a gap — verify the rule flips to non-compliant immediately.
**Expected Result:** The compliance status is shown — the compliant and the non-compliant are the state; gaps are reflected immediately.
**Priority:** High

### TC-SA-22-01-014 — Compliance count: the count (the count of the rules by status); the count is the measure
**Type:** Positive
**Covers:** 1.2 → Compliance count: the count (the count of the rules by status)
**Preconditions:** Multiple POPIA rules with mixed statuses exist.
**Steps:**
1. View the compliance count: the count (the count of the rules by status) — verify the count is the measure.
2. Verify the count per status matches the actual number of rules in that status.
3. Verify the total equals the sum of the per-status counts.
**Expected Result:** The compliance count is shown — the count of the rules by status is the measure.
**Priority:** High

### TC-SA-22-01-015 — Compliance view: the view (the compliances, the rules, the data, the dates); the adherence is managed
**Type:** Positive
**Covers:** 1.2 → Compliance view: the view (the compliances, the rules, the data, the dates); Rule: the POPIA is compliant (the compliances, the rules, the data, the dates); the adherence is managed
**Preconditions:** Multiple POPIA compliance entries exist.
**Steps:**
1. View the compliances: the view (the compliances, the rules, the data, the dates) — verify the POPIA is compliant.
2. Verify each entry shows the rule, the data, and the date.
3. Verify the adherence is managed (view, remediate gaps, re-check).
**Expected Result:** The compliances are viewed — the compliances, the rules, the data, and the dates are visible; the adherence is managed.
**Priority:** High

### TC-SA-22-01-016 — POPIA compliance is audit-logged with the compliance, rule, and timestamp
**Type:** Positive
**Covers:** 1.2 → Audit logging of the POPIA compliance; Rule: POPIA compliance is audit-logged with the compliance, rule, and timestamp
**Preconditions:** Super Admin has recorded a POPIA compliance action.
**Steps:**
1. Open the audit trail and filter by "POPIA compliance".
2. Verify entries show the compliance, the rule, and the timestamp.
**Expected Result:** The POPIA compliance is audit-logged with the compliance, rule, and timestamp.
**Priority:** Critical

## 1.3 COPPA (Children's Online Privacy)

### TC-SA-22-01-017 — Compliance: the compliance (the compliance, the rule, the child, the date); the compliance is the conformity
**Type:** Positive
**Covers:** 1.3 → Compliance: the compliance (the compliance, the rule, the child, the date); Rule: the compliance is the adherence (the compliance, the rule, the child, the date); the compliance is the conformity
**Preconditions:** Super Admin is logged in; child accounts with parental consent exist.
**Steps:**
1. Open Data Protection & Compliance → Regulatory Compliance → COPPA (Children's Online Privacy).
2. Comply with the COPPA: the compliance (the compliance, the rule, the child, the date) — verify the compliance is the adherence.
3. Verify the compliance shows the rule, the child, and the date.
4. Verify the compliance applies only to children's data.
**Expected Result:** The COPPA compliance is recorded — the compliance, the rule, the child, and the date are the conformity.
**Priority:** Critical

### TC-SA-22-01-018 — Rule: the rule (the rule of the COPPA, the requirement, the date); the rule is the law
**Type:** Positive
**Covers:** 1.3 → Rule: the rule (the rule of the COPPA, the requirement, the date); Rule: the rule is the requirement (the rule of the COPPA, the requirement, the date); the rule is the law
**Preconditions:** COPPA rules are defined in the compliance register.
**Steps:**
1. Select the rule: the rule (the rule of the COPPA, the requirement, the date) — verify the rule is the requirement.
2. Verify the rule shows the requirement and the date.
3. Verify each rule maps to a documented COPPA obligation.
**Expected Result:** The rule is selected — the rule of the COPPA, the requirement, and the date are the law.
**Priority:** High

### TC-SA-22-01-019 — Child: the child (the child, the age, the date); the child is the protected user
**Type:** Edge
**Covers:** 1.3 → Child: the child (the child, the age, the date); Rule: the child is the minor (the child, the age, the date); the child is the protected user
**Preconditions:** Child accounts exist; a user claiming an age exactly at the COPPA boundary (age-boundary edge) is also prepared.
**Steps:**
1. Select the child: the child (the child, the age, the date) — verify the child is the minor.
2. Verify the child shows the age and the date.
3. Check the boundary-age user — verify the system classifies them correctly per the documented COPPA age threshold (no off-by-one misclassification); protected handling applies when in doubt.
**Expected Result:** The child is selected — the child, the age, and the date are the protected user; boundary ages are classified exactly per the documented threshold.
**Priority:** High

### TC-SA-22-01-020 — Parental consent: the consent (the consent of the parent, the date, the scope); the consent is the agreement
**Type:** Edge
**Covers:** 1.3 → Parental consent: the consent (the consent of the parent, the date, the scope); Rule: the parental consent is the permission (the consent of the parent, the date, the scope); the consent is the agreement
**Preconditions:** Child accounts exist; a child account with NO parental consent (no-consent edge) is also prepared.
**Steps:**
1. Set the parental consent: the consent (the consent of the parent, the date, the scope) — verify the parental consent is the permission.
2. Verify the consent shows the date and the scope.
3. Attempt to collect/process the no-consent child's data — verify the system blocks it (COPPA requires verifiable parental consent); no data is collected.
**Expected Result:** The parental consent is set — the consent of the parent, the date, and the scope are the agreement; child data processing without verifiable parental consent is blocked.
**Priority:** High

### TC-SA-22-01-021 — Compliance status: the status (the compliant, the non-compliant); the status is the state
**Type:** Positive
**Covers:** 1.3 → Compliance status: the status (the compliant, the non-compliant)
**Preconditions:** COPPA rules with compliant and non-compliant statuses exist.
**Steps:**
1. View the compliance status: the status (the compliant, the non-compliant) — verify the compliance status is the state.
2. Verify a rule shows compliant when its requirement is met.
3. Introduce a gap (e.g., a child account missing parental consent) — verify the rule flips to non-compliant immediately.
**Expected Result:** The compliance status is shown — the compliant and the non-compliant are the state; gaps are reflected immediately.
**Priority:** High

### TC-SA-22-01-022 — Compliance count: the count (the count of the rules by status); the count is the measure
**Type:** Positive
**Covers:** 1.3 → Compliance count: the count (the count of the rules by status)
**Preconditions:** Multiple COPPA rules with mixed statuses exist.
**Steps:**
1. View the compliance count: the count (the count of the rules by status) — verify the count is the measure.
2. Verify the count per status matches the actual number of rules in that status.
3. Verify the total equals the sum of the per-status counts.
**Expected Result:** The compliance count is shown — the count of the rules by status is the measure.
**Priority:** High

### TC-SA-22-01-023 — Compliance view: the view (the compliances, the rules, the children, the dates); the adherence is managed
**Type:** Positive
**Covers:** 1.3 → Compliance view: the view (the compliances, the rules, the children, the dates); Rule: the COPPA is compliant (the compliances, the rules, the children, the dates); the adherence is managed
**Preconditions:** Multiple COPPA compliance entries exist.
**Steps:**
1. View the compliances: the view (the compliances, the rules, the children, the dates) — verify the COPPA is compliant.
2. Verify each entry shows the rule, the child, and the date.
3. Verify the adherence is managed (view, remediate gaps, re-check).
**Expected Result:** The compliances are viewed — the compliances, the rules, the children, and the dates are visible; the adherence is managed.
**Priority:** High

### TC-SA-22-01-024 — COPPA compliance is audit-logged with the compliance, rule, and timestamp
**Type:** Positive
**Covers:** 1.3 → Audit logging of the COPPA compliance; Rule: COPPA compliance is audit-logged with the compliance, rule, and timestamp
**Preconditions:** Super Admin has recorded a COPPA compliance action.
**Steps:**
1. Open the audit trail and filter by "COPPA compliance".
2. Verify entries show the compliance, the rule, and the timestamp.
**Expected Result:** The COPPA compliance is audit-logged with the compliance, rule, and timestamp.
**Priority:** Critical

## 1.4 FERPA (Educational Records)

### TC-SA-22-01-025 — Compliance: the compliance (the compliance, the rule, the record, the date); the compliance is the conformity
**Type:** Positive
**Covers:** 1.4 → Compliance: the compliance (the compliance, the rule, the record, the date); Rule: the compliance is the adherence (the compliance, the rule, the record, the date); the compliance is the conformity
**Preconditions:** Super Admin is logged in; student educational records exist.
**Steps:**
1. Open Data Protection & Compliance → Regulatory Compliance → FERPA (Educational Records).
2. Comply with the FERPA: the compliance (the compliance, the rule, the record, the date) — verify the compliance is the adherence.
3. Verify the compliance shows the rule, the record, and the date.
4. Verify the compliance applies to educational records.
**Expected Result:** The FERPA compliance is recorded — the compliance, the rule, the record, and the date are the conformity.
**Priority:** Critical

### TC-SA-22-01-026 — Rule: the rule (the rule of the FERPA, the requirement, the date); the rule is the law
**Type:** Positive
**Covers:** 1.4 → Rule: the rule (the rule of the FERPA, the requirement, the date); Rule: the rule is the requirement (the rule of the FERPA, the requirement, the date); the rule is the law
**Preconditions:** FERPA rules are defined in the compliance register.
**Steps:**
1. Select the rule: the rule (the rule of the FERPA, the requirement, the date) — verify the rule is the requirement.
2. Verify the rule shows the requirement and the date.
3. Verify each rule maps to a documented FERPA obligation.
**Expected Result:** The rule is selected — the rule of the FERPA, the requirement, and the date are the law.
**Priority:** High

### TC-SA-22-01-027 — Record: the record (the record of the student, the type, the date); the record is the data
**Type:** Positive
**Covers:** 1.4 → Record: the record (the record of the student, the type, the date); Rule: the record is the educational record (the record of the student, the type, the date); the record is the data
**Preconditions:** Student educational records of multiple types exist.
**Steps:**
1. Select the record: the record (the record of the student, the type, the date) — verify the record is the educational record.
2. Verify the record shows the type and the date.
3. Verify the record is linked to the correct student.
**Expected Result:** The record is selected — the record of the student, the type, and the date are the data.
**Priority:** High

### TC-SA-22-01-028 — Access: the access (the access to the record, the role, the date); the access is the control
**Type:** Edge
**Covers:** 1.4 → Access: the access (the access to the record, the role, the date); Rule: the access is the permission (the access to the record, the role, the date); the access is the control
**Preconditions:** Educational records exist; a role WITHOUT FERPA access rights (unauthorized-role edge) is also prepared.
**Steps:**
1. Set the access: the access (the access to the record, the role, the date) — verify the access is the permission.
2. Verify the access shows the role and the date.
3. Attempt to open the record with the unauthorized role — verify the system denies access with a clear error; the record is never exposed.
**Expected Result:** The access is set — the access to the record, the role, and the date are the control; unauthorized roles are always denied.
**Priority:** High

### TC-SA-22-01-029 — Compliance status: the status (the compliant, the non-compliant); the status is the state
**Type:** Positive
**Covers:** 1.4 → Compliance status: the status (the compliant, the non-compliant)
**Preconditions:** FERPA rules with compliant and non-compliant statuses exist.
**Steps:**
1. View the compliance status: the status (the compliant, the non-compliant) — verify the compliance status is the state.
2. Verify a rule shows compliant when its requirement is met.
3. Introduce a gap (e.g., a record accessible to an unauthorized role) — verify the rule flips to non-compliant immediately.
**Expected Result:** The compliance status is shown — the compliant and the non-compliant are the state; gaps are reflected immediately.
**Priority:** High

### TC-SA-22-01-030 — Compliance count: the count (the count of the rules by status); the count is the measure
**Type:** Positive
**Covers:** 1.4 → Compliance count: the count (the count of the rules by status)
**Preconditions:** Multiple FERPA rules with mixed statuses exist.
**Steps:**
1. View the compliance count: the count (the count of the rules by status) — verify the count is the measure.
2. Verify the count per status matches the actual number of rules in that status.
3. Verify the total equals the sum of the per-status counts.
**Expected Result:** The compliance count is shown — the count of the rules by status is the measure.
**Priority:** High

### TC-SA-22-01-031 — Compliance view: the view (the compliances, the rules, the records, the dates); the adherence is managed
**Type:** Positive
**Covers:** 1.4 → Compliance view: the view (the compliances, the rules, the records, the dates); Rule: the FERPA is compliant (the compliances, the rules, the records, the dates); the adherence is managed
**Preconditions:** Multiple FERPA compliance entries exist.
**Steps:**
1. View the compliances: the view (the compliances, the rules, the records, the dates) — verify the FERPA is compliant.
2. Verify each entry shows the rule, the record, and the date.
3. Verify the adherence is managed (view, remediate gaps, re-check).
**Expected Result:** The compliances are viewed — the compliances, the rules, the records, and the dates are visible; the adherence is managed.
**Priority:** High

### TC-SA-22-01-032 — FERPA compliance is audit-logged with the compliance, rule, and timestamp
**Type:** Positive
**Covers:** 1.4 → Audit logging of the FERPA compliance; Rule: FERPA compliance is audit-logged with the compliance, rule, and timestamp
**Preconditions:** Super Admin has recorded a FERPA compliance action.
**Steps:**
1. Open the audit trail and filter by "FERPA compliance".
2. Verify entries show the compliance, the rule, and the timestamp.
**Expected Result:** The FERPA compliance is audit-logged with the compliance, rule, and timestamp.
**Priority:** Critical
