# 2. Data Handling — Test Cases

User Type: **Super Administrator**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: data_handling.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature,
  expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Encryption: the encryption (the encryption, the data, the type, the date) | TC-SA-22-02-001 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Data: the data (the data, the type, the date) | TC-SA-22-02-002 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Encryption type: the type (the type of the encryption, e.g., the at-rest, the in-transit) | TC-SA-22-02-003 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Encryption status: the status (the encrypted, the unencrypted) | TC-SA-22-02-004 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Encryption count: the count (the count of the data by status) | TC-SA-22-02-005 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Encryption view: the view (the encryptions, the data, the types, the dates) | TC-SA-22-02-006 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Encryption export: the export (the encryptions, the format, the type) | TC-SA-22-02-007 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Audit logging of the data encryption | TC-SA-22-02-008 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Rule: the encryption is the protection (the encryption, the data, the type, the date); the encryption is the shield | TC-SA-22-02-001 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Rule: the data is the subject (the data, the type, the date); the data is the content | TC-SA-22-02-002 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Rule: the encryption type is the mode (the type of the encryption, e.g., the at-rest, the in-transit); the type is the state | TC-SA-22-02-003 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Rule: the encryption status is the state (the encrypted, the unencrypted); the status is the control | TC-SA-22-02-004 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Rule: the data is protected (the encryptions, the data, the types, the dates); the protection is managed | TC-SA-22-02-006 |
| 2.1 Encrypted Data Storage (at Rest and in Transit) | Rule: data encryption is audit-logged with the encryption, type, and timestamp | TC-SA-22-02-008 |
| 2.2 Right to Access Personal Data | Access: the access (the access, the user, the data, the date) | TC-SA-22-02-009 |
| 2.2 Right to Access Personal Data | User: the user (the user, the name, the access) | TC-SA-22-02-010 |
| 2.2 Right to Access Personal Data | Data: the data (the data of the user, the type, the date) | TC-SA-22-02-011 |
| 2.2 Right to Access Personal Data | Access request: the request (the request, the user, the date) | TC-SA-22-02-012 |
| 2.2 Right to Access Personal Data | Access status: the status (the requested, the granted, the denied) | TC-SA-22-02-013 |
| 2.2 Right to Access Personal Data | Access count: the count (the count of the accesses) | TC-SA-22-02-014 |
| 2.2 Right to Access Personal Data | Access view: the view (the accesses, the users, the data, the dates) | TC-SA-22-02-015 |
| 2.2 Right to Access Personal Data | Audit logging of the data access | TC-SA-22-02-016 |
| 2.2 Right to Access Personal Data | Rule: the access is the right (the access, the user, the data, the date); the access is the permission | TC-SA-22-02-009 |
| 2.2 Right to Access Personal Data | Rule: the user is the owner (the user, the name, the access); the user is the subject | TC-SA-22-02-010 |
| 2.2 Right to Access Personal Data | Rule: the data is the personal data (the data of the user, the type, the date); the data is the content | TC-SA-22-02-011 |
| 2.2 Right to Access Personal Data | Rule: the access status is the state (the requested, the granted, the denied); the status is the control | TC-SA-22-02-013 |
| 2.2 Right to Access Personal Data | Rule: the data is accessible (the accesses, the users, the data, the dates); the right is managed | TC-SA-22-02-015 |
| 2.2 Right to Access Personal Data | Rule: data access is audit-logged with the access, user, and timestamp | TC-SA-22-02-016 |
| 2.3 Right to Deletion (Be Forgotten) | Deletion: the deletion (the deletion, the user, the data, the date) | TC-SA-22-02-017 |
| 2.3 Right to Deletion (Be Forgotten) | User: the user (the user, the name, the deletion) | TC-SA-22-02-018 |
| 2.3 Right to Deletion (Be Forgotten) | Data: the data (the data of the user, the type, the date) | TC-SA-22-02-019 |
| 2.3 Right to Deletion (Be Forgotten) | Deletion request: the request (the request, the user, the date) | TC-SA-22-02-020 |
| 2.3 Right to Deletion (Be Forgotten) | Deletion status: the status (the requested, the deleted, the pending) | TC-SA-22-02-021 |
| 2.3 Right to Deletion (Be Forgotten) | Deletion count: the count (the count of the deletions) | TC-SA-22-02-022 |
| 2.3 Right to Deletion (Be Forgotten) | Deletion view: the view (the deletions, the users, the data, the dates) | TC-SA-22-02-023 |
| 2.3 Right to Deletion (Be Forgotten) | Audit logging of the data deletion | TC-SA-22-02-024 |
| 2.3 Right to Deletion (Be Forgotten) | Rule: the deletion is the right (the deletion, the user, the data, the date); the deletion is the erasure | TC-SA-22-02-017 |
| 2.3 Right to Deletion (Be Forgotten) | Rule: the user is the owner (the user, the name, the deletion); the user is the subject | TC-SA-22-02-018 |
| 2.3 Right to Deletion (Be Forgotten) | Rule: the data is the personal data (the data of the user, the type, the date); the data is the content | TC-SA-22-02-019 |
| 2.3 Right to Deletion (Be Forgotten) | Rule: the deletion status is the state (the requested, the deleted, the pending); the status is the control | TC-SA-22-02-021 |
| 2.3 Right to Deletion (Be Forgotten) | Rule: the data is deleted (the deletions, the users, the data, the dates); the right is managed | TC-SA-22-02-023 |
| 2.3 Right to Deletion (Be Forgotten) | Rule: data deletion is audit-logged with the deletion, user, and timestamp | TC-SA-22-02-024 |
| 2.4 Data Portability | Portability: the portability (the portability, the user, the data, the format) | TC-SA-22-02-025 |
| 2.4 Data Portability | User: the user (the user, the name, the portability) | TC-SA-22-02-026 |
| 2.4 Data Portability | Data: the data (the data of the user, the type, the date) | TC-SA-22-02-027 |
| 2.4 Data Portability | Format: the format (the format of the data, e.g., the JSON, the CSV) | TC-SA-22-02-028 |
| 2.4 Data Portability | Portability status: the status (the requested, the exported, the completed) | TC-SA-22-02-029 |
| 2.4 Data Portability | Portability count: the count (the count of the portabilities) | TC-SA-22-02-030 |
| 2.4 Data Portability | Portability view: the view (the portabilities, the users, the data, the formats) | TC-SA-22-02-031 |
| 2.4 Data Portability | Audit logging of the data portability | TC-SA-22-02-032 |
| 2.4 Data Portability | Rule: the portability is the transfer (the portability, the user, the data, the format); the portability is the move | TC-SA-22-02-025 |
| 2.4 Data Portability | Rule: the user is the owner (the user, the name, the portability); the user is the subject | TC-SA-22-02-026 |
| 2.4 Data Portability | Rule: the data is the personal data (the data of the user, the type, the date); the data is the content | TC-SA-22-02-027 |
| 2.4 Data Portability | Rule: the format is the structure (the format of the data, e.g., the JSON, the CSV); the format is the shape | TC-SA-22-02-028 |
| 2.4 Data Portability | Rule: the data is portable (the portabilities, the users, the data, the formats); the transfer is managed | TC-SA-22-02-031 |
| 2.4 Data Portability | Rule: data portability is audit-logged with the portability, user, and timestamp | TC-SA-22-02-032 |
| 2.5 Consent Management | Consent: the consent (the consent, the user, the scope, the date) | TC-SA-22-02-033 |
| 2.5 Consent Management | User: the user (the user, the name, the consent) | TC-SA-22-02-034 |
| 2.5 Consent Management | Scope: the scope (the scope of the consent, e.g., the marketing, the analytics) | TC-SA-22-02-035 |
| 2.5 Consent Management | Consent status: the status (the granted, the withdrawn, the pending) | TC-SA-22-02-036 |
| 2.5 Consent Management | Consent count: the count (the count of the consents) | TC-SA-22-02-037 |
| 2.5 Consent Management | Consent view: the view (the consents, the users, the scopes, the dates) | TC-SA-22-02-038 |
| 2.5 Consent Management | Consent export: the export (the consents, the format, the scope) | TC-SA-22-02-039 |
| 2.5 Consent Management | Audit logging of the consent management | TC-SA-22-02-040 |
| 2.5 Consent Management | Rule: the consent is the permission (the consent, the user, the scope, the date); the consent is the agreement | TC-SA-22-02-033 |
| 2.5 Consent Management | Rule: the user is the owner (the user, the name, the consent); the user is the subject | TC-SA-22-02-034 |
| 2.5 Consent Management | Rule: the scope is the category (the scope of the consent, e.g., the marketing, the analytics); the scope is the segment | TC-SA-22-02-035 |
| 2.5 Consent Management | Rule: the consent status is the state (the granted, the withdrawn, the pending); the status is the control | TC-SA-22-02-036 |
| 2.5 Consent Management | Rule: the consent is managed (the consents, the users, the scopes, the dates); the control is managed | TC-SA-22-02-038 |
| 2.5 Consent Management | Rule: consent management is audit-logged with the consent, scope, and timestamp | TC-SA-22-02-040 |
| 2.6 Personal Data Anonymization | Anonymization: the anonymization (the anonymization, the data, the method, the date) | TC-SA-22-02-041 |
| 2.6 Personal Data Anonymization | Data: the data (the data, the type, the date) | TC-SA-22-02-042 |
| 2.6 Personal Data Anonymization | Method: the method (the method of the anonymization, e.g., the pseudonymization, the aggregation) | TC-SA-22-02-043 |
| 2.6 Personal Data Anonymization | Anonymization status: the status (the anonymized, the pending) | TC-SA-22-02-044 |
| 2.6 Personal Data Anonymization | Anonymization count: the count (the count of the anonymizations) | TC-SA-22-02-045 |
| 2.6 Personal Data Anonymization | Anonymization view: the view (the anonymizations, the data, the methods, the dates) | TC-SA-22-02-046 |
| 2.6 Personal Data Anonymization | Anonymization export: the export (the anonymizations, the format, the method) | TC-SA-22-02-047 |
| 2.6 Personal Data Anonymization | Audit logging of the data anonymization | TC-SA-22-02-048 |
| 2.6 Personal Data Anonymization | Rule: the anonymization is the protection (the anonymization, the data, the method, the date); the anonymization is the masking | TC-SA-22-02-041 |
| 2.6 Personal Data Anonymization | Rule: the data is the subject (the data, the type, the date); the data is the content | TC-SA-22-02-042 |
| 2.6 Personal Data Anonymization | Rule: the method is the technique (the method of the anonymization, e.g., the pseudonymization, the aggregation); the method is the approach | TC-SA-22-02-043 |
| 2.6 Personal Data Anonymization | Rule: the anonymization status is the state (the anonymized, the pending); the status is the control | TC-SA-22-02-044 |
| 2.6 Personal Data Anonymization | Rule: the data is anonymized (the anonymizations, the data, the methods, the dates); the protection is managed | TC-SA-22-02-046 |
| 2.6 Personal Data Anonymization | Rule: data anonymization is audit-logged with the anonymization, method, and timestamp | TC-SA-22-02-048 |

## 2.1 Encrypted Data Storage (at Rest and in Transit)

### TC-SA-22-02-001 — Encryption: the encryption (the encryption, the data, the type, the date); the encryption is the shield
**Type:** Positive
**Covers:** 2.1 → Encryption: the encryption (the encryption, the data, the type, the date); Rule: the encryption is the protection (the encryption, the data, the type, the date); the encryption is the shield
**Preconditions:** Super Admin is logged in; platform data exists.
**Steps:**
1. Open Data Protection & Compliance → Data Handling → Encrypted Data Storage.
2. Encrypt the data storage: the encryption (the encryption, the data, the type, the date) — verify the encryption is the protection.
3. Verify the encryption shows the data, the type, and the date.
4. Verify both at-rest and in-transit encryption are active for the data.
**Expected Result:** The encryption is applied — the encryption, the data, the type, and the date are the shield.
**Priority:** Critical

### TC-SA-22-02-002 — Data: the data (the data, the type, the date); the data is the content
**Type:** Positive
**Covers:** 2.1 → Data: the data (the data, the type, the date); Rule: the data is the subject (the data, the type, the date); the data is the content
**Preconditions:** Multiple data types exist on the platform.
**Steps:**
1. Select the data: the data (the data, the type, the date) — verify the data is the subject.
2. Verify the data shows the type and the date.
3. Verify each data type is covered by the encryption scope.
**Expected Result:** The data is selected — the data, the type, and the date are the content.
**Priority:** High

### TC-SA-22-02-003 — Encryption type: the type (the type of the encryption, e.g., the at-rest, the in-transit); the type is the state
**Type:** Positive
**Covers:** 2.1 → Encryption type: the type (the type of the encryption, e.g., the at-rest, the in-transit); Rule: the encryption type is the mode (the type of the encryption, e.g., the at-rest, the in-transit); the type is the state
**Preconditions:** At-rest and in-transit encryption are configured.
**Steps:**
1. Set the encryption type: the type (the type of the encryption, e.g., the at-rest, the in-transit) — verify the encryption type is the mode.
2. Verify the at-rest type applies to stored data.
3. Verify the in-transit type applies to data moving between client and server.
**Expected Result:** The encryption type is set — the type of the encryption (the at-rest, the in-transit) is the state.
**Priority:** High

### TC-SA-22-02-004 — Encryption status: the status (the encrypted, the unencrypted); the status is the control
**Type:** Edge
**Covers:** 2.1 → Encryption status: the status (the encrypted, the unencrypted); Rule: the encryption status is the state (the encrypted, the unencrypted); the status is the control
**Preconditions:** Encrypted data exists; a newly created data store that has not yet been encrypted (unencrypted edge) is also prepared.
**Steps:**
1. View the encryption status: the status (the encrypted, the unencrypted) — verify the encryption status is the state.
2. Verify existing data shows encrypted.
3. Check the new unencrypted data store — verify it is flagged as unencrypted with an alert (never silently unencrypted); the system either encrypts it automatically or raises a visible warning.
**Expected Result:** The encryption status is shown — the encrypted and the unencrypted are the control; no data is ever silently left unencrypted.
**Priority:** High

### TC-SA-22-02-005 — Encryption count: the count (the count of the data by status); the count is the measure
**Type:** Positive
**Covers:** 2.1 → Encryption count: the count (the count of the data by status)
**Preconditions:** Data with encrypted and unencrypted statuses exists.
**Steps:**
1. View the encryption count: the count (the count of the data by status) — verify the count is the measure.
2. Verify the count per status matches the actual number of data items in that status.
3. Verify the total equals the sum of the per-status counts.
**Expected Result:** The encryption count is shown — the count of the data by status is the measure.
**Priority:** High

### TC-SA-22-02-006 — Encryption view: the view (the encryptions, the data, the types, the dates); the protection is managed
**Type:** Positive
**Covers:** 2.1 → Encryption view: the view (the encryptions, the data, the types, the dates); Rule: the data is protected (the encryptions, the data, the types, the dates); the protection is managed
**Preconditions:** Multiple encrypted data items exist.
**Steps:**
1. View the encryptions: the view (the encryptions, the data, the types, the dates) — verify the data is protected.
2. Verify each entry shows the data, the type, and the date.
3. Verify the protection is managed (view, verify, remediate gaps).
**Expected Result:** The encryptions are viewed — the encryptions, the data, the types, and the dates are visible; the protection is managed.
**Priority:** High

### TC-SA-22-02-007 — Encryption export: the export (the encryptions, the format, the type); the export is the record
**Type:** Edge
**Covers:** 2.1 → Encryption export: the export (the encryptions, the format, the type)
**Preconditions:** Encrypted data exists for multiple types; a type with no encrypted data (zero-row export edge) is also prepared.
**Steps:**
1. Export the encryptions: the export (the encryptions, the format, the type) — verify the export is the record.
2. Verify the export contains all encryption records for the selected type in the selected format.
3. Export the empty type — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The encryptions are exported — the encryptions, the format, and the type are the record; empty-type exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-02-008 — Data encryption is audit-logged with the encryption, type, and timestamp
**Type:** Positive
**Covers:** 2.1 → Audit logging of the data encryption; Rule: data encryption is audit-logged with the encryption, type, and timestamp
**Preconditions:** Super Admin has applied data encryption.
**Steps:**
1. Open the audit trail and filter by "data encryption".
2. Verify entries show the encryption, the type, and the timestamp.
**Expected Result:** The data encryption is audit-logged with the encryption, type, and timestamp.
**Priority:** Critical

## 2.2 Right to Access Personal Data

### TC-SA-22-02-009 — Access: the access (the access, the user, the data, the date); the access is the permission
**Type:** Positive
**Covers:** 2.2 → Access: the access (the access, the user, the data, the date); Rule: the access is the right (the access, the user, the data, the date); the access is the permission
**Preconditions:** Super Admin is logged in; a user has requested access to their personal data.
**Steps:**
1. Open Data Protection & Compliance → Data Handling → Right to Access Personal Data.
2. Provide the access: the access (the access, the user, the data, the date) — verify the access is the right.
3. Verify the access shows the user, the data, and the date.
4. Grant the access — verify the user receives a complete copy of their personal data.
**Expected Result:** The access is provided — the access, the user, the data, and the date are the permission.
**Priority:** Critical

### TC-SA-22-02-010 — User: the user (the user, the name, the access); the user is the subject
**Type:** Positive
**Covers:** 2.2 → User: the user (the user, the name, the access); Rule: the user is the owner (the user, the name, the access); the user is the subject
**Preconditions:** Multiple users have access requests.
**Steps:**
1. Select the user: the user (the user, the name, the access) — verify the user is the owner.
2. Verify the user shows the name and the access.
3. Verify the access is granted only to the requesting user's own data (never another user's data).
**Expected Result:** The user is selected — the user, the name, and the access are the subject; users can only access their own personal data.
**Priority:** High

### TC-SA-22-02-011 — Data: the data (the data of the user, the type, the date); the data is the content
**Type:** Positive
**Covers:** 2.2 → Data: the data (the data of the user, the type, the date); Rule: the data is the personal data (the data of the user, the type, the date); the data is the content
**Preconditions:** A user's personal data of multiple types exists.
**Steps:**
1. Select the data: the data (the data of the user, the type, the date) — verify the data is the personal data.
2. Verify the data shows the type and the date.
3. Verify the access response includes ALL personal data types held for that user (no type silently omitted).
**Expected Result:** The data is selected — the data of the user, the type, and the date are the content; the access response is complete.
**Priority:** High

### TC-SA-22-02-012 — Access request: the request (the request, the user, the date); the request is the ask
**Type:** Positive
**Covers:** 2.2 → Access request: the request (the request, the user, the date)
**Preconditions:** A user has submitted an access request.
**Steps:**
1. View the access request: the request (the request, the user, the date) — verify the request is the ask.
2. Verify the request shows the user and the date.
3. Verify the request is linked to the correct user account.
**Expected Result:** The access request is shown — the request, the user, and the date are the ask.
**Priority:** High

### TC-SA-22-02-013 — Access status: the status (the requested, the granted, the denied); the status is the control
**Type:** Edge
**Covers:** 2.2 → Access status: the status (the requested, the granted, the denied); Rule: the access status is the state (the requested, the granted, the denied); the status is the control
**Preconditions:** Access requests with requested, granted, and denied statuses exist; a request from an unverified/impersonating identity (identity-mismatch edge) is also prepared.
**Steps:**
1. View the access status: the status (the requested, the granted, the denied) — verify the access status is the state.
2. Verify a valid request moves requested → granted when fulfilled.
3. Submit the identity-mismatch request — verify the system denies it (denied status with a reason); no data is leaked to the wrong party.
**Expected Result:** The access status is shown — the requested, the granted, and the denied are the control; impersonation attempts are denied with no data leakage.
**Priority:** High

### TC-SA-22-02-014 — Access count: the count (the count of the accesses); the count is the measure
**Type:** Positive
**Covers:** 2.2 → Access count: the count (the count of the accesses)
**Preconditions:** Multiple data accesses exist.
**Steps:**
1. View the access count: the count (the count of the accesses) — verify the count is the measure.
2. Verify the count matches the actual number of accesses.
3. Grant a new access — verify the count increments.
**Expected Result:** The access count is shown — the count of the accesses is the measure.
**Priority:** High

### TC-SA-22-02-015 — Access view: the view (the accesses, the users, the data, the dates); the right is managed
**Type:** Positive
**Covers:** 2.2 → Access view: the view (the accesses, the users, the data, the dates); Rule: the data is accessible (the accesses, the users, the data, the dates); the right is managed
**Preconditions:** Multiple data accesses exist.
**Steps:**
1. View the accesses: the view (the accesses, the users, the data, the dates) — verify the data is accessible.
2. Verify each access shows the user, the data, and the date.
3. Verify the right is managed (view, fulfill, track).
**Expected Result:** The accesses are viewed — the accesses, the users, the data, and the dates are visible; the right is managed.
**Priority:** High

### TC-SA-22-02-016 — Data access is audit-logged with the access, user, and timestamp
**Type:** Positive
**Covers:** 2.2 → Audit logging of the data access; Rule: data access is audit-logged with the access, user, and timestamp
**Preconditions:** Super Admin has granted a data access.
**Steps:**
1. Open the audit trail and filter by "data access".
2. Verify entries show the access, the user, and the timestamp.
**Expected Result:** The data access is audit-logged with the access, user, and timestamp.
**Priority:** Critical

## 2.3 Right to Deletion (Be Forgotten)

### TC-SA-22-02-017 — Deletion: the deletion (the deletion, the user, the data, the date); the deletion is the erasure
**Type:** Positive
**Covers:** 2.3 → Deletion: the deletion (the deletion, the user, the data, the date); Rule: the deletion is the right (the deletion, the user, the data, the date); the deletion is the erasure
**Preconditions:** Super Admin is logged in; a user has requested deletion of their personal data.
**Steps:**
1. Open Data Protection & Compliance → Data Handling → Right to Deletion (Be Forgotten).
2. Perform the deletion: the deletion (the deletion, the user, the data, the date) — verify the deletion is the right.
3. Verify the deletion shows the user, the data, and the date.
4. Execute the deletion — verify the user's personal data is erased from the platform.
**Expected Result:** The deletion is performed — the deletion, the user, the data, and the date are the erasure.
**Priority:** Critical

### TC-SA-22-02-018 — User: the user (the user, the name, the deletion); the user is the subject
**Type:** Positive
**Covers:** 2.3 → User: the user (the user, the name, the deletion); Rule: the user is the owner (the user, the name, the deletion); the user is the subject
**Preconditions:** Multiple users have deletion requests.
**Steps:**
1. Select the user: the user (the user, the name, the deletion) — verify the user is the owner.
2. Verify the user shows the name and the deletion.
3. Verify the deletion affects ONLY the requesting user's data (no other user's data is touched).
**Expected Result:** The user is selected — the user, the name, and the deletion are the subject; deletions are strictly scoped to the requesting user.
**Priority:** High

### TC-SA-22-02-019 — Data: the data (the data of the user, the type, the date); the data is the content
**Type:** Edge
**Covers:** 2.3 → Data: the data (the data of the user, the type, the date); Rule: the data is the personal data (the data of the user, the type, the date); the data is the content
**Preconditions:** A user's personal data of multiple types exists; data with legal retention obligations (retention-conflict edge) is also prepared.
**Steps:**
1. Select the data: the data (the data of the user, the type, the date) — verify the data is the personal data.
2. Verify the data shows the type and the date.
3. Request deletion of the retention-protected data — verify the system applies the documented retention rule (keeps only what the law requires, deletes the rest, and explains the exception); no silent full deletion, no silent full retention.
**Expected Result:** The data is selected — the data of the user, the type, and the date are the content; retention conflicts are resolved per the documented rule with a clear explanation.
**Priority:** High

### TC-SA-22-02-020 — Deletion request: the request (the request, the user, the date); the request is the ask
**Type:** Positive
**Covers:** 2.3 → Deletion request: the request (the request, the user, the date)
**Preconditions:** A user has submitted a deletion request.
**Steps:**
1. View the deletion request: the request (the request, the user, the date) — verify the request is the ask.
2. Verify the request shows the user and the date.
3. Verify the request is linked to the correct user account.
**Expected Result:** The deletion request is shown — the request, the user, and the date are the ask.
**Priority:** High

### TC-SA-22-02-021 — Deletion status: the status (the requested, the deleted, the pending); the status is the control
**Type:** Positive
**Covers:** 2.3 → Deletion status: the status (the requested, the deleted, the pending); Rule: the deletion status is the state (the requested, the deleted, the pending); the status is the control
**Preconditions:** Deletion requests with requested, deleted, and pending statuses exist.
**Steps:**
1. View the deletion status: the status (the requested, the deleted, the pending) — verify the deletion status is the state.
2. Verify a requested deletion moves to pending while processing.
3. Verify it moves to deleted when the erasure is complete and verifiable.
**Expected Result:** The deletion status is shown — the requested, the deleted, and the pending are the control.
**Priority:** High

### TC-SA-22-02-022 — Deletion count: the count (the count of the deletions); the count is the measure
**Type:** Positive
**Covers:** 2.3 → Deletion count: the count (the count of the deletions)
**Preconditions:** Multiple deletions exist.
**Steps:**
1. View the deletion count: the count (the count of the deletions) — verify the count is the measure.
2. Verify the count matches the actual number of deletions.
3. Complete a new deletion — verify the count increments.
**Expected Result:** The deletion count is shown — the count of the deletions is the measure.
**Priority:** High

### TC-SA-22-02-023 — Deletion view: the view (the deletions, the users, the data, the dates); the right is managed
**Type:** Positive
**Covers:** 2.3 → Deletion view: the view (the deletions, the users, the data, the dates); Rule: the data is deleted (the deletions, the users, the data, the dates); the right is managed
**Preconditions:** Multiple deletions exist.
**Steps:**
1. View the deletions: the view (the deletions, the users, the data, the dates) — verify the data is deleted.
2. Verify each deletion shows the user, the data, and the date.
3. Verify the right is managed (view, process, verify erasure).
**Expected Result:** The deletions are viewed — the deletions, the users, the data, and the dates are visible; the right is managed.
**Priority:** High

### TC-SA-22-02-024 — Data deletion is audit-logged with the deletion, user, and timestamp
**Type:** Positive
**Covers:** 2.3 → Audit logging of the data deletion; Rule: data deletion is audit-logged with the deletion, user, and timestamp
**Preconditions:** Super Admin has performed a data deletion.
**Steps:**
1. Open the audit trail and filter by "data deletion".
2. Verify entries show the deletion, the user, and the timestamp.
**Expected Result:** The data deletion is audit-logged with the deletion, user, and timestamp.
**Priority:** Critical

## 2.4 Data Portability

### TC-SA-22-02-025 — Portability: the portability (the portability, the user, the data, the format); the portability is the move
**Type:** Positive
**Covers:** 2.4 → Portability: the portability (the portability, the user, the data, the format); Rule: the portability is the transfer (the portability, the user, the data, the format); the portability is the move
**Preconditions:** Super Admin is logged in; a user has requested data portability.
**Steps:**
1. Open Data Protection & Compliance → Data Handling → Data Portability.
2. Provide the portability: the portability (the portability, the user, the data, the format) — verify the portability is the transfer.
3. Verify the portability shows the user, the data, and the format.
4. Execute the export — verify the user receives their data in the requested format.
**Expected Result:** The portability is provided — the portability, the user, the data, and the format are the move.
**Priority:** Critical

### TC-SA-22-02-026 — User: the user (the user, the name, the portability); the user is the subject
**Type:** Positive
**Covers:** 2.4 → User: the user (the user, the name, the portability); Rule: the user is the owner (the user, the name, the portability); the user is the subject
**Preconditions:** Multiple users have portability requests.
**Steps:**
1. Select the user: the user (the user, the name, the portability) — verify the user is the owner.
2. Verify the user shows the name and the portability.
3. Verify the export contains only the requesting user's own data.
**Expected Result:** The user is selected — the user, the name, and the portability are the subject; exports are strictly scoped to the requesting user.
**Priority:** High

### TC-SA-22-02-027 — Data: the data (the data of the user, the type, the date); the data is the content
**Type:** Positive
**Covers:** 2.4 → Data: the data (the data of the user, the type, the date); Rule: the data is the personal data (the data of the user, the type, the date); the data is the content
**Preconditions:** A user's personal data of multiple types exists.
**Steps:**
1. Select the data: the data (the data of the user, the type, the date) — verify the data is the personal data.
2. Verify the data shows the type and the date.
3. Verify the portability export includes all personal data types held for that user.
**Expected Result:** The data is selected — the data of the user, the type, and the date are the content; the export is complete.
**Priority:** High

### TC-SA-22-02-028 — Format: the format (the format of the data, e.g., the JSON, the CSV); the format is the shape
**Type:** Edge
**Covers:** 2.4 → Format: the format (the format of the data, e.g., the JSON, the CSV); Rule: the format is the structure (the format of the data, e.g., the JSON, the CSV); the format is the shape
**Preconditions:** Portability requests exist; a request for an unsupported format (invalid-format edge) is also prepared.
**Steps:**
1. Set the format: the format (the format of the data, e.g., the JSON, the CSV) — verify the format is the structure.
2. Export in JSON — verify the file is valid, parseable JSON with all data intact.
3. Export in CSV — verify the file is valid, parseable CSV with all data intact.
4. Request the unsupported format — verify the system rejects it with a clear list of supported formats (no corrupt/partial file produced).
**Expected Result:** The format is set — the format of the data (the JSON, the CSV) is the shape; exports are always valid files, and unsupported formats are rejected cleanly.
**Priority:** High

### TC-SA-22-02-029 — Portability status: the status (the requested, the exported, the completed); the status is the state
**Type:** Positive
**Covers:** 2.4 → Portability status: the status (the requested, the exported, the completed)
**Preconditions:** Portability requests with requested, exported, and completed statuses exist.
**Steps:**
1. View the portability status: the status (the requested, the exported, the completed) — verify the portability status is the state.
2. Verify a requested portability moves to exported when the file is generated.
3. Verify it moves to completed when the user has received the data.
**Expected Result:** The portability status is shown — the requested, the exported, and the completed are the state.
**Priority:** High

### TC-SA-22-02-030 — Portability count: the count (the count of the portabilities); the count is the measure
**Type:** Positive
**Covers:** 2.4 → Portability count: the count (the count of the portabilities)
**Preconditions:** Multiple portabilities exist.
**Steps:**
1. View the portability count: the count (the count of the portabilities) — verify the count is the measure.
2. Verify the count matches the actual number of portabilities.
3. Complete a new portability — verify the count increments.
**Expected Result:** The portability count is shown — the count of the portabilities is the measure.
**Priority:** High

### TC-SA-22-02-031 — Portability view: the view (the portabilities, the users, the data, the formats); the transfer is managed
**Type:** Positive
**Covers:** 2.4 → Portability view: the view (the portabilities, the users, the data, the formats); Rule: the data is portable (the portabilities, the users, the data, the formats); the transfer is managed
**Preconditions:** Multiple portabilities exist.
**Steps:**
1. View the portabilities: the view (the portabilities, the users, the data, the formats) — verify the data is portable.
2. Verify each portability shows the user, the data, and the format.
3. Verify the transfer is managed (view, generate, deliver).
**Expected Result:** The portabilities are viewed — the portabilities, the users, the data, and the formats are visible; the transfer is managed.
**Priority:** High

### TC-SA-22-02-032 — Data portability is audit-logged with the portability, user, and timestamp
**Type:** Positive
**Covers:** 2.4 → Audit logging of the data portability; Rule: data portability is audit-logged with the portability, user, and timestamp
**Preconditions:** Super Admin has provided a data portability.
**Steps:**
1. Open the audit trail and filter by "data portability".
2. Verify entries show the portability, the user, and the timestamp.
**Expected Result:** The data portability is audit-logged with the portability, user, and timestamp.
**Priority:** Critical

## 2.5 Consent Management

### TC-SA-22-02-033 — Consent: the consent (the consent, the user, the scope, the date); the consent is the agreement
**Type:** Positive
**Covers:** 2.5 → Consent: the consent (the consent, the user, the scope, the date); Rule: the consent is the permission (the consent, the user, the scope, the date); the consent is the agreement
**Preconditions:** Super Admin is logged in; users have given consents.
**Steps:**
1. Open Data Protection & Compliance → Data Handling → Consent Management.
2. Manage the consent: the consent (the consent, the user, the scope, the date) — verify the consent is the permission.
3. Verify the consent shows the user, the scope, and the date.
4. Verify the consent is recorded with the exact scope the user agreed to.
**Expected Result:** The consent is managed — the consent, the user, the scope, and the date are the agreement.
**Priority:** Critical

### TC-SA-22-02-034 — User: the user (the user, the name, the consent); the user is the subject
**Type:** Positive
**Covers:** 2.5 → User: the user (the user, the name, the consent); Rule: the user is the owner (the user, the name, the consent); the user is the subject
**Preconditions:** Multiple users have consents.
**Steps:**
1. Select the user: the user (the user, the name, the consent) — verify the user is the owner.
2. Verify the user shows the name and the consent.
3. Verify each consent is tied to exactly one user (no consent is attributed to the wrong user).
**Expected Result:** The user is selected — the user, the name, and the consent are the subject.
**Priority:** High

### TC-SA-22-02-035 — Scope: the scope (the scope of the consent, e.g., the marketing, the analytics); the scope is the segment
**Type:** Positive
**Covers:** 2.5 → Scope: the scope (the scope of the consent, e.g., the marketing, the analytics); Rule: the scope is the category (the scope of the consent, e.g., the marketing, the analytics); the scope is the segment
**Preconditions:** Consents with marketing and analytics scopes exist.
**Steps:**
1. Set the scope: the scope (the scope of the consent, e.g., the marketing, the analytics) — verify the scope is the category.
2. Verify each consent shows its scope.
3. Verify consents can be filtered by scope.
**Expected Result:** The scope is set — the scope of the consent (the marketing, the analytics) is the segment.
**Priority:** High

### TC-SA-22-02-036 — Consent status: the status (the granted, the withdrawn, the pending); the status is the control
**Type:** Edge
**Covers:** 2.5 → Consent status: the status (the granted, the withdrawn, the pending); Rule: the consent status is the state (the granted, the withdrawn, the pending); the status is the control
**Preconditions:** Consents with granted, withdrawn, and pending statuses exist; a user who withdraws marketing consent while a marketing campaign is queued (withdrawal-timing edge) is also prepared.
**Steps:**
1. View the consent status: the status (the granted, the withdrawn, the pending) — verify the consent status is the state.
2. Verify a granted consent moves to withdrawn when the user revokes it.
3. Check the queued campaign for the withdrawing user — verify the user is excluded from the campaign immediately upon withdrawal (no message is sent after revocation).
**Expected Result:** The consent status is shown — the granted, the withdrawn, and the pending are the control; withdrawals take effect immediately, even for queued actions.
**Priority:** High

### TC-SA-22-02-037 — Consent count: the count (the count of the consents); the count is the measure
**Type:** Positive
**Covers:** 2.5 → Consent count: the count (the count of the consents)
**Preconditions:** Multiple consents exist.
**Steps:**
1. View the consent count: the count (the count of the consents) — verify the count is the measure.
2. Verify the count matches the actual number of consents.
3. Record a new consent — verify the count increments.
**Expected Result:** The consent count is shown — the count of the consents is the measure.
**Priority:** High

### TC-SA-22-02-038 — Consent view: the view (the consents, the users, the scopes, the dates); the control is managed
**Type:** Positive
**Covers:** 2.5 → Consent view: the view (the consents, the users, the scopes, the dates); Rule: the consent is managed (the consents, the users, the scopes, the dates); the control is managed
**Preconditions:** Multiple consents exist.
**Steps:**
1. View the consents: the view (the consents, the users, the scopes, the dates) — verify the consent is managed.
2. Verify each consent shows the user, the scope, and the date.
3. Verify the control is managed (view, grant, withdraw, re-consent).
**Expected Result:** The consents are viewed — the consents, the users, the scopes, and the dates are visible; the control is managed.
**Priority:** High

### TC-SA-22-02-039 — Consent export: the export (the consents, the format, the scope); the export is the record
**Type:** Edge
**Covers:** 2.5 → Consent export: the export (the consents, the format, the scope)
**Preconditions:** Consents exist for multiple scopes; a scope with no consents (zero-row export edge) is also prepared.
**Steps:**
1. Export the consents: the export (the consents, the format, the scope) — verify the export is the record.
2. Verify the export contains all consents for the selected scope in the selected format.
3. Export the empty scope — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The consents are exported — the consents, the format, and the scope are the record; empty-scope exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-02-040 — Consent management is audit-logged with the consent, scope, and timestamp
**Type:** Positive
**Covers:** 2.5 → Audit logging of the consent management; Rule: consent management is audit-logged with the consent, scope, and timestamp
**Preconditions:** Super Admin has managed a consent.
**Steps:**
1. Open the audit trail and filter by "consent".
2. Verify entries show the consent, the scope, and the timestamp.
**Expected Result:** The consent management is audit-logged with the consent, scope, and timestamp.
**Priority:** Critical

## 2.6 Personal Data Anonymization

### TC-SA-22-02-041 — Anonymization: the anonymization (the anonymization, the data, the method, the date); the anonymization is the masking
**Type:** Positive
**Covers:** 2.6 → Anonymization: the anonymization (the anonymization, the data, the method, the date); Rule: the anonymization is the protection (the anonymization, the data, the method, the date); the anonymization is the masking
**Preconditions:** Super Admin is logged in; personal data eligible for anonymization exists.
**Steps:**
1. Open Data Protection & Compliance → Data Handling → Personal Data Anonymization.
2. Anonymize the personal data: the anonymization (the anonymization, the data, the method, the date) — verify the anonymization is the protection.
3. Verify the anonymization shows the data, the method, and the date.
4. Execute the anonymization — verify the personal identifiers are removed or masked.
**Expected Result:** The anonymization is performed — the anonymization, the data, the method, and the date are the masking.
**Priority:** Critical

### TC-SA-22-02-042 — Data: the data (the data, the type, the date); the data is the content
**Type:** Positive
**Covers:** 2.6 → Data: the data (the data, the type, the date); Rule: the data is the subject (the data, the type, the date); the data is the content
**Preconditions:** Personal data of multiple types exists.
**Steps:**
1. Select the data: the data (the data, the type, the date) — verify the data is the subject.
2. Verify the data shows the type and the date.
3. Verify only eligible personal data is in the anonymization scope.
**Expected Result:** The data is selected — the data, the type, and the date are the content.
**Priority:** High

### TC-SA-22-02-043 — Method: the method (the method of the anonymization, e.g., the pseudonymization, the aggregation); the method is the approach
**Type:** Positive
**Covers:** 2.6 → Method: the method (the method of the anonymization, e.g., the pseudonymization, the aggregation); Rule: the method is the technique (the method of the anonymization, e.g., the pseudonymization, the aggregation); the method is the approach
**Preconditions:** Pseudonymization and aggregation methods are available.
**Steps:**
1. Set the method: the method (the method of the anonymization, e.g., the pseudonymization, the aggregation) — verify the method is the technique.
2. Apply pseudonymization — verify identifiers are replaced with irreversible pseudonyms.
3. Apply aggregation — verify individual records are combined so no individual is identifiable.
**Expected Result:** The method is set — the method of the anonymization (the pseudonymization, the aggregation) is the approach.
**Priority:** High

### TC-SA-22-02-044 — Anonymization status: the status (the anonymized, the pending); the status is the control
**Type:** Edge
**Covers:** 2.6 → Anonymization status: the status (the anonymized, the pending); Rule: the anonymization status is the state (the anonymized, the pending); the status is the control
**Preconditions:** Anonymizations with anonymized and pending statuses exist; a dataset with a failed/partial anonymization job (partial-failure edge) is also prepared.
**Steps:**
1. View the anonymization status: the status (the anonymized, the pending) — verify the anonymization status is the state.
2. Verify a completed job shows anonymized.
3. Check the failed job — verify it remains pending (never falsely marked anonymized) with a visible failure reason; no record is half-anonymized and presented as safe.
**Expected Result:** The anonymization status is shown — the anonymized and the pending are the control; failed jobs are never misreported as anonymized.
**Priority:** High

### TC-SA-22-02-045 — Anonymization count: the count (the count of the anonymizations); the count is the measure
**Type:** Positive
**Covers:** 2.6 → Anonymization count: the count (the count of the anonymizations)
**Preconditions:** Multiple anonymizations exist.
**Steps:**
1. View the anonymization count: the count (the count of the anonymizations) — verify the count is the measure.
2. Verify the count matches the actual number of anonymizations.
3. Complete a new anonymization — verify the count increments.
**Expected Result:** The anonymization count is shown — the count of the anonymizations is the measure.
**Priority:** High

### TC-SA-22-02-046 — Anonymization view: the view (the anonymizations, the data, the methods, the dates); the protection is managed
**Type:** Positive
**Covers:** 2.6 → Anonymization view: the view (the anonymizations, the data, the methods, the dates); Rule: the data is anonymized (the anonymizations, the data, the methods, the dates); the protection is managed
**Preconditions:** Multiple anonymizations exist.
**Steps:**
1. View the anonymizations: the view (the anonymizations, the data, the methods, the dates) — verify the data is anonymized.
2. Verify each anonymization shows the data, the method, and the date.
3. Verify the protection is managed (view, schedule, verify).
**Expected Result:** The anonymizations are viewed — the anonymizations, the data, the methods, and the dates are visible; the protection is managed.
**Priority:** High

### TC-SA-22-02-047 — Anonymization export: the export (the anonymizations, the format, the method); the export is the record
**Type:** Edge
**Covers:** 2.6 → Anonymization export: the export (the anonymizations, the format, the method)
**Preconditions:** Anonymizations exist for multiple methods; a method with no anonymizations (zero-row export edge) is also prepared.
**Steps:**
1. Export the anonymizations: the export (the anonymizations, the format, the method) — verify the export is the record.
2. Verify the export contains all anonymizations for the selected method in the selected format.
3. Export the empty method — verify the export completes (empty file or clear "no data" message, no error/corrupt file).
**Expected Result:** The anonymizations are exported — the anonymizations, the format, and the method are the record; empty-method exports never produce corrupt files or errors.
**Priority:** High

### TC-SA-22-02-048 — Data anonymization is audit-logged with the anonymization, method, and timestamp
**Type:** Positive
**Covers:** 2.6 → Audit logging of the data anonymization; Rule: data anonymization is audit-logged with the anonymization, method, and timestamp
**Preconditions:** Super Admin has performed a data anonymization.
**Steps:**
1. Open the audit trail and filter by "data anonymization".
2. Verify entries show the anonymization, the method, and the timestamp.
**Expected Result:** The data anonymization is audit-logged with the anonymization, method, and timestamp.
**Priority:** Critical
