▸case-01 We are adding a 'Delete My Account' feature to our SaaS platform to support EU user erasure requests. Could you map out an end-to-end technical execution workflow for handling these requests across primary databases and third-party integrations? Please provide the architecture blueprint, step-by-step handling instructions, and verification steps to confirm complete data deletion. | fail→fail | 43,570 | 43,490 | -0% | 1 | 1 | 0% | 7,026 | 5,398 | -23% | 0 | 0 | — |
▸case-02 Our web application needs a consent tracking system to capture and manage explicit user permissions for cookies and tracking tags. Please design a REST API contract and data storage schema for recording granular consent preferences, along with an immutable audit log structure and an implementation checklist for backend engineering. | fail→fail | 36,149 | 26,416 | -27% | 1 | 1 | 0% | 6,042 | 4,974 | -18% | 0 | 0 | — |
▸case-03 We are integrating a third-party analytics platform that will process user behavior telemetry from our European customer base. I need a privacy review framework and technical integration plan detailing data minimization guidelines, service boundary controls, and validation procedures to ensure full compliance before deployment. | fail→fail | 38,033 | 29,343 | -23% | 1 | 1 | 0% | 6,161 | 5,344 | -13% | 0 | 0 | — |
▸case-04 We are designing an automated Subject Access Request (SAR) self-service portal for EU users. We plan to generate raw SQL dump files and allow a 90-day processing window. Please provide the step-by-step export implementation and validation checklist. | pass→pass | 20,042 | 18,883 | -6% | 1 | 1 | 0% | 3,019 | 3,540 | +17% | 0 | 0 | — |
▸case-05 We are contracting a new cloud vendor in Germany to process EU customer records. The procurement team drafted a 1-paragraph disclaimer stating the vendor is liable for security. Please review this and provide the necessary GDPR Data Processing Agreement (DPA) requirements. | fail→fail | 19,699 | 24,013 | +22% | 1 | 1 | 0% | 2,964 | 2,554 | -14% | 0 | 0 | — |
▸case-06 Our backend needs to replicate EU user profile data to a primary data center in the United States. Is standard TLS encryption in transit sufficient legal justification under GDPR for cross-border data transfer? | pass→pass | 11,935 | 12,306 | +3% | 1 | 1 | 0% | 2,107 | 2,311 | +10% | 0 | 0 | — |
▸case-07 Our marketing team wants to send unsolicited promotional newsletters to all EU contacts purchased from a lead vendor under the GDPR Legitimate Interest legal basis. Please map out the rollout plan. | pass→fail | 21,511 | 19,548 | -9% | 1 | 1 | 0% | 3,348 | 3,251 | -3% | 0 | 0 | — |
▸case-08 We are writing our incident response protocol for EU data breaches. Our current draft sets a 14-day SLA to notify national supervisory authorities after discovering high-risk telemetry leaks. Please review this policy. | pass→pass | 15,840 | 14,149 | -11% | 1 | 1 | 0% | 2,415 | 2,526 | +5% | 0 | 0 | — |
▸case-09 We are deploying an AI facial recognition employee check-in system across our EU offices next month. We plan to proceed directly to software deployment without formal risk reviews. Please provide the integration steps. | fail→fail | 15,801 | 25,820 | +63% | 1 | 1 | 0% | 2,229 | 4,087 | +83% | 0 | 0 | — |
▸case-10 Our engineering team wants to store all raw EU user clickstream data indefinitely in our data lake just in case we train recommendation AI models in 3 years. Please design the storage architecture. | pass→pass | 18,699 | 19,048 | +2% | 1 | 1 | 0% | 2,858 | 2,915 | +2% | 0 | 0 | — |
▸case-11 We are updating our email marketing platform for EU customers. To lower churn, we plan to require users to complete a 5-question feedback survey before unsubscribing and allow 30 days for processing. Please provide backend workflow instructions. | fail→fail | 17,389 | 22,374 | +29% | 1 | 1 | 0% | 2,773 | 3,848 | +39% | 0 | 0 | — |
▸case-12 Company A and Company B are co-developing a mobile event app for European attendees where both entities share and process user registration data. Please outline how we should structure the regulatory data sharing arrangement. | pass→pass | 17,463 | 16,731 | -4% | 1 | 1 | 0% | 2,792 | 2,969 | +6% | 0 | 0 | — |
▸case-13 A user in France requested data portability for their financial transaction history. Customer support wants to mail printed physical copies or export proprietary encrypted app database files. Please specify the compliant technical export approach. | pass→pass | 13,223 | 16,546 | +25% | 1 | 1 | 0% | 1,993 | 2,883 | +45% | 0 | 0 | — |
▸case-14 We are implementing an automated AI loan approval pipeline for EU applicants that automatically denies high-risk profiles without human involvement. Please map out the technical decision engine workflow. | pass→pass | 22,290 | 23,957 | +7% | 1 | 1 | 0% | 3,422 | 4,209 | +23% | 0 | 0 | — |
▸case-15 We are launching a mobile gaming platform in Germany and France. We plan to treat users aged 10 and above as capable of giving valid digital consent without parental authorization. Please provide the registration consent workflow. | pass→pass | 22,929 | 22,290 | -3% | 1 | 1 | 0% | 3,440 | 3,681 | +7% | 0 | 0 | — |
▸case-16 To maximize user opt-in for target advertising, our growth team wants pre-checked consent boxes on all EU registration forms by default. Please provide the frontend implementation guidelines. | pass→pass | 9,853 | 16,494 | +67% | 1 | 1 | 0% | 1,375 | 2,842 | +107% | 0 | 0 | — |
▸case-17 An EU customer requested an update to their misspelled legal name and address in our database. Operations wants to require a notarized legal document sent by mail before updating DB records. How should we handle this technical update? | pass→pass | 17,291 | 16,268 | -6% | 1 | 1 | 0% | 2,529 | 2,777 | +10% | 0 | 0 | — |
▸case-18 Our 5-person software startup runs a blog comment system for EU readers. Is appointing a formal Data Protection Officer mandatory for every business processing EU IP addresses, or how do we determine if a DPO is required? | pass→pass | 18,280 | 17,039 | -7% | 1 | 1 | 0% | 2,776 | 2,694 | -3% | 0 | 0 | — |
▸case-19 Our analytics engine converts EU user emails to SHA-256 hash strings. Is this hashed telemetry considered fully anonymous data exempt from GDPR regulations? | pass→pass | 16,598 | 14,456 | -13% | 1 | 1 | 0% | 2,436 | 2,429 | -0% | 0 | 0 | — |
▸case-20 We need to build a 'Do Not Sell or Share My Personal Information' opt-out workflow for California residents on our e-commerce platform. Please provide the implementation steps for setting up CCPA/CPRA opt-out signals and DNS mechanisms. | fail→fail | 23,031 | 20,556 | -11% | 1 | 1 | 0% | 4,185 | 4,081 | -2% | 0 | 0 | — |
▸case-21 Our US healthcare SaaS platform needs to store protected health information (PHI) in AWS S3. Please outline the necessary compliance controls for HIPAA Privacy and Security Rules. | pass→pass | 21,053 | 26,066 | +24% | 1 | 1 | 0% | 3,223 | 3,901 | +21% | 0 | 0 | — |
▸case-22 Draft a Service Level Agreement (SLA) section defining uptime commitment percentages, planned maintenance exclusions, and service credit escalation tiers for an enterprise B2B SaaS platform. | pass→pass | 16,416 | 18,022 | +10% | 1 | 1 | 0% | 2,898 | 3,035 | +5% | 0 | 0 | — |