Skip to content

Add privacy policy and compliance documentation for Sentry PII collection #5

@coderabbitai

Description

@coderabbitai

Context

As discussed in PR #2, the Sentry integration currently has sendDefaultPii: true enabled, which transmits user IP addresses, cookies, and request headers to Sentry for error monitoring.

Required Actions

Before this setting can remain enabled in production, the following compliance requirements need to be addressed:

  1. Privacy Policy: Create and publish a privacy policy that discloses PII collection for error monitoring purposes
  2. Data Processing Addendum: Execute a Data Processing Addendum (DPA) with Sentry if handling EU personal data
  3. User Consent: Implement a user consent mechanism where legally required by jurisdiction
  4. Internal Documentation: Document why PII collection is required and ensure appropriate approval

References

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions