[
  {
    "runId": "f661e959-ab4a-4e96-af49-48c8191eb54d",
    "step": "report",
    "inputs": {
      "site_url": "https://example.com",
      "data_practices": "cookies analytics",
      "region": "EU"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "privacyscan@2026-07-21",
        "hits": [
          {
            "id": "PRIV-001",
            "title": "PII detection in collected data",
            "severity": "high",
            "remediation": "If you process personal data (esp. special-category data), identify a lawful basis (Art. 6) and document it per processing activity.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-003",
            "title": "Consent mechanism (Art. 7)",
            "severity": "high",
            "remediation": "Where consent is the lawful basis, implement granular, unbundled, opt-in consent with easy withdrawal (Art. 7). Avoid pre-ticked boxes.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-004",
            "title": "Cookie / tracker inventory (ePrivacy)",
            "severity": "medium",
            "remediation": "Maintain a cookie/tracker inventory. Block non-essential cookies until consent; disclose each purpose and provider.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-006",
            "title": "Data-subject rights pathway (Art. 12–22)",
            "severity": "high",
            "remediation": "Provide a clear pathway for access, rectification, erasure, and objection (Art. 15–22). Honor requests within one month.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-007",
            "title": "Accountability & principles (Art. 5)",
            "severity": "medium",
            "remediation": "Document the Art. 5 principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality, accountability.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-008",
            "title": "Security of processing (Art. 32)",
            "severity": "high",
            "remediation": "Implement Art. 32 technical/organisational measures: encryption, pseudonymisation, resilience, regular testing. Assess risk-appropriate controls.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-009",
            "title": "CCPA/CPRA (California) disclosure & opt-out",
            "severity": "medium",
            "remediation": "For CA residents, provide a \"Do Not Sell or Share\" link, notice at collection, and honor deletion/opt-out rights (CCPA/CPRA).",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-010",
            "title": "Cookie consent symmetry (no dark patterns)",
            "severity": "medium",
            "remediation": "ePrivacy/GDPR: reject must be as easy as accept; no pre-ticked boxes or dark-pattern nudges (2025 consent guidance).",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-013",
            "title": "Personal data breach notification (Art. 33)",
            "severity": "high",
            "remediation": "A personal data breach must be notified to the supervisory authority within 72 hours of becoming aware (Art. 33), and to data subjects without undue delay where high risk (Art. 34). Define an incident-response runbook.",
            "source": "Rule-based"
          }
        ]
      },
      "modelText": "GDPR COMPLIANCE SCAN - EU only\n\nPrivacy readiness score: 54/100\n\nTop issues (mapped to GDPR):\n  - Cookie banner lacks granular consent (Art. 7)\n  - No lawful basis stated for analytics (Art. 6)\n  - Missing data-retention notice (Art. 13/14)\n\nRequired fixes:\n  - Replace \"accept all\" with granular opt-in\n  - Add lawful-basis statement per purpose\n  - Publish retention periods\n\nRemediation checklist:\n  - [ ] Cookie consent v2\n  - [ ] Privacy policy refresh\n\n--- (Mock demo. Pro unlocks full-site scans + export.)"
    },
    "status": "done",
    "pipelineId": "privacyscan-gdpr-v1",
    "createdAt": "2026-07-23T14:09:07.683Z",
    "updatedAt": "2026-07-23T14:09:07.683Z",
    "rulesetVersion": "privacyscan@2026-07-21"
  },
  {
    "runId": "5e3e739f-02e1-4af0-ac25-ff6b15eea830",
    "step": "classify",
    "inputs": {},
    "artifacts": {
      "ingestedAt": "2026-07-22T21:31:31.211Z",
      "inputKeys": [],
      "ruleHits": {
        "rulesetVersion": "privacyscan@2026-07-22",
        "hits": [
          {
            "id": "PRIV-003",
            "title": "Consent mechanism (Art. 7) — no pre-ticked boxes",
            "severity": "high",
            "remediation": "Where consent is the lawful basis, implement granular, unbundled, opt-in consent with easy withdrawal (Art. 7). Pre-ticked boxes are invalid (CJEU Planet49 / C-673/17).",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-006",
            "title": "Data-subject rights pathway (Art. 12–22)",
            "severity": "high",
            "remediation": "Provide a clear pathway for access, rectification, erasure, and objection (Art. 15–22). Honor requests within one month.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-007",
            "title": "Accountability & principles (Art. 5)",
            "severity": "medium",
            "remediation": "Document the Art. 5 principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality, accountability.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-008",
            "title": "Security of processing (Art. 32)",
            "severity": "high",
            "remediation": "Implement Art. 32 technical/organisational measures: encryption, pseudonymisation, resilience, regular testing. Assess risk-appropriate controls.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-009",
            "title": "CCPA/CPRA (California) disclosure & opt-out",
            "severity": "medium",
            "remediation": "For CA residents, provide a \"Do Not Sell or Share\" link, notice at collection, and honor deletion/opt-out rights (CCPA/CPRA).",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-010",
            "title": "Cookie consent symmetry (no dark patterns / Planet49)",
            "severity": "medium",
            "remediation": "Reject must be as easy as accept; no pre-ticked boxes (CJEU C-673/17 Planet49). Disclose cookie duration and third-party access.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-013",
            "title": "Personal data breach notification (Art. 33)",
            "severity": "high",
            "remediation": "A personal data breach must be notified to the supervisory authority within 72 hours of becoming aware (Art. 33), and to data subjects without undue delay where high risk (Art. 34). Define an incident-response runbook.",
            "source": "Rule-based"
          }
        ]
      }
    },
    "status": "failed",
    "pipelineId": "privacyscan-gdpr-v1",
    "createdAt": "2026-07-22T21:31:31.210Z",
    "updatedAt": "2026-07-22T21:31:31.220Z",
    "rulesetVersion": "privacyscan@2026-07-22",
    "error": "AI request failed"
  },
  {
    "runId": "015f6bfa-b38e-4e7e-bd4e-29f6219f6437",
    "step": "classify",
    "inputs": {},
    "artifacts": {
      "ingestedAt": "2026-07-22T21:45:37.865Z",
      "inputKeys": [],
      "ruleHits": {
        "rulesetVersion": "privacyscan@2026-07-22",
        "hits": [
          {
            "id": "PRIV-003",
            "title": "Consent mechanism (Art. 7) — no pre-ticked boxes",
            "severity": "high",
            "remediation": "Where consent is the lawful basis, implement granular, unbundled, opt-in consent with easy withdrawal (Art. 7). Pre-ticked boxes are invalid (CJEU Planet49 / C-673/17).",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-006",
            "title": "Data-subject rights pathway (Art. 12–22)",
            "severity": "high",
            "remediation": "Provide a clear pathway for access, rectification, erasure, and objection (Art. 15–22). Honor requests within one month.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-007",
            "title": "Accountability & principles (Art. 5)",
            "severity": "medium",
            "remediation": "Document the Art. 5 principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality, accountability.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-008",
            "title": "Security of processing (Art. 32)",
            "severity": "high",
            "remediation": "Implement Art. 32 technical/organisational measures: encryption, pseudonymisation, resilience, regular testing. Assess risk-appropriate controls.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-009",
            "title": "CCPA/CPRA (California) disclosure & opt-out",
            "severity": "medium",
            "remediation": "For CA residents, provide a \"Do Not Sell or Share\" link, notice at collection, and honor deletion/opt-out rights (CCPA/CPRA).",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-010",
            "title": "Cookie consent symmetry (no dark patterns / Planet49)",
            "severity": "medium",
            "remediation": "Reject must be as easy as accept; no pre-ticked boxes (CJEU C-673/17 Planet49). Disclose cookie duration and third-party access.",
            "source": "Rule-based"
          },
          {
            "id": "PRIV-013",
            "title": "Personal data breach notification (Art. 33)",
            "severity": "high",
            "remediation": "A personal data breach must be notified to the supervisory authority within 72 hours of becoming aware (Art. 33), and to data subjects without undue delay where high risk (Art. 34). Define an incident-response runbook.",
            "source": "Rule-based"
          }
        ]
      }
    },
    "status": "failed",
    "pipelineId": "privacyscan-gdpr-v1",
    "createdAt": "2026-07-22T21:45:37.864Z",
    "updatedAt": "2026-07-22T21:45:37.868Z",
    "rulesetVersion": "privacyscan@2026-07-22",
    "error": "AI request failed"
  }
]