Summary
Add GDPR-compliant consent gate at registration and a visible data processing notice page.
Since the demo app lets anyone register and switch to admin role (exposing other users' data), we need to:
- Require explicit consent to data processing at registration time
- Provide a visible data processing notice page explaining what data is collected, why, and users' rights
- Add a "Your Data" info card on the settings page
Tasks
Backend
Frontend — Privacy Page
Frontend — Registration Form
Frontend — Settings Page
i18n
Verification
Context
The registration audit event timestamp already serves as the consent record — no additional database changes needed. The consent is a gate-check at the API boundary only.
Summary
Add GDPR-compliant consent gate at registration and a visible data processing notice page.
Since the demo app lets anyone register and switch to admin role (exposing other users' data), we need to:
Tasks
Backend
ConsentGivenrequired boolean property toRegisterRequestConsentGiven == trueConsentGivenConsentGiven = falserejectionFrontend — Privacy Page
/privacyroute (accessible regardless of auth state)Frontend — Registration Form
/privacypage (opens in new tab)consentGivento API request bodyconsentGivenFrontend — Settings Page
i18n
en.jsonandcs.jsonVerification
pnpm run api:generate)Context
The registration audit event timestamp already serves as the consent record — no additional database changes needed. The consent is a gate-check at the API boundary only.