UNPKG

@iota-big3/sdk-gateway

Version:

Universal API Gateway with protocol translation, intelligent routing, rate limiting, health checking, and caching

534 lines 17 kB
/** * Compliance and Regulatory Type Definitions * * @module compliance-types * @description Comprehensive types for regulatory compliance including: * - FERPA (Family Educational Rights and Privacy Act) * - HIPAA (Health Insurance Portability and Accountability Act) * - GDPR (General Data Protection Regulation) * - PCI-DSS (Payment Card Industry Data Security Standard) * - SOX (Sarbanes-Oxley Act) * * All types are designed to be AI/debugging friendly with: * - Descriptive names that explain their purpose * - Comprehensive JSDoc comments * - Built-in validation helpers * - Clear error messages */ import type { Brand, Result } from './index'; /** * Compliance framework identifier * Each framework has specific requirements and validation rules */ export declare enum ComplianceFramework { FERPA = "FERPA", HIPAA = "HIPAA", GDPR = "GDPR", PCI_DSS = "PCI_DSS", SOX = "SOX", COPPA = "COPPA", CCPA = "CCPA", ISO27001 = "ISO27001", SOC2 = "SOC2" } /** * Data classification levels * Determines handling requirements and access controls */ export declare enum DataClassification { /** Publicly available information */ Public = "PUBLIC", /** Internal use only */ Internal = "INTERNAL", /** Confidential business information */ Confidential = "CONFIDENTIAL", /** Restricted - highest security (PII, PHI, payment data) */ Restricted = "RESTRICTED" } /** * Lawful basis for data processing under GDPR */ export declare enum LawfulBasis { Consent = "CONSENT", Contract = "CONTRACT", LegalObligation = "LEGAL_OBLIGATION", VitalInterests = "VITAL_INTERESTS", PublicTask = "PUBLIC_TASK", LegitimateInterests = "LEGITIMATE_INTERESTS" } /** * Data subject rights under various regulations */ export declare enum DataSubjectRight { Access = "ACCESS", Rectification = "RECTIFICATION", Erasure = "ERASURE", Portability = "PORTABILITY", Restriction = "RESTRICTION", Object = "OBJECT", AutomatedDecisionMaking = "AUTOMATED_DECISION_MAKING", InspectRecords = "INSPECT_RECORDS", RequestAmendment = "REQUEST_AMENDMENT", ConsentToDisclosure = "CONSENT_TO_DISCLOSURE", OptOut = "OPT_OUT", KnowAboutInfo = "KNOW_ABOUT_INFO", Delete = "DELETE", NonDiscrimination = "NON_DISCRIMINATION" } /** * FERPA-compliant education record * Represents any record directly related to a student */ export interface FERPAEducationRecord { readonly recordId: Brand<string, 'FERPARecordId'>; readonly studentId: Brand<string, 'StudentId'>; readonly recordType: FERPARecordType; readonly classification: DataClassification.Confidential | DataClassification.Restricted; readonly content: unknown; readonly metadata: { readonly createdAt: string; readonly createdBy: string; readonly lastModifiedAt?: string; readonly lastModifiedBy?: string; readonly retentionPeriod: string; readonly destructionDate?: string; }; readonly access: { readonly allowedRoles: readonly string[]; readonly excludedRoles?: readonly string[]; readonly requiresConsent: boolean; readonly consentRecords?: readonly FERPAConsent[]; }; } /** * Types of education records under FERPA */ export declare enum FERPARecordType { AcademicTranscript = "ACADEMIC_TRANSCRIPT", DisciplinaryRecord = "DISCIPLINARY_RECORD", FinancialRecord = "FINANCIAL_RECORD", MedicalRecord = "MEDICAL_RECORD", CounselingRecord = "COUNSELING_RECORD", AttendanceRecord = "ATTENDANCE_RECORD", GradeReport = "GRADE_REPORT", StandardizedTestScore = "STANDARDIZED_TEST_SCORE", IEP = "IEP",// Individualized Education Program BehavioralAssessment = "BEHAVIORAL_ASSESSMENT" } /** * FERPA consent record for disclosure */ export interface FERPAConsent { readonly consentId: Brand<string, 'ConsentId'>; readonly studentId: Brand<string, 'StudentId'>; readonly parentId?: Brand<string, 'ParentId'>; readonly purpose: string; readonly recipientName: string; readonly recipientOrganization?: string; readonly recordsToDisclose: readonly FERPARecordType[]; readonly validFrom: string; readonly validUntil?: string; readonly revoked?: { readonly at: string; readonly by: string; readonly reason?: string; }; readonly signature: { readonly signedAt: string; readonly signedBy: string; readonly ipAddress?: string; readonly method: 'electronic' | 'physical' | 'verbal'; }; } /** * FERPA directory information (can be disclosed without consent) */ export interface FERPADirectoryInfo { readonly studentName: string; readonly address?: string; readonly telephone?: string; readonly email?: string; readonly photograph?: boolean; readonly dateOfBirth?: string; readonly placeOfBirth?: string; readonly gradeLevel?: string; readonly enrollment?: { readonly status: 'full-time' | 'part-time'; readonly dates: string; }; readonly major?: string; readonly activitiesAndSports?: readonly string[]; readonly awards?: readonly string[]; readonly optedOut: boolean; } /** * HIPAA Protected Health Information (PHI) */ export interface HIPAAPHI { readonly phiId: Brand<string, 'PHIId'>; readonly patientId: Brand<string, 'PatientId'>; readonly classification: DataClassification.Restricted; readonly category: PHICategory; readonly data: unknown; readonly encryption: { readonly atRest: boolean; readonly inTransit: boolean; readonly algorithm: string; }; readonly access: { readonly minimumNecessary: boolean; readonly authorizedUsers: readonly string[]; readonly purposeOfUse: string; readonly accessLog: readonly PHIAccessLog[]; }; } /** * Categories of Protected Health Information */ export declare enum PHICategory { Demographics = "DEMOGRAPHICS", MedicalHistory = "MEDICAL_HISTORY", TestResults = "TEST_RESULTS", MentalHealthRecords = "MENTAL_HEALTH_RECORDS", Insurance = "INSURANCE", Billing = "BILLING", ClinicalNotes = "CLINICAL_NOTES", Prescriptions = "PRESCRIPTIONS", DeviceData = "DEVICE_DATA", GeneticInformation = "GENETIC_INFORMATION" } /** * HIPAA access log entry */ export interface PHIAccessLog { readonly timestamp: string; readonly userId: string; readonly action: 'create' | 'read' | 'update' | 'delete' | 'transmit'; readonly justification: string; readonly dataAccessed: string[]; readonly ipAddress?: string; readonly userAgent?: string; readonly success: boolean; readonly denialReason?: string; } /** * HIPAA Business Associate Agreement tracking */ export interface HIPAABusinessAssociate { readonly baaId: Brand<string, 'BAAId'>; readonly organizationName: string; readonly contactInfo: { readonly name: string; readonly email: string; readonly phone: string; readonly address: string; }; readonly agreement: { readonly signedDate: string; readonly expirationDate?: string; readonly scopeOfWork: string; readonly safeguards: readonly string[]; }; readonly compliance: { readonly lastAuditDate?: string; readonly violations?: readonly ComplianceViolation[]; readonly trainingCompleted: boolean; }; } /** * GDPR-compliant personal data record */ export interface GDPRPersonalData { readonly dataId: Brand<string, 'PersonalDataId'>; readonly dataSubjectId: Brand<string, 'DataSubjectId'>; readonly category: GDPRDataCategory; readonly data: unknown; readonly processing: { readonly purpose: string[]; readonly lawfulBasis: LawfulBasis; readonly retention: { readonly period: string; readonly justification: string; }; readonly recipients?: string[]; readonly internationalTransfer?: { readonly country: string; readonly safeguards: string; }; }; readonly consent?: GDPRConsent; readonly source: { readonly obtainedFrom: 'data_subject' | 'third_party'; readonly date: string; readonly method: string; }; } /** * GDPR data categories */ export declare enum GDPRDataCategory { Identification = "IDENTIFICATION", Contact = "CONTACT", Financial = "FINANCIAL", Location = "LOCATION", Online = "ONLINE", Professional = "PROFESSIONAL", Special = "SPECIAL",// Sensitive data requiring explicit consent Criminal = "CRIMINAL",// Criminal convictions Children = "CHILDREN" } /** * GDPR consent record */ export interface GDPRConsent { readonly consentId: Brand<string, 'ConsentId'>; readonly version: string; readonly language: string; readonly purposes: readonly { readonly purpose: string; readonly granted: boolean; readonly mandatoryFor?: string; }[]; readonly timestamp: string; readonly withdrawable: boolean; readonly withdrawnAt?: string; readonly method: 'explicit' | 'implicit'; readonly proofOfConsent: { readonly text: string; readonly screenshot?: string; readonly ipAddress?: string; }; } /** * GDPR Data Subject Request */ export interface GDPRDataSubjectRequest { readonly requestId: Brand<string, 'DSRId'>; readonly dataSubjectId: Brand<string, 'DataSubjectId'>; readonly type: DataSubjectRight; readonly status: 'pending' | 'verified' | 'processing' | 'completed' | 'rejected'; readonly submittedAt: string; readonly deadline: string; readonly verification: { readonly method: string; readonly verifiedAt?: string; readonly verifiedBy?: string; }; readonly response?: { readonly completedAt: string; readonly completedBy: string; readonly summary: string; readonly dataProvided?: string; }; } /** * PCI-DSS cardholder data * WARNING: Most applications should NOT store full card data */ export interface PCIDSSCardholderData { readonly tokenId: Brand<string, 'PaymentTokenId'>; readonly lastFourDigits: string; readonly expiryMonth?: number; readonly expiryYear?: number; readonly cardholderName?: string; readonly metadata: { readonly environment: 'production' | 'test'; readonly tokenProvider: string; readonly createdAt: string; readonly lastUsedAt?: string; }; } /** * PCI-DSS compliance scope */ export interface PCIDSSScope { readonly scopeId: Brand<string, 'PCIScopeId'>; readonly level: 1 | 2 | 3 | 4; readonly systems: readonly { readonly systemId: string; readonly type: 'storage' | 'processing' | 'transmission'; readonly description: string; readonly inScope: boolean; }[]; readonly segmentation: { readonly implemented: boolean; readonly testedDate?: string; readonly nextTestDue?: string; }; readonly assessment: { readonly type: 'SAQ' | 'ROC'; readonly lastCompleted?: string; readonly nextDue: string; readonly attestation?: string; }; } /** * SOX internal control */ export interface SOXControl { readonly controlId: Brand<string, 'SOXControlId'>; readonly section: 302 | 404 | 409 | 802 | 906; readonly category: SOXControlCategory; readonly description: string; readonly owner: string; readonly frequency: 'real-time' | 'daily' | 'weekly' | 'monthly' | 'quarterly' | 'annual'; readonly automated: boolean; readonly evidence: { readonly required: string[]; readonly retention: string; }; readonly testing: { readonly lastTested?: string; readonly nextDue: string; readonly result?: 'effective' | 'ineffective' | 'needs-improvement'; }; } /** * SOX control categories */ export declare enum SOXControlCategory { EntityLevel = "ENTITY_LEVEL", ITGeneral = "IT_GENERAL", Application = "APPLICATION", EndUserComputing = "END_USER_COMPUTING", FinancialReporting = "FINANCIAL_REPORTING", DisclosureControls = "DISCLOSURE_CONTROLS" } /** * SOX certification record */ export interface SOXCertification { readonly certificationId: Brand<string, 'CertificationId'>; readonly period: { readonly year: number; readonly quarter?: 1 | 2 | 3 | 4; }; readonly certifier: { readonly name: string; readonly title: 'CEO' | 'CFO'; readonly signature: string; readonly date: string; }; readonly assertions: { readonly accurateFinancials: boolean; readonly adequateControls: boolean; readonly noMaterialWeaknesses: boolean; readonly disclosedDeficiencies: boolean; }; readonly materialWeaknesses?: readonly string[]; readonly significantDeficiencies?: readonly string[]; } /** * Unified compliance violation record */ export interface ComplianceViolation { readonly violationId: Brand<string, 'ViolationId'>; readonly framework: ComplianceFramework; readonly severity: 'low' | 'medium' | 'high' | 'critical'; readonly description: string; readonly detectedAt: string; readonly detectedBy: string; readonly affectedData?: { readonly type: string; readonly count: number; readonly identifiers?: string[]; }; readonly remediation: { readonly required: boolean; readonly deadline?: string; readonly status: 'pending' | 'in-progress' | 'completed'; readonly completedAt?: string; readonly completedBy?: string; readonly evidence?: string; }; readonly reportable: boolean; readonly reported?: { readonly to: string[]; readonly date: string; readonly reference: string; }; } /** * Data retention policy */ export interface DataRetentionPolicy { readonly policyId: Brand<string, 'RetentionPolicyId'>; readonly dataType: string; readonly framework: ComplianceFramework[]; readonly retention: { readonly period: string; readonly justification: string; readonly exceptions?: string[]; }; readonly deletion: { readonly method: 'soft' | 'hard' | 'anonymize'; readonly verification: boolean; readonly certification: boolean; }; readonly holds?: readonly { readonly reason: string; readonly startDate: string; readonly endDate?: string; readonly authority: string; }[]; } /** * Privacy Impact Assessment (PIA) */ export interface PrivacyImpactAssessment { readonly piaId: Brand<string, 'PIAId'>; readonly project: { readonly name: string; readonly description: string; readonly startDate: string; readonly dataTypes: string[]; }; readonly assessment: { readonly necessity: string; readonly proportionality: string; readonly risks: readonly { readonly risk: string; readonly likelihood: 'low' | 'medium' | 'high'; readonly impact: 'low' | 'medium' | 'high'; readonly mitigation: string; }[]; }; readonly consultations: readonly { readonly with: string; readonly date: string; readonly feedback: string; readonly incorporated: boolean; }[]; readonly approval: { readonly required: boolean; readonly approvedBy?: string; readonly approvedDate?: string; readonly conditions?: string[]; }; } /** * Check if data requires encryption under compliance rules */ export declare function requiresEncryption(classification: DataClassification, framework: ComplianceFramework[]): boolean; /** * Calculate data retention period based on compliance requirements */ export declare function calculateRetentionPeriod(dataType: string, frameworks: ComplianceFramework[]): string; /** * Validate consent adequacy for data processing */ export declare function validateConsent(consent: GDPRConsent | FERPAConsent, purpose: string, framework: ComplianceFramework): Result<boolean, string>; export declare const complianceTypes: { ComplianceFramework: typeof ComplianceFramework; DataClassification: typeof DataClassification; LawfulBasis: typeof LawfulBasis; DataSubjectRight: typeof DataSubjectRight; FERPARecordType: typeof FERPARecordType; PHICategory: typeof PHICategory; GDPRDataCategory: typeof GDPRDataCategory; SOXControlCategory: typeof SOXControlCategory; requiresEncryption: typeof requiresEncryption; calculateRetentionPeriod: typeof calculateRetentionPeriod; validateConsent: typeof validateConsent; }; //# sourceMappingURL=compliance-types.d.ts.map