Transparency
Compliance controls register
This is an engineering and operations register, not a certification of legal compliance. “External required” means counsel, regulator, insurer, or vendor work has not been represented as complete.
COMP-1 · operational review
Lawful-basis and processing register
Register and request workflow implemented; DPIAs, EU representative and Article 14 campaign remain external.
Owner: Privacy lead
COMP-2 · external required
Australian cross-border disclosure and breach response
Policy disclosure implemented; response plan needs Australian review.
Owner: Privacy lead
COMP-3 · implemented
Sale/sharing opt-out and Global Privacy Control
Optional tags are consent-gated; GPC forces optional categories off.
Owner: Engineering
COMP-4 · implemented
Data-subject request intake and SLA
Public six-right intake, identity-verification state, 30-day due date and transition history.
Owner: Privacy operations
COMP-5 · implemented
Cookie and analytics consent
Analytics providers do not mount before affirmative consent.
Owner: Engineering
COMP-6 · operational review
Age eligibility
Jurisdiction-aware age policy and server validation available; account onboarding integration remains.
Owner: Trust & Safety
COMP-8 · implemented
DSA notice and action
Public notice intake and mandatory decision statement.
Owner: Trust & Safety
COMP-9 · operational review
Ranking transparency
Public parameter statement includes transactability demotion; legal wording review remains.
Owner: Search
COMP-10 · operational review
Consumer price, cancellation and recurring-payment protections
All-in price and mandatory disclosure gate implemented for EU/UK/AU/US consumers; jurisdictional legal validation remains external.
Owner: Legal and Commerce
COMP-11 · implemented
Paid placement
Disabled in v1; enabling requires register update and visible labelling.
Owner: Product
COMP-12 · external required
Statutory accessibility obligations (EAA, ADA, Equality Act, DDA)
Governance control records scoped reviews and findings without claiming legal compliance; statutory assessment and remediation evidence remain required.
Owner: Legal and Engineering
COMP-13 · external required
Provider insurance position
Provider obligation stated; platform E&O/cyber placement not represented as complete.
Owner: Risk
COMP-14 · operational review
US indirect-tax monitoring
Quarterly exception model implemented; registrations and Stripe Tax setup remain external.
Owner: Finance
COMP-15 · implemented
Foreign-tax scope guard
Foreign Track B disabled and non-US performance blocked; bundled-retreat question remains with counsel.
Owner: Finance
COMP-16 · operational review
Sanctions decisions
Jurisdiction decisions include outcome, reason and list version; denied-party vendor/counsel review remains.
Owner: Compliance
Processing register
Accounts and authentication
Basis: contract. Retention: account life plus required legal period.
Marketplace bookings and payments
Basis: contract and legal obligation. Retention: statutory financial-record period.
Public professional index
Basis: legitimate interests. Retention: while current; permanent suppression after valid removal.
Health intake
Basis: explicit consent. Retention: short listing-specific period after service.
Fraud and sanctions screening
Basis: legal obligation and legitimate interests. Retention: decision log retention schedule.
Optional analytics
Basis: consent. Retention: provider-configured minimised period.