Skip to content

docs(types): source the retention floor to the acts that state it - #61

Merged
LKSNDRTMLKV merged 1 commit into
mainfrom
docs/retention-provenance
Jul 29, 2026
Merged

docs(types): source the retention floor to the acts that state it#61
LKSNDRTMLKV merged 1 commit into
mainfrom
docs/retention-provenance

Conversation

@LKSNDRTMLKV

Copy link
Copy Markdown
Member

What

MIN_RETENTION_DAYS = 3650 was documented as an "ESPR-driven minimum data-retention floor". ESPR states no retention figure at all.

Verified against the OJ text (dpp-docs/reference/legal/OJ_L_202401781_EN_TXT.pdf): Art. 9(2)(i) requires availability for "at least the expected lifetime of a specific product" — product-specific, delegated per product group, and no such delegated act has been adopted.

The 10 years is real, but it comes from the regulations that do state a figure: Reg. (EU) 2025/2509 (toys) and (EU) 2026/405 (detergents) both require 10 years after placing on the market "including in cases of insolvency, liquidation or cessation of activity", and Reg. (EU) 2024/3110 (CPR) imposes the same 10 years on the economic operator.

Comment-only change. The constant is unchanged and correct.

Two things the comment now records

  • CPR splits its duty. 10 years on the operator, 25 years on the construction DPP system. The 25 binds a passport service provider, not a node, so it is deliberately not expressible as a retentionYears value. Tracked in dpp-infra#2 and dpp-control-plane#1.
  • The ESPR sectors' figure is an assumption. Six of eleven sector manifests carry retentionYears: 10 with no legal basis. Tracked in dpp-core#65.

Note

I initially reported that construction was under-retaining by 15 years. That was wrong — I collapsed CPR's operator and system duties on first read. The manifests are correct; the provenance was not.

ESPR sets no retention figure - Art. 9(2)(i) ties availability to expected product lifetime - so attributing 3650 days to it was wrong; the 10 years comes from the toy, detergent and CPR operator duties, and the comment now records the two cases the constant deliberately does not express.
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 duplication

Metric Results
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@LKSNDRTMLKV
LKSNDRTMLKV merged commit f83751f into main Jul 29, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant