Audit evidence packet
Privacy & data handling (restricted category)
Owner: Marcus Sterling · State: Attestation open · Current version: v1
Generated for: Northstar Logistics Holdings · Prepared by: Riley Quintero (admin)
Policy
Authoritative metadata for POL-2021. This packet certifies that the policy is currently active, that the current version is v1, and that the attestation roster below reflects the state of compliance as of the printing date. Auditors should verify the publication date matches the reviewer-chain decision dates and that the attestation IP / timestamp pairs are consistent with the audit log.
- Code
- POL-2021
- Title
- CCPA Privacy Notice
- Category
- Privacy & data handling (restricted)
- State
- Attestation open
- Effective
- Mar 22, 2026
- Next review
- Mar 22, 2027
- Expires
- Mar 22, 2027
- Substantive flag
- Cosmetic only
- AI summary (current version)
- AI summary: CCPA Privacy Notice v1 — covers privacy & data handling with initial publication. Recommended attestation cycle: annual.
- Audience(s)
- No assignment rules.
Show current version body
# CCPA Privacy Notice (v1) Northstar Logistics Holdings — Privacy & data handling category. ## Purpose This is version 1 of CCPA Privacy Notice.
Version history
Every version of POL-2021 with author, publication date, and substantive-change classification. Earlier versions are retired when a new one publishes. The substantive-change column reflects the AI classifier's decision on whether the change introduced new obligations (substantive) or only clarifications (cosmetic).
| Version | State | Author | Published | Retired | Substantive |
|---|---|---|---|---|---|
| v1 | Attestation open | Marcus Sterling | Mar 22, 2026 | — | Cosmetic |
Attestation coverage
0 of 0 assigned employees have attested to POL-2021 version v1, for an overall coverage of 0%. No attestations are overdue. The roster below shows the most recent 25 entries; the full roster is exportable to CSV via the audit-bundle Export action on the policy detail page.
Coverage by team
Attestation roster (sample)
| Employee | Code | Team | Country | State | Assigned | Due | Attested at | IP |
|---|
Roster shows first 25 of 0 attestations. Full roster: see policy detail page → Export audit bundle (CSV).
Review chain
Reviewer steps and their decisions for the current version of POL-2021. Restricted-category policies (e.g. Information Security, Privacy & Data Handling) require Legal + Security reviewer approvals in addition to SME before executive sign-off; this packet records the reviewer type, identity, decision, comment, and decision timestamp for each step. The Executive approval entry at the bottom records the executive_approver's final sign-off before publication.
| Order | Reviewer type | Reviewer | State | Decision | Comment | Decided at |
|---|---|---|---|---|---|---|
| No review steps recorded for this policy. | ||||||
| Executive approval | Hank Mendez (executive_approver) | Approved | Approved | Final sign-off before publication. | Mar 22, 2026 | |
Auditor sign-off
This packet is exportable to PDF + CSV for delivery to SOC 2, ISO 27001, or SOX auditors. Sign and retain as evidence of policy publication, reviewer chain, and attestation coverage for POL-2021. Audit retention period: 7 years.