adobe-data-handling
Adobe Data Custody and Privacy Review
Overview
Analyze and enforce classification, minimization, signed-URL custody, retention, deletion, content provenance, and privacy-request boundaries for Adobe workflows. This workflow produces a reviewable artifact and evidence before any live side effect.
Prerequisites
- Current first-party Adobe documentation for every selected service, API version, auth flow, limit, and lifecycle.
- Named product, identity, security, data, budget, release, and operations owners appropriate to the scope.
- Synthetic or approved non-production fixtures with secret and content canaries.
Current Contract
Adobe services have distinct custody contracts. PDF Services can use supported customer-storage signed URLs and can delete Adobe-hosted assets through the Assets endpoint. Firefly inputs/outputs and Content Credentials require product-specific review. Privacy Service is a separate Experience Platform API with its own authorization contract. Recheck the dated evidence map before relying on mutable product behavior.
Authentication
Treat tokens and signed URLs as secrets and prompts, images, PDFs, extracted text, event bodies, and identifiers as classified content. Do not send data to a service merely because auth succeeds.