ARTICLE XII. DATA
Section 288. Privacy as a Core Institutional, Safeguards, and Governance Obligation
288.1 Privacy Purpose. GCRI Canada shall treat privacy as a core institutional, safeguards, governance, research, public authority, technical, data, AI, cyber, observability, publication, and public-benefit obligation. Privacy shall govern how GCRI Canada collects, receives, processes, stores, analyzes, links, models, infers, retrieves, embeds, publishes, shares, transfers, restricts, deletes, seals, archives, corrects, and uses personal information, rights-bearing data, sensitive data, public authority data, community-protected data, Indigenous / local / territorial knowledge, health-sensitive data, protected participant data, cyber-sensitive data, infrastructure-sensitive data, and other information capable of affecting rights, dignity, safety, autonomy, trust, or public meaning.
288.2 Privacy as Public-Benefit Duty. Privacy shall be read as part of GCRI Canada’s public-benefit duty. GCRI Canada shall not pursue evidence, research, observability, AI, compute, public-good software, technical baselines, dashboards, maps, publications, public authority learning, or Nexus interoperability in a manner that treats persons, communities, contributors, fellows, participants, public authority personnel, knowledge holders, or affected populations as extractive data sources. Public-benefit use of data shall require lawful basis, proportionality, necessity, safeguards, minimization, limitation, correctionability, and respect for rights-bearing context.
288.3 Privacy as Safeguards Duty. Privacy shall be part of GCRI Canada’s safeguards duty. Where information concerns communities, Indigenous peoples, local or territorial knowledge holders, vulnerable persons, protected participants, youth, health-sensitive populations, public authority personnel, whistleblowers, complainants, or persons affected by systemic risk, GCRI Canada shall apply privacy safeguards that account for power imbalance, retaliation risk, stigmatization, re-identification, surveillance risk, public exposure, sponsor or provider misuse, public authority sensitivity, protected knowledge, and public-safe publication.
288.4 Privacy as Governance Integrity Duty. Privacy shall support governance integrity by ensuring that governance records, Board materials, committee records, council materials, contributor records, conflict records, complaints, investigations, disciplinary records, public authority participation records, sponsor records, provider records, donor records, employment records, and controlled-room records are collected, accessed, disclosed, retained, and corrected only under lawful authority and recorded purpose. Governance integrity shall not be used to justify excessive collection, uncontrolled internal access, or indefinite retention of rights-bearing data.
288.5 Privacy as Research Integrity Duty. Privacy shall support research integrity by ensuring that research data, participant information, survey responses, interviews, community inputs, public authority inputs, health-sensitive records, model outputs, derived data, synthetic data, embeddings, inference records, and publication materials are handled in a lawful, ethical, limited, accurate, secure, transparent, and correctionable manner. Research integrity shall require privacy review where research methods, AI processing, observability, geospatial analysis, dashboards, public-safe outputs, or data linkage may create privacy risk.
288.6 Privacy as Public Authority Boundary Duty. Privacy shall preserve public authority boundaries. Public authority participation, data contribution, regulator-listening participation, public finance reader participation, emergency-management participation, public infrastructure operator participation, or public authority learning shall not authorize uncontrolled collection, reuse, publication, AI training, embedding, retrieval, cross-border transfer, provider access, sponsor access, or commercial use of public authority data. Privacy controls shall preserve capacity classification, no-delegation, no-public-warning, no-emergency-command, no-regulatory-approval, no-procurement-approval, no-funding-approval, no-public-finance-approval, and no-sovereign-obligation boundaries.
288.7 Privacy as Community Protection Duty. Privacy shall protect communities from extraction, exposure, misclassification, stigmatization, targeting, retaliation, unsafe mapping, public-safe failure, protected knowledge leakage, and loss of context. Community-related data shall not be treated as ordinary operational data merely because it is observable, mappable, contributed, inferable, or technically accessible. Community privacy shall include attention to collective harms, place-based sensitivity, small-population risk, geospatial re-identification, cultural context, environmental knowledge, and custodial authority.
288.8 Privacy as Rights-Bearing Data Duty. GCRI Canada shall treat rights-bearing data as information that may affect legal rights, dignity, autonomy, safety, participation, public standing, livelihood, employment, community relationship, cultural integrity, access to services, public authority interaction, or exposure to harm. Rights-bearing data may be personal, community-linked, location-linked, inferred, derived, synthetic, pseudonymized, de-identified with residual risk, model-generated, or embedded in records. Rights-bearing character shall trigger heightened review even where data is not obviously identifiable.
288.9 Privacy by Design. GCRI Canada shall embed privacy by design into programs, research protocols, evidence systems, observability systems, AI systems, retrieval systems, compute environments, repositories, dashboards, maps, public-safe publication workflows, controlled rooms, data rooms, technical assets, and Nexus interfaces. Privacy by design shall include purpose definition, data minimization, access control, classification, retention limits, deletion pathways, public-safe review, re-identification risk assessment, security controls, auditability, and correctionability before deployment or material use.
288.10 Privacy by Default. GCRI Canada shall apply privacy-protective defaults. Default settings shall limit collection, access, sharing, publication, AI use, embedding, retrieval, model training, external transfer, public display, export, retention, and re-disclosure unless a lawful and recorded basis permits broader use. Where privacy risk is uncertain, the more protective reasonable classification, access rule, and publication posture shall apply until review resolves the issue.
288.11 Privacy in Evidence Systems. Evidence systems shall preserve privacy by recording source authority, permission, classification, sensitivity, purpose, permitted use, prohibited use, access controls, public-safe status, confidence, limitations, correction path, retention, deletion, and dependency. Evidence status shall not override privacy obligations. No evidence record shall be used, shared, published, linked, modeled, or embedded beyond lawful authority merely because it is useful to a research, governance, public authority, finance-boundary, or Nexus interface question.
288.12 Privacy in Observability Systems. Observability systems shall apply privacy controls to telemetry, sensors, AI-RAN signals, O-RAN signals, DePIN records, cyber logs, geospatial records, Earth observation, dashboards, maps, digital twins, degraded-mode indicators, resilience indicators, and public-safe outputs. Observability shall not become surveillance by convenience, nor shall it expose persons, communities, public authority personnel, infrastructure users, protected participants, or sensitive locations through excessive granularity, uncontrolled linkage, or unsafe publication.
288.13 Privacy in AI, Model, Inference, and Compute Systems. AI, model, inference, retrieval, embedding, vector store, prompt, compute, agentic AI, Truth Engine, verifiable compute, and verifiable intelligence systems shall apply privacy controls before processing rights-bearing data. Controls shall include lawful basis, data minimization, input classification, output classification, model-use restrictions, training restrictions, embedding restrictions, retrieval permission mapping, human review, logging, leakage review, deletion pathway, provider review, cross-border review, public-safe review, and incident response.
288.14 Privacy in Publications, Dashboards, Maps, Reports, Datasets, Repositories, and Public Materials. Public-facing materials shall undergo privacy review where they contain, imply, summarize, visualize, map, aggregate, infer, or enable re-identification of rights-bearing data. GCRI Canada shall use redaction, aggregation, de-identification, suppression, delay, generalization, access restriction, controlled annexing, limitation language, and publication denial where needed. Public communication shall not sacrifice privacy to achieve visibility, sponsor value, provider value, public authority attention, media impact, or apparent technical sophistication.
288.15 Privacy in Controlled Rooms, Data Rooms, Evidence Rooms, Public Authority Rooms, and No-Download Rooms. Controlled rooms, data rooms, evidence rooms, public authority rooms, and no-download rooms shall be governed by privacy rules that identify permitted users, permitted purposes, access controls, viewing restrictions, download restrictions, AI-use restrictions, copying restrictions, export restrictions, logging, confidentiality, retention, closeout, deletion, and correction. Room access shall not authorize secondary use, model training, embedding, external sharing, publication, or commercial use.
288.16 Privacy Escalation and Stop-the-Line Duty. Any director, officer, employee, contractor, fellow, contributor, advisor, reviewer, maintainer, volunteer, committee participant, council participant, or authorized user who identifies a material privacy concern shall have a duty to escalate the concern through approved channels. Where a privacy risk may cause material harm, unlawful use, protected knowledge exposure, public authority breach, data leakage, unsafe publication, re-identification, unauthorized AI processing, or uncontrolled external transfer, GCRI Canada may impose a stop-the-line hold pending review.
288.17 Privacy Records. GCRI Canada shall maintain privacy records, including privacy purpose records, lawful basis records, classification records, privacy-by-design records, privacy-by-default records, evidence-system privacy records, observability privacy records, AI and compute privacy records, publication privacy reviews, dashboard and map privacy reviews, controlled-room privacy records, data-room privacy records, public authority room records, no-download room records, escalation records, stop-the-line records, correction records, deletion records, incident records, and archives.
Section 289. Lawful Basis, Purpose Limitation, Proportionality, Minimization, Accuracy, Storage Limitation, and Bounded Use
289.1 Lawful Basis Requirement. GCRI Canada shall collect, receive, process, store, share, publish, transfer, delete, seal, archive, retain, model, infer, embed, retrieve, train on, or otherwise use personal information and rights-bearing data only where a lawful basis, contractual basis, consent basis, public-benefit basis recognized by law, research basis, legal obligation, legitimate institutional authority, public authority term, contributor term, ethics approval, safeguards approval, or other competent authority applies. Lawful basis shall be recorded before material processing wherever practicable.
289.2 Authority to Collect. Collection of rights-bearing data shall require recorded authority identifying source, purpose, necessity, data class, collection method, consent or alternative lawful basis where applicable, notice requirements, public authority terms, protected knowledge rules, sensitive data status, safeguards requirements, and intended use. GCRI Canada shall not collect data merely because it may be interesting, useful later, technically available, funder-attractive, sponsor-requested, provider-requested, or convenient.
289.3 Authority to Process. Processing shall require authority tied to a defined purpose. Processing includes cleaning, linking, classifying, analyzing, scoring, inferring, translating, summarizing, modeling, training, fine-tuning, embedding, retrieval indexing, transforming, redacting, aggregating, de-identifying, visualizing, publishing, or otherwise using data. Authority to possess data shall not automatically include authority to process it for every possible purpose.
289.4 Authority to Store. Storage shall require authority tied to purpose, classification, retention, access controls, jurisdiction, security, and deletion or archival pathway. GCRI Canada shall not store rights-bearing data in uncontrolled repositories, unmanaged devices, unapproved cloud systems, consumer AI tools, unlogged notebooks, public folders, or environments inconsistent with sensitivity and lawful basis.
289.5 Authority to Share. Sharing shall require recorded authority identifying recipient, purpose, data class, permitted use, prohibited use, confidentiality, public authority terms, protected knowledge obligations, data rights, re-disclosure limits, AI-use restrictions, retention, deletion, correction rights, and safeguards. Internal sharing shall be subject to need-to-know and purpose limits; external sharing shall require heightened review where data is sensitive or rights-bearing.
289.6 Authority to Publish. Publication of rights-bearing data, summaries, maps, dashboards, reports, datasets, public-safe materials, or derived outputs shall require public-safe review and recorded authority. Publication authority shall address re-identification risk, protected knowledge, public authority restrictions, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive materials, community harm, participant harm, and limitation language. Publication shall not proceed merely because information has been de-identified, aggregated, or transformed.
289.7 Authority to Transfer. Transfer of rights-bearing data across systems, rooms, repositories, jurisdictions, providers, public authorities, partners, cloud regions, AI platforms, or Nexus interfaces shall require recorded authority. Transfer authority shall identify destination, jurisdiction, recipient, access controls, encryption, retention, deletion, public authority terms, protected knowledge rules, export-control considerations, sanctions screening where applicable, and correction path.
289.8 Authority to Delete, Seal, Archive, or Retain. Deletion, sealing, archival, or retention shall be governed by law, policy, consent, data subject rights, public authority terms, research integrity, legal holds, investigation requirements, public safety, cyber security, protected knowledge obligations, correctionability, and institutional memory. GCRI Canada shall not retain rights-bearing data indefinitely merely because storage is inexpensive or future utility is possible, nor shall it delete data where lawful holds or correctionability require preservation.
289.9 Purpose Limitation. Rights-bearing data shall be used only for the purpose for which it was collected, received, authorized, or lawfully repurposed. Purpose limitation shall apply to governance data, research data, evidence data, public authority data, participant data, community data, technical telemetry, AI inputs, embeddings, model outputs, dashboards, maps, and public-safe publications. Any new purpose shall require review and record.
289.10 Recorded Purpose. Each material collection or processing activity shall have a recorded purpose. The purpose shall be specific enough to determine what data is necessary, what processing is permitted, who may access the data, what outputs may be created, whether publication is permitted, whether AI use is permitted, whether transfer is permitted, and how correction, retention, deletion, or archival will occur.
289.11 Proportionality. Processing of rights-bearing data shall be proportionate to the public-benefit, governance, research, evidence, security, public authority learning, technical development, safeguards, or publication purpose pursued. GCRI Canada shall consider whether the same purpose can be achieved with less data, less sensitive data, shorter retention, narrower access, weaker identifiability, fewer linkages, no AI processing, no publication, or controlled-room use.
289.12 Necessity. GCRI Canada shall process only rights-bearing data that is necessary for the recorded purpose. Necessity shall be assessed before collection and before material secondary processing. Data shall not be deemed necessary because it improves convenience, enables speculative analysis, strengthens marketing, satisfies sponsor curiosity, supports provider advantage, or makes dashboards appear more complete.
289.13 Data Minimization. GCRI Canada shall minimize data by limiting fields, time periods, geographies, identifiers, precision, granularity, linkages, model inputs, retention, and access to what is necessary and proportionate. Minimization may include aggregation, redaction, suppression, pseudonymization, de-identification, delayed publication, controlled access, compute-to-data, and avoidance of collection. Minimization shall not strip context in a manner that creates misleading evidence or unsafe public conclusions.
289.14 Accuracy. GCRI Canada shall take reasonable steps to maintain accuracy of rights-bearing data where accuracy affects rights, dignity, safety, evidence integrity, research integrity, public authority use, public-safe outputs, or correctionability. Accuracy controls may include source verification, update requests, correction pathways, confidence notes, limitation statements, stale-data flags, and dispute markers. Inaccurate data shall not be allowed to persist in active use without limitation.
289.15 Completeness Where Required. Where incomplete data could create unfairness, misunderstanding, public authority confusion, community harm, bias, discriminatory output, unsafe publication, false confidence, or incorrect evidence, GCRI Canada shall assess completeness and record limitations. Completeness shall be required only to the extent appropriate to purpose; excessive collection shall not be justified by an abstract desire for completeness.
289.16 Storage Limitation. Rights-bearing data shall be retained only for as long as necessary for the recorded purpose, legal obligation, public authority term, research integrity, correctionability, auditability, safeguards obligation, incident response, or institutional memory. Retention schedules shall distinguish active use, restricted use, archive, sealed archive, deletion, and anonymized or aggregated retention where lawful.
289.17 Bounded Use. GCRI Canada shall maintain bounded use for rights-bearing data. Bounded use shall define permitted users, purposes, systems, environments, outputs, publications, transfers, AI processing, retention, deletion, correction, and restrictions. Bounded use shall travel with derived data, model outputs, embeddings, summaries, dashboards, maps, and public-safe materials where required.
289.18 No Secondary Use Without Recorded Authority. No secondary use of rights-bearing data shall occur without review and recorded authority. Secondary use includes using governance data for research, research data for publication, public authority data for technical development, community data for dashboards, participant data for AI training, protected knowledge for models, or provider-supplied data for sponsor-facing materials beyond the original purpose.
289.19 No Convenience Use. Convenience shall not be a lawful or sufficient institutional basis for collecting, processing, storing, linking, retrieving, embedding, transferring, publishing, or retaining rights-bearing data. GCRI Canada shall not normalize convenience use through practice, tool defaults, repository access, unrestricted dashboards, unreviewed AI workflows, informal sharing, or repeated exceptions.
289.20 Lawful Basis and Purpose Records. GCRI Canada shall maintain lawful basis and purpose records, including authority-to-collect records, authority-to-process records, authority-to-store records, authority-to-share records, authority-to-publish records, authority-to-transfer records, deletion / sealing / archival / retention authority records, purpose limitation records, recorded purpose records, proportionality records, necessity records, minimization records, accuracy records, completeness records, storage limitation records, bounded-use records, secondary-use approvals, convenience-use denials, corrections, and archives.
Section 290. Rights of Access, Correction, Restriction, Objection, Deletion, Complaint, and Appeal
290.1 Data Rights Purpose. GCRI Canada shall maintain pathways for rights of access, correction, restriction, objection, deletion, portability where applicable, complaint, and appeal in relation to personal information and rights-bearing data, subject to applicable law, identity verification, public authority terms, research integrity, safeguards, protected knowledge obligations, legal holds, cyber security, public safety, archival duties, and correctionability. Data rights procedures shall be fair, recorded, proportionate, non-retaliatory, and understandable.
290.2 Access Requests. A person may request access to personal information about that person held by GCRI Canada where applicable law or policy permits. Access requests shall be handled with identity verification, scope review, sensitivity review, third-party rights review, public authority review where applicable, protected knowledge review where applicable, and privilege review where applicable. Access may be provided, limited, redacted, deferred, or denied where lawful grounds require such treatment.
290.3 Correction Requests. A person may request correction of inaccurate, incomplete, outdated, misclassified, misleading, or improperly attributed personal information or rights-bearing data. Correction requests shall be reviewed against source records, evidence records, research records, public authority records, community safeguards, protected knowledge protocols, and institutional records. Where correction is accepted, GCRI Canada shall update affected records and review downstream dependencies where material.
290.4 Restriction Requests. A person may request restriction of processing where data is disputed, unlawfully processed, no longer necessary, subject to objection, sensitive, or otherwise eligible for restriction under law or policy. Restriction may include access limitation, processing hold, publication hold, AI-use prohibition, embedding hold, retrieval exclusion, transfer restriction, dashboard removal, map suppression, or archive-only handling.
290.5 Objection Requests. A person may object to processing where applicable law or policy permits, including processing for research, publication, AI processing, profiling, inference, public-safe outputs, dashboards, maps, external sharing, or secondary use. Objection review shall consider lawful basis, public-benefit purpose, research integrity, public authority obligations, safeguards, rights impact, and alternatives such as minimization, restriction, anonymization, aggregation, or withdrawal from publication.
290.6 Deletion Requests. A person may request deletion of personal information where applicable law or policy permits. Deletion review shall consider lawful basis, retention obligations, legal holds, public authority terms, research integrity, archival obligations, correctionability, protected knowledge obligations, cyber security, public safety, and downstream records. Deletion may include deletion, restriction, de-identification, sealing, suppression, or archive-only treatment depending on legal and institutional requirements.
290.7 Portability Requests Where Applicable. Where applicable law provides a portability right, GCRI Canada shall provide personal information in a structured, commonly used, machine-readable, or otherwise appropriate format, subject to identity verification, rights of others, security, public authority restrictions, protected knowledge, confidentiality, technical feasibility, and legal limits. Portability shall not require disclosure of internal analytics, privileged materials, protected knowledge, or third-party confidential information.
290.8 Complaint Pathways. GCRI Canada shall maintain complaint pathways for privacy concerns, data rights concerns, unauthorized use, unsafe publication, re-identification, data leakage, public authority data misuse, protected knowledge misuse, AI-use concerns, retrieval exposure, dashboard or map concerns, and retaliation concerns. Complaints shall be triaged, recorded, reviewed, and resolved or escalated under a fair process.
290.9 Appeal Pathways. GCRI Canada shall maintain appeal or reconsideration pathways where a request for access, correction, restriction, objection, deletion, portability, or complaint resolution is denied or only partially granted, where applicable and appropriate. Appeals shall be reviewed by a person or function sufficiently independent of the original decision where practicable and shall be recorded with reasons.
290.10 Identity Verification for Requests. GCRI Canada shall verify identity before disclosing, correcting, restricting, deleting, transferring, or otherwise acting on rights-bearing data where identity matters. Verification shall be proportionate and shall not require excessive collection. Where requests are made by authorized representatives, custodians, guardians, public authorities, community bodies, Indigenous governance bodies, or legal representatives, authority to act shall be reviewed.
290.11 Public Authority Data Request Handling. Requests involving public authority data shall be handled according to public authority terms, law, confidentiality, public reference limits, capacity classification, records obligations, and correction rights. GCRI Canada shall not disclose public authority-sensitive records or public authority personnel data without authority, and shall not treat public authority-provided data as ordinary organizational data.
290.12 Research Data Request Handling. Requests involving research data shall account for consent, ethics approvals, research integrity, confidentiality, anonymization, de-identification, participant protections, publication status, source integrity, and legal obligations. GCRI Canada may limit access or deletion where necessary and lawful to preserve research integrity, safety, confidentiality, or public-benefit records, while providing correction or restriction where appropriate.
290.13 Community-Protected Data Request Handling. Requests involving community-protected data shall account for individual rights, collective safeguards, community protocols, custodial authority, consent, non-extraction, public-safe use, harm prevention, and correction rights. GCRI Canada shall avoid resolving community-protected data requests in a way that exposes protected knowledge or undermines legitimate custodial governance.
290.14 Indigenous / Local / Territorial Knowledge Request Handling. Requests involving Indigenous, local, or territorial knowledge shall be handled in accordance with applicable law, protocols, custodial authority, consent or authorization, attribution, withdrawal rights, correction rights, access restrictions, public-safe limits, and safeguards. GCRI Canada shall not use generic privacy procedures to override Indigenous or local knowledge governance where more protective handling is required.
290.15 Protected Participant Request Handling. Requests involving protected participants, whistleblowers, complainants, vulnerable persons, public authority personnel, community participants, or persons at risk of retaliation shall be handled with confidentiality, safety review, anti-retaliation controls, identity protection, access limitation, and public-safe communication. Disclosure shall be limited where it could expose the person to harm.
290.16 Conflict With Legal Holds, Research Integrity, Public Safety, Cybersecurity, or Public Authority Obligations. Where a data rights request conflicts with legal holds, investigation obligations, research integrity, public safety, cybersecurity, public authority obligations, protected knowledge obligations, archival obligations, or correctionability, GCRI Canada shall balance the request against the applicable obligation and record the decision. Where full compliance is not possible, GCRI Canada may provide partial access, correction note, restriction, sealing, limitation, or explanation where lawful.
290.17 Response Timelines. GCRI Canada shall respond to data rights requests within timelines required by applicable law, agreement, policy, or recorded process. Where additional time is needed due to complexity, sensitivity, public authority terms, protected knowledge review, identity verification, legal review, or technical retrieval, the extension and reason shall be recorded and communicated where required.
290.18 Request Records and Outcome Records. GCRI Canada shall maintain request and outcome records, including access requests, correction requests, restriction requests, objection requests, deletion requests, portability requests, complaints, appeals, identity verification records, public authority data request records, research data request records, community-protected data records, Indigenous / local / territorial knowledge request records, protected participant request records, conflict-resolution records, response timelines, outcomes, notices, corrections, restrictions, deletions, refusals, reasons, and archives.
Section 291. Privacy Impact Review for High-Risk Activities and Systems
291.1 Privacy Impact Review Purpose. GCRI Canada shall conduct privacy impact review for high-risk activities, systems, programs, research, evidence processes, observability systems, AI systems, compute environments, dashboards, maps, repositories, controlled rooms, data rooms, public authority rooms, public-safe publications, and Nexus interfaces where rights-bearing data may be materially affected. Privacy impact review shall identify privacy risks, safeguards risks, legal risks, public authority risks, community risks, AI risks, cyber risks, re-identification risks, publication risks, and correction needs before material deployment or use.
291.2 High-Risk Activity Triggers. A privacy impact review shall be triggered by activities involving sensitive personal information, health-sensitive data, public authority data, community-protected data, Indigenous / local / territorial knowledge, protected participants, high-volume data, vulnerable persons, AI processing, model training, fine-tuning, embedding, retrieval, inference, observability, geospatial mapping, sensors, AI-RAN, DePIN, digital twins, dashboards, cross-border transfer, external sharing, controlled rooms, no-download rooms, or public release of rights-bearing information.
291.3 Sensitive Personal Information Trigger. Processing sensitive personal information shall trigger privacy impact review where the processing may affect rights, dignity, safety, employment, participation, health, public standing, public authority relationship, community relationship, or exposure to harm. Sensitive personal information shall include health, biometric, financial, location, identity, demographic, complaint, whistleblower, youth, vulnerable person, protected participant, and other high-impact data.
291.4 Health-Sensitive Data Trigger. Health-sensitive data shall trigger privacy impact review before collection, linkage, analysis, AI processing, dashboarding, mapping, sharing, publication, or transfer. Review shall address lawful basis, ethics, public authority terms, de-identification, small-cell risk, stigma, public-safe communication, public health sensitivity, biosecurity sensitivity, health-system sensitivity, and harm prevention.
291.5 Public Authority Data Trigger. Public authority data shall trigger privacy impact review where it includes personal information, public authority personnel data, infrastructure-sensitive data, public finance information, emergency-management information, regulatory information, public health information, public safety information, or public-sector operational context. Review shall preserve public authority capacity classification and boundary language.
291.6 Community-Protected Data Trigger. Community-protected data shall trigger privacy impact review where collection, processing, mapping, publication, AI use, retrieval, or sharing could affect community safety, dignity, autonomy, reputation, protected knowledge, territorial relationships, public standing, resource access, or exposure to targeting. Review shall include safeguards assessment and may require community or custodial consultation.
291.7 Indigenous / Local / Territorial Knowledge Trigger. Indigenous, local, or territorial knowledge shall trigger privacy impact review and safeguards review before collection, processing, publication, mapping, AI use, embedding, retrieval, transfer, or commercial use. Review shall account for custodial authority, consent, attribution, non-extraction, withdrawal rights, correction rights, protected knowledge, data sovereignty, and public-safe limits.
291.8 Cross-Border Transfer Trigger. Cross-border transfer of rights-bearing data shall trigger privacy impact review where jurisdiction, cloud region, provider access, support access, public authority terms, protected knowledge obligations, export-control rules, sanctions rules, foreign law exposure, or data sovereignty may affect rights or obligations. Review shall determine whether transfer is lawful, necessary, proportionate, secure, limited, and correctionable.
291.9 AI Processing Trigger. AI processing of rights-bearing data shall trigger privacy impact review where models, inference, summarization, classification, scoring, retrieval, embedding, agentic action, model training, model improvement, or automated analysis may affect rights, public meaning, public authority context, protected knowledge, cyber risk, infrastructure sensitivity, or public-safe outputs. Review shall include model identity, provider terms, data-use settings, human review, leakage risk, bias, drift, and correction path.
291.10 Model Training, Fine-Tuning, Embedding, Retrieval, or Inference Trigger. Any proposal to use rights-bearing data for model training, fine-tuning, embeddings, vector stores, retrieval indexing, knowledge graphs, model improvement, inference records, or public-safe AI outputs shall trigger review. Review shall verify lawful basis, consent or other authority, deletion path, access controls, re-identification risk, model-use limits, provider terms, public authority terms, protected knowledge restrictions, and safeguards.
291.11 Observability, Sensor, AI-RAN, DePIN, Geospatial, Digital Twin, or Dashboard Trigger. Observability involving persons, communities, public authority contexts, sensitive locations, infrastructure users, network identifiers, device identifiers, sensors, AI-RAN signals, O-RAN signals, DePIN records, geospatial data, Earth observation, digital twins, degraded-mode indicators, resilience indicators, or dashboards shall trigger privacy impact review where rights-bearing data or re-identification risk exists. Review shall address granularity, linkage, publication, surveillance risk, and public-safe treatment.
291.12 Controlled-Room or No-Download Room Trigger. Creation or material use of a controlled room, data room, evidence room, public authority room, safeguards room, cyber-sensitive room, infrastructure-sensitive room, finance-sensitive room, or no-download room containing rights-bearing data shall trigger privacy impact review where risk requires it. Review shall address access, logging, copying, AI use, exports, retention, closeout, deletion, and correction.
291.13 Publication, Mapping, or Public-Safe Release Trigger. Publication, mapping, dashboard display, report release, dataset release, repository publication, public-safe summary, public notice, or external communication involving rights-bearing data shall trigger privacy impact review where there is any material risk of identification, inference, protected knowledge exposure, public authority misdescription, community harm, public panic, cyber misuse, infrastructure targeting, or unsafe reliance.
291.14 Privacy Risk Assessment. Privacy risk assessment shall identify data subjects, rights-bearing communities, data categories, sensitivity, volume, identifiability, linkability, lawful basis, purpose, necessity, proportionality, minimization, access, retention, deletion, security, AI use, model use, publication risk, transfer risk, re-identification risk, public authority risk, safeguards risk, and incident risk. The assessment shall identify residual risk and decision options.
291.15 Safeguards Assessment. Where high-risk processing involves communities, Indigenous / local / territorial knowledge, protected participants, vulnerable persons, health-sensitive data, public authority personnel, protected knowledge, or community-sensitive context, the privacy impact review shall include safeguards assessment. Safeguards assessment shall address consent, custodial authority, non-extraction, attribution, withdrawal rights, correction rights, community harm, retaliation risk, and public-safe representation.
291.16 Mitigation Plan. Each material privacy impact review shall include a mitigation plan where risk is identified. Mitigations may include minimization, redaction, aggregation, pseudonymization, de-identification, suppression, access restriction, no-download controls, compute-to-data, deletion limits, retention limits, AI-use prohibition, embedding prohibition, publication denial, public-safe limitation, community review, public authority review, legal review, security controls, or re-scoping.
291.17 Approval, Deferral, Re-Scoping, Quarantine, or Denial. A privacy impact review may result in approval, conditional approval, deferral, re-scoping, quarantine, denial, escalation, or stop-the-line hold. Approval shall not be granted where privacy risk, protected knowledge risk, public authority risk, cyber risk, infrastructure risk, public-safe risk, or legal risk cannot be controlled in a manner consistent with GCRI Canada’s public-benefit purpose and non-executing role.
291.18 Privacy Impact Review Records. GCRI Canada shall maintain privacy impact review records, including high-risk trigger records, sensitive personal information reviews, health-sensitive data reviews, public authority data reviews, community-protected data reviews, Indigenous / local / territorial knowledge reviews, cross-border transfer reviews, AI processing reviews, model training / fine-tuning / embedding / retrieval / inference reviews, observability / sensor / AI-RAN / DePIN / geospatial / digital twin / dashboard reviews, controlled-room reviews, publication reviews, risk assessments, safeguards assessments, mitigation plans, decisions, conditions, corrections, and archives.
Section 292. Separation Between Governance Need, Research Need, and Convenience Use
292.1 Separation Principle. GCRI Canada shall maintain separation between governance need, research need, evidence need, public authority learning need, technical development need, security need, publication need, and convenience use. Data collected or accessed for one institutional need shall not be reused for another need unless recorded authority permits the reuse and privacy, data rights, public authority, safeguards, AI, cyber, and public-safe requirements are satisfied.
292.2 Governance Need. Governance need may include Board administration, committee administration, member or participant administration, conflict review, compliance, legal obligations, corporate records, fiduciary oversight, policy implementation, complaints, investigations, risk management, financial administration, and institutional continuity. Governance data shall not be repurposed for research, AI training, public dashboards, sponsor reports, provider materials, or commercial use without authority.
292.3 Research Need. Research need may include approved study, analysis, evidence formation, methods development, observability research, ontology development, public-good software research, public authority learning research, safeguards research, technical baseline development, or publication preparation. Research data shall remain within the scope of consent, ethics approval, lawful basis, protocol, and public-safe review.
292.4 Evidence Need. Evidence need may include source review, evidence records, confidence notes, limitation notes, assurance packs, evidence packs, Board materials, council materials, technical records, public-safe summaries, or Nexus interface artifacts. Evidence need shall not permit indiscriminate collection or unrestricted processing; evidence must remain tied to a defined question and correction path.
292.5 Public Authority Learning Need. Public authority learning need may include capacity formation, scenario literacy, evidence literacy, technical literacy, public-safe understanding, observability literacy, and policy-adjacent education. Public authority learning need shall not convert public authority data into GCRI Canada operational authority, public warning authority, regulatory authority, procurement authority, funding authority, public finance authority, or sovereign obligation.
292.6 Technical Development Need. Technical development need may include software development, schema development, API testing, dashboard development, model evaluation, test harness development, baseline development, observability tooling, retrieval tooling, and secure compute design. Technical development shall use synthetic, de-identified, minimized, public-safe, or test data where possible and shall not use sensitive real-world rights-bearing data without authority and review.
292.7 Security Need. Security need may include access logs, incident response, vulnerability management, repository security, credential controls, audit logs, threat modeling, cyber telemetry review, and abuse detection. Security data shall be accessed and retained only to the extent necessary for security, legal, audit, correction, or incident purposes and shall not be repurposed for unrelated monitoring, personnel profiling, or public claims without authority.
292.8 Publication Need. Publication need may include public-safe reports, dashboards, maps, datasets, summaries, teaching materials, public authority learning materials, technical notes, research papers, and public notices. Publication need shall require public-safe review and shall not override privacy, protected knowledge, public authority restrictions, confidentiality, data rights, or re-identification concerns.
292.9 Convenience Use. Convenience use means use of data because it is easy to access, already collected, technically searchable, useful for a dashboard, available in a repository, beneficial for a sponsor or provider, helpful for fundraising, faster for a model, attractive for publication, or administratively convenient, without a recorded lawful purpose and proportionality review. Convenience use is not an institutional purpose.
292.10 Prohibition on Convenience Use of Sensitive Data. GCRI Canada shall not use sensitive personal information, health-sensitive data, protected knowledge, public authority data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, controlled-room materials, no-download-room materials, or restricted evidence for convenience purposes. Sensitive data shall require defined purpose, lawful basis, necessity, proportionality, access control, and correction path.
292.11 Prohibition on Reusing Governance Data for Research Without Authority. Governance data shall not be reused for research without recorded authority, privacy review where required, ethics review where required, purpose compatibility review, minimization, notice or consent where required, and safeguards. Governance participation shall not become research participation by implication.
292.12 Prohibition on Reusing Research Data for Publication Without Authority. Research data shall not be reused for publication, dashboards, maps, datasets, public-safe summaries, media materials, sponsor reports, provider materials, or Nexus interface materials unless the publication use is authorized by the research protocol, consent, ethics approval, lawful basis, public-safe review, and applicable restrictions.
292.13 Prohibition on Reusing Public Authority Data for Provider, Sponsor, or Commercial Benefit. Public authority data shall not be reused for provider advantage, sponsor benefit, commercial marketing, procurement positioning, finance-readiness claims, certification claims, recognition claims, product development, model training, or external business value unless a lawful authority expressly permits such use and GCRI Canada’s public-benefit, role-separation, privacy, and public authority boundary controls are satisfied.
292.14 Prohibition on Reusing Community-Protected Data Outside Safeguarded Purpose. Community-protected data and Indigenous / local / territorial knowledge shall not be reused outside the safeguarded purpose for which it was provided or authorized. Reuse for research, publication, dashboards, maps, AI processing, training, embedding, retrieval, sponsor materials, provider materials, public authority materials, or Nexus interfaces shall require safeguards review, custodial authority, and public-safe review where applicable.
292.15 Separation Records. GCRI Canada shall maintain separation records, including governance need records, research need records, evidence need records, public authority learning need records, technical development need records, security need records, publication need records, convenience-use denials, secondary-use reviews, governance-to-research reuse records, research-to-publication reuse records, public authority data reuse records, community-protected data reuse records, safeguards records, privacy reviews, corrections, and archives.
Section 293. No Re-Identification, Secondary Use, or Broadening of Processing Without Recorded Authority
293.1 No Re-Identification Rule. GCRI Canada shall not re-identify, attempt to re-identify, enable re-identification, or publish materials likely to permit re-identification of de-identified, pseudonymized, anonymized, aggregated, masked, suppressed, synthetic, derived, embedded, or public-safe data unless lawful, necessary, authorized, safeguarded, and recorded. Re-identification prohibition shall apply to people, protected participants, knowledge holders, communities, small groups, public authority personnel, sensitive locations, and rights-bearing contexts.
293.2 Re-Identification Exception Only Where Lawful, Necessary, Authorized, and Safeguarded. Re-identification may occur only where lawful, necessary, proportionate, authorized, and safeguarded for a specific purpose such as correction, rights request, research integrity, legal obligation, public safety, cyber incident response, public authority requirement, protected knowledge withdrawal, or participant protection. Re-identification shall be limited to authorized persons, logged, access-controlled, and subject to deletion, sealing, or restriction after the purpose is complete.
293.3 No Secondary Use Without Review. No secondary use of rights-bearing data shall occur without review. Secondary use review shall assess lawful basis, purpose compatibility, consent or notice where required, public authority terms, protected knowledge, privacy, minimization, proportionality, access controls, AI-use restrictions, publication risk, transfer risk, re-identification risk, safeguards, and correctionability.
293.4 No Purpose Broadening by Practice. Purpose shall not broaden through repeated informal use, operational habit, repository access, dashboard reuse, meeting practice, contributor expectation, sponsor request, provider request, public authority request, or internal convenience. A practice inconsistent with the recorded purpose shall not become authorized merely because it has occurred before.
293.5 No Purpose Broadening by Technical Capability. Technical capability to link, retrieve, embed, infer, model, search, summarize, publish, map, visualize, or transfer data shall not broaden lawful purpose. Tools, AI systems, dashboards, APIs, repositories, vector stores, and compute environments shall be governed by recorded authority, not by what they technically allow.
293.6 No Purpose Broadening by Sponsor, Provider, Donor, Public Authority, or Partner Request. No sponsor, provider, donor, funder, public authority, partner, host, university, laboratory, National Consortium Company, Project SPV, or other external actor may broaden GCRI Canada’s data processing purpose by request, funding, participation, in-kind support, political interest, operational need, or commercial preference. Purpose broadening requires GCRI Canada’s own lawful review and record.
293.7 No AI Training, Fine-Tuning, Embedding, or Model Improvement Without Authority. Rights-bearing data shall not be used for AI training, fine-tuning, embedding, retrieval indexing, vector stores, model improvement, benchmark generation, synthetic data generation, or inference workflows without recorded authority and review. Authority shall identify data classes, model identity, provider terms, deletion path, access controls, public authority terms, protected knowledge, retention, and correction path.
293.8 No External Sharing Without Authority. Rights-bearing data shall not be shared with external actors without recorded authority. External sharing shall identify recipient, purpose, data class, legal basis, confidentiality, public authority terms, protected knowledge restrictions, AI-use limits, re-disclosure limits, transfer location, retention, deletion, and correction obligations.
293.9 No Publication Without Public-Safe Review. Rights-bearing data, derived outputs, maps, dashboards, reports, datasets, model outputs, public-safe summaries, and publications shall not be publicly released without public-safe review. Review shall address re-identification, protected knowledge, public authority limits, cyber-sensitive content, infrastructure-sensitive content, finance-sensitive content, community harm, public overclaim, and limitation language.
293.10 No Cross-Border Transfer Without Review. Rights-bearing data shall not be transferred across borders, cloud regions, support jurisdictions, provider systems, AI platforms, repositories, or partner systems without cross-border review where material. Review shall address law, public authority terms, privacy, protected knowledge, data sovereignty, export controls, sanctions, cyber risk, retention, deletion, and correctionability.
293.11 No Re-Identification in Publications, Dashboards, Maps, or Reports. Publications, dashboards, maps, reports, public-safe summaries, datasets, repositories, and visualizations shall not present information in a way that identifies or enables re-identification of persons, protected participants, small groups, sensitive locations, knowledge holders, public authority personnel, or communities unless lawful, necessary, authorized, public-safe, and safeguarded. Small-cell suppression, geospatial generalization, aggregation, delay, masking, and redaction shall be used where needed.
293.12 Secondary Use Review. Secondary use review shall document proposed new use, original purpose, compatibility, lawful basis, data categories, affected persons or communities, sensitivity, public authority terms, protected knowledge obligations, AI-use implications, transfer implications, publication implications, safeguards, minimization, retention, deletion, and correction path. Review may approve, condition, re-scope, defer, deny, quarantine, or escalate the use.
293.13 Re-Identification Incident Response. A re-identification incident shall trigger containment, access restriction, publication hold, dashboard or map restriction, source review, public-safe review, data / AI / cyber review, safeguards review, public authority review where applicable, notification review, correction, deletion or suppression where appropriate, and post-incident review. Re-identification incident records shall preserve evidence without amplifying exposure.
293.14 Secondary Use Records. GCRI Canada shall maintain secondary use records, including re-identification prohibition records, re-identification exception records, secondary use reviews, purpose-broadening denials, technical-capability limitation records, sponsor / provider / donor / public authority / partner request reviews, AI training and embedding authority records, external sharing records, public-safe publication reviews, cross-border transfer reviews, re-identification incident records, correction records, and archives.
Section 294. Personal Information and Rights-Bearing Data Categories
294.1 Personal Information. Personal information means information about an identifiable individual, whether directly identifying or reasonably capable of identifying the individual alone or in combination with other data. Personal information may include names, contact details, identifiers, demographic information, participation records, communications, images, recordings, location information, device identifiers, public authority role information, employment information, contributor records, research participation records, and other information linked or linkable to a person.
294.2 Sensitive Personal Information. Sensitive personal information means personal information that, by nature, context, linkage, inference, or potential impact, creates heightened risk to dignity, safety, autonomy, rights, employment, health, livelihood, public standing, community relationship, legal interests, or exposure to harm. Sensitive personal information may include health, biometric, financial, precise location, protected class, youth, vulnerable person, complaint, whistleblower, protected participant, political or public authority context, and safety-sensitive information.
294.3 Health Information. Health information includes medical, clinical, public health, mental health, disability, occupational health, epidemiological, biosecurity, health-system, health-related inference, health-service access, health vulnerability, and health-sensitive community information. Health information shall be classified and handled under heightened privacy, ethics, lawful basis, public authority, de-identification, public-safe, and harm-prevention controls.
294.4 Biometric Information. Biometric information includes fingerprints, facial geometry, voiceprints, iris or retina scans, gait, physiological identifiers, behavioral biometrics, biometric templates, biometric-derived identifiers, and biometric inferences. Biometric information shall not be collected, processed, modeled, embedded, published, or shared without explicit authority, heightened review, security controls, retention limits, and deletion path.
294.5 Location and Geospatial Information. Location and geospatial information includes precise or approximate location, movement patterns, address, workplace, community location, sensitive site, infrastructure proximity, device location, sensor location, map layer, GPS data, cell location, AI-RAN or O-RAN location-related data, DePIN node location, Earth observation-linked data, and geospatial inference. Location data shall be reviewed for re-identification, protected knowledge, infrastructure sensitivity, community harm, and public-safe publication.
294.6 Device and Network Identifiers. Device and network identifiers include IP addresses, MAC addresses, device IDs, cookie IDs, mobile identifiers, subscriber identifiers, network logs, telemetry identifiers, API keys, session IDs, AI-RAN identifiers, O-RAN identifiers, DePIN node identifiers, sensor identifiers, and related technical identifiers. Such identifiers may become personal information or rights-bearing data depending on context and linkage.
294.7 Employment and Contractor Information. Employment and contractor information includes recruitment records, employment records, contractor records, compensation records, performance records, access records, training records, disciplinary records, conflict disclosures, security reviews, credential records, offboarding records, and incident-related records. Such information shall be accessed only by authorized persons for legitimate governance, employment, security, legal, or operational purposes.
294.8 Member, Participant, Fellow, Advisor, Volunteer, and Contributor Information. Member, participant, fellow, advisor, volunteer, and contributor information includes application records, participation records, role records, contribution records, access records, agreements, conflicts, disclosures, training, authorship, attribution, credentials, communications, complaints, and termination or offboarding records. Participation in GCRI Canada activities shall not imply permission for unrelated research, publication, AI training, sponsor use, provider use, or public disclosure.
294.9 Public Authority Participant Information. Public authority participant information includes names, roles, offices, capacities, communications, attendance, comments, data contributions, learning participation, observer participation, regulator-listening participation, public finance reader participation, emergency-management participation, and public infrastructure operator participation. Such information shall be handled with capacity classification and public reference controls.
294.10 Community Participant Information. Community participant information includes information about community members, representatives, knowledge holders, lived-experience contributors, local organizations, protected participants, and persons contributing context, testimony, knowledge, or evidence. Such information shall be handled with confidentiality, safeguards, consent or authorization, attribution limits, withdrawal rights, correction rights, and public-safe review.
294.11 Indigenous / Local / Territorial Knowledge Holder Information. Indigenous, local, or territorial knowledge holder information includes identity, affiliation, custodial role, knowledge contribution, territorial relationship, cultural role, consent status, attribution preference, confidentiality preference, withdrawal rights, correction rights, and protected knowledge context. Such information shall be handled in accordance with applicable protocols, safeguards, and custodial authority.
294.12 Protected Participant Information. Protected participant information includes information about persons requiring confidentiality or heightened protection because of vulnerability, retaliation risk, whistleblowing, complaint status, public authority employment, community sensitivity, health sensitivity, legal sensitivity, safety risk, or protected knowledge contribution. Protected participant information shall be access-restricted and shall not be publicly identified without lawful and recorded authority.
294.13 Whistleblower and Complainant Information. Whistleblower and complainant information includes identity, allegations, supporting materials, communications, investigation records, protection measures, retaliation concerns, outcome records, and correction records. Such information shall be handled with confidentiality, anti-retaliation controls, access limitation, legal review where appropriate, and record integrity.
294.14 Youth and Vulnerable Person Information. Youth and vulnerable person information shall be subject to heightened safeguards. Collection, processing, publication, AI use, research use, or sharing of such information shall require enhanced review, lawful basis, consent or other authority where required, minimization, security, access limits, harm-prevention measures, and public-safe restrictions.
294.15 Derived, Inferred, Scored, or Profiled Information. Derived, inferred, scored, or profiled information includes classifications, risk scores, confidence scores, behavioral inferences, vulnerability indicators, readiness indicators, participation profiles, capability assessments, eligibility inferences, model outputs, and dashboard-derived conclusions. Such information may be rights-bearing even if not directly collected from the person and shall be reviewed for fairness, accuracy, bias, limitation, and correction path.
294.16 Synthetic Data Derived From Rights-Bearing Data. Synthetic data derived from rights-bearing data shall be classified according to residual risk. Synthetic data shall not be presumed non-personal, non-sensitive, non-identifying, public-safe, or rights-free. Where synthetic data can reveal, approximate, reconstruct, infer, or expose sensitive patterns, small groups, protected knowledge, public authority context, or personal attributes, it shall remain restricted and subject to safeguards.
294.17 Personal Information Classification Records. GCRI Canada shall maintain personal information classification records, including personal information records, sensitive personal information records, health information records, biometric information records, location and geospatial information records, device and network identifier records, employment and contractor information records, member / participant / fellow / advisor / volunteer / contributor information records, public authority participant information records, community participant information records, Indigenous / local / territorial knowledge holder information records, protected participant records, whistleblower and complainant records, youth and vulnerable person records, derived / inferred / scored / profiled information records, synthetic data classification records, corrections, restrictions, deletion records, and archives.
Section 295. Collection Restrictions and Necessity Test
295.1 Collection Restriction Principle. GCRI Canada shall collect rights-bearing data only when collection is lawful, necessary, proportionate, purpose-bound, minimized, classified, safeguarded, and correctionable. Collection shall be limited to information reasonably required for approved governance, research, evidence, public authority learning, technical development, security, publication, safeguards, or institutional continuity purposes. Collection shall not proceed merely because data is available, observable, inexpensive, technically accessible, useful for future speculation, attractive for dashboards, or requested by a sponsor, provider, donor, funder, partner, or public authority.
295.2 Necessity Test. Before collecting rights-bearing data, GCRI Canada shall apply a necessity test. The test shall identify the purpose, decision or output supported, data fields required, sensitivity, alternatives, source authority, lawful basis, consent or other authority where applicable, public authority terms, protected knowledge obligations, AI-use implications, retention, deletion, access, and correction path. Data that is not necessary shall not be collected.
295.3 Proportionality Test. Before collecting rights-bearing data, GCRI Canada shall apply a proportionality test. The test shall compare public-benefit value against privacy risk, rights impact, community harm, public authority sensitivity, protected knowledge, re-identification risk, cyber risk, infrastructure risk, publication risk, AI risk, sponsor or provider influence risk, and institutional burden. Collection shall be denied, narrowed, or conditioned where risk outweighs justified purpose.
295.4 Minimum Collection Rule. GCRI Canada shall collect the minimum fields, records, identifiers, time periods, geographies, precision, frequency, and sensitivity necessary for the approved purpose. Where feasible, GCRI Canada shall use less sensitive substitutes, aggregated data, de-identified data, synthetic test data, sampling, delayed data, redacted data, public-safe summaries, or controlled access rather than identifiable or sensitive data.
295.5 No Collection for Undefined Purpose. GCRI Canada shall not collect rights-bearing data for undefined, open-ended, speculative, future, generalized, or unclear purposes. A broad institutional interest in risk, resilience, innovation, observability, public-good research, public authority learning, or Nexus participation shall not itself be a sufficient purpose for collecting identifiable or sensitive information.
295.6 No Collection for Speculative Future Use Without Review. GCRI Canada shall not collect data for speculative future use unless a lawful and recorded review determines that future use is sufficiently defined, necessary, proportionate, safeguarded, minimized, and consistent with public-benefit purpose. Speculative collection of sensitive data, public authority data, protected knowledge, personal information, or community data shall be disfavoured and subject to heightened review.
295.7 No Collection for Sponsor or Provider Advantage. GCRI Canada shall not collect rights-bearing data for sponsor advantage, provider advantage, commercial lead generation, market positioning, product development, procurement influence, finance-readiness promotion, certification leverage, recognition influence, or private benefit. Sponsor or provider support shall not expand collection authority.
295.8 No Collection for Public Authority Reference Without Authority. GCRI Canada shall not collect names, roles, comments, attendance, logos, quotes, contact information, public authority data, or public authority-sensitive records for the purpose of implying public authority endorsement, approval, adoption, funding, procurement, public finance approval, public warning, emergency command, or sovereign obligation. Public authority reference shall require capacity classification and authority.
295.9 No Collection of Sensitive Data Without Enhanced Review. Sensitive personal information, health-sensitive data, biometric data, precise geospatial data, protected participant data, whistleblower data, complainant data, youth data, vulnerable person data, public authority-sensitive data, cyber-sensitive data, infrastructure-sensitive data, and finance-sensitive data shall not be collected without enhanced review, lawful basis, minimization, security, retention limits, and correction path.
295.10 No Collection of Protected Knowledge Without Safeguards Review. GCRI Canada shall not collect Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, community-protected information, or other protected knowledge without safeguards review and applicable custodial authority, consent or authorization, context, attribution rules, access restrictions, AI-use restrictions, publication limits, withdrawal rights, and correction rights.
295.11 No Coercive Collection. Collection shall not be coercive. GCRI Canada shall not use participation, funding, access to learning, public authority convening, community vulnerability, employment dependency, fellowship opportunity, contributor status, sponsorship, provider relationship, host relationship, or research participation to pressure persons or communities into providing rights-bearing data beyond what is lawful, necessary, and voluntary where voluntariness is required.
295.12 Collection Notice Where Required. Where required by law, policy, ethics approval, contract, public authority term, or safeguards process, GCRI Canada shall provide collection notice. Notice shall identify who is collecting, purpose, data collected, lawful basis, use, sharing, publication, AI use where material, retention, rights, complaint pathway, contact point, and limits. Notice shall be clear and suitable to audience.
295.13 Consent Where Required. Where consent is required, consent shall be informed, specific, meaningful, documented, and revocable where applicable. Consent shall not be bundled with unrelated participation where separate consent is required. Consent to one use shall not imply consent to AI training, embedding, publication, public authority sharing, sponsor sharing, provider sharing, commercial use, or indefinite retention.
295.14 Collection Approval Records. GCRI Canada shall maintain collection approval records, including collection purpose, necessity test, proportionality test, minimum collection rule, undefined-purpose denials, speculative-use reviews, sponsor and provider advantage denials, public authority reference reviews, sensitive-data enhanced reviews, protected knowledge safeguards reviews, coercion reviews, collection notices, consent records, approval conditions, corrections, restrictions, and archives.
Section 296. Use Restrictions, Internal Access Controls, Disclosure Restrictions, Redaction Standards, and De-Identification
296.1 Use Restriction Principle. GCRI Canada shall restrict use of rights-bearing data to lawful, recorded, purpose-bound, proportionate, minimized, secure, and correctionable uses. Use restrictions shall follow the data into evidence records, research outputs, dashboards, maps, AI systems, retrieval systems, embeddings, compute workloads, public-safe publications, controlled rooms, data rooms, public authority rooms, Nexus interfaces, archives, and derived materials.
296.2 Role-Based Use. Rights-bearing data shall be used only by persons or systems with roles authorized for the relevant purpose and classification. Role-based use may distinguish Board roles, officer roles, research roles, data steward roles, AI steward roles, cyber steward roles, safeguards reviewer roles, public authority interface roles, publication roles, repository roles, controlled-room roles, and audit roles. Role assignment shall not override purpose limitation.
296.3 Purpose-Based Use. Use of rights-bearing data shall be limited by recorded purpose. A person with access for governance may not use the same data for research; a researcher may not use research data for publication beyond authority; a technical developer may not use live sensitive data for testing without approval; and a public authority learning participant may not reuse materials for public authority action unless separately authorized by the public authority and GCRI Canada records.
296.4 Least-Privilege Access. Access to rights-bearing data shall follow least privilege. Users and systems shall receive only the fields, records, rooms, repositories, dashboards, maps, models, tools, outputs, and time periods necessary for the approved purpose. Least privilege shall apply to viewing, downloading, exporting, copying, querying, retrieving, embedding, training, editing, publishing, and deleting.
296.5 Time-Limited Access Where Appropriate. Access to sensitive or restricted rights-bearing data may be time-limited by project, review, meeting, controlled-room session, public authority engagement, incident response, research protocol, contract, fellowship, employment role, or correction process. Expired access shall be revoked unless reapproved by recorded process.
296.6 Need-to-Know Access. Need-to-know access shall apply to personal information, sensitive personal information, health-sensitive data, protected participant data, whistleblower data, public authority-sensitive data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, controlled annexes, and no-download rooms. Curiosity, seniority, general governance role, sponsor interest, provider relationship, or technical ability shall not create need to know.
296.7 Internal Disclosure Restrictions. Internal disclosure of rights-bearing data shall be limited to authorized persons, authorized systems, approved rooms, approved repositories, and approved purposes. Internal disclosure shall not include broad email circulation, unrestricted chat posting, unmanaged notebooks, informal file sharing, uncontrolled AI prompts, or meeting materials beyond attendees with need to know.
296.8 External Disclosure Restrictions. External disclosure shall require recorded authority and review. External recipients may include public authorities, universities, laboratories, partners, communities, providers, sponsors, donors, funders, contractors, consultants, National Consortium Companies, Project SPVs, or Nexus interfaces only where sharing is lawful, necessary, proportionate, restricted, and subject to confidentiality, re-disclosure limits, AI-use limits, retention, deletion, and correction.
296.9 Public Disclosure Restrictions. Public disclosure of rights-bearing data or derived outputs shall require public-safe review. GCRI Canada shall not publicly disclose personal information, protected participant information, precise sensitive location data, protected knowledge, public authority-sensitive data, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive materials, or small-cell community data unless lawful, authorized, public-safe, and safeguarded.
296.10 Redaction Standards. Redaction shall remove or obscure information sufficient to protect privacy, protected knowledge, public authority sensitivity, cyber security, infrastructure security, finance sensitivity, confidentiality, and public-safe use. Redaction shall address direct identifiers, indirect identifiers, small-cell risk, contextual identifiers, metadata, file properties, geospatial precision, timestamps, images, comments, tracked changes, hidden layers, and embedded data. Redaction shall not distort meaning or conceal material limitations.
296.11 De-Identification. De-identification may be used to reduce identifiability but shall not be treated as absolute. De-identification shall account for direct identifiers, indirect identifiers, linkage risk, small-cell risk, geospatial risk, temporal risk, rare attributes, public authority context, community context, model-enabled inference, and auxiliary datasets. De-identified data shall remain classified where residual risk remains.
296.12 Pseudonymization. Pseudonymization may replace identifiers with codes or substitutes while preserving linkage under controlled conditions. Pseudonymization shall require key separation, access controls, retention rules, re-identification restrictions, and correction path. Pseudonymized data shall remain rights-bearing data and shall not be treated as public-safe without review.
296.13 Aggregation. Aggregation may reduce privacy and public-safe risk by combining records into groups, time periods, locations, categories, or ranges. Aggregation shall be designed to avoid small-cell disclosure, re-identification, protected knowledge exposure, infrastructure targeting, stigmatization, and false precision. Aggregated outputs shall include limitations where aggregation affects interpretation.
296.14 Masking. Masking may be used to obscure identifiers, values, fields, locations, or sensitive portions of records for development, testing, review, publication, or controlled sharing. Masking shall be appropriate to the risk and shall not be reversible by unauthorized persons. Masked data may still be sensitive where patterns remain identifying.
296.15 Suppression of Sensitive Fields. Sensitive fields shall be suppressed where they are not necessary for the approved purpose or where disclosure would create privacy, protected knowledge, public authority, cyber, infrastructure, finance, community, or public-safe risk. Suppression may apply to names, contacts, precise locations, demographic attributes, health fields, identifiers, public authority details, complainant status, whistleblower status, protected knowledge fields, and incident details.
296.16 Re-Disclosure Restrictions. Recipients of rights-bearing data shall be restricted from re-disclosing, republishing, re-identifying, training models on, embedding, indexing, transferring, commercializing, or using the data beyond authorized purpose. Re-disclosure restrictions shall be included in contracts, room rules, data-sharing terms, licenses, public authority terms, controlled annex terms, and public-safe release notes where applicable.
296.17 Use and Disclosure Records. GCRI Canada shall maintain use and disclosure records, including role-based use records, purpose-based use records, least-privilege records, time-limited access records, need-to-know records, internal disclosure records, external disclosure records, public disclosure reviews, redaction records, de-identification records, pseudonymization records, aggregation records, masking records, sensitive-field suppression records, re-disclosure restrictions, access logs, disclosure logs, correction records, and archives.
Section 297. Vulnerable, Protected, High-Risk, Community, Indigenous, Public Authority, Whistleblower, Youth, and Protected Participant Data
297.1 Heightened Protection Purpose. GCRI Canada shall maintain heightened protection rules for vulnerable, protected, high-risk, community, Indigenous, public authority, whistleblower, youth, health-sensitive, remote community, public-safe mapping, and protected participant data. The purpose of heightened protection is to prevent harm, retaliation, re-identification, stigmatization, exposure, surveillance misuse, protected knowledge leakage, public authority confusion, unsafe publication, coercive participation, sponsor or provider misuse, commercial exploitation, and uncontrolled AI, compute, observability, mapping, retrieval, embedding, or publication use. Heightened protection shall be applied as a public-benefit, safeguards, privacy, research integrity, public authority boundary, data / AI / cyber, and correctionability obligation.
297.2 Vulnerable Participant Data. Vulnerable participant data includes information concerning persons whose circumstances, dependence, age, health, disability, legal status, employment status, community position, public authority role, economic position, location, safety risk, or exposure to retaliation may reduce their ability to refuse, challenge, withdraw, correct, or control use of their information. GCRI Canada shall apply enhanced notice, consent where required, minimization, confidentiality, access limitation, publication controls, AI-use restrictions, withdrawal pathways, correction pathways, and harm-prevention measures for vulnerable participant data.
297.3 Protected Participant Data. Protected participant data includes information concerning persons whose identity, participation, statements, evidence, complaints, knowledge contributions, public authority context, community role, whistleblower status, witness status, or safety circumstances require confidentiality or heightened protection. Protected participant data shall be handled on a need-to-know basis, classified as restricted or controlled where appropriate, excluded from public repositories, excluded from public dashboards unless public-safe and approved, and protected against re-identification, retaliation, public exposure, and unauthorized internal disclosure.
297.4 High-Risk Data. High-risk data includes data that, if misused, disclosed, linked, inferred, mapped, published, trained on, embedded, exported, or transferred, could materially affect rights, dignity, safety, privacy, public trust, community standing, public authority relationships, cyber security, infrastructure security, finance sensitivity, protected knowledge, or institutional integrity. High-risk data shall require enhanced review before collection, processing, sharing, publication, AI use, retrieval indexing, embedding, transfer, retention, deletion, or archival.
297.5 Community-Protected Data. Community-protected data includes information about communities, local systems, lived experience, environmental knowledge, community vulnerability, cultural context, livelihood, safety conditions, public service access, public authority relationships, risk exposure, and community-sensitive observations that require collective or contextual safeguards. GCRI Canada shall not treat community-protected data as ordinary open data. Community-protected data shall be governed by purpose limitation, safeguards review, public-safe review, attribution limits, consent or authorization where applicable, non-extraction, access restriction, correction rights, and withdrawal pathways.
297.6 Indigenous Data. Indigenous data includes information relating to Indigenous peoples, communities, governments, Nations, organizations, knowledge holders, lands, territories, waters, cultural knowledge, environmental knowledge, language, governance, sacred sites, resource relationships, health, community conditions, or protected knowledge. GCRI Canada shall handle Indigenous data in accordance with applicable law, Indigenous data governance principles where applicable, custodial authority, consent or authorization, community protocols, attribution rules, non-extraction, access restrictions, AI-use restrictions, publication limits, withdrawal rights, correction rights, and safeguards review. Indigenous data shall not be processed, mapped, published, embedded, trained on, commercialized, or transferred merely because it is accessible.
297.7 Local and Territorial Knowledge Data. Local and territorial knowledge data includes place-based knowledge, environmental knowledge, infrastructure knowledge, community resilience knowledge, geographic knowledge, traditional or lived experience, territorial context, and knowledge held by local actors, community institutions, residents, workers, or custodians. Such data may be sensitive even where not individually identifying. GCRI Canada shall classify and protect local and territorial knowledge according to context, custodial expectations, public-safe risk, geospatial sensitivity, community harm risk, and correctionability.
297.8 Public Authority Data. Public authority data includes data received from, created with, or concerning public authorities, public authority personnel, regulators, ministries, municipalities, Crown entities, public finance bodies, emergency management bodies, public infrastructure operators, public health bodies, public safety bodies, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, and related public-sector actors. Public authority data shall be handled according to capacity classification, lawful basis, data-sharing terms, confidentiality, retention, public reference limits, public-safe release rules, no-delegation boundaries, no-public-warning boundaries, no-emergency-command boundaries, no-procurement boundaries, no-funding boundaries, no-public-finance-approval boundaries, and correction rights.
297.9 Whistleblower Data. Whistleblower data includes identity, reports, allegations, supporting materials, communications, metadata, investigation records, protection measures, retaliation concerns, and outcome records relating to a person reporting misconduct, risk, breach, overclaim, privacy concern, data misuse, cyber issue, protected knowledge misuse, public authority misdescription, finance overclaim, certification overclaim, procurement implication, provider preference, sponsor control, or institutional integrity concern. Whistleblower data shall be access-restricted, confidentiality-protected, retaliation-protected, legally reviewed where appropriate, and excluded from public or broad internal disclosure unless lawful and necessary.
297.10 Complainant and Witness Data. Complainant and witness data includes identity, statements, allegations, observations, evidence, communications, risk concerns, support needs, and participation records of persons involved in complaints, investigations, reviews, challenges, disputes, grievances, or correction processes. Such data shall be handled with confidentiality, fairness, anti-retaliation controls, access limits, integrity preservation, correction pathways, and safeguards against intimidation, exposure, or misuse.
297.11 Youth Data. Youth data includes information concerning minors, young persons, students, trainees, youth fellows, youth participants, or persons whose age triggers special protection. Youth data shall be collected, processed, shared, published, or used in AI systems only under lawful basis, consent or authorization where required, enhanced review, minimization, age-appropriate notice, safety controls, retention limits, access restriction, and public-safe protections. Youth data shall not be used for speculative research, public dashboards, maps, AI training, or public materials without enhanced review.
297.12 Health-Sensitive Data. Health-sensitive data includes medical, clinical, public health, mental health, disability, occupational health, epidemiological, biosecurity, health-system resilience, health service access, community health, and health-related inference data. Health-sensitive data shall require lawful basis, privacy review, ethics review where required, public authority review where applicable, de-identification or aggregation where appropriate, security controls, publication review, AI-use restrictions, retention limits, and correction pathways. Health-sensitive data shall not be exposed through public-safe outputs in a manner that stigmatizes or re-identifies persons or communities.
297.13 Remote Community Data. Remote community data includes information concerning communities where small population size, geographic specificity, limited infrastructure, public authority dependency, community visibility, cultural context, resource conditions, or service scarcity increases re-identification, stigmatization, targeting, or public-safe mapping risk. GCRI Canada shall apply geospatial generalization, small-cell suppression, contextual review, safeguards review, public-safe review, and community-sensitive limitation language where remote community data is used.
297.14 Public-Safe Mapping Risk Data. Public-safe mapping risk data includes any location-linked, geospatial, infrastructure, community, public authority, protected knowledge, cyber, health, environmental, or risk indicator data that may create harm if mapped or visualized publicly. Public-safe mapping risk shall be assessed before publication, dashboard display, map release, geospatial layer sharing, public-safe report release, or repository publication. Controls may include aggregation, masking, generalization, delayed release, suppression, redaction, no-download treatment, controlled annexing, or publication denial.
297.15 Enhanced Access Controls. Heightened-protection data shall be subject to enhanced access controls proportionate to sensitivity. Controls may include role-based access, attribute-based access, need-to-know review, time-limited access, controlled-room access, no-download rooms, logging, named-user access, conflict screening, MFA, device controls, export restrictions, AI-use restrictions, retrieval restrictions, embedding restrictions, and offboarding procedures. Seniority, curiosity, general governance role, sponsor interest, provider interest, public authority participation, or technical capability shall not create access rights.
297.16 Enhanced Publication Controls. Heightened-protection data shall not be published, mapped, dashboarded, summarized, quoted, visualized, included in open datasets, placed in public repositories, used in demonstrations, converted into public training data, or released through public-safe outputs without enhanced publication review. Review shall address identifiability, small-cell risk, community harm, retaliation risk, protected knowledge, public authority restrictions, cyber and infrastructure sensitivity, health sensitivity, youth protections, finance sensitivity, sponsor or provider misuse, public overclaim, and correction path.
297.17 Enhanced Correction and Withdrawal Pathways. GCRI Canada shall maintain enhanced correction and withdrawal pathways for heightened-protection data. Such pathways shall allow errors, misclassification, unsafe publication, protected knowledge concern, consent withdrawal, public authority restriction, participant safety risk, community harm, re-identification risk, AI-use concern, retrieval exposure, or public-safe failure to be raised and reviewed. Correction or withdrawal may include access restriction, publication removal, dashboard or map suppression, reclassification, re-indexing, deletion, sealing, notice, dependency review, and archival.
297.18 Heightened Protection Records. GCRI Canada shall maintain heightened protection records, including vulnerable participant data records, protected participant data records, high-risk data records, community-protected data records, Indigenous data records, local and territorial knowledge data records, public authority data records, whistleblower data records, complainant and witness data records, youth data records, health-sensitive data records, remote community data records, public-safe mapping risk records, enhanced access records, enhanced publication review records, correction records, withdrawal records, incident records, and archives.
Section 298. No PII in Public Repositories, Open Releases, Public Technical Packages, Public Documentation, or On-Chain Artifacts
298.1 No PII in Public Repositories. GCRI Canada shall not place personal information, sensitive personal information, protected participant information, public authority-sensitive personal data, community participant data, youth data, health-sensitive data, precise location data, whistleblower data, complainant data, witness data, or other rights-bearing identifiable data in public repositories. Public repositories shall be treated as public disclosure environments and shall require pre-release review, scanning, redaction, test-data discipline, and repository hygiene.
298.2 No PII in Open Releases. Open releases of software, schemas, APIs, SDKs, dashboards, maps, datasets, test harnesses, benchmark assets, documentation, technical baselines, public-safe packages, model cards, dataset cards, system cards, or reference implementations shall not include PII unless lawful, necessary, public-safe, specifically approved, and accompanied by limitation language. By default, open releases shall use dummy, synthetic, de-identified, aggregated, redacted, or public-safe demonstration data.
298.3 No PII in Public Technical Packages. Public technical packages shall not include PII in source files, compiled assets, package metadata, examples, tests, logs, screenshots, fixtures, comments, notebooks, configuration files, hidden files, environment files, telemetry samples, model prompts, embeddings, vector stores, caches, release artifacts, or documentation. Package release shall include review for embedded metadata and accidental disclosures.
298.4 No PII in Public Documentation. Public documentation shall not contain PII unless lawful, necessary, public-safe, and approved. Documentation controls shall apply to examples, screenshots, diagrams, case studies, issue references, contributor names where sensitive, public authority participant names, meeting notes, API examples, dashboard examples, map examples, code comments, release notes, benchmark explanations, and public-safe summaries. Public documentation shall avoid realistic examples that identify or expose persons or protected groups.
298.5 No PII in Public Test Fixtures. Public test fixtures shall not include real personal information, real participant records, real public authority personnel data, real protected knowledge, real health-sensitive data, real community-sensitive data, real cyber-sensitive identifiers, or real infrastructure-sensitive identifiers. Test fixtures shall use dummy, generated, synthetic, minimized, or approved public-safe data. Synthetic test data shall be reviewed where it may approximate or reconstruct real persons, communities, or sensitive contexts.
298.6 No PII in Public Training Data. GCRI Canada shall not release public training data containing PII unless a lawful basis, rights clearance, privacy review, consent or other authority where required, de-identification review, re-identification risk review, public-safe review, and approval record support the release. Public training data shall not include protected participant data, whistleblower data, complainant data, youth data, health-sensitive data, protected knowledge, or public authority-sensitive personal data by default.
298.7 No PII in Public Demonstration Data. Public demonstration data used in documentation, workshops, dashboards, public-good software examples, APIs, SDKs, tutorials, model demos, or public authority learning materials shall not include real PII unless lawful, necessary, public-safe, and approved. Demonstration data should be synthetic, dummy, aggregated, or de-identified with residual-risk review. Demonstrations shall not expose hidden identifiers, metadata, precise location, or small-cell community attributes.
298.8 No PII in Public Dashboards Unless Lawful, Necessary, Public-Safe, and Approved. Public dashboards shall not display PII, personal-level records, identifiable participation, precise sensitive locations, protected participant status, health-sensitive records, whistleblower information, complainant information, public authority personnel data, or community-identifying small-cell data unless lawful, necessary, public-safe, and approved. Dashboard review shall include source review, privacy review, public authority review where applicable, safeguards review, aggregation review, geospatial review, access-control review, stale-data review, limitation language, and correction path.
298.9 No PII in Public Maps Unless Lawful, Necessary, Public-Safe, and Approved. Public maps shall not display PII, identifiable locations of persons, households, protected participants, youth, health-sensitive populations, community knowledge holders, public authority personnel, or sensitive community sites unless lawful, necessary, public-safe, and approved. Public maps shall apply aggregation, generalization, masking, delay, suppression, or controlled access where needed to prevent re-identification, targeting, protected knowledge exposure, infrastructure risk, or community harm.
298.10 No PII On-Chain. GCRI Canada shall not place PII on public, permissionless, immutable, or externally controlled ledgers, blockchains, registries, or on-chain artifacts. On-chain permanence, replication, indexing, analytics, cross-border access, and deletion limitations create heightened privacy risk. No person shall infer that hashing, pseudonymization, tokenization, encryption, or wallet separation automatically makes PII suitable for on-chain use.
298.11 No Protected Knowledge On-Chain. GCRI Canada shall not place protected knowledge, Indigenous / local / territorial knowledge, community-protected data, sacred-site information, protected participant information, or safeguards-sensitive records on-chain unless a lawful, safeguards-compliant, custodially authorized, deletion-aware, public-safe, and exceptional approval record exists. By default, protected knowledge shall not be placed in immutable or broadly replicated systems.
298.12 No Public Authority Sensitive Data On-Chain. GCRI Canada shall not place public authority-sensitive data, public authority personnel data, public finance reader materials, emergency-management data, public infrastructure operator data, public safety-sensitive records, regulator-sensitive materials, or public authority confidential information on-chain unless lawful, expressly authorized by the competent public authority where required, public-safe, and approved after legal, data, cyber, and public authority review.
298.13 No Hashing of Sensitive Data On-Chain Without Review. Hashes, commitments, proofs, attestations, tokens, metadata, pointers, merkle roots, signatures, or other cryptographic references derived from sensitive data shall not be placed on-chain without review. Review shall consider whether the hash or metadata may enable confirmation attacks, linkage, re-identification, inference, proof of possession, timing disclosure, source disclosure, legal exposure, protected knowledge exposure, or irreversible misuse. Hashing shall not be treated as automatic anonymization.
298.14 Synthetic or Dummy Data Requirement Where Appropriate. GCRI Canada shall use synthetic, dummy, minimized, public-safe, de-identified, aggregated, masked, or generated data for public repositories, open releases, public technical packages, public documentation, public test fixtures, public demonstrations, and public tutorials where real data is not necessary. Synthetic or dummy data shall be labelled and shall not be used to imply real-world findings, public authority approval, certification, finance-readiness, provider performance, or public warning.
298.15 Pre-Release PII Scan. Before public release, GCRI Canada shall conduct pre-release PII scans and review proportionate to risk. Scans may include automated secret scanning, metadata review, file inspection, notebook output review, screenshot review, dataset review, fixture review, log review, commit-history review where feasible, archive review, model prompt review, embedding review, and dashboard review. Automated scans shall not replace human review for sensitive or high-risk releases.
298.16 Public Repository Incident Response. Where PII, protected knowledge, public authority-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, or restricted material is discovered in a public repository, open release, public package, public documentation, public dashboard, public map, public test fixture, public training data, public demonstration, or on-chain artifact, GCRI Canada shall initiate incident response. Response may include containment, takedown, repository history review, access revocation, key rotation, deletion where feasible, re-release, public-safe notice, affected-party notice where required, legal review, public authority review, safeguards review, and correction.
298.17 Public Repository and On-Chain Data Records. GCRI Canada shall maintain public repository and on-chain data records, including public repository reviews, open release reviews, public package reviews, public documentation reviews, public test fixture reviews, public training data reviews, public demonstration data reviews, public dashboard reviews, public map reviews, on-chain review records, protected knowledge on-chain review records, public authority sensitive data on-chain review records, sensitive data hash review records, synthetic or dummy data records, pre-release scan records, incident response records, corrections, takedowns, notices, and archives.
Section 299. Sovereign Data Zones
299.1 Sovereign Data Zone Purpose. GCRI Canada may establish sovereign data zones to govern sensitive data according to jurisdiction, data class, public authority terms, protected knowledge obligations, community safeguards, cyber sensitivity, infrastructure sensitivity, health sensitivity, finance sensitivity, research restrictions, access controls, compute-to-data requirements, transfer limits, audit rules, and correctionability. Sovereign data zones shall provide disciplined containment and lawful processing, not public authority status, national security authority, procurement approval, finance-readiness, or operational control.
299.2 Canadian Sovereign Data Zone. A Canadian Sovereign Data Zone may be established for Canadian public-benefit records, Canadian public authority materials, Canadian participant data, Canadian community-protected data, Canadian infrastructure-sensitive data, Canadian cyber-sensitive data, Canadian health-sensitive data, Canadian Nexus interface records, and other materials requiring Canadian governance, Canadian data residency, Canadian legal accountability, or Canadian access oversight. Such zone shall preserve GCRI Canada’s legal separateness and non-executing role.
299.3 Public Authority Data Zone. A Public Authority Data Zone may be established for data received from or concerning public authorities. The zone shall reflect capacity classification, data-sharing terms, confidentiality, access limits, public reference controls, public-safe publication limits, retention requirements, deletion or return obligations, correction rights, and no-delegation boundaries. Access to the zone shall not create public authority status or authority to act on behalf of any public body.
299.4 Indigenous Data Zone Where Applicable and Lawfully Structured. An Indigenous Data Zone may be established where Indigenous data requires separate custodial, legal, ethical, territorial, cultural, or governance controls. Such a zone shall be structured only where lawful and appropriate, and shall respect custodial authority, Indigenous data governance principles where applicable, consent or authorization, access protocols, attribution rules, non-extraction, AI-use restrictions, publication limits, withdrawal rights, correction rights, and data sovereignty considerations.
299.5 Community-Protected Data Zone. A Community-Protected Data Zone may be established for community-sensitive data, local knowledge, territorial knowledge, lived-experience records, environmental knowledge, vulnerability data, community-risk records, and public-safe mapping risk data. The zone shall apply safeguards review, small-cell risk controls, geospatial generalization, access limitation, publication restrictions, re-identification controls, and correction pathways.
299.6 Research-Controlled Data Zone. A Research-Controlled Data Zone may be established for datasets, participant data, research protocols, interviews, surveys, field notes, model outputs, derived data, synthetic data, evidence candidates, and research records requiring protocol-specific access. The zone shall align with lawful basis, consent or ethics approval where required, research integrity, data minimization, retention, publication review, AI-use restrictions, and correctionability.
299.7 Cyber-Sensitive Data Zone. A Cyber-Sensitive Data Zone may be established for logs, vulnerabilities, threat intelligence, incident records, SBOMs, dependency records, access records, security architecture, repository records, prompt injection tests, model attack records, and cyber telemetry. The zone shall include need-to-know access, no-publication defaults, coordinated disclosure rules, secure storage, logging, incident response, and public-safe redaction.
299.8 Infrastructure-Sensitive Data Zone. An Infrastructure-Sensitive Data Zone may be established for data concerning telecom, AI-RAN, O-RAN, DePIN, compute, energy, water, food, health, ports, transport, public works, emergency management, supply chains, critical facilities, geospatial layers, digital twins, degraded-mode indicators, and infrastructure vulnerabilities. The zone shall restrict access, prevent unsafe maps, control public-safe outputs, and avoid operational security exposure.
299.9 Health-Sensitive Data Zone. A Health-Sensitive Data Zone may be established for health, public health, clinical, epidemiological, biosecurity, mental health, disability, health-system resilience, occupational health, and community health data. The zone shall include lawful basis review, privacy review, ethics review where required, public authority review where applicable, de-identification or aggregation controls, access limitation, retention limits, and harm-prevention measures.
299.10 Finance-Sensitive Evidence Zone. A Finance-Sensitive Evidence Zone may be established for finance-boundary notes, public finance reader materials, capital-readability materials, insurance-sensitive evidence, lending-sensitive evidence, project finance materials, National Consortium Company materials, Project SPV materials, guarantee-related records, underwriting-adjacent materials, rating-adjacent materials, and Nexus Rails technical evidence inputs. The zone shall include express boundaries that GCRI Canada does not provide investment advice, securities advice, lending advice, insurance advice, underwriting approval, ratings, public finance approval, capital placement, investor matchmaking, or finance-readiness determinations.
299.11 No-Download Zone. A No-Download Zone may be established where data may be viewed or reviewed but not downloaded, copied, printed, screenshotted, scraped, exported, embedded, indexed, uploaded into AI systems, or redistributed. No-download treatment may be required for protected knowledge, public authority-sensitive data, cyber-sensitive materials, infrastructure-sensitive maps, finance-sensitive materials, health-sensitive data, controlled annexes, and confidential third-party materials. No-download status shall be supported by room rules, technical controls, access logs, and closeout obligations.
299.12 Compute-to-Data Zone. A Compute-to-Data Zone may be established where sensitive data should remain within a controlled environment while approved code, queries, models, or analysis are brought to the data. Outputs may leave only after review, classification, redaction, aggregation, de-identification, public-safe review, and approval. Compute-to-data zones shall prevent bulk export, uncontrolled copying, unauthorized AI use, and unreviewed model training.
299.13 Zone Admission Rules. Admission of data into a sovereign data zone shall require classification, authority review, purpose review, lawful basis, rights review, public authority review where applicable, safeguards review where applicable, cyber review where applicable, infrastructure review where applicable, finance-boundary review where applicable, retention review, deletion path, and correction path. Data shall not be admitted to a zone merely because it is technically available.
299.14 Zone Access Rules. Zone access shall be role-based, purpose-bound, need-to-know, least-privilege, logged, time-limited where appropriate, and conditioned on confidentiality, training, conflict review, and room rules where applicable. Access shall be revoked when no longer necessary, when a project closes, when a person offboards, when a conflict arises, when an incident occurs, or when zone rules change.
299.15 Zone Transfer Rules. Transfers into, within, or out of a sovereign data zone shall require recorded authority, recipient review, purpose review, classification review, public authority review where applicable, safeguards review where applicable, cross-border review where applicable, encryption, access controls, re-disclosure restrictions, retention controls, deletion obligations, and correction path. Zone transfer shall not dilute restrictions.
299.16 Zone Exit Rules. Zone exit shall govern data, outputs, temporary files, logs, extracts, summaries, dashboards, maps, models, embeddings, indexes, and derived records leaving a zone. Exit review shall confirm public-safe status, output classification, residual risk, limitation language, recipient authority, no-download restrictions where applicable, deletion of temporary materials, and closeout. Outputs shall not leave merely because a project or meeting is complete.
299.17 Zone Audit Rules. Sovereign data zones shall be audited proportionate to risk. Audits may review access logs, transfer logs, query logs, AI-use logs, export logs, deletion records, user lists, permissions, public-safe releases, incidents, corrections, retention, and zone compliance. Audit findings shall be corrected and escalated where required.
299.18 Sovereign Data Zone Records. GCRI Canada shall maintain sovereign data zone records, including Canadian Sovereign Data Zone records, Public Authority Data Zone records, Indigenous Data Zone records, Community-Protected Data Zone records, Research-Controlled Data Zone records, Cyber-Sensitive Data Zone records, Infrastructure-Sensitive Data Zone records, Health-Sensitive Data Zone records, Finance-Sensitive Evidence Zone records, No-Download Zone records, Compute-to-Data Zone records, admission records, access records, transfer records, exit records, audit records, incidents, corrections, restrictions, and archives.
Section 300. Localization Requirements by Data Class, Context, and Jurisdiction
300.1 Localization Purpose. GCRI Canada shall assess localization requirements by data class, context, jurisdiction, public authority terms, protected knowledge obligations, community safeguards, health sensitivity, cyber sensitivity, infrastructure sensitivity, controlled technology, contractual commitments, donor or grant conditions, host requirements, and Nexus regional or national context. Localization shall support lawful stewardship, trust, rights protection, data sovereignty, public authority confidence, public-benefit purpose, and correctionability, and shall not be used to fragment evidence integrity, weaken safeguards, create provider lock-in, or imply public authority delegation.
300.2 Data Class Localization. Localization requirements may differ by data class. Personal information, sensitive personal information, health-sensitive data, public authority data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, research-controlled data, controlled technology, export-controlled data, and public-safe data shall be assessed for whether storage, processing, backup, administrative access, support access, compute, AI processing, retrieval indexing, embedding, transfer, or archival must occur in a specified jurisdiction or environment.
300.3 Public Authority Localization. Public authority data may require localization according to statute, regulation, policy, data-sharing agreement, procurement term, confidentiality term, public finance term, emergency management term, infrastructure operator rule, or public authority instruction. GCRI Canada shall not transfer or process public authority data in a non-localized environment where doing so conflicts with applicable terms or public authority boundary rules.
300.4 Indigenous and Community Protocol Localization. Indigenous and community-protected data may require localization according to custodial authority, Indigenous data governance principles where applicable, community protocols, territorial expectations, cultural restrictions, non-extraction commitments, consent terms, protected knowledge rules, and safeguards review. Localization may include community-controlled access, restricted jurisdiction, controlled-room access, data-return obligations, or no-external-transfer requirements.
300.5 Health Data Localization. Health data may require localization according to health privacy law, public health terms, ethics requirements, public authority rules, hospital or health-system policies, research agreements, cross-border restrictions, de-identification requirements, and harm-prevention controls. GCRI Canada shall review health data localization before storage, compute, sharing, AI processing, publication, or transfer.
300.6 Infrastructure-Sensitive Data Localization. Infrastructure-sensitive data may require localization where telecom, AI-RAN, O-RAN, DePIN, compute, energy, water, food, health, ports, transport, public works, emergency management, cyber-physical systems, or mission-critical dependencies are involved. Localization review shall consider operational security, public authority terms, cyber risk, critical infrastructure exposure, cloud region, foreign access, support access, and public-safe risk.
300.7 Cyber-Sensitive Data Localization. Cyber-sensitive data may require localization or restricted environment handling where logs, vulnerabilities, incident records, threat intelligence, credentials, security architecture, repository records, SBOMs, model attack records, or cyber telemetry are involved. Localization review shall account for cyber law, public authority terms, breach risk, export-control issues, foreign access, threat exposure, and coordinated disclosure.
300.8 Controlled Technology Localization. Controlled technology, dual-use materials, encryption-related assets, cyber tools, AI systems, telecom-related materials, AI-RAN materials, O-RAN materials, DePIN-related methods, advanced sensing, robotics, drones, compute systems, or quantum-relevant systems may require localization or restricted-transfer controls. GCRI Canada shall review applicable export-control, sanctions, contractual, national security, and public authority restrictions before transfer or external access.
300.9 Contractual Localization. Contracts, data-sharing agreements, public authority agreements, research agreements, host agreements, provider agreements, sponsor agreements, donor agreements, grant agreements, university agreements, laboratory agreements, controlled-room terms, and partner agreements may impose localization requirements. GCRI Canada shall record such requirements and configure systems, rooms, repositories, compute environments, and retention rules accordingly.
300.10 Grant or Donor Condition Localization. Grant or donor conditions may impose localization, access, publication, data residency, open access, restricted access, public authority access, or community safeguard requirements. GCRI Canada shall accept only those localization conditions that are lawful, consistent with public-benefit purpose, non-execution, role separation, privacy, security, protected knowledge obligations, donor restrictions, and correctionability.
300.11 Host Institution Localization. Host institutions may require data localization, facility-based access, restricted storage, local compute, no-download rooms, public authority rooms, community data protocols, cyber controls, or infrastructure-sensitive treatment. Host localization terms shall be recorded and shall not create host control over GCRI Canada governance, research conclusions, public-safe publication, correction, or Nexus interface meaning.
300.12 Nexus Regional or National Localization. Nexus regional or national localization may be required where regional consortiums, national consortiums, public authorities, communities, National Consortium Companies, Project SPVs, hosts, or public-good infrastructure require local legal, cultural, linguistic, technical, or data governance adaptation. Localization shall preserve Nexus role separation, GCRI Canada legal separateness, public-benefit purpose, non-execution, public authority boundaries, finance boundaries, certification boundaries, and correctionability.
300.13 Localization Without Fragmentation. Localization shall be implemented without fragmenting evidence integrity, semantic interoperability, correctionability, version control, public-safe meaning, or public-good stewardship. Where localized copies, zones, schemas, models, dashboards, maps, or records exist, GCRI Canada shall maintain compatibility notes, divergence logs, version records, correction paths, and supersession records to prevent inconsistent or obsolete local meanings.
300.14 Localization Without Weakening Public-Good Purpose or Non-Execution. Localization shall not weaken GCRI Canada’s public-benefit purpose, nonprofit and non-distribution character, non-execution boundary, legal separateness, sponsor support-without-control, provider neutrality, procurement neutrality, finance-readiness boundary, certification boundary, public authority boundary, safeguards obligations, privacy obligations, data / AI / cyber controls, or correctionability. Local adaptation shall not become local capture.
300.15 Localization Review. Localization review shall identify applicable data class, jurisdiction, source, public authority terms, protected knowledge obligations, community protocols, health rules, cyber rules, infrastructure sensitivity, controlled technology, contractual terms, grant or donor conditions, host requirements, Nexus regional or national context, cross-border implications, provider dependencies, storage location, processing location, support access, backup location, and correction path. Review may approve, condition, re-scope, deny, quarantine, or suspend localization or transfer.
300.16 Localization Records. GCRI Canada shall maintain localization records, including localization purpose records, data class localization records, public authority localization records, Indigenous and community protocol localization records, health data localization records, infrastructure-sensitive localization records, cyber-sensitive localization records, controlled technology localization records, contractual localization records, grant and donor condition localization records, host institution localization records, Nexus regional and national localization records, compatibility notes, divergence logs, localization reviews, decisions, conditions, corrections, and archives.
Section 301. Compute-to-Data as Default for Restricted or Sovereign-Sensitive Material
301.1 Compute-to-Data Purpose. GCRI Canada shall use compute-to-data as a preferred or default architecture for restricted or sovereign-sensitive material where moving data would create privacy, public authority, protected knowledge, cyber, infrastructure, health, finance, export-control, sanctions, contractual, or public-safe risk. Compute-to-data allows approved code, queries, models, methods, or analysis to operate within a controlled environment while reviewed outputs, rather than raw data, leave the environment. Its purpose is to reduce transfer risk, leakage risk, uncontrolled copying, unauthorized AI use, and loss of data sovereignty.
301.2 Restricted Data Default. Restricted data shall be handled through compute-to-data by default where bulk export, open download, broad repository access, external processing, or uncontrolled compute would create material risk. Exceptions shall require review and recorded approval. Restricted data includes controlled evidence, public authority data, protected knowledge, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, controlled-room records, no-download-room records, and restricted research datasets.
301.3 Sovereign-Sensitive Data Default. Sovereign-sensitive data shall be processed through compute-to-data where jurisdiction, data residency, public authority terms, Indigenous or community data sovereignty, Canadian governance, critical infrastructure sensitivity, cross-border transfer exposure, foreign access risk, or legal control concerns make data movement inappropriate. Sovereign-sensitive data shall remain in approved zones unless output review permits limited release.
301.4 Public Authority Data Default. Public authority data shall be subject to compute-to-data by default where data-sharing terms, confidentiality, public authority capacity, public reference limits, emergency management sensitivity, public infrastructure sensitivity, public finance sensitivity, regulatory sensitivity, or public-sector operational context restrict transfer or download. Public authority data outputs shall be reviewed to prevent endorsement implication, public warning implication, emergency command implication, procurement implication, funding implication, public finance implication, or sovereign-obligation implication.
301.5 Community-Protected Data Default. Community-protected data shall be processed through compute-to-data by default where export, external sharing, publication, mapping, dashboarding, AI processing, or broad internal access may expose community identity, vulnerability, local knowledge, territorial context, protected participation, or public-safe mapping risk. Outputs shall be reviewed for aggregation, generalization, attribution limits, non-extraction, and community harm.
301.6 Indigenous / Local / Territorial Knowledge Default. Indigenous, local, or territorial knowledge shall be processed through compute-to-data by default where such processing is lawful and safeguards-compliant, and where data should remain under custodial, territorial, community, or controlled-room protections. Compute-to-data shall not authorize processing absent consent, authorization, custodial authority, protocol compliance, AI-use permission, and public-safe review.
301.7 Cyber-Sensitive Data Default. Cyber-sensitive data shall be processed through compute-to-data by default where logs, vulnerabilities, threat intelligence, incident records, SBOMs, dependency records, repository records, model attack records, prompt injection examples, or cyber telemetry would create security risk if exported. Outputs shall be reviewed to prevent exploit disclosure, credential exposure, infrastructure targeting, or unsafe publication.
301.8 Infrastructure-Sensitive Data Default. Infrastructure-sensitive data shall be processed through compute-to-data by default where raw data, precise geospatial data, operating conditions, degraded-mode indicators, digital twin inputs, AI-RAN signals, O-RAN signals, DePIN records, telemetry, maps, or dependency records could expose mission-critical systems. Outputs shall be public-safe, aggregated, delayed, generalized, or controlled as appropriate.
301.9 Health-Sensitive Data Default. Health-sensitive data shall be processed through compute-to-data by default where external transfer, raw download, uncontrolled linkage, AI processing, or publication could create privacy, stigma, public health, ethics, or public authority risk. Outputs shall be reviewed for de-identification, small-cell suppression, aggregation, public-safe language, and harm prevention.
301.10 Finance-Sensitive Evidence Default. Finance-sensitive evidence shall be processed through compute-to-data by default where raw export could create investment sensitivity, insurance sensitivity, underwriting-adjacent implications, lender sensitivity, public finance sensitivity, project finance exposure, sponsor benefit, provider benefit, competition sensitivity, or market distortion. Outputs shall include finance-boundary language and shall not imply finance-readiness, insurance-readiness, bankability, creditworthiness, rating, underwriting approval, public finance approval, capital placement, investor matchmaking, or investment advice.
301.11 No Bulk Export Without Review. Bulk export of restricted or sovereign-sensitive material shall not occur without review and recorded authority. Bulk export review shall consider lawful basis, recipient, jurisdiction, data class, purpose, necessity, proportionality, encryption, access controls, re-disclosure limits, AI-use restrictions, retention, deletion, public authority terms, protected knowledge, cyber sensitivity, infrastructure sensitivity, finance sensitivity, export-control rules, sanctions rules, and correction path.
301.12 No Download Without Authority. No user, model, agent, tool, workflow, provider, sponsor, partner, public authority participant, researcher, contractor, fellow, maintainer, or contributor shall download restricted or sovereign-sensitive material unless authorized by recorded process. Download authority shall be specific, purpose-bound, time-limited where appropriate, logged, and subject to confidentiality, no-redistribution, AI-use restrictions, and deletion obligations.
301.13 Output Review Before Release. Outputs from compute-to-data environments shall be reviewed before release. Review shall classify outputs, assess residual risk, identify whether outputs reveal source data, protected knowledge, small-cell information, public authority-sensitive information, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive information, or restricted patterns, and determine whether redaction, aggregation, de-identification, suppression, limitation language, controlled release, or denial is required.
301.14 Aggregate or Synthetic Output Preference Where Appropriate. Where appropriate, compute-to-data environments should prefer aggregate, synthetic, minimized, redacted, masked, generalized, or public-safe outputs over raw exports. Synthetic or aggregate outputs shall still be reviewed for re-identification, reconstruction, protected knowledge exposure, cyber or infrastructure sensitivity, finance sensitivity, and false precision. Synthetic status shall not automatically make an output public-safe.
301.15 Compute-to-Data Exception Review. Exceptions to compute-to-data default shall require review and recorded rationale. Exception review shall identify why compute-to-data is infeasible or unnecessary, what data will move, recipient, environment, jurisdiction, safeguards, encryption, access controls, logging, retention, deletion, AI-use limits, public authority terms, protected knowledge restrictions, and correction path. Exceptions may be denied, narrowed, conditioned, or time-limited.
301.16 Compute-to-Data Records. GCRI Canada shall maintain compute-to-data records, including purpose records, restricted data default records, sovereign-sensitive data records, public authority data records, community-protected data records, Indigenous / local / territorial knowledge records, cyber-sensitive data records, infrastructure-sensitive data records, health-sensitive data records, finance-sensitive evidence records, bulk export review records, download authority records, output review records, aggregate and synthetic output records, exception review records, corrections, incidents, and archives.
Section 302. Cross-Border Transfer Rule and Legal / Safeguards Review
302.1 Cross-Border Transfer Rule. GCRI Canada shall not transfer, store, process, back up, provide access to, make available, index, embed, train on, retrieve, publish, or otherwise expose rights-bearing, restricted, public authority-sensitive, protected-knowledge, cyber-sensitive, infrastructure-sensitive, health-sensitive, finance-sensitive, controlled-technology, or sovereign-sensitive data across borders, jurisdictions, cloud regions, provider systems, support channels, repositories, AI platforms, or partner systems without legal, privacy, safeguards, data / AI / cyber, and classification review proportionate to risk.
302.2 Transfer Trigger. A cross-border transfer trigger occurs when data moves or becomes accessible outside its approved jurisdiction, zone, room, cloud region, repository, compute environment, public authority context, community protocol, or localization boundary. Transfer may occur through direct file movement, remote access, provider support, cloud backup, AI processing, embedding, retrieval indexing, API use, model training, dashboard hosting, repository mirroring, email, messaging, screenshots, exports, logs, or metadata exposure.
302.3 Legal Review. Legal review shall identify applicable laws, contractual terms, public authority terms, data-sharing agreements, consent terms, research ethics conditions, protected knowledge obligations, privacy obligations, export-control rules, sanctions rules, confidentiality obligations, disclosure obligations, foreign access risks, litigation risks, and available transfer mechanisms. Legal review shall determine whether transfer is lawful, restricted, conditional, or prohibited.
302.4 Privacy Review. Privacy review shall assess data categories, identifiability, sensitivity, data subjects, rights impact, lawful basis, purpose, minimization, access controls, retention, deletion, re-identification risk, onward transfer risk, data processor obligations, breach response, data rights, transparency, and correctionability. Privacy review shall be heightened for sensitive personal information, health-sensitive data, youth data, protected participant data, whistleblower data, and community-linked data.
302.5 Public Authority Review. Public authority review shall occur where transfer involves public authority data, public authority personnel data, public finance materials, emergency-management data, public infrastructure data, regulatory materials, public health data, public safety data, or public authority-sensitive records. Review shall confirm capacity classification, public reference terms, confidentiality, localization rules, data-sharing terms, public-safe limits, and no-delegation boundaries.
302.6 Community Safeguards Review. Community safeguards review shall occur where transfer involves community-protected data, remote community data, protected participant data, local knowledge, territorial knowledge, community vulnerability, public-safe mapping risk, or community-sensitive information. Review shall address consent or authorization, custodial context, harm risk, re-identification, attribution, withdrawal rights, correction rights, public-safe limitations, and non-extraction.
302.7 Indigenous / Local / Territorial Knowledge Review. Indigenous, local, or territorial knowledge review shall occur where transfer involves Indigenous data, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, protected knowledge, or custodially governed data. Review shall respect applicable protocols, data sovereignty, custodial authority, consent or authorization, AI-use restrictions, publication limits, withdrawal rights, correction rights, and localization.
302.8 Cybersecurity Review. Cybersecurity review shall assess security of transfer, encryption, key control, access control, identity, authentication, logging, provider security, cloud region security, support access, endpoint security, repository security, AI platform security, incident response, and risk of cyber-sensitive disclosure. Transfer involving cyber logs, vulnerabilities, credentials, security architecture, or incident records shall require heightened review.
302.9 Infrastructure Sensitivity Review. Infrastructure sensitivity review shall occur where transfer involves telecom, AI-RAN, O-RAN, DePIN, compute, energy, water, food, health, ports, transport, public works, emergency management, digital twin, geospatial, sensor, or mission-critical infrastructure data. Review shall consider targeting risk, operational security, public authority terms, public-safe mapping risk, foreign access, and downstream misuse.
302.10 Export-Control Review. Export-control review shall assess whether data, software, models, methods, encryption, cyber tools, controlled technology, AI systems, telecom-related materials, advanced sensing, robotics, drones, compute methods, or dual-use materials are subject to export-control or restricted-transfer rules. Transfer shall not proceed where export-control requirements are unresolved or prohibitive.
302.11 Sanctions Review. Sanctions review shall assess recipients, jurisdictions, counterparties, providers, hosts, funders, sponsors, public authorities, institutions, sectors, technologies, services, and access pathways for sanctions restrictions. GCRI Canada shall deny, suspend, or restrict transfers involving prohibited persons, prohibited jurisdictions, prohibited sectors, or prohibited services where required.
302.12 Contractual Review. Contractual review shall assess data-sharing agreements, public authority terms, host terms, provider agreements, sponsor terms, donor conditions, grant conditions, university agreements, laboratory agreements, partner agreements, contributor terms, licenses, data processing agreements, no-download rules, confidentiality, onward transfer, retention, deletion, audit rights, and correction obligations.
302.13 Data Processor Review. Data processor review shall assess processors, subprocessors, cloud providers, AI providers, repository hosts, analytics providers, dashboard providers, support providers, and other service providers that may access or process transferred data. Review shall address security, jurisdiction, data-use terms, training settings, retention, deletion, breach response, auditability, onward transfer, and provider dependency.
302.14 Host and Jurisdiction Review. Host and jurisdiction review shall assess legal environment, foreign government access risk, data protection adequacy, public authority constraints, public safety concerns, cybersecurity posture, sanctions exposure, export-control exposure, court or disclosure obligations, political risk, infrastructure risk, and compatibility with public-benefit purpose and safeguards.
302.15 Transfer Risk Decision. A transfer risk decision shall determine whether the proposed transfer is approved, conditionally approved, re-scoped, denied, quarantined, suspended, localized, replaced by compute-to-data, replaced by synthetic output, restricted to aggregate output, restricted to controlled room, or escalated. The decision shall be recorded with rationale, conditions, residual risk, reviewer, authority, and correction path.
302.16 Transfer Approval, Denial, Re-Scoping, Quarantine, or Suspension. GCRI Canada may approve, deny, re-scope, quarantine, or suspend a transfer based on law, privacy, public authority terms, community safeguards, Indigenous / local / territorial knowledge, cyber security, infrastructure sensitivity, export-control rules, sanctions, contracts, processor risk, host jurisdiction risk, public-safe risk, or correctionability. Transfer shall not proceed where unresolved risk is inconsistent with GCRI Canada’s public-benefit purpose, safeguards, legal obligations, or non-executing role.
302.17 Cross-Border Transfer Records. GCRI Canada shall maintain cross-border transfer records, including transfer trigger records, legal reviews, privacy reviews, public authority reviews, community safeguards reviews, Indigenous / local / territorial knowledge reviews, cybersecurity reviews, infrastructure sensitivity reviews, export-control reviews, sanctions reviews, contractual reviews, data processor reviews, host and jurisdiction reviews, transfer risk decisions, approvals, denials, re-scoping decisions, quarantine records, suspension records, conditions, corrections, incidents, and archives.
Section 303. Conflict-of-Law Assessment for Multi-Jurisdiction Data Handling
303.1 Conflict-of-Law Assessment Purpose. GCRI Canada shall conduct conflict-of-law assessment where data handling, storage, processing, transfer, access, publication, AI use, research use, public authority use, community-protected use, controlled technology, export-control exposure, sanctions exposure, disclosure obligations, or localization requirements involve more than one jurisdiction or legal regime. The purpose of assessment is to identify legal conflict, prevent unlawful handling, preserve rights, protect public authority terms, safeguard communities, maintain data sovereignty, preserve GCRI Canada’s public-benefit purpose, and support correctionability.
303.2 Jurisdiction Identification. Conflict-of-law assessment shall identify all relevant jurisdictions, including jurisdiction of data subjects, communities, public authorities, collection, storage, processing, backup, cloud region, provider support, AI provider, repository host, compute environment, publication, recipient, host institution, sponsor, provider, contractor, partner, and governing law of agreements. Jurisdictional identification shall include remote access and administrative access where material.
303.3 Applicable Law Mapping. GCRI Canada shall map applicable laws and obligations, including privacy law, nonprofit law, corporate law, public authority law, health law, research ethics, public records obligations, Indigenous or community data protocols where applicable, cybersecurity law, critical infrastructure law, export-control law, sanctions law, procurement law where relevant, data localization rules, confidentiality law, privilege, court disclosure, and contractual obligations.
303.4 Privacy Law Conflict. Where privacy laws conflict, GCRI Canada shall identify differences in lawful basis, consent, notice, data rights, retention, deletion, transfer, breach notification, processor obligations, sensitive data handling, youth data, health data, automated processing, profiling, AI processing, and public disclosure. GCRI Canada shall apply the most protective lawful handling rule where feasible and shall not exploit weaker jurisdictional rules to reduce protection.
303.5 Public Authority Data Conflict. Where public authority data obligations conflict across jurisdictions, GCRI Canada shall review data-sharing terms, confidentiality, records law, disclosure obligations, public reference rules, emergency management rules, public finance rules, public infrastructure rules, public safety rules, and public authority capacity classification. GCRI Canada shall not allow foreign or conflicting rules to create public authority delegation, public warning authority, public finance approval, procurement approval, or sovereign obligation.
303.6 Indigenous / Community Data Protocol Conflict. Where Indigenous, local, territorial, or community data protocols conflict with external legal, contractual, research, public authority, or technical requirements, GCRI Canada shall assess custodial authority, consent, non-extraction, attribution, territorial context, protected knowledge, data sovereignty, withdrawal rights, correction rights, publication limits, and harm prevention. GCRI Canada shall not treat protocol conflicts as ordinary administrative inconvenience.
303.7 Research Ethics Conflict. Where research ethics requirements differ across institutions, jurisdictions, universities, laboratories, funders, public authorities, or community protocols, GCRI Canada shall identify the applicable approval path, consent requirements, participant protections, publication limits, data retention, secondary use limits, and withdrawal rights. Research shall be re-scoped, suspended, compartmentalized, or denied where ethical conflict cannot be resolved.
303.8 Cybersecurity Law Conflict. Where cybersecurity laws, incident reporting rules, vulnerability disclosure rules, critical infrastructure rules, cyber log rules, or security obligations conflict, GCRI Canada shall assess which obligations apply, what disclosure is required or restricted, what data must be protected, what public-safe handling is required, and whether coordinated disclosure or legal review is necessary. Cybersecurity conflict shall be handled to prevent unsafe disclosure and unlawful concealment.
303.9 Export-Control or Sanctions Conflict. Where export-control or sanctions obligations conflict with openness, research collaboration, public-good software release, public authority learning, provider access, cross-border support, or Nexus interoperability, GCRI Canada shall restrict, re-scope, deny, or suspend access as necessary. Export-control and sanctions conflicts shall be escalated where unresolved and shall not be bypassed through informal sharing, remote access, AI platforms, repositories, or public releases.
303.10 Data Localization Conflict. Where localization obligations differ or conflict, GCRI Canada shall identify which data must remain in which jurisdiction, whether compute-to-data is required, whether controlled-room access can satisfy the obligation, whether public-safe outputs may transfer, whether backups or support access violate localization, and whether alternative routing is required. Localization conflicts shall be recorded and resolved before transfer.
303.11 Disclosure Obligation Conflict. Where one law, contract, public authority request, court process, regulator request, research obligation, participant right, public safety duty, or cyber incident rule requires disclosure and another obligation restricts disclosure, GCRI Canada shall seek legal review where appropriate and shall preserve confidentiality, privilege, public authority terms, protected knowledge, privacy, and public-safe handling to the maximum lawful extent. Disclosure conflicts shall be recorded.
303.12 Government Access Risk. GCRI Canada shall assess government access risk where data may be subject to foreign access, compelled disclosure, surveillance, national security orders, law enforcement access, regulatory access, or provider-controlled disclosure. Government access risk shall be considered in localization, encryption, key control, provider selection, transfer approval, cloud region selection, AI provider use, and controlled-room design.
303.13 Most Protective Lawful Handling Rule. Where multiple legal or protocol regimes apply, GCRI Canada shall apply the most protective lawful handling rule where feasible, including narrower purpose, stronger access control, shorter retention, stronger localization, stricter publication review, stronger AI-use restriction, stronger protected knowledge control, or stricter transfer limits. The most protective rule shall not require unlawful conduct and shall be documented where trade-offs are necessary.
303.14 Suspension, Narrowing, Compartmentalization, or Alternative Routing. Where conflict-of-law assessment identifies unresolved or excessive risk, GCRI Canada may suspend processing, narrow the purpose, reduce data fields, restrict access, compartmentalize data, localize processing, use compute-to-data, use public-safe outputs, replace real data with synthetic or aggregate data, deny transfer, or route work through an alternative lawful structure. Such actions shall preserve public-benefit purpose and correctionability.
303.15 Conflict-of-Law Records. GCRI Canada shall maintain conflict-of-law records, including purpose records, jurisdiction identification, applicable law mapping, privacy law conflict records, public authority data conflict records, Indigenous / community protocol conflict records, research ethics conflict records, cybersecurity law conflict records, export-control and sanctions conflict records, data localization conflict records, disclosure obligation conflict records, government access risk records, most protective lawful handling decisions, suspension records, narrowing records, compartmentalization records, alternative routing records, corrections, incidents, and archives.
Section 304. Transfer Mechanisms, Safeguards, Denial, Suspension, Re-Scoping, and High-Risk Jurisdiction Controls
304.1 Transfer Mechanism Requirement. Any approved transfer of rights-bearing, restricted, public authority-sensitive, protected-knowledge, cyber-sensitive, infrastructure-sensitive, health-sensitive, finance-sensitive, controlled-technology, or sovereign-sensitive data shall use an appropriate transfer mechanism. Transfer mechanisms may include contractual safeguards, data processing agreements, approved transfer clauses where applicable, controlled-room arrangements, compute-to-data arrangements, encryption and key controls, no-download controls, access logging, recipient restrictions, localization, public-safe output release, aggregation, synthetic outputs, or other lawful safeguards proportionate to risk.
304.2 Contractual Safeguards. Contractual safeguards shall define permitted use, prohibited use, confidentiality, data classes, access controls, re-disclosure limits, AI-use limits, model-training restrictions, embedding restrictions, retention, deletion, return, breach notification, audit rights, public authority terms, protected knowledge obligations, public-safe restrictions, export-control obligations, sanctions obligations, incident response, correction obligations, and termination. Contractual safeguards shall not be used to authorize a transfer that is otherwise unlawful or unsafe.
304.3 Data Processing Agreement. Where a recipient acts as a processor, service provider, cloud provider, AI provider, repository host, analytics provider, dashboard provider, model provider, contractor, consultant, or technical operator, GCRI Canada shall require a data processing agreement or equivalent terms where appropriate. Such agreement shall address processing instructions, confidentiality, subprocessors, security controls, jurisdiction, data-use restrictions, training restrictions, retention, deletion, breach notification, audits, assistance with rights requests, and return or destruction of data.
304.4 Standard or Approved Transfer Clauses Where Applicable. Where standard contractual clauses, approved transfer clauses, adequacy mechanisms, inter-institutional agreements, public authority terms, research data-sharing instruments, or other legal transfer instruments are required or appropriate, GCRI Canada shall use them in a manner consistent with the relevant data class, jurisdiction, and purpose. Standard clauses shall not replace substantive review of actual risk, public authority terms, protected knowledge, cyber security, infrastructure sensitivity, or public-safe concerns.
304.5 Technical Safeguards. Technical safeguards may include encryption in transit, encryption at rest, key separation, secure enclaves, confidential computing, access control, MFA, IP restrictions, device controls, logging, watermarking, download prevention, data loss prevention, pseudonymization, de-identification, aggregation, masking, secure APIs, tokenization, secure transfer protocols, and secure deletion. Safeguards shall be selected according to sensitivity and verified where material.
304.6 Organizational Safeguards. Organizational safeguards may include training, confidentiality obligations, role limits, need-to-know rules, access approval, conflict screening, public authority capacity controls, safeguards review, privacy review, cyber review, incident procedures, rights request procedures, data retention policies, audit processes, and accountability assignments. Organizational safeguards shall be documented and communicated to recipients where relevant.
304.7 Encryption and Key Controls. Transfers of sensitive or restricted data shall use encryption and key controls appropriate to risk. Key control shall identify key owner, custodian, storage, access, rotation, revocation, escrow where any, jurisdiction, provider access, and compromise response. Where government access or provider access risk exists, GCRI Canada shall consider whether keys should remain under GCRI Canada or approved Canadian control.
304.8 No-Download Controls. No-download controls may be required where data may be viewed or queried but not copied, downloaded, exported, printed, screenshotted, scraped, embedded, indexed, trained on, or redistributed. No-download controls shall be supported by room rules, technical restrictions, logs, watermarks where appropriate, user commitments, and incident response. No-download status shall not by itself make a transfer safe if other risks remain unresolved.
304.9 Access Logging. Transfers shall include access logging where appropriate. Logs may identify recipient, user, role, access time, files accessed, queries run, exports attempted, downloads permitted, downloads denied, AI-use events, retrieval events, deletion events, and unusual activity. Logs shall be retained, classified, reviewed, and used for audit, incident response, correction, and rights-request handling.
304.10 Transfer Denial. GCRI Canada shall deny a transfer where no lawful basis exists, safeguards are inadequate, recipient risk is unacceptable, jurisdiction risk is unacceptable, public authority terms prohibit transfer, protected knowledge obligations prohibit transfer, privacy risk is excessive, cyber or infrastructure risk is excessive, export-control or sanctions rules prohibit transfer, contractual restrictions prohibit transfer, or public-safe risk cannot be controlled. Transfer denial shall be recorded with reasons.
304.11 Transfer Suspension. GCRI Canada may suspend a transfer where law changes, public authority terms change, recipient risk changes, provider terms change, jurisdiction risk increases, breach occurs, incident occurs, protected knowledge concern arises, cyber risk emerges, export-control concern arises, sanctions concern arises, recipient fails safeguards, or data is misused. Suspension may include access revocation, data return, deletion, processing hold, output quarantine, notice, and investigation.
304.12 Transfer Re-Scoping. GCRI Canada may re-scope a transfer to reduce risk. Re-scoping may include reducing fields, removing identifiers, aggregating data, using synthetic data, limiting recipients, limiting jurisdiction, requiring compute-to-data, imposing no-download controls, limiting duration, excluding public authority data, excluding protected knowledge, excluding sensitive geographies, excluding health data, excluding cyber-sensitive details, or limiting outputs to public-safe summaries.
304.13 High-Risk Jurisdiction Review. Transfers involving high-risk jurisdictions shall require enhanced review. High-risk jurisdiction factors may include weak data protection, high government access risk, sanctions exposure, export-control risk, cybersecurity risk, political instability, public authority sensitivity, protected knowledge risk, inadequate rule of law, compelled disclosure risk, provider dependency, or incompatibility with public-benefit purpose. High-risk jurisdiction review may result in denial, localization, encryption with local key control, compute-to-data, or controlled output only.
304.14 High-Risk Recipient Review. Transfers involving high-risk recipients shall require enhanced review. High-risk recipients may include recipients with weak security, unclear ownership, sanctions exposure, conflicts, sponsor or provider interests, commercial incentives, history of misuse, inability to comply with deletion, inability to preserve confidentiality, public authority ambiguity, insufficient safeguards, or lack of auditability. Review may deny, condition, re-scope, or monitor the transfer.
304.15 Ongoing Monitoring. Approved transfers may require ongoing monitoring of recipient compliance, access logs, deletion obligations, security posture, legal changes, public authority terms, protected knowledge obligations, data-use restrictions, AI-use restrictions, re-disclosure restrictions, provider terms, jurisdiction risk, and incidents. Ongoing monitoring shall trigger correction, suspension, re-scoping, or termination where risk changes.
304.16 Transfer Mechanism and Safeguards Records. GCRI Canada shall maintain transfer mechanism and safeguards records, including transfer mechanism records, contractual safeguard records, data processing agreements, standard or approved transfer clause records, technical safeguard records, organizational safeguard records, encryption and key control records, no-download control records, access logs, transfer denial records, transfer suspension records, transfer re-scoping records, high-risk jurisdiction reviews, high-risk recipient reviews, ongoing monitoring records, incidents, corrections, notices, and archives.
Section 305. Sanctions, Export Controls, National Security, Public-Sector Sensitivity, and Controlled Technology Review
305.1 Sanctions Review. GCRI Canada shall conduct sanctions review before entering, continuing, expanding, publishing, transferring, licensing, sharing, granting access, providing technical support, accepting contributions, accepting sponsorship, accepting funding, engaging collaborators, releasing repositories, enabling AI processing, enabling compute access, or permitting Nexus interface participation where a person, entity, jurisdiction, sector, technology, dataset, software asset, model, repository, provider, host, funder, public authority, contractor, consultant, university, laboratory, National Consortium Company, Project SPV, or other counterparty may be subject to sanctions, restricted-party controls, prohibited-sector controls, restricted-service controls, asset-freeze obligations, controlled-technology restrictions, or other legal restrictions. Sanctions review shall identify relevant counterparties, beneficial ownership where reasonably required, jurisdictional exposure, payment flows, data access, technology access, service provision, export or re-export implications, public authority sensitivity, controlled-room access, AI-use access, cloud or provider access, and any indirect access through intermediaries. GCRI Canada shall deny, restrict, suspend, quarantine, re-scope, terminate, or escalate any activity where sanctions risk is unresolved, prohibited, or inconsistent with law, public-benefit purpose, public authority obligations, protected knowledge safeguards, or institutional integrity.
305.2 Export-Control Review. GCRI Canada shall conduct export-control review before exporting, re-exporting, publishing, transferring, licensing, providing access to, demonstrating, training on, embedding, hosting, releasing, sharing, or enabling use of software, models, datasets, technical documentation, cryptographic materials, AI systems, telecom materials, AI-RAN materials, O-RAN materials, DePIN materials, cyber tools, geospatial materials, satellite or remote-sensing materials, drone or robotics materials, sensor systems, compute methods, quantum-adjacent materials, dual-use technologies, controlled technology, or technical assistance that may be subject to export-control or restricted-transfer rules. Export-control review shall include technology classification, destination, end user, end use, access pathway, remote access, cloud region, repository exposure, public release status, source-code status, model-weight status, controlled data status, training data status, publication classification, public-safe status, and whether legal advice or competent authority guidance is required.
305.3 National Security Review. GCRI Canada shall conduct national security review where an activity, technical asset, data zone, repository, compute environment, model, AI system, observability system, dashboard, map, public authority interface, infrastructure analysis, public-safe output, controlled technology, cross-border transfer, collaboration, publication, or Nexus interface could create national security, public safety, foreign interference, critical infrastructure, strategic technology, data sovereignty, supply-chain, cyber, telecom, compute, or sensitive public-sector risk. National security review shall not make GCRI Canada a national security authority or public authority; it shall operate as an internal risk, legal, safeguards, and institutional integrity review to prevent unlawful or unsafe handling.
305.4 Public-Sector Sensitivity Review. GCRI Canada shall conduct public-sector sensitivity review where materials involve public authorities, public authority personnel, public finance readers, regulators, emergency management bodies, public health bodies, public safety bodies, municipalities, ministries, Crown entities, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, public infrastructure operators, public procurement contexts, or public-sector data. Review shall confirm capacity classification, confidentiality, reference permissions, public-safe release status, public authority boundary language, no-delegation treatment, no-public-warning treatment, no-emergency-command treatment, no-regulatory-approval treatment, no-procurement-approval treatment, no-funding-approval treatment, no-public-finance-approval treatment, and no-sovereign-obligation treatment.
305.5 Controlled Technology Review. GCRI Canada shall review controlled technology before access, transfer, release, publication, repository placement, public-good licensing, provider collaboration, public authority sharing, AI processing, model training, compute execution, external demonstration, or Nexus interface use. Controlled technology includes technology subject to export-control, sanctions, cyber, encryption, telecom, AI, compute, national security, dual-use, critical infrastructure, public safety, contractual, public authority, or restricted-transfer controls. Controlled technology review shall determine permitted users, permitted jurisdictions, permitted uses, prohibited uses, publication limits, repository restrictions, controlled-room requirements, licensing limits, transfer mechanisms, export-control posture, sanctions posture, and correction path.
305.6 Sensitive AI Review. GCRI Canada shall conduct sensitive AI review for AI systems, models, datasets, training data, model weights, fine-tuned models, embeddings, retrieval systems, agentic AI systems, inference systems, AI-enabled dashboards, AI-enabled maps, automated source-comparison systems, Truth Engine methods, or AI-assisted public-safe outputs involving sensitive data, dual-use use cases, public authority data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, controlled technology, public-sector sensitivity, finance-sensitive evidence, or public meaning. Sensitive AI review shall address model identity, provider terms, data-use terms, training restrictions, model-improvement restrictions, deployment environment, tool permissions, human review, bias, drift, hallucination risk, prompt injection, data leakage, output limits, publication limits, export-control exposure, sanctions exposure, and correctionability.
305.7 AI-RAN and O-RAN Review. GCRI Canada shall conduct AI-RAN and O-RAN review where technical assets, observability methods, datasets, telemetry, signals, models, dashboards, reference architectures, profiles, test harnesses, public-good baselines, provider materials, public authority materials, or Nexus Observatory interfaces involve AI-enabled radio access networks, open radio access networks, telecom systems, edge compute, network telemetry, private wireless, critical communications, public safety communications, cyber-physical dependencies, or telecom-related controlled technology. Review shall address telecom sensitivity, public authority sensitivity, infrastructure sensitivity, cyber risk, provider neutrality, procurement neutrality, export-control exposure, national security sensitivity, public-safe publication, and prohibition on using GCRI Canada materials as telecom certification, provider approval, procurement approval, public authority approval, or network performance warranty.
305.8 DePIN and DLT Review. GCRI Canada shall conduct DePIN and distributed ledger technology review where technical assets, observability systems, proof systems, telemetry, node records, smart contracts, tokens, ledgers, blockchain records, decentralized identifiers, attestations, verifiable credentials, public-good software, public authority records, finance-sensitive evidence, or Nexus interface records involve decentralized physical infrastructure networks, blockchain, distributed ledgers, Web3 systems, tokenized incentive structures, oracle systems, or on-chain artifacts. Review shall address privacy, on-chain permanence, sanctions, financial regulation exposure, token incentive manipulation, sybil risk, public authority sensitivity, protected knowledge, no-PII-on-chain rules, no-protected-knowledge-on-chain rules, no-public-authority-sensitive-data-on-chain rules, cyber risk, provider neutrality, public-safe publication, and no-finance-readiness or investment implication.
305.9 Cyber Tool Review. GCRI Canada shall conduct cyber tool review before using, releasing, transferring, publishing, licensing, demonstrating, or sharing tools that may scan, test, exploit, detect, monitor, simulate, attack, defend, analyze, disclose, or affect cyber systems. Cyber tools include vulnerability scanners, exploit proofs, penetration testing tools, prompt injection test tools, model attack tools, log analysis tools, credential analysis tools, malware analysis tools, security telemetry tools, threat intelligence tools, incident response tools, and repository security tools. Review shall identify whether the tool is public-safe, controlled, restricted, dual-use, export-controlled, provider-sensitive, infrastructure-sensitive, public authority-sensitive, or capable of misuse. Cyber tools shall not be released where release would materially increase exploitation risk without lawful and controlled justification.
305.10 Cryptography Review. GCRI Canada shall conduct cryptography review where technical assets involve encryption, signing, hashing, commitments, proofs, key management, secure enclaves, confidential computing, zero-knowledge proofs, multi-party computation, verifiable credentials, digital signatures, authentication, tokenization, privacy-preserving computation, on-chain proofs, or cryptographic references to sensitive data. Review shall consider export-control issues, key custody, deletion limitations, public authority terms, protected knowledge, sensitive hash risks, confirmation attacks, metadata leakage, public-safe limitations, and whether cryptographic mechanisms are being overclaimed as truth, compliance, certification, privacy, security, or public authority approval.
305.11 Geospatial and Earth Observation Review. GCRI Canada shall conduct geospatial and Earth observation review where data, maps, dashboards, public-safe outputs, remote sensing, satellite imagery, drone imagery, sensor data, location data, infrastructure data, community data, environmental data, hazard data, public authority data, or protected knowledge may reveal sensitive locations, community vulnerabilities, infrastructure dependencies, public safety conditions, sacred sites, health-sensitive locations, cyber-physical exposure, or public-safe mapping risk. Review shall address resolution, precision, time delay, aggregation, masking, generalization, re-identification risk, infrastructure targeting risk, protected knowledge exposure, community harm, public authority boundaries, and publication controls.
305.12 Satellite and Remote-Sensing Review. GCRI Canada shall conduct satellite and remote-sensing review for satellite imagery, aerial imagery, Earth observation data, remote-sensing analytics, derived geospatial outputs, climate and nature observations, infrastructure observations, port observations, utility observations, emergency-related observations, degraded-mode awareness, resilience indicators, digital twin inputs, and public-safe maps. Review shall identify licensing, source restrictions, public authority restrictions, export-control issues, national security sensitivity, cloud cover or accuracy limitations, inference limitations, public-safe status, infrastructure sensitivity, protected knowledge, and prohibition on representing remote-sensing outputs as official public warning, emergency command, public authority decision, or operational instruction.
305.13 Drone, Robotics, Autonomous Systems, and Sensor Review. GCRI Canada shall conduct drone, robotics, autonomous systems, and sensor review where technical assets, datasets, maps, models, telemetry, software, reference architectures, observability profiles, or public-safe outputs involve drones, robotics, autonomous vehicles, sensor networks, edge devices, actuator systems, cyber-physical systems, public safety devices, infrastructure sensors, environmental sensors, or community sensors. Review shall consider lawful operation, data collection authority, privacy, geospatial sensitivity, public authority terms, cyber risk, physical safety, dual-use implications, export-control exposure, protected knowledge, and the non-execution boundary. GCRI Canada shall not use review of such systems to assume operator, dispatcher, emergency command, public authority, procurement, or certification functions.
305.14 Telecom and Critical Infrastructure Review. GCRI Canada shall conduct telecom and critical infrastructure review where activities involve communications networks, AI-RAN, O-RAN, private wireless, cloud, sovereign compute, DePIN, cyber systems, energy, water, food, health, ports, transport, public works, emergency management, supply chains, utilities, digital twins, degraded-mode indicators, resilience maps, or infrastructure dependencies. Review shall address public authority terms, cyber risk, infrastructure sensitivity, national security sensitivity, foreign access, provider dependencies, critical dependency exposure, public-safe publication, and no-operational-control language. GCRI Canada’s review shall not create infrastructure approval, public authority approval, telecom certification, procurement approval, finance-readiness, insurance-readiness, or performance warranty.
305.15 Quantum-Adjacent and Dual-Use Review. GCRI Canada shall conduct quantum-adjacent and dual-use review where technical assets involve quantum-relevant systems, cryptography, post-quantum migration, advanced compute, high-performance computing, advanced sensing, optimization, cyber tools, AI systems, robotics, drones, remote sensing, advanced manufacturing, semiconductors, biosecurity, or other technologies that may have beneficial public-good and harmful misuse potential. Dual-use review shall address publication limits, transfer limits, export-control exposure, public authority sensitivity, cyber risk, protected knowledge, research integrity, safety, misuse prevention, and whether controlled access or defensive publication is more appropriate than open release.
305.16 Transfer, Publication, Access, Repository, and Collaboration Controls. Where sanctions, export-control, national security, public-sector sensitivity, or controlled technology review identifies material risk, GCRI Canada may impose controls on transfer, publication, access, repositories, collaboration, licensing, AI use, compute use, retrieval, embedding, model training, public-safe release, controlled-room access, data-room access, public authority sharing, partner sharing, provider access, sponsor access, and Nexus interface participation. Controls may include denial, restricted access, localization, compute-to-data, no-download rooms, public-safe redaction, aggregation, delayed publication, legal review, export review, sanctions screening, credential restriction, repository segregation, controlled annexing, or Board escalation.
305.17 Denial, Restriction, Licensing, or Escalation. GCRI Canada may deny, restrict, license, re-scope, condition, quarantine, suspend, terminate, or escalate any activity where sanctions, export-control, national security, public-sector sensitivity, controlled technology, sensitive AI, AI-RAN, O-RAN, DePIN, DLT, cyber tool, cryptography, geospatial, remote sensing, drone, robotics, telecom, critical infrastructure, quantum-adjacent, or dual-use risk cannot be adequately controlled. Escalation may be to an officer, committee, Board, legal counsel, safeguards function, data / AI / cyber function, public authority contact where lawful and appropriate, or other competent reviewer. No urgency, sponsor interest, provider interest, publication opportunity, public authority curiosity, or technical convenience shall override required denial, restriction, or escalation.
305.18 Sanctions, Export-Control, National Security, and Controlled Technology Records. GCRI Canada shall maintain sanctions, export-control, national security, public-sector sensitivity, and controlled technology records, including sanctions reviews, export-control reviews, national security reviews, public-sector sensitivity reviews, controlled technology reviews, sensitive AI reviews, AI-RAN and O-RAN reviews, DePIN and DLT reviews, cyber tool reviews, cryptography reviews, geospatial and Earth observation reviews, satellite and remote-sensing reviews, drone / robotics / autonomous systems / sensor reviews, telecom and critical infrastructure reviews, quantum-adjacent and dual-use reviews, transfer controls, publication controls, access controls, repository controls, collaboration controls, denials, restrictions, licenses, escalations, legal reviews, corrections, suspensions, withdrawals, and archives.
Section 306. Divergence Logs and Compatibility Notes for Cross-Border Data Handling Exceptions
306.1 Divergence Log Purpose. GCRI Canada shall maintain divergence logs where cross-border data handling, localization, transfer, access, processing, publication, AI use, compute use, public authority terms, protected knowledge protocols, data rights, cyber controls, infrastructure controls, finance-sensitive evidence handling, or Nexus interface practices depart from ordinary GCRI Canada rules, Canadian baseline handling, Nexus-compatible handling, public-good baseline handling, or prior approved practice. Divergence logs shall preserve transparency, traceability, legal accountability, safeguards accountability, public authority boundary discipline, correctionability, and institutional memory.
306.2 Compatibility Note Purpose. GCRI Canada shall maintain compatibility notes where an exception, localized practice, cross-border handling structure, public authority term, community protocol, data zone, transfer mechanism, controlled-room arrangement, compute-to-data configuration, or legal requirement remains compatible with GCRI Canada’s public-benefit purpose, non-execution boundary, role separation, privacy obligations, data / AI / cyber controls, protected knowledge safeguards, public authority boundaries, finance-boundary discipline, certification-boundary discipline, procurement neutrality, and Nexus interface requirements. Compatibility notes shall explain compatibility without converting an exception into a general rule.
306.3 Exception Identification. Each cross-border data handling exception shall be identified with sufficient specificity to determine affected data, source, jurisdiction, recipient, environment, purpose, legal basis, data class, sensitivity, transfer pathway, localization issue, public authority issue, community issue, protected knowledge issue, AI-use issue, cyber issue, infrastructure issue, publication issue, retention issue, deletion issue, and correction path. Exceptions shall not be generalized, implied, repeated informally, or expanded by practice without renewed review.
306.4 Legal Basis for Exception. Each exception shall identify its legal basis, including statute, regulation, contract, consent, public authority term, research ethics approval, data-sharing agreement, processor agreement, transfer mechanism, legal opinion, localization rule, export-control determination, sanctions review, court process, or other competent authority. A legal basis shall be recorded in a form sufficient for audit and correction. Where legal basis is uncertain, the exception shall be denied, narrowed, suspended, or escalated.
306.5 Safeguards Basis for Exception. Each exception involving community-protected data, Indigenous data, local or territorial knowledge, protected participants, youth, vulnerable persons, health-sensitive data, public-safe mapping risk, or rights-bearing data shall identify safeguards basis. Safeguards basis may include consent, custodial authority, community protocol, non-extraction condition, access restriction, no-download room, compute-to-data requirement, aggregation requirement, publication restriction, withdrawal right, correction right, and harm-prevention controls.
306.6 Nexus Compatibility Analysis. Each material exception shall include Nexus compatibility analysis where the exception affects Nexus interface records, Nexus Observatory methods, Nexus Truth Engine methods, Nexus Rails technical evidence inputs, Nexus Grid inputs, Nexus Academy materials, National Consortium interfaces, Regional Nexus Consortium interfaces, public authority learning, public-good baselines, or interoperability. Nexus compatibility analysis shall confirm that the exception does not create agency, merger, shared liability, shared treasury, public authority delegation, finance-readiness determination, certification, procurement approval, provider preference, sponsor control, or execution authority.
306.7 Canadian Compliance Analysis. Each exception affecting Canadian data, Canadian public authority data, Canadian participants, Canadian communities, Canadian infrastructure-sensitive data, Canadian health-sensitive data, Canadian protected knowledge, or GCRI Canada governance records shall include Canadian compliance analysis. Canadian compliance analysis shall review applicable Canadian legal, privacy, corporate, public authority, contractual, research, cyber, data residency, sanctions, export-control, and safeguards obligations. Canadian compliance analysis shall not be bypassed by reliance on foreign processing convenience or partner preference.
306.8 Local Law Analysis. Each exception involving a non-Canadian jurisdiction, regional consortium, national consortium, host institution, local public authority, community protocol, local law, data localization requirement, provider location, cloud region, support location, or partner location shall include local law analysis. Local law analysis shall identify local permissions, restrictions, disclosure risks, government access risks, privacy obligations, research ethics, community protocols, public authority terms, export or sanctions constraints, and conflict with GCRI Canada rules.
306.9 Public Authority Data Analysis. Where an exception involves public authority data, the divergence log and compatibility note shall analyze public authority data terms, capacity classification, confidentiality, public reference controls, official-capacity limits, observer-capacity limits, public finance reader limits, regulator-listening limits, emergency-management limits, infrastructure-operator limits, public-safe publication limits, localization requirements, retention, deletion, and correction rights. No exception shall imply public authority endorsement, delegation, public warning, emergency command, procurement approval, funding approval, public finance approval, or sovereign obligation.
306.10 Community and Protected Knowledge Analysis. Where an exception involves community-protected data, Indigenous data, local or territorial knowledge, protected participants, remote community data, public-safe mapping risk, or community-sensitive data, the divergence log and compatibility note shall analyze custodial authority, consent or authorization, community protocol, non-extraction, attribution, access limits, AI-use restrictions, publication limits, localization, withdrawal rights, correction rights, and harm-prevention measures. No exception shall convert protected knowledge into ordinary reusable data.
306.11 Data / AI / Cyber Analysis. Each exception shall include data / AI / cyber analysis where data processing, AI use, model training, fine-tuning, embedding, retrieval indexing, inference, compute, cloud processing, repository access, API access, cyber-sensitive data, infrastructure-sensitive data, public dashboards, public maps, or technical asset release is involved. Analysis shall address data classification, access controls, provider terms, model identity, training settings, deletion path, leakage risk, prompt injection, cyber controls, encryption, logging, incident response, and correctionability.
306.12 Time Limitation. Each exception shall be time-limited unless a competent authority records why no time limit is appropriate. Time limitation shall identify effective date, expiration date, review date, conditions for renewal, conditions for suspension, and conditions for termination. Exceptions shall not continue indefinitely by neglect, technical persistence, repository continuation, cloud configuration, or repeated informal use.
306.13 Review Cycle. Each exception shall have a review cycle proportionate to risk. Review shall assess whether the legal basis remains valid, safeguards remain adequate, public authority terms remain current, local law has changed, Canadian compliance remains satisfied, data / AI / cyber controls remain effective, recipient risk has changed, jurisdiction risk has changed, technology has changed, incidents have occurred, or public-safe conditions require modification. Review may confirm, narrow, suspend, terminate, or renew the exception.
306.14 Renewal, Suspension, or Termination. An exception may be renewed only through recorded review. It shall be suspended or terminated where legal basis fails, safeguards fail, public authority terms change, consent is withdrawn, protected knowledge concern arises, cyber incident occurs, public-safe risk emerges, recipient risk increases, jurisdiction risk increases, sanctions or export-control risk arises, misuse occurs, or the exception becomes inconsistent with GCRI Canada’s public-benefit purpose, non-execution boundary, role separation, or correctionability. Suspension or termination shall include access review, transfer stop, output quarantine, deletion or return where required, and correction.
306.15 Divergence and Compatibility Records. GCRI Canada shall maintain divergence and compatibility records, including divergence logs, compatibility notes, exception identifiers, legal basis records, safeguards basis records, Nexus compatibility analysis, Canadian compliance analysis, local law analysis, public authority data analysis, community and protected knowledge analysis, data / AI / cyber analysis, time limitations, review cycles, renewals, suspensions, terminations, access changes, deletion or return records, corrections, incidents, and archives.
Section 307. Minimum Cybersecurity Baseline
307.1 Cybersecurity Baseline Purpose. GCRI Canada shall maintain a minimum cybersecurity baseline for its systems, repositories, technical assets, data zones, compute environments, AI systems, dashboards, maps, public-good software, public-safe publication workflows, controlled rooms, data rooms, public authority rooms, public-facing materials, and Nexus interface environments. The purpose of the cybersecurity baseline is to preserve confidentiality, integrity, availability, authenticity, provenance, public-safe publication, data rights, protected knowledge safeguards, public authority trust, research integrity, public-benefit purpose, and correctionability.
307.2 Security Governance. GCRI Canada shall assign security governance responsibility through the Board, an authorized officer, a data / AI / cyber function, a technical asset owner, a repository custodian, or another competent record. Security governance shall establish policies, roles, risk acceptance rules, escalation pathways, incident procedures, access-review procedures, vulnerability procedures, third-party review, training, and records. Security governance shall preserve role separation and shall not create public authority, certification, procurement, provider-selection, or execution authority.
307.3 Asset Inventory. GCRI Canada shall maintain an asset inventory for material systems, repositories, datasets, models, dashboards, maps, APIs, SDKs, schemas, technical baselines, compute environments, cloud environments, data rooms, controlled rooms, credentials, keys, public authority data stores, protected knowledge stores, cyber-sensitive stores, infrastructure-sensitive stores, finance-sensitive stores, and public-facing assets. Asset inventory shall identify owner, custodian, classification, location, dependencies, access controls, security status, public-safe status, and correction path.
307.4 Identity and Access Management. GCRI Canada shall maintain identity and access management controls for users, service accounts, models, agents, workflows, repositories, data rooms, compute environments, dashboards, package channels, and public-facing systems. Identity controls shall include named users where feasible, role-based permissions, attribute-based controls where appropriate, onboarding, offboarding, least privilege, privileged access review, logging, and revocation.
307.5 Multi-Factor Authentication. GCRI Canada shall require multi-factor authentication for systems and roles involving repositories, cloud environments, data rooms, controlled rooms, public authority data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, release systems, package channels, administrative accounts, secrets-management systems, and other high-risk assets. Exceptions shall be risk-reviewed, recorded, time-limited where possible, and corrected where no longer justified.
307.6 Least-Privilege Access. GCRI Canada shall apply least-privilege access to systems, repositories, data, models, AI tools, dashboards, maps, rooms, credentials, keys, APIs, compute environments, and release channels. Users and systems shall receive only the access necessary for the approved purpose and duration. Broad access shall not be granted for convenience, seniority, sponsor preference, provider preference, public authority interest, or technical ease.
307.7 Secure Configuration. GCRI Canada shall maintain secure configurations for cloud systems, repositories, endpoints, servers, databases, dashboards, APIs, CI / CD pipelines, model environments, retrieval systems, vector stores, data rooms, controlled rooms, public websites, and package channels. Secure configuration shall address default settings, authentication, authorization, encryption, logging, backups, network exposure, public access, secrets, dependency management, and update posture.
307.8 Endpoint Security. Endpoints used to access GCRI Canada systems or data shall be secured proportionate to risk. Endpoint controls may include encryption, operating system updates, endpoint protection, malware protection, screen locks, device inventory, remote wipe, local storage restrictions, no-download controls, secure browser requirements, patching, and prohibition on unmanaged or shared devices for restricted materials.
307.9 Network Security. Network security shall include secure connectivity, segmentation, firewall rules, access restrictions, VPN or secure access where appropriate, monitoring, intrusion detection where appropriate, public exposure review, administrative interface protection, secure remote access, and separation between public, development, staging, production, research, controlled-room, and restricted environments. Network controls shall reduce unauthorized access, lateral movement, exfiltration, and public-safe failure.
307.10 Cloud Security. Cloud security shall address account structure, identity, access controls, cloud regions, data residency, encryption, key management, logging, monitoring, backup, secure configuration, public bucket prevention, provider terms, AI provider settings, support access, administrative access, vulnerability management, incident response, and exit. Cloud systems handling restricted or sovereign-sensitive data shall be reviewed for localization, cross-border access, public authority terms, protected knowledge, cyber sensitivity, and infrastructure sensitivity.
307.11 Repository Security. Repository security shall include access controls, branch protections, code review, signed commits where appropriate, secrets scanning, dependency scanning, license review, vulnerability alerts, protected releases, issue classification, restricted repository treatment, public-safe review, takedown procedures, archive controls, and incident response. Public repositories shall be treated as public disclosure environments and shall not contain restricted data or PII by default.
307.12 Application Security. Application security shall apply to public-good software, internal software, restricted software, dashboards, APIs, SDKs, data pipelines, model pipelines, retrieval systems, public-safe publication tools, and Nexus interface tools. Controls may include secure design, threat modeling, input validation, output encoding, authentication, authorization, rate limiting, secure session management, logging, dependency review, testing, code review, and incident response.
307.13 Data Security. Data security shall protect data according to classification, including personal information, sensitive personal information, public authority data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, health-sensitive data, finance-sensitive evidence, confidential materials, controlled annexes, and public-safe outputs. Controls may include encryption, access control, minimization, data zones, compute-to-data, deletion paths, backups, retention, logging, public-safe review, and incident response.
307.14 Logging and Monitoring. GCRI Canada shall maintain logging and monitoring proportionate to risk. Logs may include access logs, administrative logs, repository logs, release logs, credential logs, API logs, data room logs, controlled-room logs, AI-use logs, retrieval logs, compute logs, transfer logs, public dashboard logs, security logs, and incident logs. Logs shall be protected, classified, retained, reviewed where required, and used for detection, investigation, correction, and audit.
307.15 Vulnerability Management. GCRI Canada shall maintain vulnerability management for systems, repositories, software, dependencies, cloud environments, dashboards, APIs, AI systems, retrieval systems, compute environments, package channels, and technical assets. Vulnerability management shall include intake, classification, severity, remediation clocks, patching, mitigation, compensating controls, disclosure review, dependency review, public-safe notice where required, and records.
307.16 Incident Response. GCRI Canada shall maintain incident response procedures for data incidents, privacy incidents, cybersecurity incidents, AI incidents, repository incidents, public authority data incidents, protected knowledge incidents, publication incidents, credential incidents, transfer incidents, and public-safe failures. Incident response shall include preparedness, triage, containment, eradication, recovery, notification review, public-safe communication, correction, post-incident review, and learning loop.
307.17 Backup and Recovery. GCRI Canada shall maintain backup and recovery controls for material systems, repositories, records, datasets, models, technical assets, dashboards, maps, public-safe outputs, controlled annexes, data rooms, and critical governance records. Backups shall be classified, secured, access-controlled, tested where appropriate, encrypted where appropriate, localized where required, and subject to retention, deletion, public authority, protected knowledge, and correction rules.
307.18 Security Awareness and Training. GCRI Canada shall provide security awareness and training proportionate to roles. Training may include phishing awareness, credential hygiene, secrets control, repository security, data classification, public authority data handling, protected knowledge handling, AI-use controls, prompt injection, public repository hygiene, incident reporting, secure development, privacy, cyber sensitivity, infrastructure sensitivity, and public-safe publication. Training shall be recorded where required.
307.19 Third-Party Security. GCRI Canada shall review third-party security for providers, cloud services, AI providers, repository hosts, dashboard providers, data processors, contractors, consultants, universities, laboratories, hosts, sponsors, public authority systems, and partners where they access or process GCRI Canada data, systems, technical assets, or restricted materials. Third-party review shall address security posture, access, data-use terms, jurisdiction, subprocessors, breach response, auditability, retention, deletion, and correctionability.
307.20 Cybersecurity Baseline Records. GCRI Canada shall maintain cybersecurity baseline records, including security governance records, asset inventory records, identity and access records, MFA records, least-privilege records, secure configuration records, endpoint security records, network security records, cloud security records, repository security records, application security records, data security records, logging and monitoring records, vulnerability management records, incident response records, backup and recovery records, security awareness and training records, third-party security records, exceptions, corrections, incidents, and archives.
Section 308. Secure Architecture, Hardening, Segmentation, and Environment Separation
308.1 Secure Architecture Purpose. GCRI Canada shall maintain secure architecture, hardening, segmentation, and environment separation for systems, repositories, data zones, compute environments, AI systems, retrieval systems, dashboards, maps, APIs, public-good technical assets, public-safe publication systems, controlled rooms, data rooms, public authority rooms, public-facing environments, and Nexus interface environments. Secure architecture shall reduce unauthorized access, data leakage, public-safe failure, repository compromise, cyber risk, infrastructure exposure, protected knowledge exposure, public authority data misuse, AI misuse, and uncontrolled authority inflation.
308.2 Defense-in-Depth. GCRI Canada shall apply defense-in-depth where risk requires it. Defense-in-depth may include identity controls, MFA, least privilege, segmentation, encryption, logging, monitoring, secure configuration, endpoint security, network security, repository protection, secrets management, vulnerability management, secure development, public-safe review, incident response, backup and recovery, and human review. No single control shall be treated as sufficient where layered protection is reasonably required.
308.3 Secure-by-Design. Systems, repositories, dashboards, AI tools, data rooms, controlled rooms, APIs, software, data zones, public-safe workflows, and Nexus interfaces shall be designed with security requirements from the outset. Secure-by-design shall include purpose definition, threat modeling where appropriate, data classification, access model, abuse cases, public-safe risks, privacy risks, protected knowledge risks, public authority risks, cyber risks, infrastructure risks, finance-sensitive risks, logging, incident response, and correction path before material deployment.
308.4 Secure-by-Default. GCRI Canada shall configure systems to be secure by default. Default access shall be limited, public sharing shall be disabled unless approved, AI training or model improvement shall be disabled where possible unless authorized, logging shall be enabled where appropriate, encryption shall be enabled where appropriate, administrative access shall be restricted, downloads shall be restricted where needed, and public release shall require affirmative approval. Defaults shall not rely on users remembering to add protection later.
308.5 Hardening. Hardening shall be applied to systems, cloud environments, endpoints, repositories, servers, databases, dashboards, APIs, data rooms, controlled rooms, AI systems, retrieval systems, build pipelines, release systems, and package channels according to risk. Hardening may include removal of unnecessary services, restricted administrative access, secure configuration, patching, disabling public access, secrets control, network restrictions, logging, backup controls, and vulnerability remediation.
308.6 Segmentation. Segmentation shall separate systems, environments, data classes, roles, networks, repositories, cloud accounts, rooms, AI systems, retrieval systems, and release channels to reduce unauthorized access, lateral movement, accidental disclosure, public-safe failure, and cross-contamination. Segmentation shall be based on classification, purpose, sensitivity, public authority terms, protected knowledge, cyber sensitivity, infrastructure sensitivity, finance sensitivity, and operational risk.
308.7 Network Segmentation. Network segmentation may separate public-facing systems, administrative systems, development systems, staging systems, production systems, research systems, controlled-room systems, data-room systems, sovereign compute environments, cyber-sensitive environments, infrastructure-sensitive environments, public authority environments, and archive environments. Network segmentation shall protect restricted data and critical systems from unnecessary exposure.
308.8 Environment Segmentation. Environment segmentation shall distinguish production, staging, development, research, controlled-room, data-room, public authority, public-safe, public, sandbox, incident-response, backup, and archive environments. Each environment shall have defined permitted data classes, permitted users, permitted tools, permitted AI uses, public-safe status, security controls, logging, retention, deletion, and correction path.
308.9 Production Environment. Production environments shall host operative systems, official dashboards, official APIs, official repositories, public-safe outputs, controlled systems, or other assets intended for ongoing use. Production environments shall be hardened, access-controlled, logged, monitored, backed up, versioned, and subject to release controls. Production systems shall not use uncontrolled test data or process restricted data beyond recorded authority.
308.10 Staging Environment. Staging environments shall be used to test releases, dashboards, APIs, maps, AI systems, retrieval systems, schemas, technical baselines, or public-safe outputs before production. Staging shall use synthetic, dummy, minimized, de-identified, or approved test data where possible. Restricted real data shall not be used in staging without authority, classification, access controls, logging, and deletion path.
308.11 Development Environment. Development environments shall be used for coding, prototyping, schema development, test harness development, model experimentation, documentation preparation, and technical review. Development environments shall not contain production credentials, restricted data, public authority data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, health-sensitive data, or finance-sensitive data unless expressly approved and controlled. Development outputs shall not be treated as official releases.
308.12 Research Environment. Research environments shall support approved research, methods development, evidence review, observability analysis, model evaluation, public authority learning research, and public-good technical development. Research environments shall be governed by research protocols, privacy controls, data rights, ethics approvals where required, public authority terms, protected knowledge safeguards, AI-use restrictions, compute records, and correctionability.
308.13 Controlled-Room Environment. Controlled-room environments shall support access to restricted materials under defined purpose, access control, confidentiality, no-download rules where applicable, AI-use restrictions, logging, public-safe output review, retention, closeout, and correction. Controlled-room environments may be used for protected knowledge, public authority data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, legal materials, or sensitive review processes.
308.14 Public Environment. Public environments include websites, public repositories, public dashboards, public maps, public documentation, public APIs, open technical packages, public datasets, public-safe publications, public-good software releases, and open baselines. Public environments shall contain only materials approved for public release and shall undergo privacy, public-safe, security, license, export-control where applicable, and boundary review. Public environments shall not contain restricted data by default.
308.15 Air-Gapped or Restricted Environment Where Appropriate. Air-gapped or restricted environments may be required for highly sensitive cyber materials, controlled technology, public authority-sensitive data, protected knowledge, infrastructure-sensitive records, incident investigations, source-integrity review, high-risk model evaluation, or other high-risk materials. Such environments shall have import and export procedures, media controls, access logs, chain-of-custody, malware review where appropriate, output review, secure deletion, and closeout records.
308.16 No Commingling of Restricted Data With Public Environments. Restricted data shall not be commingled with public environments, public repositories, public dashboards, public maps, public documentation, public APIs, public packages, public training data, public demonstrations, or public-safe materials unless public-safe transformation and approval are complete. Commingling includes hidden metadata, logs, screenshots, notebook outputs, embedded vectors, cached records, source maps, comments, issue threads, and repository history. Commingling shall trigger incident response and correction.
308.17 Architecture Review and Records. GCRI Canada shall maintain architecture review records for material systems and environments, including secure architecture purpose records, defense-in-depth records, secure-by-design records, secure-by-default records, hardening records, segmentation records, network segmentation records, environment segmentation records, production environment records, staging environment records, development environment records, research environment records, controlled-room environment records, public environment records, air-gapped or restricted environment records, no-commingling reviews, incidents, corrections, and archives.
Section 309. Vulnerability Management, Patch Management, Exposure Reduction, Logging, Monitoring, Detection, and Security Telemetry
309.1 Vulnerability Management Purpose. GCRI Canada shall maintain vulnerability management, patch management, exposure reduction, logging, monitoring, detection, and security telemetry processes for systems, repositories, cloud environments, endpoints, dashboards, APIs, SDKs, software, schemas, build pipelines, release systems, package channels, data rooms, controlled rooms, AI systems, retrieval systems, compute environments, public-facing assets, public-good technical assets, and Nexus interfaces. The purpose is to identify, prioritize, remediate, mitigate, monitor, correct, and learn from security weaknesses while preserving public-safe handling and avoiding unsafe disclosure.
309.2 Vulnerability Intake. GCRI Canada shall maintain vulnerability intake channels for internal reports, contributor reports, maintainer reports, user reports, researcher reports, third-party reports, automated scans, dependency alerts, provider notifications, public authority notices, incident findings, penetration test findings, red-team findings, AI safety findings, prompt injection findings, repository findings, and public-safe publication findings. Intake shall classify reports, preserve confidentiality, protect good-faith reporters where appropriate, and prevent public exposure of exploitable details.
309.3 Vulnerability Classification. Vulnerabilities shall be classified by affected asset, affected system, affected data class, exploitability, exposure, dependency status, public authority impact, protected knowledge impact, privacy impact, cyber impact, infrastructure impact, finance-sensitive impact, public-safe impact, AI impact, repository impact, and Nexus interface impact. Classification shall determine severity, access restriction, disclosure handling, remediation clock, escalation, and records.
309.4 Vulnerability Severity. Vulnerability severity may be classified as informational, low, moderate, high, critical, emergency, or by another approved scale. Severity shall consider likelihood, impact, exploit availability, public exposure, affected data, privilege required, scope, persistence, affected users, public authority sensitivity, protected knowledge sensitivity, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, and whether exploitation could cause public-safe failure, public authority confusion, or institutional harm.
309.5 Remediation Clocks. GCRI Canada may establish remediation clocks based on severity, exploitability, exposure, public authority impact, protected knowledge risk, data sensitivity, cyber sensitivity, infrastructure sensitivity, finance sensitivity, availability of patch, availability of mitigation, dependency ownership, and public-safe risk. Remediation clocks shall be tracked and escalated where missed. Where a clock cannot be met, compensating controls, restriction, suspension, depublication, or risk acceptance shall be recorded.
309.6 Patch Management. Patch management shall apply to operating systems, applications, repositories, dependencies, packages, containers, cloud configurations, dashboards, APIs, SDKs, AI systems, retrieval systems, build pipelines, release systems, endpoint systems, and technical assets. Patch management shall include review, testing where appropriate, deployment, rollback plan, user notice where needed, versioning, dependency updates, public-safe release notes, and correction records.
309.7 Exposure Reduction. GCRI Canada shall reduce exposure by limiting public access, closing unnecessary ports, disabling unused services, restricting administrative interfaces, limiting credentials, reducing data fields, removing stale assets, deprecating unsupported assets, restricting downloads, disabling unsafe public dashboards, applying no-download controls, segmenting environments, and removing restricted data from public environments. Exposure reduction shall be prioritized where sensitive data or public-facing systems are involved.
309.8 Compensating Controls. Where immediate patching is not feasible, GCRI Canada may apply compensating controls, including access restriction, network blocking, feature disablement, configuration change, monitoring, WAF or equivalent controls, key rotation, credential restriction, rate limiting, no-download restrictions, controlled-room migration, temporary suspension, public-safe notice, or asset withdrawal. Compensating controls shall be documented and reviewed until permanent remediation occurs.
309.9 Vulnerability Disclosure. GCRI Canada shall handle vulnerability disclosure through public-safe, coordinated, controlled, delayed, or restricted disclosure according to risk. Disclosure shall consider affected parties, public authorities, providers, maintainers, users, exploitation risk, patch availability, legal obligations, confidentiality, cyber-sensitive details, infrastructure sensitivity, protected knowledge, and public safety. Disclosure shall not amplify exploitation or expose restricted information unnecessarily.
309.10 Logging. GCRI Canada shall maintain logs proportionate to system and data risk. Logs may include authentication logs, access logs, administrative logs, repository logs, API logs, cloud logs, endpoint logs, data room logs, controlled-room logs, AI-use logs, retrieval logs, transfer logs, dashboard logs, build logs, release logs, credential logs, vulnerability logs, and incident logs. Logs shall be protected, classified, retained, and reviewed according to risk.
309.11 Monitoring. Monitoring may include system health, access activity, privilege changes, unusual downloads, repository changes, public exposure, dependency alerts, credential use, API activity, cloud configuration changes, data transfer, AI tool use, retrieval anomalies, public dashboard anomalies, failed login patterns, and incident indicators. Monitoring shall be proportionate and shall not become unjustified surveillance of persons or communities.
309.12 Detection. Detection controls shall identify potential unauthorized access, credential compromise, data leakage, repository compromise, dependency compromise, malicious code, prompt injection, model misuse, abnormal retrieval, unusual transfers, public repository exposure, public dashboard exposure, protected knowledge exposure, public authority data exposure, cyber-sensitive disclosure, infrastructure-sensitive disclosure, and finance-sensitive disclosure. Detection findings shall be triaged and escalated where material.
309.13 Security Telemetry. Security telemetry may be collected to support cybersecurity, incident response, vulnerability management, access review, repository security, AI safety, and public-safe publication integrity. Security telemetry shall itself be classified and protected where it may reveal personal information, public authority data, cyber-sensitive details, infrastructure-sensitive information, credentials, system architecture, or behavioural patterns. Security telemetry shall be used only for authorized purposes.
309.14 Alerting. Alerting shall be configured for material systems and risks where timely response is required. Alerts may concern unauthorized access, credential exposure, suspicious repository changes, public bucket exposure, vulnerability alerts, dependency compromise, unusual data export, prompt injection, AI misuse, dashboard anomalies, transfer failures, public repository PII, public authority data exposure, protected knowledge exposure, or critical system failure. Alerts shall route to responsible persons and shall not be represented as public warnings or emergency commands.
309.15 Threat Intelligence. GCRI Canada may use threat intelligence to inform vulnerability management, security telemetry, incident response, public-safe publication, repository security, controlled technology review, public authority data protection, protected knowledge protection, and infrastructure-sensitive handling. Threat intelligence shall be classified, sourced, limited, and handled to prevent unsafe disclosure, stigmatization, public authority overclaim, or unsupported attribution.
309.16 Security Testing. Security testing may include vulnerability scans, penetration tests, code review, dependency scans, configuration review, prompt injection testing, retrieval leakage testing, model security testing, red-team exercises, tabletop exercises, incident simulations, and public repository scans. Security testing shall be authorized, scoped, logged, and controlled to avoid unlawful access, data leakage, disruption, public-safe failure, or exposure of sensitive systems.
309.17 Vulnerability, Patch, Monitoring, and Detection Records. GCRI Canada shall maintain vulnerability, patch, monitoring, and detection records, including vulnerability intake records, classification records, severity records, remediation clocks, patch records, exposure reduction records, compensating control records, vulnerability disclosure records, logging records, monitoring records, detection records, security telemetry records, alerting records, threat intelligence records, security testing records, incidents, corrections, restrictions, suspensions, withdrawals, and archives.
Section 310. Incident Preparedness, Severity Classification, Response, Recovery, Notification, Post-Incident Review, and Learning Loop
310.1 Incident Preparedness. GCRI Canada shall maintain incident preparedness for data incidents, privacy incidents, cybersecurity incidents, AI incidents, repository incidents, public authority data incidents, protected knowledge incidents, publication incidents, controlled-room incidents, transfer incidents, credential incidents, public-safe failures, technical asset incidents, and Nexus interface incidents. Preparedness shall include roles, escalation pathways, contact lists, severity classification, response playbooks, evidence preservation, containment procedures, notification review, public-safe communications, recovery procedures, correction pathways, and learning loops.
310.2 Incident Taxonomy. GCRI Canada shall maintain an incident taxonomy sufficient to classify and route incidents. Incident categories may include data incident, privacy incident, cybersecurity incident, AI incident, repository incident, public authority data incident, protected knowledge incident, publication incident, credential incident, vulnerability incident, transfer incident, controlled-room incident, public-safe output incident, technical asset incident, finance-boundary incident, certification-boundary incident, procurement-boundary incident, provider-neutrality incident, sponsor-control incident, and Nexus interface incident. An incident may belong to multiple categories.
310.3 Data Incident. A data incident means unauthorized or unsafe collection, access, use, disclosure, transfer, deletion, retention, publication, linkage, inference, embedding, retrieval, model training, public dashboard display, public map display, repository exposure, or other handling of data inconsistent with law, policy, classification, data rights, public authority terms, protected knowledge obligations, privacy, safeguards, cyber controls, finance-sensitive restrictions, or correctionability. Data incidents shall be contained, classified, reviewed, corrected, and recorded.
310.4 Privacy Incident. A privacy incident means any actual or suspected breach of privacy, personal information protection, rights-bearing data controls, consent terms, purpose limitation, minimization, access restriction, public-safe publication, re-identification prohibition, data rights pathway, deletion pathway, or confidentiality requirement. Privacy incidents may include unauthorized disclosure, public release of PII, re-identification, excessive collection, unauthorized secondary use, AI processing without authority, or failure to respond to rights requests where material.
310.5 Cybersecurity Incident. A cybersecurity incident means any actual or suspected compromise, unauthorized access, credential exposure, malware, vulnerability exploitation, repository compromise, dependency compromise, cloud exposure, API abuse, data exfiltration, ransomware, denial of service, prompt injection with security impact, model misuse with security impact, unauthorized system change, or other event affecting confidentiality, integrity, availability, authenticity, or provenance of GCRI Canada systems or assets. Cybersecurity incidents shall trigger containment, evidence preservation, eradication, recovery, notification review, and post-incident review.
310.6 AI Incident. An AI incident means an incident involving AI systems, models, embeddings, retrieval systems, agentic workflows, inference records, model outputs, model drift, hallucinations, fabricated citations, prompt injection, data leakage, unauthorized agent actions, unsafe outputs, bias, public overclaim, public authority misdescription, finance overclaim, certification overclaim, procurement implication, provider preference, protected knowledge exposure, cyber-sensitive disclosure, or public-safe failure. AI incidents shall be handled under AI incident controls and cross-routed to privacy, cyber, safeguards, public authority, finance-boundary, or publication review where applicable.
310.7 Repository Incident. A repository incident means unauthorized access, unauthorized commit, malicious code, exposed secrets, PII in public repository, restricted data in public repository, protected knowledge exposure, public authority data exposure, branch protection bypass, release compromise, package compromise, dependency compromise, license issue, public overclaim, or takedown event involving a repository or package channel. Repository incidents shall trigger access review, release freeze where appropriate, credential rotation, history review, takedown or correction, and dependency review.
310.8 Public Authority Data Incident. A public authority data incident means unauthorized access, use, disclosure, transfer, publication, AI processing, embedding, retrieval, misdescription, reference misuse, capacity misclassification, or public-safe failure involving public authority data, public authority personnel data, public finance materials, emergency-management data, public infrastructure data, regulatory materials, or public authority-sensitive records. Such incidents shall be reviewed for public authority terms, capacity classification, confidentiality, notification requirements, public-safe correction, and no-delegation boundaries.
310.9 Protected Knowledge Incident. A protected knowledge incident means unauthorized or unsafe collection, processing, publication, mapping, dashboard display, AI use, embedding, retrieval, transfer, commercial use, misattribution, decontextualization, exposure, or failure to honour withdrawal or correction rights involving Indigenous knowledge, local knowledge, territorial knowledge, community-protected data, cultural knowledge, environmental knowledge, sacred-site information, protected participant information, or safeguards-sensitive material. Protected knowledge incidents shall trigger safeguards review, access restriction, publication hold, custodial consultation where appropriate, correction, withdrawal, and harm-prevention measures.
310.10 Publication Incident. A publication incident means public release, open repository publication, public dashboard display, public map display, public report release, public documentation release, public technical package release, media statement, public-safe summary, or external communication that contains inaccurate, unsupported, unsafe, restricted, personal, protected, public authority-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, misleading, overclaiming, or unauthorized material. Publication incidents shall trigger public-safe review, correction notice, withdrawal, retraction, dashboard suppression, map suppression, repository takedown, or public clarification where required.
310.11 Severity Classification. Incidents shall be classified by severity based on data class, affected persons, affected communities, public authority sensitivity, protected knowledge, cyber impact, infrastructure impact, health impact, finance sensitivity, legal exposure, public exposure, public-safe risk, operational impact, recurrence, maliciousness, agent autonomy, affected systems, affected records, downstream dependency, and reputational impact. Severity may be informational, low, moderate, high, critical, emergency, or another approved scale. Severity classification shall determine escalation, response speed, notification review, Board notice, and post-incident review depth.
310.12 Incident Commander for Internal Response Without Public Emergency Command. GCRI Canada may designate an incident commander or internal response lead for coordinating incident response, containment, investigation, recovery, communication, correction, and closeout. The incident commander role is an internal governance and coordination role only and shall not constitute public emergency command, incident command system authority, public warning authority, public safety authority, public health authority, public infrastructure authority, regulator authority, public finance authority, or authority to direct external responders, public authorities, or infrastructure operators.
310.13 Containment. Containment may include access revocation, credential rotation, key rotation, repository lockdown, release freeze, public dashboard disablement, map suppression, data room restriction, controlled-room hold, model suspension, agent shutdown, retrieval index freeze, transfer suspension, public material takedown, output quarantine, legal hold, evidence preservation, affected-party isolation, provider contact, public authority contact where appropriate, and safeguards escalation. Containment shall be prompt, proportionate, recorded, and designed to prevent further harm while preserving evidence.
310.14 Eradication. Eradication shall remove or neutralize the cause of the incident where feasible. Eradication may include vulnerability patching, malware removal, credential removal, malicious commit removal, misconfiguration correction, dependency replacement, prompt injection source removal, retrieval index repair, public repository history mitigation, data deletion where lawful, model configuration change, tool permission change, workflow correction, access rule correction, or provider remediation. Eradication shall be recorded and verified where appropriate.
310.15 Recovery. Recovery shall restore affected systems, records, assets, workflows, publications, dashboards, maps, repositories, models, data rooms, controlled rooms, or Nexus interfaces to safe and authorized operation. Recovery may include restoring backups, reissuing releases, re-indexing retrieval systems, correcting public materials, restoring access, reclassifying data, re-running compute workloads, revalidating outputs, updating limitations, notifying users, and monitoring for recurrence. Recovery shall not restore unsafe configurations or unreviewed public materials.
310.16 Notification Where Required. GCRI Canada shall provide notification where required by law, contract, public authority terms, privacy obligations, cyber obligations, research ethics, protected knowledge protocols, donor or grant terms, provider agreements, data processing agreements, Board policy, or public-safe integrity. Notification may be internal, Board-level, public authority-specific, participant-specific, community-specific, provider-specific, sponsor-specific, public-safe, or public. Notification shall be accurate, timely where required, proportionate, non-alarming, and protective of sensitive details.
310.17 Public-Safe Communications. Public-safe communications concerning incidents shall be reviewed before release. Such communications shall avoid disclosure of exploitable cyber details, protected knowledge, personal information, public authority-sensitive details, infrastructure-sensitive details, finance-sensitive materials, confidential information, investigation-sensitive details, or unsupported blame. Public-safe communications shall include what is necessary for transparency, correction, risk reduction, and trust, without creating public warning, emergency command, public authority misdescription, finance overclaim, certification implication, or provider preference.
310.18 Post-Incident Review. Material incidents shall receive post-incident review proportionate to severity. Review shall identify timeline, root cause, affected data, affected systems, affected persons, affected communities, affected public authorities, affected repositories, affected models, affected outputs, failed controls, successful controls, legal obligations, safeguards issues, public-safe issues, sponsor or provider influence, third-party issues, notification decisions, correction decisions, dependency impacts, and recurrence prevention. Post-incident review shall not be used to assign blame unfairly or suppress correction.
310.19 Corrective Actions. Corrective actions may include policy updates, technical controls, access changes, training, repository changes, release process changes, model restriction, model suspension, retrieval repair, data deletion, reclassification, public-safe review changes, controlled-room rule changes, provider remediation, contract amendments, licensing changes, public authority reference correction, protected knowledge safeguards changes, vulnerability remediation, publication correction, dashboard correction, map correction, or Board-level governance change. Corrective actions shall have owners, deadlines, and closeout records.
310.20 Learning Loop. GCRI Canada shall maintain a learning loop from incidents into improved governance, evidence methods, data controls, AI controls, cyber controls, privacy controls, safeguards, public authority boundary rules, finance-boundary rules, certification-boundary rules, procurement-neutrality controls, provider-neutrality controls, publication processes, technical baselines, training, and correctionability. Lessons learned shall be converted into updated records, policies, methods, tests, controls, checklists, training, baselines, or public-safe notices where appropriate.
310.21 Incident Records. GCRI Canada shall maintain incident records, including preparedness records, incident taxonomy records, data incident records, privacy incident records, cybersecurity incident records, AI incident records, repository incident records, public authority data incident records, protected knowledge incident records, publication incident records, severity classifications, incident commander or response lead records, containment records, eradication records, recovery records, notification records, public-safe communication records, post-incident reviews, corrective actions, learning-loop records, dependency reviews, closure records, corrections, notices, and archives.
Section 311. Technology Governance for Tools, Platforms, Collaboration Environments, Repositories, Automation Services, AI Assistants, Storage, and Communications
311.1 Technology Governance Purpose. GCRI Canada shall maintain technology governance for tools, platforms, collaboration environments, repositories, automation services, AI assistants, storage systems, communications channels, public cloud environments, SaaS systems, messaging systems, video conference systems, document collaboration systems, ticketing systems, task systems, data rooms, controlled rooms, public authority rooms, public-safe publication environments, and Nexus interface environments. Technology governance shall ensure that institutional work is conducted through approved, secure, logged, classified, purpose-bound, privacy-respecting, public-benefit-aligned, correctionable, and accountable systems. Technology governance shall preserve GCRI Canada’s legal separateness, nonprofit and non-distribution character, non-execution boundary, role separation, public authority boundaries, finance-readiness boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor support-without-control, data / AI / cyber controls, protected knowledge safeguards, research integrity, and public-safe publication discipline.
311.2 Approved Tool Register. GCRI Canada shall maintain an Approved Tool Register for material tools used to create, process, store, analyze, publish, transmit, retrieve, summarize, model, compute, classify, visualize, govern, or archive institutional records, technical assets, public-good software, evidence records, public authority materials, protected knowledge, rights-bearing data, finance-sensitive evidence, cyber-sensitive materials, infrastructure-sensitive materials, public-safe outputs, controlled annexes, or Nexus interface materials. The Approved Tool Register shall identify tool name, provider, purpose, owner, custodian, permitted users, permitted data classes, prohibited data classes, AI-use permissions, model-training settings, storage location, jurisdiction, logging status, security posture, privacy posture, public authority suitability, protected knowledge suitability, export-control concerns, sanctions concerns, retention, deletion, incident response, renewal date, revocation path, and correction path.
311.3 Approved Platform Register. GCRI Canada shall maintain an Approved Platform Register for material platforms used for collaboration, repositories, cloud hosting, document management, data rooms, controlled rooms, public authority rooms, project management, communications, video conferencing, public-safe publication, dashboards, maps, APIs, analytics, AI assistance, verifiable compute, retrieval, embeddings, ticketing, task management, learning, academy delivery, and Nexus interface support. Platform approval shall identify platform scope, permitted records, prohibited records, access controls, administrative controls, audit logs, encryption, provider terms, subprocessors, cloud regions, support access, data-use terms, AI-use terms, model-training restrictions, export controls, sanctions exposure, business continuity, exit readiness, and records disposition.
311.4 Collaboration Environment Controls. Collaboration environments used by GCRI Canada shall be configured to preserve classification, access control, record integrity, confidentiality, versioning, correctionability, and public-safe discipline. Collaboration environments shall distinguish public, internal, controlled, restricted, confidential, no-download, public authority-limited, safeguards-limited, cyber-limited, infrastructure-limited, finance-boundary-limited, and archive-only spaces where required. Collaboration environments shall not allow uncontrolled access, hidden external sharing, unmanaged guest access, uncontrolled AI indexing, uncontrolled synchronization, unreviewed public links, or commingling of restricted data with public materials.
311.5 Repository Controls. Repositories used for code, schemas, models, datasets, documentation, technical baselines, public-good software, test harnesses, benchmark assets, dashboards, maps, ontology files, public-safe publications, controlled annexes, and Nexus interface materials shall be approved, access-controlled, classified, versioned, logged, security-reviewed, license-reviewed, and correctionable. Repository controls shall include owner records, custodian records, branch protection, access review, code review, secrets scanning, dependency review, public-safe release review, vulnerability management, takedown process, archival process, and no-PII-in-public-repository controls.
311.6 Automation Service Controls. Automation services, including workflow automation, scheduled jobs, CI / CD systems, bots, agents, scripts, connectors, integrations, notification systems, synchronization services, robotic process automation, and AI-assisted automation, shall be approved before material use. Automation controls shall identify purpose, owner, service identity, permissions, data classes, trigger conditions, external calls, logging, human approval gates, error handling, access revocation, incident response, and correction path. Automation services shall not autonomously publish, transfer restricted data, communicate with public authorities, approve contracts, make payments, procure, select providers, alter official records, issue public warnings, create finance-readiness implications, or bind GCRI Canada without competent human authority and record.
311.7 AI Assistant Controls. AI assistants used by GCRI Canada shall be governed by model identity, provider review, data-use terms, training and model-improvement settings, permitted data classes, prohibited data classes, prompt handling, retrieval handling, output classification, human review, public-safe status, logging, retention, deletion, privacy review, protected knowledge review, public authority review, cyber review, finance-boundary review, certification-boundary review, procurement-boundary review, and incident response. No restricted material, public authority-sensitive data, protected knowledge, personal information, cyber-sensitive material, infrastructure-sensitive material, finance-sensitive evidence, controlled-room material, or no-download-room material shall be entered into an AI assistant unless the assistant is approved for that class and purpose.
311.8 Storage Controls. Storage systems used by GCRI Canada shall be approved for the data classes they hold. Storage controls shall identify owner, custodian, jurisdiction, access model, encryption, backup, retention, deletion, logging, public sharing settings, synchronization settings, AI indexing settings, public authority terms, protected knowledge restrictions, cross-border exposure, export-control exposure, sanctions exposure, incident response, and exit path. Storage shall not occur in personal drives, unmanaged devices, unapproved cloud accounts, consumer applications, uncontrolled chat systems, public folders, or unlogged locations for material records.
311.9 Communications Channel Controls. Communications channels used for GCRI Canada business shall be approved or otherwise governed by policy. Communications controls shall identify whether a channel may be used for ordinary business, Board materials, committee materials, council materials, public authority communications, public authority-sensitive materials, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive materials, controlled-room notices, legal materials, public-safe publication review, or incident response. Sensitive communications shall use appropriate channels, access controls, retention rules, confidentiality language, and record capture procedures.
311.10 Personal Device and Bring-Your-Own-Device Controls. Personal devices and bring-your-own-device access may be permitted only where security, privacy, confidentiality, access control, device posture, local storage, remote wipe where appropriate, MFA, endpoint protection, encryption, offboarding, and data classification requirements are satisfied. Personal devices shall not be used to store restricted records, public authority data, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, controlled annexes, no-download-room materials, credentials, secrets, or official archives unless expressly approved and controlled.
311.11 Public Cloud Controls. Public cloud services shall be governed by approval, classification, region selection, data residency, access control, identity management, encryption, key management, logging, monitoring, backup, provider terms, subprocessors, AI-use settings, support access, administrative access, incident response, business continuity, exit readiness, and cross-border review. Public cloud use shall not override public authority terms, protected knowledge obligations, privacy obligations, localization requirements, compute-to-data requirements, export-control restrictions, sanctions restrictions, or public-safe controls.
311.12 SaaS Controls. SaaS systems used by GCRI Canada shall be reviewed for purpose, data class suitability, provider terms, data-use terms, AI or analytics use, model-training settings, subprocessors, jurisdiction, security posture, privacy posture, audit logs, export controls, deletion capability, retention, access controls, guest access, public link controls, incident notification, support access, and exit readiness. SaaS approval shall be renewed periodically and revoked where the service becomes unsafe, unsupported, noncompliant, captured by provider risk, or inconsistent with GCRI Canada’s public-benefit purpose.
311.13 Messaging and Chat Controls. Messaging and chat systems shall be governed by classification and recordkeeping rules. Ordinary coordination may occur in approved channels, but controlled materials, Board-sensitive records, public authority-sensitive information, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, legal materials, credentials, secrets, and incident details shall not be shared in informal or unapproved messaging channels. Messaging records that constitute official records shall be captured, retained, restricted, corrected, or archived according to policy.
311.14 Video Conference Controls. Video conference systems shall be approved and configured for meeting sensitivity. Controls may include waiting rooms, authenticated access, meeting passwords, recording restrictions, transcription restrictions, AI note-taking restrictions, participant admission, public authority capacity records, confidentiality reminders, screen-share controls, chat controls, breakout room controls, recording storage, retention, deletion, and public-safe review. Meetings involving Board matters, public authority-sensitive materials, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, or controlled rooms shall use heightened controls.
311.15 Document Collaboration Controls. Document collaboration systems shall preserve access control, version history, permissions, classification, comment sensitivity, tracked change sensitivity, public link restrictions, external sharing approval, AI assistance restrictions, export restrictions, download restrictions where applicable, redaction, publication review, and archival. Draft documents shall not become public records, public-safe outputs, Board-approved records, public authority-facing materials, finance-boundary materials, certification-boundary materials, or Nexus interface records without competent review and adoption.
311.16 Ticketing and Task System Controls. Ticketing and task systems used for issues, vulnerabilities, corrections, incidents, research tasks, public authority requests, protected knowledge issues, data rights requests, finance-boundary reviews, certification-boundary reviews, procurement-sensitive reviews, repository work, or public-safe publication shall be classified and access-controlled. Tickets shall avoid unnecessary sensitive detail where broader access exists and shall use controlled annexes or restricted links for sensitive materials. Ticket status shall not itself constitute Board approval, public authority decision, finance-readiness, certification, procurement approval, or provider selection.
311.17 Tool Approval, Review, Renewal, and Revocation. Tools, platforms, services, repositories, AI assistants, storage systems, communications channels, and collaboration environments shall be approved before material use, reviewed periodically, renewed where appropriate, and revoked where unsafe, unsupported, noncompliant, overbroad, insecure, inconsistent with data rights, inconsistent with public authority terms, inconsistent with protected knowledge obligations, or inconsistent with GCRI Canada’s public-benefit purpose. Revocation shall include access removal, data export or migration where lawful, deletion or return where required, credential removal, integration shutdown, record preservation, user notice, and correction of dependent workflows.
311.18 Technology Governance Records. GCRI Canada shall maintain technology governance records, including Approved Tool Register records, Approved Platform Register records, collaboration environment records, repository control records, automation service records, AI assistant records, storage control records, communications channel records, personal device and bring-your-own-device records, public cloud records, SaaS records, messaging and chat records, video conference records, document collaboration records, ticketing and task system records, approval records, review records, renewal records, revocation records, exceptions, incidents, corrections, migrations, decommissions, and archives.
Section 312. No Shadow IT, Unlogged Storage, Personal Drives, Informal AI Processing, or Side-Channel Processing
312.1 No Shadow IT Rule. GCRI Canada shall not permit shadow IT for material institutional work. Shadow IT means any unapproved, unregistered, unreviewed, unmanaged, unlogged, or side-channel tool, platform, storage system, AI system, messaging channel, repository, automation service, cloud account, SaaS service, notebook environment, file transfer method, personal device storage, or collaboration environment used to create, process, store, share, publish, analyze, retrieve, embed, train on, transfer, or archive GCRI Canada records, technical assets, rights-bearing data, public authority data, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, controlled annexes, or Nexus interface materials outside approved governance. Shadow IT is prohibited because it undermines security, privacy, record integrity, correctionability, public authority boundaries, protected knowledge safeguards, and public-good stewardship.
312.2 No Unapproved Storage. No GCRI Canada record, technical asset, dataset, model, public authority material, protected knowledge, cyber-sensitive material, infrastructure-sensitive material, finance-sensitive evidence, controlled annex, credential, secret, key, Board material, committee material, council material, public-safe publication material, or Nexus interface material shall be stored in unapproved systems. Unapproved storage includes unmanaged cloud accounts, personal drives, consumer file sharing tools, public paste systems, unmanaged notebooks, unauthorized external repositories, unapproved AI platforms, personal email archives, uncontrolled chat attachments, and personal devices not approved for the relevant data class.
312.3 No Unlogged Storage for Material Records. Material records shall not be stored in environments that fail to support recordkeeping, access logging where required, versioning, retention, deletion, correction, archival, and incident response. Unlogged storage prevents institutional accountability and shall not be used for official records, evidence records, public authority materials, protected knowledge, restricted data, technical asset releases, Board records, committee records, council records, correction records, or public-safe publication records.
312.4 No Personal Drives for Official Records. Personal drives shall not be used as the official location for GCRI Canada records. Personal drives may not hold official copies of Board records, committee records, council records, public authority data, protected knowledge, controlled-room materials, repositories, technical assets, datasets, models, evidence packs, public-safe publication materials, finance-sensitive evidence, credentials, secrets, or Nexus interface materials unless an emergency exception applies and the material is promptly captured, reviewed, migrated, restricted, or deleted according to policy.
312.5 No Personal Email for Official Records Except Emergency Capture. Personal email shall not be used for official GCRI Canada records, public authority communications, protected knowledge, controlled annexes, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, Board materials, committee materials, council materials, or official approvals except for emergency capture where no approved channel is available and delay would create greater risk. Emergency personal email use shall be reported, captured into approved systems, reviewed, remediated, and deleted from personal systems where lawful and feasible.
312.6 No Informal AI Processing. No person shall use informal AI processing for GCRI Canada materials where the AI system, provider, data-use terms, training settings, retention, jurisdiction, security, privacy, deletion path, logging, or permitted data classes have not been approved. Informal AI processing includes pasting, uploading, summarizing, translating, coding, analyzing, embedding, indexing, or asking questions about GCRI Canada records in unapproved AI assistants, consumer AI tools, browser extensions, productivity plugins, meeting bots, coding assistants, or automated agents.
312.7 No Upload of Restricted Materials to Unapproved AI Systems. Restricted materials shall not be uploaded, pasted, synchronized, embedded, indexed, summarized, translated, analyzed, used for model training, or otherwise processed in unapproved AI systems. Restricted materials include personal information, sensitive personal information, public authority data, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, health-sensitive data, finance-sensitive evidence, controlled-room materials, no-download-room materials, confidential materials, Board materials, committee materials, council materials, credentials, secrets, and controlled annexes.
312.8 No Side-Channel Processing. Side-channel processing is prohibited for material GCRI Canada work. Side-channel processing includes using unofficial spreadsheets, personal notebooks, private databases, unauthorized scripts, external analytics accounts, unmanaged dashboards, unofficial chat groups, personal AI accounts, personal cloud drives, unapproved repositories, screenshots, local copies, copied datasets, or informal workarounds to process records outside approved controls. Side-channel processing shall be treated as a governance, security, privacy, and correctionability risk.
312.9 No Unapproved Data Export. No person shall export, download, scrape, copy, print, screenshot, synchronize, mirror, email, upload, transfer, or otherwise remove GCRI Canada data from approved environments without recorded authority. Export controls shall apply to public authority data, protected knowledge, personal information, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, controlled annexes, repositories, AI outputs, embeddings, vector stores, logs, dashboards, maps, and technical assets. Unapproved export shall trigger review and may trigger incident response.
312.10 No Unapproved Repository Mirror. No official repository, restricted repository, schema registry, package channel, technical baseline repository, model registry, dataset repository, dashboard repository, public-safe publication repository, or controlled annex repository shall be mirrored, forked, cloned externally, synchronized, or backed up to an unapproved location without authority. Repository mirrors shall be classified, licensed, access-controlled, public-safe-reviewed where public, and tracked in official records.
312.11 No Unapproved Messaging Channel for Controlled Materials. Controlled materials shall not be shared through unapproved messaging channels, informal groups, personal messaging applications, external chat spaces, public forums, or channels not approved for the material classification. Controlled materials include public authority-sensitive materials, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, Board materials, committee materials, council materials, legal materials, confidential materials, incident materials, and controlled annexes.
312.12 Emergency Exception Subject to Capture, Review, and Remediation. An emergency exception may be permitted only where use of an unapproved channel or system is necessary to prevent greater harm, preserve evidence, respond to an incident, protect safety, maintain institutional continuity, or comply with urgent legal or public authority obligations, and no approved method is reasonably available. Emergency use shall be minimized, time-limited, reported promptly, captured into approved systems, classified, reviewed, remediated, deleted or restricted where lawful, and documented. Emergency exception shall not create continuing approval.
312.13 Detection, Correction, and Offboarding. GCRI Canada may detect shadow IT, side-channel processing, unapproved storage, unapproved AI processing, personal drive use, unapproved repository mirrors, unapproved messaging channels, and unapproved exports through access review, repository review, endpoint review, cloud review, audit, incident reports, user reports, training, offboarding review, and technical controls. Detected issues shall be corrected through migration, deletion, access revocation, credential rotation, reclassification, public-safe review, incident response, training, disciplinary action where appropriate, and offboarding capture.
312.14 Shadow IT and Side-Channel Records. GCRI Canada shall maintain shadow IT and side-channel records, including shadow IT reports, unapproved storage records, unlogged storage records, personal drive records, personal email emergency records, informal AI processing records, restricted-material AI upload records, side-channel processing records, unapproved export records, unapproved repository mirror records, unapproved messaging channel records, emergency exception records, detection records, correction records, migration records, deletion records, access revocation records, incidents, training records, offboarding records, and archives.
Section 313. Vendor Security, Third-Party Risk, Data Processors, Outsourcing, Tool Approval, Exit Readiness, and Critical Supplier Concentration
313.1 Vendor Security Purpose. GCRI Canada shall maintain vendor security and third-party risk governance for providers, vendors, contractors, consultants, SaaS platforms, cloud providers, AI providers, cybersecurity providers, repository providers, data processors, subprocessors, outsourcing arrangements, storage providers, communications providers, dashboard providers, data room providers, controlled-room providers, public authority interface providers, technical asset providers, and other third parties that may access, process, host, support, store, secure, transmit, analyze, retrieve, embed, train on, or otherwise affect GCRI Canada records, data, systems, technical assets, public authority materials, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, or Nexus interface materials. Vendor governance shall prevent uncontrolled dependency, unsafe processing, provider capture, sponsor influence, public authority misdescription, data leakage, security failure, lock-in, and loss of correctionability.
313.2 Third-Party Risk Review. Third-party risk review shall be conducted before engaging a third party for material services or before allowing access to sensitive systems or data. Review shall assess purpose, service scope, data classes, access level, jurisdiction, ownership, security posture, privacy posture, data-use terms, AI-use terms, model-training restrictions, subprocessors, support access, logging, deletion, retention, incident response, business continuity, sanctions exposure, export-control exposure, public authority suitability, protected knowledge suitability, financial stability where relevant, reputational risk, conflicts, and exit readiness.
313.3 Data Processor Review. Where a third party processes personal information, rights-bearing data, public authority data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, health-sensitive data, finance-sensitive evidence, or other restricted data on behalf of GCRI Canada, GCRI Canada shall conduct data processor review. Review shall address processing instructions, confidentiality, security controls, subprocessors, cross-border transfer, data-use limits, AI training restrictions, retention, deletion, breach notification, assistance with rights requests, auditability, and correctionability.
313.4 Subprocessor Review. Subprocessors shall be identified, reviewed, and controlled where they may access or process GCRI Canada data. Subprocessor review shall address jurisdiction, service function, data classes, security posture, privacy posture, onward transfer, subcontracting chain, notification of changes, objection rights where appropriate, deletion, retention, incident response, and compatibility with public authority terms and protected knowledge obligations. Unapproved subprocessor use may require denial, restriction, contract amendment, or vendor rejection.
313.5 Outsourcing Review. Outsourcing review shall occur where a material governance, technical, data, AI, cyber, publication, repository, public authority support, controlled-room, data-room, observability, or Nexus interface function is performed by a third party. Outsourcing shall not transfer fiduciary responsibility, public-benefit responsibility, public authority boundary responsibility, finance-boundary responsibility, certification-boundary responsibility, procurement-neutrality responsibility, or correctionability away from GCRI Canada. Outsourced functions shall remain subject to oversight, records, audit rights where appropriate, and exit rights.
313.6 Tool Approval Review. Tool approval review shall assess whether a third-party tool is appropriate for the intended data classes, users, purpose, jurisdiction, workflows, public authority materials, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive materials, public-safe outputs, and Nexus interface needs. Tool approval shall identify permitted uses, prohibited uses, data-use settings, AI-use settings, retention, deletion, logs, access controls, support access, export controls, sanctions exposure, renewal date, and revocation path.
313.7 Cloud Provider Review. Cloud provider review shall assess cloud region, data residency, jurisdiction, security controls, encryption, key management, identity controls, logging, monitoring, backup, resilience, support access, administrative access, subprocessors, contractual terms, AI or analytics use, data-use restrictions, incident notification, deletion capability, export-control exposure, sanctions exposure, business continuity, concentration risk, and exit readiness. Cloud provider use shall be restricted where public authority terms, protected knowledge obligations, sovereignty, cyber risk, or infrastructure sensitivity require restriction.
313.8 AI Provider Review. AI provider review shall assess model identity, provider terms, data retention, data-use settings, training and model-improvement settings, prompt handling, output handling, embeddings, retrieval, tool use, security, privacy, jurisdiction, subprocessors, deletion path, logging, human review support, hallucination risk, bias risk, prompt injection risk, data leakage risk, enterprise controls, public authority suitability, protected knowledge suitability, and exit readiness. AI providers shall not receive restricted materials unless approved for the data class and purpose.
313.9 Cybersecurity Provider Review. Cybersecurity provider review shall assess provider access to sensitive systems, logs, vulnerabilities, credentials, incident records, cyber telemetry, infrastructure information, public authority materials, protected knowledge, repositories, endpoints, cloud systems, and technical assets. Review shall include confidentiality, need-to-know, coordinated disclosure, legal privilege where applicable, access logging, data retention, evidence handling, export-control issues, incident notification, and conflict of interest.
313.10 Repository Provider Review. Repository provider review shall assess repository hosting, access control, branch protection, issue visibility, public link controls, secrets scanning, dependency scanning, artifact storage, release controls, logging, jurisdiction, support access, data-use terms, AI code assistance terms, deletion, export, mirroring, incident response, and public repository hygiene. Repository providers shall be suitable for the classification of assets hosted.
313.11 Public Authority Data Handling Review. Vendors and third parties handling public authority data shall be reviewed for public authority terms, confidentiality, localization, access controls, public reference limits, public-safe publication limits, retention, deletion, incident notification, auditability, subprocessors, and no-delegation boundaries. Vendor handling of public authority data shall not imply public authority endorsement, public authority approval, public warning authority, emergency command, procurement approval, funding approval, public finance approval, or sovereign obligation.
313.12 Community and Protected Knowledge Handling Review. Vendors and third parties handling community-protected data, Indigenous data, local or territorial knowledge, protected participant information, or safeguards-sensitive material shall be reviewed for custodial authority compatibility, consent or authorization, non-extraction, AI-use restrictions, access controls, localization, no-download rules, publication restrictions, withdrawal rights, correction rights, confidentiality, and harm-prevention controls. Vendors unable to honour such controls shall not receive such materials.
313.13 Contractual Control Requirements. Contracts with vendors and third parties shall include controls proportionate to risk, including scope, permitted use, prohibited use, confidentiality, data ownership, data rights, public authority terms, protected knowledge obligations, security controls, privacy controls, AI-use restrictions, model-training restrictions, subprocessor controls, breach notification, incident cooperation, retention, deletion, return, audit rights where appropriate, business continuity, exit assistance, IP rights, public reference limits, non-endorsement, no-provider-preference, and correction obligations.
313.14 Security Addendum. GCRI Canada may require a security addendum for vendors handling material systems or data. The security addendum may address identity and access management, MFA, encryption, key management, logging, monitoring, vulnerability management, secure development, incident response, backup, disaster recovery, subcontractors, penetration testing, security certifications where relevant, audit rights, secure deletion, and security contacts. A vendor security certification shall not substitute for GCRI Canada review where risk requires review.
313.15 Privacy Addendum. GCRI Canada may require a privacy addendum where vendors process personal information, rights-bearing data, public authority data, protected knowledge, health-sensitive data, or community data. The privacy addendum may address lawful processing instructions, confidentiality, data subject rights, purpose limitation, minimization, cross-border transfer, subprocessors, retention, deletion, breach notification, privacy incident cooperation, AI-use limits, model-training restrictions, and return or destruction of data.
313.16 Incident Notification Terms. Vendor contracts shall include incident notification terms proportionate to risk. Terms shall require prompt notification of data incidents, privacy incidents, cybersecurity incidents, AI incidents, repository incidents, public authority data incidents, protected knowledge incidents, credential incidents, availability incidents, or other events affecting GCRI Canada data, systems, records, or public-safe outputs. Notification terms shall identify timing, content, cooperation, evidence preservation, remediation, affected data, affected systems, and public-safe communication coordination.
313.17 Audit Rights Where Appropriate. GCRI Canada may require audit rights, assurance reports, security reports, compliance reports, access logs, deletion certificates, subprocessor reports, vulnerability remediation evidence, incident reports, penetration test summaries, or equivalent assurance where vendor risk warrants. Audit rights shall be proportionate and shall respect confidentiality, security, public authority terms, protected knowledge, and legal privilege.
313.18 Exit Readiness. GCRI Canada shall maintain exit readiness for material vendors and third parties. Exit readiness shall include data export, data return, data deletion, transition support, successor provider readiness, credential revocation, integration shutdown, repository transfer, key transfer or destruction, continuity plan, archive preservation, public-safe notice where required, and avoidance of provider lock-in. Exit readiness shall be considered before approval and throughout the relationship.
313.19 Critical Supplier Concentration Review. GCRI Canada shall review critical supplier concentration where reliance on one vendor, cloud provider, AI provider, repository provider, cybersecurity provider, data processor, communications provider, or platform creates resilience, bargaining, security, public authority, protected knowledge, sovereignty, cost, continuity, or capture risk. Concentration review may require diversification, exit planning, backup arrangements, escrow, open standards, data portability, local copies, sovereign compute alternatives, or Board escalation.
313.20 Vendor and Third-Party Risk Records. GCRI Canada shall maintain vendor and third-party risk records, including vendor security purpose records, third-party risk reviews, data processor reviews, subprocessor reviews, outsourcing reviews, tool approval reviews, cloud provider reviews, AI provider reviews, cybersecurity provider reviews, repository provider reviews, public authority data handling reviews, community and protected knowledge handling reviews, contractual control records, security addenda, privacy addenda, incident notification terms, audit rights, exit readiness records, critical supplier concentration reviews, incidents, renewals, revocations, corrections, and archives.
Section 314. Business Continuity, Backup, Disaster Recovery, RTO / RPO Targets, Testing, and Decommissioning
314.1 Business Continuity Purpose. GCRI Canada shall maintain business continuity, backup, disaster recovery, resilience, testing, and decommissioning arrangements for critical functions, critical records, critical systems, repositories, technical assets, data rooms, controlled rooms, public authority rooms, public-safe publication systems, public-good software, dashboards, maps, evidence records, Board records, committee records, council records, data / AI / cyber records, privacy records, safeguards records, public authority interface records, finance-boundary records, technical baselines, and Nexus interface materials. Continuity arrangements shall preserve institutional survival, legal compliance, public-benefit purpose, evidence integrity, data protection, correctionability, and public-safe communications without converting GCRI Canada into an emergency command body, public authority operator, infrastructure operator, finance execution body, certification body, or managed service provider.
314.2 Critical Function Identification. GCRI Canada shall identify critical functions that must continue, resume, or be recoverable after disruption. Critical functions may include corporate governance, Board and officer records, legal compliance, finance administration, payroll where applicable, data protection, incident response, public-safe communications, public authority contact points, repository stewardship, technical asset stewardship, evidence record access, correction pathways, cybersecurity response, privacy response, protected knowledge safeguards, controlled-room administration, public-safe publication control, and Nexus interface continuity. Critical function identification shall include owners, dependencies, minimum operating capability, continuity priority, and recovery pathway.
314.3 Critical Record Identification. GCRI Canada shall identify critical records requiring protection, backup, restricted access, archival, legal hold, or continuity access. Critical records may include Articles, Bylaws, Board minutes, resolutions, registers, policies, contracts, donor and grant records, employment records, contributor records, IP records, licenses, public authority terms, data-sharing agreements, protected knowledge records, privacy records, cybersecurity records, incident records, evidence records, model records, dataset records, technical asset records, source records, correction records, and Nexus interface records. Critical records shall be classified and protected against loss, corruption, unauthorized deletion, and uncontrolled disclosure.
314.4 Critical System Identification. GCRI Canada shall identify critical systems supporting governance, records, repositories, data storage, cloud environments, identity and access management, secrets management, communications, ticketing, public-safe publication, dashboards, maps, data rooms, controlled rooms, AI systems, retrieval systems, compute environments, backup systems, incident response, and Nexus interfaces. Critical system records shall identify owner, custodian, dependency, provider, location, classification, backup method, recovery priority, RTO, RPO, alternate process, and decommissioning path.
314.5 Backup Requirements. GCRI Canada shall maintain backups for critical records and systems proportionate to risk. Backup requirements shall address scope, frequency, location, encryption, access controls, retention, data residency, public authority terms, protected knowledge restrictions, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive materials, immutable backups where appropriate, offline backups where appropriate, backup testing, deletion obligations, and restoration procedures. Backups shall not become uncontrolled secondary repositories.
314.6 Backup Encryption. Backups containing personal information, public authority data, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, health-sensitive data, finance-sensitive evidence, confidential materials, controlled annexes, or credentials shall be encrypted where appropriate and protected through key management, access control, logging, storage segregation, and recovery procedures. Backup encryption shall not prevent lawful recovery, correction, retention compliance, or deletion where required.
314.7 Backup Testing. Backups shall be tested periodically and after material system changes where risk requires it. Backup testing shall verify recoverability, integrity, completeness, access control, classification, restoration time, dependency availability, encryption key availability, public authority term compliance, protected knowledge restrictions, and correction records. Backup tests shall use safe environments and shall not expose restricted data through testing.
314.8 Disaster Recovery Plan. GCRI Canada shall maintain disaster recovery plans for critical systems and records. Plans shall identify failure scenarios, responsible persons, escalation paths, recovery steps, communications, backup locations, system dependencies, provider contacts, credential recovery, public authority contact procedures where applicable, protected knowledge safeguards, public-safe communications, manual workarounds, restoration verification, and post-recovery correction. Disaster recovery plans shall be reviewed and updated when systems, vendors, data classes, or risks change.
314.9 Recovery Time Objectives. GCRI Canada may establish recovery time objectives for critical systems and functions. Recovery time objectives shall identify the target time within which a system or function should be restored after disruption. RTOs shall be proportionate to public-benefit need, governance obligations, legal obligations, data protection, incident response, public authority commitments, research continuity, correctionability, and available resources. Failure to meet an RTO shall trigger review and improvement where material.
314.10 Recovery Point Objectives. GCRI Canada may establish recovery point objectives for critical records and systems. Recovery point objectives shall identify the maximum tolerable data loss measured by time or record state. RPOs shall reflect record criticality, legal obligations, public authority terms, research integrity, evidence integrity, repository activity, data rights, correctionability, and backup feasibility. RPOs shall be reviewed where systems or risks change.
314.11 Continuity Testing. GCRI Canada shall conduct continuity testing proportionate to risk. Testing may include backup restoration, failover exercises, access recovery, communication drills, tabletop exercises, repository recovery, credential recovery, data room recovery, controlled-room recovery, public-safe publication suspension, incident response integration, and vendor continuity tests. Continuity testing shall be recorded and shall not expose sensitive information unnecessarily.
314.12 Tabletop Exercises. GCRI Canada may conduct tabletop exercises for disruptions involving cyber incidents, repository compromise, cloud outage, data room outage, public authority data incident, protected knowledge incident, AI system incident, public-safe publication incident, credential loss, vendor failure, critical supplier failure, natural disaster, office inaccessibility, or key personnel unavailability. Tabletop exercises shall test roles, escalation, decision authority, public-safe communications, records access, continuity priorities, and correction paths.
314.13 Dependency Review. Business continuity shall include dependency review for vendors, cloud providers, AI providers, repository providers, communications providers, identity providers, data processors, controlled-room providers, key personnel, licenses, public authority interfaces, host institutions, critical records, technical assets, and Nexus interfaces. Dependency review shall identify single points of failure, concentration risk, exit readiness, alternate processes, backup access, and successor arrangements where lawful and necessary.
314.14 Successor Access Where Lawful and Necessary. GCRI Canada may establish successor access procedures to ensure lawful continuity where key personnel, custodians, maintainers, officers, repository owners, secrets custodians, data room administrators, or controlled-room custodians become unavailable. Successor access shall be limited, logged, approved, confidential, and subject to separation of duties. Successor access shall not authorize misuse of protected knowledge, public authority data, credentials, finance-sensitive evidence, or official records.
314.15 Decommissioning. Systems, repositories, tools, platforms, AI assistants, storage environments, data rooms, controlled rooms, public authority rooms, dashboards, maps, APIs, package channels, compute environments, and technical assets shall be decommissioned through an approved process where they are no longer needed, unsafe, unsupported, superseded, legally restricted, insecure, inconsistent with public-benefit purpose, or replaced. Decommissioning shall address data export, data return, deletion, archival, access revocation, credential revocation, public-safe notices, dependency review, successor system, and records preservation.
314.16 Data Disposition on Decommissioning. Data disposition on decommissioning shall identify whether data will be migrated, returned, deleted, sealed, anonymized, aggregated, archived, restricted, or retained. Disposition shall comply with law, public authority terms, protected knowledge obligations, privacy rights, data rights, research integrity, legal holds, incident holds, retention schedules, deletion obligations, correctionability, and institutional memory. Decommissioning shall not leave orphaned datasets, unmanaged backups, stale embeddings, uncontrolled logs, forgotten credentials, public links, or unreviewed archives.
314.17 System Retirement. System retirement shall identify retired systems, retirement date, reason, successor system where any, affected data, affected users, affected integrations, affected repositories, affected outputs, access revocation, credential revocation, deletion or archival, public-safe notice where appropriate, vendor termination, license termination, dependency updates, and continuing records. Retired systems shall not continue operating informally, through old credentials, hidden integrations, unapproved exports, or shadow IT.
314.18 Continuity, Backup, Recovery, Testing, and Decommissioning Records. GCRI Canada shall maintain continuity, backup, recovery, testing, and decommissioning records, including business continuity purpose records, critical function records, critical record records, critical system records, backup requirements, backup encryption records, backup testing records, disaster recovery plans, recovery time objectives, recovery point objectives, continuity testing records, tabletop exercise records, dependency reviews, successor access records, decommissioning records, data disposition records, system retirement records, incidents, corrective actions, lessons learned, and archives.
Last updated
Was this helpful?