ARTICLE X. DATA
Section 279. Data, AI, Cybersecurity, and Verifiable Compute Governance Purpose
279.1 Data Governance Purpose.
279.1.1 Data governance shall protect the Corporation’s public-benefit purposes, research integrity, evidence integrity, methods integrity, public-good technical asset stewardship, public authority trust, community safeguards, privacy, cybersecurity, protected knowledge, legal compliance, correctionability, and institutional continuity by governing the collection, receipt, creation, classification, access, processing, use, sharing, publication, retention, deletion, correction, restriction, and archival of data.
279.1.2 Data governance shall apply to all data received, generated, observed, inferred, derived, classified, transformed, stored, accessed, transmitted, published, restricted, or archived by or for the Corporation, including research data, evidence data, observability data, public authority data, personal information, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, community-protected data, Tribal / Indigenous data, local and territorial knowledge, cultural and environmental knowledge, protected knowledge, model outputs, inference records, telemetry, logs, datasets, documents, maps, dashboards, repositories, software artifacts, and technical baselines.
279.1.3 Data governance shall be interpreted as a fiduciary-grade institutional control function and not as a technical convenience, file-management practice, informal research preference, platform default, vendor feature, or optional administrative procedure.
279.2 Privacy Purpose.
279.2.1 Privacy governance shall protect persons, communities, rights-bearing data, personal information, sensitive personal information, health-sensitive data, public authority data, children’s or youth data where applicable, education data where applicable, community-protected data, and other privacy-relevant information from unauthorized collection, use, disclosure, retention, linkage, profiling, inference, publication, AI processing, re-identification, or misuse.
279.2.2 Privacy governance shall support lawfulness, fairness, transparency, purpose limitation, data minimization, access control, security, accuracy, correction, deletion where applicable, complaint pathways, non-retaliation, public-safe publication, and rights-respecting research.
279.2.3 Privacy protection shall not be subordinated to institutional convenience, sponsor preference, provider capability, AI-tool availability, publication pressure, public authority interest, capital-reader interest, media interest, or technical ambition.
279.3 AI Governance Purpose.
279.3.1 AI governance shall control the acquisition, development, deployment, configuration, access, use, monitoring, review, and retirement of AI systems used by the Corporation, including generative AI, agentic systems, retrieval systems, classifiers, summarizers, transcription tools, translation tools, embedding systems, model-evaluation tools, anomaly detectors, routing tools, decision-support systems, and AI-assisted research workflows.
279.3.2 AI governance shall preserve human responsibility, source-grounded evidence, model transparency where appropriate, no-training restrictions, prompt and inference controls, bias review, hallucination review, data leakage prevention, protected knowledge protection, public authority boundary discipline, public-safe publication, correctionability, and non-execution.
279.3.3 AI systems shall not be treated as directors, officers, public authorities, certifiers, recognizers, finance-readiness authorities, procurement authorities, legal advisors, auditors, emergency commanders, public warning bodies, or final arbiters of technical truth.
279.4 Cybersecurity Purpose.
279.4.1 Cybersecurity governance shall protect the Corporation’s systems, records, repositories, credentials, keys, tokens, datasets, models, inference records, controlled rooms, public-good software, technical baselines, dashboards, maps, communications, financial systems, and institutional operations from unauthorized access, misuse, compromise, disclosure, manipulation, destruction, disruption, or exfiltration.
279.4.2 Cybersecurity shall support confidentiality, integrity, availability, resilience, least privilege, secure development, secure collaboration, vulnerability management, incident response, business continuity, evidence preservation, public authority trust, protected knowledge protection, and public-safe publication.
279.4.3 Cybersecurity governance shall not convert the Corporation into a managed security services provider, incident commander, regulator, cyber-certification body, public authority cyber command body, insurance underwriter, or cyber-compliance approver.
279.5 Verifiable Compute Purpose.
279.5.1 Verifiable compute governance shall support trustworthy, traceable, reproducible where appropriate, auditable where lawful and safe, and correctionable computation used in research, evidence, methods, observability, AI evaluation, public-good software, technical baselines, dashboards, simulations, digital twins, and public-safe publications.
279.5.2 Verifiable compute may include compute provenance, environment records, code versioning, dependency records, execution logs, workflow receipts, cryptographic receipts where appropriate, container records, hardware or cloud environment records, model evaluation records, reproducible computation methods, secure execution records, and controlled compute access.
279.5.3 Verifiable compute shall support evidence integrity and technical memory but shall not constitute certification, legal compliance approval, public authority approval, finance-readiness, procurement approval, security guarantee, rating, or enterprise execution.
279.6 Verifiable Intelligence Purpose.
279.6.1 Verifiable intelligence governance shall support source-grounded, evidence-linked, reviewable, auditable where appropriate, human-governed, and correctionable use of AI-assisted analysis, machine inference, knowledge retrieval, classification, summarization, translation, anomaly detection, and decision-support outputs.
279.6.2 Verifiable intelligence shall require linkage between AI-assisted outputs and source records, methods, model identity, version, inference context, human review, limitations, uncertainty, access class, public-safe status, and correction path where material.
279.6.3 Verifiable intelligence shall not mean that AI outputs are inherently true. It means that intelligence outputs are traceable, reviewable, bounded, documented, and capable of correction.
279.7 Controlled-Room Purpose.
279.7.1 Controlled rooms shall provide secure, access-controlled, purpose-limited environments for reviewing restricted data, public authority data, cyber-sensitive data, infrastructure-sensitive data, health-sensitive data, community-protected data, protected knowledge, confidential research materials, controlled technology, privileged materials, or other sensitive records.
279.7.2 Controlled rooms may include clean rooms, data rooms, no-download rooms, restricted repositories, public authority rooms, regulator-listening rooms, public finance reader rooms, safeguards rooms, cyber rooms, protected knowledge rooms, and other controlled environments approved by competent authority.
279.7.3 Controlled-room access shall be based on eligibility, authority, need, confidentiality obligations, data / AI / cyber controls, conflict review, public authority capacity, safeguards, and access records, and shall not be granted as a donor, sponsor, provider, investor, public authority, or relationship benefit.
279.8 Public Authority Data Protection Purpose.
279.8.1 Public authority data protection shall preserve the confidentiality, integrity, lawful use, public records status, restricted-use status, public-sector ethics status, security, privacy, and public-safe meaning of data received from or relating to public authorities.
279.8.2 Public authority data shall be handled according to applicable law, contract, public records requirements, FOIA and state sunshine considerations where applicable, public authority restrictions, confidentiality terms, procurement rules, grant rules, government ethics rules, security requirements, and public authority capacity records.
279.8.3 Receipt or handling of public authority data shall not create public authority delegation, official adoption, public warning authority, emergency command, procurement approval, regulatory approval, public finance approval, grant approval, or sovereign decision-making authority.
279.9 Rights-Bearing Data Protection Purpose.
279.9.1 Rights-bearing data protection shall govern data that relates to persons, communities, groups, identities, protected classes, rights, benefits, access, participation, vulnerability, civil rights, accessibility, public health, employment, education, housing, public safety, emergency exposure, environmental justice, or other interests capable of affecting rights, dignity, safety, or opportunity.
279.9.2 Rights-bearing data shall be governed by heightened safeguards, including purpose limitation, minimization, fairness, bias review, civil rights review, accessibility review, non-discrimination, non-retaliation, privacy, security, consent or lawful basis where required, public-safe review, and correction pathways.
279.10 Health-Sensitive Data Protection Purpose.
279.10.1 Health-sensitive data protection shall govern health, public health, clinical, behavioral, epidemiological, disability-related, emergency medical, health-system, vulnerable-population, youth, or health-adjacent information handled by the Corporation.
279.10.2 Health-sensitive data shall be reviewed for applicable privacy obligations, ethical review, consent, de-identification, re-identification risk, public health authority restrictions, vulnerable-population safeguards, AI-use restrictions, publication risk, and public-safe handling.
279.10.3 The Corporation shall not use health-sensitive data to provide diagnosis, clinical advice, public health orders, emergency medical direction, health certification, public warning, or public authority action.
279.11 Cyber-Sensitive and Infrastructure-Sensitive Data Protection Purpose.
279.11.1 Cyber-sensitive and infrastructure-sensitive data protection shall govern data that could expose vulnerabilities, credentials, keys, tokens, architecture diagrams, network configurations, incident records, telemetry, security logs, critical infrastructure locations, operational dependencies, emergency systems, public works systems, utilities, telecom systems, ports, transportation, water, energy, food, health systems, or other sensitive infrastructure.
279.11.2 Such data shall be handled through access controls, need-to-know review, public-safe publication review, redaction, aggregation, controlled-room use, cyber review, incident-response coordination, and correctionability.
279.11.3 The Corporation shall not publish or route cyber-sensitive or infrastructure-sensitive data in a manner that increases harm, enables misuse, creates public warning confusion, or compromises public authority trust.
279.12 Community-Protected, Tribal / Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge Protection Purpose.
279.12.1 Community-protected, Tribal / Indigenous, local, territorial, cultural, environmental, sacred, ecological, vulnerability-related, and protected knowledge shall be handled with heightened respect, restriction, protocol sensitivity, consent awareness, attribution discipline, public-safe mapping controls, AI-use restrictions, non-extraction discipline, non-retaliation, and correction pathways.
279.12.2 Protected knowledge shall not be collected, translated, generalized, embedded, trained on, mapped, published, transferred, commercialized, or used for sponsor, provider, public authority, finance-facing, or enterprise purposes without lawful authority, appropriate permission, protocol compliance where applicable, and safeguards review.
279.13 Public-Safe Publication Support Purpose.
279.13.1 Data, AI, cybersecurity, and compute governance shall support public-safe publication by ensuring that outputs released by the Corporation are accurate, lawful, evidence-supported, privacy-aware, cyber-safe, infrastructure-safe, protected-knowledge-safe, public authority-boundary compliant, finance-boundary compliant, certification-boundary compliant, procurement-neutral, recognition-boundary compliant, and correctionable.
279.13.2 Public-safe publication controls may require redaction, aggregation, masking, delay, controlled annexes, restricted circulation, no-download access, non-attribution, limitation language, correction notices, or withdrawal.
279.14 Evidence Integrity Support Purpose.
279.14.1 Data, AI, cybersecurity, and compute governance shall support evidence integrity by preserving source lineage, provenance, custody, timestamps, permissions, data rights, transformation history, model identity, inference records, compute records, access logs, correction history, and auditability where appropriate.
279.14.2 No data, AI output, cyber log, compute result, telemetry stream, model output, or dashboard element shall be treated as evidence unless reviewed, classified, permissioned, contextualized, and correctionable under the applicable evidence controls.
279.15 Research Integrity Support Purpose.
279.15.1 Data, AI, cybersecurity, and compute governance shall support research integrity by ensuring lawful collection, ethical use, secure storage, accurate analysis, appropriate AI assistance, reproducible or reviewable computation where appropriate, limitation disclosure, uncertainty disclosure, bias review, conflict management, and correction.
279.15.2 Research integrity shall not be compromised by undocumented data transformations, unapproved AI tools, insecure repositories, hidden model training, missing inference records, uncontrolled access, provider dependency, sponsor pressure, or public authority ambiguity.
279.16 Public-Good Technical Asset Support Purpose.
279.16.1 Data, AI, cybersecurity, and compute governance shall support public-good technical assets, including public-good software, open technical baselines, schemas, APIs, SDKs, dashboards, maps, model cards, system cards, benchmark cards, proof receipts, observability tools, methods repositories, and technical documentation.
279.16.2 Public-good technical assets shall be secured, versioned, licensed, documented, access-controlled where appropriate, dependency-reviewed, vulnerability-reviewed, AI-use-reviewed where applicable, protected from private enclosure, and correctionable.
279.17 Incident Response Purpose.
279.17.1 Incident response shall ensure that suspected or confirmed data, AI, cybersecurity, privacy, compute, controlled-room, protected knowledge, public authority data, repository, model, or publication incidents are identified, contained, investigated, corrected, reported where required, and learned from.
279.17.2 Incident response shall preserve evidence, logs, privilege, confidentiality, public authority trust, non-retaliation, protected knowledge, affected-person protection, public-safe communication, and recurrence prevention.
279.18 Non-Execution Boundary for Data, AI, Cybersecurity, and Compute Outputs.
279.18.1 Data, AI, cybersecurity, verifiable compute, verifiable intelligence, controlled-room outputs, dashboards, logs, model outputs, benchmark outputs, public-good software outputs, technical baselines, and public-safe reports shall not constitute or be represented as:
279.18.1(a) public authority action, public warning, emergency command, public safety order, regulatory approval, procurement approval, grant approval, public finance approval, or sovereign decision; 279.18.1(b) securities offering, investment advice, broker-dealer activity, capital placement, lending, insurance, underwriting, rating, guarantee, bankability, investability, finance-readiness, or public finance execution; 279.18.1(c) certification, accreditation, legal compliance approval, cybersecurity compliance approval, privacy compliance approval, AI safety approval, professional advice, provider qualification, or procurement qualification; or 279.18.1(d) provider preference, enterprise deployment approval, infrastructure operation, national company execution, Project SPV execution, managed security service, commercial AI service, or operational command.
279.18.2 Where outputs may be misread as execution, the Corporation shall apply limitation language, restrict access, re-scope the output, correct public claims, or decline publication.
279.19 Data, AI, Cybersecurity, and Verifiable Compute Governance Records.
279.19.1 The Corporation shall maintain Data, AI, Cybersecurity, and Verifiable Compute Governance Records, including data governance records, privacy records, AI governance records, cybersecurity records, verifiable compute records, verifiable intelligence records, controlled-room records, public authority data protection records, rights-bearing data records, health-sensitive data records, cyber-sensitive and infrastructure-sensitive data records, protected knowledge records, public-safe publication support records, evidence integrity support records, research integrity support records, public-good technical asset records, incident response records, non-execution boundary records, corrections, supersessions, withdrawals, and archive records.
Section 280. Data Governance Program
280.1 Data Governance Program Requirement.
280.1.1 The Corporation shall maintain a Data Governance Program proportionate to its size, risk profile, data classes, research activities, public authority interfaces, public-good technical assets, AI use, cyber exposure, controlled rooms, publications, cross-border activities, community safeguards, protected knowledge obligations, and institutional maturity.
280.1.2 The Data Governance Program shall govern data inventory, data classification, data stewardship roles, lawful basis, authority, permission, consent, notice, access control, use limitation, data quality, minimization, retention, deletion, sharing, publication, AI use, security, incident response, correction, and records.
280.1.3 The Data Governance Program shall apply to all directors, officers, employees, contractors, fellows, advisors, volunteers, committee members, researchers, technical contributors, reviewers, collaborators, vendors, providers, sponsors, public authority participants, and other persons with access to Corporation data.
280.2 Board Oversight.
280.2.1 The Board shall oversee the Data Governance Program at the level of mission alignment, legal compliance, risk appetite, public-benefit purpose, fiscal capacity, public authority trust, privacy, cybersecurity, AI governance, protected knowledge, safeguards, and institutional accountability.
280.2.2 Board oversight may include approval of data governance policies, risk thresholds, sensitive-data categories, AI-use restrictions, controlled-room rules, incident escalation thresholds, public-safe publication principles, and records-retention frameworks.
280.2.3 The Board may delegate implementation oversight to a committee, officer, data governance body, security body, research integrity body, or other competent authority, provided that delegation is recorded and does not eliminate Board accountability for material governance failures.
280.3 Officer Responsibility.
280.3.1 Officers designated by the Board or policy shall be responsible for implementing the Data Governance Program within delegated authority.
280.3.2 Officer responsibilities may include maintaining inventories, approving data classifications, overseeing access controls, coordinating privacy review, coordinating AI governance, coordinating cybersecurity, maintaining controlled rooms, ensuring records retention, managing incidents, and reporting material risks to the Board.
280.3.3 Officers shall not authorize data use, AI processing, access, publication, sharing, deletion, or transfer inconsistent with law, restriction, public authority obligations, protected knowledge duties, safeguards, or this Bylaw.
280.4 Data Governance Policy.
280.4.1 The Corporation shall adopt and maintain one or more data governance policies or equivalent recorded controls addressing data lifecycle, classification, access, stewardship, lawful basis, permissions, consent, notice, sharing, publication, AI use, retention, deletion, correction, incident response, and controlled-room use.
280.4.2 Data governance policies shall be reviewed periodically and updated when law, technology, data classes, public authority interfaces, AI tools, cybersecurity risk, research activities, safeguards, or institutional operations materially change.
280.4.3 Policy exceptions shall require recorded approval, risk assessment, mitigation, expiry or review date, and correction path.
280.5 Data Inventory.
280.5.1 The Corporation shall maintain a Data Inventory identifying material datasets, records collections, evidence repositories, research datasets, public authority data, personal information, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, protected knowledge, model records, inference records, telemetry streams, logs, dashboards, maps, software repositories, and technical asset data.
280.5.2 The Data Inventory shall identify, where applicable, source, owner, custodian, purpose, data class, location, system, format, access class, lawful basis, permissions, restrictions, retention, deletion, AI-use status, public-safe status, and correction path.
280.6 Data Register.
280.6.1 The Corporation shall maintain a Data Register or equivalent structured record for material data assets.
280.6.2 The Data Register shall support governance, auditability, access control, public-safe publication, research integrity, privacy compliance, AI governance, cybersecurity, data rights, protected knowledge handling, and correctionability.
280.6.3 Data Register entries shall be updated when data is received, created, transformed, reclassified, shared, published, restricted, corrected, superseded, archived, deleted, or affected by an incident.
280.7 Processing Register.
280.7.1 The Corporation shall maintain a Processing Register or equivalent record identifying material processing activities, including collection, receipt, storage, analysis, transformation, AI processing, sharing, publication, retention, deletion, transfer, and archival.
280.7.2 The Processing Register shall identify purpose, lawful basis or authority, data categories, data subjects or rights-bearing persons where applicable, recipients, systems, processors, cross-border transfers, AI tools, security controls, retention, public-safe status, and risk assessments where applicable.
280.8 Data Stewardship Roles.
280.8.1 The Corporation shall define data stewardship roles sufficient to manage data responsibly throughout the data lifecycle.
280.8.2 Data stewardship roles may include Data Owner, Data Custodian, Data Processor, Data User, Data Contributor, reviewer, approver, privacy lead, security lead, AI governance lead, public authority data lead, protected knowledge lead, and controlled-room custodian.
280.8.3 Data stewardship roles shall be recorded and shall not create authority beyond the applicable delegation, policy, contract, access control, or law.
280.9 Data Owner.
280.9.1 A Data Owner is the authorized person, role, committee, or body responsible for determining the business, research, evidence, public-good, or institutional purpose of a data asset and approving its use within applicable authority.
280.9.2 The Data Owner shall ensure that data use aligns with lawful basis, permission, purpose limitation, classification, access controls, retention, public-safe publication status, and correction obligations.
280.9.3 Data Owner status does not create personal ownership, private control, publication veto, public authority authority, finance-readiness authority, certification authority, recognition authority, or procurement authority.
280.10 Data Custodian.
280.10.1 A Data Custodian is the authorized person, role, system owner, or function responsible for operational custody, storage, security, access control, backup, retention, deletion, logging, archival, and technical integrity of a data asset.
280.10.2 The Data Custodian shall maintain access records, security controls, system records, version records, correction records, and incident records as appropriate.
280.10.3 Custody shall not confer authority to use, publish, share, train on, commercialize, or disclose data beyond approved purpose and permission.
280.11 Data Processor.
280.11.1 A Data Processor is a person or entity that processes data on behalf of the Corporation or under the Corporation’s instructions, including vendors, service providers, cloud providers, AI providers, software providers, contractors, consultants, and technical processors.
280.11.2 Data Processors shall be governed by written or recorded terms appropriate to data class and risk, including confidentiality, security, permitted use, prohibited use, sub-processing, breach notice, retention, deletion, audit, no-sale, no-unauthorized-use, no-unauthorized-AI-training, and return or deletion obligations.
280.11.3 No Data Processor shall use Corporation data for its own purposes unless separately authorized by lawful agreement, data rights, public-safe review, and competent approval.
280.12 Data User.
280.12.1 A Data User is any person authorized to access or use data for a defined purpose.
280.12.2 Data Users shall comply with access limits, purpose limits, confidentiality, privacy, AI-use restrictions, public authority restrictions, protected knowledge restrictions, cyber controls, publication controls, and correction obligations.
280.12.3 Data Users shall not copy, export, upload, train on, disclose, publish, share, or reuse data outside authorized purpose.
280.13 Data Contributor.
280.13.1 A Data Contributor is any person, entity, system, public authority, community participant, provider, sponsor, researcher, collaborator, sensor, repository, model, or other source contributing data to the Corporation.
280.13.2 Data Contributor records shall identify contributor identity where lawful and appropriate, contributor capacity, authority, permissions, restrictions, source context, data rights, attribution status, public-safe status, and correction path.
280.13.3 Contribution of data shall not itself create ownership transfer, publication permission, AI-training permission, public authority action, recognition, finance-readiness, certification, procurement approval, provider preference, or endorsement.
280.14 Data Subject or Rights-Bearing Person Where Applicable.
280.14.1 A Data Subject or rights-bearing person includes a person whose personal information, sensitive personal information, health-sensitive data, education data, youth data, biometric data, geolocation data, public authority-related data, civil rights-related data, or other rights-bearing data is collected, used, stored, analyzed, inferred, shared, published, or otherwise processed by the Corporation.
280.14.2 Where applicable law or policy gives such persons rights of access, correction, deletion, restriction, objection, portability, appeal, complaint, consent withdrawal, or other rights, the Corporation shall maintain pathways to receive and process such requests.
280.15 Data Source Authority.
280.15.1 Data Source Authority means the legal, contractual, institutional, public authority, community, Tribal / Indigenous, contributor, license, consent, research, or other authority under which data is provided to or used by the Corporation.
280.15.2 Data Source Authority shall be recorded for material datasets and sensitive data classes.
280.15.3 Where source authority is uncertain, the Corporation shall restrict, hold, quarantine, clarify, delete, return, or decline use pending review.
280.16 Data Lifecycle Governance.
280.16.1 Data Lifecycle Governance shall govern collection, receipt, creation, ingestion, classification, storage, transformation, analysis, AI processing, review, sharing, publication, retention, correction, restriction, archival, deletion, and secure disposal.
280.16.2 Each lifecycle stage shall be governed by purpose limitation, data minimization, access control, security, permission, data quality, public-safe status, safeguards, and correctionability.
280.17 Data Quality Governance.
280.17.1 Data Quality Governance shall address completeness, accuracy, timeliness, consistency, validity, reliability, representativeness, bias, missingness, duplication, transformation history, source authority, and fitness for purpose.
280.17.2 Data of insufficient quality shall be labeled, corrected, supplemented, restricted, excluded, or used only with limitations appropriate to the intended purpose.
280.18 Data Minimization.
280.18.1 The Corporation shall collect, receive, process, retain, publish, and share only data reasonably necessary for lawful, public-benefit, mission-aligned, and approved purposes.
280.18.2 Data minimization shall apply to research design, evidence intake, AI processing, public authority learning, controlled-room access, public-safe publication, datasets, dashboards, maps, model prompts, inference records, and technical baselines.
280.18.3 Data shall not be retained merely because storage is inexpensive, AI systems may later find it useful, sponsors or providers request it, public authority participants show interest, or future unspecified research might arise.
280.19 Purpose Limitation.
280.19.1 Data shall be used only for the purpose for which it was collected, received, generated, authorized, or otherwise lawfully approved, unless reuse is reviewed and authorized under this Bylaw.
280.19.2 Purpose limitation shall prevent unauthorized reuse for AI training, model improvement, embeddings, public-safe publication, finance-readiness inputs, provider development, sponsor benefit, public authority use beyond capacity, commercial use, or external sharing.
280.20 Data Governance Records.
280.20.1 The Corporation shall maintain Data Governance Records, including data governance policies, Board oversight records, officer responsibility records, Data Inventory entries, Data Register entries, Processing Register entries, stewardship role records, Data Owner records, Data Custodian records, Data Processor records, Data User records, Data Contributor records, Data Subject or rights-bearing person records where applicable, Data Source Authority records, lifecycle governance records, data quality records, minimization records, purpose limitation records, corrections, deletions, restrictions, and archive records.
Section 281. Lawful Basis, Authority, Permission, Consent, Notice, and Use Limitation
281.1 Lawful Basis Requirement.
281.1.1 The Corporation shall not collect, receive, store, process, analyze, transform, classify, publish, share, license, train on, embed, archive, delete, or otherwise use data unless a lawful basis, authority, permission, consent where required, notice where required, or other competent basis supports the activity.
281.1.2 Lawful basis shall be determined in relation to the data class, jurisdiction, source, data subject, contributor, public authority context, research purpose, contract, consent, license, legal obligation, legitimate institutional function, public-benefit purpose, and applicable law.
281.1.3 Absence of objection, technical access, platform availability, public website availability, sponsor submission, provider submission, public authority presence, community participation, or prior informal use shall not by itself establish lawful basis.
281.2 Authority Record Requirement.
281.2.1 Material data activities shall have authority records identifying the institutional, legal, contractual, research, public authority, community, Tribal / Indigenous, license, consent, or contributor authority under which the activity occurs.
281.2.2 Authority records shall be required for public authority data, rights-bearing data, health-sensitive data, children’s or youth data where applicable, education data where applicable, cyber-sensitive data, infrastructure-sensitive data, controlled technology data, export-controlled or sanctions-sensitive data, community-protected data, and protected knowledge.
281.3 Permission Record Requirement.
281.3.1 Permission records shall identify whether the Corporation may receive, access, store, process, analyze, transform, summarize, classify, publish, share, license, embed, train on, archive, delete, or otherwise use the data.
281.3.2 Permission records shall include permitted uses, prohibited uses, restrictions, attribution terms, non-attribution terms, retention terms, deletion terms, sharing terms, publication terms, AI-use terms, no-training terms, and correction terms where applicable.
281.4 Consent Where Required.
281.4.1 Consent shall be obtained where required by law, ethics review, research protocol, contract, community safeguards, Tribal / Indigenous protocol, public authority restriction, data contributor requirement, or institutional policy.
281.4.2 Consent shall be specific enough for the data activity, informed to the extent required, voluntary, recorded, revocable where applicable, and not obtained through coercion, retaliation threat, public authority pressure, sponsor pressure, provider pressure, scholarship pressure, employment pressure, or community pressure.
281.4.3 Consent for one purpose shall not automatically permit reuse for AI training, publication, mapping, finance-readiness inputs, provider development, sponsor benefit, public authority sharing, external transfer, or commercial use.
281.5 Notice Where Required.
281.5.1 Notice shall be provided where required by law, policy, research protocol, consent process, public authority requirement, platform terms, or institutional practice.
281.5.2 Notice shall describe, as applicable, the Corporation’s identity, purpose of processing, data categories, sources, uses, recipients, AI use, retention, rights, complaint pathways, public-safe publication possibility, restrictions, and contact pathway.
281.5.3 Notice shall be accurate and shall not conceal AI processing, public authority data use, sponsor or provider involvement where material, protected knowledge implications, or publication risks.
281.6 Contractual Authority.
281.6.1 Contractual authority may support data processing where a valid contract, data-sharing agreement, research agreement, grant agreement, sponsorship agreement, vendor agreement, public authority agreement, contributor agreement, license, or other instrument grants or restricts the activity.
281.6.2 Contractual authority shall be reviewed for scope, term, permitted use, prohibited use, confidentiality, privacy, public authority restrictions, data rights, AI-use restrictions, sub-processing, cross-border transfer, publication, retention, deletion, audit, correction, and termination obligations.
281.7 Public Authority Permission.
281.7.1 Public authority permission shall be recorded where data is received from, provided to, generated with, or used in relation to public authorities.
281.7.2 Public authority permission records shall identify the public authority entity, contributor capacity, official or non-official status, data restrictions, public records implications, public-sector ethics implications, confidentiality, security, permitted uses, publication limits, and whether any public authority approval or action exists.
281.7.3 Public authority permission to receive or use data shall not imply official adoption, public warning authority, emergency command, procurement approval, regulatory approval, public finance approval, grant approval, or sovereign obligation.
281.8 Research Authority.
281.8.1 Research authority may arise from approved research protocol, ethics determination, IRB or equivalent review, public-benefit purpose, data contributor agreement, license, consent, law, or other competent record.
281.8.2 Research authority shall identify scope, data classes, participant protections, privacy protections, AI-use limits, publication limits, retention, deletion, safeguards, and correction path.
281.8.3 Research authority shall not be used to bypass privacy, public authority, protected knowledge, cyber, export-control, sanctions, or publication restrictions.
281.9 Community Permission Where Applicable.
281.9.1 Community permission shall be obtained or respected where required by law, ethics review, community safeguards, research protocol, local practice, protected knowledge requirements, or public-safe mapping review.
281.9.2 Community permission may include consent, non-consent, attribution rules, non-attribution rules, withdrawal pathways, restriction terms, grievance pathways, public-safe publication conditions, and correction rights.
281.9.3 Community participation shall not be treated as blanket permission for publication, mapping, AI processing, sponsor use, provider use, or public authority sharing.
281.10 Tribal / Indigenous Protocol Permission Where Applicable.
281.10.1 Tribal / Indigenous protocol permission shall be required where applicable for Tribal or Indigenous data, Indigenous knowledge, cultural knowledge, environmental knowledge, sacred knowledge, land-based knowledge, local knowledge, community-protected information, public-safe mapping, or other protected knowledge.
281.10.2 The Corporation shall not assume that public availability, academic publication, government possession, platform access, individual disclosure, sponsor possession, or provider access creates Tribal / Indigenous permission.
281.10.3 Where permission is uncertain, the Corporation shall apply restrictive handling until clarified by competent record.
281.11 Data Contributor Permission.
281.11.1 Data Contributor permission shall identify what data is contributed, by whom or what source, in what capacity, under what rights, for what purposes, under what restrictions, and with what correction or withdrawal pathways.
281.11.2 Data Contributor permission shall not be overread to include broader reuse, publication, AI training, public authority sharing, finance-facing use, provider development, sponsor benefit, or external sharing without review.
281.12 Dataset License Authority.
281.12.1 Dataset license authority shall be reviewed before using licensed datasets, open datasets, proprietary datasets, research datasets, public authority datasets, commercial datasets, geospatial datasets, model datasets, or community datasets.
281.12.2 License review shall assess permitted use, attribution, redistribution, derivative works, commercial use, public authority use, AI training, embeddings, model improvement, publication, restrictions, termination, and audit obligations.
281.13 Open Data Authority.
281.13.1 Open data may be used only according to its actual license, public release terms, public authority restrictions, data rights, privacy constraints, attribution requirements, and public-safe status.
281.13.2 Open availability shall not eliminate obligations relating to privacy, re-identification, protected knowledge, public authority sensitivity, cyber sensitivity, infrastructure sensitivity, export-control, sanctions, or public-safe publication.
281.14 Restricted Data Authority.
281.14.1 Restricted data shall be used only under the restrictions that govern it and only by authorized persons, for approved purposes, in approved systems, with approved safeguards.
281.14.2 Restricted data shall not be copied, exported, summarized, embedded, trained on, published, mapped, disclosed, or externally shared except as expressly authorized.
281.15 Use Limitation.
281.15.1 Data use shall be limited to approved purposes, approved users, approved systems, approved time periods, approved outputs, approved AI tools, approved publication pathways, and approved sharing pathways.
281.15.2 Use limitation shall be enforced through access controls, policy controls, workflow controls, contracts, technical controls, training, monitoring, and corrective action.
281.16 Reuse Review.
281.16.1 Reuse of data for a purpose different from the original purpose shall require review for lawful basis, permission, consent, notice, contract restrictions, data rights, public authority restrictions, privacy, AI-use restrictions, cyber risk, protected knowledge, community safeguards, ethics, public-safe publication, and correctionability.
281.16.2 Reuse review shall be documented before reuse occurs, except in emergency protective action where immediate action is necessary and subsequent review is recorded promptly.
281.17 No Unauthorized Reuse for AI Training, Fine-Tuning, Embeddings, Publication, Finance-Readiness Inputs, Provider Development, Sponsor Benefit, or External Sharing.
281.17.1 No data shall be reused for AI training, fine-tuning, embeddings, model improvement, retrieval systems, publication, finance-readiness inputs, GRA-facing inputs, provider development, sponsor benefit, donor benefit, public authority sharing, commercial use, external sharing, or enterprise-stack activity unless lawful basis, permission, data rights, public-safe status, safeguards, and competent approval support such use.
281.17.2 Unauthorized reuse shall trigger hold, deletion where appropriate, access restriction, incident review, correction of affected outputs, notification where required, and enforcement.
281.18 Lawful Basis, Permission, Consent, Notice, and Use Records.
281.18.1 The Corporation shall maintain Lawful Basis, Permission, Consent, Notice, and Use Records, including lawful basis determinations, authority records, permission records, consent records, consent withdrawal records, notice records, contractual authority records, public authority permission records, research authority records, community permission records, Tribal / Indigenous protocol permission records, Data Contributor permission records, dataset license records, open data authority records, restricted data authority records, use limitation records, reuse reviews, unauthorized reuse records, corrections, deletions, restrictions, and archive records.
Section 282. Data Classification System
282.1 Data Classification Purpose.
282.1.1 The Corporation shall maintain a Data Classification System to classify data according to public-safe status, confidentiality, rights impact, privacy sensitivity, public authority restrictions, cyber sensitivity, infrastructure sensitivity, financial sensitivity, commercial sensitivity, research sensitivity, community safeguards, protected knowledge, controlled technology, export-control, sanctions sensitivity, children’s or youth status where applicable, and permitted use.
282.1.2 Data classification shall determine access controls, storage requirements, AI-use rules, sharing limits, publication pathways, controlled-room requirements, retention, deletion, public-safe review, incident escalation, and correction obligations.
282.1.3 Classification shall be reviewed and updated when facts, law, permissions, restrictions, public authority status, data rights, sensitivity, technology, public-safe status, or safeguards change.
282.2 Public Data.
282.2.1 Public Data means data lawfully available for public access and approved for public use by the Corporation without additional access restriction.
282.2.2 Public Data shall still be reviewed for accuracy, source, license, attribution, re-identification risk, protected knowledge risk, public authority sensitivity, cyber sensitivity, infrastructure sensitivity, and public-safe context before reliance or publication.
282.2.3 Public availability shall not by itself authorize AI training, redistribution, derivative use, commercial use, or publication in a new public-safe context.
282.3 Public-Safe Data.
282.3.1 Public-Safe Data means data approved for public release or public-facing use after review for privacy, confidentiality, public authority restrictions, protected knowledge, cyber sensitivity, infrastructure sensitivity, community harm, public-safe mapping, boundary risks, and misuse risk.
282.3.2 Public-Safe Data may include redacted, aggregated, masked, delayed, summarized, generalized, or otherwise controlled data.
282.3.3 Public-Safe Data classification shall identify limitations, permitted uses, public-safe status, correction path, and whether downstream users may rely on, reproduce, or redistribute the data.
282.4 Internal Data.
282.4.1 Internal Data means data intended for ordinary internal Corporation use by authorized persons for approved purposes and not approved for public release.
282.4.2 Internal Data shall be protected from unauthorized external sharing and shall not be uploaded to unapproved AI systems, public repositories, external platforms, or public communication channels.
282.5 Confidential Data.
282.5.1 Confidential Data means data subject to confidentiality obligations, including contracts, grants, donor restrictions, sponsorship terms, employment records, personnel records, unpublished research, internal deliberations, Board materials, non-public financial information, non-public partner information, non-public public authority materials, and controlled communications.
282.5.2 Confidential Data shall be access-controlled, stored securely, shared only with authorized persons, and reviewed before AI processing, publication, external sharing, or deletion.
282.6 Restricted Data.
282.6.1 Restricted Data means data subject to heightened access, use, sharing, publication, processing, AI-use, retention, or deletion limitations due to law, contract, public authority restriction, privacy, security, protected knowledge, export-control, sanctions, ethics review, or safeguards.
282.6.2 Restricted Data may require controlled-room handling, no-download access, encryption, segmentation, logging, approval workflows, and special incident escalation.
282.7 Rights-Bearing Data.
282.7.1 Rights-Bearing Data means data whose collection, classification, inference, use, sharing, publication, or automated processing may affect the rights, access, dignity, safety, opportunity, benefits, vulnerability, reputation, participation, or legal interests of persons or communities.
282.7.2 Rights-Bearing Data shall receive heightened review for fairness, bias, civil rights, accessibility, consent, notice, privacy, non-retaliation, public-safe publication, and correction.
282.8 Personal Information.
282.8.1 Personal Information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular person or household, subject to applicable law.
282.8.2 Personal Information shall be handled according to applicable privacy obligations, notices, consents where required, access controls, retention limits, security controls, rights pathways, and breach response rules.
282.9 Sensitive Personal Information.
282.9.1 Sensitive Personal Information includes personal information that receives heightened legal, ethical, or institutional protection, including government identifiers, financial account information, precise geolocation, biometric information, health information, disability information, racial or ethnic information, religious information, union status, sexual orientation, citizenship or immigration information, children’s data, education data, vulnerability-related data, or other sensitive categories under applicable law.
282.9.2 Sensitive Personal Information shall be collected and used only where necessary, lawful, protected, purpose-limited, access-controlled, and reviewed for publication and AI-use risk.
282.10 Health-Sensitive Data.
282.10.1 Health-Sensitive Data includes health, public health, medical, clinical, behavioral health, disability, epidemiological, health-system, emergency medical, health-services, or health-adjacent information capable of affecting privacy, stigma, rights, safety, or public interpretation.
282.10.2 Health-Sensitive Data shall be handled through heightened privacy, ethics, security, consent, de-identification, public-safe publication, and public authority review where applicable.
282.11 Public Authority Data.
282.11.1 Public Authority Data means data received from, created with, relating to, or restricted by a public authority, including data from agencies, public officials, public employees, public institutions, public infrastructure operators, public health bodies, emergency management bodies, public safety bodies, utilities, public works bodies, regulators, grantors, procurement bodies, and public finance actors.
282.11.2 Public Authority Data shall be classified according to capacity, authority, public records implications, confidentiality, security, official status, permitted use, public-safe status, and publication restrictions.
282.12 Cyber-Sensitive Data.
282.12.1 Cyber-Sensitive Data includes credentials, keys, tokens, secrets, authentication records, access logs, endpoint logs, network logs, cloud logs, repository logs, incident records, vulnerability details, exploit information, security architecture, threat indicators, forensic records, and cyber-risk information.
282.12.2 Cyber-Sensitive Data shall be access-controlled, secured, logged, restricted from public release unless public-safe, and handled under incident and vulnerability protocols where applicable.
282.13 Infrastructure-Sensitive Data.
282.13.1 Infrastructure-Sensitive Data includes data relating to the location, design, operation, vulnerability, dependency, performance, outage, recovery, security, or resilience of critical infrastructure, public works, utilities, telecom, ports, transportation, energy, water, food, health, emergency, cyber-physical, or industrial systems.
282.13.2 Infrastructure-Sensitive Data shall be reviewed for public-safe mapping, national security sensitivity, cyber risk, public authority restrictions, community harm, insurance sensitivity, finance-boundary risk, and misuse risk.
282.14 Finance-Sensitive Data.
282.14.1 Finance-Sensitive Data includes non-public financial information, donor information, sponsor information, funder information, grant budgets, restricted-fund data, bank data, payment data, payroll data, reimbursement data, reserve data, contract pricing, capital-reader materials, finance-readiness-facing inputs, and financial boundary-sensitive materials.
282.14.2 Finance-Sensitive Data shall not be used to imply investment advice, finance-readiness, underwriting approval, rating, public finance approval, bankability, insurance-readiness, creditworthiness, or capital execution.
282.15 Commercially Sensitive Data.
282.15.1 Commercially Sensitive Data includes trade secrets, non-public business information, vendor information, provider documentation, pricing, roadmap information, customer information, procurement-sensitive materials, proprietary datasets, technical documentation, product information, and confidential collaboration materials.
282.15.2 Commercially Sensitive Data shall be handled according to contract, confidentiality, IP, public-safe, competition, procurement-neutrality, provider-neutrality, and conflict controls.
282.16 Research-Sensitive Data.
282.16.1 Research-Sensitive Data includes unpublished research, preliminary findings, reviewer notes, peer review records, ethics records, participant information, raw field notes, protected research materials, experimental results, incomplete datasets, disputed evidence, and materials not ready for publication.
282.16.2 Research-Sensitive Data shall be protected to preserve research integrity, confidentiality, participant protection, public-safe framing, and correctionability.
282.17 Community-Protected Data.
282.17.1 Community-Protected Data includes data provided by or relating to communities where disclosure, misuse, mapping, attribution, AI processing, re-identification, public authority sharing, sponsor use, provider use, or external sharing could create harm, stigma, retaliation, extraction, vulnerability, or loss of trust.
282.17.2 Community-Protected Data shall be governed by safeguards, consent or non-consent, attribution or non-attribution, public-safe mapping, grievance pathways, restriction, correction, and non-retaliation.
282.18 Tribal / Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge Data.
282.18.1 Tribal / Indigenous, local, territorial, cultural, environmental, sacred, ecological, land-based, vulnerability-related, and Protected Knowledge Data shall be treated as highly sensitive unless competent record determines otherwise.
282.18.2 Such data shall be governed by protocol respect, authority records, permission records, protected knowledge review, public-safe mapping controls, AI-use restrictions, attribution discipline, withdrawal or restriction pathways, and correction.
282.19 Controlled Technology Data.
282.19.1 Controlled Technology Data includes technical data, software, designs, specifications, methods, encryption information, AI models, cybersecurity tools, telecom methods, AI-RAN / O-RAN materials, DePIN or DLT materials, geospatial systems, digital twin systems, advanced manufacturing information, semiconductor information, controlled research, or other materials subject to controlled-technology review.
282.19.2 Controlled Technology Data shall be reviewed for access, nationality where lawful and required, export-control, sanctions, licensing, public release, controlled-room requirements, and technical security.
282.20 Export-Controlled or Sanctions-Sensitive Data.
282.20.1 Export-Controlled or Sanctions-Sensitive Data includes data, software, technical information, controlled technology, transaction information, end-user information, restricted-party information, jurisdiction-sensitive information, or other materials that may implicate sanctions, export-control, anti-terrorism, or national security-sensitive obligations.
282.20.2 Such data shall be held, restricted, licensed where required, denied, deleted, returned, quarantined, or otherwise controlled pending competent review.
282.21 Children’s or Youth Data Where Applicable.
282.21.1 Children’s or Youth Data includes data concerning minors, students, youth participants, school participants, youth program participants, or other protected young persons.
282.21.2 Children’s or Youth Data shall receive heightened privacy, consent, notice, ethics, safety, access, retention, deletion, publication, AI-use, and safeguards review where applicable.
282.22 Data Classification Review and Reclassification.
282.22.1 Data classification shall be reviewed at intake, before material processing, before AI use, before sharing, before publication, before controlled-room access, before cross-border transfer, before retention expiry, after correction, after challenge, after incident, and when law, facts, permissions, sensitivity, or public-safe status changes.
282.22.2 Reclassification shall be recorded, including reason, authority, prior classification, new classification, affected users, affected outputs, access changes, publication effects, and correction obligations.
282.23 Data Classification Records.
282.23.1 The Corporation shall maintain Data Classification Records, including classification rules, classification decisions, public data records, public-safe data records, internal data records, confidential data records, restricted data records, rights-bearing data records, personal information records, sensitive personal information records, health-sensitive data records, public authority data records, cyber-sensitive data records, infrastructure-sensitive data records, finance-sensitive data records, commercially sensitive data records, research-sensitive data records, community-protected data records, Tribal / Indigenous and protected knowledge data records, controlled technology records, export-control and sanctions-sensitive records, children’s or youth data records, classification reviews, reclassifications, corrections, restrictions, and archive records.
Section 283. Privacy Compliance and Rights-Bearing Data
283.1 Privacy Compliance Purpose.
283.1.1 Privacy compliance shall ensure that the Corporation collects, receives, processes, stores, analyzes, shares, publishes, deletes, restricts, and archives personal information, sensitive personal information, rights-bearing data, health-sensitive data, children’s or youth data, education data, public authority data, and community-protected data lawfully, fairly, securely, transparently, purpose-limited, and correctionably.
283.1.2 Privacy compliance shall be interpreted broadly to include legal compliance, ethical data stewardship, civil rights, accessibility, data minimization, privacy by design, privacy impact assessment, public-safe publication, AI-use controls, cross-border transfer controls, complaint pathways, and incident response.
283.2 Federal Privacy Obligations Where Applicable.
283.2.1 The Corporation shall comply with applicable federal privacy, consumer protection, health, education, communications, cybersecurity, civil rights, public authority, employment, tax, nonprofit, and sectoral requirements where they apply to the Corporation’s data activities.
283.2.2 Federal privacy review shall be conducted where data relates to health, children, education, telecommunications, financial information, biometric information, consumer protection, public authority data, grants, public-sector programs, research activities, or federally funded activity.
283.3 State Privacy Obligations Where Applicable.
283.3.1 The Corporation shall comply with applicable state privacy, consumer data protection, biometric, health data, breach notification, data security, children’s privacy, education privacy, employment privacy, charitable solicitation, public records, cybersecurity, and civil rights obligations where they apply.
283.3.2 State privacy obligations shall be reviewed in relation to the Corporation’s all-states-and-territories operating posture, events, research, public authority learning, donor and sponsor activity, contractors, employees, datasets, publications, websites, platforms, subscriptions, Academy programs, and AI use.
283.4 Territorial Privacy Obligations Where Applicable.
283.4.1 The Corporation shall review and comply with applicable privacy, data protection, public authority, health, youth, employment, breach notification, civil rights, and local legal obligations in United States territorial and insular contexts where they apply.
283.4.2 Territorial privacy review shall account for language access, infrastructure constraints, disaster contexts, public health contexts, public authority capacity, local law, federal-territorial interfaces, and public-safe publication.
283.5 Sectoral Privacy Obligations Where Applicable.
283.5.1 The Corporation shall identify and comply with sectoral privacy obligations where data relates to health, education, communications, employment, financial information, biometric information, geolocation, public authority data, public safety, emergency management, utilities, critical infrastructure, research, or other regulated sectors.
283.5.2 Sectoral privacy obligations shall be addressed before data is collected, received, processed, shared, published, used in AI systems, or transferred across jurisdictions.
283.6 Health Privacy Obligations Where Applicable.
283.6.1 Health privacy obligations shall be reviewed wherever the Corporation handles health-sensitive data, public health data, clinical data, health-system data, disability-related data, health-adjacent data, emergency medical information, epidemiological data, or vulnerable-population health information.
283.6.2 Health-sensitive processing may require consent, authorization, de-identification, ethical review, public health authority review, business associate or equivalent terms where applicable, security controls, publication restrictions, and heightened incident response.
283.6.3 Health privacy governance shall preserve the Corporation’s non-clinical, non-diagnostic, non-public-health-order, non-emergency-command role.
283.7 Children’s Data Obligations Where Applicable.
283.7.1 Children’s or youth data shall be processed only where lawful, necessary, safeguarded, consented where required, noticed where required, ethically reviewed where appropriate, and protected against profiling, exposure, retaliation, inappropriate AI use, public-safe mapping risk, and publication harm.
283.7.2 Children’s or youth data shall not be processed through AI systems, published, shared, mapped, or retained beyond approved purpose without heightened review.
283.8 Education Data Obligations Where Applicable.
283.8.1 Education data shall be governed where the Corporation works with students, fellows, schools, universities, training programs, Academy programs, workforce programs, public authority learning, or research involving education records.
283.8.2 Education data processing shall be reviewed for applicable law, institutional policy, consent, school or university restrictions, student privacy, youth safeguards, accessibility, civil rights, AI-use limits, publication limits, and retention.
283.9 Public Authority Data Privacy Obligations.
283.9.1 Public authority data involving personal information, public health data, emergency management data, public safety data, benefits data, utility data, infrastructure data, procurement data, grant data, regulatory data, or public finance data shall be processed according to public authority restrictions, applicable privacy law, public records requirements, confidentiality, security, and capacity records.
283.9.2 Public authority data shall not be repurposed for sponsor benefit, provider development, AI training, finance-readiness inputs, public release, or external sharing without competent public authority permission and Corporation review.
283.10 Cross-Border Privacy Obligations.
283.10.1 Cross-border data processing shall be reviewed for privacy, data protection, data localization, transfer restrictions, contractual safeguards, public authority restrictions, Indigenous data governance, protected knowledge, cloud location, AI processing, cybersecurity, sanctions, export-control, and public-safe publication.
283.10.2 Cross-border privacy review shall preserve the Corporation’s United States legal-seat discipline, legal separateness from GCRI Canada and other entities, no shared treasury, no agency, no partnership, no joint venture, and no uncontrolled data transfer.
283.11 Notice and Transparency.
283.11.1 The Corporation shall provide privacy notices, research notices, public authority data notices, participant notices, website notices, AI-use notices, controlled-room notices, or other notices where required or appropriate.
283.11.2 Notices shall be accurate, accessible, understandable for the intended audience, updated when material practices change, and aligned with actual data use.
283.11.3 Notice shall not be used as a substitute for consent, legal authority, ethics review, public authority permission, protected knowledge permission, or safeguards where those are required.
283.12 Consent and Choice Where Required.
283.12.1 The Corporation shall provide consent, choice, opt-in, opt-out, withdrawal, restriction, non-attribution, or similar mechanisms where required by law, ethics review, protocol, contract, public authority terms, community safeguards, or institutional policy.
283.12.2 Consent and choice mechanisms shall be accessible, not coercive, records-supported, and capable of honoring withdrawal or restriction where applicable.
283.13 Access, Correction, Deletion, Portability, Restriction, and Objection Where Applicable.
283.13.1 Where applicable law, policy, contract, research protocol, public authority requirement, or institutional commitment provides rights to access, correction, deletion, portability, restriction, objection, withdrawal, or similar rights, the Corporation shall maintain processes to receive, verify, evaluate, respond to, record, and implement such requests.
283.13.2 Rights requests may be limited where necessary to protect other persons, public authority restrictions, legal obligations, research integrity, evidence integrity, protected knowledge, cybersecurity, privilege, retention obligations, or public-safe archive obligations.
283.13.3 Denials, partial denials, delays, or limitations shall be recorded with reason and appeal or complaint pathway where applicable.
283.14 Complaint and Appeal Pathways Where Applicable.
283.14.1 The Corporation shall maintain complaint and appeal pathways where required or appropriate for privacy concerns, rights-bearing data concerns, data misuse, AI misuse, protected knowledge misuse, public authority data concerns, rights requests, access denials, correction denials, deletion denials, publication concerns, and safeguards concerns.
283.14.2 Complaint pathways shall protect good-faith complainants from retaliation and shall provide accessible channels appropriate to the affected population.
283.15 Privacy Impact Assessment Where Required or Appropriate.
283.15.1 Privacy Impact Assessment shall be conducted where required or appropriate for material processing of personal information, sensitive personal information, rights-bearing data, health-sensitive data, children’s or youth data, public authority data, community-protected data, AI-assisted processing, cross-border transfer, public-safe publication, dashboards, maps, controlled rooms, or new systems.
283.15.2 Privacy Impact Assessment shall identify purpose, lawful basis, data categories, affected persons, risks, safeguards, retention, deletion, sharing, AI use, public-safe publication, incident response, rights pathways, and residual risk.
283.16 Data Protection Impact Assessment Where Required or Appropriate.
283.16.1 Data Protection Impact Assessment or equivalent heightened assessment shall be conducted where processing presents heightened risk to rights, freedoms, dignity, safety, civil rights, accessibility, protected participation, public authority trust, community safeguards, or protected knowledge.
283.16.2 Heightened risk processing may include large-scale processing, sensitive data processing, automated processing, profiling, AI-assisted classification, public-safe mapping, cyber-sensitive processing, infrastructure-sensitive processing, health-sensitive processing, children’s data processing, cross-border transfer, or processing involving vulnerable communities.
283.16.3 Processing shall be modified, restricted, delayed, refused, or escalated where assessment identifies unacceptable residual risk.
283.17 Privacy by Design.
283.17.1 The Corporation shall apply privacy by design and privacy by default principles to systems, repositories, dashboards, maps, AI tools, controlled rooms, research protocols, public authority learning materials, publications, software, technical baselines, and data-sharing arrangements.
283.17.2 Privacy by design may include minimization, pseudonymization, aggregation, access controls, encryption, logging, deletion schedules, no-training defaults, restricted embeddings, differential access, public-safe review, role separation, and human review.
283.17.3 Privacy controls shall be integrated at design stage rather than retrofitted after collection, processing, AI use, or publication where reasonably feasible.
283.18 Privacy Compliance Records.
283.18.1 The Corporation shall maintain Privacy Compliance Records, including federal privacy reviews, state privacy reviews, territorial privacy reviews, sectoral privacy reviews, health privacy reviews, children’s data reviews, education data reviews, public authority data privacy reviews, cross-border privacy reviews, notices, consent records, choice records, access requests, correction requests, deletion requests, portability requests, restriction requests, objection requests, complaint records, appeal records, privacy impact assessments, data protection impact assessments, privacy by design records, incident records, corrections, restrictions, deletions, and archive records.
Section 284. Public Authority Data
284.1 Public Authority Data Definition.
284.1.1 Public Authority Data means any data, record, document, dataset, telemetry, image, map, dashboard material, operational information, public-sector communication, public records material, confidential public-sector material, public health material, emergency-management material, public safety material, public works material, utility material, infrastructure material, regulatory material, grant material, procurement material, public finance material, cyber material, environmental material, geospatial material, or other information received from, created with, held for, generated by, derived from, or relating to a public authority.
284.1.2 Public Authority Data includes data associated with federal, state, District of Columbia, territorial, Tribal, Indigenous governmental, local, county, municipal, metropolitan, utility, port, public health, emergency management, public safety, public works, telecom, energy, water, food, cyber, infrastructure, regulatory, grant, procurement, and public finance contexts.
284.1.3 Public Authority Data shall be treated according to its source, authority, legal status, public records status, confidentiality status, capacity record, data class, permitted use, public-safe status, publication restrictions, transfer restrictions, AI-use restrictions, and correction path.
284.2 Public Authority Data Contribution Purpose.
284.2.1 Public Authority Data may be contributed to the Corporation only for lawful public-benefit purposes, including research, evidence development, methods development, observability methods, ontology, public authority learning, public-good software, technical baselines, public-safe publication, safeguards, and Nexus-compatible evidence infrastructure.
284.2.2 Public Authority Data contribution shall not create public authority delegation, official adoption, public warning authority, emergency command, procurement approval, grant approval, regulatory approval, public finance approval, sovereign obligation, public-private partnership, recognition, finance-readiness, certification, or enterprise execution.
284.2.3 The Corporation shall not accept, use, publish, transfer, or process Public Authority Data where the authority, permission, capacity, restriction, confidentiality, or public-safe status is unclear and material to lawful handling.
284.3 Federal Public Authority Data.
284.3.1 Federal Public Authority Data shall be reviewed for applicable federal restrictions, public records considerations, confidentiality terms, grant conditions, procurement rules, government ethics rules, privacy, security, controlled unclassified information where applicable, export-control, sanctions, public health rules, cyber rules, infrastructure sensitivity, and public-safe publication constraints.
284.3.2 Federal participation or federal data contribution shall be capacity-classified and shall not be represented as federal endorsement, official adoption, regulatory approval, procurement approval, grant approval, public finance approval, public warning, emergency command, or federal decision unless supported by a separate competent federal record.
284.4 State Public Authority Data.
284.4.1 State Public Authority Data shall be reviewed according to the applicable state’s law, public records obligations, open meetings or sunshine rules where applicable, procurement rules, grant rules, privacy rules, cybersecurity rules, public health rules, emergency management rules, public-sector ethics rules, and confidentiality obligations.
284.4.2 State Public Authority Data shall not be generalized across states where state-specific law, agency structure, public records status, privacy obligation, public authority capacity, or publication restriction materially differs.
284.5 District of Columbia and Territorial Public Authority Data.
284.5.1 District of Columbia and territorial Public Authority Data shall be reviewed according to applicable District, territorial, federal-territorial, local, public authority, public records, procurement, grant, privacy, cybersecurity, public health, emergency management, civil rights, language-access, and public-safe publication obligations.
284.5.2 Territorial Public Authority Data shall be handled with attention to island, insular, disaster, infrastructure, public health, public safety, supply chain, language access, accessibility, and community context.
284.6 Tribal and Indigenous Government Data Where Lawfully and Respectfully Handled.
284.6.1 Tribal and Indigenous government data shall be handled only through lawful, respectful, authority-sensitive, protocol-aware, consent-aware, restriction-aware, and safeguards-based pathways.
284.6.2 The Corporation shall not assume that federal, state, local, academic, public authority, nonprofit, sponsor, provider, or individual possession of Tribal or Indigenous government data authorizes use, disclosure, AI processing, mapping, translation, publication, transfer, or reuse.
284.6.3 Where Tribal or Indigenous authority, consent, restriction, attribution, non-attribution, publication permission, mapping permission, AI-use permission, or withdrawal right is uncertain, the Corporation shall apply restrictive handling pending competent clarification.
284.7 Local, County, Municipal, Metropolitan, Utility, Port, Public Health, Emergency Management, Public Safety, Public Works, Telecom, Energy, Water, Food, Cyber, and Infrastructure Data.
284.7.1 Local and sectoral Public Authority Data shall be reviewed for source authority, operational sensitivity, public records status, public-safe mapping, infrastructure sensitivity, cyber sensitivity, privacy, community exposure, procurement sensitivity, utility restrictions, emergency-management restrictions, public health restrictions, and public safety implications.
284.7.2 Utility, port, telecom, energy, water, food, cyber, public works, transportation, public health, emergency management, and infrastructure data shall be classified for misuse risk, operational exposure, cyber risk, public authority restriction, and public-safe publication status before use in reports, dashboards, maps, technical baselines, public authority learning materials, or Nexus-facing materials.
284.8 Capacity Record Requirement.
284.8.1 Public Authority Data shall be accompanied by a Capacity Record where public authority involvement may affect meaning, access, restriction, publication, reliance, public records status, or public-safe interpretation.
284.8.2 Capacity Records shall identify whether the contributor or participant acts in official capacity, observer capacity, learning capacity, regulator-listening capacity, public finance reader capacity, technical staff capacity, procurement capacity, grant capacity, emergency-management capacity, public health capacity, personal capacity, advisory capacity, or another recorded capacity.
284.8.3 Absence of a Capacity Record shall require hold, restriction, clarification, non-public handling, or limitation language where public authority meaning is material.
284.9 Lawful Authority Requirement.
284.9.1 The Corporation shall not receive, process, analyze, publish, share, transfer, embed, train on, or archive Public Authority Data unless lawful authority, permission, contract, grant term, public authority instruction, research authority, data-sharing agreement, license, or other competent basis supports the activity.
284.9.2 Lawful authority shall be specific enough for the proposed use and shall not be inferred from meeting attendance, public authority interest, informal email exchange, verbal encouragement, technical access, platform access, sponsor involvement, provider involvement, or prior collaboration.
284.10 Permitted Use Record.
284.10.1 Each material Public Authority Data activity shall identify permitted uses, including research, evidence classification, methods development, observability analysis, public authority learning, public-safe publication, technical baseline support, controlled-room review, dashboard use, map use, software use, AI-assisted processing, internal review, external sharing, retention, archival, deletion, and correction.
284.10.2 Permitted use records shall be interpreted narrowly where the data is confidential, restricted, rights-bearing, cyber-sensitive, infrastructure-sensitive, health-sensitive, protected knowledge-related, procurement-sensitive, grant-sensitive, or public finance-sensitive.
284.11 Prohibited Use Record.
284.11.1 Public Authority Data records shall identify prohibited uses where applicable, including unauthorized AI training, fine-tuning, embeddings, model improvement, publication, mapping, transfer, external sharing, sponsor benefit, provider development, finance-readiness input, public authority use beyond capacity, commercial reuse, public warning, emergency command, procurement advice, investment advice, recognition, certification, or enterprise execution.
284.11.2 Prohibited uses shall be enforced through access control, contractual restrictions, technical controls, controlled-room rules, review workflows, monitoring, training, and corrective action.
284.12 Public Authority Data Classification.
284.12.1 Public Authority Data shall be classified according to confidentiality, public records status, official status, source authority, sensitivity, privacy, public authority restriction, cyber sensitivity, infrastructure sensitivity, procurement sensitivity, grant sensitivity, public finance sensitivity, health sensitivity, public-safe status, AI-use status, transfer status, retention status, and correction path.
284.12.2 Classification shall be reviewed at intake, before AI processing, before sharing, before publication, before cross-border transfer, after public authority clarification, after correction, after challenge, and after incident.
284.13 Public Authority AI-Use Restrictions.
284.13.1 Public Authority Data shall not be processed through AI systems unless the AI system is approved for the applicable data class, permitted use is recorded, no-training or equivalent restrictions are in place where required, public authority restrictions are satisfied, and human review is required for material outputs.
284.13.2 AI-use restrictions may prohibit prompt submission, model training, fine-tuning, embeddings, retrieval indexing, summarization, translation, classification, anomaly detection, external API processing, cross-border processing, or vendor model improvement.
284.13.3 AI-assisted outputs derived from Public Authority Data shall not imply official public authority interpretation, decision, approval, warning, command, procurement action, or public finance action.
284.14 Public Authority Publication Restrictions.
284.14.1 Public Authority Data shall not be published, summarized, mapped, quoted, visualized, included in dashboards, included in technical baselines, included in public-safe reports, or externally circulated unless publication authority, public-safe status, confidentiality status, public records status, privacy status, and public authority restrictions support the release.
284.14.2 Publication may require aggregation, redaction, masking, delay, controlled annex, non-attribution, limitation language, public authority capacity statement, or non-public handling.
284.15 Public Authority Transfer Restrictions.
284.15.1 Public Authority Data shall not be transferred to third parties, cross-border collaborators, vendors, AI providers, cloud providers, researchers, sponsors, providers, public authorities other than the source authority, national companies, Project SPVs, enterprise actors, GRF-facing recipients, GRA-facing recipients, or Nexus-facing recipients unless lawful authority, permitted use, data rights, security, and public-safe controls support the transfer.
284.15.2 Transfers shall be logged, access-controlled, purpose-limited, and subject to confidentiality, security, deletion, correction, and onward-transfer restrictions.
284.16 Public Records, FOIA, Sunshine, Open Meetings, Public Procurement, Grant, and Confidentiality Considerations Where Applicable.
284.16.1 Public Authority Data shall be reviewed for public records, FOIA, sunshine law, open meeting, procurement, grant, government ethics, lobbying, gifts, confidentiality, public-sector cybersecurity, public-sector privacy, public authority retention, and official-capacity implications where applicable.
284.16.2 The Corporation shall not structure records, meetings, controlled rooms, or data handling to evade lawful public-sector requirements, nor shall it expose restricted public authority information without lawful authority.
284.16.3 Public records considerations may affect recordkeeping, redaction, meeting design, controlled-room procedures, public-safe publication, public authority notices, and retention.
284.17 Public Authority Data Correction, Withdrawal, and Closeout.
284.17.1 Public Authority Data shall be corrected, restricted, superseded, withdrawn, deleted where lawful, or archived where source authority, public authority clarification, corrected records, changed restrictions, privacy issues, cyber issues, public-safe defects, or data quality defects require action.
284.17.2 Closeout shall verify final status, continuing restrictions, access revocation, retention, deletion, publication status, correction status, downstream dependency notification, and public authority notice where required.
284.18 Public Authority Data Records.
284.18.1 The Corporation shall maintain Public Authority Data Records, including definition records, contribution records, federal records, state records, District of Columbia and territorial records, Tribal and Indigenous government data records, local and sectoral data records, Capacity Records, lawful authority records, permitted use records, prohibited use records, classification records, AI-use restriction records, publication restriction records, transfer restriction records, public records / FOIA / sunshine / open meetings / procurement / grant / confidentiality reviews, correction records, withdrawal records, closeout records, and archive records.
Section 285. Health-Sensitive, Public Health, Biosecurity, Youth, and Vulnerable-Population Data
285.1 Health-Sensitive Data Purpose.
285.1.1 Health-Sensitive Data shall be governed to protect privacy, dignity, safety, public health trust, research integrity, rights-bearing persons, youth, vulnerable populations, communities, public authorities, health systems, protected knowledge, and public-safe publication.
285.1.2 Health-Sensitive Data includes health, medical, clinical, behavioral health, disability-related, public health, epidemiological, emergency medical, health-system, biosecurity, youth, vulnerable-population, health-adjacent, and health-infrastructure information capable of affecting privacy, rights, stigma, access, safety, or public interpretation.
285.2 Public Health Data.
285.2.1 Public Health Data shall be handled according to applicable public health law, privacy obligations, public authority restrictions, research ethics, de-identification requirements, public-safe publication limits, and community safeguards.
285.2.2 Public Health Data may support public-benefit research, evidence, methods, observability, public authority learning, public-good software, and technical baselines, but shall not be used by the Corporation to issue public health orders, public warnings, emergency commands, medical advice, regulatory determinations, or clinical guidance.
285.3 Biosecurity Data.
285.3.1 Biosecurity Data shall be classified for misuse risk, dual-use risk, public health sensitivity, public authority restriction, national security sensitivity, controlled technology implications, publication risk, and public-safe status.
285.3.2 Biosecurity Data shall not be published, transferred, AI-processed, or included in public-facing technical materials where doing so may increase misuse, expose vulnerability, enable harmful action, or violate law, public authority restriction, research ethics, or safeguards.
285.4 Health System Data.
285.4.1 Health System Data includes information about hospitals, clinics, public health agencies, health infrastructure, medical supply chains, workforce capacity, emergency medical systems, health-system cyber exposure, health-system resilience, and health-service continuity.
285.4.2 Health System Data shall be reviewed for privacy, infrastructure sensitivity, public authority restrictions, operational sensitivity, cyber sensitivity, public-safe mapping, emergency-management implications, and community harm.
285.5 Clinical or Medical Data Where Applicable.
285.5.1 Clinical or Medical Data shall be handled only where lawful authority, consent or authorization where required, ethics review where applicable, privacy protections, security controls, and data minimization support the activity.
285.5.2 The Corporation shall not use Clinical or Medical Data to diagnose, treat, prescribe, provide medical advice, issue clinical recommendations, determine patient care, or substitute for licensed health professionals.
285.6 Youth and Children’s Data.
285.6.1 Youth and Children’s Data shall be collected, used, AI-processed, shared, published, or retained only where lawful, necessary, consented or authorized where required, ethically reviewed where appropriate, and protected through heightened safeguards.
285.6.2 Youth and Children’s Data shall not be included in public-safe maps, dashboards, public reports, AI training, external sharing, or sponsor or provider materials without heightened review and documented public-safe justification.
285.7 Vulnerable-Population Data.
285.7.1 Vulnerable-Population Data includes data concerning persons or communities facing heightened risk due to age, disability, health status, economic insecurity, housing insecurity, immigration status, disaster exposure, environmental exposure, public safety exposure, public health exposure, discrimination, marginalization, dependency, institutionalization, or retaliation risk.
285.7.2 Vulnerable-Population Data shall receive heightened review for privacy, civil rights, accessibility, consent, public-safe publication, AI bias, stigmatization, retaliation, and community safeguards.
285.8 Public Health Emergency Context Data.
285.8.1 Public Health Emergency Context Data shall be handled with urgency-aware safeguards that preserve privacy, public authority boundaries, public-safe communication, security, and correctionability.
285.8.2 Emergency context shall not eliminate lawful basis, consent where required, data minimization, public authority restrictions, research ethics, cyber controls, protected knowledge protections, or public-safe publication review.
285.8.3 The Corporation shall not use emergency context data to issue public health orders, emergency commands, public warnings, or operational directives.
285.9 Health Privacy Review.
285.9.1 Health Privacy Review shall be required for Health-Sensitive Data, Public Health Data, Clinical or Medical Data, youth health data, vulnerable-population health data, and health-system data where privacy or re-identification risk exists.
285.9.2 Health Privacy Review shall assess lawful basis, consent or authorization where required, notice, de-identification, minimum necessary use, access controls, AI-use restrictions, sharing restrictions, retention, deletion, publication, incident response, and rights pathways.
285.10 Research Ethics Review.
285.10.1 Health-sensitive, public health, biosecurity, youth, and vulnerable-population data shall receive research ethics review where required or appropriate.
285.10.2 Ethics review shall assess risk, benefit, consent, coercion, vulnerability, privacy, stigma, discrimination, public authority pressure, emergency context, publication risk, AI use, and correction pathways.
285.11 Minimization and De-Identification.
285.11.1 Health-sensitive, youth, vulnerable-population, and public health data shall be minimized and de-identified, pseudonymized, aggregated, masked, or otherwise protected where feasible and appropriate.
285.11.2 De-identification shall be reviewed for re-identification risk, linkage risk, small-cell risk, geospatial risk, temporal risk, public authority context, community context, and AI inference risk.
285.11.3 De-identified data shall not be treated as risk-free where re-identification, linkage, stigmatization, or community exposure remains plausible.
285.12 Access Restriction.
285.12.1 Access to health-sensitive, public health, biosecurity, youth, and vulnerable-population data shall be limited to authorized persons with a documented need to know.
285.12.2 Access may require controlled-room handling, no-download access, logging, special approvals, confidentiality commitments, ethics training, security review, and periodic access review.
285.13 AI-Use Restriction.
285.13.1 Health-sensitive, youth, vulnerable-population, public health, clinical, medical, and biosecurity data shall not be processed through AI systems unless the system is approved for the data class, AI use is lawful and permitted, no-training restrictions are in place where required, and human review is required for material outputs.
285.13.2 AI use shall be reviewed for bias, hallucination, re-identification, unauthorized inference, health misinformation, clinical overclaim, public authority overclaim, and publication risk.
285.14 Publication Restriction.
285.14.1 Health-sensitive, public health, biosecurity, youth, and vulnerable-population data shall not be published except in public-safe form approved through privacy, ethics, public authority, safeguards, and publication review.
285.14.2 Publication shall not reveal personal information, small-cell information, sensitive locations, clinical information, vulnerable-population identity, biosecurity vulnerability, emergency-system weakness, or stigmatizing community information beyond lawful and approved scope.
285.15 Public-Safe Aggregation.
285.15.1 Public-safe aggregation shall be used where publication, dashboarding, mapping, or reporting of health-sensitive or vulnerable-population data could create identification, stigma, retaliation, panic, public authority confusion, or misuse risk.
285.15.2 Aggregation shall be designed to preserve meaning without exposing protected persons, communities, or sensitive systems.
285.16 No Clinical Advice, Public Health Order, Emergency Command, or Public Warning by Data Use.
285.16.1 No use of health-sensitive, public health, biosecurity, youth, vulnerable-population, clinical, medical, or health-system data shall be represented as clinical advice, medical diagnosis, public health order, emergency command, official public warning, regulatory determination, treatment instruction, public safety order, or substitute for licensed professional or public authority action.
285.16.2 Outputs shall include limitation language where necessary to prevent such reliance.
285.17 Health-Sensitive Data Incident Escalation.
285.17.1 Suspected or confirmed incidents involving health-sensitive, public health, biosecurity, youth, vulnerable-population, clinical, medical, or health-system data shall be escalated promptly.
285.17.2 Incident escalation may require access restriction, system isolation, evidence preservation, privacy review, legal review, public authority notice where required, affected-person notice where required, funder notice where required, public-safe correction, data deletion where appropriate, and recurrence prevention.
285.18 Health-Sensitive Data Records.
285.18.1 The Corporation shall maintain Health-Sensitive Data Records, including public health data records, biosecurity data records, health-system data records, clinical or medical data records where applicable, youth and children’s data records, vulnerable-population data records, public health emergency context data records, health privacy reviews, research ethics reviews, minimization records, de-identification records, access restriction records, AI-use restriction records, publication restriction records, public-safe aggregation records, non-execution limitation records, incident escalation records, corrections, deletions, restrictions, and archive records.
Section 286. Cyber-Sensitive, Infrastructure-Sensitive, Security-Sensitive, and Controlled Technology Data
286.1 Cyber-Sensitive Data Purpose.
286.1.1 Cyber-Sensitive Data shall be governed to protect systems, credentials, keys, tokens, secrets, repositories, logs, vulnerabilities, incident records, threat intelligence, AI systems, cloud environments, networks, public authority data, public-good software, technical baselines, and institutional operations from misuse, disclosure, manipulation, compromise, or exploitation.
286.1.2 Cyber-Sensitive Data shall be classified, access-controlled, logged, minimized, secured, publication-reviewed, incident-reviewed, and correctionable.
286.2 Infrastructure-Sensitive Data Purpose.
286.2.1 Infrastructure-Sensitive Data shall be governed to protect critical infrastructure, public works, utilities, telecom, energy, water, food, ports, transportation, public health systems, emergency systems, cyber-physical systems, industrial systems, satellite systems, geospatial assets, AI-RAN / O-RAN systems, digital twins, and other mission-critical systems from harm, exposure, misuse, or exploitation.
286.2.2 Infrastructure-Sensitive Data shall be reviewed for public-safe mapping, operational exposure, cyber risk, physical security risk, public authority restrictions, insurance sensitivity, finance-boundary risk, community exposure, and national security sensitivity.
286.3 Security-Sensitive Data Purpose.
286.3.1 Security-Sensitive Data includes information that could compromise confidentiality, integrity, availability, safety, resilience, access control, physical security, cyber defense, operational continuity, or public authority trust if disclosed or misused.
286.3.2 Security-Sensitive Data shall be handled under need-to-know, access restriction, secure storage, secure transmission, logging, monitoring, redaction, and incident-response controls.
286.4 Controlled Technology Data Purpose.
286.4.1 Controlled Technology Data shall be governed to comply with export-control, sanctions, controlled-technology, national security sensitivity, contractual, IP, public authority, cyber, research ethics, and public-safe publication constraints.
286.4.2 Controlled Technology Data may include technical data, software, encryption information, AI models, cybersecurity methods, telecom methods, AI-RAN / O-RAN materials, DePIN or DLT materials, geospatial systems, digital twin systems, robotics, drones, advanced manufacturing, semiconductors, industrial control systems, and other controlled or potentially controlled materials.
286.5 Vulnerability Data.
286.5.1 Vulnerability Data includes information about software, hardware, model, data, network, repository, cloud, identity, AI, cyber-physical, infrastructure, telecom, or operational weaknesses.
286.5.2 Vulnerability Data shall be handled through restricted access, secure storage, need-to-know review, coordinated disclosure where applicable, public-safe redaction, remediation tracking, and incident escalation where needed.
286.6 Exploit, Indicator, Threat-Intelligence, and Incident Data.
286.6.1 Exploit, indicator, threat-intelligence, and incident data shall be classified according to sensitivity, source, permission, reliability, operational use, public authority restrictions, legal privilege, confidentiality, and public-safe status.
286.6.2 Such data shall not be publicly released or externally transferred where release would enable harm, expose defenders, compromise investigations, violate restrictions, or weaken public authority trust.
286.7 Critical Infrastructure Location, Dependency, Configuration, and Weakness Data.
286.7.1 Data identifying critical infrastructure location, dependency, configuration, operational weakness, outage pattern, recovery capacity, degraded-mode exposure, redundancy gap, supply-chain dependency, or security gap shall receive heightened review before processing, mapping, dashboarding, publication, transfer, or AI use.
286.7.2 Public-safe treatment may require aggregation, masking, coordinate reduction, time delay, omission of technical detail, controlled annexes, no-download rooms, or non-public handling.
286.8 AI-RAN, O-RAN, Telecom, Energy, Water, Port, Utility, Public Works, Transportation, Cyber-Physical, Sensor, Robotics, Drone, Satellite, Geospatial, and Digital Twin Sensitive Data.
286.8.1 Sensitive data relating to AI-RAN, O-RAN, telecom, energy, water, ports, utilities, public works, transportation, cyber-physical systems, sensors, robotics, drones, satellites, geospatial systems, and digital twins shall be reviewed for operational exposure, cyber exposure, public authority restrictions, public-safe mapping, export-control, sanctions, provider sensitivity, community exposure, and misuse risk.
286.8.2 Such data shall not be used to certify systems, approve procurement, direct operations, issue public warnings, command emergency response, guarantee resilience, or provide regulated telecom, utility, cyber, or infrastructure determinations.
286.9 Export-Control and Sanctions Review.
286.9.1 Export-Control and Sanctions Review shall be required where data, software, technical information, models, encryption, cybersecurity methods, AI-RAN / O-RAN materials, telecom materials, geospatial materials, digital twin materials, controlled technologies, restricted parties, restricted jurisdictions, prohibited end users, or prohibited end uses may be involved.
286.9.2 Data subject to unresolved export-control or sanctions concern shall be held, restricted, quarantined, denied, deleted where appropriate, returned, licensed where required, or escalated before access, transfer, publication, AI processing, or repository release.
286.10 National Security Sensitivity Review.
286.10.1 National Security Sensitivity Review shall assess whether data may implicate defense, critical infrastructure, cyber operations, controlled technology, geospatial sensitivity, public authority security, foreign access, public safety, or other national security-sensitive considerations.
286.10.2 National Security Sensitivity Review may require counsel review, access restriction, publication delay, controlled-room handling, public authority consultation where appropriate, export-control review, sanctions review, or refusal.
286.11 Access Restriction.
286.11.1 Cyber-sensitive, infrastructure-sensitive, security-sensitive, and controlled technology data shall be access-restricted according to sensitivity, lawful authority, need-to-know, role, jurisdiction, export-control status, public authority restriction, contractual obligation, and public-safe status.
286.11.2 Access may require multi-factor authentication, privileged access controls, no-download access, secure workstation requirements, controlled-room access, logging, monitoring, and periodic review.
286.12 Need-to-Know Handling.
286.12.1 Need-to-know handling shall limit access to persons whose role, task, authority, training, and approved purpose require access.
286.12.2 Curiosity, seniority, sponsor relationship, provider relationship, public authority proximity, Board status without need, technical interest, or publication role shall not by itself establish need to know.
286.13 Secure Storage and Transmission.
286.13.1 Cyber-sensitive, infrastructure-sensitive, security-sensitive, and controlled technology data shall be stored and transmitted through secure systems appropriate to classification and risk.
286.13.2 Secure storage and transmission may require encryption, access logging, secure file transfer, repository controls, key management, segmentation, backup controls, data loss prevention, endpoint controls, and prohibition on unapproved email, messaging, personal devices, public links, or unapproved AI tools.
286.14 Public-Safe Redaction.
286.14.1 Public-safe redaction shall remove or obscure details that could enable harm, compromise systems, expose protected knowledge, reveal sensitive locations, disclose credentials, identify vulnerable persons, reveal operational weaknesses, or create public authority confusion.
286.14.2 Redaction shall preserve integrity and shall not create misleading summaries, false assurance, or false absence of risk.
286.15 Coordinated Vulnerability Disclosure Where Applicable.
286.15.1 Where the Corporation identifies or receives Vulnerability Data, it may follow coordinated vulnerability disclosure practices appropriate to the source, affected system, legal constraints, public authority context, researcher safety, confidentiality, exploitability, severity, and public-safe communication.
286.15.2 Coordinated disclosure shall not be represented as certification, managed security service, public authority cyber command, emergency command, cyber insurance determination, or legal compliance approval.
286.16 No Public Release of Sensitive Operational Weakness Without Review.
286.16.1 The Corporation shall not publicly release sensitive operational weakness, exploit detail, infrastructure dependency, cyber vulnerability, system configuration, critical location, emergency-system weakness, or other sensitive operational data without competent public-safe, legal, cyber, public authority, safeguards, and publication review.
286.16.2 Where public interest supports disclosure, the Corporation shall use the least harmful lawful form, including aggregation, redaction, controlled notice, delayed disclosure, or referral.
286.17 Cyber-Sensitive and Infrastructure-Sensitive Data Records.
286.17.1 The Corporation shall maintain Cyber-Sensitive and Infrastructure-Sensitive Data Records, including cyber-sensitive data records, infrastructure-sensitive data records, security-sensitive data records, controlled technology data records, vulnerability data records, exploit / indicator / threat-intelligence / incident data records, critical infrastructure location / dependency / configuration / weakness records, AI-RAN / O-RAN / telecom / energy / water / port / utility / public works / transportation / cyber-physical / sensor / robotics / drone / satellite / geospatial / digital twin sensitive data records, export-control reviews, sanctions reviews, national security sensitivity reviews, access restriction records, need-to-know records, secure storage and transmission records, redaction records, coordinated vulnerability disclosure records, public-release review records, corrections, restrictions, incidents, and archive records.
Section 287. Community-Protected Data, Tribal / Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, and Protected Knowledge
287.1 Community-Protected Data Purpose.
287.1.1 Community-Protected Data shall be governed to prevent extraction, exposure, stigmatization, retaliation, misattribution, cultural harm, environmental harm, public authority misuse, sponsor misuse, provider misuse, AI misuse, public-safe mapping harm, and loss of trust.
287.1.2 Community-Protected Data may include community observations, local resilience knowledge, vulnerability information, lived experience, grievance information, public health concerns, environmental information, cultural information, territorial knowledge, protected participation information, and other data whose misuse could harm a community or rights-bearing group.
287.2 Tribal Sovereignty Respect.
287.2.1 The Corporation shall respect Tribal sovereignty and shall not treat Tribal-related data or knowledge as ordinary public information merely because it is technically accessible, publicly visible, held by another government, included in an academic source, or disclosed by an individual participant.
287.2.2 Tribal-related data shall be handled through authority-sensitive, protocol-aware, permission-based, and safeguards-based pathways where applicable.
287.3 Indigenous Data Safeguards.
287.3.1 Indigenous Data shall be governed with heightened safeguards reflecting Indigenous governance, collective rights, cultural context, territorial context, knowledge stewardship, consent, non-consent, attribution, non-attribution, restriction, withdrawal, correction, and benefit considerations where applicable.
287.3.2 Indigenous Data shall not be reused for AI training, public mapping, finance-facing materials, sponsor benefit, provider development, public authority sharing, or external transfer without lawful authority and appropriate safeguards review.
287.4 Indigenous Knowledge Safeguards.
287.4.1 Indigenous Knowledge shall not be extracted, generalized, translated, summarized, embedded, trained on, mapped, published, commercialized, or transferred without lawful authority, respectful permission, protocol compliance where applicable, public-safe review, and protected knowledge safeguards.
287.4.2 Indigenous Knowledge safeguards shall apply even where the knowledge has been partially published, informally shared, observed, or referenced in public authority materials.
287.5 Local Knowledge Safeguards.
287.5.1 Local Knowledge shall be handled with respect for context, attribution, non-attribution, consent, public-safe mapping, local vulnerability, community exposure, and correction.
287.5.2 Local Knowledge shall not be generalized into universal claims, used to stigmatize communities, or converted into public authority, finance, procurement, sponsor, provider, or enterprise claims without proper review and limitation.
287.6 Territorial Knowledge Safeguards.
287.6.1 Territorial Knowledge shall be handled with attention to island, insular, border, coastal, Arctic, rural, remote, and jurisdiction-specific contexts, including language access, infrastructure dependence, environmental exposure, disaster exposure, local law, and community authority.
287.6.2 Territorial Knowledge shall not be published or mapped in a manner that exposes vulnerability, infrastructure dependency, cultural sites, ecological assets, or community risk beyond public-safe scope.
287.7 Cultural Knowledge Safeguards.
287.7.1 Cultural Knowledge shall be protected against unauthorized extraction, misattribution, decontextualization, translation harm, commercialization, AI training, public mapping, and publication without appropriate authority and safeguards.
287.7.2 Cultural Knowledge restrictions may require non-attribution, restricted access, sealed records, controlled-room review, publication refusal, or withdrawal.
287.8 Environmental Knowledge Safeguards.
287.8.1 Environmental Knowledge, including ecological, biodiversity, habitat, water, land, species, climate, and environmental vulnerability information, shall be reviewed for protected knowledge, sensitive location, community, Indigenous, public authority, environmental harm, and public-safe mapping concerns.
287.8.2 Environmental Knowledge shall not be released in a manner that enables exploitation, poaching, resource extraction, ecological harm, cultural harm, or community exposure.
287.9 Protected Knowledge Definition.
287.9.1 Protected Knowledge means knowledge, data, information, observations, practices, locations, relationships, records, or meaning that require heightened protection due to Tribal, Indigenous, local, territorial, cultural, environmental, ecological, sacred, vulnerability-related, community-protected, security, privacy, dignity, rights, or public-safe considerations.
287.9.2 Protected Knowledge may be individual, collective, institutional, community-held, place-based, relational, unpublished, partially published, orally shared, inferred, mapped, observed, or embedded in data.
287.10 Community Protocols.
287.10.1 The Corporation shall respect applicable community protocols governing consent, participation, attribution, non-attribution, mapping, publication, AI use, data sharing, correction, withdrawal, grievance, and remedy.
287.10.2 Community protocols shall be recorded where appropriate and shall not be overridden by sponsor preference, provider convenience, public authority interest, publication deadline, AI-tool capability, or institutional convenience.
287.11 Consent, Non-Consent, Attribution, Withdrawal, Restriction, and Correction Pathways.
287.11.1 Community-Protected and Protected Knowledge Data shall include pathways for consent, non-consent, attribution, non-attribution, withdrawal, restriction, correction, grievance, and remedy where applicable.
287.11.2 Withdrawal or restriction requests shall receive good-faith review and may require immediate hold, access restriction, publication withdrawal, public-safe correction, or controlled correction.
287.12 Access Restriction.
287.12.1 Community-Protected and Protected Knowledge Data shall be access-restricted according to authority, consent, sensitivity, public-safe status, safeguards, role, need-to-know, and correction requirements.
287.12.2 Access may require controlled-room handling, non-download access, non-attribution, redaction, special reviewer approval, community or Tribal review where applicable, and logging.
287.13 AI-Use Restriction.
287.13.1 Community-Protected, Tribal / Indigenous, local, territorial, cultural, environmental, and Protected Knowledge Data shall not be processed through AI systems unless lawful authority, protocol permission where applicable, consent or permission where required, protected knowledge review, data rights, public-safe status, and no-training restrictions support the use.
287.13.2 AI use shall be prohibited where it risks unauthorized extraction, semantic drift, decontextualization, re-identification, sensitive mapping, cultural harm, ecological harm, or unauthorized generalization.
287.14 Public-Safe Mapping Restriction.
287.14.1 Public-safe mapping of Community-Protected or Protected Knowledge Data shall require safeguards review before release.
287.14.2 Mapping controls may include aggregation, coordinate reduction, masking, blurring, omission, delay, non-attribution, controlled legends, no-download access, or non-public handling.
287.15 No Extraction for Sponsor, Provider, Donor, Funder, Host, Public Authority, or Institutional Convenience.
287.15.1 Community-Protected and Protected Knowledge Data shall not be collected, processed, translated, summarized, mapped, AI-processed, published, shared, or transferred for sponsor storytelling, provider development, donor reporting, funder pressure, host convenience, public authority persuasion, institutional visibility, capital-reader interest, or enterprise advantage.
287.15.2 The Corporation shall reject or re-scope activities where protected knowledge would be used as reputational, financial, procurement, public authority, or commercial leverage.
287.16 Safeguards Review Before Data Sharing, Publication, Mapping, AI Use, or External Transfer.
287.16.1 Safeguards review shall be required before sharing, publishing, mapping, AI processing, embedding, external transfer, controlled-room release, public authority sharing, sponsor sharing, provider sharing, or Nexus-facing routing of Community-Protected or Protected Knowledge Data.
287.16.2 Safeguards review shall assess authority, consent, non-consent, attribution, restriction, withdrawal, community impact, retaliation risk, public-safe status, AI risk, mapping risk, public authority risk, and correction path.
287.17 Grievance and Remedy Pathway.
287.17.1 The Corporation shall maintain grievance and remedy pathways for concerns relating to Community-Protected Data, Indigenous Data, Indigenous Knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, public-safe mapping, protected knowledge, consent, attribution, withdrawal, restriction, AI use, publication, or transfer.
287.17.2 Remedies may include access restriction, correction, withdrawal, deletion where lawful, non-attribution, apology where appropriate, public-safe clarification, controlled clarification, community review, Tribal or Indigenous review where applicable, contract remedy, staff training, or recurrence prevention.
287.18 Community-Protected and Protected Knowledge Records.
287.18.1 The Corporation shall maintain Community-Protected and Protected Knowledge Records, including purpose records, Tribal sovereignty respect records, Indigenous data safeguard records, Indigenous knowledge safeguard records, local knowledge safeguard records, territorial knowledge safeguard records, cultural knowledge safeguard records, environmental knowledge safeguard records, Protected Knowledge classifications, community protocol records, consent records, non-consent records, attribution records, withdrawal records, restriction records, correction records, access restriction records, AI-use restriction records, public-safe mapping restriction records, no-extraction records, safeguards reviews, grievance records, remedy records, deletions, withdrawals, and archive records.
Section 288. Cross-Border Data Transfers, Sovereign Data Zones, Compute-to-Data, and North America Data Interfaces
288.1 Cross-Border Transfer Purpose.
288.1.1 Cross-border transfer controls shall ensure that data, records, evidence, datasets, model outputs, inference records, compute records, public authority data, personal information, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, controlled technology, and protected knowledge are transferred, accessed, processed, or stored across jurisdictions only where lawful, authorized, secure, necessary, public-benefit aligned, and safeguarded.
288.1.2 Cross-border transfer includes physical transfer, electronic transfer, cloud storage, remote access, API access, AI processing, inference logging, embedding, repository access, controlled-room access, publication, dashboarding, model transfer, compute transfer, and personnel access from another jurisdiction.
288.2 United States Data Localization Review.
288.2.1 United States Data Localization Review shall determine whether data must or should remain within United States systems, United States legal control, United States cloud regions, United States controlled rooms, United States repositories, or United States personnel access boundaries.
288.2.2 Localization review shall consider law, contract, public authority restrictions, privacy, cyber risk, national security sensitivity, controlled technology, public-safe publication, donor or funder restrictions, data subject rights, and institutional resilience.
288.3 State and Territorial Data Localization Review.
288.3.1 State and territorial data localization review shall determine whether data is subject to state-specific, territory-specific, local, public authority, health, education, employment, public records, procurement, cybersecurity, privacy, grant, or contractual restrictions affecting location, access, storage, processing, or transfer.
288.3.2 State and territorial restrictions shall not be overridden by national convenience, cloud defaults, AI provider settings, collaborator preference, or cross-border program design.
288.4 Tribal and Indigenous Data Sovereignty Review.
288.4.1 Tribal and Indigenous Data Sovereignty Review shall be required where data concerns Tribal Nations, Indigenous governments, Indigenous communities, Indigenous Data, Indigenous Knowledge, protected knowledge, land-based knowledge, cultural knowledge, environmental knowledge, sacred knowledge, or community-protected information.
288.4.2 Review shall assess authority, protocol, consent, non-consent, attribution, restriction, localization, access, publication, AI use, mapping, transfer, withdrawal, correction, grievance, and remedy.
288.5 Canadian Interface Review.
288.5.1 Canadian Interface Review shall be required where data is transferred to, received from, accessed by, processed in, stored in, or coordinated with GCRI Canada, Canadian public authorities, Canadian institutions, Canadian communities, Canadian providers, Canadian infrastructure actors, or Canadian collaborators.
288.5.2 Canadian Interface Review shall preserve legal separateness, no shared treasury, no agency, no partnership, no joint venture, separate records, separate authority, separate liabilities, privacy compliance, public authority restrictions, Indigenous data safeguards, cross-border transfer controls, and public-safe publication limitations.
288.6 Mexico, Caribbean, Arctic, and North America Interface Review.
288.6.1 Mexico, Caribbean, Arctic, and North America Interface Review shall be required where data is transferred to, received from, accessed by, processed in, stored in, or coordinated across those interfaces.
288.6.2 Review shall address applicable law, public authority capacity, privacy, cybersecurity, controlled technology, sanctions, export-control, public health, infrastructure sensitivity, Indigenous rights, protected knowledge, language access, disaster context, environmental context, and public-safe publication.
288.7 Public Authority Cross-Border Data Review.
288.7.1 Public Authority Data shall not be transferred across borders unless the source authority, applicable law, contract, public authority permission, confidentiality, security, public records implications, and public-safe publication status permit the transfer.
288.7.2 Public authority cross-border transfer shall not imply public authority delegation, treaty action, sovereign decision, public finance approval, procurement approval, emergency command, public warning, or official adoption.
288.8 Personal Information Cross-Border Review.
288.8.1 Personal information and rights-bearing data shall receive cross-border privacy review before transfer, remote access, cloud storage, AI processing, publication, dashboarding, or external sharing across jurisdictions.
288.8.2 Review shall assess notice, consent where required, contractual safeguards, data subject rights, security, processor terms, onward transfer, localization, breach obligations, retention, deletion, and public-safe publication.
288.9 Health, Cyber, Infrastructure, Controlled Technology, and Protected Knowledge Cross-Border Review.
288.9.1 Health-sensitive, cyber-sensitive, infrastructure-sensitive, controlled technology, export-controlled, sanctions-sensitive, and protected knowledge data shall receive heightened cross-border review.
288.9.2 Cross-border transfer may be denied, restricted, localized, aggregated, redacted, processed through compute-to-data, or handled only in a sovereign data zone or restricted processing environment.
288.10 Sanctions, Export-Control, and National Security Sensitivity Review.
288.10.1 Cross-border data activity shall be screened where required or prudent for sanctions, export-control, controlled technology, restricted parties, restricted jurisdictions, prohibited end users, prohibited end uses, anti-terrorism, national security sensitivity, and public authority restrictions.
288.10.2 Unresolved sanctions, export-control, or national security sensitivity shall require hold, denial, restriction, counsel review, public authority consultation where appropriate, or termination.
288.11 Sovereign Data Zone.
288.11.1 A Sovereign Data Zone means a legally, technically, and operationally bounded environment designed to keep data within defined jurisdictional, institutional, cloud, access, processing, or control boundaries.
288.11.2 Sovereign Data Zones may be used for public authority data, sensitive personal information, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, controlled technology, protected knowledge, or cross-border data requiring localization or heightened control.
288.11.3 Use of the term Sovereign Data Zone shall not imply sovereign authority, public authority delegation, public finance approval, public warning authority, emergency command, certification, or legal compliance guarantee.
288.12 Compute-to-Data.
288.12.1 Compute-to-Data means a controlled method in which approved computation is brought to data within a restricted environment, rather than transferring the underlying data to the compute user or external system.
288.12.2 Compute-to-Data may be used to preserve privacy, localization, public authority restrictions, protected knowledge, cyber security, infrastructure sensitivity, and data rights.
288.12.3 Compute-to-Data outputs shall be reviewed before release to ensure they do not reveal restricted data, enable re-identification, expose protected knowledge, or violate export-control, sanctions, public authority, or public-safe restrictions.
288.13 No-Download Room.
288.13.1 A No-Download Room means a controlled environment in which authorized users may view, query, analyze, or review data without downloading, copying, exporting, embedding, photographing, scraping, or transferring the underlying material.
288.13.2 No-Download Rooms shall include access controls, logging, monitoring, user obligations, output review, incident reporting, and access revocation rules.
288.14 Restricted Processing Environment.
288.14.1 A Restricted Processing Environment means an approved technical, contractual, and governance environment for processing data subject to heightened restrictions.
288.14.2 Restricted Processing Environments shall define permitted users, permitted data, permitted tools, AI-use restrictions, export restrictions, network restrictions, output review, logging, monitoring, retention, deletion, and incident response.
288.15 Contractual Transfer Controls.
288.15.1 Cross-border data transfers shall be governed by contractual controls where appropriate, including confidentiality, permitted use, prohibited use, data security, AI-use restrictions, sub-processing, onward transfer, audit, breach notice, localization, deletion, return, correction, public authority restrictions, protected knowledge restrictions, and termination.
288.15.2 Contractual controls shall not be used to authorize transfer where law, public authority restriction, protected knowledge protocol, export-control, sanctions, or safeguards prohibit transfer.
288.16 Cross-Border Transfer Denial, Restriction, Redaction, Aggregation, or Re-Scoping.
288.16.1 The Corporation shall deny, restrict, redact, aggregate, localize, anonymize, pseudonymize, summarize, re-scope, or terminate cross-border transfer where lawful authority is absent, permission is unclear, residual risk is unacceptable, protected knowledge is at risk, public authority restrictions prohibit transfer, privacy risk is excessive, cyber risk is unresolved, or export-control / sanctions concerns remain.
288.16.2 Transfer denial or restriction shall be recorded with rationale and correction pathway where applicable.
288.17 Cross-Border Transfer Records.
288.17.1 The Corporation shall maintain Cross-Border Transfer Records, including transfer purpose records, United States localization reviews, state and territorial localization reviews, Tribal and Indigenous data sovereignty reviews, Canadian Interface Reviews, Mexico / Caribbean / Arctic / North America Interface Reviews, public authority cross-border reviews, personal information cross-border reviews, health / cyber / infrastructure / controlled technology / protected knowledge cross-border reviews, sanctions reviews, export-control reviews, national security sensitivity reviews, Sovereign Data Zone records, Compute-to-Data records, No-Download Room records, Restricted Processing Environment records, contractual transfer controls, transfer denials, restrictions, redactions, aggregations, re-scoping records, corrections, deletions, and archive records.
Section 289. Data Access Controls, Identity, Least Privilege, Logging, Monitoring, and Access Reviews
289.1 Access Control Purpose.
289.1.1 Access controls shall protect the Corporation’s data, records, systems, repositories, controlled rooms, AI tools, models, inference records, public-good software, technical baselines, dashboards, maps, financial systems, public authority data, rights-bearing data, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, community-protected data, protected knowledge, and confidential materials.
289.1.2 Access controls shall preserve confidentiality, integrity, availability, privacy, public authority trust, research integrity, evidence integrity, cyber resilience, least privilege, segregation of duties, public-safe publication, and correctionability.
289.2 Identity Verification.
289.2.1 Access shall be granted only to persons, roles, service accounts, systems, or processors whose identity has been verified through procedures appropriate to risk.
289.2.2 Identity verification shall be required for employees, contractors, fellows, advisors, volunteers, directors, officers, researchers, reviewers, collaborators, public authority participants, providers, vendors, controlled-room users, data processors, and system administrators.
289.2.3 Shared accounts, unidentified accounts, informal access, unverified external accounts, and personal credentials shall be prohibited for material systems unless a documented exception is approved with compensating controls.
289.3 Role-Based Access Control.
289.3.1 The Corporation shall use role-based access control where appropriate to assign access according to approved roles, responsibilities, authority, training, data class, system need, and purpose.
289.3.2 Role definitions shall be reviewed periodically to ensure that access remains aligned with current duties and does not create excessive privilege, conflict, data exposure, or segregation-of-duties failure.
289.4 Attribute-Based Access Control Where Appropriate.
289.4.1 Attribute-based access control may be used where access depends on data classification, jurisdiction, public authority capacity, export-control status, project, role, time, location, device posture, training status, conflict status, confidentiality agreement, or controlled-room eligibility.
289.4.2 Attribute-based rules shall be documented, tested, reviewed, and corrected where they create improper access or improper denial.
289.5 Least Privilege.
289.5.1 Least privilege shall require that users receive only the minimum access necessary for approved purpose, task, role, duration, and data class.
289.5.2 Least privilege shall apply to repositories, datasets, dashboards, maps, AI tools, cloud systems, financial systems, collaboration tools, controlled rooms, public authority materials, protected knowledge, and administrative systems.
289.6 Need-to-Know Access.
289.6.1 Need-to-know access shall be required for restricted, confidential, cyber-sensitive, infrastructure-sensitive, health-sensitive, rights-bearing, public authority, controlled technology, community-protected, and protected knowledge data.
289.6.2 Need to know shall be determined by approved task and authority, not curiosity, seniority, sponsor status, provider status, public authority proximity, donor status, Board status without need, or general institutional interest.
289.7 Time-Limited Access.
289.7.1 Access shall be time-limited where access is temporary, project-based, review-based, incident-based, emergency-based, controlled-room-based, contractor-based, public authority-based, or otherwise not continuing.
289.7.2 Time-limited access shall expire automatically where feasible or be reviewed before renewal.
289.8 Conditional Access.
289.8.1 Conditional access may require approved device, network, location, authentication method, training completion, confidentiality agreement, conflict disclosure, export-control clearance where applicable, controlled-room authorization, or security posture before access is granted.
289.8.2 Conditional access may be tightened or suspended during incidents, elevated threat conditions, suspected compromise, policy violations, or sensitive review periods.
289.9 Multi-Factor Authentication.
289.9.1 Multi-factor authentication shall be required for material systems, privileged accounts, repositories, cloud systems, financial systems, AI systems, controlled rooms, public authority data environments, sensitive data environments, and remote access unless a documented exception with compensating controls is approved.
289.9.2 Weak, shared, reused, or unmanaged authentication methods shall be replaced where risk warrants.
289.10 Privileged Access Management.
289.10.1 Privileged access shall be limited, documented, approved, monitored, reviewed, and revoked when no longer required.
289.10.2 Privileged users shall not use administrative privileges for ordinary work where separate non-privileged access is feasible.
289.10.3 Privileged access to public authority data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, financial systems, repositories, models, inference records, or controlled rooms shall receive heightened review.
289.11 Segregation of Duties.
289.11.1 Access controls shall preserve segregation of duties in research review, evidence classification, publication approval, financial systems, procurement, contracting, payment authorization, repository release, software deployment, model approval, data deletion, incident response, and controlled-room administration.
289.11.2 No person should have unchecked authority to create, approve, publish, delete, pay, release, classify, correct, or close records where such combination creates material integrity risk.
289.12 Access Logging.
289.12.1 Access to material systems and sensitive data shall be logged to the extent technically feasible and proportionate to risk.
289.12.2 Logs may include user identity, date, time, system, data accessed, action taken, export, download, change, deletion, administrative action, AI processing, controlled-room access, and failed access attempt.
289.12.3 Logs shall be protected against unauthorized alteration, deletion, and excessive access.
289.13 Monitoring.
289.13.1 Access activity shall be monitored proportionate to risk, including unusual access, excessive download, after-hours access, failed login patterns, privileged action, repository change, dataset export, AI-tool use, controlled-room activity, and access to protected knowledge.
289.13.2 Monitoring shall be used for security, compliance, incident detection, and integrity protection and shall not be used for retaliation, improper surveillance, discrimination, or unauthorized personnel action.
289.14 Periodic Access Review.
289.14.1 The Corporation shall conduct periodic access reviews for material systems and sensitive data environments.
289.14.2 Access reviews shall verify that users, roles, privileges, service accounts, external collaborators, public authority participants, vendors, providers, contractors, and privileged accounts remain authorized and necessary.
289.14.3 Access reviews shall result in continuation, modification, reduction, suspension, or revocation of access.
289.15 Access Revocation.
289.15.1 Access shall be revoked promptly when a person’s role ends, contract ends, project ends, authorization expires, conflict requires restriction, incident requires suspension, legal restriction applies, public authority permission ends, consent is withdrawn where applicable, or access is no longer needed.
289.15.2 Revocation shall include user accounts, service accounts, repository permissions, cloud access, AI-tool access, controlled-room access, financial system access, shared drives, collaboration tools, devices, tokens, keys, certificates, and physical access where applicable.
289.16 Emergency Access.
289.16.1 Emergency access may be granted where necessary to protect data, systems, public authority trust, public safety learning materials, cyber security, protected knowledge, financial systems, evidence integrity, or institutional continuity.
289.16.2 Emergency access shall be time-limited, logged, reviewed after use, and revoked when emergency need ends.
289.17 Break-Glass Access.
289.17.1 Break-glass access means extraordinary privileged access used only when ordinary access processes are unavailable or insufficient to address urgent risk.
289.17.2 Break-glass access shall require the highest feasible authentication, logging, notice to competent authority, post-use review, justification, and correction of any excessive access.
289.17.3 Break-glass access shall not be used to bypass lawful restrictions, access protected knowledge unnecessarily, suppress evidence, alter records, approve payments, publish materials, or avoid oversight.
289.18 Access Control Records.
289.18.1 The Corporation shall maintain Access Control Records, including access control policies, identity verification records, role-based access records, attribute-based access rules, least-privilege records, need-to-know determinations, time-limited access records, conditional access rules, multi-factor authentication records, privileged access records, segregation-of-duties records, access logs, monitoring records, periodic access reviews, access revocations, emergency access records, break-glass access records, incidents, corrections, and archive records.
Section 290. Data Quality, Accuracy, Integrity, Provenance, Versioning, and Correction
290.1 Data Quality Purpose.
290.1.1 Data quality governance shall ensure that data used, received, generated, derived, processed, classified, analyzed, published, routed, retained, deleted, archived, or relied upon by the Corporation is sufficiently accurate, complete, timely, relevant, reliable, traceable, permissioned, versioned, integrity-protected, limitation-aware, and correctionable for the purpose for which it is used.
290.1.2 Data quality shall support research integrity, evidence integrity, methods integrity, observability integrity, AI governance, verifiable compute, verifiable intelligence, public authority trust, public-safe publication, public-good technical asset stewardship, community safeguards, protected knowledge protection, and validity-by-record.
290.1.3 Data quality controls shall apply to raw data, processed data, derived data, synthetic data, datasets, documents, telemetry, logs, sensor readings, AI-RAN and O-RAN signals, DePIN records, blockchain / DLT records, cyber logs, geospatial data, Earth observation data, digital twin outputs, public authority data, community-protected data, health-sensitive data, rights-bearing data, protected knowledge, model outputs, embeddings, inference records, dashboards, maps, repositories, technical baselines, and public-safe reports.
290.2 Accuracy Review.
290.2.1 Accuracy Review shall determine whether data accurately reflects the source record, observation, measurement, statement, signal, event, system state, computation, model output, contributor input, public authority record, community input, or protected knowledge input from which it derives.
290.2.2 Accuracy Review shall include review for transcription error, extraction error, translation error, unit error, coordinate error, timestamp error, version error, metadata error, identity error, source error, classification error, calculation error, AI summarization error, model inference error, transformation error, and context error.
290.2.3 Data that is inaccurate, materially misleading, unsupported, or unverifiable for its intended use shall be corrected, restricted, labeled, excluded, superseded, withdrawn, or treated as exploratory only.
290.3 Completeness Review.
290.3.1 Completeness Review shall assess whether a dataset, data record, evidence record, log, telemetry stream, dashboard, map, model output, baseline input, or public-safe report contains the fields, source context, metadata, permissions, restrictions, timestamps, versions, quality indicators, limitations, and correction path necessary for the intended use.
290.3.2 Incomplete data shall be marked and shall not be silently completed through assumption, interpolation, AI generation, model inference, synthetic substitution, sponsor-provided supplementation, provider-provided supplementation, or public authority implication unless the method is documented, lawful, limitation-aware, and reviewed.
290.3.3 Completeness deficiencies shall be disclosed where they materially affect interpretation, public-safe publication, public authority learning, technical baselines, dashboards, maps, AI outputs, Docket inputs, Grid inputs, GRF-facing inputs, or GRA-facing inputs.
290.4 Timeliness Review.
290.4.1 Timeliness Review shall determine whether data is current enough for the intended use and whether changed facts, changed law, changed public authority status, changed technology, changed infrastructure condition, changed provider status, changed community condition, changed risk context, or superseding records affect reliability.
290.4.2 Data may be classified as current, time-bounded, stale, superseded, archived, historical, corrected, withdrawn, or restricted based on timeliness.
290.4.3 Stale data shall not be used for high-reliance public-safe publication, public authority learning, dashboards, maps, technical baselines, AI evaluation, verifiable compute outputs, or Nexus-facing materials unless age and limitations are disclosed and competent authority approves such use.
290.5 Relevance Review.
290.5.1 Relevance Review shall determine whether data is materially connected to the purpose, research question, evidence claim, method output, observability output, AI use case, technical baseline, public authority learning material, safeguards review, publication, dashboard, map, or correction matter for which it is proposed.
290.5.2 Data shall not be treated as relevant merely because it is available, voluminous, machine-readable, recently generated, visually persuasive, sponsor-submitted, provider-submitted, public authority-adjacent, ledger-recorded, AI-generated, or technically convenient.
290.5.3 Data of limited relevance may be excluded, separately labeled, used only for background context, used only for exploratory analysis, or restricted from public-safe outputs.
290.6 Integrity Review.
290.6.1 Integrity Review shall determine whether data has been preserved from unauthorized alteration, deletion, substitution, corruption, tampering, spoofing, poisoning, unauthorized enrichment, unauthorized de-identification, unauthorized re-identification, unauthorized linkage, or unauthorized AI transformation.
290.6.2 Integrity Review shall consider checksums, hashes, signatures, audit logs, repository history, access logs, custody records, system logs, change logs, validation records, source confirmations, cryptographic receipts where appropriate, and other integrity controls.
290.6.3 Data with unresolved integrity concerns shall be quarantined, access-restricted, revalidated, corrected, superseded, withdrawn, or excluded from reliance.
290.7 Provenance Review.
290.7.1 Provenance Review shall identify how data was created, collected, generated, received, extracted, transformed, processed, enriched, combined, analyzed, stored, transferred, published, corrected, superseded, withdrawn, archived, or deleted.
290.7.2 Provenance records shall identify source systems, contributors, tools, methods, AI systems where applicable, processing steps, transformation logic, versions, timestamps, custody changes, permission changes, and known limitations.
290.7.3 Data lacking sufficient provenance shall not be used for high-reliance evidence, public authority learning, public-safe publication, technical baselines, AI evaluation, or Nexus-facing inputs unless competent authority records why such use is necessary and how limitations will prevent misleading reliance.
290.8 Source Lineage Review.
290.8.1 Source Lineage Review shall preserve traceability from data to its originating source, source chain, contributor, system, sensor, public authority, community, protected knowledge source, dataset, document, model, ledger, repository, or compute environment.
290.8.2 Source lineage shall be documented sufficiently to support review, challenge, correction, supersession, withdrawal, archive, rights management, public-safe publication, and downstream dependency notification.
290.8.3 Source lineage uncertainty shall require restriction, labeling, further review, or exclusion where reliance would otherwise be misleading.
290.9 Version Control.
290.9.1 Material datasets, data records, evidence packs, schemas, data dictionaries, dashboards, maps, models, embeddings, prompts where safe, inference records, technical baselines, software, publications, and public-safe outputs shall be version-controlled where necessary to preserve integrity, reproducibility, auditability, correctionability, and technical memory.
290.9.2 Version records shall identify version number or identifier, date, custodian, author or system source where appropriate, change reason, affected fields, affected outputs, compatibility with prior versions, review status, public-safe status, and supersession relationship.
290.9.3 No person shall replace, overwrite, silently alter, relabel, or republish material data in a way that obscures prior versions, correction history, or reliance status.
290.10 Change Log.
290.10.1 The Corporation shall maintain change logs for material datasets, repositories, dashboards, maps, technical baselines, models, inference workflows, evidence records, and public-safe publications.
290.10.2 Change logs shall identify material additions, deletions, transformations, corrections, reclassifications, access changes, publication changes, AI-use changes, permission changes, restriction changes, and archive changes.
290.10.3 Change logs shall be protected from unauthorized alteration and retained according to the applicable retention schedule.
290.11 Derived Data Controls.
290.11.1 Derived Data means data created through transformation, aggregation, calculation, inference, summarization, enrichment, linkage, normalization, de-identification, pseudonymization, geospatial processing, AI processing, model output, or other processing of source data.
290.11.2 Derived Data shall retain traceability to source data, methods, transformations, permissions, restrictions, data rights, public authority conditions, protected knowledge conditions, AI-use restrictions, and correction obligations.
290.11.3 Derived Data shall not be treated as free from source restrictions merely because it has been transformed, summarized, aggregated, embedded, de-identified, or converted into model output.
290.12 Synthetic Data Controls.
290.12.1 Synthetic Data means artificially generated data intended to resemble, simulate, augment, substitute for, or test against real data.
290.12.2 Synthetic Data shall be labeled as synthetic and shall include records identifying generation method, source dependencies, model used where applicable, purpose, limitations, re-identification risk, bias risk, representativeness limits, prohibited uses, and public-safe status.
290.12.3 Synthetic Data shall not be presented as observed data, public authority data, community input, protected knowledge, verified evidence, real-world measurement, benchmark truth, public-safe fact, or operational condition.
290.12.4 Synthetic Data derived from sensitive source data shall remain subject to review for privacy leakage, protected knowledge leakage, public authority restrictions, cyber sensitivity, infrastructure sensitivity, and AI model inversion risk.
290.13 Data Labeling Controls.
290.13.1 Data Labeling Controls shall govern labels applied to data for classification, annotation, AI training, AI evaluation, evidence classification, public-safe status, confidence, uncertainty, technology category, public authority capacity, rights-bearing status, protected knowledge status, or publication use.
290.13.2 Labels shall be accurate, consistent with controlled vocabulary, versioned where material, reviewer-supported where required, and correctionable.
290.13.3 AI-assisted labeling shall be reviewed for hallucination, bias, semantic drift, protected knowledge misclassification, public authority capacity error, finance-boundary error, certification-boundary error, recognition-boundary error, procurement-boundary error, and public-safe status error.
290.14 Error Correction.
290.14.1 Data errors shall be corrected promptly when identified, including errors in values, labels, classifications, timestamps, sources, permissions, restrictions, access classes, public-safe status, AI-use status, derived data, synthetic data, maps, dashboards, model outputs, or publications.
290.14.2 Correction shall preserve prior state where necessary for historical traceability, auditability, legal compliance, public authority trust, protected knowledge duties, and technical memory.
290.14.3 Corrected data shall trigger downstream review where affected outputs, publications, dashboards, maps, repositories, AI outputs, technical baselines, public authority learning materials, Docket inputs, Grid inputs, GRF-facing inputs, or GRA-facing inputs may have relied on the erroneous data.
290.15 Supersession.
290.15.1 Data shall be superseded when a newer, corrected, more authoritative, more complete, more accurate, more current, or more appropriate record replaces or materially qualifies an earlier record.
290.15.2 Superseded data shall be marked as superseded and shall not be used as current data unless its historical status is clearly identified and such use is appropriate.
290.15.3 Supersession shall identify affected records, affected outputs, replacement records, effective date, reason, and downstream notification requirements.
290.16 Withdrawal.
290.16.1 Data shall be withdrawn from use where it is unlawful to use, improperly permissioned, materially inaccurate, unsafe, misclassified, compromised, rights-restricted, protected-knowledge-exposing, public authority-restricted, cyber-unsafe, infrastructure-unsafe, or inconsistent with this Bylaw.
290.16.2 Withdrawal may apply to source data, derived data, synthetic data, datasets, dashboards, maps, embeddings, model outputs, repositories, public-safe reports, technical baselines, or publications.
290.16.3 Withdrawal shall include access restriction, reliance status marking, downstream dependency review, public or controlled notice where required, and archive treatment.
290.17 Retraction Where Public Outputs Are Affected.
290.17.1 Where public outputs materially relied on erroneous, fabricated, falsified, improperly permissioned, restricted, unsafe, or withdrawn data, the Corporation shall consider retraction where correction or supersession is insufficient to prevent misleading reliance.
290.17.2 Retraction may apply to public-safe reports, dashboards, maps, datasets, technical baselines, software releases, model cards, system cards, benchmark cards, Academy materials, public authority learning materials, donor reports, sponsor reports, or Nexus-facing materials.
290.17.3 Retraction records shall identify reason, scope, affected outputs, replacement status, archive status, and notice requirements while protecting restricted information.
290.18 Data Quality, Integrity, and Correction Records.
290.18.1 The Corporation shall maintain Data Quality, Integrity, and Correction Records, including data quality reviews, accuracy reviews, completeness reviews, timeliness reviews, relevance reviews, integrity reviews, provenance reviews, source lineage reviews, version records, change logs, derived data records, synthetic data records, data labeling records, error correction records, supersession records, withdrawal records, retraction records, downstream dependency records, notices, restrictions, deletions, and archive records.
Section 291. Retention, Deletion, Sealing, Archival, Legal Holds, and Secure Disposal
291.1 Retention Purpose.
291.1.1 Retention governance shall ensure that Corporation data, records, research materials, evidence materials, methods, public authority data, privacy records, cyber records, AI records, model records, inference records, compute records, controlled-room records, fiscal records, governance records, technical baselines, software records, publication records, correction records, and protected knowledge records are retained for lawful, public-benefit, institutional, evidentiary, audit, tax, research, public authority, safeguards, and technical memory purposes.
291.1.2 Retention shall be balanced with data minimization, privacy, protected knowledge duties, public authority restrictions, cybersecurity, confidentiality, legal holds, correctionability, and secure disposal.
291.2 Retention Schedule.
291.2.1 The Corporation shall maintain one or more retention schedules identifying categories of records, minimum retention periods, legal requirements, contractual requirements, grant requirements, public authority requirements, research requirements, privacy requirements, deletion rules, archive rules, and secure disposal rules.
291.2.2 Retention schedules shall be reviewed periodically and updated when law, grants, contracts, public authority requirements, research obligations, privacy obligations, technology, institutional operations, or risk context changes.
291.3 Minimum Retention Requirements.
291.3.1 Minimum retention requirements shall be set for governance records, fiscal records, tax records, grant records, contract records, employment records, research records, evidence records, data records, privacy records, cybersecurity records, AI governance records, model records, controlled-room records, publication records, correction records, and incident records.
291.3.2 No record shall be deleted before the applicable minimum retention period expires unless lawful authority, applicable restriction, privacy obligation, protected knowledge duty, or competent legal review permits or requires deletion.
291.4 Contractual Retention Requirements.
291.4.1 Contractual retention requirements shall be identified and followed for contracts, data-sharing agreements, licenses, vendor agreements, AI-provider agreements, cloud agreements, public authority agreements, grants, sponsorships, research agreements, collaboration agreements, and controlled-room agreements.
291.4.2 Contractual deletion, return, audit, access, archive, confidentiality, and evidence-preservation obligations shall be reflected in retention controls.
291.5 Public Authority Retention Requirements.
291.5.1 Public Authority Data and related records shall be retained, sealed, deleted, returned, transferred, archived, or disposed of according to applicable law, public authority instructions, public records considerations, contracts, grants, confidentiality obligations, security requirements, and capacity records.
291.5.2 The Corporation shall not destroy, alter, conceal, or withhold Public Authority Data to evade lawful public records, audit, grant, procurement, investigation, or public authority requirements.
291.6 Research Retention Requirements.
291.6.1 Research records shall be retained as required by law, research ethics, IRB or equivalent determinations, grant terms, publication standards, data rights, institutional policy, correction obligations, and technical memory needs.
291.6.2 Research retention shall include protocols, ethics records, consent records, source records, datasets, evidence records, method records, reviewer notes where retained, analysis records, AI-use records, compute records, publication records, challenge records, and correction records.
291.7 Grant and Funder Retention Requirements.
291.7.1 Grant and funder records shall be retained according to grant terms, funder requirements, accounting rules, tax obligations, audit requirements, donor restrictions, public authority requirements, and Board policy.
291.7.2 Grant and funder retention shall include applications, agreements, budgets, restrictions, expenditure records, deliverables, reports, correspondence, modifications, public-safe outputs, corrections, and closeout records.
291.8 Legal Holds.
291.8.1 A Legal Hold shall suspend ordinary deletion, alteration, disposal, or destruction of records where litigation, investigation, claim, audit, regulatory inquiry, public authority inquiry, subpoena, preservation request, incident, misconduct review, or legal risk requires preservation.
291.8.2 Legal Holds shall identify scope, affected custodians, affected systems, affected data, start date, responsible authority, notice requirements, preservation steps, and release conditions.
291.8.3 No person shall delete, alter, conceal, overwrite, or destroy records subject to Legal Hold.
291.9 Regulatory Holds.
291.9.1 A Regulatory Hold shall preserve records where a regulator, public authority, grantor, auditor, tax authority, charitable solicitation authority, privacy authority, cybersecurity authority, or other competent body requires or may require preservation.
291.9.2 Regulatory Holds shall be coordinated with counsel or competent authority where appropriate and shall be recorded.
291.10 Litigation Holds.
291.10.1 A Litigation Hold shall be imposed when litigation is pending, threatened, reasonably anticipated, or otherwise requires preservation of records.
291.10.2 Litigation Holds shall preserve relevant records, including email, messaging, documents, datasets, logs, repositories, model records, inference records, dashboards, maps, financial records, governance records, contracts, and communications.
291.11 Sealing.
291.11.1 Sealing shall restrict access to records that require heightened protection due to privilege, confidentiality, investigation sensitivity, public authority restriction, protected knowledge, personal information, health-sensitive data, cyber sensitivity, infrastructure sensitivity, export-control, sanctions sensitivity, misconduct review, or legal hold.
291.11.2 Sealed records shall identify sealing authority, reason, scope, access conditions, review date, and unsealing conditions where appropriate.
291.12 Archival.
291.12.1 Archival shall preserve records for institutional memory, legal compliance, research integrity, evidence integrity, technical memory, correctionability, auditability, historical traceability, and public-benefit continuity.
291.12.2 Archived records shall be classified by current, historical, superseded, corrected, withdrawn, retracted, restricted, sealed, privileged, public-safe, internal, controlled, deleted-under-policy, or preserved-under-hold status where applicable.
291.12.3 Archived records shall not be treated as current authority unless their current status is confirmed by competent record.
291.13 Deletion.
291.13.1 Deletion shall occur where required by law, contract, consent withdrawal, rights request, public authority instruction, data minimization, retention schedule, protected knowledge restriction, ethics requirement, or competent institutional decision, provided that no Legal Hold, Regulatory Hold, Litigation Hold, audit requirement, correction obligation, or preservation duty prevents deletion.
291.13.2 Deletion shall be recorded and shall identify data deleted, authority, reason, date, method, affected systems, backups where applicable, and residual limitations.
291.13.3 Deletion shall not be used to conceal misconduct, evade review, destroy evidence, suppress unfavorable findings, avoid correction, or frustrate public authority, legal, audit, research, or safeguards obligations.
291.14 Secure Disposal.
291.14.1 Secure disposal shall ensure that records and data approved for disposal are destroyed or rendered inaccessible using methods appropriate to classification, medium, system, and sensitivity.
291.14.2 Secure disposal may include secure deletion, cryptographic erasure, physical destruction, certified disposal, repository removal, access revocation, key destruction, storage wipe, or vendor-certified destruction.
291.14.3 Secure disposal of sensitive records shall be documented and may require witness, certificate, audit trail, or vendor confirmation.
291.15 Backup and Archive Alignment.
291.15.1 Retention, deletion, sealing, archival, and disposal controls shall address backups, replicas, logs, snapshots, caches, AI embeddings, derived datasets, external processors, vendor systems, cloud storage, controlled rooms, collaboration platforms, and repository mirrors where feasible and appropriate.
291.15.2 Where immediate deletion from backup systems is not technically feasible, the Corporation shall prevent restoration into active use except in accordance with deletion restrictions, legal holds, and correction obligations.
291.16 Data Subject or Participant Deletion Requests Where Applicable.
291.16.1 Data subject, participant, contributor, community, or rights-bearing person deletion requests shall be reviewed under applicable law, consent terms, research ethics, public authority restrictions, protected knowledge protocols, retention obligations, legal holds, and institutional policy.
291.16.2 The Corporation may deny, defer, limit, or partially fulfill deletion where lawful grounds require retention, but shall record the basis and provide explanation or appeal pathway where applicable.
291.17 Protected Knowledge Disposition.
291.17.1 Protected Knowledge disposition shall be governed by consent, non-consent, withdrawal, restriction, community protocols, Tribal / Indigenous protocols, safeguards review, public-safe status, legal obligations, and institutional correction duties.
291.17.2 Protected Knowledge may require return, deletion, sealing, controlled archive, non-public retention, restricted access, non-attribution, public-safe correction, or withdrawal of downstream outputs.
291.18 Retention, Deletion, Sealing, Archival, Legal Hold, and Secure Disposal Records.
291.18.1 The Corporation shall maintain Retention, Deletion, Sealing, Archival, Legal Hold, and Secure Disposal Records, including retention schedules, minimum retention records, contractual retention records, public authority retention records, research retention records, grant and funder retention records, Legal Holds, Regulatory Holds, Litigation Holds, sealing records, archival records, deletion records, secure disposal records, backup and archive alignment records, data subject or participant deletion request records, protected knowledge disposition records, corrections, restrictions, and closeout records.
Section 292. AI Governance Program
292.1 AI Governance Program Purpose.
292.1.1 The Corporation shall maintain an AI Governance Program to ensure that AI systems are acquired, developed, configured, approved, used, monitored, evaluated, restricted, retired, and corrected in a lawful, secure, human-governed, evidence-grounded, public-benefit, bias-aware, privacy-protective, public-safe, and correctionable manner.
292.1.2 The AI Governance Program shall apply to generative AI, agentic AI, retrieval systems, embedding systems, classifiers, summarizers, transcription tools, translation tools, anomaly detectors, routing tools, model evaluation tools, autonomous or semi-autonomous workflows, AI-enabled software, AI-assisted research tools, AI-enabled cybersecurity tools, and any system that materially produces, ranks, classifies, infers, recommends, drafts, summarizes, translates, routes, detects, or evaluates information for Corporation purposes.
292.1.3 The AI Governance Program shall preserve non-execution, public authority boundary discipline, finance-boundary discipline, certification-boundary discipline, recognition-boundary discipline, procurement neutrality, provider neutrality, sponsor non-control, public-safe publication, data / AI / cyber security, protected knowledge safeguards, research integrity, evidence integrity, verifiable intelligence, and correctionability.
292.2 AI-Use Policy.
292.2.1 The Corporation shall adopt and maintain an AI-Use Policy or equivalent recorded controls governing permitted AI uses, prohibited AI uses, approved systems, approved data classes, prohibited data classes, human review, model records, inference records, data retention, no-training requirements, prompt restrictions, output review, publication controls, incident response, and enforcement.
292.2.2 The AI-Use Policy shall prohibit AI uses that bypass human judgment, fabricate evidence, generate unsupported public claims, process restricted data in unapproved systems, disclose protected knowledge, issue public authority statements, create finance-readiness claims, create certification claims, create recognition claims, create procurement recommendations, or provide regulated advice.
292.2.3 The AI-Use Policy shall be reviewed and updated when AI systems, law, data classes, research practices, public authority interfaces, cybersecurity risk, protected knowledge duties, publication risks, or institutional operations materially change.
292.3 AI System Inventory.
292.3.1 The Corporation shall maintain an AI System Inventory identifying material AI systems used, tested, procured, deployed, or approved by the Corporation.
292.3.2 The AI System Inventory shall identify system name, provider, deployment environment, owner, custodian, model family where known, approved use cases, prohibited use cases, data classes permitted, data classes prohibited, access controls, integration points, risk class, review cycle, incident history, and retirement status.
292.4 Model Register.
292.4.1 The Corporation shall maintain a Model Register for material models used in Corporation activities, including externally hosted models, internally hosted models, open-source models, proprietary models, embedding models, retrieval models, classification models, summarization models, anomaly detection models, transcription models, translation models, evaluation models, and agentic systems.
292.4.2 The Model Register shall support model governance, approved use, risk review, AI vendor review, data protection, human review, incident response, evaluation, retirement, and correction.
292.5 AI Risk Classification.
292.5.1 Each material AI use case or AI system shall be assigned an AI Risk Classification proportionate to its data class, use case, autonomy, human review, public authority relevance, rights impact, public-safe publication risk, cybersecurity risk, protected knowledge risk, research integrity impact, evidence integrity impact, and boundary risk.
292.5.2 AI Risk Classification may include low, moderate, high, restricted, prohibited, experimental, controlled-room-only, public-authority-restricted, protected-knowledge-restricted, cyber-restricted, or other approved categories.
292.5.3 Higher-risk AI uses shall require heightened approval, documentation, human review, monitoring, testing, access controls, incident escalation, and public-safe review.
292.6 AI Use Case Approval.
292.6.1 Material AI use cases shall be approved before use by competent authority under the AI Governance Program.
292.6.2 AI use case approval shall identify purpose, system, model, users, data classes, permitted inputs, prohibited inputs, permitted outputs, prohibited outputs, human review, access controls, records, retention, publication limits, privacy review, security review, protected knowledge review, public authority boundary review, finance-boundary review, certification-boundary review, recognition-boundary review, procurement-boundary review, and incident response.
292.6.3 Experimental AI uses shall be clearly labeled, bounded, access-controlled, and barred from public reliance unless separately approved.
292.7 AI System Owner.
292.7.1 Each material AI system shall have an AI System Owner responsible for institutional purpose, approved use, risk classification, compliance, monitoring, review, and retirement.
292.7.2 AI System Owner status shall not create personal ownership, unrestricted authority, publication authority, certification authority, public authority authority, finance-readiness authority, procurement authority, or recognition authority.
292.8 Model Owner.
292.8.1 Each material model in the Model Register shall have a Model Owner responsible for the model’s permitted use, risk classification, evaluation status, known limitations, incident history, and continued suitability for approved purposes.
292.8.2 The Model Owner shall ensure that model use remains aligned with data rights, AI-use restrictions, no-training terms, public-safe requirements, and human review requirements.
292.9 Model Custodian.
292.9.1 Each material model shall have a Model Custodian responsible for technical custody, access controls, configuration, deployment records, version records, inference records, monitoring records, incident records, retirement records, and archive status.
292.9.2 Model Custodians shall preserve logs and records sufficient for correction, auditability where appropriate, and incident response.
292.10 Data Steward Interface.
292.10.1 AI governance shall interface with data stewardship to ensure that data used in AI systems is lawfully sourced, properly classified, permissioned, purpose-limited, access-controlled, retention-managed, protected from unauthorized training or embedding, and public-safe where used externally.
292.10.2 Data Stewards shall be consulted where AI use involves public authority data, personal information, health-sensitive data, rights-bearing data, cyber-sensitive data, infrastructure-sensitive data, controlled technology data, community-protected data, protected knowledge, confidential data, finance-sensitive data, or research-sensitive data.
292.11 AI Vendor Review.
292.11.1 AI vendors and AI service providers shall be reviewed before material use for security, privacy, data retention, training terms, model improvement terms, inference logging, sub-processors, cross-border processing, access controls, confidentiality, auditability, incident response, deletion, export-control, sanctions, IP, public authority restrictions, and contractual controls.
292.11.2 AI vendor review shall consider whether vendor terms permit provider training, model improvement, human review by vendor personnel, retention of prompts, retention of outputs, embedding reuse, or onward transfer.
292.11.3 AI vendors shall not be approved for sensitive data classes unless contractual, technical, and governance controls are sufficient for those classes.
292.12 AI Procurement Review.
292.12.1 Procurement of AI systems shall be subject to procurement controls, contract review, data protection review, cybersecurity review, AI governance review, public authority boundary review, IP review, accessibility review, bias review, sanctions and export-control review where applicable, and provider-neutrality review.
292.12.2 AI procurement shall not create provider lock-in, unsupported dependency, hidden data transfer, unauthorized training, proprietary enclosure of public-good assets, certification implication, public authority overclaim, or procurement neutrality violation.
292.13 AI Public-Safe Review.
292.13.1 AI-assisted outputs intended for external circulation, public-safe publication, public authority learning, dashboards, maps, technical baselines, donor reports, sponsor reports, GRF-facing inputs, GRA-facing inputs, Docket inputs, Grid inputs, or Nexus-facing materials shall receive public-safe review.
292.13.2 Public-safe review shall assess accuracy, source support, hallucination risk, bias, public authority boundary, finance boundary, certification boundary, recognition boundary, procurement neutrality, provider neutrality, protected knowledge, privacy, cyber sensitivity, infrastructure sensitivity, and correction path.
292.14 AI Human Review Requirement.
292.14.1 Human review shall be required before material AI outputs are used for evidence classification, public-safe publication, public authority learning materials, technical baselines, controlled-room outputs, dashboards, maps, external reports, donor reports, sponsor reports, Docket inputs, Grid inputs, GRF-facing inputs, GRA-facing inputs, or other high-reliance purposes.
292.14.2 Human review shall verify that AI outputs are source-supported, limitation-aware, uncertainty-aware, non-hallucinated, non-fabricated, properly classified, safe for intended use, and within the Corporation’s non-executing role.
292.14.3 Human review shall not be nominal. Reviewers shall have sufficient competence, access, time, and authority to reject, revise, restrict, or escalate AI outputs.
292.15 AI Monitoring.
292.15.1 The Corporation shall monitor material AI systems and use cases proportionate to risk.
292.15.2 AI monitoring may include review of usage logs, output quality, hallucination rates, bias concerns, data leakage indicators, prompt injection risk, retrieval quality, access patterns, vendor changes, model version changes, drift, incidents, and user compliance.
292.15.3 Monitoring shall be used to protect integrity, privacy, security, safeguards, and public-safe publication, and shall not be used for improper surveillance, retaliation, discrimination, or unauthorized personnel action.
292.16 AI Incident Response.
292.16.1 AI Incident Response shall address suspected or confirmed AI-related incidents, including unauthorized data upload, unauthorized training, prompt leakage, embedding leakage, model hallucination in material output, fabricated citations, biased output, protected knowledge exposure, public authority overclaim, finance overclaim, certification overclaim, procurement overclaim, recognition overclaim, cyber compromise, model misuse, agentic misaction, or vendor incident.
292.16.2 AI Incident Response may require model-use hold, prompt review where safe, inference record review, access revocation, vendor notice, data deletion, unlearning request where available, output correction, publication withdrawal, public-safe notice, legal review, public authority notice where required, and recurrence prevention.
292.17 AI Governance Training.
292.17.1 Persons using AI systems for Corporation work shall receive training appropriate to role and risk.
292.17.2 AI governance training may address approved tools, prohibited tools, prohibited data inputs, no-training rules, hallucination risk, bias risk, confidentiality, protected knowledge, public authority data, cyber-sensitive data, human review, publication limits, prompt hygiene, incident reporting, and non-execution boundaries.
292.18 AI Governance Records.
292.18.1 The Corporation shall maintain AI Governance Records, including AI-Use Policy records, AI System Inventory entries, Model Register entries, AI Risk Classifications, AI use case approvals, AI System Owner records, Model Owner records, Model Custodian records, Data Steward interface records, AI vendor reviews, AI procurement reviews, AI public-safe reviews, human review records, monitoring records, AI incident response records, AI governance training records, corrections, restrictions, retirements, and archive records.
Section 293. Model Register, Model Records, Dataset Cards, Model Cards, System Cards, Benchmark Cards, and Evaluation Harnesses
293.1 Model Register Requirement.
293.1.1 The Corporation shall maintain a Model Register for material AI models, machine learning models, embedding models, retrieval models, classification models, summarization models, transcription models, translation models, anomaly detection models, evaluation models, simulation models, digital twin models, risk models, and other models used in Corporation activities.