For the complete documentation index, see llms.txt. This page is also available as Markdown.

VI. Security

Security, Privacy, Restricted Handling, and Controlled Rooms

89. Purpose, Constitutional Function, and Governing Rule

89.1 Purpose

89.1.1 Part VI constitutes the controlling constitutional framework of GCRI Canada for security, privacy, confidentiality, restricted handling, controlled-room operation, access discipline, protected information governance, incident response, and the lawful safeguarding of persons, evidence, systems, repositories, technical infrastructure, and rights-bearing materials within the Corporation’s mission-bearing perimeter.

89.1.2 This Part shall be interpreted as the Security, Privacy, Restricted Handling, and Controlled Rooms Part of these bylaws. Its purpose is not merely to prescribe technical safeguards or administrative precautions, but to establish the legal and institutional architecture by which GCRI Canada preserves trust, prevents harm, protects protected persons and protected information, sustains continuity of public-good infrastructure, and ensures that its evidence, records, systems, and controlled processes remain lawful, reviewable, and resistant to misuse, coercion, breach, or capture.

89.1.3 Security under this Part includes physical, digital, procedural, organizational, informational, and contextual protections. Privacy includes lawful and proportionate treatment of personal and rights-bearing data, protection against unnecessary or unsafe processing, and preservation of dignity, autonomy, and safeguarded participation. Restricted handling includes classification, controlled access, custody, minimization, and bounded disclosure of materials whose exposure would create legal, ethical, operational, or public-harm risk. Controlled rooms include formalized environments—physical, virtual, or hybrid—used for matters requiring heightened access discipline, secure deliberation, handling integrity, and constrained output.

89.1.4 Part VI exists because the Corporation’s public-good function depends on institutional trustworthiness, and institutional trustworthiness depends not only on mission and governance but on the practical ability to protect what must be protected, restrict what must be restricted, disclose only what may lawfully and safely be disclosed, and preserve the conditions under which evidence, systems, repositories, and human participation can remain secure, rights-respecting, and non-exploitative.

89.1.5 This Part therefore rejects the false distinction between “real work” and “security work,” or between “substantive mission” and “protective controls.” For GCRI Canada, protection is part of mission execution. The institution cannot credibly steward evidence, semantics, systems, repositories, or public-good infrastructure while allowing uncontrolled access, porous handling, casual disclosure, silent re-identification, insecure collaboration, or unbounded operational exposure.

89.1.6 The purpose of this Part is also preventive. It is designed not only to respond to breaches and incidents after the fact, but to embed security, privacy, and protected-handling logic into classification, architecture, access, workflows, publication, repositories, controlled-room practice, incident preparedness, cross-border handling, third-party management, and institutional decision-making from the outset.

89.1.7 This Part shall further ensure that GCRI Canada’s non-executing, public-benefit, rights-sensitive, and evidence-stewarding posture is not defeated by informal channels, over-broad access, weak identity controls, misclassified materials, unsafe vendor practices, uncontrolled repositories, or technically convenient but legally and ethically defective handling patterns.

89.1.8 No person may read this Part as a narrow cybersecurity annex, a privacy notice substitute, or an operations manual detached from constitutional meaning. It is a core institutional Part through which the Corporation preserves lawful boundedness, protected participation, continuity of stewardship, and safe operation of the public-good base layer.

89.1.9 The purposes of Part VI are, accordingly: (a) to protect persons, especially protected, vulnerable, or rights-bearing persons, from unnecessary exposure, misuse, coercion, or unsafe handling of information; (b) to protect evidence, records, repositories, systems, and technical assets from corruption, unauthorized access, misuse, loss, tampering, or silent distortion; (c) to preserve the confidentiality and integrity of restricted and controlled information; (d) to ensure lawful, proportionate, and reviewable handling of personal, sensitive, sovereign-sensitive, and rights-bearing materials; (e) to govern controlled-room and clean-room environments for high-sensitivity work; (f) to maintain trustworthy identity, access, logging, and custody discipline; (g) to preserve continuity through incident, migration, transition, and crisis conditions; and (h) to ensure that all later Parts of the bylaws operate within a security, privacy, and safeguarded-handling architecture adequate to the Corporation’s mission and risk profile.

89.1.10 This clause shall be interpreted as the purpose and constitutional identity clause for the whole of Part VI.


89.2 Relationship of Part VI to Mission Lock, Safeguards, Public-Benefit Stewardship, and Non-Execution Boundary

89.2.1 Part VI shall be interpreted under the primacy of mission lock, safeguards, public-benefit stewardship, and the non-execution boundary of GCRI Canada. No security, privacy, or handling control may be designed or applied in a manner that undermines those superior constitutional commitments, just as no mission-bearing activity may be conducted in a manner that disregards the protections established in this Part.

89.2.2 Mission lock requires that protective controls serve the Corporation’s public-benefit objects and not become independent instruments of concealment, exclusion, opacity, prestige, or arbitrary institutional power. Security and privacy shall protect lawful stewardship; they shall not become mechanisms for hiding weakness, suppressing dissent, blocking accountability, or manufacturing false authority.

89.2.3 Safeguards obligations require that the Corporation protect protected participants, contributors, communities, rights-bearing persons, whistleblowers, evidence providers, and others whose engagement with the institution may expose them to retaliation, coercion, surveillance, re-identification, or contextual harm if handling is careless or overly broad. Security and privacy are therefore not simply system concerns; they are direct instruments of harm prevention and protected participation.

89.2.4 Public-benefit stewardship requires that the Corporation preserve a proportionate balance between openness and protection. GCRI Canada is not a secrecy-maximizing institution. It is an institution that must know when to disclose, when to restrict, when to sanitize, when to localize, when to separate, and when to maintain controlled access in order to protect persons, rights, systems, and the continuity of the public-good infrastructure it stewards.

89.2.5 The non-execution boundary requires that security and privacy controls not be used to drift the Corporation into execution-layer functions, intelligence hoarding, enforcement postures, covert operational activity, unbounded surveillance, or hidden market-facing control. This Part protects governance, evidence, systems, and lawful stewardship; it does not authorize GCRI Canada to assume public-authority, police, intelligence, or licensed execution roles beyond its actual remit.

89.2.6 This relationship also works in the opposite direction: mission, stewardship, and non-execution do not excuse weak security. The Corporation may not justify loose access, uncontrolled export, unsafe cross-border handling, or casual disclosure by appealing to openness, collaboration, speed, innovation, or public-good purpose. Public-benefit duty heightens the need for disciplined handling where harm, rights exposure, or institutional compromise is reasonably foreseeable.

89.2.7 Where tension appears between transparency and protection, the Corporation shall prefer the path that best preserves: (a) lawful public accountability; (b) rights and dignity; (c) safety of persons and systems; (d) continuity and integrity of the evidence and technical infrastructure; and (e) mission-faithful public-benefit operation. Neither indiscriminate disclosure nor indiscriminate secrecy shall be presumed correct.

89.2.8 No one may invoke security, privacy, or controlled handling to create hidden substantive authority, to avoid correction or oversight, or to mask the need for clearer public-safe outputs. Equally, no one may invoke transparency or collaboration to demand access inconsistent with safeguards, rights protection, or continuity of the Corporation’s protected infrastructure.

89.2.9 This Part shall therefore be read as a mission-preserving protective architecture and not as a separate or competing logic. It supports the same constitutional order established in Parts I through V by ensuring that people, evidence, systems, repositories, and controlled processes can exist and operate safely within it.

89.2.10 This clause shall be interpreted as the governing relationship rule linking Part VI to the broader constitutional framework of the bylaws.


89.3 Security and Privacy as Constitutional Control Surfaces, Not Merely Technical Controls

89.3.1 Security and privacy shall be treated by GCRI Canada as constitutional control surfaces and not merely as technical controls, compliance checkboxes, operational afterthoughts, or delegated specialist functions.

89.3.2 A constitutional control surface for purposes of this clause is any discipline whose structure materially shapes institutional truth, permissible action, participation safety, public trust, legal boundedness, and the practical distribution of power within and around the Corporation. Security and privacy plainly meet that test. They determine who may see what, who may decide what, what may circulate, what may be retained, what may be disclosed, what may be trusted, and how harm is prevented.

89.3.3 The Corporation shall therefore reject the view that security belongs only to technical teams, that privacy belongs only to legal teams, or that handling belongs only to operations staff. These matters shape the real constitutional life of the institution and must be embedded in governance, records, publication, repository control, contributor management, cross-entity interfaces, and program design.

89.3.4 Security as a constitutional control surface includes, without limitation: (a) access architecture; (b) classification discipline; (c) custody and chain-of-custody; (d) repository and release integrity; (e) key and secret management; (f) controlled-room and clean-room practice; (g) incident escalation; and (h) continuity under disruption.

89.3.5 Privacy as a constitutional control surface includes, without limitation: (a) lawful basis and purpose limitation; (b) minimization of collection and exposure; (c) role-bounded access to rights-bearing data; (d) de-identification and pseudonymization discipline; (e) constraints on secondary use; (f) cross-border and jurisdiction-sensitive handling; (g) response to rights requests and complaints; and (h) prevention of dignity harm through careless disclosure or uncontrolled inference.

89.3.6 Because these are constitutional control surfaces, failure in security or privacy is not merely a technical defect. It may constitute a mission failure, an integrity failure, a safeguards failure, a records failure, or a public-trust failure depending on the nature and consequence of the lapse.

89.3.7 The Corporation shall also recognize that security and privacy decisions can alter institutional power. Unbounded access creates hidden influence; uncontrolled classification can suppress scrutiny; poor logging destroys accountability; weak controlled-room discipline can chill or expose protected participation; careless public release can irreversibly collapse rights-bearing context. All such effects are constitutional in nature.

89.3.8 No later policy, platform choice, workflow shortcut, or vendor architecture shall be interpreted to reduce security or privacy to optional implementation detail where the effect would be materially to distort the constitutional protections of this Part.

89.3.9 This clause shall be interpreted as the doctrinal elevation rule for security and privacy across the whole of GCRI Canada.


89.4 Protection of People, Evidence, Systems, and Public-Good Infrastructure as a Core Institutional Duty

89.4.1 GCRI Canada shall have a core institutional duty to protect people, evidence, systems, repositories, technical infrastructure, controlled environments, and other mission-critical elements entrusted to or operated by the Corporation.

89.4.2 Protection of people includes protection of staff, contributors, fellows, participants, protected disclosers, rights-bearing persons, vulnerable communities, public representatives, reviewers, custodians, and any other persons whose engagement with the Corporation may expose them to retaliation, misuse, overexposure, re-identification, coercion, targeted pressure, reputational harm, or other material risk if security, privacy, and handling controls fail.

89.4.3 Protection of evidence includes preservation of integrity, provenance, chain-of-custody, contextual meaning, admissibility for governance use, resistance to tampering, and prevention of unauthorized exposure or silent distortion. Evidence is not protected merely by being stored; it is protected when it can still be trusted, bounded, and lawfully interpreted.

89.4.4 Protection of systems includes safeguarding the Corporation’s repositories, build and release environments, identity systems, controlled collaboration spaces, logging and audit systems, key and secret material, technical baselines, and other digital or hybrid infrastructures essential to the operation of the public-good layer.

89.4.5 Protection of public-good infrastructure includes preserving the continuity, non-fragmentation, and trustworthy operation of the common technical and semantic assets the Corporation stewards, including their security against sabotage, covert alteration, hostile dependence, silent enclosure, or attack-enabled loss of public trust.

89.4.6 This duty is preventive, active, and ongoing. The Corporation shall not wait for a breach, public incident, or external challenge to recognize its protection responsibilities. It shall architect, classify, train, monitor, review, correct, and escalate in a manner proportionate to foreseeable harm and foreseeable misuse.

89.4.7 This duty also includes protecting the conditions of safe participation. A governance system is not meaningfully safe if persons with relevant information cannot contribute without fear of uncontrolled exposure, or if controlled rooms, evidence channels, and review environments are porous, informally handled, or dependent on interpersonal trust alone.

89.4.8 No person or office may dismiss protection obligations on the ground that the Corporation is not a bank, a government, a defense agency, or a critical-infrastructure operator. The relevant question is not sector label but the actual value, sensitivity, dependency, and harm potential of the people, evidence, systems, and infrastructure entrusted to the Corporation.

89.4.9 This clause shall be interpreted as the positive institutional duty from which the detailed obligations of Part VI derive.


89.5 Binding Effect of Part VI Across All Organs, Participants, Platforms, Repositories, Programs, and Cross-Entity Interfaces

89.5.1 Part VI shall bind all organs, officers, directors, committees, working groups, secretariat functions, contributors, contractors, fellows, secondees, volunteers, partners, hosts, vendors, repositories, programs, collaboration environments, publication channels, technical systems, and cross-entity interfaces operating by, through, or for GCRI Canada to the extent that they handle, access, influence, store, transmit, classify, release, or otherwise affect information, systems, evidence, or materials within the scope of this Part.

89.5.2 This binding effect applies regardless of format or medium. It governs physical records, digital records, structured data, semantic assets, repositories, source code systems, publication workflows, messages, meeting environments, controlled-room materials, logs, backups, exports, package artifacts, and all other information-bearing or access-bearing surfaces within the Corporation’s perimeter.

89.5.3 This binding effect also applies regardless of employment or organizational status. No one is exempt from Part VI because they are external, senior, temporary, prestigious, highly trusted, technically privileged, donor-linked, or public-facing. If they handle or influence covered materials or systems, they are subject to this Part within the scope of that handling or influence.

89.5.4 Cross-entity interfaces with GRF, GRA, Protocol Authority, national entities, regional entities, hosts, governments, public authorities, academic institutions, or technical partners shall remain governed by Part VI to the extent that GCRI Canada’s own duties of security, privacy, restricted handling, or controlled-room discipline are engaged. Another entity’s controls do not displace GCRI’s own obligations unless and to the extent a lawful and adequate interface arrangement expressly provides a compatible mechanism.

89.5.5 No repository practice, platform default, partner agreement, host arrangement, collaboration custom, or tool choice may be treated as outside the reach of Part VI merely because it is operational, distributed, technically externalized, or historically inherited. Governance follows the handling and risk reality of the asset or process, not the convenience of the platform.

89.5.6 Where ambiguity exists concerning whether a person, platform, repository, program, or interface falls within the scope of Part VI, the Corporation shall presume that it does where the matter involves protected information, controlled handling, personal data, repository authority, evidence integrity, cross-border processing, or security-sensitive infrastructure.

89.5.7 This clause shall be interpreted as the universal application rule for Part VI and as the closing clause of Section 89.

90. Core Security, Privacy, and Handling Principles

90.1 Confidentiality, Integrity, Availability, and Auditability as Baseline Principles

90.1.1 GCRI Canada shall adopt confidentiality, integrity, availability, and auditability as baseline principles governing all information, systems, repositories, evidence artifacts, communication channels, controlled environments, technical assets, and protected-handling activities within the scope of Part VI.

90.1.2 Confidentiality means that information, systems, and materials shall be visible, knowable, and accessible only to those persons, roles, systems, or counterparties lawfully and operationally entitled to such access within the bounds of mission, rights, handling classification, and recorded authority. Confidentiality is not secrecy for its own sake; it is the disciplined prevention of unnecessary, unsafe, or unlawful exposure.

90.1.3 Integrity means that records, evidence, repositories, controlled outputs, technical assets, classifications, identities, and system states shall remain accurate, attributable, authentic, tamper-evident where appropriate, and resistant to unauthorized alteration, corruption, substitution, silent downgrade, or contextual distortion. Integrity also requires that authorized change remain traceable and reviewable rather than informal or opaque.

90.1.4 Availability means that systems, repositories, evidence, and protected materials shall remain accessible, recoverable, and usable by authorized actors when required for lawful institutional function, continuity, safety, incident response, review, correction, and stewardship. Availability does not mean unrestricted access; it means reliable access for those with lawful and recorded need.

90.1.5 Auditability means that the Corporation shall preserve enough records, logs, metadata, custody trace, access trace, review trace, and system observability to determine what happened, what existed, who accessed what, who changed what, what authority supported the action, and how later verification or correction may occur. Auditability is indispensable to accountability and correctionability.

90.1.6 These four principles are mutually reinforcing and shall not be applied in isolation. Confidentiality without integrity can protect falsehood. Integrity without availability can immobilize lawful stewardship. Availability without confidentiality can expose rights-bearing persons and protected systems. Auditability without meaningful control becomes retrospective theater.

90.1.7 The Corporation shall not privilege one of these principles to the total destruction of the others absent a lawful, proportionate, and recorded basis requiring temporary priority. In ordinary governance, the correct design posture is balanced sufficiency rather than absolutist singular optimization.

90.1.8 These baseline principles apply to physical and digital environments alike, to controlled rooms and ordinary working environments, to public-good and restricted assets, to human and machine-mediated handling, and to internal and cross-entity interfaces.

90.1.9 No team, vendor, partner, or internal function may characterize these principles as merely “IT objectives.” They are constitutional operating requirements of the Corporation’s protective architecture.

90.1.10 This clause shall be interpreted as the baseline doctrinal foundation for all later operational requirements in Part VI.


90.2 Least-Privilege, Need-to-Know, and Minimum Exposure Rule

90.2.1 GCRI Canada shall apply least-privilege, need-to-know, and minimum exposure as controlling principles for access, handling, storage, transmission, review, collaboration, and system design.

90.2.2 Least-privilege means that each person, role, system account, automation, vendor function, or collaborator shall receive only the minimum permissions, visibility, and operational capability necessary to perform its lawful and recorded function. No broader entitlement shall be created merely because broader access is convenient, historically inherited, socially expected, or technically easy to grant.

90.2.3 Need-to-know means that access to restricted, sensitive, confidential, controlled-room, rights-bearing, or otherwise protected materials shall be granted only where the person or system has a specific, current, and legitimate necessity tied to institutional duties or governed participation. General relevance, curiosity, prestige, general oversight desire, or associative involvement shall not satisfy this standard.

90.2.4 Minimum exposure means that even where access is lawfully permitted, the Corporation shall reduce the volume, duration, precision, identifiability, transportability, and onward circulation of the information or asset exposed to what is actually necessary. The correct question is not merely “who may see this” but also “how much of it, in what form, for how long, in what environment, and with what onward-use restrictions.”

90.2.5 These principles apply equally to human-readable materials, structured data, metadata, logs, schemas, dashboards, repositories, derivative summaries, meeting participation, transcripts, evidence packets, and system interfaces. They also apply to machine and service accounts, integration tokens, AI-enabled tooling, and automated retrieval layers.

90.2.6 No person may rely on role seniority, institutional trust, donor significance, committee status, board prominence, or technical centrality as grounds to bypass least-privilege or need-to-know. High status may increase responsibility; it does not automatically increase entitlement.

90.2.7 Where uncertainty exists as to the proper scope of access or disclosure, the Corporation shall resolve the issue toward the narrower and safer exposure posture until a stronger access basis is affirmatively established and recorded.

90.2.8 This principle also governs publication and external communication. Public-safe disclosure shall expose only what must be disclosed to satisfy lawful transparency, mission purpose, or public explanation, and not the full sensitive substrate where such disclosure would exceed necessity.

90.2.9 The Corporation shall treat repeated or structurally broad access grants as a governance signal requiring review, not as a sign of efficiency. Widespread visibility often means silent failure of the access architecture.

90.2.10 This clause shall be interpreted as the principal minimization rule for all handling and access decisions under Part VI.


90.3 Proportionality and Context-Sensitive Protection Requirements

90.3.1 GCRI Canada shall apply proportionality and context-sensitive protection to all security, privacy, classification, handling, access, and disclosure decisions under this Part.

90.3.2 Proportionality means that protective measures shall be calibrated to the actual sensitivity, consequence, threat profile, legal obligation, dependency value, and human-risk profile of the material, system, environment, or activity concerned. The Corporation shall neither under-protect high-risk assets nor overburden ordinary activity with unnecessary friction that weakens governability without materially improving safety.

90.3.3 Context-sensitive protection means that the same item, system, or class of information may require different handling depending on context, including jurisdiction, timing, participant mix, surrounding evidence, public salience, threat conditions, sovereign sensitivity, or whether the material is being used in research, governance, controlled-room deliberation, external collaboration, or public communication.

90.3.4 No one may apply a flat and context-blind security or privacy rule where the effect would be either unsafe looseness or dysfunctional rigidity. What is appropriate for an internal draft may be inappropriate for a whistleblower disclosure; what is safe in a closed review may be unsafe in a public repository; what may be shareable in de-identified form may be prohibited in raw form.

90.3.5 Proportionality does not authorize minimization of controls merely because work is urgent or politically important. Nor does it authorize maximal restriction merely because an asset is important. It requires a reasoned match between control strength and actual risk.

90.3.6 Context-sensitive protection also requires attention to the position of affected persons. Materials relating to vulnerable individuals, protected communities, public authorities, sovereignty-sensitive contexts, or active incidents may require stronger controls than technically similar materials in ordinary contexts.

90.3.7 The Corporation shall preserve documentation sufficient to show that material protection decisions were made on a reasoned and reviewable basis and not merely by habit, instinct, or overbroad default.

90.3.8 Where the correct level of protection is uncertain and the downside of under-protection is materially significant, the Corporation shall use the more protective interim posture pending review, while avoiding unnecessary permanence of temporary over-classification.

90.3.9 This clause shall be interpreted as the calibration rule for the whole of Part VI.


90.4 Security-by-Design, Privacy-by-Design, and Safeguards-by-Design

90.4.1 GCRI Canada shall require security-by-design, privacy-by-design, and safeguards-by-design across its systems, workflows, repositories, tools, programs, evidence architectures, technical baselines, collaboration environments, publication processes, and controlled-handling environments.

90.4.2 Security-by-design means that systems and processes shall be structured from the outset to reduce attack surface, prevent unauthorized access, preserve integrity, support logging, support containment, and minimize recoverable harm if failure occurs. Security shall not be deferred to last-stage patching or appended as a decorative review layer after core architecture is already fixed.

90.4.3 Privacy-by-design means that personal and rights-bearing data shall be minimized, segmented, appropriately de-identified where possible, protected by purpose limitation, bounded by role and context, and prevented from unnecessary replication, export, aggregation, or cross-context reuse by architectural means rather than by goodwill alone.

90.4.4 Safeguards-by-design means that systems and workflows shall be intentionally structured to protect protected participants, sensitive disclosures, whistleblowers, vulnerable communities, community- or sovereignty-sensitive information, and high-risk evidentiary material through built-in handling rules, access boundaries, sanitization pathways, and escalation logic.

90.4.5 No system or workflow shall be considered compliant merely because its operators promise to behave carefully. The architecture itself must narrow unsafe behavior, log material actions, preserve controlled states, and support proportionate response. Human trust may supplement design; it shall not replace it.

90.4.6 This clause applies to procurement, vendor integration, system development, workflow configuration, repository architecture, controlled-room infrastructure, public release tooling, incident handling, and AI-assisted or automated processing environments.

90.4.7 The Corporation shall reject the pattern in which mission teams move quickly and “security cleans up later.” In GCRI Canada, design choices are stewardship choices and must embody protective obligations from inception.

90.4.8 Where legacy systems or inherited practices do not meet design-based expectations, the Corporation shall apply compensating controls and migrate toward compliant design rather than normalizing the inherited weakness.

90.4.9 This clause shall be interpreted as the embedding rule for protective obligations across the whole institutional stack.


90.5 No Informal Access, No Unlogged Handling, and No Governance Through Uncontrolled Channels

90.5.1 GCRI Canada shall prohibit informal access, unlogged handling of material protected assets, and governance-bearing activity through uncontrolled channels.

90.5.2 Informal access means any access to protected materials, systems, repositories, environments, identities, keys, controlled-room outputs, or rights-bearing data that occurs outside the authorized identity, access, approval, logging, or handling framework of the Corporation.

90.5.3 Unlogged handling means any material viewing, transfer, export, copy, controlled disclosure, repository modification, badge issuance, release action, custody movement, or equivalent action taken without the traceability necessary to preserve accountability, correctionability, and later reconstruction.

90.5.4 Governance through uncontrolled channels includes, without limitation, use of personal email, informal consumer messaging, private cloud folders, unmanaged drives, unsanctioned chat groups, unapproved AI tools, unlogged file-transfer services, informal physical circulation, or undocumented side channels to process matters that properly belong within governed institutional systems.

90.5.5 No urgency, convenience, travel condition, trust relationship, partner expectation, or technical frustration shall justify migration of protected handling into uncontrolled channels absent a recorded emergency exception under the applicable deviation rules of the bylaws.

90.5.6 No one may argue that a channel is acceptable merely because it is encrypted, popular, temporary, or familiar. The question is whether it is governed, approvable, loggable, retrievable, and compatible with the Corporation’s duties of security, privacy, handling, and official record discipline.

90.5.7 Where a material protected matter has already been handled through an uncontrolled channel, the Corporation shall treat that fact as a governance incident requiring containment, regularization, or remediation rather than as a trivial convenience lapse.

90.5.8 This clause shall be interpreted as the no-shadow-handling rule for all protected institutional work.


90.6 Protection of Human Subjects, Protected Participants, and Rights-Bearing Data as a Priority Over Convenience

90.6.1 In all activities governed by Part VI, GCRI Canada shall prioritize the protection of human subjects, protected participants, vulnerable persons, rights-bearing data, community-sensitive information, and safeguarded disclosures over convenience, speed, rhetorical transparency, institutional appetite, partner demand, or technical elegance.

90.6.2 This priority applies whenever a handling, access, publication, analysis, transfer, aggregation, retention, or sharing decision could materially affect the dignity, safety, autonomy, confidentiality, re-identifiability, or exposure risk of a person or protected group.

90.6.3 No project value, scientific interest, public curiosity, collaboration pressure, or donor expectation shall by itself justify broader exposure of rights-bearing data or protected participation than is necessary and lawful.

90.6.4 Where the Corporation must choose between richer internal convenience and narrower protection of a protected person or rights-bearing dataset, the narrower protective posture shall prevail unless a clearly recorded and lawful reason demonstrates that a different route is necessary and proportionate.

90.6.5 This priority does not prohibit research, evidence work, publication, or structured review; it requires that such activities be designed and conducted in ways that preserve protected handling, minimization, contextual integrity, and safe-publication boundaries.

90.6.6 The Corporation shall also recognize that harm may arise not only from direct disclosure but from contextual inference, linkage, metadata visibility, timing signals, identity-pattern exposure, or reuse in settings removed from the original protective context. Protection must therefore be substantive and not formalistic.

90.6.7 This clause shall be interpreted as the human-protection priority rule for all privacy and safeguarded-handling decisions under Part VI.


90.7 No Relaxation of Controls by Urgency, Status, Seniority, or External Pressure Without Recorded Authority

90.7.1 No security, privacy, classification, access, controlled-room, retention, export, or handling control established under Part VI may be relaxed, overridden, narrowed, or bypassed on the basis of urgency, institutional status, seniority, public pressure, donor pressure, political pressure, technical prestige, or partner insistence absent recorded authority and lawful grounds under the exception architecture of these bylaws.

90.7.2 Seniority does not create handling privilege. Visibility does not create disclosure entitlement. Strategic importance does not erase need-to-know. External pressure does not create lawful basis for broader exposure.

90.7.3 Where time-sensitive action is genuinely required, the Corporation may use bounded emergency or exception pathways; however, those pathways must remain documented, narrowly tailored, temporary, and reviewable. The existence of urgency strengthens the need for traceability; it does not eliminate it.

90.7.4 No person shall use phrases such as “just this once,” “executive need,” “board visibility,” “government interest,” “partner urgency,” or “reputational necessity” as substitutes for an actual authority basis.

90.7.5 If control relaxation occurs under recorded emergency authority, the Corporation shall preserve: (a) the reason for relaxation; (b) the control altered; (c) the duration and scope of the alteration; (d) the authority that approved it; and (e) the pathway back to ordinary compliant handling.

90.7.6 Any recurring demand for control relaxation by senior or external actors shall be treated as a governance signal requiring review, because repeated exception pressure may indicate attempted capture, design inadequacy, or cultural drift away from the protective constitution of this Part.

90.7.7 This clause shall be interpreted as the anti-pressure and anti-status-exception rule for all protective controls under Part VI.


90.8 Most-Protective Reading Where Harm, Exposure, or Misuse Risk Is Material or Uncertain

90.8.1 Where material doubt, uncertainty, or unresolved risk exists concerning the possible harm, exposure, misuse potential, legal sensitivity, rights impact, or institutional consequence of disclosure, access, handling, export, retention, or release, GCRI Canada shall adopt the most protective reading reasonably compatible with law, mission, and later review.

90.8.2 The most-protective reading under this clause means the interpretation or interim handling posture that best preserves: (a) safety of persons and protected participants; (b) confidentiality of restricted or controlled materials; (c) integrity and trustworthiness of evidence and systems; (d) lawful compliance with privacy, confidentiality, and rights obligations; (e) continuity of public-good infrastructure; and (f) the possibility of later lawful disclosure, decontrol, or narrowing once the uncertainty is resolved.

90.8.3 This rule shall not be used to justify indefinite over-classification, permanent secrecy by inertia, or blanket refusal to create public-safe outputs. Its purpose is to guide interim and ambiguous cases where under-protection could create serious or irreversible harm before fuller review occurs.

90.8.4 When the more protective posture is adopted under uncertainty, the Corporation shall record the reason, assign review responsibility, and revisit the classification or handling decision within a period proportionate to the significance of the matter. Temporary caution shall not become unreviewed permanence.

90.8.5 No one may insist on the less protective reading merely because the harm is hard to quantify, the actors are trusted, the asset is technically complex, or the disclosure would be institutionally convenient. Where material harm is plausible and not yet resolved, caution is constitutionally preferred.

90.8.6 This clause shall be interpreted as the closing interpretive safeguard of Section 90 and as the guiding presumption for difficult security, privacy, and handling decisions throughout Part VI.

91. Security Classification and Handling Principles

91.1 Institutional Information Classification Framework

91.1.1 GCRI Canada shall maintain one institutional information classification framework governing the identification, marking, handling, access, transfer, retention, publication posture, controlled-room treatment, and decontrol of information, materials, records, repositories, technical artifacts, and derivative outputs falling within the scope of Part VI.

91.1.2 The classification framework shall be records-valid, role-bound, reviewable, and integrated with the official record, repository, publication, access-control, and incident-management architecture of the Corporation. It shall not exist as an isolated security manual detached from actual institutional workflows.

91.1.3 The purpose of the framework is to ensure that information is not handled by instinct, prestige, habit, or ad hoc judgment, but according to a governed and intelligible structure that aligns protection strength to actual risk, legal duty, rights sensitivity, public-good stewardship, and continuity requirements.

91.1.4 The framework shall apply to information regardless of medium, including physical documents, digital files, repositories, datasets, communications, meeting artifacts, logs, metadata, visual materials, exports, prints, recordings, transcriptions, summaries, screenshots, and machine-readable outputs.

91.1.5 Classification under this framework shall determine, as appropriate: (a) who may access the information; (b) what handling controls apply; (c) whether controlled-room or clean-room treatment is required; (d) whether public or stakeholder release is permissible; (e) what transfer, export, or localization controls apply; (f) what retention and disposal rules govern; and (g) what escalation or incident obligations apply if the information is mishandled.

91.1.6 No information of material consequence shall be handled outside the classification framework merely because it is technically new, informally produced, socially circulated, or operationally awkward to classify. Novelty does not exempt protected matter from governance.

91.1.7 The framework shall be sufficiently structured to support consistent treatment across the Corporation while remaining flexible enough to account for context, rights posture, evolving risk, and lawful review.

91.1.8 No office, platform, vendor, or program may substitute its own incompatible ad hoc classification scheme for the institutional framework without recorded authority and explicit compatibility rules.

91.1.9 This clause shall be interpreted as the foundational classification-architecture rule for all protected handling under Part VI.


91.2 Categories of Protected Information in Scope

91.2.1 The classification framework shall apply to all protected information categories within the mission-bearing and governance-bearing perimeter of GCRI Canada, whether internally generated, externally received, jointly handled, or technically derived.

91.2.2 Protected information in scope includes, without limitation: (a) personal information and rights-bearing data; (b) sovereign-sensitive, public-authority-sensitive, and jurisdiction-sensitive information; (c) Indigenous, community-sensitive, and vulnerability-sensitive information; (d) whistleblower materials, protected disclosures, and retaliation-sensitive content; (e) investigation materials, legal-privilege materials, and litigation-hold content; (f) credentials, secrets, keys, tokens, and identity artifacts; (g) security-sensitive technical materials and infrastructure details; (h) controlled evidence and custody-governed governance artifacts; (i) sensitive research, model, or abuse-prone technical material; (j) third-party confidential information and contract-protected materials; (k) controlled-room and clean-room materials; and (l) any derivative, summary, metadata, log, or transformed state of the foregoing that preserves or materially reveals the protected content.

91.2.3 Protected information may arise by content, by context, by origin, by legal duty, by linkage, or by practical consequence. It need not bear a formal external label to fall within scope if the actual handling risk is material.

91.2.4 The framework shall also recognize that a low-sensitivity item, when combined with other information, may become protected by linkage, inference, triangulation, or contextual aggregation. Classification shall not be blind to combinational risk.

91.2.5 No person may argue that a material falls outside protected scope merely because it is derivative, decontextualized, operational, or “only metadata” where that derivative state still reveals or enables misuse of the protected underlying matter.

91.2.6 This clause shall be interpreted as the broad coverage rule ensuring that protection follows actual risk-bearing information and not only obvious categories.


91.3 Public, Restricted, Sensitive, Confidential, and Controlled-Room Classes

91.3.1 GCRI Canada shall maintain a structured set of information classes sufficient to distinguish between information that is safely public and information requiring progressively stronger control.

91.3.2 Without limiting the Corporation’s ability to refine class names or sub-classes through controlled policy, the primary institutional classes shall include: (a) Public; (b) Restricted; (c) Sensitive; (d) Confidential; and (e) Controlled-Room.

91.3.3 Public information is information approved for open release or general distribution and suitable for broad internal and external access consistent with public-truthfulness, publication rules, and any remaining attribution or mark restrictions. Public classification does not waive provenance, authenticity, or correctionability duties.

91.3.4 Restricted information is information not suitable for general public circulation and not available by default to all internal participants, but which may be handled within bounded internal or stakeholder channels under ordinary governed access conditions. Restricted treatment applies where unnecessary exposure would create moderate legal, operational, rights, or reputational risk.

91.3.5 Sensitive information is information requiring heightened access discipline, more tightly bounded need-to-know logic, stronger handling conditions, and more deliberate transfer, derivative, and collaboration constraints because exposure could materially affect persons, systems, repositories, evidence integrity, public trust, or lawful institutional operation.

91.3.6 Confidential information is information requiring strong restrictions on access, copying, transfer, derivative production, and communication because disclosure or misuse would create serious harm, rights breach, legal exposure, security compromise, or institutional distortion. Confidential treatment ordinarily requires tighter logging, narrower visibility, and stronger environment controls.

91.3.7 Controlled-Room information is information or matter requiring handling within a formal controlled-room environment or equivalent highly bounded process because the combination of sensitivity, legal obligation, rights impact, competition sensitivity, evidence integrity, public consequence, or abuse potential makes ordinary handling insufficient. Controlled-Room classification is not merely a higher secrecy level; it is an environment-dependent handling state.

91.3.8 The Corporation may define sub-classes, overlays, or handling modifiers, provided they remain compatible with the primary classes and do not obscure their basic meaning.

91.3.9 No one may improvise intermediate labels, rhetorical substitutes, or informal handling phrases that blur the distinction among these classes. Class language is governance-bearing and shall remain controlled.

91.3.10 This clause shall be interpreted as the principal classification-tier rule for the institutional handling framework.


91.4 Authority to Assign, Change, Review, and Remove Security Classifications

91.4.1 Only competent authority surfaces designated by GCRI Canada may assign, confirm, change, downgrade, upgrade, remove, or otherwise materially alter security classifications and handling states applicable to information or materials governed by this Part.

91.4.2 Classification authority may vary by matter type, asset class, source origin, legal sensitivity, or operational consequence, but in all cases shall be role-bound, documented, and subject to review.

91.4.3 The authority to create information does not by itself create authority to classify or declassify it. Authors, technical operators, contributors, or project leads may propose classifications, but formal handling state must be set or confirmed by the competent classification authority where material consequence exists.

91.4.4 The authority to assign classification may differ from the authority to review or remove it, particularly in high-sensitivity, legal, controlled-room, or sovereign-sensitive contexts. Segregation of these powers may be required where independent scrutiny is needed.

91.4.5 No person may downgrade, broaden access to, or decontrol protected information solely because it has become operationally useful, politically salient, reputationally attractive, or requested by a senior or external actor.

91.4.6 Emergency or interim classification may be applied where needed to prevent harm, but such classification shall be promptly reviewed and regularized through the normal governance pathway.

91.4.7 No technical administrator, platform owner, or repository maintainer may treat metadata edit capability, access-admin rights, or platform configuration power as authority to alter the legal or governance classification of material.

91.4.8 This clause shall be interpreted as the authority-bounded rule for classification lifecycle decisions.


91.5 Marking, Labeling, and Metadata Requirements for Classified Materials

91.5.1 All classified or otherwise handling-governed materials shall be marked, labeled, or metadata-tagged in a manner sufficient to make their classification status, handling posture, and relevant restrictions intelligible to authorized users and governable by systems.

91.5.2 Marking under this clause may be textual, visual, metadata-based, system-enforced, or hybrid, provided it is reliable, retrievable, and proportionate to the medium and risk.

91.5.3 Marking and metadata shall identify, as appropriate: (a) the classification class; (b) handling modifiers or restrictions; (c) effective date or review date; (d) source or source class; (e) whether controlled-room or clean-room treatment applies; (f) access basis or audience restrictions; and (g) whether derivative public-safe use is prohibited, restricted, or conditionally permitted.

91.5.4 Labels shall not be decorative or generic. They must carry real operational consequence and map to actual handling rules.

91.5.5 Where materials are transformed, excerpted, compiled, translated, summarized, or exported, the resulting derivative must preserve or re-evaluate classification marking as appropriate. Classification shall not be lost merely because the form has changed.

91.5.6 Unmarked or weakly marked protected material remains protected if its actual nature or recorded classification supports that status. However, failure to mark correctly is itself a handling defect requiring remediation.

91.5.7 The Corporation shall also ensure that system metadata, repository state, file properties, and public-facing renderings do not contradict each other concerning classification, because inconsistent marking can produce unauthorized exposure or false restriction.

91.5.8 This clause shall be interpreted as the visibility-and-system-integrity rule for classified materials.


91.6 Least Restrictive Classification Compatible With Safety, Rights, and Institutional Integrity

91.6.1 GCRI Canada shall apply the least restrictive classification compatible with safety, rights protection, legal duty, institutional integrity, evidence integrity, protected participation, and continuity of the public-good infrastructure.

91.6.2 This principle requires that the Corporation avoid both under-classification and over-classification. Under-classification exposes persons, rights, systems, and institutional trust. Over-classification suppresses legitimate review, impairs public-safe communication, concentrates hidden power, and may create unnecessary opacity inconsistent with public-benefit stewardship.

91.6.3 Least restrictive does not mean casually open. It means that the Corporation shall not impose a stronger classification than the actual risk, legal posture, and contextual handling need require, once those factors are properly assessed.

91.6.4 No one may use this principle to force disclosure or weak controls where under-protection would create material harm. The phrase “least restrictive” shall always be read together with “compatible with safety, rights, and institutional integrity.”

91.6.5 Classification shall be narrowed where safe to do so through methods such as segmentation, sanitization, redaction, abstraction, de-identification, controlled summary, or separation of protected substrata from publishable outputs. Broad classification of entire packages shall not be preferred if narrower protected handling can preserve both safety and institutional legibility.

91.6.6 Equally, no person may invoke transparency or collaboration to resist classification where actual risk or legal duty demands stronger protection.

91.6.7 This clause shall be interpreted as the anti-excess and anti-insufficiency rule in the classification framework.


91.7 Periodic Review, Downgrading, Reclassification, and Decontrol Procedures

91.7.1 GCRI Canada shall subject classified and handling-governed information to periodic review sufficient to determine whether the original classification remains appropriate, whether a narrower class is now sufficient, whether stronger classification has become necessary, or whether the material may lawfully and safely be decontrolled, sanitized, or converted into a public-safe or lower-class form.

91.7.2 Periodic review shall be proportionate to classification level, consequence, and expected change in context. Information whose sensitivity depends on time, incident status, legal posture, investigation stage, political context, or ongoing operational significance shall be reviewed more actively than static materials.

91.7.3 Downgrading may occur where the reasons for stronger classification have diminished and a narrower class is now compatible with safety, rights, and institutional integrity. Decontrol may occur where the material can safely leave the classified regime altogether, whether in original or sanitized form.

91.7.4 Reclassification upward may be required where changed context, aggregation effects, legal developments, incident conditions, or newly appreciated misuse risks show that the existing classification is insufficient.

91.7.5 No classification shall remain indefinitely unchanged merely because no one has time to review it. Unreviewed permanence is itself a governance defect.

91.7.6 Downgrading, reclassification, and decontrol shall be recorded, attributable, and linked to the authoritative record so that users can determine what the material’s handling status was, is, and became over time.

91.7.7 This clause shall be interpreted as the lifecycle-governance rule for classification states.


91.8 Invalidity of Unmarked or Misclassified Sensitive Handling in the Absence of Recorded Review

91.8.1 Sensitive, confidential, or controlled-room handling shall not be deemed valid merely because an actor informally believes the material is sensitive or because social custom has led users to “treat it carefully.” Materially significant protection status must rest on an actual or reviewable classification basis consistent with this Part.

91.8.2 Where sensitive material is unmarked, ambiguously marked, or misclassified, the Corporation shall not treat the protection need as nonexistent; however, it shall also not treat informal handling folklore as an adequate substitute for records-valid classification.

91.8.3 In the absence of proper marking or correct classification, the Corporation shall take interim protective action proportionate to apparent risk, while promptly initiating recorded review to regularize the handling posture.

91.8.4 No person may defend inconsistent access, secret handling, or ad hoc disclosure restriction on the basis that “everyone knew it was sensitive” if there is no reviewable classification basis supporting that claim. Informal secrecy can conceal both under-protection and arbitrary opacity.

91.8.5 Likewise, no actor may justify disclosure of apparently sensitive material solely because the file lacked a label or because the metadata state was incomplete where context and available records made the sensitivity reasonably knowable.

91.8.6 This clause ensures that classification remains both real and governable: not defeated by clerical error, but not replaced by personal instinct.

91.8.7 This clause shall be interpreted as the closing integrity safeguard of Section 91 and as the bridge to the protected-information categories that follow.

92. Protected Information Categories and Scope

92.1 Rights-Bearing Data and Personal Information

92.1.1 GCRI Canada shall classify and govern as protected all rights-bearing data and personal information processed, stored, transmitted, or otherwise handled within its institutional perimeter, whether such data originates internally, is provided by third parties, or is derived through analysis, aggregation, or inference.

92.1.2 Rights-bearing data includes any information relating to an identified or identifiable person, as well as any information which, alone or in combination with other data, may reasonably lead to identification, profiling, targeting, reputational harm, discrimination, coercion, or loss of autonomy.

92.1.3 Protection under this clause shall extend not only to direct identifiers, but also to indirect identifiers, contextual signals, behavioral traces, metadata, and derived attributes that may enable re-identification or materially affect an individual’s rights or safety.

92.1.4 The Corporation shall treat rights-bearing data as presumptively sensitive and subject to classification, minimization, controlled access, and purpose limitation unless a lawful, recorded basis supports a narrower treatment.

92.1.5 No dataset shall be treated as “non-personal” merely because explicit identifiers have been removed where re-identification remains reasonably possible or where contextual linkage may expose individuals.

92.1.6 Special protection shall apply where data concerns vulnerable persons, protected participants, whistleblowers, public officials in sensitive roles, or individuals in contexts of heightened risk, including conflict, governance disputes, or exposure-sensitive environments.

92.1.7 This clause shall be interpreted as the primary anchor for privacy and human-protection obligations under Part VI.


92.2 Sovereign-Sensitive, Security-Sensitive, and Public-Authority-Sensitive Information

92.2.1 Information that is sovereign-sensitive, security-sensitive, or public-authority-sensitive shall be classified and handled with heightened protection due to its potential impact on national security, public safety, regulatory integrity, diplomatic relations, or lawful public authority functions.

92.2.2 Such information may include, without limitation: (a) government-origin or government-adjacent materials not designated for public release; (b) infrastructure or system-level information that could expose vulnerabilities; (c) policy deliberations, regulatory strategies, or enforcement-sensitive materials; (d) cross-border coordination data involving public institutions; and (e) any information whose misuse could materially disrupt governance, public order, or institutional trust.

92.2.3 The Corporation shall not assume that sovereign-sensitive information is governed solely by its source institution. Once handled within GCRI Canada’s systems or processes, it becomes subject to this Part’s classification, access, and protection rules in addition to any originating obligations.

92.2.4 No person may treat such information as shareable or publishable merely because it has been indirectly referenced, summarized, or technically transformed. Sensitivity follows substance, not format.

92.2.5 This clause shall be interpreted as the sovereignty-protection rule within the classification system.


92.3 Indigenous, Community, and Vulnerability-Sensitive Information

92.3.1 Information relating to Indigenous communities, local communities, or groups in conditions of vulnerability shall be treated as protected where disclosure, misuse, or decontextualization may cause cultural harm, rights violations, exploitation, misrepresentation, or loss of control over community knowledge or identity.

92.3.2 Such information may include traditional knowledge, community data, localized evidence, participatory research outputs, culturally sensitive materials, and context-dependent narratives that require stewardship beyond standard privacy rules.

92.3.3 The Corporation shall apply heightened safeguards, including consent alignment, contextual integrity, restricted access, and culturally appropriate handling protocols, in collaboration with relevant communities where applicable.

92.3.4 No person may assume that absence of formal legal restriction implies permission for unrestricted use. Community legitimacy and contextual appropriateness shall be treated as binding considerations.

92.3.5 This clause shall be interpreted as the dignity, cultural integrity, and community-rights safeguard within Part VI.


92.4 Controlled Evidence, Protected Disclosures, and Whistleblower Materials

92.4.1 Evidence, disclosures, and materials provided under conditions of protection, confidentiality, or safeguarded participation shall be classified and handled as protected, with strict controls over access, replication, transmission, and derivative use.

92.4.2 This includes whistleblower disclosures, confidential submissions, protected testimony, and any evidence provided with an expectation of restricted handling or risk-sensitive exposure.

92.4.3 The Corporation shall ensure that such materials are handled in a manner that: (a) preserves chain-of-custody and evidentiary integrity; (b) protects the identity and safety of the discloser where applicable; (c) prevents unauthorized replication or uncontrolled circulation; and (d) ensures that any use in governance or publication contexts is appropriately sanitized or bounded.

92.4.4 No person may extract, summarize, or indirectly disclose protected evidence in a way that compromises the protections under which it was provided.

92.4.5 This clause shall be interpreted as the protected-disclosure and evidentiary-integrity rule within the classification framework.


92.5 Research-Sensitive, Model-Sensitive, and Abuse-Prone Technical Materials

92.5.1 Technical materials that are research-sensitive, model-sensitive, or abuse-prone shall be classified and handled as protected where their disclosure could enable misuse, manipulation, exploitation, or systemic harm.

92.5.2 Such materials may include: (a) advanced models, algorithms, or system architectures with dual-use potential; (b) datasets that could be repurposed for harmful or exploitative outcomes; (c) simulation outputs or predictive systems that could influence behavior or markets if misused; and (d) experimental or pre-release systems not yet validated for safe public use.

92.5.3 The Corporation shall assess not only technical sensitivity but also misuse pathways, adversarial use cases, and systemic impact before determining release or classification posture.

92.5.4 No technical sophistication, research interest, or innovation imperative shall justify release of materials where misuse risk is materially foreseeable and not adequately mitigated.

92.5.5 This clause shall be interpreted as the dual-use and abuse-prevention rule for technical assets.


92.6 Third-Party Confidential Information and Contract-Protected Information

92.6.1 Information received from third parties under confidentiality, contract, or trust-based conditions shall be classified and handled in accordance with both the originating obligations and the Corporation’s own protective framework.

92.6.2 Such information may include proprietary data, commercial information, contractual deliverables, shared research, or any material subject to confidentiality clauses or restricted-use terms.

92.6.3 The Corporation shall ensure that such information is not: (a) repurposed beyond agreed scope; (b) disclosed to unauthorized parties; (c) merged into public or open repositories without lawful basis; or (d) transformed in a manner that circumvents the original restrictions.

92.6.4 No person may treat third-party information as internally owned or freely usable merely because it resides within GCRI systems.

92.6.5 This clause shall be interpreted as the contractual-integrity rule for externally sourced information.


92.7.1 Materials subject to legal privilege, investigation status, or litigation hold shall be classified and handled with the highest degree of protection consistent with their legal status and institutional importance.

92.7.2 This includes communications with legal counsel, investigative records, internal review materials, dispute-related evidence, and any content subject to preservation obligations.

92.7.3 Such materials shall not be disclosed, summarized, or indirectly revealed without explicit legal authorization and recorded review.

92.7.4 The Corporation shall ensure strict segregation of privileged materials from general repositories and enforce access limitations aligned with legal requirements.

92.7.5 This clause shall be interpreted as the legal-protection and evidentiary-preservation rule.


92.8 Credentials, Keys, Tokens, Identity Artifacts, and Access-Control Secrets

92.8.1 Credentials, cryptographic keys, authentication tokens, identity artifacts, and all forms of access-control secrets shall be classified as highly sensitive and subject to strict protection, handling, and lifecycle controls.

92.8.2 Such materials shall never be exposed in public repositories, shared informally, embedded in code without protection, or transmitted through uncontrolled channels.

92.8.3 Access to such materials shall be limited to authorized roles under least-privilege principles, with strong logging, rotation, and revocation mechanisms.

92.8.4 Any compromise, suspected compromise, or improper exposure of such materials shall be treated as a security incident requiring immediate escalation under Part VI.

92.8.5 No system, workflow, or environment shall rely on static or ungoverned credentials where dynamic, auditable, and revocable alternatives are available.

92.8.6 This clause shall be interpreted as the access-integrity and system-protection rule within the classification framework.


92.9 Composite and Derived Sensitivity Rule

92.9.1 Where multiple information elements, each individually of lower classification, are combined in a manner that creates higher sensitivity through aggregation, inference, or contextual linkage, the resulting composite shall be classified according to its combined risk profile.

92.9.2 This rule applies to datasets, reports, dashboards, analytics outputs, and any derived artifacts that materially increase exposure, identifiability, or misuse potential.

92.9.3 No person may treat composite outputs as low-sensitivity merely because their components were individually less sensitive.

92.9.4 This clause ensures that classification reflects actual risk rather than isolated components.


92.10 Closing Scope Rule for Protected Information

92.10.1 The categories set out in this Section are illustrative and non-exhaustive. Protection under Part VI follows actual risk, rights posture, legal duty, and institutional consequence rather than rigid taxonomy.

92.10.2 Where doubt exists as to whether information falls within protected scope, the Corporation shall apply the most-protective interim classification consistent with Section 90.8 pending formal review.

92.10.3 This clause shall be interpreted as the closing scope rule for protected information and as the bridge to access governance and identity controls.

Thought for 6s

94. Controlled-Room Doctrine

94.1 Controlled Room as a Formal Governance and Handling Environment

94.1.1 GCRI Canada shall recognize the Controlled Room as a formal governance and handling environment established for the bounded review, discussion, analysis, decision-support, evidence handling, or structured interaction with materials, persons, systems, or issues that cannot safely, lawfully, or appropriately be handled through ordinary institutional channels.

94.1.2 A Controlled Room is not merely a secure meeting, a confidential folder, a restricted call, or an informal arrangement among trusted persons. It is a specifically designated and governable environment with defined admission criteria, handling rules, scope limitations, output controls, logging or attendance discipline, and closure conditions.

94.1.3 The function of a Controlled Room is to create a lawful and reviewable container within which the Corporation may: (a) preserve confidentiality and rights protection; (b) reduce exposure and misuse risk; (c) maintain evidentiary or deliberative integrity; (d) protect protected participants and protected disclosures; (e) allow sensitive institutional work to proceed without uncontrolled diffusion; and (f) generate bounded, sanitized, or public-safe outputs where appropriate without disclosing the full protected substrate.

94.1.4 A Controlled Room shall be treated as a handling environment and not as a source of independent constitutional authority. It may govern how a matter is handled, who may participate, what may be seen, and what outputs may be produced; it does not by itself change the underlying legal competence, decision authority, or role boundaries established elsewhere in these bylaws.

94.1.5 The Controlled Room doctrine exists to prevent two equal and opposite institutional failures: (a) handling highly sensitive or rights-bearing matters through ordinary, porous, or socially informal channels; and (b) allowing the aura of secrecy or exclusivity to create unjustified opacity, informal power, or hidden governance outside the records-valid architecture of the Corporation.

94.1.6 Every Controlled Room shall therefore remain bounded by mission, safeguards, classification, access governance, official record discipline, and the non-execution boundary of the Corporation. No Controlled Room may be treated as an exception space in which ordinary constitutional duties disappear.

94.1.7 Controlled Rooms may be physical, virtual, or hybrid, but in all forms they must preserve equivalent governance qualities: attributable admission, scope discipline, protected handling, output control, closure logic, and reviewability.

94.1.8 No person may describe a matter as “in the Controlled Room” as a substitute for explaining its actual classification, scope, legal posture, or institutional handling basis. Controlled-Room designation is a governance state, not a rhetorical shield.

94.1.9 This clause shall be interpreted as the definitional and doctrinal foundation for all later Controlled-Room provisions in this Part.


94.2 Purpose and Trigger Conditions for Controlled-Room Use

94.2.1 Controlled-Room use shall be triggered only where ordinary classified handling, repository segmentation, or bounded access measures are insufficient to preserve the safety, rights, integrity, legal compliance, or public-trust conditions required for the matter concerned.

94.2.2 The purpose of invoking a Controlled Room is to create a higher-order handling discipline for matters involving one or more of the following conditions: (a) acute confidentiality or exposure sensitivity; (b) rights-bearing, retaliation-sensitive, or identity-sensitive participation; (c) evidentiary fragility or chain-of-custody significance; (d) legal privilege, investigation sensitivity, or litigation posture; (e) competition-sensitive, abuse-prone, or misuse-sensitive information; (f) sovereign-sensitive or public-authority-sensitive material; (g) cross-entity coordination requiring unusually narrow access boundaries; or (h) any context in which uncontrolled circulation would materially and foreseeably impair mission, safety, continuity, or lawful institutional action.

94.2.3 Trigger conditions shall be specific, recorded, and reviewable. A matter shall not be placed into a Controlled Room merely because it is politically delicate, reputationally awkward, donor-sensitive, executive-interesting, or institutionally prestigious.

94.2.4 Controlled-Room designation is appropriate where the risk arises from a combination of content, context, participant exposure, legal posture, and public consequence that cannot be safely managed by standard restricted or confidential handling alone.

94.2.5 No person may invoke the Controlled Room to avoid documentation, ordinary review, or accountability. If ordinary governance is adequate, the Controlled Room shall not be used. If extraordinary protected handling is required, the Controlled Room may be used, but only under the discipline of this Section.

94.2.6 The burden of establishing a valid trigger condition shall rest with the proposing or designating authority, and that burden shall be met in a written or otherwise governable record sufficient to support later oversight.

94.2.7 Where uncertainty exists as to whether a Controlled Room is required, the Corporation shall assess whether narrower handling controls would suffice. The use of a Controlled Room shall be justified by necessity and proportionality, not by caution alone.

94.2.8 This clause shall be interpreted as the necessity-and-trigger rule for Controlled-Room activation.


94.3 Matters Requiring Controlled-Room Treatment

94.3.1 Without limiting the generality of Section 94.2, the following matters shall ordinarily require Controlled-Room treatment unless a recorded review determines that a narrower protected-handling mechanism is sufficient: (a) protected disclosures or whistleblower matters where identity, retaliation, coercion, or source integrity risk is material; (b) sensitive investigations, privileged inquiries, or disciplinary matters involving high reputational, legal, or rights-bearing consequence; (c) evidence collections or evidentiary analyses whose chain-of-custody, admissibility, or tamper sensitivity requires highly bounded access; (d) highly sensitive technical materials, vulnerability intelligence, key-management matters, or repository compromise analyses that cannot safely circulate through ordinary channels; (e) competition-sensitive or clean-room-adjacent collaboration where the matter requires controlled interaction among participants who may not otherwise safely share information; (f) sovereign-sensitive, public-authority-sensitive, or jurisdiction-sensitive materials where uncontrolled access would create material governance, legal, or diplomatic risk; (g) cases involving vulnerable persons, community-sensitive information, or protected participation requiring heightened identity shielding or bounded visibility; and (h) any matter designated under lawful policy as Controlled-Room required due to recurring sensitivity patterns or structural risk.

94.3.2 The list above is illustrative and not exhaustive. What determines the need for Controlled-Room treatment is not the label of the matter but the actual combination of sensitivity, rights posture, misuse risk, participant risk, and institutional consequence.

94.3.3 A matter shall not escape Controlled-Room treatment merely because it is technically distributed across multiple repositories or because portions of it are publicly known. The relevant question is whether the full protected matter, if ordinarily handled, would create material additional risk.

94.3.4 Conversely, a matter shall not be forced into Controlled-Room treatment merely because it is important, complex, or high-profile if the actual conditions requiring such treatment are absent.

94.3.5 This clause shall be interpreted as the ordinary-scope rule for matters presumptively requiring Controlled-Room handling.


94.4 Authority to Designate, Activate, and Close a Controlled Room

94.4.1 Only competent authority surfaces designated by GCRI Canada may designate, activate, extend, narrow, suspend, or close a Controlled Room.

94.4.2 Such authority may vary by matter type, but shall always be role-bound, recorded, and subject to review. The authority to contribute to or participate in a sensitive matter does not by itself create authority to place that matter into Controlled-Room status.

94.4.3 The authority record for Controlled-Room designation shall identify, at minimum: (a) the matter or case concerned; (b) the trigger condition or conditions; (c) the designated class or type of Controlled Room if relevant; (d) the duration or review period; (e) the initial access list or access-governance process; and (f) any specific operating restrictions, output rules, or closure conditions.

94.4.4 Authority to close a Controlled Room shall include responsibility to determine whether: (a) the matter has concluded; (b) the sensitivity has reduced sufficiently for downgrade or decontrol; (c) sanitized or public-safe outputs are required; (d) materials must transition to other classified repositories or archives; and (e) access rights, logs, and retained materials have been correctly reconciled.

94.4.5 No Controlled Room may remain active indefinitely by inertia. If ongoing handling is required, the continuation basis must be reviewable and periodically reauthorized.

94.4.6 Emergency activation may be permitted where delay would materially increase risk, but emergency designation must be recorded promptly and reviewed within the shortest safe period.

94.4.7 This clause shall be interpreted as the authority-and-lifecycle rule for Controlled-Room status.


94.5 Relationship Between Controlled Rooms and Publication Classes

94.5.1 Controlled-Room status shall govern handling and access environment; it shall not be confused with publication class, nor treated as equivalent to non-publication. A matter may be handled in a Controlled Room while still requiring, permitting, or eventually resulting in public-safe, stakeholder-bounded, or otherwise classified outputs under the publication rules of the Corporation.

94.5.2 The Corporation shall preserve a clear distinction between: (a) materials and discussions confined to the Controlled Room; (b) derivative outputs authorized for narrower internal circulation; (c) sanitized summaries or public-safe explanations derived from the Controlled Room; and (d) any final public or stakeholder release generated after review and approval.

94.5.3 Controlled-Room status shall not be used to imply that no disclosure may ever occur. Rather, it indicates that disclosure, if any, must be governed, bounded, and formed through authorized derivative outputs rather than by uncontrolled direct exposure of the underlying matter.

94.5.4 Where a Controlled-Room matter gives rise to public-safe release, the release shall identify or imply no more of the protected substratum than is necessary to preserve truthfulness, accountability, and public understanding.

94.5.5 No person may treat a public-safe derivative as though it were a complete substitute for the Controlled-Room record. Equally, no person may disclose Controlled-Room substrata on the theory that some public-safe output already exists.

94.5.6 This clause shall be interpreted as the separation rule between protected environment and publication posture.


94.6 No Controlled-Room Use for Mere Convenience or Prestige

94.6.1 A Controlled Room shall not be used for mere convenience, social exclusivity, institutional dramatization, executive prestige, donor impressiveness, reputational theater, or the creation of informal insider circles.

94.6.2 Convenience for purposes of this clause includes using a Controlled Room because ordinary meeting or repository discipline would require more documentation, broader justified consultation, more careful classification, or more explicit explanation than certain actors prefer to undertake.

94.6.3 Prestige misuse includes any use of Controlled-Room designation to signal importance, elevate perceived seriousness, or justify exclusion where actual protected-handling necessity is absent.

94.6.4 No person may invoke the Controlled Room as a cultural shortcut to indicate that a matter is “high level,” “executive,” “too sensitive to discuss normally,” or “for selected people only” if the underlying grounds do not satisfy the classification, rights, security, legal, or safeguards-based trigger conditions of this Part.

94.6.5 Where repeated or patterned Controlled-Room use appears linked to prestige rather than necessity, the matter shall be treated as a governance-control concern requiring review, because misuse of the doctrine erodes both transparency and legitimate protected handling.

94.6.6 This clause shall be interpreted as the anti-theater and anti-exclusivity rule for Controlled-Room governance.


94.7 Record of Designation, Scope, Access List, and Expiry Conditions

94.7.1 Every Controlled Room shall have a formal designation record sufficient to preserve legality, accountability, continuity, and later review.

94.7.2 The designation record shall include, at minimum and as appropriate: (a) a unique identifier or linked Case ID; (b) the matter description or bounded matter class; (c) the authority that designated the room; (d) the trigger condition and classification basis; (e) the defined scope of information, participants, and permissible activities; (f) the access-approval basis and initial or evolving access list; (g) the applicable restrictions on devices, outputs, derivatives, and onward handling; (h) the review date, expiry date, or condition for periodic revalidation; and (i) the closure and post-closure handling expectations.

94.7.3 The scope of a Controlled Room shall be stated with sufficient precision that users can determine what is inside the room, what is outside it, what outputs may be created, and what materials may or may not be carried into related but less restricted channels.

94.7.4 The access list shall be maintained as a living but governed record. Changes to admission status shall be recorded rather than left to implicit invitation practice or social memory.

94.7.5 Expiry conditions shall not be nominal only. Each Controlled Room must have a real logic of continuation, closure, or review so that temporary heightened handling does not become permanent opaque holding by default.

94.7.6 This clause shall be interpreted as the record-validity and boundary-definition rule for Controlled-Room operation.


94.8 Minimum Transparency and Publishable Summary Rule for Controlled-Room Matters

94.8.1 Except where law, rights protection, privilege, or material harm risk clearly prevents it, GCRI Canada shall maintain a minimum transparency obligation for Controlled-Room matters by requiring the creation, at the appropriate time and classification, of a publishable or shareable summary sufficient to preserve institutional legibility without compromising the protected substratum.

94.8.2 The minimum transparency obligation does not require disclosure of protected details, identities, evidence, or methods whose release would defeat the purpose of the Controlled Room. It requires only that the Corporation not allow Controlled-Room handling to produce total opacity where a truthful and bounded summary can lawfully be made available.

94.8.3 A publishable or shareable summary may include, as appropriate: (a) the existence and purpose of the matter; (b) the broad category of issue addressed; (c) the fact of Controlled-Room treatment and its lawful basis in abstracted form; (d) the broad outcome, status, or next step; and (e) any public-safe explanation necessary to prevent false rumor, false certainty, or false public narratives.

94.8.4 No Controlled-Room process shall be designed on the assumption that secrecy is complete virtue. Where the Corporation can explain itself without creating material harm, it shall do so through bounded, accurate, and role-faithful summary.

94.8.5 The timing, audience, and classification of such summary shall be determined according to the actual risk and legal posture of the matter, and may range from internal-only to public-safe, but the duty to consider such a summary is mandatory.

94.8.6 This clause shall be interpreted as the closing transparency safeguard of Section 94 and as the bridge to admission standards for Controlled-Room participation.

95. Controlled-Room Admission Standards

95.1 Eligibility Criteria for Admission

95.1.1 Admission to a Controlled Room shall be limited to persons whose participation is necessary, lawful, role-faithful, and proportionate to the scope, classification, and purpose of the matter for which the Controlled Room has been designated.

95.1.2 Eligibility for admission shall not arise from status, office, seniority, title, visibility, institutional proximity, donor significance, technical prestige, or mere interest in the subject matter. Admission is a handling decision governed by need, fit, and risk, not a privilege of rank.

95.1.3 A person shall be eligible for admission only where the Corporation can establish, through a recorded and reviewable basis, that the person: (a) has a current and legitimate need-to-know; (b) has a function or participation role materially connected to the purpose of the Controlled Room; (c) satisfies applicable competency, trust, and handling requirements; (d) does not present a disqualifying conflict, exposure, or integrity risk; and (e) can participate without undermining the security, privacy, rights-protective, evidentiary, or controlled-handling conditions of the room.

95.1.4 Eligibility shall be assessed with reference to the specific Controlled Room and the specific matter within it. Eligibility for one Controlled Room, or for one phase of a Controlled Room matter, shall not be presumed to carry over to another matter, another room, or another phase without renewed basis.

95.1.5 A person may be eligible for full participation, limited participation, observer-only participation, or no participation at all, depending on the classification, role, and handling needs of the matter. Admission is not necessarily binary.

95.1.6 The Corporation shall also preserve the principle that some roles may need access to summaries, outputs, or bounded derivatives without requiring admission to the underlying Controlled Room itself. Admission shall not be granted where a narrower informational path is sufficient.

95.1.7 Where uncertainty exists as to whether a person’s participation is necessary, the Corporation shall prefer the narrower access posture until a stronger and reviewable case for admission is established.

95.1.8 This clause shall be interpreted as the threshold eligibility rule for all Controlled-Room participation.


95.2 Credential, Fit-and-Proper, and Current-Status Requirements

95.2.1 Admission to a Controlled Room shall require satisfaction of credential, fit-and-proper, and current-status requirements proportionate to the classification level, participant role, and sensitivity of the matter under review.

95.2.2 Credential requirements may include, as appropriate: (a) verified identity; (b) confirmed institutional affiliation or lawful participation basis; (c) role validation; (d) current training and attestation status; (e) specific controlled-handling qualification; and (f) any additional trust, legal, or technical prerequisites required by the classification of the room.

95.2.3 Fit-and-proper assessment under this clause means an evaluation of whether the individual is, in the context of the specific room and matter, suitable for access in light of integrity, competence, conflict posture, handling reliability, exposure risk, legal restrictions, and prior conduct materially relevant to controlled participation.

95.2.4 Current-status requirements mean that the person’s eligibility must be live and current at the time of admission. Expired credentials, lapsed attestations, stale role assignments, suspended access status, incomplete conflict declarations, or unresolved handling violations shall be grounds for withholding or conditioning admission.

95.2.5 No one shall be admitted on the theory that deficiencies in credentialing or current-status checks may be cured informally after access is granted, unless an emergency exception under the bylaws has been lawfully invoked and recorded.

95.2.6 The Corporation shall calibrate fit-and-proper assessments carefully so that they protect safety and integrity without becoming arbitrary, discriminatory, or socially selective. The standard is risk-faithful suitability, not personal preference or institutional politics.

95.2.7 This clause shall be interpreted as the qualification-and-suitability rule for Controlled-Room admission.


95.3 Need-to-Know Justification and Access Approval Workflow

95.3.1 No person shall be admitted to a Controlled Room without a need-to-know justification recorded through a defined approval workflow proportionate to the classification and risk profile of the room.

95.3.2 The justification shall identify, at minimum: (a) the specific reason the individual requires access; (b) the role or function to be performed in the room; (c) the scope of information or participation actually needed; (d) the expected duration or phase of access; and (e) any conditions, limitations, or segmentation applicable to the admission.

95.3.3 Need-to-know shall be construed narrowly. It is not enough that a person’s work is adjacent to the matter, that they may become interested later, that they are influential, or that they occupy a broad governance or advisory position. The access sought must materially correspond to a current and specific handling need.

95.3.4 The access approval workflow shall be attributable, reviewable, and integrated with the access-governance and classification architecture of Part VI. Approval may require one or more validating roles depending on the matter class, including controlled-room managers, information custodians, safeguards roles, security roles, or other competent authority surfaces.

95.3.5 The Corporation shall maintain the distinction between admission approval and meeting invitation. A person is not admitted merely because they appear on a calendar entry, a distribution list, or a technical access group. Admission must rest on the governed workflow.

95.3.6 Where the matter evolves and the original need-to-know basis narrows or expands, the access approval shall be revisited rather than assumed to remain valid indefinitely.

95.3.7 This clause shall be interpreted as the formal access-basis rule for Controlled-Room participation.


95.4 Confidentiality Undertakings and Controlled-Handling Acknowledgments

95.4.1 Admission to a Controlled Room shall require confidentiality undertakings and controlled-handling acknowledgments proportionate to the class of room, the material sensitivity of the matter, and the role of the participant.

95.4.2 Such undertakings or acknowledgments shall confirm, as appropriate, that the participant understands and accepts: (a) the classification and handling posture of the room; (b) restrictions on disclosure, copying, note-taking, onward transmission, and derivative use; (c) device, recording, and communication limitations; (d) obligations regarding identity protection, source protection, and rights-bearing materials; (e) duties on exit, closure, or revocation of admission; and (f) consequences of breach, misuse, or circumvention.

95.4.3 A general employment, consultancy, or participation confidentiality clause may supplement but shall not necessarily substitute for a Controlled-Room-specific acknowledgment where the room involves materially heightened handling conditions.

95.4.4 No participant shall be admitted on the assumption that they “already know the rules” where the room depends on explicit understanding of room-specific restrictions and protected-handling duties.

95.4.5 Controlled-handling acknowledgment shall be recorded in a form sufficient to support later review, access challenge, incident response, and enforcement if needed.

95.4.6 This clause shall be interpreted as the acknowledgment-and-obligation rule for all Controlled-Room participants.


95.5 Restrictions on Advisers, Observers, Vendors, and External Participants

95.5.1 Advisers, observers, vendors, consultants, service providers, and other external or semi-external participants shall not be admitted to a Controlled Room unless their presence is specifically justified, narrowly bounded, and compatible with the classification, legal posture, and safeguards obligations of the matter.

95.5.2 No external participant shall be admitted merely because they are useful in ordinary operations, have broad commercial importance, are technically sophisticated, or have a general advisory relationship with the Corporation. Controlled-Room participation requires a matter-specific need and a lawful participation basis.

95.5.3 Where external participation is justified, the Corporation shall specify, as appropriate: (a) whether access is full or partial; (b) whether access is time-limited or topic-limited; (c) whether note-taking, device use, or derivative handling is prohibited or further restricted; (d) whether the participant may interact directly with protected materials or only with sanitized or segmented views; and (e) whether additional contractual, legal, or security conditions apply.

95.5.4 Vendor or service-provider admission shall be especially restricted where the matter involves canonical assets, protected disclosures, sovereign-sensitive information, privileged material, or high-risk evidence.

95.5.5 Observer status shall not be treated as a low-risk category by default. A silent observer can still receive and later misuse highly sensitive information. Observation itself must be justified.

95.5.6 This clause shall be interpreted as the bounded-external-participation rule for Controlled Rooms.


95.6 Special Conditions for Participation by Public Officials, Community Representatives, and Protected Persons

95.6.1 Participation by public officials, community representatives, protected participants, whistleblowers, vulnerable persons, Indigenous or community-designated representatives, or similarly situated persons shall be subject to special conditions sufficient to preserve dignity, role-clarity, safety, lawful participation, and contextual integrity.

95.6.2 Such special conditions may include, as appropriate: (a) segmentation of attendance; (b) role-specific confidentiality and attribution restrictions; (c) identity-shielding or role-marker treatment; (d) support or accompaniment conditions; (e) constraints on other participants’ visibility into sensitive identity or source context; and (f) protected communication channels before, during, and after participation.

95.6.3 Public officials shall not be admitted on the false premise that public role alone creates unrestricted access to controlled matters. Their participation shall remain bounded to lawful institutional purpose and need-to-know.

95.6.4 Community representatives and protected persons shall not be required to accept generalized institutional handling risk merely because the room is formally “secure.” Their participation conditions must account for real contextual risks of exposure, misuse, retaliation, or decontextualization.

95.6.5 No person in a protected or vulnerable participation category shall be admitted under circumstances that make the room formally compliant but substantively unsafe.

95.6.6 This clause shall be interpreted as the heightened-participation-protection rule for specially situated participants in Controlled Rooms.


95.7 Admission Denial, Conditional Admission, Suspension, and Removal Procedures

95.7.1 GCRI Canada shall maintain formal procedures for denial, conditional admission, suspension, and removal of persons from Controlled-Room participation where eligibility, fit, current status, need-to-know, or handling integrity requirements are not met or no longer met.

95.7.2 Admission may be denied where the person lacks a sufficient handling basis, presents unresolved conflict or risk, lacks required credentials or training, seeks access beyond necessity, or otherwise fails to satisfy the controlled-handling requirements of the room.

95.7.3 Conditional admission may be used where participation is legitimate but must be narrowed by time, topic, visibility, device restrictions, accompaniment, segmentation, or other proportional safeguards.

95.7.4 Suspension or removal may occur where: (a) the need-to-know basis expires; (b) a classification, legal, or safeguards condition changes; (c) a breach or attempted circumvention occurs; (d) the participant’s status, role, or eligibility changes; or (e) continued participation would create material risk to the room or its protected matter.

95.7.5 Denial, conditional admission, suspension, and removal shall be recorded with enough specificity to support continuity, later review, and any necessary appeal or escalation, while preserving the confidentiality of the room and the protection of affected persons.

95.7.6 No person may remain in a Controlled Room merely because they were admitted earlier. Admission is a governed status, not a vested entitlement.

95.7.7 This clause shall be interpreted as the admission-lifecycle control rule for Controlled-Room participation.


95.8 Review and Appeal of Access Decisions Where Appropriate

95.8.1 GCRI Canada may provide for review or appeal of Controlled-Room admission decisions where appropriate to fairness, due process, institutional legitimacy, or protected participation, provided that any such mechanism remains compatible with the classification, safety, legal, and rights-protective requirements of the matter.

95.8.2 Review or appeal shall not be presumed necessary in every case. It shall be available where the significance of the exclusion, the role of the applicant, or the possible effect on lawful participation warrants a second look without undermining the protected-handling basis of the room.

95.8.3 Any review or appeal mechanism shall be bounded such that: (a) the existence of the Controlled Room is not unnecessarily exposed; (b) sensitive reasons for denial are not over-disclosed; (c) rights of protected persons and sources are not compromised; and (d) the review authority is competent, independent enough for the matter, and itself subject to appropriate handling restrictions.

95.8.4 An appeal shall not create an entitlement to see the underlying protected material in order to challenge exclusion. Access challenge may be reviewed on the basis of governed access records, eligibility criteria, and handling logic rather than forced substantive disclosure.

95.8.5 This clause shall be interpreted as the fairness-without-exposure rule for contested Controlled-Room admission decisions and as the bridge to Controlled-Room operating procedures.

96. Controlled-Room Operating Procedures

96.1 Physical, Virtual, and Hybrid Controlled-Room Modalities

96.1.1 GCRI Canada may operate Controlled Rooms in physical, virtual, or hybrid form, provided that each modality satisfies the same governing requirements of attributable admission, classification fidelity, access control, handling discipline, output control, reviewability, and closure integrity.

96.1.2 A physical Controlled Room means a bounded in-person environment in which entry, presence, materials, devices, observation, note-taking, and onward communication are subject to formalized restrictions appropriate to the classification and purpose of the matter.

96.1.3 A virtual Controlled Room means a digitally mediated environment in which participation is restricted through verified identity, controlled access pathways, monitored session conditions, restricted collaboration features, controlled artifacts, and output limitations sufficient to replicate, to the degree reasonably possible, the discipline of an in-person controlled environment.

96.1.4 A hybrid Controlled Room means a combined environment in which some participants are physically present and others participate through controlled virtual means. Hybrid operation shall not be used where the combination materially weakens attendance verification, access parity, identity assurance, segmentation, or output control beyond what the matter safely permits.

96.1.5 The choice of modality shall be determined by the sensitivity, rights posture, legal constraints, participant composition, technical risk, and operational needs of the matter, and not merely by convenience, travel patterns, habitual tool use, or social preference.

96.1.6 No modality shall be presumed equivalent in all respects. Physical rooms may reduce some remote risks but create physical observation or document-movement risks; virtual rooms may improve logging but create device, export, and screen-capture risks; hybrid rooms may multiply edge cases in both directions. The Corporation shall therefore assess the actual risk posture of the chosen modality before activation.

96.1.7 Where the modality changes during the life of a Controlled Room, the Corporation shall review and, where necessary, update participation conditions, device rules, segmentation logic, output restrictions, and logging controls. A matter that is safe in a physical room may not be safe under unchanged rules when converted to hybrid or virtual handling.

96.1.8 No person may assume that because a session is “virtual,” “internal,” “small,” or “invite only,” it thereby qualifies as a Controlled Room. The modality is a technical form; the Controlled Room is a governed handling state.

96.1.9 This clause shall be interpreted as the modality-governance rule for Controlled-Room operation.


96.2 Entry, Exit, Attendance, and Presence Verification Controls

96.2.1 Every Controlled Room shall maintain entry, exit, attendance, and presence verification controls sufficient to establish who was present, when they were present, under what authority they were present, and whether their presence remained lawful and bounded throughout the session or access period.

96.2.2 Entry controls shall ensure that only admitted participants, under verified identity and applicable conditions, may enter the Controlled Room environment or access the controlled materials associated with it.

96.2.3 Exit controls shall ensure that participation ends when authorized access ends and that no continuing session state, open credential, unreturned material, residual download, unmanaged copy, or implied attendance survives beyond the authorized period without recorded basis.

96.2.4 Attendance records shall identify, as appropriate: (a) participant identity or protected role marker; (b) entry time and exit time; (c) participation mode; (d) admission basis or class; and (e) any conditional or segmented attendance restrictions applicable to that participant.

96.2.5 Presence verification shall be proportionate to sensitivity and may include physical sign-in, supervised entry, identity-confirmed digital join, waiting-room control, continuous session identity assurance, roll verification, or other technical and procedural means compatible with the handling class of the room.

96.2.6 In virtual and hybrid settings, the Corporation shall not rely solely on invitation distribution or conferencing platform assumptions to establish verified presence. Attendance must remain attributable, not merely technically logged.

96.2.7 Any unexplained attendance anomaly, unauthorized presence, ambiguous identity, unattended session continuation, or unresolved attendance discrepancy shall be treated as a handling incident requiring review, even if no material breach is yet proven.

96.2.8 This clause shall be interpreted as the attributable-presence rule for Controlled-Room participation.


96.3 Device, Recording, Printing, Copying, and Communication Restrictions

96.3.1 GCRI Canada shall impose device, recording, printing, copying, and communication restrictions within Controlled Rooms proportionate to the classification level, rights sensitivity, evidentiary posture, and misuse risk of the matter under review.

96.3.2 Unless a narrower or broader rule is specifically recorded for the room, no participant may record, screenshot, photograph, print, locally download, forward, duplicate, or externally communicate Controlled-Room materials or discussions outside the authorized handling pathway.

96.3.3 Device restrictions may include, as appropriate: (a) prohibition of personal devices; (b) requirement for approved or managed devices only; (c) camera, microphone, and local-storage restrictions; (d) disabling of copy, print, or export functions; (e) offline note-taking controls; and (f) controlled use of encrypted or air-gapped environments where required.

96.3.4 Printing shall be presumed restricted and allowed only where operationally necessary, logged, uniquely traceable where appropriate, and subject to controlled return, destruction, or archival. Printed material shall not be treated as a safer fallback merely because it is physical.

96.3.5 Copying restrictions apply not only to full documents or files but also to extracts, screenshots, handwritten reproductions, copied metadata, transcribed identifiers, and any other reproduction likely materially to preserve the protected substance of the room.

96.3.6 Communication restrictions shall prohibit discussion of Controlled-Room matters through uncontrolled channels, including personal messaging, informal calls, ad hoc summaries, unsanctioned AI tools, or any outward communication path not expressly permitted within the room’s operating rules.

96.3.7 No participant may rely on memory alone as a pretext to reconstruct and circulate Controlled-Room substance outside authorized channels. The duty of controlled handling includes restraint against informal recollection-based disclosure where the substance remains protected.

96.3.8 This clause shall be interpreted as the anti-leakage and anti-uncontrolled-reproduction rule for Controlled-Room operations.


96.4 Screen-Sharing, Whiteboard, Note-Taking, and Collaboration Restrictions

96.4.1 Screen-sharing, whiteboard use, annotation, note-taking, collaborative editing, chat, side-channel discussion, and other interactive collaboration functions within a Controlled Room shall be governed by explicit rules proportionate to the sensitivity and legal posture of the matter.

96.4.2 Screen-sharing shall be limited to approved surfaces and content necessary for the room’s purpose. Participants shall not share broader desktops, unrelated applications, personal notification streams, or uncontrolled repositories where such sharing risks exposing information outside the room’s approved scope.

96.4.3 Whiteboards, shared canvases, collaborative documents, or equivalent tools may be used only where the Corporation can preserve classification fidelity, access segmentation, retention rules, authorship or attribution trace, and post-session control over the resulting artifact.

96.4.4 Note-taking shall be limited to authorized forms. The Corporation may require no personal notes, structured notes only, room-issued note templates, note review before retention, or destruction/return of participant notes, depending on the matter class.

96.4.5 Participants shall not create informal summaries, side notes, action lists, or off-platform transcripts of Controlled-Room content unless specifically permitted and governed as derivative controlled outputs.

96.4.6 Internal chat, sidebar exchanges, and collaboration features within virtual tools shall be treated as part of the Controlled Room and subject to the same classification and retention rules as spoken discussion and shared materials. They are not casual sub-channels exempt from governance.

96.4.7 No collaborative feature shall be enabled merely because it is platform-default. Collaboration capability must remain subordinate to the protective logic of the room.

96.4.8 This clause shall be interpreted as the interactive-collaboration control rule for Controlled-Room activity.


96.5 Secure Minutes, Limited Notes, and Restricted Summary Preparation

96.5.1 GCRI Canada shall govern the creation of minutes, notes, internal records, restricted summaries, and any other documentary outputs arising from a Controlled Room so that the room remains accountable without becoming over-documented in ways that replicate the protected matter outside its proper boundaries.

96.5.2 Secure minutes may be produced where institutional memory, continuity, evidentiary support, or decision trace requires them, but such minutes shall be narrowly drafted, access-controlled, properly classified, and retained only within the designated record and handling architecture applicable to the room.

96.5.3 Limited notes may be authorized where the matter requires participant recall or bounded task execution, provided such notes remain within the handling class of the room, are reviewed where appropriate, and are not used to create uncontrolled parallel records.

96.5.4 Restricted summaries may be prepared for narrower internal distribution, escalation, legal review, or continuity purposes, but only under an explicit derivative-output pathway that preserves classification, provenance, and scope limitation.

96.5.5 No minute, note, or summary shall include more personal, technical, evidentiary, or rights-sensitive detail than is necessary for its legitimate purpose. The correct standard is sufficient trace, not maximal capture.

96.5.6 Where the matter requires a later public-safe or stakeholder-safe summary, that summary shall be prepared from the protected record under the publishable-summary logic of Section 94.8 and not by casual re-use of the room’s internal minutes or restricted notes.

96.5.7 The Corporation shall maintain a distinction among: (a) official secure minutes; (b) operational restricted summaries; (c) participant working notes if any are allowed; and (d) public-safe outputs. These are different document classes and shall not be conflated.

96.5.8 This clause shall be interpreted as the bounded-documentation rule for Controlled-Room outputs.


96.6 Segmentation by Topic, Case, and Participant Need-to-Know

96.6.1 GCRI Canada shall segment Controlled-Room participation, materials, and discussion by topic, case, evidence set, participant role, and need-to-know wherever full-room visibility would exceed what is necessary or safe for the matter concerned.

96.6.2 Segmentation may include, as appropriate: (a) sub-room structures; (b) phased admission; (c) topic-based attendance windows; (d) document-layer permissions; (e) redacted or role-specific views; (f) identity shielding for certain participants; and (g) separation of raw evidentiary substrata from broader analytical or governance discussion.

96.6.3 No Controlled Room shall assume that once a person is admitted to one part of the matter, they are thereby entitled to all materials, all participants, all source identities, or all related discussions. Controlled-Room admission remains bounded by need-to-know even within the room.

96.6.4 Segmentation is especially required where the room includes a mixture of internal staff, external advisers, public officials, community representatives, protected persons, evidence custodians, or technical specialists with materially different handling needs and exposure risks.

96.6.5 The Corporation shall not treat segmentation as evidence of distrust or inefficiency. It is a core means of implementing the least-privilege and minimum-exposure principles within a Controlled-Room environment.

96.6.6 Where segmentation is not feasible, the Corporation shall assess whether the room is improperly composed or whether a different handling structure is required.

96.6.7 This clause shall be interpreted as the internal-boundedness rule for Controlled-Room handling.


96.7 Controlled-Room Timeboxing, Continuation, and Extension Discipline

96.7.1 Controlled Rooms shall be timeboxed or otherwise bounded by reviewable continuation logic so that heightened handling persists only as long as necessary for the protected purpose of the matter.

96.7.2 Timeboxing may be defined by a specific session duration, a matter phase, a review window, an incident period, an evidentiary milestone, or another clearly stated boundary consistent with the room’s designation record.

96.7.3 Continuation beyond the original timebox shall require review sufficient to determine whether: (a) the trigger condition remains active; (b) the current participant set remains justified; (c) the classification remains appropriate; (d) narrower handling would now suffice; and (e) outputs, summaries, or transition actions are needed.

96.7.4 Extension shall be an affirmative act and not a default result of organizational inertia, incomplete decisions, or reluctance to reclassify.

96.7.5 Repeated extensions of the same room or matter shall trigger higher scrutiny, because prolonged Controlled-Room status may indicate unresolved legal posture, design weakness, over-classification, or inappropriate dependence on extraordinary handling.

96.7.6 No participant may continue to rely on room status after expiry or lapse of extension authority. If the room has expired, the matter must either be reauthorized, migrated, downgraded, or closed.

96.7.7 This clause shall be interpreted as the anti-permanent-exception rule for Controlled-Room temporal governance.


96.8 Closure, Material Return, Sanitization, and Secure Disposal Procedures

96.8.1 Upon closure of a Controlled Room, or upon exit of a participant from a Controlled Room, GCRI Canada shall ensure orderly return, reconciliation, sanitization, archival transfer, or secure disposal of all materials, copies, derivative notes, access artifacts, session residues, and temporary handling environments associated with the room.

96.8.2 Closure procedures shall address, as appropriate: (a) revocation or expiration of access credentials; (b) return or destruction of printed materials; (c) reconciliation of notes and working documents; (d) retention or deletion of chat, whiteboard, or session artifacts according to classification and retention rules; (e) migration of official protected outputs to the correct repository or archive; and (f) confirmation that no unauthorized copies, local exports, uncontrolled derivatives, or lingering devices remain in active possession.

96.8.3 Sanitization shall be used where a system, workspace, device, or document environment must be cleansed of protected material before reuse, downgrade, or broader operational circulation. Sanitization shall be documented where material significance warrants it.

96.8.4 Secure disposal shall follow the retention and destruction rules of this Part and shall be proportionate to the sensitivity and recoverability of the material concerned. Disposal shall not erase the official trace that the room existed, what class it held, and what official outputs or archives remain.

96.8.5 Closure is not complete merely because the meeting ends or the file is archived. A Controlled Room remains active in governance terms until the Corporation has reconciled its participants, materials, outputs, retention posture, and residual access conditions.

96.8.6 Where the matter continues in downgraded, reclassified, or public-safe form, closure of the Controlled Room shall include explicit transition rules so that participants understand what remains protected, what has changed status, and what outputs may now circulate lawfully.

96.8.7 This clause shall be interpreted as the closure-integrity rule for Controlled-Room operations and as the bridge to Clean-Room procedures and other high-sensitivity workflows.

97. Clean-Room Procedures and High-Sensitivity Workflows

97.1 Distinction Between Controlled Room and Clean Room

97.1.1 GCRI Canada shall maintain a strict distinction between a Controlled Room and a Clean Room. A Controlled Room is a formal protected-handling environment for bounded access, discussion, review, and controlled output concerning sensitive matters. A Clean Room is a more restrictive and methodologically constrained environment designed for handling highly sensitive, competition-sensitive, rights-sensitive, legally restricted, source-sensitive, or misuse-prone materials under conditions of stronger separation, minimization, transformation control, and output constraint.

97.1.2 A Clean Room is not merely a more serious Controlled Room, nor a label for matters that are politically delicate, prestigious, or high-visibility. It is a specialized handling architecture used where the Corporation must create a stronger separation between raw or protected source materials and any resulting analytical, governance, public-safe, or operational outputs.

97.1.3 The defining feature of a Clean Room is that it is structured to prevent direct or uncontrolled propagation of underlying protected matter into externalized outputs, downstream processes, partner interactions, or decision environments except through specifically governed transformation, aggregation, minimization, sanitization, or equivalence pathways.

97.1.4 Controlled Rooms may protect discussion and access; Clean Rooms additionally protect transformation logic. A Clean Room exists where it is not enough merely to limit who sees the source material. It is also necessary to regulate how the material is processed, abstracted, compared, combined, or translated into outputs.

97.1.5 The Corporation shall not use the terms “Controlled Room” and “Clean Room” interchangeably in records, policies, repository annotations, or public-safe descriptions. Each term has distinct legal and operational consequence within this Part.

97.1.6 Where a matter begins in a Controlled Room and later requires Clean-Room treatment, the Corporation shall expressly redesignate the handling state and adjust access, workflow, output, and review conditions accordingly.

97.1.7 No person may describe a workflow as “clean-room” merely because it is confidential, segregated, or technically secure. The term shall be reserved for workflows meeting the stronger separation and transformation logic required by this Section.

97.1.8 This clause shall be interpreted as the doctrinal distinction rule between the two highest protected-handling environments in Part VI.


97.2 Clean-Room Use for Competition-Sensitive, Rights-Sensitive, or Highly Restricted Work

97.2.1 GCRI Canada shall use Clean-Room procedures where the matter involves competition-sensitive, rights-sensitive, source-sensitive, highly restricted, or otherwise high-risk material that cannot safely be handled through ordinary classified workflows or even through a standard Controlled Room without stronger separation and transformation controls.

97.2.2 Clean-Room use may be required, without limitation, where the Corporation handles: (a) competition-sensitive information that must not be directly shared across participants or roles in a form capable of distorting markets, procurement, negotiations, or counterpart behavior; (b) rights-bearing or identity-sensitive data requiring strong separation between raw protected inputs and publishable or decision-support outputs; (c) highly sensitive technical materials, model artifacts, vulnerability-related materials, or abuse-prone systems requiring tightly controlled review and constrained downstream disclosure; (d) privileged, investigative, or evidentiary material whose direct exposure must be minimized while still permitting bounded review or structured determination; (e) community-, sovereignty-, or culturally sensitive materials requiring context-preserving but highly restricted treatment; or (f) cross-entity matters where direct sharing of source material would create legal, ethical, or institutional conflicts, but controlled aggregation or transformation remains legitimate.

97.2.3 The use of a Clean Room shall be justified only where the stronger environment is necessary to reduce exposure, preserve legal or ethical boundaries, prevent misuse, or avoid improper influence or contamination of downstream processes.

97.2.4 No matter shall be placed into a Clean Room merely because it is important or because certain actors prefer stronger secrecy. Clean-Room designation shall rest on actual transformation risk, contamination risk, or source-separation necessity.

97.2.5 Where the matter could be handled safely through narrower means, including segmentation within a Controlled Room, the narrower means shall ordinarily be preferred. Clean-Room use must remain proportionate.

97.2.6 This clause shall be interpreted as the necessity-and-scope rule for Clean-Room activation.


97.3 Aggregation, Minimization, and De-Identification Requirements in Clean-Room Contexts

97.3.1 Clean-Room workflows shall require aggregation, minimization, de-identification, abstraction, or equivalent transformation of source materials wherever such steps are necessary to permit lawful downstream use without exposing raw protected matter beyond what the matter requires.

97.3.2 Aggregation under this clause means combining or summarizing underlying materials in a manner that reduces direct identifiability, tactical sensitivity, proprietary specificity, or legally restricted granularity while preserving sufficient meaning for the legitimate downstream purpose.

97.3.3 Minimization means that only the smallest volume, precision, and identifiability of source material necessary for the immediate Clean-Room task shall be introduced, retained, or externalized. A Clean Room is not a general high-sensitivity warehouse. It is a tightly bounded processing environment.

97.3.4 De-identification or pseudonymization shall be used where personal, community-linked, or source-sensitive material is involved and where the downstream function does not require direct identity. The Corporation shall not assume that simple redaction is sufficient if contextual or structural re-identification remains material.

97.3.5 No person may export, share, or embed raw Clean-Room source materials in external analyses, working papers, dashboards, governance notes, model outputs, or public-safe summaries unless a recorded authority basis explicitly permits it and the handling architecture remains intact.

97.3.6 Where aggregation or abstraction materially changes meaning, the Corporation shall record the transformation logic sufficiently to preserve later review, challenge, and accountability without unnecessarily exposing the protected substrate.

97.3.7 This clause shall be interpreted as the minimum-exposure transformation rule for Clean-Room work.


97.4 Separation of Source Data From Publishable or Operational Outputs

97.4.1 GCRI Canada shall preserve strict separation between source data or source materials handled within a Clean Room and any publishable, shareable, operational, governance, or decision-support outputs produced from that material.

97.4.2 The purpose of this separation is to ensure that downstream outputs are fit for their intended audience and function without silently carrying through protected content, sensitive identifiers, tactical details, legal encumbrances, or misuse-enabling detail from the source layer.

97.4.3 No output shall leave a Clean Room unless it has passed through the required transformation, review, and release pathway appropriate to its intended class, audience, and use.

97.4.4 The Corporation shall distinguish clearly among: (a) raw source inputs; (b) transformed internal analytical products; (c) governance or determination outputs; (d) restricted summaries; and (e) public-safe or stakeholder-safe outputs. These are different product classes and shall not be treated as interchangeable merely because they arise from the same source set.

97.4.5 Where an output is based on Clean-Room source materials, the output record shall indicate that the underlying substrate remains controlled, even if the output itself is no longer in Clean-Room class.

97.4.6 No person may attempt to bypass separation by exporting partial raw content, screenshots, uncited excerpts, direct field values, repository identifiers, or context-rich fragments that materially reconstruct the protected source layer.

97.4.7 This clause shall be interpreted as the source-output firewall rule for Clean-Room operations.


97.5 Clean-Room Access, Processing, Review, and Exit Controls

97.5.1 Access to a Clean Room shall be more restrictive than access to an ordinary Controlled Room and shall be limited to specifically approved roles, persons, and systems whose participation is essential to the defined purpose of the workflow.

97.5.2 The Corporation shall govern Clean-Room access by: (a) stronger admission criteria; (b) tighter topic and material segmentation; (c) limited and attributable processing privileges; (d) stronger logging and session trace; (e) narrower export and note-taking permissions; and (f) explicit exit and decontamination obligations.

97.5.3 Processing inside a Clean Room shall occur only through approved tools, datasets, workspaces, and transformation methods consistent with the room’s designation and technical control requirements.

97.5.4 Review of intermediate and final outputs shall occur before release from the Clean Room, with attention to residual identifiers, inferential leakage, legal restrictions, provenance loss, semantic distortion, and unauthorized continuity of protected details.

97.5.5 Exit controls shall ensure that participants do not leave the Clean Room carrying unauthorized copies, retained raw source traces, unreviewed notes, personal extracts, or lingering credentials or access states.

97.5.6 The Corporation shall not treat completion of analysis as equivalent to clean exit. A Clean-Room process remains active in governance terms until materials, outputs, identities, and environment state have been reconciled and closed.

97.5.7 This clause shall be interpreted as the bounded-processing and controlled-exit rule for Clean-Room operations.


97.6 No Public Release of Clean-Room Materials Without Recorded Reclassification or Sanitization

97.6.1 No material originating in, stored in, or governed by a Clean Room may be publicly released, broadly circulated, or moved into a less restrictive environment unless it has undergone recorded reclassification, sanitization, abstraction, or equivalent review sufficient to establish that the proposed new handling state is lawful and safe.

97.6.2 This prohibition applies not only to full source materials but also to transformed outputs, if those outputs still preserve or reveal protected substrate beyond the level appropriate for their intended audience.

97.6.3 Reclassification or sanitization shall identify, as appropriate: (a) what source class the material originated from; (b) what transformations were performed; (c) what protected elements were removed, abstracted, or bounded; (d) what new classification or publication class now applies; and (e) what residual restrictions remain even after the release or downgrade.

97.6.4 No one may justify public release by arguing that the material is already “processed,” “summarized,” “technical,” or “anonymous” unless a recorded review confirms that those descriptions are sufficient to overcome the original Clean-Room basis.

97.6.5 If uncertainty remains about residual exposure or misuse risk, the Corporation shall retain the stronger handling state or use a narrower stakeholder-bounded derivative rather than release the material into public circulation prematurely.

97.6.6 This clause shall be interpreted as the no-direct-release rule for Clean-Room source and derivative materials.


97.7 Independent Review and Auditability of Clean-Room Operations

97.7.1 Clean-Room operations shall be subject to independent review and auditability sufficient to demonstrate that source separation, access discipline, transformation logic, output control, and closure requirements have been followed in practice and not merely declared in policy.

97.7.2 Independent review may include, as appropriate: (a) audit of access logs and session traces; (b) review of transformation and aggregation methodology; (c) confirmation of source-output separation; (d) inspection of classification and reclassification records; (e) review of de-identification or minimization sufficiency; and (f) testing of whether unauthorized reconstruction or leakage risk remains material.

97.7.3 The persons who operated the Clean Room or produced the outputs may provide explanatory support, but they shall not be the sole and final judges of whether the workflow remained clean, bounded, and compliant where material consequence exists.

97.7.4 Auditability under this clause requires preservation of enough records to reconstruct who entered, what was processed, what transformations occurred, what outputs were authorized, and how closure was achieved.

97.7.5 No Clean-Room process shall be considered complete if its internal discipline cannot later be explained or evidenced without relying solely on participant recollection.

97.7.6 This clause shall be interpreted as the assurance-and-verifiability rule for high-sensitivity workflow operation.


97.8 Cross-Entity and Third-Party Conditions for Clean-Room Participation

97.8.1 Where a Clean Room involves cross-entity participation, external reviewers, vendors, hosts, public authorities, community representatives, academic partners, or other third parties, GCRI Canada shall impose additional conditions sufficient to preserve role-bounded participation, legal compliance, source protection, and non-transfer of uncontrolled influence or custody.

97.8.2 Such conditions may include, as appropriate: (a) narrower role-based visibility; (b) stricter contractual or legal undertakings; (c) segregated workspaces or sub-rooms; (d) prohibition on raw-source retention by external participants; (e) explicit limits on derivative use, publication, and onward transmission; and (f) stronger exit, revocation, and enforcement provisions.

97.8.3 No third party shall be admitted to a Clean Room merely because they are technically useful, commercially important, politically relevant, or affiliated with a related institution. Their inclusion must be justified by specific handling need and compatibility with the protective purpose of the room.

97.8.4 Cross-entity participation shall not blur ownership, custody, or classification boundaries. GCRI Canada shall preserve a clear record of what remains within its protected-handling perimeter, what is shared, and under what exact conditions.

97.8.5 This clause shall be interpreted as the closing cross-boundary safeguard of Section 97 and as the bridge to chain-of-custody rules for evidence and governance artifacts.

98. Chain-of-Custody for Evidence and Governance Artifacts

98.1 Chain-of-Custody as a Mandatory Condition for Sensitive Evidence Handling

98.1.1 GCRI Canada shall treat chain-of-custody as a mandatory condition for the lawful, reliable, and reviewable handling of sensitive evidence and governance artifacts whose credibility, admissibility, traceability, or protected status depends materially on the Corporation’s ability to show what the item is, where it came from, how it was handled, by whom it was handled, and whether its integrity has been preserved across time.

98.1.2 Chain-of-custody is not merely a forensic preference or a technical logging feature. It is a governance discipline by which the Corporation preserves trust in evidence, protects participants, limits fabrication or tampering risk, and ensures that materials capable of influencing governance, safeguards, publication, institutional consequence, or cross-entity action are not moved through informal, undocumented, or non-attributable channels.

98.1.3 A chain-of-custody obligation arises where the item handled is sufficiently sensitive, contested, rights-bearing, source-dependent, legally relevant, or institutionally consequential that later reliance upon it may reasonably depend on trustworthy proof of continuity and integrity of handling.

98.1.4 No item shall be treated as custody-governed merely for rhetorical gravity; equally, no item requiring custody discipline shall be handled casually because it appears administratively routine, digitally convenient, or widely copied. The governing question is the item’s actual evidentiary and institutional consequence.

98.1.5 Chain-of-custody under this Part applies to physical and digital materials alike. It applies to raw evidence, structured evidence packages, witness-linked materials, restricted disclosures, logs, extracts, derivative summaries, governance exhibits, and any transformed version of a controlled item where the transformed version still depends materially on the integrity of the source chain.

98.1.6 No person may claim that because an item is stored in a digital system or has metadata attached, chain-of-custody requirements have automatically been satisfied. Digital presence does not equal governed custody. Custody requires accountable control over identity, movement, access, transformation, and state changes.

98.1.7 This clause shall be interpreted as the threshold doctrine for all evidence and governance-artifact custody requirements under Part VI.


98.2 Scope of Materials Subject to Custody Controls

98.2.1 Materials subject to chain-of-custody controls shall include all evidence and governance artifacts whose sensitivity, source dependence, dispute potential, classification, protected-participation relevance, or institutional consequence makes trustworthy handling trace essential.

98.2.2 Without limitation, such materials may include: (a) protected disclosures, whistleblower submissions, and retaliation-sensitive source materials; (b) evidentiary files used in internal review, integrity review, safeguard matters, or formal governance deliberation; (c) controlled interview notes, transcripts, recordings, or source-linked extracts; (d) legal, investigative, or disciplinary exhibits; (e) logs, technical traces, incident artifacts, or forensic captures used in material incident handling; (f) restricted model outputs, technical diagnostic artifacts, or analysis packages where later challenge or review may depend on intact provenance; (g) controlled-room and clean-room source bundles or designated derivative outputs; (h) decision-support artifacts whose weight depends on continuity from protected source matter; and (i) any governance artifact that is formally designated as custody-governed because of its likely institutional, legal, or evidentiary significance.

98.2.3 The scope of custody control shall also extend to copies, extracts, transformed versions, summaries, annotations, and derivatives where such items are sufficiently connected to the controlled source that their reliability or handling safety depends on the integrity of the original chain.

98.2.4 Not every note, memo, or operational file shall require formal chain-of-custody treatment. The Corporation shall apply custody controls where consequence warrants, and shall avoid both under-classifying genuinely sensitive items and overburdening low-consequence work with theatrical evidentiary procedure.

98.2.5 Where uncertainty exists as to whether a material should be treated as custody-governed, the Corporation shall prefer interim custody discipline pending review if the downside of non-custodial handling could materially impair trust, reviewability, or rights protection.

98.2.6 This clause shall be interpreted as the scope-defining rule for custody-governed materials.


98.3 Custody Record, Identifier, Timestamp, and Handler Requirements

98.3.1 Every custody-governed material shall have a custody record sufficient to establish its identity, provenance, current state, handling history, and authorized custodial pathway.

98.3.2 The custody record shall include, as appropriate: (a) a unique identifier or linked case identifier; (b) a description of the item or item class; (c) source or origin information to the degree lawful and safe; (d) classification and handling status; (e) creation, receipt, or intake timestamp; (f) each material handoff, access event, transformation, or state change of custody significance; (g) the identity or attributable role marker of each authorized handler; and (h) the current custody location or authoritative custody surface.

98.3.3 Timestamps shall be sufficiently precise and consistent to permit later reconstruction of sequence, overlap, access period, and timing of material transformation or movement.

98.3.4 Handler identification shall preserve accountability. Anonymous handling shall not be accepted for custody-governed materials except where a protected role marker or specially governed source-protection mechanism has been explicitly approved and recorded. Even then, the system must preserve attributable control through the protected handling architecture.

98.3.5 No custody-governed material shall be moved, transformed, reclassified, extracted, or materially used in governance or review without a custody record that is capable of supporting later explanation of what happened to the item.

98.3.6 The custody record shall itself be protected against silent alteration, deletion, or informal parallel replacement. If the record of custody is weak, the credibility of the item itself is correspondingly impaired.

98.3.7 This clause shall be interpreted as the record-formation rule for all custody-governed materials.


98.4 Transfer, Copying, Access, and Movement Controls

98.4.1 Transfer, copying, access, movement, duplication, export, and transformation of custody-governed materials shall occur only through authorized and attributable pathways consistent with the classification, need-to-know, and handling requirements applicable to the item.

98.4.2 No custody-governed item may be passed hand-to-hand, forwarded through informal channels, exported to unmanaged environments, or duplicated into uncontrolled derivative spaces merely because the recipient is trusted, the process is faster, or the material appears operationally urgent.

98.4.3 Transfer controls shall identify: (a) who may initiate transfer; (b) who may receive the item; (c) what form of the item may be transferred; (d) what conditions attach to the transfer; and (e) whether the transfer changes custody location, access rights, or handling class.

98.4.4 Copying of custody-governed materials shall be minimized and shall be permitted only where necessary for lawful review, continuity, security, or bounded operational use. Each authorized copy shall itself be traceable or otherwise governed so that the chain does not dissolve through proliferation.

98.4.5 Access to a custody-governed item is a custody-relevant event where the access is material to evidentiary integrity, source protection, transformation, or decision consequence. The Corporation shall not treat all access as mere passive viewing if the access meaningfully changes the trust or exposure profile of the item.

98.4.6 Movement controls apply to both physical relocation and digital migration. A repository change, system export, platform shift, or attachment to a new controlled-room workflow may be as custody-significant as physical handoff of a sealed document.

98.4.7 This clause shall be interpreted as the controlled-movement rule for all custody-governed materials.


98.5 Tamper-Evidence, Integrity Checks, and Preservation Rules

98.5.1 GCRI Canada shall preserve tamper-evidence, integrity checks, and preservation measures for custody-governed materials sufficient to support later trust, challenge, and accountable use.

98.5.2 Tamper-evidence means that the Corporation can detect, or has materially reduced the risk of failing to detect, unauthorized alteration, substitution, partial corruption, unexplained truncation, silent metadata change, or unexplained break in continuity of the item or its custody record.

98.5.3 Integrity checks may include, as appropriate: (a) hashes or equivalent digital integrity controls; (b) sealed storage or packaging; (c) version lock or immutable-copy mechanisms; (d) reconciliation checks on receipt and transfer; (e) controlled imaging or forensic capture methods; and (f) review of metadata or artifact structure against expected prior state.

98.5.4 Preservation rules shall ensure that custody-governed materials are stored, archived, or maintained in ways that prevent loss of context, degradation of evidentiary value, corruption of file state, unauthorized replacement, or exposure inconsistent with the item’s handling class.

98.5.5 No one may rely on a custody-governed item as though its integrity were intact if tamper-evidence or preservation controls are known to have materially failed and no reviewable remediation has occurred.

98.5.6 Where exact tamper-proofing is not technically possible, the Corporation shall apply compensating controls sufficient to preserve practical confidence proportionate to the item’s significance and shall disclose residual limits where those limits materially affect reliance.

98.5.7 This clause shall be interpreted as the integrity-preservation rule for evidence and governance artifacts under custody control.


98.6 Admissibility and Traceability Standards for Governance Use

98.6.1 Custody-governed materials shall meet traceability standards sufficient for their intended governance use, and where the Corporation relies materially on such materials in protected review, safeguards, integrity matters, publication correction, or other institutional consequence-bearing processes, the chain shall support a reasoned conclusion that the item remains sufficiently attributable, intact, and contextually anchored for the use being made of it.

98.6.2 “Admissibility” for purposes of this clause does not necessarily mean judicial admissibility in a court of law, although it may include that where relevant. It means fitness for responsible institutional use in a process whose legitimacy depends in part on the trustworthiness of the material.

98.6.3 Traceability standards shall be calibrated to the significance of the intended use. Material used only for preliminary triage may require less rigorous trace than material used as the basis for formal institutional determination, disciplinary action, public correction, or cross-entity escalated consequence.

98.6.4 No custody-governed material shall be treated as equivalent to a fully traceable item where significant gaps, unexplained alterations, provenance ambiguities, or classification inconsistencies remain unresolved.

98.6.5 The Corporation may use a defective or incomplete chain for limited contextual or directional purposes if that limited use is explicitly recognized and does not overstate the material’s reliability. The Corporation shall not convert a weak chain into strong institutional proof by presentation style alone.

98.6.6 This clause shall be interpreted as the fitness-for-governance-use rule for custody-governed materials.


98.7 Breach, Break, or Gap in Custody and Required Remediation

98.7.1 Any breach, break, unexplained gap, integrity defect, unauthorized access event, uncontrolled copy event, unexplained movement, or material inconsistency in the custody chain of a governed item shall be treated as a custody incident requiring review, classification, and remediation proportionate to the seriousness of the defect.

98.7.2 A custody break may arise, without limitation, where: (a) an item cannot be located within its recorded custody path; (b) a transfer occurred without traceable authorization; (c) a copy exists without accounted-for origin; (d) a timestamp sequence materially conflicts; (e) a handler cannot be reliably identified; (f) integrity checks fail or cannot be completed; or (g) the item is found to have entered an uncontrolled environment.

98.7.3 On discovering a custody defect, the Corporation shall, as appropriate: (a) contain further handling; (b) preserve the current state of the item and surrounding records; (c) reconstruct the known chain to the extent reasonably possible; (d) classify the seriousness of the defect; (e) assess impact on admissibility, reliability, rights protection, and downstream use; and (f) determine whether withdrawal, re-collection, sanitization, public correction, or other remedy is required.

98.7.4 A custody defect does not automatically nullify all later use, but neither may it be minimized or ignored. The Corporation must explicitly determine what use, if any, remains legitimate and how the defect affects confidence in the material.

98.7.5 No one may conceal a custody break to preserve narrative continuity, institutional convenience, or evidentiary weight. Truth about the defect is itself part of the governance integrity of the process.

98.7.6 This clause shall be interpreted as the breach-and-remediation rule for broken or doubtful chains.


98.8 Retention, Secure Archival, and Disposal of Custody-Governed Materials

98.8.1 Custody-governed materials shall be retained, archived, and disposed of according to a controlled lifecycle sufficient to preserve legal, evidentiary, institutional, and safeguards obligations while preventing indefinite, unmanaged, or unsafe persistence.

98.8.2 Retention periods shall be determined by the material’s legal posture, incident significance, rights implications, investigation status, publication or correction relevance, and continuity needs, and shall not be shortened merely because the material is sensitive or cumbersome to store securely.

98.8.3 Secure archival shall preserve, to the extent necessary for future review and integrity: (a) the item itself or an appropriately preserved form of it; (b) its custody record; (c) associated classification and handling metadata; (d) integrity evidence; and (e) any linked determination of admissibility, remediation, or closure.

98.8.4 Disposal of custody-governed materials shall occur only when retention obligations have ended and only through secure disposal pathways appropriate to the medium and sensitivity of the item. Disposal shall not destroy the official trace that the item existed, that it was custody-governed, and how its lifecycle concluded.

98.8.5 Where litigation hold, investigation hold, public-authority hold, or other preservation override exists, the ordinary disposal path shall be suspended and the item shall remain preserved until lawful release of the hold.

98.8.6 This clause shall be interpreted as the lifecycle-closure rule for evidence and governance artifacts under custody control and as the bridge to the privacy and data-rights baseline.

99. Privacy and Data Rights Baseline

99.1 Privacy as a Core Institutional and Safeguards Obligation

99.1.1 GCRI Canada shall treat privacy as a core institutional, safeguards, and governance obligation and not merely as a technical compliance matter, legal disclaimer, or administrative processing requirement. Privacy under these bylaws is a condition of lawful stewardship, protected participation, public trust, and rights-respecting institutional operation.

99.1.2 Privacy protects not only against unlawful disclosure of personal information, but also against unnecessary collection, unjustified access, function creep, re-identification, profiling, contextual misuse, coercive visibility, and secondary use inconsistent with the basis on which information was collected, received, inferred, or entrusted to the Corporation.

99.1.3 The Corporation shall recognize that privacy harms may arise even where information is not publicly disclosed. Internal overexposure, excessive linkage, unjustified analytics, careless repository design, uncontrolled metadata, misuse of identifiers, and technically permissible but contextually inappropriate processing may all constitute privacy failures under this Part.

99.1.4 Privacy shall be interpreted in continuity with mission lock, public-benefit stewardship, protected participation, non-execution, and the official-record architecture of the Corporation. GCRI Canada does not hold personal or rights-bearing data as a general-purpose exploitable resource. It holds and processes such data only within bounded, reviewable, and necessary institutional purposes.

99.1.5 No function, team, project, repository, workflow, or platform of GCRI Canada may treat privacy as subordinate to speed, technical convenience, fundraising interest, external pressure, research enthusiasm, or institutional centrality. The greater the sensitivity of the matter and the vulnerability of the persons or communities concerned, the stronger the privacy duty.

99.1.6 This privacy baseline applies to direct collection, indirect receipt, collaborative handling, ingestion from hosts or partners, derivative analytics, structured repositories, metadata-bearing systems, model-assisted processing, and any other form of institutional interaction with personal or rights-bearing information.

99.1.7 Privacy under this Section includes dignity, contextual integrity, proportionality, bounded use, exposure minimization, and meaningful respect for the legitimate expectations and rights of persons and communities affected by the Corporation’s work.

99.1.8 This clause shall be interpreted as the foundational privacy doctrine for Part VI and as a controlling rule for all later data-handling sections.


99.2 Lawful Basis, Purpose Limitation, and Proportionality in Data Processing

99.2.1 GCRI Canada shall process personal information and other rights-bearing data only on a lawful, documented, and reviewable basis appropriate to the nature of the data, the context of handling, the role of the Corporation, and the rights and risks implicated by the processing.

99.2.2 No data-processing activity shall proceed on the theory that institutional possession, technical capability, mission alignment, or generalized public-interest aspiration alone is sufficient lawful basis. The Corporation shall identify the actual basis on which processing is justified and shall be able to explain that basis if challenged.

99.2.3 Purpose limitation shall require that data be collected, received, created, inferred, transformed, or otherwise processed only for defined, legitimate, bounded, and mission-faithful purposes. Those purposes shall be specific enough to constrain later handling and to prevent gradual expansion into generalized institutional reuse.

99.2.4 Proportionality shall require that the scale, granularity, duration, sensitivity, aggregation level, and onward use of data processing remain proportionate to the actual institutional need. The Corporation shall not process more data, more precise data, more linked data, or more persistent data than is reasonably necessary for the relevant purpose.

99.2.5 No one may broaden the purpose of processing merely because the data later appears useful for research, reporting, training, coordination, fundraising, productization, pattern detection, or institutional memory. Any material broadening of purpose shall require a new lawful basis, new review, or a decision not to proceed.

99.2.6 Where multiple possible lawful bases are available, the Corporation shall adopt the one most consistent with its role-bounded, public-benefit, and least-intrusive posture, rather than the one that merely provides the broadest discretion.

99.2.7 Purpose limitation shall also govern derivative analytics and transformed data products. A dataset or output produced from rights-bearing material shall not be treated as free from purpose limits merely because it is aggregated, modeled, or technically restructured.

99.2.8 This clause shall be interpreted as the lawful-basis and bounded-purpose rule for all data processing by GCRI Canada.


99.3 Data Minimization, Accuracy, and Storage Limitation

99.3.1 GCRI Canada shall apply data minimization, accuracy, and storage limitation as standing requirements for all processing of personal information and other rights-bearing data.

99.3.2 Data minimization means that the Corporation shall collect, receive, retain, infer, or use only the minimum categories, fields, identifiers, and context necessary to achieve the lawful and mission-faithful purpose of the processing activity.

99.3.3 The Corporation shall not collect or retain data merely because it might later become analytically useful, institutionally interesting, operationally convenient, or technically inexpensive to store. Speculative utility is not sufficient justification for collection or retention.

99.3.4 Accuracy shall require that rights-bearing data used for governance, publication, protected handling, research, evidence, or decision-support purposes be maintained with a degree of correctness, contextual fidelity, and currentness proportionate to the seriousness of its possible effects.

99.3.5 No person may knowingly rely on materially inaccurate, stale, miscontextualized, or unresolved rights-bearing data where that reliance could affect a person’s safety, status, dignity, or exposure. Where uncertainty exists, the Corporation shall preserve the uncertainty explicitly rather than fabricate false precision.

99.3.6 Storage limitation means that rights-bearing data shall not be retained in identifiable or readily linkable form longer than is necessary for the lawful purpose, retention obligation, or safeguarded institutional function that justified its retention.

99.3.7 Where continued retention is necessary for legal, evidentiary, archival, research, or accountability reasons, the Corporation shall prefer narrowed access, de-identification, segmentation, or controlled archival over broad ongoing operational availability.

99.3.8 This clause shall be interpreted as the minimization-and-retention baseline for privacy-safe data stewardship.


99.4 Rights of Access, Correction, Restriction, and Deletion Where Applicable

99.4.1 GCRI Canada shall recognize and operationalize, where applicable under law, policy, context, and the nature of the data relationship, rights of access, correction, restriction, objection, and deletion or erasure in relation to personal information and other rights-bearing data.

99.4.2 The Corporation shall maintain procedures sufficient to assess such requests lawfully, proportionately, and in a manner compatible with evidence integrity, legal holds, protected-source obligations, controlled-room duties, and the official record.

99.4.3 The right of access shall not require the Corporation to expose protected third-party information, privileged matter, source-sensitive material, or controlled-room substrata beyond what lawfully and safely may be disclosed. However, neither may the Corporation use generalized sensitivity claims to avoid legitimate response obligations.

99.4.4 The right of correction shall require the Corporation to assess whether data is materially inaccurate, incomplete, or misleading in context and, where correction is justified, to correct the relevant record or append a suitable qualification, dispute note, or contextual clarification.

99.4.5 Restriction rights shall be honored where continued broad processing is no longer justified, is contested, or is otherwise inappropriate pending resolution, provided that the Corporation may still preserve and handle the data to the limited extent necessary for lawful retention, incident response, audit, or evidentiary continuity.

99.4.6 Deletion or erasure shall be handled consistently with legal obligations, retention duties, litigation holds, archival obligations, public-interest evidence requirements, and the Corporation’s duty not to destroy material needed for accountability or correctionability.

99.4.7 No rights-response process shall be allowed to mutate into a hidden broad-disclosure pathway, nor into an opaque refusal machine. The Corporation shall pursue the narrowest lawful and most rights-faithful response in the circumstances.

99.4.8 This clause shall be interpreted as the data-rights operationalization rule for Part VI.


99.5 Privacy Impact Review for High-Risk Activities and Systems

99.5.1 GCRI Canada shall require privacy impact review for high-risk activities, high-risk systems, high-risk repositories, high-sensitivity workflows, and any material change to institutional practice reasonably likely to affect the rights, exposure, identifiability, dignity, or lawful expectations of persons or communities.

99.5.2 A privacy impact review shall assess, as appropriate: (a) the categories of data involved; (b) the lawful basis and purpose of processing; (c) the identifiability and re-identifiability risks; (d) the number and vulnerability of affected persons or groups; (e) the processing methods, repositories, tools, vendors, and jurisdictions involved; (f) the exposure, misuse, and secondary-use risks; (g) the safeguards, minimization, de-identification, and retention controls proposed; and (h) whether the activity should proceed, be narrowed, be redesigned, or not proceed at all.

99.5.3 High-risk status may arise from sensitivity, scale, aggregation, inference capability, automation, cross-border handling, model use, sovereign sensitivity, vulnerable-population context, or any other factor materially increasing the probability or consequence of privacy harm.

99.5.4 No system or program shall be permitted to bypass privacy impact review merely because it is strategically important, pilot-stage, technically novel, or built by a trusted partner. High novelty often increases the need for prior review.

99.5.5 Privacy impact review shall occur before the relevant activity becomes operational to a material degree and shall be revisited when the purpose, data categories, users, integrations, or risk profile materially change.

99.5.6 This clause shall be interpreted as the anticipatory-review rule for privacy-risk governance.


99.6 Separation Between Governance Need, Research Need, and Convenience Use

99.6.1 GCRI Canada shall preserve a strict separation between governance need, research need, and convenience use in relation to rights-bearing data and personal information.

99.6.2 Governance need means processing necessary for the Corporation’s lawful governance, safeguards, evidence, incident, custody, records, controlled-room, or oversight functions. Research need means processing necessary for a bounded and lawful research, methods, or analytical purpose within the Corporation’s mission. Convenience use means processing undertaken because the data is already available, easy to access, broadly useful, or tempting to repurpose.

99.6.3 Convenience use shall not constitute sufficient basis for rights-bearing data processing under this Part. The fact that a dataset is already held, already ingested, already linked, or already technically searchable does not authorize further use.

99.6.4 Governance need shall not automatically authorize research use, and research need shall not automatically authorize governance use. Distinct purposes remain distinct unless and until a lawful, reviewed, and proportionate bridge is explicitly established.

99.6.5 The Corporation shall therefore prevent informal reuse of rights-bearing data across teams, projects, repositories, models, and analyses where the original purpose does not clearly support the later use.

99.6.6 Where the same data supports more than one legitimate function, the Corporation shall document the legal and operational basis for each use and impose segmentation, minimization, and access rules sufficient to preserve purpose integrity.

99.6.7 This clause shall be interpreted as the anti-function-creep rule for privacy governance.


99.7 No Re-Identification, Secondary Use, or Broadening of Processing Without Recorded Authority

99.7.1 GCRI Canada shall prohibit re-identification, unauthorized secondary use, and broadening of processing of personal or rights-bearing data without recorded authority, lawful basis, and proportionality review.

99.7.2 Re-identification includes any act intended to reverse de-identification, combine datasets, infer identity, reconstruct protected source identity, or otherwise make a person or protected group more identifiable than the current handling state permits.

99.7.3 Secondary use includes any reuse outside the original documented purpose or compatible lawful purpose, including internal repurposing, model training, publication support, external coordination, institutional profiling, or analytics expansion not already justified by the original processing basis.

99.7.4 Broadening of processing includes increase in scope, granularity, audience, persistence, linkage, transfer, automation, or downstream use of rights-bearing data beyond the originally reviewed handling architecture.

99.7.5 No person may argue that re-identification or secondary use is acceptable because it remains internal, technically efficient, analytically interesting, or institutionally beneficial. Without recorded authority and lawful basis, such acts are prohibited.

99.7.6 If a legitimate case for broader use exists, it shall be handled through new review, revised safeguards, and where necessary reclassification, consent alignment, or refusal to proceed.

99.7.7 This clause shall be interpreted as the no-unreviewed-expansion rule for privacy-safe processing.


99.8 Privacy Escalation, Review, and Complaint Handling

99.8.1 GCRI Canada shall maintain escalation, review, and complaint-handling mechanisms for privacy concerns, privacy incidents, suspected over-collection, overexposure, improper linkage, unlawful secondary use, re-identification risk, denial of rights, or other claimed or suspected privacy failures under this Part.

99.8.2 Such mechanisms shall allow concerns to be raised through appropriate internal channels and, where relevant, through protected pathways for persons or groups who may face retaliation, dependency risk, or unequal institutional power.

99.8.3 Privacy complaints and escalations shall be reviewed by competent authority surfaces capable of assessing legal basis, technical architecture, safeguards posture, and practical harm rather than by ad hoc operational discretion alone.

99.8.4 The Corporation shall not dismiss privacy concerns merely because no formal breach has yet occurred. Near misses, structural exposure, and misuse-prone architecture may warrant escalation and redesign even before demonstrable harm has fully materialized.

99.8.5 Review outcomes may include, as appropriate: (a) confirmation of compliance; (b) correction or narrowing of processing; (c) access restriction; (d) deletion or de-identification; (e) rights-response action; (f) incident escalation; (g) policy or system redesign; and (h) notification duties where legally or ethically required.

99.8.6 The Corporation shall maintain records of privacy escalations and their resolution sufficient to support accountability, learning, and recurrence prevention while preserving confidentiality and protected-participation obligations.

99.8.7 This clause shall be interpreted as the complaint, escalation, and review rule for privacy governance and as the bridge to personal information and rights-bearing data handling.

100. Personal Information and Rights-Bearing Data Handling

100.1 Categories of Personal and Rights-Bearing Data in Scope

100.1.1 GCRI Canada shall classify personal information and rights-bearing data broadly enough to protect the real interests of persons, communities, protected participants, and affected groups, and not merely the narrowest technical category of direct personal identifiers.

100.1.2 Personal and rights-bearing data in scope includes, without limitation: (a) names, contact details, identifiers, credentials, demographic attributes, role information, affiliations, and biographical details; (b) location, mobility, device, network, behavioural, participation, access, and metadata traces; (c) testimony, submissions, disclosures, complaints, interview records, meeting records, and source-linked evidence; (d) inferred, derived, scored, clustered, profiled, or model-generated attributes concerning a person or group; (e) data relating to vulnerable persons, protected participants, public officials in sensitive contexts, whistleblowers, community representatives, or persons exposed through governance, research, evidence, or safeguards processes; and (f) any information which, alone or combined with other information, may reasonably enable identification, targeting, coercion, exclusion, reputational harm, or other material rights impact.

100.1.3 The Corporation shall treat metadata, indirect identifiers, contextual descriptors, and linkage keys as potentially rights-bearing where they can expose identity, participation, location, affiliation, vulnerability, or source relationship.

100.1.4 No record, dataset, repository, dashboard, model output, or evidence artifact shall be classified as outside this Section merely because direct names have been removed where re-identification, contextual linkage, or group harm remains reasonably possible.


100.2 Collection Restrictions and Necessity Test

100.2.1 GCRI Canada shall collect, receive, infer, generate, or otherwise acquire personal information and rights-bearing data only where the collection is necessary, lawful, proportionate, purpose-bound, and consistent with the Corporation’s mission and safeguards obligations.

100.2.2 Before collection or acquisition, the Corporation shall determine: (a) the specific purpose for which the data is required; (b) the lawful and institutional basis for collection; (c) whether less identifiable, less granular, less sensitive, or already aggregated data would suffice; (d) the expected retention, access, transfer, and publication posture; and (e) whether the collection creates special risks requiring privacy impact review, controlled-room handling, or additional safeguards.

100.2.3 Data shall not be collected merely because it may be useful, because a partner can provide it, because a tool can capture it, because it improves analytic richness, or because future research may find it valuable.

100.2.4 Where the Corporation cannot articulate a concrete and lawful necessity for a category of personal or rights-bearing data, that category shall not be collected or shall be excluded, redacted, aggregated, or otherwise minimized before ingestion.


100.3 Use Restrictions and Internal Access Controls

100.3.1 Personal information and rights-bearing data shall be used only for the purpose or compatible lawful purpose for which it was collected, received, or generated, and only by authorized persons or systems with a current need-to-know.

100.3.2 Internal access shall be role-bound, classification-aligned, logged where material, and limited to the minimum data elements necessary for the relevant function.

100.3.3 No person may access rights-bearing data for curiosity, general awareness, institutional convenience, relationship management, communications advantage, donor engagement, reputational monitoring, or exploratory analysis absent recorded authority and lawful basis.

100.3.4 Use restrictions shall apply equally to raw data, extracts, copies, dashboards, model outputs, summaries, transcripts, metadata, and derivatives capable of revealing protected identity, source, affiliation, vulnerability, or rights-impacting context.

100.3.5 Where a new use is proposed, the Corporation shall assess whether it is within the original purpose, requires new lawful basis, requires consent or notice, requires additional safeguards, or must be refused.


100.4 Disclosure Restrictions and Redaction Standards

100.4.1 GCRI Canada shall not disclose personal information or rights-bearing data externally, or internally beyond authorized need-to-know boundaries, unless the disclosure is lawful, necessary, proportionate, recorded, and consistent with classification, consent, contractual, legal, and safeguards obligations.

100.4.2 Disclosure may occur only through approved channels and shall be limited to the minimum audience, detail, duration, and format necessary for the legitimate purpose.

100.4.3 Redaction shall be required where disclosure of a document, evidence artifact, summary, publication, or dataset is otherwise legitimate but direct or contextual exposure of personal or rights-bearing information is not.

100.4.4 Redaction standards shall account for: (a) direct identifiers; (b) indirect identifiers; (c) context that may reveal identity; (d) metadata and embedded file properties; (e) visual, audio, or geospatial clues; (f) linkage keys and unique event patterns; and (g) inference risks created by small groups, rare attributes, or sensitive timing.

100.4.5 No redacted output may be released unless the Corporation has reviewed whether the redaction is substantively protective rather than merely cosmetic.


100.5 De-Identification, Pseudonymization, and Reversibility Rules

100.5.1 GCRI Canada may use de-identification, pseudonymization, aggregation, masking, tokenization, generalization, or other privacy-preserving techniques to reduce exposure and enable lawful use of personal or rights-bearing data where appropriate.

100.5.2 De-identification shall not be treated as absolute unless the Corporation has reasonably assessed re-identification risk in context, including available auxiliary data, recipient capabilities, dataset uniqueness, and future linkage risk.

100.5.3 Pseudonymized data shall remain protected where the Corporation or another actor can reasonably re-link it to an identifiable person or protected source. Pseudonymization reduces exposure; it does not automatically remove data from privacy governance.

100.5.4 Re-identification keys, linkage tables, tokens, and reversibility mechanisms shall be separately protected, access-restricted, logged, and subject to heightened handling controls.

100.5.5 No person may attempt re-identification, linkage reconstruction, or reversal except under recorded authority, lawful basis, and specific necessity.

100.5.6 Where de-identified or aggregated outputs are intended for publication, sharing, or repository release, the Corporation shall assess whether residual re-identification, group harm, or contextual exposure remains material before release.


100.6 Retention, Secure Deletion, and Data Subject Request Handling

100.6.1 Personal information and rights-bearing data shall be retained only for as long as necessary to satisfy the lawful purpose, legal obligation, evidentiary need, safeguards requirement, archival duty, or accountability function that justifies retention.

100.6.2 Retention shall be classification-aware and shall distinguish among active operational use, restricted archival retention, legal hold, investigation hold, public-interest record preservation, and secure deletion eligibility.

100.6.3 Where identifiable data is no longer needed in identifiable form, the Corporation shall delete, de-identify, aggregate, archive under restricted access, or otherwise minimize continued exposure.

100.6.4 Secure deletion shall be performed in a manner appropriate to the medium, system architecture, backup structure, and sensitivity of the data, and shall preserve required deletion records without retaining unnecessary protected content.

100.6.5 Data subject requests concerning access, correction, restriction, deletion, or other rights shall be handled through a recorded process capable of balancing requester rights with legal holds, third-party rights, privilege, source protection, evidence integrity, and controlled-room obligations.


100.7 No PII in Public Repositories, Open Releases, or On-Chain Artifacts

100.7.1 GCRI Canada shall prohibit the placement of personal information, direct identifiers, sensitive rights-bearing data, protected-source information, or re-identifiable materials in public repositories, open releases, public technical packages, public documentation, or on-chain artifacts.

100.7.2 This prohibition applies to visible content and hidden content, including metadata, commit history, issue history, comments, logs, screenshots, embedded files, sample datasets, test fixtures, examples, configuration files, and historical repository states.

100.7.3 No person may rely on later deletion from a public repository as an adequate substitute for prior review. Once disclosed in public or distributed technical environments, exposure may be difficult or impossible to fully reverse.

100.7.4 Where personal or rights-bearing data is required for testing, demonstration, training, or public explanation, the Corporation shall use synthetic, anonymized, aggregated, or specially approved public-safe examples that do not expose real persons or protected sources.

100.7.5 Any suspected publication of personal or rights-bearing data in a public repository, open release, or on-chain artifact shall be treated as a privacy and security incident requiring immediate containment, review, and remediation.


100.8 Special Rules for Vulnerable, Protected, or High-Risk Persons

100.8.1 GCRI Canada shall apply heightened handling rules to data concerning vulnerable persons, protected participants, whistleblowers, confidential sources, community representatives, children or youth where applicable, persons in conflict-affected or coercive contexts, public officials in sensitive roles, and any person whose exposure could create elevated risk of harm.

100.8.2 Such data shall be subject to stricter necessity review, narrower access, stronger minimization, more cautious disclosure, and heightened contextual risk assessment.

100.8.3 The Corporation shall consider not only formal legal status but practical vulnerability, including dependency, retaliation risk, political exposure, social marginalization, community sensitivity, or asymmetric power relationships.

100.8.4 No high-risk person’s information may be exposed, summarized, triangulated, or used in public-safe outputs without specific review of whether the person remains protected against identification, retaliation, coercion, or dignity harm.

100.8.5 Where participation by a vulnerable or protected person is necessary, the Corporation shall design the process around safety, consent alignment where applicable, controlled attribution, identity shielding, and post-participation protection.

100.8.6 This clause shall be interpreted as the heightened human-safeguards rule for personal information and rights-bearing data and as the bridge to sovereign data, localization, and compute-to-data controls.

101. Sovereign Data, Localization, and Compute-to-Data Controls

101.1 Sovereign Data Zones as a Primary Control for Sensitive and Sovereign Contexts

101.1.1 GCRI Canada shall recognize Sovereign Data Zones (SDZs) as a primary control surface for the lawful, secure, and context-faithful handling of sovereign-sensitive, jurisdiction-bound, rights-bearing, and high-consequence data.

101.1.2 An SDZ is a logically and/or physically bounded data and compute environment aligned to a specific jurisdiction, legal regime, or sovereign context, within which data remains governed by the applicable legal, institutional, and safeguards obligations of that jurisdiction.

101.1.3 SDZs shall be used where: (a) data is subject to jurisdiction-specific legal controls or expectations; (b) sovereign actors require in-country or jurisdiction-aligned control; (c) cross-border transfer would create legal, political, or trust risk; (d) rights-bearing or sensitive data requires contextual governance fidelity; or (e) institutional trust depends on demonstrable respect for sovereignty and locality.

101.1.4 The Corporation shall not treat SDZs as optional technical architecture. They are governance instruments ensuring that data handling respects sovereignty, legal order, and public trust.

101.1.5 SDZs may vary in implementation (physical, cloud-based, hybrid, enclave-based), but must preserve: (a) jurisdictional control; (b) access governance aligned to local and institutional rules; (c) logging and auditability; (d) segregation from unauthorized cross-border access; and (e) enforceable handling discipline consistent with this Part.

101.1.6 No system design shall centralize or externalize sovereign-sensitive data in a manner that defeats SDZ protections merely for efficiency, cost, analytics convenience, or architectural simplification.


101.2 Localization Requirements by Data Class, Context, and Jurisdiction

101.2.1 GCRI Canada shall apply data localization requirements proportionate to the classification, sensitivity, legal context, and sovereign expectations applicable to each dataset or data class.

101.2.2 Localization may require that certain categories of data: (a) remain stored within a specific jurisdiction; (b) be processed only within defined environments; (c) be accessed only through approved in-jurisdiction pathways; or (d) be subject to additional safeguards when accessed remotely.

101.2.3 Localization requirements shall be determined by: (a) applicable law and regulation; (b) agreements with host institutions or sovereign partners; (c) classification and handling rules under Part VI; (d) rights-bearing and community-sensitive considerations; and (e) institutional trust and safeguards obligations.

101.2.4 No person may bypass localization requirements through indirect technical means, including remote extraction, mirroring, shadow replication, unmanaged caching, or export via intermediate systems.

101.2.5 Where conflicting localization expectations arise across jurisdictions, the Corporation shall apply the most protective lawful posture until a resolved and recorded approach is established.


101.3 Compute-to-Data as Default for Restricted or Sovereign-Sensitive Material

101.3.1 GCRI Canada shall adopt compute-to-data as the default operating principle for restricted, sensitive, confidential, controlled-room, clean-room, or sovereign-sensitive data.

101.3.2 Compute-to-data means that analysis, processing, modeling, and transformation occur within the environment where the data resides, rather than moving the data to external systems or users.

101.3.3 This approach reduces exposure risk, preserves sovereignty, minimizes duplication, and maintains alignment between data, context, and applicable controls.

101.3.4 Under this principle: (a) users access controlled environments rather than extracting datasets; (b) outputs are governed and bounded before leaving the environment; (c) intermediate states remain within protected zones; and (d) logs and controls remain co-located with the data.

101.3.5 No person may export raw or high-sensitivity data for convenience where compute-to-data architecture can support the required function.

101.3.6 Exceptions to compute-to-data shall require explicit justification, risk review, and recorded authority.


101.4.1 GCRI Canada shall prohibit cross-border transfer of personal, rights-bearing, sovereign-sensitive, or otherwise protected data unless such transfer has undergone recorded legal, safeguards, and classification review.

101.4.2 Cross-border transfer includes physical movement, digital transmission, remote access equivalent to export, cloud replication across jurisdictions, or any technical process that places data under a different legal or sovereignty regime.

101.4.3 Before transfer, the Corporation shall assess: (a) legal permissibility; (b) safeguards adequacy in the receiving environment; (c) purpose necessity; (d) risks of exposure, misuse, or loss of control; and (e) whether compute-to-data or alternative architectures could avoid transfer.

101.4.4 No transfer shall proceed where the legal basis is unclear, safeguards are insufficient, or sovereignty protections would be materially weakened.

101.4.5 Emergency transfers may occur only under strict necessity and must be promptly recorded, reviewed, and regularized.


101.5 Logging, Approval, and Reconciliation of Cross-Border Access and Processing

101.5.1 All cross-border access and processing events involving protected data shall be logged, attributable, and subject to approval consistent with classification and access governance rules.

101.5.2 Logs shall record: (a) identity of accessing party; (b) jurisdiction of origin and destination; (c) data classes involved; (d) purpose of access; (e) duration and scope of processing; and (f) any transformation or output produced.

101.5.3 The Corporation shall periodically reconcile cross-border activities to ensure they remain within approved scope and that no unauthorized or unrecorded transfers have occurred.

101.5.4 Any discrepancy between approved and actual cross-border activity shall be treated as a security and privacy incident.


101.6 Exit, Suspension, and Continuity Rules for Sovereign Data Environments

101.6.1 GCRI Canada shall define exit, suspension, and continuity rules for SDZs and other sovereign data environments to ensure that data remains protected, recoverable, and lawfully handled in the event of system change, contract termination, jurisdictional shift, or operational disruption.

101.6.2 Exit rules shall specify how data is: (a) returned to sovereign control; (b) securely migrated to an equivalent protected environment; (c) archived under lawful conditions; or (d) securely destroyed where appropriate.

101.6.3 Suspension rules shall define how access is restricted or halted while preserving integrity and preventing loss.

101.6.4 Continuity rules shall ensure that critical governance, evidence, and safeguards functions are not interrupted by infrastructure changes.

101.6.5 No exit or migration process shall result in uncontrolled duplication, loss of custody trace, or weakening of classification and access controls.


101.7 No Architectural Design That Defeats Sovereignty Protections by Default

101.7.1 GCRI Canada shall prohibit architectural designs, system integrations, or platform dependencies that inherently defeat or undermine sovereignty protections, localization requirements, or SDZ controls.

101.7.2 This includes, without limitation: (a) centralized architectures requiring bulk data export; (b) tools that cannot operate within SDZ constraints; (c) vendor solutions requiring uncontrolled data replication; (d) default cross-border storage or processing; and (e) hidden or non-configurable data flows.

101.7.3 All systems and tools shall be evaluated for compatibility with sovereign data governance before adoption or integration.

101.7.4 Where a tool cannot meet sovereignty requirements, it shall not be used for protected data unless compensating controls are sufficient and formally approved.


101.8 Coordination With Hosts, Governments, and National Entities on Data Jurisdiction Matters

101.8.1 GCRI Canada shall coordinate with host institutions, governments, national entities, and relevant stakeholders on data jurisdiction, sovereignty, and localization matters where its operations intersect with sovereign contexts.

101.8.2 Coordination shall aim to: (a) align handling practices with local legal and institutional expectations; (b) ensure clarity of roles and responsibilities; (c) prevent jurisdictional conflict; and (d) maintain trust and legitimacy in cross-border and multi-entity operations.

101.8.3 No assumption shall be made that institutional standards alone suffice in sovereign contexts. Local alignment is a required component of lawful and legitimate operation.