For the complete documentation index, see llms.txt. This page is also available as Markdown.

XIII. DATA

13.1 Privacy and Data Rights as Constitutional Safeguards

13.1.1 Privacy as a Charter-Level Public-Benefit Safeguard. 13.1.1(a) Privacy shall be a Charter-level public-benefit safeguard of GCRI Canada and shall apply to all data, records, research, evidence, observability, ontology, AI, compute, dashboards, maps, publications, software, technical baselines, public authority learning, Academy materials, controlled rooms, clean rooms, data rooms, evidence rooms, Nexus interfaces, and public-safe outputs that may affect persons, communities, public authorities, Indigenous knowledge holders, protected participants, vulnerable groups, confidential sources, or public trust.

13.1.1(b) Privacy shall be treated as a constitutional stewardship obligation, not merely an administrative compliance function, contractual notice exercise, security checklist, consent form, publication redaction task, or downstream legal review. It shall be embedded at the point of data conception, collection, receipt, creation, processing, analysis, storage, transfer, sharing, publication, correction, retention, sealing, archival, and destruction.

13.1.1(c) GCRI Canada shall not pursue evidence, observability, technical truth, AI-enabled analysis, public-good software, technical baselines, dashboards, maps, or Nexus interoperability in a manner that treats privacy as secondary to research convenience, sponsor interest, provider capability, public authority curiosity, finance readability, media visibility, or technical excitement.

13.1.1(d) Privacy safeguards shall preserve dignity, autonomy, contextual integrity, lawful purpose, data minimization, access limitation, use limitation, disclosure limitation, correctionability, and public-safe publication.

13.1.1(e) The controlling rule shall be that GCRI Canada’s evidence function must become more trustworthy because it protects privacy, not less effective because it ignores privacy.


13.1.2 Data Rights as Governance Obligations, Not Optional Administrative Controls. 13.1.2(a) Data rights shall be governance obligations of GCRI Canada and shall not be treated as optional administrative controls, post-hoc compliance steps, technical preferences, publication filters, or discretionary courtesy practices.

13.1.2(b) Data rights may include rights, interests, duties, restrictions, expectations, permissions, conditions, limitations, withdrawal pathways, grievance pathways, correction pathways, access limits, use limits, disclosure limits, deletion or sealing requirements, and community or protected knowledge obligations arising under law, contract, ethics, public authority permission, community protocol, Indigenous or protected knowledge safeguards, research protocol, data agreement, or public-safe publication rules.

13.1.2(c) GCRI Canada shall maintain data governance practices capable of identifying whose rights, interests, duties, permissions, or safeguards may be implicated by data use, including individuals, communities, public authorities, Indigenous knowledge holders, local knowledge holders, territorial knowledge holders, protected participants, whistleblowers, confidential sources, universities, providers, sponsors, hosts, partners, National Companies, Project SPVs, GRF, GRA, Protocol Authority, and Nexus entities.

13.1.2(d) Data rights shall travel with data through derived data, synthetic data, aggregated data, de-identified data, metadata, embeddings, feature stores, retrieval indexes, model outputs, dashboards, maps, publications, public-safe summaries, evidence packs, decision packs, software releases, APIs, schemas, and technical baselines unless lawfully and properly reviewed otherwise.

13.1.2(e) The controlling rule shall be that data rights must be governed as institutional obligations before data becomes evidence, output, publication, model input, or public-safe claim.


13.1.3 Rights-Bearing Data as Data Capable of Affecting Persons, Communities, Public Authorities, Indigenous Knowledge Holders, Vulnerable Groups, Protected Participants, or Public Trust. 13.1.3(a) Rights-bearing data shall mean data, metadata, derived data, linked data, inferred data, model output, dashboard output, map output, AI output, or publication content capable of affecting persons, communities, public authorities, Indigenous knowledge holders, vulnerable groups, protected participants, confidential sources, whistleblowers, protected persons, or public trust.

13.1.3(b) Rights-bearing data shall include personal information, health-sensitive data, public authority data, community-protected information, Indigenous knowledge where applicable, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, geospatial data, sensitive-location data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, commercially sensitive data, confidential source information, whistleblower information, public participation records, and protected knowledge.

13.1.3(c) Data may be rights-bearing even where it does not directly identify an individual, where linkage, inference, geospatial precision, temporal precision, group attributes, community context, public authority context, AI modeling, or mosaic effects may create harm, stigma, exposure, discrimination, surveillance, retaliation, extraction, public authority confusion, or public-safe risk.

13.1.3(d) Rights-bearing status shall require classification, purpose review, access controls, public-safe review, AI-use review, retention controls, correction path, and safeguards proportionate to risk.

13.1.3(e) The controlling rule shall be that data shall be treated as rights-bearing where its misuse could affect rights, dignity, safety, authority, trust, or protected knowledge, even if it appears technically non-personal.


13.1.4 Privacy as Applicable to Research, Evidence, Observability, AI, Compute, Dashboards, Maps, Publications, Public Authority Learning, Academy Materials, Software, Technical Baselines, and Nexus Interfaces. 13.1.4(a) Privacy shall apply to research, evidence intake, evidence records, evidence packs, decision packs, observability methods, Observatory outputs, Truth Engine outputs, AI-assisted research, model use, compute workloads, dashboards, maps, publications, public-safe summaries, public authority learning materials, Academy materials, software, APIs, schemas, data contracts, technical baselines, technical notes, datasets, benchmark sets, evaluation harnesses, controlled rooms, clean rooms, data rooms, evidence rooms, and Nexus interfaces.

13.1.4(b) Privacy controls shall apply whether data is collected directly, received from third parties, generated by sensors, generated by AI-RAN or O-RAN systems, generated by DePIN systems, generated by digital twins, derived from cyber logs, derived from satellite or Earth observation systems, extracted from documents, provided by public authorities, provided by communities, provided by providers, provided by sponsors, produced through research, or obtained from public sources.

13.1.4(c) Privacy shall apply to operational workflows as well as final outputs, including drafts, notes, prompts, embeddings, retrieval indexes, logs, screenshots, code examples, test data, sample files, backups, archives, public-safe summaries, and correction records.

13.1.4(d) Privacy review shall not be bypassed by describing an activity as technical prototyping, research support, visualization, public-good software development, dashboard preparation, public-safe publication, Academy training, or Nexus interoperability.

13.1.4(e) The controlling rule shall be that privacy follows data and data-derived meaning across the full GCRI Canada lifecycle.


13.1.5 Privacy as Applicable Across Personal, Health-Sensitive, Community-Protected, Public Authority, Infrastructure-Sensitive, Cyber-Sensitive, Finance-Sensitive, Commercially Sensitive, and Protected Knowledge Contexts. 13.1.5(a) Privacy and data rights safeguards shall apply across personal, health-sensitive, rights-bearing, community-protected, Indigenous, local, territorial, cultural, environmental, public authority, infrastructure-sensitive, cyber-sensitive, finance-sensitive, commercially sensitive, confidential source, whistleblower, and protected knowledge contexts.

13.1.5(b) Personal and health-sensitive contexts shall require heightened review for dignity, consent or lawful basis, minimization, access control, de-identification or aggregation where appropriate, AI-use restrictions, re-identification risk, publication risk, retention limits, correction, and deletion or sealing where required.

13.1.5(c) Community-protected and protected knowledge contexts shall require safeguards, consent or non-consent treatment where applicable, community review where appropriate, attribution or non-attribution controls, geospatial controls, AI-use restrictions, publication limits, withdrawal pathways, grievance pathways, remedy pathways, and correction.

13.1.5(d) Public authority contexts shall require capacity classification, authority or permission record, confidentiality, public-safe status, reference controls, no-delegation language, no-endorsement language, no-public-warning language, and no-public-authority-effect language.

13.1.5(e) Infrastructure-sensitive and cyber-sensitive contexts shall require security classification, need-to-know access, controlled disclosure, public-safe technical handling, secure collaboration, no-public-repository controls, and incident response.

13.1.5(f) Finance-sensitive and commercially sensitive contexts shall require purpose limitation, access controls, conflict review, finance-boundary review, public-safe review, and protection against data use that creates investment advice, finance-readiness, provider preference, sponsor control, or market signal by implication.

13.1.5(g) The controlling rule shall be that privacy is not limited to personal data; it includes any data context where exposure or misuse may create rights, safety, authority, or trust harm.


13.1.6 Privacy as Compatible With Evidence Stewardship Only Where Lawful, Necessary, Proportionate, Bounded, Classified, Secured, and Correctionable. 13.1.6(a) Privacy shall be compatible with evidence stewardship only where data collection, receipt, processing, analysis, storage, transfer, sharing, publication, retention, and correction are lawful, necessary, proportionate, bounded, classified, secured, and correctionable.

13.1.6(b) Lawfulness shall require a lawful, contractual, consent, research, public authority, community, protected knowledge, public-benefit, or other approval basis where applicable.

13.1.6(c) Necessity shall require that the data is reasonably required for the recorded purpose and that less intrusive alternatives have been considered where risk is material.

13.1.6(d) Proportionality shall require that the evidence value, public-benefit value, technical value, public authority learning value, or Nexus interoperability value justify the privacy, rights, public-safe, cybersecurity, protected knowledge, and public trust risk.

13.1.6(e) Boundedness shall require purpose limits, access limits, use limits, transfer limits, publication limits, retention limits, AI-use limits, and correction paths.

13.1.6(f) Classification shall require data class, handling class, access class, release class, retention class, public-safe status, and sensitivity status appropriate to the data and context.

13.1.6(g) Security shall require technical, organizational, contractual, and procedural controls proportionate to risk.

13.1.6(h) Correctionability shall require that erroneous, outdated, overbroad, unauthorized, unsafe, or misclassified data and data-derived outputs can be corrected, restricted, withdrawn, retracted, sealed, deleted where lawful and required, or archived.

13.1.6(i) The controlling rule shall be that evidence stewardship may use data only within a privacy-valid governance envelope.


13.1.7 Privacy as Anti-Extraction, Anti-Surveillance, Anti-Function-Creep, and Anti-Overexposure Discipline. 13.1.7(a) Privacy shall operate as anti-extraction, anti-surveillance, anti-function-creep, and anti-overexposure discipline within GCRI Canada.

13.1.7(b) Anti-extraction discipline shall prohibit collection, use, modeling, mapping, publishing, or reuse of data from persons, communities, public authorities, Indigenous knowledge holders, protected participants, vulnerable groups, hosts, or partners in a manner that extracts value without lawful purpose, safeguards, context, reciprocity where appropriate, or correction path.

13.1.7(c) Anti-surveillance discipline shall prohibit research, observability, dashboards, maps, AI systems, sensors, AI-RAN, DePIN, digital twins, cyber logs, or public authority interfaces from being used to monitor, profile, target, rank, police, discipline, or expose persons or communities beyond recorded lawful and public-benefit purposes.

13.1.7(d) Anti-function-creep discipline shall prohibit data collected for one purpose from being reused for another purpose, including AI training, finance-facing use, provider development, sponsor benefit, public authority sharing, public release, dashboarding, mapping, benchmarking, or Nexus interface use, without recorded authority and review.

13.1.7(e) Anti-overexposure discipline shall require GCRI Canada to reduce unnecessary detail, precision, access, visibility, linkage, publication, geospatial resolution, and retention where such exposure is not necessary or public-safe.

13.1.7(f) The controlling rule shall be that privacy protects public-good evidence from becoming extraction, surveillance, uncontrolled reuse, or harmful visibility.


13.1.8 Privacy as Public-Safe Publication Requirement. 13.1.8(a) Privacy shall be a public-safe publication requirement for all external publications, public-safe summaries, dashboards, maps, datasets, technical releases, API documentation, software examples, Academy materials, public authority learning materials, media statements, social media statements, website materials, sponsor materials, provider materials, and Nexus interface materials.

13.1.8(b) Public-safe publication review shall assess whether publication may expose personal information, rights-bearing data, health-sensitive data, public authority data, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive information, commercially sensitive information, community-protected information, Indigenous or protected knowledge, confidential sources, whistleblowers, sensitive locations, controlled technology, unsafe metadata, or re-identification pathways.

13.1.8(c) Public-safe publication may require redaction, aggregation, generalization, delay, masking, controlled annexes, restricted annexes, synthetic data, metadata-only release, no-map release, no-dashboard release, or refusal of publication.

13.1.8(d) Privacy-related public-safe publication decisions shall be recorded where material and shall include correction path.

13.1.8(e) The controlling rule shall be that publication shall not be public-safe unless privacy and data rights have been reviewed and protected.


13.1.9 Privacy as Data Minimization, Purpose Limitation, Access Limitation, Retention Limitation, and Disclosure Limitation. 13.1.9(a) Privacy shall require data minimization, purpose limitation, access limitation, retention limitation, disclosure limitation, transfer limitation, AI-use limitation, and publication limitation.

13.1.9(b) Data minimization shall require GCRI Canada to collect, receive, generate, process, link, store, map, dashboard, analyze, publish, or retain only the data reasonably necessary and proportionate for the recorded purpose.

13.1.9(c) Purpose limitation shall require data to be used only for recorded and authorized purposes and not repurposed by convenience, technical possibility, sponsor interest, provider usefulness, public authority curiosity, finance readability, or Nexus interoperability demand.

13.1.9(d) Access limitation shall require role-based, least-privilege, purpose-bound, time-limited where appropriate, logged where material, and revocable access.

13.1.9(e) Retention limitation shall require data to be retained only for lawful, necessary, mission-justified, audit, research integrity, correctionability, legal hold, or archival reasons, and not retained merely because storage is inexpensive or future use is possible.

13.1.9(f) Disclosure limitation shall require external sharing, publication, dashboarding, mapping, API access, dataset release, and annex distribution to be limited to approved recipients, approved purposes, approved forms, approved classifications, and approved public-safe status.

13.1.9(g) The controlling rule shall be that privacy is operationalized through limits, not merely through statements of principle.


13.1.10 Privacy as Board, Officer, Committee, Program, Research, Technical, Publication, and Participant Responsibility. 13.1.10(a) Privacy and data rights shall be responsibilities of the Board, officers, committees, research leads, program leads, technical leads, publication authorities, data custodians, cybersecurity stewards, public-safe reviewers, safeguards reviewers, staff, fellows, advisors, contributors, contractors, members, participants, councils, sponsors, providers, hosts, partners, and any other actor with access to GCRI Canada data or data-derived records.

13.1.10(b) The Board shall oversee privacy and data rights as mission, risk, public-benefit, and trust safeguards. Officers shall implement privacy controls through delegations, policies, procedures, records, training, incident response, and assurance. Committees shall review privacy matters within mandate. Program, research, technical, and publication leaders shall implement privacy controls in daily work.

13.1.10(c) Participants and contributors shall comply with confidentiality, classification, access, AI-use, public-safe publication, cybersecurity, protected knowledge, and correction rules.

13.1.10(d) Sponsors, providers, hosts, partners, universities, public authorities, and other external actors shall comply with data-use, confidentiality, public-safe, access, AI-use, correction, and role-boundary terms when receiving or contributing data.

13.1.10(e) Privacy failures shall be treated as governance, data, research, publication, cybersecurity, safeguards, or public-safe incidents as applicable.

13.1.10(f) The controlling rule shall be that privacy responsibility is distributed across roles but cannot be diluted by distributed responsibility.


13.2 Data Governance Purpose

13.2.1 Data Governance as Public-Good Stewardship Function. 13.2.1(a) Data governance shall be a public-good stewardship function of GCRI Canada and shall govern the collection, receipt, creation, processing, analysis, storage, transfer, publication, sharing, licensing, deletion, sealing, archival, destruction, correction, and reuse of data and data-derived materials.

13.2.1(b) Data governance shall ensure that data supports GCRI Canada’s evidence, methods, observability, ontology, public-good R&D, public-good software, Open Technical Baseline, public-safe publication, public authority learning, Academy, and Nexus interface functions without becoming extraction, surveillance, market data brokerage, public authority substitution, finance execution, provider preference, sponsor control, or unbounded technical reuse.

13.2.1(c) Data governance shall preserve lawful authority, purpose limitation, minimization, classification, access control, security, source lineage, public-safe status, correctionability, retention discipline, and public trust.

13.2.1(d) Data governance shall apply to all data forms, all data sources, all data environments, all publication classes, and all Nexus interfaces within GCRI Canada’s scope.

13.2.1(e) The controlling rule shall be that GCRI Canada stewards data to support public-good truth, not to accumulate data for its own sake.


13.2.2 Data Governance as Legal, Technical, Ethical, Public Authority, Research, Community, and Cybersecurity Control. 13.2.2(a) Data governance shall operate as a legal, technical, ethical, public authority, research, community, and cybersecurity control.

13.2.2(b) As a legal control, data governance shall address lawful basis, authority, consent where applicable, contracts, public authority permissions, privacy, IP, licensing, confidentiality, sanctions, export controls, controlled technology, liability, retention, deletion, legal hold, and disclosure.

13.2.2(c) As a technical control, data governance shall address architecture, access control, encryption where appropriate, secure storage, secure transfer, logging, data quality, lineage, metadata, APIs, schemas, data contracts, model interfaces, dashboards, maps, repositories, backups, and incident response.

13.2.2(d) As an ethical control, data governance shall address dignity, proportionality, contextual integrity, consent or non-consent where applicable, vulnerable groups, protected participants, protected knowledge, public-safe publication, and do-no-harm.

13.2.2(e) As a public authority control, data governance shall address capacity classification, public authority data permissions, public authority references, no-delegation, no-endorsement, no-public-warning, no-procurement, no-public-finance, and sovereign obligation boundaries.

13.2.2(f) As a research control, data governance shall address research protocols, source lineage, method integrity, reproducibility where appropriate, peer review, AI use, publication class, and correction path.

13.2.2(g) As a community control, data governance shall address Indigenous, local, territorial, cultural, environmental, community-protected, and protected knowledge safeguards, withdrawal, grievance, remedy, attribution, non-attribution, and correction.

13.2.2(h) As a cybersecurity control, data governance shall address cyber-sensitive data, infrastructure-sensitive data, secure collaboration, secrets, credentials, vulnerability exposure, controlled disclosure, and secure release.

13.2.2(i) The controlling rule shall be that data governance must be multi-disciplinary because data risk is never merely technical.


13.2.3 Data Governance as Applicable to Collection, Receipt, Creation, Processing, Analysis, Storage, Transfer, Publication, Sharing, Licensing, Deletion, Sealing, Archival, and Destruction. 13.2.3(a) Data governance shall apply throughout the data lifecycle, including collection, receipt, creation, generation, derivation, transformation, processing, analysis, linkage, enrichment, modeling, storage, indexing, embedding, retrieval, transfer, sharing, publication, licensing, access, export, retention, correction, deletion, sealing, archival, and destruction.

13.2.3(b) Collection and receipt shall require authority, purpose, source lineage, classification, minimization, access limits, and initial risk review.

13.2.3(c) Creation and generation shall include derived data, model outputs, AI outputs, synthetic data, aggregated data, metadata, embeddings, feature stores, logs, dashboards, maps, reports, and public-safe summaries, all of which shall inherit governance requirements from source materials unless reviewed otherwise.

13.2.3(d) Processing and analysis shall require method discipline, access controls, AI-use controls, cybersecurity controls, public authority controls, protected knowledge controls, and auditability where material.

13.2.3(e) Storage and transfer shall require secure environments, permitted locations, cross-border review where applicable, sovereign data zone review where applicable, logging where material, and retention controls.

13.2.3(f) Publication and sharing shall require public-safe review, release class, access class, use terms, boundary language, and correction path.

13.2.3(g) Licensing shall require IP, data rights, public authority permission, protected knowledge, commercial use, AI-use, redistribution, attribution, anti-enclosure, and public-good purpose review.

13.2.3(h) Deletion, sealing, archival, and destruction shall be governed by law, protocol, records requirements, legal hold, correctionability, public-safe obligations, and data rights.

13.2.3(i) The controlling rule shall be that data governance begins before collection and continues beyond publication.


13.2.4 Data Governance as Applicable to Raw Data, Derived Data, Synthetic Data, Aggregated Data, De-Identified Data, Metadata, Embeddings, Feature Stores, Logs, Model Outputs, Dashboard Outputs, Maps, Reports, and Public-Safe Summaries. 13.2.4(a) Data governance shall apply to raw data, derived data, synthetic data, aggregated data, de-identified data, pseudonymized data, anonymized data where claimed, metadata, embeddings, feature stores, retrieval indexes, logs, model inputs, model outputs, AI outputs, dashboard outputs, map outputs, reports, public-safe summaries, benchmark sets, evaluation sets, and technical release examples.

13.2.4(b) Derived data shall inherit source restrictions unless reviewed and lawfully transformed. Synthetic data shall be labeled and reviewed for re-identification or reconstruction risk. Aggregated data shall be reviewed for small-cell, geospatial, temporal, and mosaic risks. De-identified data shall be reviewed for re-identification risk before release or reuse.

13.2.4(c) Metadata, logs, prompts, embeddings, and retrieval indexes shall be treated as potentially sensitive because they may reveal source content, user behavior, public authority data, protected knowledge, model configuration, cyber-sensitive details, or confidential context.

13.2.4(d) Model outputs, dashboard outputs, maps, reports, and public-safe summaries shall be treated as data-derived materials subject to source-lineage, public-safe, classification, and correction controls.

13.2.4(e) The controlling rule shall be that governance does not end when data changes form.


13.2.5 Data Governance as Applicable to Data From Public Authorities, Communities, Indigenous Knowledge Holders, Universities, Providers, Sponsors, Hosts, National Companies, Project SPVs, Sensors, AI-RAN Systems, DePIN Systems, Digital Twins, Cyber Systems, and Public Sources. 13.2.5(a) Data governance shall apply to data from public authorities, communities, Indigenous knowledge holders where applicable, local knowledge holders, territorial knowledge holders, universities, laboratories, providers, sponsors, hosts, donors, funders, partners, National Companies, Project SPVs, sensors, AI-RAN systems, O-RAN systems, private wireless systems, DePIN systems, blockchain or distributed ledger systems, digital twins, cyber systems, operational technology systems, public sources, media sources, open data portals, field observations, satellite systems, and Earth observation systems.

13.2.5(b) Public authority data shall require authority or permission records, capacity classification, permitted use, prohibited use, confidentiality, public-safe status, publication controls, AI-use controls, retention, transfer, and correction path.

13.2.5(c) Community and protected knowledge data shall require safeguards, consent or non-consent treatment where applicable, attribution or non-attribution controls, community review where appropriate, public-safe mapping controls, grievance, remedy, withdrawal, and correction.

13.2.5(d) University, provider, sponsor, host, National Company, Project SPV, and partner data shall require contribution records, rights review, conflict review, role-boundary review, IP and license review, confidentiality, public-safe review, and anti-capture controls.

13.2.5(e) Sensor, AI-RAN, DePIN, digital twin, cyber, and technical system data shall require technical classification, source-lineage records, security review, data quality review, model or system limitations, public-safe status, and correction path.

13.2.5(f) Public source and open data shall still require contextual integrity, source reliability, public-safe review, rights review where applicable, and misuse-risk review before institutional use or publication.

13.2.5(g) The controlling rule shall be that data source affects governance, and no source category is governance-free.


13.2.6 Data Governance as Distinct From Data Ownership Claims Where Data Is Stewarded, Licensed, Contributed, Permissioned, Publicly Available, or Protected. 13.2.6(a) Data governance shall be distinct from data ownership claims. GCRI Canada may steward, receive, access, process, analyze, hold, publish, license, or correct data without claiming ownership over all underlying data or knowledge.

13.2.6(b) Data may be owned, licensed, contributed, permissioned, publicly available, restricted, protected, community-governed, public authority-governed, university-governed, provider-governed, host-governed, sponsor-contributed, or subject to mixed rights and obligations.

13.2.6(c) GCRI Canada shall not claim ownership over Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, community-protected information, public authority data, provider data, sponsor data, host data, confidential source information, or third-party data beyond lawful stewardship, license, contribution, or record rights.

13.2.6(d) Data governance records shall distinguish owner, contributor, licensor, source, custodian, processor, steward, maintainer, access holder, publication authority, and correction authority where material.

13.2.6(e) The controlling rule shall be that GCRI Canada’s duty to govern data does not require, and shall not imply, ownership of data or protected knowledge.


13.2.7 Data Governance as a Condition of Nexus Interoperability. 13.2.7(a) Data governance shall be a condition of Nexus interoperability. Data shall not be exchanged, routed, transformed, mapped, interpreted, embedded, indexed, dashboarded, or published across Nexus interfaces unless authority, purpose, classification, access, handling, public-safe status, semantic meaning, and correction path are established.

13.2.7(b) Nexus interoperability may involve GRF, GRA, Protocol Authority, Nexus Observatory, Nexus Truth Engine, Nexus Rails, Nexus Grid, Nexus Academy, National Consortiums, National Companies, Project SPVs, providers, hosts, public authorities, universities, communities, and other Nexus entities.

13.2.7(c) Interoperability shall not override privacy, public authority restrictions, protected knowledge safeguards, finance-boundary controls, cybersecurity controls, export controls, sanctions controls, controlled technology limits, or data rights.

13.2.7(d) Shared schemas, APIs, data contracts, ontologies, controlled vocabularies, technical baselines, proof receipts, dashboards, and evidence packs shall preserve source authority, role boundaries, classification, and correctionability.

13.2.7(e) The controlling rule shall be that Nexus interoperability depends on governed data, not merely compatible systems.


13.2.8 Data Governance as a Condition of Verifiable Compute and Verifiable Intelligence. 13.2.8(a) Data governance shall be a condition of verifiable compute and verifiable intelligence. Compute workloads, model runs, inference records, proof receipts, logs, datasets, prompts, retrieval configurations, embeddings, feature stores, outputs, and audit trails shall be governed before they are treated as verifiable or institutionally usable.

13.2.8(b) Verifiability shall not override data rights, privacy, protected knowledge, public authority restrictions, cybersecurity, or public-safe publication. Hashes, signatures, timestamps, proof receipts, blockchain anchors, DePIN records, or compute attestations shall not create substantive authority by default.

13.2.8(c) Verifiable compute records shall identify data sources, data classes, lawful or approval basis, permitted use, model or compute environment, access controls, output class, public-safe status, and correction path where material.

13.2.8(d) Verifiable intelligence outputs shall be subject to human review, source verification, method review, AI-use controls, hallucination controls, bias controls, public-safe review, and correctionability.

13.2.8(e) The controlling rule shall be that verifiability without data governance is technical traceability without institutional trust.


13.2.9 Data Governance as a Condition of Public-Safe Publication. 13.2.9(a) Data governance shall be a condition of public-safe publication. No publication, dashboard, map, dataset, API, schema, software release, technical note, report, public-safe summary, Academy material, media statement, or Nexus interface output shall be released externally unless data governance requirements applicable to the underlying data and data-derived materials have been satisfied.

13.2.9(b) Public-safe publication shall require review of data source, data class, lawful or approval basis, purpose, minimization, access, retention, transfer, public authority restrictions, AI use, cybersecurity, protected knowledge, re-identification risk, sensitive-location risk, publication class, and correction path.

13.2.9(c) Where data governance review is incomplete, publication shall be held, narrowed, redacted, aggregated, generalized, restricted, converted to public-safe summary, or refused.

13.2.9(d) Public-safe publication status shall be reviewed when data sources, classifications, permissions, public authority roles, sponsor roles, provider roles, model outputs, dashboards, maps, or correction status changes.

13.2.9(e) The controlling rule shall be that public-safe publication is impossible without governed data.


13.2.10 Data Governance as a Condition of Institutional Trust. 13.2.10(a) Data governance shall be a condition of institutional trust in GCRI Canada and shall protect the legitimacy of GCRI Canada’s evidence, methods, observability, ontology, public-good software, technical baselines, public-safe publication, public authority learning, Academy, and Nexus interface functions.

13.2.10(b) Weak data governance may create privacy harm, public authority confusion, community harm, protected knowledge exposure, cybersecurity risk, finance overclaim, provider preference, sponsor capture, research error, publication defect, AI misuse, map harm, dashboard harm, dataset misuse, and loss of public trust.

13.2.10(c) GCRI Canada shall treat data governance failures as institutional integrity risks, not merely administrative defects.

13.2.10(d) Data governance shall be subject to training, records, registers, incident response, assurance, Board or committee reporting where material, and correctionability.

13.2.10(e) The controlling rule shall be that public-good truth depends on trust, and trust depends on disciplined data governance.


13.3 Lawful Basis and Authority for Data

13.3.1 Lawful Basis Required for Material Data Collection, Processing, Sharing, Publication, Transfer, or Retention. 13.3.1(a) GCRI Canada shall require a lawful basis, approval basis, contractual basis, consent basis, research basis, public authority permission, community authority, protected knowledge authority, legitimate public-benefit basis where lawful, or other recorded authority for material data collection, receipt, creation, processing, analysis, storage, sharing, publication, transfer, retention, deletion, sealing, archival, or destruction.

13.3.1(b) Lawful basis and authority shall be established before material data use begins, except where urgent safeguarding, incident response, legal preservation, or emergency record procedures permit limited preliminary action subject to prompt review.

13.3.1(c) Data shall not be used merely because it is available, publicly accessible, technically obtainable, sponsor-provided, provider-provided, public authority-adjacent, dashboard-accessible, AI-generated, found online, scraped, stored in a repository, or previously used for another project.

13.3.1(d) Lawful basis records shall identify data source, data type, authority, purpose, scope, classification, access, handling, retention, transfer, AI-use status, publication status, public-safe status, restrictions, and correction path.

13.3.1(e) The controlling rule shall be that material data must have a recorded path into use.


13.3.2 Contractual Authority. 13.3.2(a) Contractual authority may support data collection, receipt, processing, sharing, publication, transfer, retention, or deletion where an agreement, data sharing agreement, research agreement, grant agreement, sponsorship agreement, provider agreement, host agreement, university agreement, public authority agreement, partner agreement, contributor agreement, license, or other instrument grants or defines data rights and obligations.

13.3.2(b) Contractual authority shall be reviewed for purpose, scope, permitted use, prohibited use, confidentiality, access, security, AI use, publication, sublicensing, onward transfer, cross-border transfer, retention, deletion, audit, incident notice, public authority limits, protected knowledge limits, IP, license, and correction.

13.3.2(c) Contractual authority shall not override law, privacy rights, community safeguards, public authority restrictions, cybersecurity, export controls, sanctions, controlled technology limits, protected knowledge obligations, or GCRI Canada’s mission lock.

13.3.2(d) Where contractual language is ambiguous, GCRI Canada shall apply the narrower, more protective interpretation until clarified by record.

13.3.2(e) The controlling rule shall be that contractual access is not unrestricted use.


13.3.3 Consent Where Applicable. 13.3.3(a) Consent shall be obtained where applicable by law, ethics, research protocol, community protocol, data agreement, public authority requirement, partner requirement, or safeguards review.

13.3.3(b) Consent shall be informed, purpose-specific, role-appropriate, documented where required, understandable, accessible, time-bounded where appropriate, and linked to withdrawal, grievance, remedy, data use, AI use, publication, retention, transfer, and correction treatment.

13.3.3(c) Consent shall not be bundled, coerced, implied by attendance, inferred from silence, extracted through power imbalance, or used to justify uses beyond the recorded purpose.

13.3.3(d) Non-consent, refusal, restriction, or withdrawal shall be respected according to law, ethics, research integrity, community safeguards, public-safe obligations, and applicable records.

13.3.3(e) Consent records shall identify the consenting party, authority to consent where relevant, scope, date, purpose, permitted uses, prohibited uses, withdrawal conditions, publication status, AI-use status, and correction path.

13.3.3(f) The controlling rule shall be that consent supports data use only within the consent actually given.


13.3.4 Research Authority Where Applicable. 13.3.4(a) Research authority may support data use where an approved research protocol, ethics approval where required, university review, public-benefit research basis, community review where appropriate, data governance review, or Board or committee approval authorizes the data use.

13.3.4(b) Research authority shall identify research question, public-benefit purpose, data sources, data classes, methods, access, AI use, retention, transfer, publication, public-safe status, safeguards, review status, and correction path.

13.3.4(c) Research authority shall not permit data use for unrelated publication, finance-facing materials, provider development, sponsor benefit, AI training, model improvement, public authority sharing, or external release unless separately authorized.

13.3.4(d) Research authority shall be suspended, narrowed, or corrected where protocol conditions are breached, ethics review is missing or violated, data use exceeds scope, public-safe risk emerges, or protected knowledge risk emerges.

13.3.4(e) The controlling rule shall be that research authority is bounded by protocol and does not create general data authority.


13.3.5 Public Authority Permission Where Applicable. 13.3.5(a) Public authority permission shall be required where data is received from, generated with, derived from, referring to, or materially involving public authorities, public programs, public finance, public infrastructure, public health, public safety, emergency management, regulatory activity, procurement, or public authority learning.

13.3.5(b) Public authority permission records shall identify source, authority basis, authorized representative where applicable, capacity classification, permitted use, prohibited use, confidentiality, publication permission, AI-use limits, transfer limits, retention, public-safe status, reference approval, and correction path.

13.3.5(c) Public authority permission shall not create public authority endorsement, adoption, approval, procurement approval, funding approval, regulatory approval, public finance approval, official guidance, public warning, emergency command, sovereign obligation, or public-law status unless a competent public authority record separately creates such effect.

13.3.5(d) Public authority data shall not be repurposed for finance-facing materials, provider materials, sponsor materials, public claims, AI training, dashboards, maps, datasets, or Nexus interfaces beyond recorded permission and review.

13.3.5(e) The controlling rule shall be that public authority data carries public power risk and must remain bounded by permission.


13.3.6 Legitimate Public-Benefit Purpose Where Lawful and Properly Reviewed. 13.3.6(a) A legitimate public-benefit purpose may support data use only where lawful, mission-compatible, necessary, proportionate, recorded, reviewed, and consistent with privacy, data rights, public-safe publication, protected knowledge, community safeguards, public authority boundaries, cybersecurity, and correctionability.

13.3.6(b) Public-benefit purpose may include evidence quality, methods development, observability, ontology, public-good software, technical baselines, public-safe publication, public authority learning, research integrity, community safeguards, systemic de-risking, or Nexus public-good interoperability.

13.3.6(c) Public-benefit purpose shall not be used as a blanket justification for broad data collection, indefinite retention, AI training, surveillance, public release, finance-facing reuse, provider development, sponsor benefit, public authority sharing, or uncontrolled publication.

13.3.6(d) Public-benefit purpose review shall assess necessity, proportionality, data minimization, source context, rights impact, safeguards, public-safe status, and alternatives.

13.3.6(e) The controlling rule shall be that public benefit authorizes only bounded, reviewed, and rights-respecting data use.


13.3.7 Grant, Sponsorship, Host, University, Provider, or Partner Data Authority. 13.3.7(a) Data authority arising from grants, sponsorships, host relationships, university relationships, provider relationships, partner relationships, or in-kind contributions shall be recorded and reviewed before data use.

13.3.7(b) Such authority records shall identify contributor, data source, contribution type, ownership or license status, permitted uses, prohibited uses, confidentiality, IP, publication, AI-use status, retention, transfer, security, public-safe status, conflicts, sponsor non-control, provider neutrality, host boundaries, and correction path.

13.3.7(c) Sponsor, donor, funder, provider, host, university, or partner data contribution shall not give the contributor control over research questions, methods, evidence interpretation, publication, correction, public-safe summaries, technical baselines, public claims, or institutional meaning.

13.3.7(d) Provider or sponsor data shall be reviewed for bias, completeness, conflict, limitations, dependency, validation status, and public-safe use before reliance.

13.3.7(e) The controlling rule shall be that contributed data may support public-good work but shall not purchase truth or control.


13.3.8 Community, Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge Authority. 13.3.8(a) Data involving communities, Indigenous knowledge where applicable, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred sites, sensitive ecological sites, community context, community-protected information, or protected knowledge shall require appropriate authority, safeguards, review, and records before use.

13.3.8(b) Such authority may arise from consent, community protocol, Indigenous or local governance process where applicable, research protocol, partnership agreement, data agreement, protected knowledge agreement, ethical approval, or other recorded and appropriate process.

13.3.8(c) Authority records shall identify knowledge holders or representatives where appropriate, scope, purpose, permitted use, prohibited use, attribution or non-attribution, publication status, mapping limits, AI-use limits, transfer limits, retention, withdrawal, grievance, remedy, and correction path.

13.3.8(d) GCRI Canada shall not claim ownership of protected knowledge beyond lawful stewardship, license, or permission, and shall not use public-benefit purpose to override protected knowledge safeguards.

13.3.8(e) The controlling rule shall be that protected knowledge requires authority grounded in context, not merely institutional access.


13.3.9 Open Data and Public Data Authority Subject to Contextual Integrity and Public-Safe Review. 13.3.9(a) Open data and public data may be used only subject to contextual integrity, source reliability, permitted use, license terms, privacy review, public authority review where applicable, protected knowledge review where applicable, cybersecurity review where applicable, re-identification review, public-safe review, and correction path.

13.3.9(b) Public availability shall not eliminate data rights, ethical obligations, public-safe restrictions, community safeguards, protected knowledge concerns, public authority restrictions, IP rights, database rights, terms of use, or misuse risk.

13.3.9(c) Public data shall not be scraped, linked, enriched, geocoded, modeled, embedded, trained upon, dashboarded, mapped, or republished in a manner inconsistent with context, law, source terms, public-safe status, or GCRI Canada’s mission.

13.3.9(d) Open data used in public-safe outputs shall include source attribution where required, license compliance, limitations, freshness status, and correction path.

13.3.9(e) The controlling rule shall be that public availability is not public-good permission for every use.


13.3.10 No Data Use Without Authority, Scope, Classification, Purpose, Access, Retention, and Correction Record. 13.3.10(a) No material data use shall occur without a record identifying authority, scope, classification, purpose, access, handling, retention, AI-use status where applicable, transfer status where applicable, publication status where applicable, public-safe status where applicable, and correction path.

13.3.10(b) The required record may be a data intake record, research protocol, data agreement, public authority permission record, contribution record, dataset card, data contract, access record, processing record, publication record, or other approved data governance record.

13.3.10(c) Data lacking adequate authority or scope shall be held, quarantined, restricted, returned, deleted where lawful and required, sealed, or not used until governance is resolved.

13.3.10(d) Ambiguous authority shall be escalated, clarified, narrowed, or refused before use.

13.3.10(e) The controlling rule shall be no authority, no scope, no classification, no purpose, no access record, no retention rule, no correction path, no material data use.


13.4 Purpose Limitation and Anti-Function-Creep

13.4.1 Purpose Limitation as Mandatory Data Governance Rule. 13.4.1(a) Purpose limitation shall be a mandatory data governance rule of GCRI Canada. Data shall be collected, received, created, processed, linked, analyzed, stored, shared, published, retained, or transferred only for recorded and authorized purposes.

13.4.1(b) Purpose shall be specific enough to guide data minimization, access, AI use, publication, retention, public-safe review, and correction.

13.4.1(c) Purpose limitation shall apply to raw data, derived data, synthetic data, aggregated data, de-identified data, metadata, embeddings, feature stores, logs, model outputs, dashboards, maps, reports, public-safe summaries, datasets, APIs, schemas, software examples, and technical releases.

13.4.1(d) Purpose shall not be expanded by technical possibility, organizational convenience, sponsor interest, provider usefulness, public authority curiosity, finance readability, media opportunity, or future potential.

13.4.1(e) The controlling rule shall be that data may do only what its recorded purpose permits.


13.4.2 Data Collected for One Purpose Shall Not Be Reused for Another Purpose Without Recorded Authority and Review. 13.4.2(a) Data collected, received, or created for one purpose shall not be reused for another purpose without recorded authority and review.

13.4.2(b) Reuse includes additional research, AI training, fine-tuning, embedding, retrieval, model improvement, publication, dashboarding, mapping, benchmarking, technical release, provider development, sponsor benefit, finance-facing use, public authority sharing, Nexus interface routing, or external release.

13.4.2(c) Reuse review shall assess original purpose, new purpose, lawful or approval basis, consent or non-consent where applicable, public authority permission where applicable, community safeguards, protected knowledge, privacy, cybersecurity, IP, license, classification, public-safe status, and correction path.

13.4.2(d) Where original authority does not support the new purpose, GCRI Canada shall obtain new authority, narrow the use, transform the data, restrict access, or refuse reuse.

13.4.2(e) The controlling rule shall be that a new purpose requires new review.


13.4.3 No Secondary Use for AI Training, Fine-Tuning, Embeddings, Model Improvement, Publication, Finance-Readiness Inputs, Provider Development, Sponsor Benefit, Public Authority Sharing, or External Release Without Authority. 13.4.3(a) GCRI Canada shall not use data for secondary AI training, fine-tuning, embeddings, retrieval, indexing, model improvement, synthetic data generation, publication, finance-readiness inputs, provider development, sponsor benefit, public authority sharing, external release, commercial reuse, or Nexus interface routing without recorded authority.

13.4.3(b) AI-related secondary use shall require AI-use review, data classification, source permission, privacy review, cybersecurity review, model register review, retention review, public-safe review where output may be released, and correction path.

13.4.3(c) Finance-facing secondary use shall require finance-boundary review and shall preserve GRA’s role and regulated perimeter discipline.

13.4.3(d) Provider or sponsor-benefit secondary use shall require conflict review and shall not create provider preference, sponsor control, outcome purchase, or method capture.

13.4.3(e) Public authority sharing shall require public authority permission, capacity classification, lawful basis, confidentiality, public-safe status, and no-delegation boundary review.

13.4.3(f) External release shall require publication, licensing, public-safe, re-identification, protected knowledge, cybersecurity, and data-rights review.

13.4.3(g) The controlling rule shall be that secondary use is prohibited unless authority travels with the data or is newly obtained.


13.4.4 No Function-Creep From Research Into Surveillance. 13.4.4(a) Research data, observability outputs, sensor data, AI-RAN data, DePIN data, cyber logs, digital twin outputs, dashboard data, maps, public authority data, community data, and AI outputs shall not function-creep into surveillance.

13.4.4(b) Surveillance shall include monitoring, tracking, profiling, ranking, targeting, disciplining, policing, exposing, or predicting persons, communities, protected participants, public officials in sensitive roles, vulnerable groups, confidential sources, whistleblowers, or groups beyond recorded lawful and public-benefit purposes.

13.4.4(c) GCRI Canada shall not use research or evidence systems to create watchlists, behavioral profiles, public authority enforcement tools, finance risk profiles of persons, community vulnerability targeting, provider scoring for procurement, or other surveillance-like outputs outside lawful authority and mission.

13.4.4(d) Where research creates surveillance risk, the activity shall be narrowed, redesigned, aggregated, generalized, restricted, subject to safeguards review, or refused.

13.4.4(e) The controlling rule shall be that research shall not become surveillance through data accumulation or analytic power.


13.4.5 No Function-Creep From Observability Into Public Warning by GCRI Canada. 13.4.5(a) Observability data, dashboards, maps, digital twins, sensor outputs, AI-RAN signals, DePIN records, cyber telemetry, geospatial data, model outputs, and public-safe summaries shall not function-creep into public warning by GCRI Canada.

13.4.5(b) GCRI Canada may support observability methods, evidence literacy, public-safe interpretation, and public authority learning, but shall not issue official public warnings, emergency alerts, evacuation notices, public safety commands, public health orders, emergency directives, or operational instructions by default.

13.4.5(c) Observability outputs shall include public warning boundary controls where necessary and shall be designed to prevent visual, textual, or automated signals from being mistaken for public authority warning.

13.4.5(d) Where observability data indicates potential urgency, GCRI Canada shall follow role-appropriate escalation, public authority boundary, public-safe, and records procedures rather than assuming public warning authority.

13.4.5(e) The controlling rule shall be that observability may inform awareness but shall not become public warning by drift.


13.4.6 No Function-Creep From Public Authority Learning Into Public Authority Delegation. 13.4.6(a) Public authority learning data, materials, dashboards, maps, controlled rooms, public-safe summaries, evidence packs, and technical notes shall not function-creep into public authority delegation.

13.4.6(b) Public authority participation, attendance, data contribution, regulator-listening, public finance reader participation, emergency-management participation, or public infrastructure learning shall not make GCRI Canada a public authority, delegate, agent, regulator, procurement body, public finance approver, public warning authority, or emergency command actor.

13.4.6(c) Data shared for learning shall not be reused for public authority decision support beyond recorded permission and shall not be presented as official guidance, approval, adoption, funding approval, procurement approval, public finance approval, public warning, sovereign obligation, or public-law status.

13.4.6(d) Where public authority learning materials risk becoming public authority decision instruments, GCRI Canada shall narrow, relabel, restrict, obtain proper authority, or refuse the use.

13.4.6(e) The controlling rule shall be that learning support shall not become delegated public authority through reuse.


13.4.7 No Function-Creep From Evidence Into Finance Execution. 13.4.7(a) Evidence data, risk data, technical data, project data, dashboard data, map data, public-safe summaries, proof inputs, and diligence gap information shall not function-creep into finance execution by GCRI Canada.

13.4.7(b) GCRI Canada shall not use data to provide investment advice, securities solicitation, brokerage, finder activity, placement, underwriting, lending, insurance placement, rating, guarantee, public finance approval, capital commitment, transaction intermediation, or financial execution.

13.4.7(c) Finance-facing data reuse shall require finance-boundary review, GRA interface review where appropriate, legal review where risk exists, no-reliance language, no-solicitation language, no-advice language, no-rating language, no-guarantee language, and no-commitment language.

13.4.7(d) Data prepared for research or technical purposes shall not be repurposed into offering materials, investment decks, capital solicitation, public finance applications, insurance submissions, or lender materials by GCRI Canada.

13.4.7(e) The controlling rule shall be that evidence may be readable by finance actors, but shall not become finance execution.


13.4.8 No Function-Creep From Dataset Release Into Data Brokerage. 13.4.8(a) Dataset release, API access, dashboard access, map access, repository access, controlled room access, data room access, or public-safe publication shall not function-creep into data brokerage.

13.4.8(b) GCRI Canada shall not collect, package, sell, license, trade, monetize, route, rank, profile, or broker data about persons, communities, public authorities, providers, sponsors, hosts, projects, or technologies in a manner inconsistent with its public-benefit purpose, non-execution posture, privacy duties, public-safe publication rules, and anti-enclosure discipline.

13.4.8(c) Fees, subscriptions, cost recovery, training fees, technical access arrangements, or public-good support mechanisms shall not convert GCRI Canada into a data broker or market data vendor by implication.

13.4.8(d) Dataset releases shall include permitted use, prohibited use, anti-brokerage language where material, AI-use limits, redistribution limits, commercial-use limits, and correction path.

13.4.8(e) The controlling rule shall be that data release supports public-good evidence and interoperability, not extraction markets.


13.4.9 Purpose Change Review, Consent / Non-Consent Review Where Applicable, Public Authority Review, Community Review, and Safeguards Review. 13.4.9(a) Any material purpose change shall require purpose change review before data is reused, repurposed, shared, published, transferred, embedded, indexed, trained upon, mapped, dashboarded, or routed to a new interface.

13.4.9(b) Purpose change review shall assess original authority, proposed authority, data class, source expectations, consent or non-consent where applicable, withdrawal conditions, public authority permission where applicable, community review where appropriate, Indigenous or protected knowledge safeguards where applicable, privacy, cybersecurity, IP, license, finance boundary, provider or sponsor conflict, public-safe status, and correction path.

13.4.9(c) Consent or non-consent review shall be required where the purpose change affects persons, participants, communities, protected knowledge, health-sensitive data, rights-bearing data, or prior participation terms.

13.4.9(d) Public authority review shall be required where the purpose change affects public authority data, public authority references, public programs, public infrastructure, public finance, emergency management, regulatory context, or public authority learning.

13.4.9(e) Community and safeguards review shall be required where the purpose change affects communities, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, vulnerable groups, protected persons, or sensitive locations.

13.4.9(f) The controlling rule shall be that purpose change is a governance event, not a technical adjustment.


13.4.10 Purpose Limitation Records, Exceptions, Corrections, and Incident Handling. 13.4.10(a) GCRI Canada shall maintain purpose limitation records for material data uses, purpose changes, exceptions, corrections, and incidents.

13.4.10(b) Purpose limitation records shall identify data source, original purpose, proposed or actual use, authority, review, classification, access, AI-use status, public-safe status, approval, limitations, exception basis where any, correction path, and closeout.

13.4.10(c) Exceptions to purpose limitation shall be narrow, lawful, recorded, time-bound where appropriate, risk-reviewed, and justified by public-benefit, legal, safeguarding, incident response, correction, audit, or emergency record needs.

13.4.10(d) Purpose limitation breaches shall be treated as data incidents, privacy incidents, AI incidents, publication incidents, public authority incidents, finance-boundary incidents, sponsor or provider incidents, safeguards incidents, or cybersecurity incidents as applicable.

13.4.10(e) Corrections may include cessation of use, access restriction, deletion where lawful and required, sealing, public-safe notice, controlled notice, dataset withdrawal, dashboard removal, map withdrawal, AI index remediation, model remediation, publication correction, or relationship review.

13.4.10(f) The controlling rule shall be that purpose drift must be recorded, stopped, corrected, and learned from.


13.5 Data Minimization, Necessity, and Proportionality

13.5.1 Data Minimization as Charter-Level Rule. 13.5.1(a) Data minimization shall be a Charter-level rule of GCRI Canada. GCRI Canada shall collect, receive, create, generate, process, analyze, store, transfer, publish, share, license, retain, or expose only the data reasonably necessary and proportionate for a recorded lawful and public-benefit purpose.

13.5.1(b) Data minimization shall apply to raw data, derived data, synthetic data, aggregated data, de-identified data, metadata, embeddings, feature stores, logs, model outputs, AI outputs, dashboard outputs, maps, reports, public-safe summaries, datasets, APIs, schemas, software examples, and technical releases.

13.5.1(c) Data minimization shall not be displaced by storage capacity, future utility, sponsor interest, provider usefulness, public authority curiosity, finance readability, AI capability, research ambition, technical convenience, or publication attractiveness.

13.5.1(d) Data minimization shall be implemented through design, collection, access, processing, publication, retention, and deletion decisions.

13.5.1(e) The controlling rule shall be that GCRI Canada shall not hold more data, more precision, more access, or more exposure than its mission requires.


13.5.2 Collection Limited to What Is Necessary and Proportionate. 13.5.2(a) Data collection shall be limited to what is necessary and proportionate for the recorded purpose, research protocol, evidence requirement, public-good technical need, public authority learning purpose, public-safe publication purpose, or Nexus interface purpose.

13.5.2(b) Before collecting material data, GCRI Canada shall assess whether the purpose can be met through less sensitive data, fewer fields, shorter time periods, lower resolution, aggregated data, de-identified data, synthetic data, metadata-only records, public-safe summaries, compute-to-data, controlled access, or existing records.

13.5.2(c) Collection shall avoid unnecessary personal information, health-sensitive data, public authority restricted data, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive data, commercially sensitive data, protected knowledge, sensitive locations, confidential source information, credentials, keys, tokens, secrets, and controlled technology.

13.5.2(d) Collection instruments, intake forms, APIs, surveys, interviews, sensors, dashboards, maps, repositories, and AI tools shall be designed to avoid overcollection.

13.5.2(e) The controlling rule shall be that data not collected cannot be breached, misused, overclaimed, or overexposed.


13.5.3 Processing Limited to What Is Necessary and Proportionate. 13.5.3(a) Data processing shall be limited to what is necessary and proportionate for the recorded purpose and shall not expand by technical capability, analytic curiosity, AI convenience, dashboard design, publication interest, sponsor interest, provider usefulness, public authority curiosity, or finance readability.

13.5.3(b) Processing includes cleaning, transforming, linking, enriching, geocoding, classifying, indexing, embedding, modeling, summarizing, translating, visualizing, benchmarking, scoring, dashboarding, mapping, publishing, and deriving outputs.

13.5.3(c) High-risk processing, including linkage, geospatial precision, AI analysis, embeddings, feature extraction, profiling-like analysis, cyber analysis, public authority data analysis, protected knowledge analysis, or finance-facing analysis, shall require proportionality review.

13.5.3(d) Processing shall be restricted, anonymized, aggregated, generalized, performed in controlled environments, or refused where full processing would create unnecessary exposure.

13.5.3(e) The controlling rule shall be that data processing must remain bounded by need, not shaped by what tools can do.


13.5.4 Publication Limited to What Is Necessary and Public-Safe. 13.5.4(a) Data publication shall be limited to what is necessary and public-safe for the publication purpose and audience.

13.5.4(b) GCRI Canada shall not publish raw data, detailed data, high-resolution maps, precise locations, sensitive metadata, personal information, public authority restricted data, cyber-sensitive information, infrastructure-sensitive information, protected knowledge, finance-sensitive information, commercially sensitive information, confidential source information, or controlled technology where a public-safe summary, aggregation, redaction, generalization, synthetic data, controlled annex, restricted annex, or no-publication approach is sufficient.

13.5.4(c) Publication shall preserve limitations, source context, public-safe transformations, update status, confidence, uncertainty, boundary language, and correction path.

13.5.4(d) Public-safe publication review shall assess whether the publication exposes more data than necessary to support the public-good purpose.

13.5.4(e) The controlling rule shall be that public transparency shall be achieved by safe sufficiency, not maximal disclosure.


13.5.5 Retention Limited to What Is Necessary, Lawful, and Mission-Justified. 13.5.5(a) Data retention shall be limited to what is necessary, lawful, and mission-justified for research integrity, evidence quality, auditability, correctionability, legal compliance, public-safe accountability, technical continuity, contractual duty, public authority requirement, community safeguard, incident response, or legal hold.

13.5.5(b) Retention periods shall reflect data class, sensitivity, source authority, lawful basis, research protocol, public authority restrictions, protected knowledge restrictions, cybersecurity risk, publication dependency, correction needs, and archival value.

13.5.5(c) GCRI Canada shall not retain sensitive data merely because it may be useful in the future, inexpensive to store, attractive for AI training, potentially valuable to sponsors, useful to providers, helpful to finance readers, or convenient for institutional memory.

13.5.5(d) Retention shall include review dates, deletion or sealing triggers, archive conditions, legal hold exceptions, and correction path.

13.5.5(e) The controlling rule shall be that retention must serve lawful mission memory, not indefinite accumulation.


13.5.6 Access Limited to What Is Necessary for Role and Purpose. 13.5.6(a) Data access shall be limited to what is necessary for role, purpose, authority, classification, access class, handling class, public-safe status, and time period.

13.5.6(b) Access shall be role-based, least-privilege, purpose-bound, time-limited where appropriate, logged where material, reviewable, revocable, and subject to confidentiality, AI-use, copy, download, export, onward disclosure, and publication restrictions.

13.5.6(c) Directors, officers, staff, fellows, advisors, committees, councils, researchers, contributors, contractors, sponsors, providers, hosts, universities, public authorities, communities, capital readers, GRF, GRA, Protocol Authority, Nexus entities, National Companies, and Project SPVs shall receive only the access required for their recorded role and purpose.

13.5.6(d) Access to sensitive data shall require heightened review and may require controlled rooms, clean rooms, data rooms, evidence rooms, public authority rooms, capital-reader rooms, no-download rooms, or need-to-know restrictions.

13.5.6(e) The controlling rule shall be that participation does not create data access; role and purpose do.


13.5.7 Granularity Reduction, Aggregation, Generalization, Redaction, De-Identification, Synthetic Substitution, and Metadata-Only Release. 13.5.7(a) GCRI Canada shall use granularity reduction, aggregation, generalization, redaction, de-identification, pseudonymization, synthetic substitution, masking, suppression, delayed release, metadata-only release, and controlled annexes where such measures reduce privacy, rights, public authority, cybersecurity, infrastructure, community, protected knowledge, finance, or public-safe risk while preserving sufficient public-benefit value.

13.5.7(b) Granularity reduction shall be used to reduce excessive detail, including geospatial precision, temporal precision, individual-level detail, small-group detail, infrastructure detail, cyber detail, and sensitive metadata.

13.5.7(c) Aggregation and generalization shall be reviewed for small-cell, mosaic, linkage, and re-identification risk.

13.5.7(d) Redaction shall remove sensitive details without misleading users about limitations. De-identification shall not be claimed unless supported by review. Synthetic substitution shall be labeled and shall not be represented as original data. Metadata-only release shall be reviewed for inference risk.

13.5.7(e) The controlling rule shall be that data utility shall be preserved through safe transformation where possible, not through unnecessary exposure.


13.5.8 Least Exposure Rule for Dashboards, Maps, Public-Safe Reports, Data Releases, APIs, and Technical Notes. 13.5.8(a) Dashboards, maps, public-safe reports, data releases, APIs, schemas, technical notes, software examples, release notes, Academy materials, public authority learning materials, media statements, and public communications shall comply with the least exposure rule.

13.5.8(b) The least exposure rule requires that public or external outputs expose the least amount of data, precision, source detail, sensitive metadata, personal information, public authority information, cyber-sensitive information, infrastructure-sensitive information, protected knowledge, finance-sensitive information, or commercially sensitive information necessary for the approved purpose.

13.5.8(c) Dashboards shall limit fields, layers, exports, filters, downloads, screenshots, access roles, and drill-downs where greater exposure is unnecessary or unsafe.

13.5.8(d) Maps shall limit resolution, exact coordinates, sensitive layers, labels, and over-precision where public-safe mapping requires limitation.

13.5.8(e) APIs and technical notes shall limit sample data, logs, endpoint details, credentials, sensitive configurations, and exploit-enabling information.

13.5.8(f) The controlling rule shall be that external utility shall be designed around minimum safe disclosure.


13.5.9 Proportionality Review for High-Risk Data. 13.5.9(a) High-risk data shall require proportionality review before collection, processing, linkage, AI use, dashboarding, mapping, publication, transfer, retention, or external sharing.

13.5.9(b) High-risk data includes personal information, health-sensitive data, rights-bearing data, public authority restricted data, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive information, commercially sensitive information, community-protected information, Indigenous or protected knowledge, confidential source information, whistleblower information, sensitive-location data, controlled technology, export-control-sensitive information, sanctions-sensitive information, credentials, keys, tokens, secrets, and privileged material.

13.5.9(c) Proportionality review shall assess public-benefit purpose, necessity, alternatives, minimization, safeguards, access controls, AI-use restrictions, publication risks, public-safe transformations, retention, deletion, community implications, public authority implications, finance implications, cybersecurity implications, and correction path.

13.5.9(d) High-risk data use shall be refused, narrowed, aggregated, generalized, restricted, or routed to controlled environments where benefits do not justify risks.

13.5.9(e) The controlling rule shall be that high-risk data may be used only when the public-benefit need is strong and safeguards are stronger.


13.5.10 Minimization Records and Exceptions. 13.5.10(a) GCRI Canada shall maintain minimization records for material high-risk data activities and for exceptions to ordinary minimization rules.

13.5.10(b) Minimization records shall identify data requested, data collected, data excluded, purpose, necessity, proportionality, alternatives considered, sensitivity, classification, access limits, retention limits, public-safe treatment, AI-use limits, publication limits, approval authority, exception basis where any, and correction path.

13.5.10(c) Exceptions to minimization shall be narrow, lawful, recorded, time-limited where appropriate, public-benefit justified, risk-reviewed, and subject to enhanced access, retention, public-safe, and assurance controls.

13.5.10(d) Overcollection, overprocessing, overretention, overexposure, or unnecessary access shall trigger correction, deletion where lawful and required, sealing, access reduction, publication correction, dashboard or map revision, dataset withdrawal, AI index remediation, training, or incident response as appropriate.

13.5.10(e) The controlling rule shall be that minimization must be provable by record, and exceptions must be exceptional.

13.6 Data Classification Architecture

13.6.1 Public Data. 13.6.1(a) Public Data shall mean data approved for public release without special access restriction, provided that such approval has been made through lawful authority, source review, license review where applicable, public-safe review where applicable, and correction-path assignment.

13.6.1(b) Public Data may include data lawfully published by GCRI Canada, data lawfully obtained from public sources, open data, public reports, public-safe summaries, public technical documentation, public dataset cards, public metadata, or other data determined to be suitable for unrestricted public access.

13.6.1(c) Public Data shall not be presumed free of governance obligations merely because it is public. Public Data remains subject to source attribution, license terms, contextual integrity, public-safe limits, controlled vocabulary, correctionability, anti-misuse rules, and role-boundary discipline.

13.6.1(d) Public Data shall not include personal information, health-sensitive data, public authority restricted data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, commercially sensitive data, community-protected data, Indigenous or protected knowledge, controlled technology, credentials, keys, tokens, secrets, confidential materials, or other sensitive materials unless lawfully transformed, reviewed, and approved for public release.

13.6.1(e) The controlling rule shall be that Public Data is data approved for public access by record, not data assumed safe because it is visible.


13.6.2 Public-Safe Data. 13.6.2(a) Public-Safe Data shall mean data or data-derived material approved for public-facing or external communication only after review for privacy, public authority restrictions, cybersecurity, infrastructure sensitivity, finance sensitivity, commercial sensitivity, community safeguards, Indigenous or protected knowledge, re-identification risk, sensitive-location risk, public harm, and boundary overclaim.

13.6.2(b) Public-Safe Data may include redacted data, aggregated data, generalized data, synthetic data, public-safe summaries, public-safe map layers, public-safe dashboard outputs, public-safe dataset cards, public-safe technical notes, and other transformed outputs suitable for publication within stated limits.

13.6.2(c) Public-Safe Data is not necessarily full disclosure and shall not imply that underlying controlled or restricted data is public, open, reproducible, transferable, reusable, finance-ready, public authority-approved, certified, recognized, or protocol-effective.

13.6.2(d) Public-Safe Data shall include source limits, transformation notes where material, limitations, public-safe status, permitted uses, prohibited uses, version, and correction path.

13.6.2(e) The controlling rule shall be that Public-Safe Data is safe for the approved public purpose, not automatically safe for every reuse.


13.6.3 Internal Data. 13.6.3(a) Internal Data shall mean data intended for use within GCRI Canada or authorized internal governance, research, technical, publication, administrative, program, or assurance processes, and not approved for public release unless separately reviewed and reclassified.

13.6.3(b) Internal Data may include working drafts, internal research notes, internal metadata, preliminary evidence records, internal dashboards, internal issue records, internal training materials, internal operational records, and other materials not intended for external reliance.

13.6.3(c) Internal Data shall be access-controlled according to role and purpose and shall not be circulated externally, uploaded to unauthorized AI systems, placed in public repositories, used in public claims, or incorporated into public-safe materials without review.

13.6.3(d) Internal classification shall not be used to hide materials that should be corrected, disclosed through public-safe notice, escalated, or governed under a higher sensitivity class.

13.6.3(e) The controlling rule shall be that Internal Data may support institutional work, but does not create external public meaning.


13.6.4 Confidential Data. 13.6.4(a) Confidential Data shall mean data subject to confidentiality obligations, internal sensitivity, contractual restriction, research restriction, contributor restriction, public authority restriction, sponsor or provider restriction, partner restriction, privacy concern, IP concern, commercial sensitivity, or other lawful limitation on access or disclosure.

13.6.4(b) Confidential Data shall be accessed only by authorized persons with a recorded role and purpose, and shall be subject to confidentiality, access, handling, AI-use, transfer, publication, retention, and correction controls.

13.6.4(c) Confidential Data shall not be copied, exported, published, summarized publicly, dashboarded, mapped, embedded, indexed, trained upon, or shared externally unless authorized by record and reviewed for public-safe status.

13.6.4(d) Confidentiality shall not override correctionability, legal duties, public-safe duties, cybersecurity duties, public authority duties, protected knowledge duties, or Board oversight where applicable, but disclosure shall occur only through lawful and properly classified channels.

13.6.4(e) The controlling rule shall be that Confidential Data requires controlled trust, not informal discretion.


13.6.5 Restricted Data. 13.6.5(a) Restricted Data shall mean data requiring heightened access control because unauthorized access, disclosure, processing, publication, transfer, or reuse may create material legal, privacy, public authority, cybersecurity, infrastructure, finance, commercial, community, protected knowledge, safety, dignity, rights, or public trust harm.

13.6.5(b) Restricted Data may include personal information, health-sensitive data, public authority restricted data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, commercially sensitive data, community-protected data, Indigenous or protected knowledge, confidential source information, whistleblower information, controlled technology, export-control-sensitive data, sanctions-sensitive data, privileged materials, credentials, keys, tokens, secrets, and legal-hold materials.

13.6.5(c) Restricted Data shall be subject to need-to-know access, heightened logging where material, no-download or controlled-room treatment where appropriate, AI-use restrictions, transfer restrictions, publication restrictions, retention controls, incident response, and periodic review.

13.6.5(d) Restricted Data shall not be placed in public repositories, public datasets, public dashboards, public maps, unauthorized AI systems, unmanaged email, open chat, personal storage, or uncontrolled collaboration environments.

13.6.5(e) The controlling rule shall be that Restricted Data requires affirmative permission and protective environment before use.


13.6.6 Personal Information and Rights-Bearing Data. 13.6.6(a) Personal Information and Rights-Bearing Data shall be classified as data capable of identifying, relating to, describing, affecting, or being linked to an individual, group, community, protected participant, vulnerable person, confidential source, public official in a sensitive role, or other rights-bearing subject.

13.6.6(b) This class shall include direct identifiers, indirect identifiers, quasi-identifiers, contact data, device data, location data, mobility data, biometric data, health data, financial data, employment data, participation data, research subject data, public authority interaction data, and AI-derived or inferred data capable of affecting persons or communities.

13.6.6(c) Personal Information and Rights-Bearing Data shall require lawful or approval basis, purpose limitation, minimization, access limitation, retention limitation, disclosure limitation, AI-use review, re-identification review where applicable, public-safe review, and correction path.

13.6.6(d) Data that appears de-identified, aggregated, synthetic, or derived shall remain within this class where linkage, inference, small population, geospatial precision, temporal precision, or mosaic risk may affect rights.

13.6.6(e) The controlling rule shall be that rights-bearing effect governs classification, not merely whether a name appears.


13.6.7 Health-Sensitive Data. 13.6.7(a) Health-Sensitive Data shall mean data relating to health, public health, clinical status, disability, mental health, biosecurity, biosurveillance, environmental health, health systems, population health, vulnerability, mobility-health links, sensor-derived health indicators, wastewater surveillance, or other health-related information capable of affecting dignity, rights, privacy, stigma, access, safety, or public trust.

13.6.7(b) Health-Sensitive Data shall require heightened lawful or approval basis review, ethics review where applicable, minimization, de-identification or aggregation where appropriate, AI-use restrictions, access controls, re-identification review, public-safe publication review, retention limits, and correction path.

13.6.7(c) Health-Sensitive Data shall not be published, mapped, dashboarded, placed in datasets, used in AI systems, used in media materials, or routed to Nexus interfaces unless properly reviewed and transformed for the approved purpose.

13.6.7(d) Health-Sensitive Data involving public authorities, communities, vulnerable groups, geospatial precision, public health events, or protected knowledge shall receive combined review across all applicable classes.

13.6.7(e) The controlling rule shall be that health sensitivity requires heightened protection because health data can harm even when anonymized or aggregated poorly.


13.6.8 Public Authority Data. 13.6.8(a) Public Authority Data shall mean data received from, generated with, derived from, referring to, or materially involving public authorities, public programs, public finance, public infrastructure, public health, public safety, emergency management, regulatory activity, procurement, public authority learning, or public authority participation.

13.6.8(b) Public Authority Data shall require authority or permission records, capacity classification, source record, permitted use, prohibited use, confidentiality, reference approval where applicable, AI-use limits, transfer limits, retention limits, publication controls, public-safe status, and correction path.

13.6.8(c) Public Authority Data shall not create public authority delegation, endorsement, adoption, procurement approval, funding approval, regulatory approval, public warning, emergency command, public finance approval, sovereign obligation, official guidance, or public-law status by its contribution or use.

13.6.8(d) Public Authority Data shall not be reused in dashboards, maps, datasets, finance-facing materials, sponsor materials, provider materials, public claims, AI training, or Nexus interfaces beyond recorded permission and review.

13.6.8(e) The controlling rule shall be that Public Authority Data carries public power risk and must be governed before it is made visible.


13.6.9 Cyber-Sensitive Data. 13.6.9(a) Cyber-Sensitive Data shall mean vulnerability information, exploit information, threat intelligence, incident records, logs, credentials, keys, tokens, secrets, system configurations, network diagrams, attack paths, malware samples, detection logic, repository security data, dependency vulnerabilities, infrastructure telemetry, or other information that may increase cybersecurity risk if mishandled.

13.6.9(b) Cyber-Sensitive Data shall require cybersecurity classification, need-to-know access, secure storage, secure transfer, AI-use restrictions, public-safe technical review, coordinated disclosure where appropriate, release controls, retention controls, and incident response.

13.6.9(c) Cyber-Sensitive Data shall not be placed in public repositories, public issue trackers, public datasets, public dashboards, public maps, public documentation, uncontrolled AI systems, unmanaged email, or open chat.

13.6.9(d) Publication or technical release involving Cyber-Sensitive Data shall remove, generalize, delay, restrict, or control details that would enable exploitation, unauthorized access, credential abuse, operational compromise, or infrastructure harm.

13.6.9(e) The controlling rule shall be that cyber data shall be governed to reduce vulnerability, not distribute it.


13.6.10 Infrastructure-Sensitive Data. 13.6.10(a) Infrastructure-Sensitive Data shall mean data concerning critical infrastructure, mission-critical infrastructure, public infrastructure, energy, water, food, health, transportation, ports, corridors, telecommunications, AI-RAN, O-RAN, private wireless, DePIN, sensors, cyber-physical systems, operational technology, data centers, compute environments, public facilities, emergency systems, or other systems whose exposure may create operational, security, public safety, or public trust risk.

13.6.10(b) Infrastructure-Sensitive Data shall require classification, access control, public-safe mapping review, cybersecurity review, public authority review where applicable, host or operator review where appropriate, sensitive-location controls, publication controls, and correction path.

13.6.10(c) Infrastructure-Sensitive Data shall not expose system dependencies, vulnerabilities, exact sensitive locations, access routes, operational weaknesses, failure points, emergency response gaps, cyber-physical attack paths, or security controls unless lawfully authorized and controlled.

13.6.10(d) Public-safe outputs may use aggregation, generalization, delayed release, controlled annexes, restricted annexes, or no-map approaches to preserve resilience learning without increasing risk.

13.6.10(e) The controlling rule shall be that infrastructure evidence shall improve resilience without making infrastructure easier to harm.


13.6.11 Finance-Sensitive Data. 13.6.11(a) Finance-Sensitive Data shall mean data whose use or disclosure may affect capital readers, finance-readiness interpretation, public finance, insurance, lending, underwriting, ratings, guarantees, project finance, budgets, grants, capital commitments, valuation, market perception, securities treatment, or financial decision-making.

13.6.11(b) Finance-Sensitive Data may include project data, diligence data, proof-pack inputs, risk evidence, finance-facing gap maps, sponsor information, provider information, public finance participation information, cost information, revenue information, insurance information, capital-reader room materials, and public finance reader materials.

13.6.11(c) Finance-Sensitive Data shall require finance-boundary review, GRA role preservation, legal review where risk exists, access controls, no-advice language, no-solicitation language, no-rating language, no-guarantee language, no-commitment language, and correction path.

13.6.11(d) Finance-Sensitive Data shall not be used to provide investment advice, securities solicitation, brokerage, underwriting, lending, insurance placement, rating, guarantee, public finance approval, capital commitment, or financial execution by GCRI Canada.

13.6.11(e) The controlling rule shall be that finance-sensitive evidence must not become finance authority through data presentation.


13.6.12 Commercially Sensitive Data. 13.6.12(a) Commercially Sensitive Data shall mean data involving confidential business information, trade secrets, proprietary methods, pricing, cost, customers, suppliers, contracts, business plans, product plans, technical roadmaps, provider systems, sponsor systems, host systems, partner materials, competitive information, or other commercial information requiring protection.

13.6.12(b) Commercially Sensitive Data shall require source authority, confidentiality controls, access limits, IP and license review, conflict review, competition-safe handling, public-safe publication review, and correction path.

13.6.12(c) Commercial sensitivity shall not be used to suppress legitimate correction, conceal sponsor or provider control, hide public-safe risks, avoid conflict disclosure where required, or convert GCRI Canada into a private service desk for commercial actors.

13.6.12(d) Publications referencing Commercially Sensitive Data shall preserve confidentiality while disclosing conflicts, limitations, dependencies, and role boundaries at a public-safe level where material.

13.6.12(e) The controlling rule shall be that commercial confidentiality may protect legitimate interests but shall not capture public-good truth.


13.6.13 Community-Protected Data. 13.6.13(a) Community-Protected Data shall mean data, knowledge, context, testimony, observations, locations, practices, environmental information, cultural information, community conditions, vulnerability information, or participation records that a community, group, or affected population treats as sensitive, protected, contextual, restricted, or subject to safeguards.

13.6.13(b) Community-Protected Data shall require safeguards review, consent or non-consent treatment where applicable, community review where appropriate, attribution or non-attribution controls, access limits, mapping limits, AI-use restrictions, publication limits, withdrawal pathways, grievance pathways, remedy pathways, and correction path.

13.6.13(c) Community-Protected Data shall not be treated as ordinary open data, public authority data, sponsor material, provider material, finance material, AI training material, dashboard content, map layer, or media material without recorded authority and safeguards.

13.6.13(d) Community-Protected Data shall remain protected when summarized, translated, mapped, embedded, modeled, dashboarded, aggregated, or converted into public-safe outputs unless properly reviewed and transformed.

13.6.13(e) The controlling rule shall be that community context determines protection even where formal legal ownership is unclear.


13.6.14 Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge Data. 13.6.14(a) Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge Data shall mean knowledge, records, observations, sites, routes, practices, ecological information, cultural information, territorial context, environmental context, oral knowledge, community knowledge, sensitive locations, sacred sites, protected sites, and related data requiring contextual, legal, ethical, cultural, or community safeguards.

13.6.14(b) Such data shall require appropriate authority, safeguards review, community or knowledge-holder review where applicable, consent or non-consent treatment where applicable, attribution or non-attribution controls, public-safe mapping controls, AI-use restrictions, transfer limits, publication limits, retention controls, withdrawal, grievance, remedy, and correction pathways.

13.6.14(c) GCRI Canada shall not claim ownership over such knowledge beyond lawful stewardship, license, permission, or record rights and shall not expose such knowledge through dashboards, maps, datasets, repositories, AI systems, publications, or media materials without proper review.

13.6.14(d) Derived materials, translations, embeddings, model outputs, public-safe summaries, Academy materials, GRF inputs, GRA inputs, Protocol Authority inputs, and Nexus interfaces shall inherit protective restrictions unless lawfully transformed and reviewed.

13.6.14(e) The controlling rule shall be that protected knowledge remains protected across format, language, model, map, and publication.


13.6.15 Controlled Technology and Export-Control-Sensitive Data. 13.6.15(a) Controlled Technology and Export-Control-Sensitive Data shall mean technical data, software, models, methods, designs, documentation, datasets, system details, cyber capabilities, encryption-sensitive materials, AI capabilities, advanced infrastructure details, dual-use technologies, telecommunications-sensitive materials, AI-RAN or O-RAN implementation details, sovereign compute details, or other materials subject to export-control, sanctions, controlled technology, national security, or dual-use review.

13.6.15(b) Such data shall require export-control review, sanctions review, controlled technology review, cybersecurity review, access controls, jurisdictional review, release controls, contribution controls, transfer controls, publication controls, and correction path.

13.6.15(c) Controlled Technology and Export-Control-Sensitive Data shall not be released publicly, transferred cross-border, shared with contributors, placed in repositories, used in AI systems, included in technical notes, or distributed through training materials without appropriate review and authorization.

13.6.15(d) Where public-good technical release is mission-compatible but sensitive, GCRI Canada may use redaction, delayed release, restricted licensing, controlled access, jurisdictional controls, public-safe summaries, or refusal of release.

13.6.15(e) The controlling rule shall be that public-good openness shall not override controlled technology, export, sanctions, or cyber-safety discipline.


13.6.16 Classification Review, Reclassification, Downgrade, Upgrade, Sealing, Deletion, and Public-Safe Transformation. 13.6.16(a) GCRI Canada shall review data classification at intake, before access, before processing, before AI use, before transfer, before dashboarding, before mapping, before publication, before dataset release, before technical release, before archive, and whenever material circumstances change.

13.6.16(b) Reclassification shall occur where data was incorrectly classified, source context changes, public authority permission changes, consent changes, protected knowledge status changes, cybersecurity risk changes, finance sensitivity changes, public-safe status changes, or correction reveals misclassification.

13.6.16(c) Downgrade may occur only after review supports lower sensitivity, lower access restriction, or public-safe transformation. Upgrade shall occur promptly where risk is higher than previously understood.

13.6.16(d) Sealing shall be used where data must be preserved but access must be restricted due to law, safety, public authority sensitivity, cybersecurity, protected knowledge, legal privilege, confidential source protection, whistleblower protection, or public-safe risk.

13.6.16(e) Deletion shall occur where lawful, required, authorized, and consistent with retention, legal hold, correctionability, public authority restrictions, protected knowledge obligations, and research integrity.

13.6.16(f) Public-safe transformation may include redaction, aggregation, generalization, masking, synthetic substitution, metadata-only release, delayed release, restricted annex treatment, or no-release determination.

13.6.16(g) The controlling rule shall be that classification is a living governance state, not a one-time label.


13.7 Rights-Bearing Data

13.7.1 Rights-Bearing Data as Data That May Affect Human Rights, Dignity, Privacy, Safety, Access, Inclusion, Exclusion, Reputation, Public Authority Treatment, Community Interests, Cultural Integrity, or Protected Knowledge. 13.7.1(a) Rights-Bearing Data shall mean data, metadata, derived data, linked data, inferred data, AI output, model output, dashboard output, map output, publication content, or technical output that may affect human rights, dignity, privacy, safety, access, inclusion, exclusion, reputation, public authority treatment, community interests, cultural integrity, protected knowledge, or public trust.

13.7.1(b) Rights-Bearing Data may concern individuals, groups, communities, Indigenous knowledge holders, local knowledge holders, territorial knowledge holders, protected participants, vulnerable groups, public officials in sensitive roles, confidential sources, whistleblowers, research participants, or affected populations.

13.7.1(c) Rights-Bearing Data shall be treated as such where misuse, misclassification, exposure, inference, linkage, publication, mapping, dashboarding, AI use, public authority use, finance use, provider use, sponsor use, or media use may create harm.

13.7.1(d) Rights-Bearing Data shall require purpose limitation, minimization, access control, safeguards, public-safe review, AI-use review where applicable, correction path, and grievance or remedy pathway where applicable.

13.7.1(e) The controlling rule shall be that data capable of affecting rights must be governed as rights-bearing before it becomes institutional evidence.


13.7.2 Rights-Bearing Personal Data. 13.7.2(a) Rights-Bearing Personal Data shall include personal information and data capable of identifying, relating to, describing, locating, profiling, classifying, assessing, or affecting a person directly or indirectly.

13.7.2(b) Such data may include identity, contact, demographic, location, mobility, device, biometric, health, financial, employment, education, public authority interaction, research participation, community participation, public event participation, online activity, or inferred data.

13.7.2(c) Rights-Bearing Personal Data shall require lawful or approval basis, notice where applicable, consent where applicable, minimization, access controls, AI-use restrictions, retention limits, disclosure limits, correction process, and deletion or sealing where applicable.

13.7.2(d) Personal data shall remain rights-bearing when de-identified, pseudonymized, aggregated, embedded, modeled, summarized, or translated where re-identification, inference, group harm, or contextual harm remains possible.

13.7.2(e) The controlling rule shall be that personal data protection follows the person, not only the identifier.


13.7.3 Rights-Bearing Community Data. 13.7.3(a) Rights-Bearing Community Data shall include data that may affect communities, vulnerable groups, remote communities, Indigenous communities where applicable, local communities, territorial communities, cultural communities, environmental communities, or groups subject to stigma, extraction, surveillance, targeting, exclusion, or misrepresentation.

13.7.3(b) Such data may include community testimony, environmental observations, vulnerability indicators, location data, service access data, public authority interaction data, health or disaster context, infrastructure context, protected sites, cultural context, or community participation records.

13.7.3(c) Rights-Bearing Community Data shall require safeguards review, community review where appropriate, consent or non-consent treatment where applicable, attribution or non-attribution controls, minimization, public-safe mapping review, access limits, publication limits, grievance pathways, remedy pathways, withdrawal pathways, and correction path.

13.7.3(d) Community data shall not be used to rank, stigmatize, expose, surveil, extract from, or speak for a community without recorded authority and safeguards.

13.7.3(e) The controlling rule shall be that communities can be harmed by data even where no individual is named.


13.7.4 Rights-Bearing Indigenous, Local, Territorial, Cultural, and Environmental Knowledge. 13.7.4(a) Indigenous, Local, Territorial, Cultural, and Environmental Knowledge shall be rights-bearing where its use, disclosure, mapping, modeling, translation, publication, or reuse may affect cultural integrity, territorial integrity, ecological integrity, dignity, self-determination, community safety, protected knowledge, or public trust.

13.7.4(b) Such knowledge may include oral knowledge, local observations, environmental patterns, cultural sites, sacred sites, protected sites, territorial relationships, ecological indicators, community histories, language context, and knowledge shared under conditions of trust.

13.7.4(c) GCRI Canada shall not treat such knowledge as ordinary research input, open data, public-source material, or extractable evidence merely because it is shared, observed, recorded, translated, or made technically accessible.

13.7.4(d) Use shall require appropriate authority, safeguards, attribution or non-attribution controls, publication limits, mapping controls, AI-use limits, retention limits, grievance, remedy, withdrawal, and correction pathways.

13.7.4(e) The controlling rule shall be that protected knowledge shall not be converted into institutional truth without respecting its source, context, and limits.


13.7.5 Rights-Bearing Public Authority Data Where Individuals or Communities May Be Affected. 13.7.5(a) Public Authority Data shall be rights-bearing where it may affect persons, communities, public service access, public authority treatment, public safety, public health, emergency response, infrastructure service, public finance, regulatory treatment, procurement, reputation, or public trust.

13.7.5(b) Such data may include public program data, public service data, regulatory data, public health data, public safety data, emergency management data, public infrastructure data, public finance data, public authority participation data, and data contributed by public officials.

13.7.5(c) Rights-bearing Public Authority Data shall require public authority permission, capacity classification, privacy review, public-safe review, access controls, AI-use limits, publication limits, retention limits, reference approval where applicable, and correction path.

13.7.5(d) GCRI Canada shall not use Public Authority Data to imply public authority endorsement, adoption, approval, public warning, emergency command, procurement approval, funding approval, public finance approval, official guidance, or sovereign obligation.

13.7.5(e) The controlling rule shall be that public authority data may carry both rights risk and public power risk.


13.7.6 Rights-Bearing AI, Sensor, Location, Mobility, Health, Biometric, Geospatial, Cyber, and Infrastructure Data. 13.7.6(a) AI, sensor, location, mobility, health, biometric, geospatial, cyber, and infrastructure data shall be rights-bearing where it can identify, infer, profile, classify, locate, expose, or affect persons, communities, public authorities, infrastructure operators, protected sites, vulnerable groups, or protected knowledge.

13.7.6(b) AI-derived data, embeddings, feature stores, retrieval indexes, model outputs, inference records, sensor signals, AI-RAN signals, O-RAN signals, DePIN records, cyber logs, digital twin outputs, and geospatial layers may be rights-bearing even when not intended to describe persons.

13.7.6(c) Such data shall require technical review, privacy review, public-safe review, cybersecurity review, re-identification review, sensitive-location review, AI-use review, and safeguards review where applicable.

13.7.6(d) GCRI Canada shall not use such data to create unauthorized surveillance, behavioral profiling, public authority decision tools, finance scoring, provider preference, sponsor benefit, or public warning surfaces.

13.7.6(e) The controlling rule shall be that technical data becomes rights-bearing when technical insight can affect people, communities, or public trust.


13.7.7 Rights-Bearing Data Impact Review. 13.7.7(a) GCRI Canada shall conduct Rights-Bearing Data Impact Review for material activities involving data that may affect rights, dignity, privacy, safety, access, inclusion, exclusion, reputation, public authority treatment, community interests, cultural integrity, protected knowledge, or public trust.

13.7.7(b) Review shall assess data source, authority, purpose, affected persons or communities, sensitivity, minimization, proportionality, access, AI use, linkage, inference, publication, dashboarding, mapping, public authority use, finance use, provider or sponsor use, retention, transfer, safeguards, and correction path.

13.7.7(c) Review shall identify risks of discrimination, stigma, exclusion, surveillance, retaliation, re-identification, overexposure, extraction, public authority overreach, finance misuse, community harm, protected knowledge exposure, and public misinterpretation.

13.7.7(d) Review outcomes may require refusal, redesign, minimization, aggregation, de-identification, controlled-room use, access restriction, no-publication, public-safe transformation, additional consent, community review, public authority review, or Board or committee escalation.

13.7.7(e) The controlling rule shall be that rights-bearing data requires impact review before institutional use creates institutional consequence.


13.7.8 Rights of Access, Correction, Restriction, Deletion, Objection, Portability, or Equivalent Rights Where Applicable. 13.7.8(a) GCRI Canada shall recognize and operationalize rights of access, correction, restriction, deletion, objection, portability, withdrawal, explanation, grievance, remedy, or equivalent rights where applicable by law, contract, research protocol, public authority permission, community protocol, or protected knowledge safeguard.

13.7.8(b) Requests shall be received, verified where appropriate, classified, reviewed, responded to, and recorded according to applicable law, authority, data class, retention rules, legal hold, public authority restrictions, research integrity, public-safe obligations, and correctionability.

13.7.8(c) Where a request cannot be fulfilled in whole or in part, GCRI Canada shall record the reason, lawful basis, limitation, alternative remedy where available, and appeal or escalation pathway where applicable.

13.7.8(d) Rights requests may require correction of datasets, dashboards, maps, AI indexes, embeddings, retrieval stores, publications, public-safe summaries, research records, or downstream dependencies where appropriate.

13.7.8(e) The controlling rule shall be that rights-bearing data must remain reachable by rights processes.


13.7.9 Rights-Bearing Data Complaints, Grievances, and Remedies. 13.7.9(a) GCRI Canada shall maintain complaints, grievance, and remedy pathways for Rights-Bearing Data concerns.

13.7.9(b) Complaints and grievances may concern unauthorized collection, overcollection, improper use, purpose drift, unsafe publication, harmful mapping, protected knowledge exposure, AI misuse, public authority misdescription, finance misuse, inaccurate data, misclassification, access denial, correction failure, deletion failure, or community harm.

13.7.9(c) Grievance processes shall be accessible, documented, timely, proportionate, protective of complainants, confidential where appropriate, culturally respectful where applicable, public-safe, and correctionable.

13.7.9(d) Remedies may include correction, restriction, deletion where lawful and required, sealing, withdrawal, retraction, public-safe notice, controlled notice, access change, apology where appropriate, safeguards revision, training, relationship review, or Board or committee escalation.

13.7.9(e) The controlling rule shall be that rights-bearing data governance must include pathways for affected persons and communities to challenge institutional use.


13.7.10 Rights-Bearing Data Correction, Withdrawal, Sealing, Deletion, and Public-Safe Notice. 13.7.10(a) Rights-Bearing Data shall be corrected, restricted, withdrawn, sealed, deleted where lawful and required, reclassified, or subject to public-safe notice or controlled notice where data is inaccurate, outdated, unauthorized, excessive, unsafe, misclassified, overexposed, improperly used, improperly published, or inconsistent with rights, safeguards, or authority.

13.7.10(b) Correction shall address source data, derived data, metadata, embeddings, feature stores, retrieval indexes, model outputs, dashboard outputs, map outputs, datasets, publications, public-safe summaries, technical releases, and downstream dependencies where appropriate.

13.7.10(c) Sealing shall be used where preservation is required but access must be restricted. Deletion shall be used where lawful, required, authorized, and consistent with legal hold, research integrity, public authority restrictions, protected knowledge obligations, and correctionability.

13.7.10(d) Public-safe notice shall be issued where public materials are affected and notice can be safely provided. Controlled notice shall be issued where restricted recipients or sensitive materials are affected.

13.7.10(e) The controlling rule shall be that rights-bearing data must remain correctable across its source, derivative, publication, and archive forms.


13.8 Personal Information Governance

13.8.1 Personal Information Handling Requirements. 13.8.1(a) GCRI Canada shall handle Personal Information according to lawful authority, purpose limitation, data minimization, access limitation, security, retention limitation, disclosure limitation, AI-use controls, public-safe publication controls, breach response, correctionability, and applicable rights.

13.8.1(b) Personal Information shall not be collected, received, processed, analyzed, linked, embedded, indexed, dashboarded, mapped, published, transferred, or retained unless necessary and proportionate for a recorded lawful and public-benefit purpose.

13.8.1(c) Personal Information shall be classified at intake and reviewed before use in research, evidence records, public authority learning, AI systems, dashboards, maps, datasets, software, technical notes, Academy materials, media materials, or Nexus interfaces.

13.8.1(d) Personal Information shall not be placed in public repositories, unauthorized AI systems, uncontrolled spreadsheets, public datasets, public dashboards, public maps, open chat, unmanaged email, or personal storage.

13.8.1(e) The controlling rule shall be that personal information requires governance before usefulness.


13.8.2 Collection, Notice, Consent Where Applicable, Authority, Purpose, and Minimization. 13.8.2(a) Collection of Personal Information shall require recorded authority, purpose, minimization, classification, source, notice where applicable, consent where applicable, access controls, retention, publication status, AI-use status, and correction path.

13.8.2(b) Notice shall be clear, accessible, purpose-specific, and proportionate to the context, and shall identify how Personal Information may be collected, used, shared, protected, retained, corrected, deleted where applicable, or subject to rights requests.

13.8.2(c) Consent shall be obtained where required by law, ethics, research protocol, community protocol, public authority requirement, agreement, or safeguards review, and shall be informed, specific, documented where required, and revocable or limited according to applicable conditions.

13.8.2(d) Collection shall avoid unnecessary identifiers, sensitive attributes, precise location, excessive metadata, health data, biometric data, financial data, vulnerable-person data, and other high-risk fields unless necessary and approved.

13.8.2(e) The controlling rule shall be that Personal Information shall be collected only with authority, purpose, and restraint.


13.8.3 Sensitive Personal Information Controls. 13.8.3(a) Sensitive Personal Information shall include information that may create heightened risk to dignity, rights, safety, access, inclusion, reputation, privacy, security, or public trust if misused or disclosed.

13.8.3(b) Sensitive Personal Information may include health information, biometric data, precise location, mobility data, financial data, employment data, identity documents, public authority interaction data, research participant data, vulnerable-person data, protected participant data, confidential source data, whistleblower data, children’s or youth data, and data revealing sensitive social, cultural, political, or community context.

13.8.3(c) Sensitive Personal Information shall require heightened authority review, minimization, access restriction, encryption where appropriate, logging where material, AI-use restrictions, transfer restrictions, public-safe review, retention limits, and incident response.

13.8.3(d) Sensitive Personal Information shall not be used in public outputs unless lawfully transformed and public-safe, and shall not be used in AI systems unless expressly authorized and governed.

13.8.3(e) The controlling rule shall be that sensitivity increases the burden of justification and protection.


13.8.4 Identity, Contact, Location, Device, Health, Biometric, Financial, Employment, Public Authority, Research Participant, and Vulnerable Person Data. 13.8.4(a) GCRI Canada shall apply specific controls to identity, contact, location, device, health, biometric, financial, employment, public authority, research participant, and vulnerable person data.

13.8.4(b) Identity and contact data shall be limited to necessary relationship, governance, participation, access, safety, or legal purposes and protected against unauthorized disclosure.

13.8.4(c) Location and mobility data shall require geospatial sensitivity review, re-identification review, minimization, aggregation or generalization where appropriate, and public-safe mapping controls.

13.8.4(d) Device data and logs shall be reviewed for identifiers, behavioral patterns, cyber risk, access risk, and metadata sensitivity.

13.8.4(e) Health, biometric, financial, employment, public authority, research participant, and vulnerable person data shall receive heightened classification, access, use, transfer, retention, AI-use, and publication controls.

13.8.4(f) The controlling rule shall be that each personal data type carries distinct risks and shall not be governed by a single generic privacy label.


13.8.5 De-Identification, Pseudonymization, Aggregation, and Re-Identification Risk Review. 13.8.5(a) De-identification, pseudonymization, aggregation, masking, generalization, suppression, synthetic substitution, and other privacy-preserving transformations shall be used where appropriate to reduce risk while preserving lawful public-benefit value.

13.8.5(b) GCRI Canada shall not claim data is anonymous, de-identified, public-safe, or low-risk unless review supports that status in context.

13.8.5(c) Re-identification risk review shall assess direct identifiers, quasi-identifiers, rare attributes, small populations, geospatial precision, temporal precision, linkage risk, mosaic risk, external data availability, AI-assisted inference, and future data availability.

13.8.5(d) Pseudonymized data shall remain Personal Information where re-identification keys, linkage, inference, or contextual risk persists.

13.8.5(e) Aggregation shall be reviewed for small-cell risk, group harm, public-safe mapping risk, and protected knowledge exposure.

13.8.5(f) The controlling rule shall be that transformation reduces risk only when supported by review, not by label.


13.8.6 Personal Information in AI, Model, Embedding, Retrieval, and Inference Systems. 13.8.6(a) Personal Information shall not be entered into AI, model, embedding, retrieval, inference, agentic, prompt, training, fine-tuning, summarization, translation, coding, analysis, visualization, or model-improvement systems unless expressly authorized, classified, and governed.

13.8.6(b) AI use involving Personal Information shall require lawful or approval basis, purpose, minimization, model register status, data retention review, provider terms review where applicable, cross-border review where applicable, cybersecurity review, access controls, inference records where material, and correction path.

13.8.6(c) Embeddings, retrieval indexes, feature stores, prompts, model outputs, inference records, logs, and evaluation records containing or derived from Personal Information shall inherit Personal Information restrictions unless reviewed and lawfully transformed.

13.8.6(d) Personal Information shall not be used for unauthorized AI training, fine-tuning, model improvement, profiling, automated decision-making, public authority use, finance use, sponsor benefit, provider development, or external release.

13.8.6(e) The controlling rule shall be that AI systems do not reduce privacy obligations; they multiply them.


13.8.7 Personal Information in Dashboards, Maps, Reports, Datasets, Repositories, Logs, and Public-Safe Outputs. 13.8.7(a) Personal Information shall not be displayed, mapped, published, released, included in repositories, included in logs, included in datasets, included in examples, or included in public-safe outputs unless lawful, necessary, proportionate, minimized, classified, reviewed, and approved.

13.8.7(b) Dashboards and maps shall avoid individual-level display, precise location, small-cell exposure, identity leakage, sensitive labels, vulnerable-person indicators, and re-identification pathways unless controlled and justified.

13.8.7(c) Reports and public-safe summaries shall use aggregation, redaction, generalization, anonymization where supported, pseudonymization where appropriate, and non-identifying language.

13.8.7(d) Repositories, logs, sample data, screenshots, release notes, API examples, schema examples, and technical documentation shall be reviewed to prevent accidental Personal Information disclosure.

13.8.7(e) Public-safe outputs containing Personal Information risk shall include correction path and shall be withdrawn or corrected where exposure occurs.

13.8.7(f) The controlling rule shall be that Personal Information shall not leak through outputs that appear technical, visual, or incidental.


13.8.8 Access Rights, Correction Requests, Deletion Requests, and Complaints Where Applicable. 13.8.8(a) GCRI Canada shall maintain processes for access rights, correction requests, deletion requests, restriction requests, objection requests, portability requests, complaints, grievances, and equivalent rights where applicable.

13.8.8(b) Requests shall be received, logged, verified where appropriate, classified, reviewed, answered, and closed according to applicable law, authority, data class, identity verification, security, public authority restrictions, research integrity, legal hold, protected knowledge obligations, and correctionability.

13.8.8(c) Correction requests shall be reviewed for impact on source records, derived records, datasets, dashboards, maps, AI indexes, embeddings, retrieval stores, publications, public-safe summaries, and downstream dependencies.

13.8.8(d) Deletion requests shall be honored where lawful and required, subject to retention obligations, legal hold, public authority restrictions, research integrity, safeguards, and archive requirements.

13.8.8(e) Complaints shall be handled through accessible, protective, timely, and recorded procedures.

13.8.8(f) The controlling rule shall be that Personal Information governance must include a route back from the data subject or affected person to the record.


13.8.9 Personal Information Breach Response. 13.8.9(a) A Personal Information breach shall include unauthorized access, disclosure, loss, misuse, alteration, deletion, copying, publication, AI ingestion, transfer, dataset release, dashboard display, map display, repository exposure, credential exposure, or other compromise of Personal Information.

13.8.9(b) Breach response shall include containment, severity classification, data identification, affected-person assessment, rights impact assessment, public authority assessment where applicable, cybersecurity assessment, legal review where applicable, notification review, correction, mitigation, recovery, post-incident review, and assurance.

13.8.9(c) Notification shall be provided where required by law, contract, public authority permission, research protocol, community safeguards, or risk-based procedure, and shall be public-safe or controlled according to sensitivity.

13.8.9(d) Breach correction may include access revocation, data takedown, dataset withdrawal, dashboard removal, map withdrawal, repository purge, AI index remediation, model remediation, publication correction, public-safe notice, controlled notice, deletion where lawful and required, sealing, or training.

13.8.9(e) The controlling rule shall be that Personal Information breach response must address harm, exposure, correction, and system weakness.


13.8.10 Personal Information Records, Processing Register, and Review Cycle. 13.8.10(a) GCRI Canada shall maintain Personal Information records, processing registers, and review cycles for material Personal Information activities.

13.8.10(b) Processing records shall identify data type, source, authority, purpose, data subjects or affected persons where applicable, classification, access roles, processing activity, AI-use status, transfer status, retention, publication status, public-safe status, security controls, rights process, correction path, and legal hold status where applicable.

13.8.10(c) Review cycles shall assess whether Personal Information remains necessary, accurate, proportionate, properly classified, properly secured, properly accessed, properly retained, properly excluded from unauthorized AI systems, and properly protected from publication exposure.

13.8.10(d) Processing records shall link to research protocols, public authority permissions, consent records, data agreements, datasets, dashboards, maps, publications, AI-use records, incident records, and correction records where applicable.

13.8.10(e) The controlling rule shall be that Personal Information processing must be known, reviewable, and correctable as an institutional system.


13.9 Health-Sensitive Data

13.9.1 Health-Sensitive Data as Heightened Safeguard Category. 13.9.1(a) Health-Sensitive Data shall be a heightened safeguard category within GCRI Canada’s data classification architecture because misuse, exposure, inaccurate analysis, public-safe failure, or context loss may affect dignity, privacy, rights, stigma, public health trust, community safety, public authority action, or vulnerable populations.

13.9.1(b) Health-Sensitive Data shall include personal health information, public health data, health system data, clinical data, biosecurity data, biosurveillance data, wastewater data, environmental health data, population health data, mobility-health data, sensor-derived health indicators, health vulnerability data, disability-related data, mental health data, and health-related geospatial data.

13.9.1(c) Health-Sensitive Data shall require heightened authority, purpose limitation, minimization, ethics review where applicable, public authority review where applicable, community review where appropriate, de-identification or aggregation where appropriate, AI-use restrictions, access controls, public-safe publication review, retention limits, and correction path.

13.9.1(d) Health-Sensitive Data shall not be treated as ordinary research data, ordinary public data, ordinary open data, ordinary dashboard data, or ordinary map data.

13.9.1(e) The controlling rule shall be that health-related evidence requires heightened safeguards because health information can harm persons and communities even when used for public benefit.


13.9.2 Health, Public Health, Biosecurity, Clinical, Sensor, Mobility, Environmental Health, Wastewater, Vulnerability, and Population Health Data. 13.9.2(a) GCRI Canada shall apply Health-Sensitive Data controls to health, public health, biosecurity, clinical, sensor, mobility, environmental health, wastewater, vulnerability, and population health data.

13.9.2(b) Health and clinical data shall require heightened privacy and research governance. Public health and population health data shall require public authority context review where applicable, small-cell review, public-safe interpretation, and stigma-risk review. Biosecurity data shall require public-safe, cybersecurity, controlled technology, and public authority review where applicable.

13.9.2(c) Sensor, mobility, environmental health, and wastewater data shall require review for geospatial precision, temporal precision, re-identification, group inference, public-safe mapping, vulnerable community exposure, and public warning confusion.

13.9.2(d) Vulnerability data shall not be used to stigmatize, rank, target, surveil, or expose persons or communities.

13.9.2(e) The controlling rule shall be that health context may transform otherwise technical or environmental data into heightened safeguard data.


13.9.3 Human-Subjects and Research Ethics Review Where Applicable. 13.9.3(a) Health-Sensitive Data activities shall undergo human-subjects, research ethics, institutional review, community review, public authority review, or equivalent review where applicable by law, research protocol, university requirement, public authority requirement, funder requirement, community safeguard, or GCRI Canada policy.

13.9.3(b) Review shall address research purpose, participant risk, consent or waiver where applicable, data minimization, vulnerability, confidentiality, recruitment, withdrawal, grievance, remedy, retention, publication, AI use, cross-border transfer, and correction.

13.9.3(c) GCRI Canada shall not bypass applicable ethics review by characterizing health-sensitive work as observability, dashboarding, public-safe communication, technical prototyping, AI evaluation, public authority learning, or Nexus interoperability.

13.9.3(d) Ethics-related conditions shall be recorded and carried into data access, processing, publication, retention, and correction.

13.9.3(e) The controlling rule shall be that health-sensitive research must be ethically authorized before it becomes institutionally usable.


13.9.4 Public Authority Health Data and Public Health Participant Controls. 13.9.4(a) Public Authority Health Data shall require public authority permission, capacity classification, lawful or approval basis, permitted use, prohibited use, confidentiality, public-safe status, AI-use limits, transfer limits, retention limits, publication limits, reference approval, and correction path.

13.9.4(b) Public health participant controls shall distinguish public authority learning, listening, data contribution, review, or participation from public health guidance, public health order, emergency declaration, regulatory approval, health system adoption, official public warning, public authority endorsement, or sovereign obligation.

13.9.4(c) Public health authority names, logos, titles, quotes, agency names, jurisdiction references, data contributions, and participation descriptions shall require approval and boundary language where used.

13.9.4(d) Public Authority Health Data shall not be used in dashboards, maps, reports, AI systems, datasets, public-safe summaries, finance-facing materials, sponsor materials, provider materials, or Nexus interfaces beyond recorded permission and public-safe review.

13.9.4(e) The controlling rule shall be that public health data requires both health safeguards and public authority boundary discipline.


13.9.5 Health-Sensitive Data Minimization, De-Identification, Aggregation, and Public-Safe Review. 13.9.5(a) Health-Sensitive Data shall be minimized, de-identified, aggregated, generalized, redacted, masked, synthetically substituted, or restricted where such measures preserve public-benefit purpose while reducing rights, stigma, re-identification, geospatial, public authority, and public-safe risks.

13.9.5(b) De-identification and aggregation shall be reviewed for small-cell risk, rare condition risk, community identification risk, geospatial precision, temporal precision, linkage risk, AI-assisted inference, and future data combination risk.

13.9.5(c) Public-safe review shall assess whether publication could expose individuals, communities, health conditions, vulnerable groups, sensitive sites, public health vulnerabilities, public authority restricted data, or stigmatizing inferences.

13.9.5(d) Health-sensitive outputs shall avoid false precision, unsupported certainty, warning-like presentation, public authority confusion, and clinical or public health advice implications.

13.9.5(e) The controlling rule shall be that health-sensitive publication shall be sufficient for learning and accountability, not excessive in detail.


13.9.6 AI Use Restrictions for Health-Sensitive Data. 13.9.6(a) Health-Sensitive Data shall not be entered into, trained on, fine-tuned with, embedded in, retrieved through, analyzed by, summarized by, translated by, or otherwise processed in AI systems unless expressly authorized and governed.

13.9.6(b) AI use involving Health-Sensitive Data shall require lawful or approval basis, ethics review where applicable, model register approval, data minimization, access controls, retention review, provider terms review where applicable, cross-border review where applicable, cybersecurity review, bias review, hallucination controls, human review, and correction path.

13.9.6(c) AI outputs derived from Health-Sensitive Data shall be treated as Health-Sensitive Data or rights-bearing data unless reviewed and lawfully transformed.

13.9.6(d) GCRI Canada shall not use Health-Sensitive Data for unauthorized AI training, model improvement, profiling, public authority decision support, public warning, clinical recommendation, insurance inference, finance inference, provider development, sponsor benefit, or public release.

13.9.6(e) The controlling rule shall be that AI use increases the sensitivity of health data governance, not the freedom to process it.


13.9.7 Cross-Border Transfer and Sovereign Data Review for Health-Sensitive Data. 13.9.7(a) Cross-border transfer, remote access, cloud processing, AI processing, backup, mirroring, repository storage, embedding, indexing, or external sharing of Health-Sensitive Data shall require cross-border and sovereign data review where applicable.

13.9.7(b) Review shall address law, health privacy, public authority restrictions, research ethics, data localization, sovereign data zones, compute-to-data options, contractual restrictions, conflict-of-law risk, cybersecurity, protected knowledge, public-safe status, sanctions, export controls, controlled technology, retention, deletion, and correction.

13.9.7(c) Compute-to-data, controlled rooms, clean rooms, data rooms, local processing, aggregation, or synthetic data shall be preferred where research value can be achieved without transferring Health-Sensitive Data.

13.9.7(d) Transfer shall be refused where legal, privacy, public authority, cybersecurity, protected knowledge, or public-safe risks cannot be adequately controlled.

13.9.7(e) The controlling rule shall be that health-sensitive interoperability shall not override jurisdictional and rights protections.


13.9.8 Health-Sensitive Dashboards, Maps, and Reports as Public-Safe Outputs Only Where Properly Reviewed. 13.9.8(a) Health-sensitive dashboards, maps, reports, public-safe summaries, datasets, and visualizations shall be released externally only where properly reviewed and classified as public-safe, controlled, or restricted.

13.9.8(b) Review shall assess personal data exposure, small-cell exposure, sensitive-condition exposure, vulnerable group exposure, re-identification, geospatial precision, public authority permission, public warning confusion, stigma, public health advice implication, AI output error, and correction path.

13.9.8(c) Health-sensitive dashboards and maps shall avoid exact sensitive locations, individual-level information, small groups, unsupported risk labels, warning-like design, public authority implication, and stigmatizing displays.

13.9.8(d) Reports shall include limitations, confidence, uncertainty, source basis, public-safe transformation, non-clinical status where applicable, no-public-health-order language where applicable, and correction path.

13.9.8(e) The controlling rule shall be that health-sensitive outputs may be public-safe only through deliberate transformation and review.


13.9.9 Health-Sensitive Data Incidents, Breach Notice, Correction, and Withdrawal. 13.9.9(a) Health-Sensitive Data incidents shall include unauthorized access, disclosure, AI ingestion, transfer, publication, dataset release, dashboard display, map display, re-identification risk, public authority breach, stigma risk, small-cell exposure, inaccurate health claim, public warning confusion, or protected knowledge exposure.

13.9.9(b) Incident response shall include containment, severity classification, affected data identification, affected-person or affected-community assessment where applicable, public authority notice where applicable, legal review where applicable, ethics review where applicable, cybersecurity review where applicable, correction, mitigation, withdrawal, retraction, and post-incident review.

13.9.9(c) Notice shall be provided where required by law, agreement, public authority permission, research protocol, ethics condition, community safeguard, or risk-based procedure.

13.9.9(d) Correction may include data correction, access restriction, dataset withdrawal, dashboard removal, map withdrawal, public-safe correction notice, controlled notice, AI index remediation, model remediation, report correction, or deletion where lawful and required.

13.9.9(e) The controlling rule shall be that health-sensitive incidents require response calibrated to dignity, rights, public health trust, and public-safe risk.


13.9.10 Health-Sensitive Data Register and Assurance. 13.9.10(a) GCRI Canada shall maintain a Health-Sensitive Data Register or equivalent records for material Health-Sensitive Data activities.

13.9.10(b) The Register shall identify data source, data type, authority, research protocol where applicable, ethics review where applicable, public authority permission where applicable, affected population or community where appropriate, classification, access roles, AI-use status, transfer status, retention, publication status, public-safe status, safeguards, correction path, incident status, and legal hold status where applicable.

13.9.10(c) Health-Sensitive Data assurance shall periodically review whether data remains necessary, properly classified, properly secured, lawfully retained, ethically governed, public-safe, protected from unauthorized AI use, and correctionable.

13.9.10(d) Assurance findings may require access reduction, data deletion, sealing, aggregation, public-safe transformation, publication correction, dashboard withdrawal, map withdrawal, training, or Board or committee reporting.

13.9.10(e) The controlling rule shall be that Health-Sensitive Data requires continuing assurance because risk changes with context, linkage, and time.


13.10 Public Authority Data

13.10.1 Public Authority Data as Special Handling Category. 13.10.1(a) Public Authority Data shall be a special handling category because it may carry public power, legal duties, public trust, public authority confidentiality, public finance sensitivity, public safety sensitivity, public health sensitivity, regulatory sensitivity, procurement sensitivity, emergency-management sensitivity, infrastructure sensitivity, and public-law implication risk.

13.10.1(b) Public Authority Data includes data received from, generated with, derived from, referencing, or materially involving public authorities, public programs, public infrastructure, public finance, emergency management, public health, public safety, regulatory activity, procurement, public authority learning, or public authority participation.

13.10.1(c) Public Authority Data shall be governed through authority records, capacity classification, permitted use, prohibited use, confidentiality, publication limits, AI-use limits, retention, transfer, public-safe review, reference approval, and correction path.

13.10.1(d) Public Authority Data shall not be treated as ordinary public data merely because the public authority is public, the data concerns public matters, or the data was shared in a meeting, event, controlled room, public authority room, or email.

13.10.1(e) The controlling rule shall be that Public Authority Data must be handled as data with both information risk and authority risk.


13.10.2 Public Authority Data Contribution Records. 13.10.2(a) GCRI Canada shall maintain Public Authority Data Contribution Records for material data received from, generated with, derived from, or involving public authorities.

13.10.2(b) Contribution records shall identify the public authority, contributor, authorized representative where applicable, capacity classification, data description, source, date, authority or permission basis, purpose, permitted uses, prohibited uses, classification, confidentiality, AI-use limits, transfer limits, publication limits, retention, correction path, and reference approval status.

13.10.2(c) Contribution records shall distinguish official data contribution, learning-context sharing, informal background information, public source information, confidential information, restricted information, and controlled-room material.

13.10.2(d) Data lacking adequate contribution record shall be held, restricted, clarified, returned, deleted where lawful and required, or not used until authority is resolved.

13.10.2(e) The controlling rule shall be that public authority data must enter GCRI Canada through a record, not through assumption.


13.10.3 Authority, Capacity, Scope, Permitted Use, Disclosure Limits, AI-Use Limits, Retention, Transfer, Publication, and Correction Terms. 13.10.3(a) Every material Public Authority Data record shall identify authority, capacity, scope, permitted use, prohibited use, disclosure limits, AI-use limits, retention, transfer, publication, public-safe status, reference approval, correction terms, and closeout requirements.

13.10.3(b) Authority shall identify the basis on which GCRI Canada may receive, hold, process, analyze, use, share, publish, or retain the data. Capacity shall identify whether the public authority acted as observer, learning participant, regulator-listening participant, public finance reader, emergency-management participant, public infrastructure operator participant, public health participant, data contributor, technical reviewer, host, funder, statutory authority, or other recorded capacity.

13.10.3(c) Permitted use shall be narrow enough to guide research, evidence processing, dashboarding, mapping, public-safe publication, Academy use, Nexus interface routing, and correction. Prohibited use shall expressly exclude uses not authorized, including public claims, AI training, finance-facing reuse, provider materials, sponsor materials, or external release where not permitted.

13.10.3(d) Disclosure limits shall specify whether data may be internal, controlled, restricted, public-safe, public, included in annexes, used in public-safe summaries, included in dashboards, included in maps, included in datasets, or shared with GRF, GRA, Protocol Authority, Nexus entities, public authorities, providers, sponsors, hosts, universities, communities, National Companies, or Project SPVs.

13.10.3(e) AI-use limits shall specify whether data may be used in AI-assisted research, summarization, translation, embedding, retrieval, model evaluation, training, fine-tuning, or model improvement, and shall prohibit unauthorized AI use.

13.10.3(f) The controlling rule shall be that Public Authority Data permissions must be explicit enough to prevent drift.


13.10.4 Public Authority Data Does Not Create Public Authority Delegation to GCRI Canada. 13.10.4(a) Public Authority Data contribution, access, analysis, review, dashboarding, mapping, publication, or discussion shall not create public authority delegation to GCRI Canada.

13.10.4(b) GCRI Canada shall not become a regulator, procurement body, public finance approver, public warning authority, emergency command actor, public health authority, public safety authority, public infrastructure operator, licensing authority, permitting authority, enforcement body, or sovereign actor by receiving or using Public Authority Data.

13.10.4(c) Publications, dashboards, maps, reports, public-safe summaries, Academy materials, technical notes, and Nexus interface materials using Public Authority Data shall include no-delegation language where material.

13.10.4(d) Where Public Authority Data use risks creating delegation confusion, GCRI Canada shall narrow use, add boundary language, restrict access, seek clarification, or refuse the activity.

13.10.4(e) The controlling rule shall be that data sharing is not delegation of public power.


13.10.5 Public Authority Data Does Not Create Endorsement, Adoption, Procurement Approval, Funding Approval, Regulatory Approval, Public Warning, or Sovereign Obligation. 13.10.5(a) Public Authority Data contribution, access, review, comment, publication, dashboard use, map use, participation, attendance, or public authority learning shall not create endorsement, adoption, procurement approval, funding approval, public finance approval, regulatory approval, official guidance, public warning, emergency command, sovereign obligation, or public-law status.

13.10.5(b) GCRI Canada shall not state or imply that use of Public Authority Data means a public authority has approved GCRI Canada, adopted findings, endorsed a provider, approved a project, funded an activity, issued guidance, made a public finance decision, issued a warning, or accepted sovereign obligation.

13.10.5(c) Public materials referencing Public Authority Data shall use approved capacity language and non-endorsement language where material.

13.10.5(d) Sponsors, providers, hosts, National Companies, Project SPVs, capital readers, media, or other third parties shall not use Public Authority Data references to imply public authority support, procurement advantage, finance-readiness, or provider preference.

13.10.5(e) The controlling rule shall be that public authority data presence is not public authority approval.


13.10.6 Public Authority Data in Evidence Packs, Dashboards, Maps, Publications, Truth Engine Outputs, Observatory Outputs, and Academy Materials. 13.10.6(a) Public Authority Data may be used in evidence packs, dashboards, maps, publications, Truth Engine outputs, Observatory outputs, technical notes, Academy materials, public authority learning materials, public-safe summaries, controlled annexes, restricted annexes, and Nexus interface materials only within recorded authority, classification, purpose, access, publication, and correction terms.

13.10.6(b) Evidence packs using Public Authority Data shall preserve source lineage, authority, capacity, permitted use, limitations, confidence, uncertainty, public-safe status, and correction path.

13.10.6(c) Dashboards and maps using Public Authority Data shall include public authority boundary controls, public warning boundary controls where applicable, sensitive-location controls where applicable, update status, limitations, and correction path.

13.10.6(d) Truth Engine and Observatory outputs using Public Authority Data shall not be represented as public authority determinations, public warnings, regulatory guidance, procurement decisions, funding decisions, or sovereign acts.

13.10.6(e) Academy and public authority learning materials using Public Authority Data shall support learning only and shall include no-delegation and no-endorsement language where material.

13.10.6(f) The controlling rule shall be that Public Authority Data may support evidence and learning only within recorded public authority boundaries.


13.10.7 Public Authority Data Reference Approval for Names, Logos, Titles, Agency Names, Jurisdictions, Quotes, Photos, Attendance, and Data Contributions. 13.10.7(a) GCRI Canada shall obtain required approval before publishing or externally using public authority names, logos, titles, agency names, jurisdictions, quotes, photos, attendance, role descriptions, data contributions, or other public authority references.

13.10.7(b) Reference approval records shall identify approved language, approved visual use, permitted publication contexts, prohibited implications, expiration where any, confidentiality limits, public-safe status, and correction path.

13.10.7(c) Public authority reference approval shall not imply approval of GCRI Canada, approval of the publication, adoption of findings, public authority endorsement, procurement approval, funding approval, regulatory approval, public finance approval, official guidance, public warning, emergency command, or sovereign obligation unless a competent public authority record expressly provides such effect.

13.10.7(d) Public authority references shall be corrected, removed, narrowed, or clarified where approval is absent, expired, exceeded, misdescribed, or likely to mislead.

13.10.7(e) The controlling rule shall be that public authority identity shall be used only with approved scope and boundary.


13.10.8 Public Authority Data Cross-Border Transfer, Localization, and Sovereign Data Controls. 13.10.8(a) Cross-border transfer, remote access, cloud processing, backup, mirroring, AI processing, embedding, indexing, repository storage, or external sharing of Public Authority Data shall require cross-border, localization, and sovereign data review where applicable.

13.10.8(b) Review shall address law, public authority permission, jurisdictional limits, confidentiality, public sector duties, data localization, sovereign data zones, compute-to-data options, conflict-of-law risk, cybersecurity, public-safe status, retention, deletion, sanctions, export controls, controlled technology, and correction path.

13.10.8(c) Compute-to-data, local processing, controlled rooms, public authority rooms, clean rooms, data rooms, restricted access, aggregation, or public-safe summaries shall be preferred where public authority purposes can be met without transferring sensitive data.

13.10.8(d) Public Authority Data shall not be transferred or accessed across borders where permission, law, confidentiality, cybersecurity, public authority restrictions, or public-safe review do not support the transfer.

13.10.8(e) The controlling rule shall be that public authority interoperability shall not override localization, sovereignty, or public trust.


13.10.9 Public Authority Data Incidents and Correction. 13.10.9(a) Public Authority Data incidents shall include unauthorized access, unauthorized disclosure, unauthorized AI use, unauthorized transfer, publication error, public authority misdescription, reference misuse, public warning confusion, emergency command implication, procurement implication, finance implication, regulatory implication, data breach, dashboard defect, map defect, dataset release defect, or correction failure involving Public Authority Data.

13.10.9(b) Incident response shall include containment, severity classification, public authority notice where appropriate or required, legal review where applicable, cybersecurity review where applicable, public-safe review, correction, withdrawal, retraction, access restriction, dependency review, and post-incident review.

13.10.9(c) Correction may include data correction, reference correction, dashboard removal, map withdrawal, dataset withdrawal, AI index remediation, publication correction, public-safe notice, controlled notice, or third-party correction request.

13.10.9(d) Incidents involving public warning confusion, regulatory implication, procurement implication, funding implication, public finance implication, emergency command implication, or sovereign obligation implication shall receive heightened review.

13.10.9(e) The controlling rule shall be that Public Authority Data incidents must repair both data handling and public authority meaning.


13.10.10 Public Authority Data Register and Assurance. 13.10.10(a) GCRI Canada shall maintain a Public Authority Data Register for material Public Authority Data activities.

13.10.10(b) The Register shall identify public authority, data contribution, authority or permission basis, capacity classification, data class, access class, permitted use, prohibited use, confidentiality, AI-use status, transfer status, retention, publication status, public-safe status, reference approval, dependencies, correction path, incident status, and closeout status.

13.10.10(c) The Register shall link to public authority capacity records, data contribution records, research protocols, evidence records, dashboard records, map records, publication records, public-safe review records, AI-use records, cross-border review records, reference records, incident records, and correction records.

13.10.10(d) Public Authority Data assurance shall periodically review whether data remains properly authorized, properly classified, properly accessed, properly protected, properly referenced, properly bounded, properly retained, properly excluded from unauthorized AI use, and properly correctable.

13.10.10(e) Assurance findings may require access reduction, data return, deletion where lawful and required, sealing, publication correction, dashboard correction, map correction, public authority notice, training, agreement revision, or Board or committee reporting.

13.10.10(f) The controlling rule shall be that Public Authority Data must remain governed for as long as GCRI Canada holds, references, derives from, or relies on it.

13.11 Cyber-Sensitive Data

13.11.1 Cyber-Sensitive Data as Heightened Safeguard Category. 13.11.1(a) Cyber-Sensitive Data shall be a heightened safeguard category within GCRI Canada’s data classification architecture because unauthorized access, disclosure, publication, transfer, AI ingestion, repository exposure, or uncontrolled reuse may create cybersecurity harm, infrastructure harm, public authority harm, operational harm, public-safe harm, legal risk, or public trust harm.

13.11.1(b) Cyber-Sensitive Data shall include data, records, findings, logs, configurations, technical details, incident materials, vulnerability information, exploit information, threat signals, security architecture, credentials, keys, tokens, secrets, system diagrams, dependency risks, repository risks, and other materials whose disclosure or misuse could enable unauthorized access, compromise, disruption, exploitation, surveillance, evasion, or harm.

13.11.1(c) Cyber-Sensitive Data shall be governed through classification, need-to-know access, secure storage, secure transfer, AI-use restrictions, repository controls, publication controls, coordinated disclosure where applicable, public-safe review, retention limits, sealing where required, incident response, and correctionability.

13.11.1(d) Cyber-Sensitive Data shall not be treated as ordinary technical data merely because it is useful for research, evidence, observability, technical baselines, dashboards, maps, software, public-good release, or Nexus interoperability.

13.11.1(e) The controlling rule shall be that cyber-sensitive evidence shall strengthen security and public trust, not distribute avoidable risk.


13.11.2 Vulnerability Data, Exploit Information, Security Logs, Incident Data, Threat Signals, Network Data, Credentials, Keys, Tokens, Secrets, System Diagrams, and Security Findings. 13.11.2(a) Cyber-Sensitive Data shall include vulnerability data, exploit information, proof-of-concept exploit detail, incident data, threat signals, security logs, access logs, authentication logs, network data, telemetry, packet captures, malware indicators, detection logic, security findings, repository findings, dependency findings, configuration findings, system diagrams, architecture diagrams, network layouts, endpoint details, administrative interfaces, and infrastructure dependencies.

13.11.2(b) Cyber-Sensitive Data shall also include credentials, passwords, API keys, service tokens, access tokens, encryption keys, signing keys, recovery codes, wallet keys where applicable, administrative credentials, session tokens, certificates, secrets, private endpoints, sensitive environment variables, and other access materials.

13.11.2(c) Cyber-Sensitive Data shall include security findings concerning public-good software, APIs, schemas, data contracts, dashboards, maps, datasets, repositories, technical baselines, AI systems, compute workloads, controlled rooms, public authority rooms, data rooms, evidence rooms, and Nexus interfaces.

13.11.2(d) Cyber-Sensitive Data shall be classified according to exploitability, affected systems, affected data, public authority relevance, infrastructure relevance, dependency impact, disclosure risk, remediation status, and public-safe publication status.

13.11.2(e) The controlling rule shall be that any material that can materially assist attack, evasion, unauthorized access, exposure, or compromise shall be handled as Cyber-Sensitive Data until reviewed otherwise.


13.11.3 Restricted Access, Need-to-Know, Controlled Room, and No-Download Handling. 13.11.3(a) Cyber-Sensitive Data shall be subject to restricted access, need-to-know authorization, purpose limitation, role-based access, time-limited access where appropriate, access logging where material, secure storage, secure transfer, and revocation upon role change, purpose expiry, incident, or misuse risk.

13.11.3(b) Highly sensitive cyber materials may require controlled room, clean room, evidence room, technical review room, incident room, no-download room, or equivalent restricted handling environment.

13.11.3(c) No-download handling shall be used where copying, export, screenshotting, local storage, model ingestion, uncontrolled sharing, or repository inclusion would create material cybersecurity risk.

13.11.3(d) Cyber-Sensitive Data shall not be shared by unmanaged email, open chat, personal cloud storage, public links, public repositories, public issue trackers, unauthorized ticketing systems, unauthorized AI tools, or uncontrolled collaboration environments.

13.11.3(e) Access permissions shall identify permitted use, prohibited use, copy controls, AI-use restrictions, onward disclosure limits, retention limits, incident reporting duties, and correction path.

13.11.3(f) The controlling rule shall be that cyber-sensitive access shall be granted by need and environment, not by general participation or technical curiosity.


13.11.4 Coordinated Vulnerability Disclosure and Public-Safe Cyber Publication. 13.11.4(a) GCRI Canada shall use coordinated vulnerability disclosure where Cyber-Sensitive Data concerns vulnerabilities, exploitability, affected systems, affected providers, public authorities, hosts, communities, repositories, dependencies, public-good software, technical baselines, dashboards, APIs, schemas, or Nexus interfaces.

13.11.4(b) Coordinated vulnerability disclosure shall identify affected system, owner or maintainer, severity, validation status, remediation status, disclosure timeline, embargo where appropriate, affected parties, notice recipients, public-safe summary, and correction path.

13.11.4(c) Public-safe cyber publication shall avoid exploit-enabling details, sensitive configurations, credentials, attack paths, system-specific weaknesses, precise infrastructure exposure, or operational details that increase risk before remediation or where disclosure is otherwise unsafe.

13.11.4(d) Public-safe cyber publication may use summaries, general descriptions, delayed disclosure, controlled advisories, restricted annexes, patched-release notes, or vulnerability identifiers where appropriate.

13.11.4(e) Coordinated disclosure shall not create certification, security guarantee, provider endorsement, public authority approval, procurement approval, finance-readiness, or protocol effect.

13.11.4(f) The controlling rule shall be that cyber publication shall inform protection without enabling exploitation.


13.11.5 No Release of Exploit-Enabling Details Without Lawful, Safety-Justified, and Security-Reviewed Authority. 13.11.5(a) GCRI Canada shall not release exploit-enabling details without lawful authority, safety justification, security review, public-safe review, affected-system review where appropriate, coordinated disclosure review where appropriate, and recorded approval.

13.11.5(b) Exploit-enabling details may include working exploit code, step-by-step exploit instructions, unpatched vulnerability details, bypass techniques, credential misuse pathways, privilege escalation methods, system-specific attack paths, sensitive endpoint information, security control weaknesses, operational diagrams, and details likely to materially increase unauthorized exploitation risk.

13.11.5(c) Release of exploit-enabling details shall be refused, delayed, restricted, redacted, generalized, or routed through controlled disclosure where publication would create disproportionate risk.

13.11.5(d) Security research, public-good software, technical baseline publication, Academy training, public authority learning, or media engagement shall not justify disclosure of exploit-enabling detail without required review.

13.11.5(e) The controlling rule shall be that cyber transparency shall not become exploit distribution.


13.11.6 Cyber-Sensitive Data in Truth Engine, Observatory, Dashboards, Reports, Software, Repositories, and Technical Baselines. 13.11.6(a) Cyber-Sensitive Data may appear in or support Truth Engine methods, Observatory methods, evidence packs, dashboards, reports, software, APIs, schemas, repositories, technical baselines, technical notes, release notes, benchmark harnesses, Academy materials, public authority learning materials, and Nexus interfaces only within recorded authority, classification, access, publication, and correction controls.

13.11.6(b) Truth Engine and Observatory use of Cyber-Sensitive Data shall preserve source lineage, classification, confidence, limitations, disclosure restrictions, public-safe status, and correction path.

13.11.6(c) Dashboards and reports involving Cyber-Sensitive Data shall avoid exposing live vulnerabilities, sensitive logs, system diagrams, infrastructure dependencies, credentials, unpatched weaknesses, or threat details that enable misuse.

13.11.6(d) Software, repositories, examples, documentation, test data, issue trackers, release notes, and technical baselines shall be reviewed to ensure they do not include secrets, credentials, exploit-enabling detail, sensitive configurations, vulnerable code patterns, or unsafe operational instructions.

13.11.6(e) Public-good technical release shall not override cyber-sensitive classification, coordinated disclosure obligations, secure release discipline, or public-safe publication review.

13.11.6(f) The controlling rule shall be that cyber-sensitive material shall remain protected even when embedded inside technical assets or evidence systems.


13.11.7 Export-Control, Sanctions, Controlled Technology, and National Security Review. 13.11.7(a) Cyber-Sensitive Data shall be reviewed for export-control, sanctions, controlled technology, dual-use, national security, infrastructure-security, and jurisdictional restrictions where risk exists.

13.11.7(b) Review shall assess whether the data includes advanced cyber capabilities, exploit capabilities, malware-related information, encryption-sensitive information, controlled technology, telecommunications-sensitive information, AI-enabled cyber capability, critical infrastructure information, sovereign compute details, or materials restricted by law or public-safe policy.

13.11.7(c) Access, transfer, publication, repository inclusion, training use, contribution, collaboration, or release may be restricted by person, entity, jurisdiction, purpose, technology class, security status, or public-safe status.

13.11.7(d) Sanctions review shall assess whether access, support, collaboration, contribution, download, hosting, disclosure, or technical assistance may involve prohibited persons, entities, jurisdictions, or uses.

13.11.7(e) Where risk cannot be adequately controlled, GCRI Canada shall refuse release, restrict access, generalize disclosure, delay publication, or use public-safe summaries.

13.11.7(f) The controlling rule shall be that public-good cyber work shall remain lawful, security-reviewed, and jurisdictionally disciplined.


13.11.8 Cyber-Sensitive Data Incidents, Containment, Notification, Correction, and Lessons Learned. 13.11.8(a) Cyber-Sensitive Data incidents shall include unauthorized access, unauthorized disclosure, credential exposure, key exposure, token exposure, secret leakage, repository exposure, public issue exposure, unauthorized AI ingestion, unauthorized transfer, unsafe publication, exploit-enabling release, dashboard exposure, map exposure, dataset release, public authority breach, infrastructure exposure, or correction failure.

13.11.8(b) Incident response shall include immediate containment, access revocation where appropriate, credential or key rotation where appropriate, repository takedown or purge where appropriate, affected-system assessment, severity classification, legal review where applicable, public authority notice where applicable, provider or host notice where applicable, coordinated disclosure where applicable, correction, mitigation, and post-incident review.

13.11.8(c) Notification shall be public-safe, controlled, restricted, or confidential according to sensitivity, affected parties, law, contracts, public authority requirements, cybersecurity risk, and public-safe implications.

13.11.8(d) Correction may include publication correction, repository correction, dashboard removal, dataset withdrawal, technical release patch, credential rotation, AI index remediation, model remediation, access restriction, controlled notice, public-safe notice, or training.

13.11.8(e) Lessons learned shall address root cause, access controls, release gates, repository controls, AI-use controls, training, monitoring, and assurance.

13.11.8(f) The controlling rule shall be that cyber-sensitive incidents must repair exposure and reduce future exploitability.


13.11.9 Cyber-Sensitive Data Retention, Sealing, Deletion, and Legal Hold. 13.11.9(a) Cyber-Sensitive Data shall be retained only for lawful, necessary, mission-justified, security, audit, incident response, research integrity, correctionability, contractual, public authority, or legal hold purposes.

13.11.9(b) Retention periods shall reflect severity, sensitivity, affected systems, remediation status, public authority obligations, legal obligations, coordinated disclosure status, vulnerability lifecycle, and continuing security need.

13.11.9(c) Sealing shall be used where Cyber-Sensitive Data must be preserved but access must be tightly restricted due to exploitability, legal privilege, public authority sensitivity, active incident, investigation, national security, or public-safe risk.

13.11.9(d) Deletion or destruction shall occur where lawful, required, authorized, and consistent with legal hold, auditability, correctionability, incident response, and public authority obligations.

13.11.9(e) Archived cyber materials shall be marked to prevent current reliance and protected against uncontrolled access.

13.11.9(f) The controlling rule shall be that Cyber-Sensitive Data shall not be retained indefinitely merely because it may be technically interesting or future-useful.


13.11.10 Cyber-Sensitive Data Register and Assurance. 13.11.10(a) GCRI Canada shall maintain a Cyber-Sensitive Data Register or equivalent records for material Cyber-Sensitive Data activities.

13.11.10(b) The Register shall identify data ID, Case ID, source, system, owner, custodian, sensitivity, vulnerability or incident status where applicable, classification, access roles, handling class, AI-use status, transfer status, publication status, coordinated disclosure status, remediation status, retention status, sealing status, correction path, and legal hold status where applicable.

13.11.10(c) Cyber-Sensitive Data assurance shall periodically review whether data remains properly classified, properly accessed, properly secured, properly retained, properly excluded from unauthorized AI systems, properly handled in repositories, properly controlled in publications, and properly correctable.

13.11.10(d) Assurance findings may require access reduction, key rotation, secret removal, repository remediation, dashboard revision, dataset withdrawal, publication correction, secure release update, coordinated disclosure update, training, or Board or committee reporting.

13.11.10(e) The controlling rule shall be that cyber-sensitive governance must be auditable because security risk changes with exposure, dependencies, and time.


13.12 Infrastructure-Sensitive Data

13.12.1 Infrastructure-Sensitive Data as Heightened Safeguard Category. 13.12.1(a) Infrastructure-Sensitive Data shall be a heightened safeguard category because unauthorized access, disclosure, mapping, publication, AI use, dashboarding, transfer, or reuse may create physical security risk, cyber-physical risk, public safety risk, operational risk, public authority risk, national or regional resilience risk, or public trust harm.

13.12.1(b) Infrastructure-Sensitive Data shall include data concerning critical infrastructure, mission-critical infrastructure, public infrastructure, private infrastructure serving public functions, utilities, telecommunications, AI-RAN, O-RAN, private wireless, DePIN, energy, water, food, transport, ports, corridors, logistics, public safety systems, health systems, emergency systems, industrial systems, data centers, compute environments, sensors, operational technology, and cyber-physical dependencies.

13.12.1(c) Infrastructure-Sensitive Data shall require classification, need-to-know access, public-safe mapping review, cybersecurity review, public authority review where applicable, host or operator review where appropriate, publication controls, transfer controls, AI-use controls, retention limits, incident response, and correctionability.

13.12.1(d) Infrastructure-Sensitive Data shall not be treated as ordinary geospatial, technical, public, or public authority data merely because infrastructure is visible, publicly known, or discussed in public policy.

13.12.1(e) The controlling rule shall be that infrastructure evidence shall support resilience without creating infrastructure exposure.


13.12.2 Critical Infrastructure Locations, Dependencies, Vulnerabilities, Operational Weaknesses, Network Layouts, Utility Systems, Ports, Corridors, Energy, Water, Food, Telecom, Public Safety, Industrial, and Logistics Data. 13.12.2(a) Infrastructure-Sensitive Data shall include critical infrastructure locations, sensitive site locations, system dependencies, chokepoints, operational weaknesses, vulnerabilities, failure points, network layouts, control system details, access routes, security controls, recovery dependencies, capacity limits, and interdependency maps.

13.12.2(b) This category shall apply to utility systems, ports, corridors, logistics systems, energy systems, water systems, food systems, telecommunications systems, AI-RAN systems, O-RAN systems, private wireless systems, DePIN systems, public safety systems, industrial systems, health infrastructure, emergency systems, data centers, compute facilities, sensor networks, and operational technology systems.

13.12.2(c) Infrastructure-Sensitive Data may be generated by sensors, observability nodes, digital twins, satellite systems, geospatial analysis, cyber logs, public authority data, provider data, host data, field research, dashboards, maps, or public-source aggregation.

13.12.2(d) Data that is individually public may become Infrastructure-Sensitive Data when linked, mapped, aggregated, enriched, or combined into dependency, vulnerability, operational, or targeting insight.

13.12.2(e) The controlling rule shall be that infrastructure sensitivity depends on what the data enables, not only whether each fact is public.


13.12.3 Public-Safe Mapping and Visualization Controls. 13.12.3(a) Infrastructure-Sensitive Data shall be subject to public-safe mapping and visualization controls before inclusion in maps, dashboards, reports, digital twins, Observatory outputs, Truth Engine outputs, public-safe summaries, public authority learning materials, Academy materials, or media materials.

13.12.3(b) Public-safe mapping review shall assess whether visualization exposes sensitive locations, operational dependencies, vulnerabilities, access paths, failure points, response gaps, cyber-physical attack surfaces, public authority restricted data, host data, provider data, or protected knowledge.

13.12.3(c) Visualization controls may include aggregation, generalization, resolution reduction, masking, delay, layer suppression, sensitive-site removal, access restriction, controlled annex treatment, no-download rules, and no-map publication.

13.12.3(d) Dashboard and map design shall avoid warning-like, operational, targeting, or status labels that could mislead users or increase infrastructure risk.

13.12.3(e) The controlling rule shall be that infrastructure visualization must be safe by design, not merely disclaimed.


13.12.4 Aggregation, Generalization, Redaction, Delay, Resolution Reduction, and Restricted Annex Treatment. 13.12.4(a) GCRI Canada shall use aggregation, generalization, redaction, delayed release, resolution reduction, restricted annex treatment, controlled annex treatment, synthetic substitution, metadata limitation, or no-release treatment where necessary to reduce infrastructure-sensitive risk.

13.12.4(b) Aggregation shall reduce site-specific exposure. Generalization shall reduce exactness. Redaction shall remove sensitive operational or security detail. Delay shall reduce time-sensitive exploitability. Resolution reduction shall reduce map or dashboard precision. Restricted annex treatment shall allow authorized review without public exposure.

13.12.4(c) Public-safe transformation shall not distort evidence or conceal material limitations. Where transformation changes meaning, the public-safe output shall disclose limitations at a safe level.

13.12.4(d) Restricted annexes containing infrastructure-sensitive details shall be distributed only under need-to-know, access logging where material, no-download restrictions where appropriate, AI-use restrictions, and onward disclosure limits.

13.12.4(e) The controlling rule shall be that infrastructure-sensitive evidence should be transformed before release where safe transformation can preserve public-benefit value.


13.12.5 Host, Operator, Public Authority, Provider, National Company, and Project SPV Data Controls. 13.12.5(a) Infrastructure-Sensitive Data received from or involving hosts, infrastructure operators, public authorities, providers, National Companies, Project SPVs, universities, sponsors, partners, or communities shall be governed according to contribution records, source permissions, confidentiality, role boundaries, public-safe review, access controls, AI-use restrictions, transfer limits, publication limits, and correction path.

13.12.5(b) Host or operator participation shall not grant GCRI Canada operational control, infrastructure ownership, emergency command authority, public warning authority, procurement authority, public authority status, finance-readiness authority, provider approval authority, or execution authority.

13.12.5(c) Provider participation shall not create provider preference, procurement advantage, certification, public authority endorsement, finance-readiness, technical approval, or Nexus-compatible status by default.

13.12.5(d) National Company or Project SPV data use shall preserve legal separateness and shall not make GCRI Canada an executing party, project operator, asset owner, or investment recommender.

13.12.5(e) The controlling rule shall be that infrastructure data relationships must preserve both security and role separation.


13.12.6 Infrastructure-Sensitive Data in Observatory Nodes, Digital Twins, Dashboards, Maps, Reports, and Evidence Packs. 13.12.6(a) Infrastructure-Sensitive Data may be used in Observatory nodes, digital twins, dashboards, maps, reports, technical notes, evidence packs, decision packs, public-safe summaries, and Nexus interfaces only within recorded authority, classification, access, public-safe status, and correction controls.

13.12.6(b) Observatory nodes and digital twins shall not expose sensitive operational details, attack paths, real-time sensitive telemetry, exact vulnerable locations, public authority restricted data, or host/operator confidential information unless controlled and authorized.

13.12.6(c) Evidence packs and reports shall distinguish infrastructure evidence from operational instruction, public warning, public authority decision, procurement approval, finance-readiness, provider preference, and execution authority.

13.12.6(d) Dashboards and maps shall include update status, limitations, sensitive-location controls, public authority boundary language where applicable, public warning boundary language where applicable, and correction path.

13.12.6(e) The controlling rule shall be that infrastructure-sensitive outputs must be useful enough to support resilience and safe enough not to create vulnerability.


13.12.7 AI Use and Model Training Restrictions. 13.12.7(a) Infrastructure-Sensitive Data shall not be entered into, trained on, fine-tuned with, embedded in, indexed by, retrieved through, summarized by, analyzed by, or used to improve AI systems unless expressly authorized and governed.

13.12.7(b) AI use involving Infrastructure-Sensitive Data shall require source authority, purpose limitation, model register status, cybersecurity review, public-safe review, public authority review where applicable, host or operator review where appropriate, access controls, retention review, transfer review, inference record where material, and correction path.

13.12.7(c) AI outputs derived from Infrastructure-Sensitive Data shall inherit restrictions unless reviewed and lawfully transformed.

13.12.7(d) GCRI Canada shall not use Infrastructure-Sensitive Data to create unauthorized targeting tools, exploit path analysis, operational control tools, public warning surfaces, provider advantage, sponsor benefit, finance signaling, or execution guidance.

13.12.7(e) The controlling rule shall be that AI use shall not convert infrastructure observability into infrastructure exposure.


13.12.8 Cross-Border and Controlled Technology Review. 13.12.8(a) Cross-border transfer, remote access, cloud processing, backup, mirroring, AI processing, repository storage, external sharing, or publication of Infrastructure-Sensitive Data shall require cross-border, sovereign data, controlled technology, export-control, sanctions, cybersecurity, and public-safe review where risk exists.