Current section
Files
Jump to
Current section
Files
priv/toolchain/canon/docs/governance.stub.md
# Governance β the counsel worklist
> π§ **dds-stub** β a scaffold awaiting human work; the holes (`TODO`, `needs-ratification`, `β `) are the worklist. Remove this line when none remain.
> **Regime: TODO** β name the governing regime(s); **Scope: TODO** β
> name the protection scope(s). These two lines are MACHINE-READ: each
> token must name a carried obligation profile (`gdpr`, `ferpa`,
> `confidentiality`, β¦), whose demands the check enforces only while
> declared; `TODO` is the honest hole (core facet law only, reported).
> Declaring is itself a judgment β profiles are never detected. Until
> counsel confirms, the position across this file is **provisional**,
> and field names are the NEUTRAL slots β each active profile's
> terminology maps them (lawful basis under GDPR; disclosure ground
> under FERPA; confidentiality terms under the scope).
This file is the ONE in-repo governance surface. The *inventory* β what
data, flows, secrets, capabilities, subjects, and activities exist β is
witnessed from the code: by an external machine-authoritative register
where one exists (see [`registers.md`](registers.md)), and by the code
itself otherwise; judgments about inventory rows (classifications,
ratifications, implicated risks) live with the register. What lives
*here* is what neither code nor scan can produce: the **regime
declaration** above, the **lawful-basis and retention join targets**
that inventory rows point at, and the **questions an external authority
(counsel, security) must answer**. A governed fact with no answer is
`G Β· needs-legal-review` until sourced β never a fabricated value.
**Format:** each entity is a `### Human name Β· id` heading with a
one-line blockquote summary and a fact table; provenance marks are
**D** (derived from code), **C** (claimed judgment), **G** (governed
fact requiring an external authority). Open states are honest structure:
`G Β· needs-legal-review` (not sourced), `β ` (an ambiguity named, not
resolved). The π§ stub marker clears when no holes remain (see
`conventions.md` Β§11). Entity references use the external register's
discovered ids where one exists; ids minted here use `basis.*` and
`retention.*` stems β they are the join targets register rows and risk
files resolve against.
## Lawful bases
> TODO β one `basis.*` entry per distinct permitting ground. Sub-steps of
> processing sharing a basis are one entry; steps needing different bases
> are separate β let the basis decide the grain. Each entry: the ground
> (and special-category condition where one applies), what depends on it,
> the risks it implicates, and the counsel questions as `β ` lines.
> Written by `/dds-sync` from the survey; sourced by counsel.
## Retention rules
> TODO β one `retention.*` entry per lifespan policy (period + trigger +
> disposition). Each entry: what depends on it, the risks it implicates,
> and the counsel questions as `β ` lines. A `Direction` field declares
> the rule's sign β `ceiling` (delete by: minimization) or `floor`
> (preserve until: accountability evidence, audit trails) β because the
> two obligations point opposite ways and a store can owe both.
## Terms β contractual and licensed constraints
> TODO β one `terms.*` entry per governing instrument that is a
> contract, not a law: customer confidentiality terms, NDAs, licenses
> on third-party content, written agreements behind disclosures. The
> entry records the instrument and what depends on it; org/internal
> datums' classifications answer to these.
## Processor instruments β to source
> TODO β the processor *population* is witnessed (register flow parties /
> the code's integrations); what counsel must source per party is the
> instrument: role (controller/processor), DPA or equivalent terms,
> residency, sub-processors, training-use prohibition.
## Subject consent and notice β to source
> TODO β the subject *population* is witnessed and ratified register-side
> (or enumerated from the code); what counsel must source is consent and
> notice: the consent mechanism and record (and, for minors,
> parental/guardian consent), required notices, and any dual-purpose use
> needing distinct authority.