FILE 01Inventory before controls
List each data field, who supplies it, why the system needs it, where it is stored, who can access it, and when it should be removed.
- Minimize names, identifiers, location, and sensitive records
- Separate public, staff, administrator, and vendor access
- Document logs, backups, exports, and deletion behavior
FILE 02Map vendors and borders
Identify hosting, analytics, email, AI, payment, file-storage, support, and security providers, including their data locations and contract owners.
- Do not promise a hosting location that has not been verified
- Do not send client data to an AI tool without an approved purpose and boundary
- Treat third-party terms and availability as dependencies
FILE 03Release decision
The client and qualified adviser approve notices, permissions, rights handling, retention, transfers, incident duties, and any sector-specific requirements. Engineering records the approved rule and validation evidence.
- No claim of blanket compliance
- No legal conclusion from automated research
- Recheck material rules and vendors before release