BLACKSWANCapital Markets OS Data Governance, Retention & Privacy Centre · v1.0 draft ← Return to OS Architecture
Data Governance, Retention & Privacy · Founder-only staging

Data Governance, Retention & Privacy Centre Inventory, classification, lawful basis, retention, deletion, DSR readiness, cross-border transfers, vendor controls, privacy incident linkage, and lineage evidence.

This Centre is internal data-governance readiness workflow. Numbers below are staging / simulated privacy data. Nothing here is legal advice, privacy compliance certification, regulatory approval, an audit opinion, or authorization for external launch. Statutory retention and notification deadlines require external counsel confirmation against the rule set in force.

Datasets in inventory
11
Mapped
Founder identity · auth logs · evidence packs · audit log · data-room access · exports · stakeholder rooms · onboarding/KYB · billing · incidents · regulator binders.
Restricted / MNPI · Sensitive
4
Restricted
Data-room access ledger · stakeholder room recipients · regulator binders · incident timelines.
Personal data records
3
Personal
Founder identity · onboarding/KYB · stakeholder room recipients.
Cross-border transfers · counsel
Counsel
Review
UK / EEA international-transfer safeguards drafted; counsel review outstanding.
Data states used on this Centre
Unclassified
Discovered but not yet classified; default deny on external distribution.
Classified
Tier and class recorded with owner; baseline controls applied.
Restricted / MNPI
MNPI policy-version binding required; non-downloadable by default.
Personal Data
Personal data with lawful basis recorded; DSR rights apply.
Sensitive / High-Risk
Heightened controls; counsel-only annotations excluded by default.
Retention Hold
Legal, regulatory, or audit hold; deletion suspended.
Deletion Eligible
Past retention; no hold; eligible for documented deletion.
Deletion Blocked
Deletion blocked by legal/regulatory hold or evidence dependency.
Transfer Review
Cross-border transfer review in flight; counsel safeguard pending.
Privacy Review
Privacy owner reviewing scope or DSR exemption.
Approved
Privacy owner has approved processing for the named purpose.
Archived
Out of active use; immutable retention until end of retention class.
Purged
Documented deletion with evidence hash; cannot be reinstated.
Twelve data governance domains

Each domain has named owner, evidence pack, audit-event tag

Domains map back to Stakeholder Rooms MNPI controls, Production Monitoring SIEM forwarding, and Approval & Sign-Off audit chain.

Domain 1
Data Inventory System / dataset register with owner, jurisdiction, purpose, retention class.
Green
Domain 2
Data Classification Unclassified / Classified / Restricted / Personal / Sensitive scheme applied per dataset.
Green
Domain 3
Processing Purpose Each dataset bound to a named processing purpose; secondary use blocked.
Green
Domain 4
Lawful Basis / Justification Internal justification evidence; counsel confirmation required for personal data.
Amber
Domain 5
Data Minimisation Fields captured limited to documented purpose; periodic field-level review.
Amber
Domain 6
Retention & Deletion Retention classes mapped; deletion playbook drafted; counsel-confirmed periods pending.
Amber
Domain 7
Legal / Regulatory Holds Hold register tied to Regulatory Notification & Board Escalation Centre triggers.
Amber
Domain 8
Cross-Border Transfers UK / EEA international transfer safeguards drafted; counsel review outstanding.
Amber
Domain 9
Data Subject Rights / DSAR Intake → verify → discover → response → log; counsel confirmation per request type.
Amber
Domain 10
Vendor / Sub-Processor Controls DPA / SCC / contract status, location, data categories, review cadence.
Amber
Domain 11
Privacy Incident Linkage Privacy events tie to Production Monitoring, Regulatory Escalation, Data-Room MNPI.
Green
Domain 12
Privacy Evidence & Audit Trail Every state change emits an audit event with hash; SIEM forwarding mandatory at cutover.
Green
Data inventory · eleven datasets

Each dataset owner-named with classification, jurisdiction, purpose, retention, transfer posture

Sample staging rows aligned to existing OS posture. Personal-data datasets carry the lawful basis flag and DSR coverage; restricted/MNPI datasets carry the policy-version binding flag.

Dataset · owner
Jurisdiction · purpose · retention · transfer · blocker · next
Classification
State
Founder identity
CCO · CISO
Jurisdiction
ADGM/FSRA (founder seat)
Purpose
Founder MFA · session issuance · audit chain.
Retention
10y · regulator audit class.
Transfer
Internal only; no cross-border processing today.
Blocker
None.
Next
D+30 review; counsel confirmation on retention period.
Personal
Approved
Auth / session logs
CISO
Jurisdiction
Internal staging
Purpose
Auth audit · session anomaly triage · SIEM forwarding.
Retention
2y default · 7y if regulator-relevant.
Transfer
Staging-only; production SIEM target identified.
Blocker
None.
Next
Confirm production SIEM forwarding at cutover.
Classified
Approved
Evidence pack metadata
CCO · Founder Admin
Jurisdiction
ADGM/FSRA · UK · MiFID · MAS
Purpose
Readiness evidence; reviewer trail; Pack Registry.
Retention
7y immutable · regulator audit class.
Transfer
Internal · controlled bundles by Stakeholder Rooms only.
Blocker
None.
Next
Production cutover signs hash continuity.
Classified
Approved
Audit log events
CISO · Founder Admin
Jurisdiction
Internal staging
Purpose
Immutable audit-event capture; SIEM forwarding evidence.
Retention
7y immutable · audit class.
Transfer
Staging-only; production SIEM target identified.
Blocker
None.
Next
Confirm hash continuity at cutover.
Classified
Approved
Data-room access ledger
CCO · CISO
Jurisdiction
ADGM/FSRA · UK · MAS · EEA
Purpose
MNPI access ledger · token issuance · recipient ack.
Retention
10y immutable · MNPI class.
Transfer
Restricted; recipient-scoped.
Blocker
MNPI policy-version binding pending.
Next
Re-attest binding; CCO + CISO co-sign.
Restricted / MNPI
Privacy Review
Export manifests
CCO
Jurisdiction
ADGM/FSRA · UK · MiFID · MAS
Purpose
Bundle manifest · hash continuity · reviewer signature.
Retention
7y immutable · audit class.
Transfer
Recipient-scoped via Stakeholder Rooms.
Blocker
None.
Next
Pre-launch reviewer pass.
Classified
Approved
Stakeholder room recipients
Founder Admin · CCO
Jurisdiction
ADGM/FSRA · UK · MiFID · MAS
Purpose
Director, counsel, auditor, counterparty, observer identity for room access.
Retention
7y immutable · audit class.
Transfer
Personal data · per-recipient; counsel-only annotations excluded.
Blocker
Counsel confirmation on lawful-basis evidence.
Next
D+30 recipient verification refresh.
Personal
Privacy Review
Client onboarding / KYB data
CCO · MLRO observer
Jurisdiction
ADGM/FSRA · UK · EEA (cohort-dependent)
Purpose
KYC / KYB / sanctions / PEP screening; partner-routed.
Retention
5y (post relationship) · regulatory class.
Transfer
Partner-routed; transfer safeguards drafted.
Blocker
Counsel confirmation on partner-route safeguards.
Next
Confirm DPA / SCC chain with partner KYC vendor.
Personal
Transfer Review
Billing / invoice records
CFO · CCO
Jurisdiction
ADGM/FSRA · UK · MAS · EEA
Purpose
Invoice ledger · revenue recognition evidence · tax evidence.
Retention
7y · statutory accounting class (counsel confirmation pending).
Transfer
Pre-launch; billing not enabled.
Blocker
Tax / VAT opinion outstanding.
Next
Counsel confirmation on statutory retention.
Classified
Privacy Review
Incident timelines
CISO · CCO · Founder Admin
Jurisdiction
Internal staging
Purpose
Incident command evidence · post-incident review · regulator readiness.
Retention
10y immutable · incident class.
Transfer
Internal; restricted scope.
Blocker
None.
Next
Confirm retention class at counsel review.
Sensitive
Approved
Regulatory exam response binders
CCO · Regulatory Affairs
Jurisdiction
ADGM/FSRA · UK · MAS · MiFID/MiFID II
Purpose
Regulator response readiness · FSRA bundle scope.
Retention
10y immutable · regulator response class.
Transfer
FSRA scope only; UK / MAS / EEA internal-only.
Blocker
UK / MAS / EEA perimeter red.
Next
External counsel perimeter opinions.
Restricted
Retention Hold
Retention schedule matrix

Internal retention policy pending counsel confirmation

Default periods are internal retention policy; statutory retention requires counsel confirmation per jurisdiction.

Record type
Retention basis · default · hold trigger · deletion method · evidence · review
Owner
State
Auth / session logs
Basis: internal audit · Default: 2y staging / 7y if regulator-relevant · Hold trigger: incident, regulator request · Deletion: cryptographic erase + SIEM tombstone · Evidence: SIEM hash · Review: 60d.
CISO
Approved
Audit log events
Basis: internal audit · Default: 7y immutable · Hold trigger: regulator notification · Deletion: not eligible during hold · Evidence: hash chain · Review: 60d.
CISO · Founder Admin
Hold
Evidence pack metadata
Basis: internal audit · Default: 7y immutable · Hold trigger: regulator response · Deletion: only on retention class expiry · Evidence: Pack Registry hash · Review: 90d.
CCO · Founder Admin
Approved
Data-room access ledger
Basis: MNPI · Default: 10y immutable · Hold trigger: MNPI incident, regulator request · Deletion: not eligible during hold · Evidence: SIEM-forwarded ledger · Review: 60d.
CCO · CISO
Hold
Stakeholder room recipients
Basis: audit · Default: 7y immutable · Hold trigger: regulator audit · Deletion: redact personal fields after retention class · Evidence: recipient ledger hash · Review: 90d.
Founder Admin · CCO
Privacy Review
Client onboarding / KYB data
Basis: AML/KYC obligation (partner-routed) · Default: 5y post relationship · Hold trigger: sanctions hit, regulator request · Deletion: partner-managed where applicable · Evidence: partner SOC + internal hash · Review: 90d.
CCO · MLRO observer
Transfer Review
Billing / invoice records
Basis: statutory accounting (counsel confirmation pending) · Default: 7y · Hold trigger: tax authority enquiry · Deletion: archive then purge per jurisdiction · Evidence: finance close hash · Review: 90d.
CFO · CCO
Privacy Review
Incident timelines
Basis: incident audit · Default: 10y immutable · Hold trigger: regulator notification · Deletion: not eligible during hold · Evidence: incident pack hash · Review: 90d.
CISO · CCO · Founder Admin
Approved
Regulator response binders
Basis: regulator response · Default: 10y immutable · Hold trigger: open exam · Deletion: not eligible during hold · Evidence: bundle scope hash · Review: 60d.
CCO · Regulatory Affairs
Hold
DSR / DSAR readiness

Nine-step intake-to-response readiness

DSR / DSAR framing is generic; counsel confirmation on the applicable rule set is required per request. No live request is in flight; readiness rows track what must be in place before any production scope.

✓Closed ~Partial ✗Blocking
Step
Owner
~
Request intake
Founder-only mailbox; counsel and CCO copied; intake template drafted.
Founder Admin · CCO
~
Identity verification
Multi-factor identity verification policy drafted; partner-routed verification optional.
CCO · CISO
~
Scope review
Request scoped to specific datasets; counsel-confirmed scope template.
Legal Counsel · CCO
~
Exemption / hold check
Cross-reference with regulator response binders and incident timeline holds.
Legal Counsel · CCO · CISO
~
Data discovery
Discovery query across the 11 inventory datasets; partner-routed datasets queried via vendor channel.
CISO · Vendor liaison
~
Response package
Counsel-reviewed response template; limitation text; redaction policy; recipient-watermarked bundle.
CCO · Legal Counsel
✗
Deletion / rectification handling
Awaiting counsel confirmation on deletion methods that satisfy regulator hold tension; safe-default is hold + tombstone.
CCO · CISO · Legal Counsel
✓
Evidence log
Every DSR action emits an audit event with hash; SIEM forwarding mandatory at production cutover.
CISO · Founder Admin
~
Deadline watch
Internal watch windows (30d default) framed pending counsel confirmation on the applicable rule.
CCO · Legal Counsel
Cross-border transfer & jurisdiction matrix

Per-jurisdiction transfer posture & safeguards

Safeguards (SCC / IDTA / supplementary measures) are drafted as internal transfer policy; counsel confirmation required before any production cross-border transfer.

Drafted Counsel Review Blocking Not-in-scope
Jurisdiction Outbound personal Outbound restricted Vendor / sub-processor Safeguard Owner · Note
ADGM / UAE Drafted Drafted Counsel Review Founder seat · internal scope Regulatory Affairs · counsel confirmation pending.
UK Counsel Review Counsel Review Counsel Review IDTA / SCC + supplementary measures (drafted) Legal Counsel · pending opinion against rule set in force.
EU / MiFID Counsel Review Counsel Review Counsel Review SCC + supplementary measures (drafted) Legal Counsel · transfer impact assessment template drafted.
Singapore / MAS Counsel Review Blocking Counsel Review Partner-routed; appointment evidence outstanding Regulatory Affairs · MAS partner appointment evidence outstanding.
US / vendor tooling Counsel Review Counsel Review Counsel Review SCC + supplementary measures · DPF eligibility check CISO · cross-check vendor SOC 2 evidence chain.
Vendor / sub-processor control panel

Service · data categories · location · safeguard · DPA · review

Vendor register tied to the Outsourcing Concentration pack on Launch Readiness. DPA / SCC chain requires counsel review for each external scope.

Vendor · data categories
Location · purpose · safeguard · DPA/SCC · review
Owner
State
Identity Provider (target Entra)
Personal data · auth events.
EU / multi-region · auth issuance · DPA + SCC drafted · cutover pending · 90d review.
CISO · IAM
Cutover pending
Hosting
Static + Node backend · staging data only.
Single-tenant staging · DPA drafted · transfer safeguards counsel review pending · 60d review.
CISO · COO
Privacy Review
GitHub · repo
Source code · pack hashes · no client personal data.
US · code · DPA on file · OAuth restrictions enforced · 90d review.
CISO · Founder Admin
Approved
Email / notifications
Personal data · stakeholder identifiers.
Multi-region · stakeholder comms · DPA + SCC drafted · counsel review pending · 60d review.
Founder Admin · CCO
Counsel Review
Data storage
In-memory session registry · file-system Pack Registry · no real client data.
Internal · staging · no cross-border processing today · 60d review.
CISO
Approved
Monitoring / logging
Audit events · session telemetry · no real client data.
Staging SIEM · production target identified · DPA + SCC drafted · counsel review pending · 60d review.
CISO
Counsel Review
KYC partner (target)
Personal · UBO · sanctions / PEP.
Multi-region · partner-routed · SOC 2 + DPA outstanding · 60d review.
CCO · MLRO observer
Outstanding
External counsel firm
Personal · client identifiers · privileged work product.
Multi-region · counsel · NDA + privilege wording on file · 90d review.
Legal Counsel
Approved
Privacy incident linkage

Where privacy events surface elsewhere in the OS

Privacy events do not live alone: they connect to monitoring, escalation, and stakeholder rooms so containment and notification review are owner-named.

Data lineage / evidence map

Source → downstream artefacts → evidence packs → access restriction

Lineage rows trace personal / restricted data from source to downstream artefacts so deletion, retention, and DSR scope can be reasoned about cleanly.

Source system
Downstream artefacts · evidence packs · access restriction · audit event
Retention class
Founder identity
→ Auth/session logs → Audit log → Stakeholder Rooms recipient ledger (founder) → memo/notification-review. Access: founder-only. Audit event SR-GRANT.
10y · regulator audit
Evidence pack metadata
→ Bundle manifest → Stakeholder Rooms export → Regulator response binders. Access: recipient-scoped, watermarked. Audit event SR-GRANT · SR-ACCESS.
7y immutable · audit
Data-room access ledger
→ MNPI access events → SIEM forwarding → memo/notification-review. Access: CCO + CISO co-sign for changes. Audit event SR-SUSPEND on MNPI drift.
10y · MNPI
Client onboarding / KYB
→ Partner KYC vendor → Counterparty DD bundle (paused) → Audit log. Access: partner-routed; internal scope-limited. Audit event CR-ONBOARD.
5y · regulatory class
Billing / invoice
→ Pre-launch only; no live invoices today. Future: finance close pack → audit evidence hash. Audit event FIN-PENDING.
7y · statutory accounting
Incident timeline
→ Production Monitoring incident card → memo/notification-review → Stakeholder Rooms exception (where personal data implicated). Audit event NR-DETECT.
10y · incident
Regulator binders
→ FSRA bundle scope · UK/MAS/EEA internal-only · Stakeholder Rooms regulator prep. Access: counsel-signed limitation text. Audit event SR-GRANT.
10y · regulator response
Privacy control exception register

Open items blocking governance progression

Closure requires owner action and a Pack Registry hash. Each row carries trigger, scope, and audit-event tag.

Item
Detail · audit event
Owner
State
Unclassified data
Two staging telemetry endpoints not yet classified; default-deny on external distribution in force. DG-EXC-UNCLASS
CISO · CCO
Amber
Stale retention owner
Billing / invoice retention owner pending CFO sign-off; counsel confirmation on statutory period outstanding. DG-EXC-RET-OWNER
CFO · CCO
Amber
Missing DPA / SCC
KYC partner DPA + SOC 2 outstanding; KYC onboarding-data transfer review held. DG-EXC-DPA
CCO · MLRO observer
Transfer Review
Transfer review pending
UK + EEA cross-border transfer safeguards drafted; counsel review outstanding before any production scope. DG-EXC-XBORDER
Legal Counsel · CISO
Transfer Review
Deletion blocked by hold
Regulator response binders + incident timeline + data-room access ledger all under retention hold; deletion not eligible. DG-EXC-HOLD
CCO · CISO
Deletion Blocked
Excessive access
Founder-only access today; any future Tier 2 / Tier 3 access expansion requires privacy review and Stakeholder Rooms re-grant. DG-EXC-ACCESS
CISO · CCO
Privacy Review
DSAR response blocker
Deletion/rectification handling step blocking; counsel confirmation on tension between deletion and regulator hold. DG-EXC-DSAR
CCO · CISO · Legal Counsel
Amber
Stale vendor review
Email / notifications vendor 60-day review approaching; transfer safeguard counsel review outstanding. DG-EXC-VENDOR
Founder Admin · CCO
Amber
Secret Rotation, Key Custody & Recovery Drill Evidence Loop

Custody · rotation cadence · recovery drill evidence posture

Internal key-custody readiness posture only. No secret value, certificate private key, encryption key, password, client secret, token, connection string, backup key, signing material, mTLS private key, break-glass credential, or recovery code appears in this Centre, in the API at /api/secret-rotation-key-custody, in the fixture, or in any commit. Only ownership, custodian, custody model, declared (non-secret) reference NAMES, presence flags, approval state, rotation cadence, last-rotation evidence date, next rotation due, recovery drill status / date, and evidence references are recorded. Staging or demo credentials do not count as production secret custody evidence. Not security certification, not regulatory approval, not legal advice, not audit opinion, not external endpoint authorisation, and not external-use authorisation.

Items assessed
15

Session · token · OIDC · storage · SIEM · monitoring · TLS · mTLS · backup · DB · break-glass · CI/CD · regulatory

Ready · internal
0

Custody + approval + rotation + drill evidence captured

Rotation overdue
0

Next-rotation due elapsed without captured evidence

Recovery untested
13

Restore / revocation drill not within freshness window

Custody approval pending
13

Required items lacking captured custody approval

Missing / blocked
13

Required custody / rotation / drill evidence not captured

In review
0

Owner / custodian / evidence in flight

Production launch
HOLD · NO-GO

Until custody + rotation evidence + recovery drill captured

Authoritative row table is rendered in the Security Operations · IAM · Zero-Trust Centre and the Final Production Launch Control Tower. Day-2 custody & rotation register lives in the Operational Runbooks & Day-2 Support Centre. Mirrored summary in the Completeness Command Centre. Read-only fixture exposed via /api/secret-rotation-key-custody; cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/entra-oidc-readiness, and /api/auth/posture. No secret value, certificate private key, encryption key, password, client secret, token, connection string, backup key, signing material, mTLS private key, break-glass credential, or recovery code is returned from any endpoint. Internal key-custody readiness posture only · not security certification · not regulatory approval · not legal advice · not audit opinion · not external endpoint authorisation · not external-use authorisation. Staging or demo credentials do not count as production secret custody evidence.

Production Backup, Restore & Data Recovery Evidence Centre

Backup scope · restore drills · RPO/RTO · retention · DR · recovery authority

Internal backup/recovery readiness posture only. No backup vault credential, storage account key, database credential, encryption key material, recovery code, signed-URL secret, private endpoint, production data row, or live production dataset appears in this Centre, in the API at /api/backup-restore-recovery-evidence, in the fixture, or in any commit. Only ownership, custodian, custody model, declared (non-secret) reference NAMES, presence flags, approval state, backup cadence, last-backup evidence date, last restore drill date, RPO/RTO targets, measured RPO/RTO, retention / legal-hold posture, and evidence references are recorded. Staging or demo backups do not count as production recovery evidence. Not security certification, not regulatory approval, not legal advice, not audit opinion, not external endpoint authorisation, and not external-use authorisation.

Controls assessed
15

Schedule · scope · encryption · restore · RPO/RTO · WORM · evidence · audit · DB · IaC · runbook · DR · monitoring · retention · authority

Ready · internal
0

Owner + approval + cadence + last backup + restore drill + RPO/RTO + retention captured

Recovery untested
15

Restore drill / DR exercise not within freshness window

RPO/RTO unverified
8

Targets declared · measurement not captured against drill

Retention unverified
15

Retention lock + legal-hold alignment not evidenced end-to-end

Approval pending
15

Required items lacking recovery authority counter-sign

Missing / blocked
10

Required backup / restore / retention evidence not captured

Production launch
HOLD · NO-GO

Until backup scope + restore drill + RPO/RTO + retention + authority captured

Authoritative row table is rendered in the Security Operations · IAM · Zero-Trust Centre and the Final Production Launch Control Tower. Day-2 backup, restore & recovery runbook lives in the Operational Runbooks & Day-2 Support Centre. Mirrored summary in the Production Monitoring Centre and the Completeness Command Centre. Read-only fixture exposed via /api/backup-restore-recovery-evidence; cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, and /api/jurisdictional-permissions-matrix. No backup vault credential, storage account key, database credential, encryption key material, recovery code, signed-URL secret, private endpoint, production data row, or live production dataset is returned from any endpoint. Internal backup/recovery readiness posture only · not security certification · not regulatory approval · not legal advice · not audit opinion · not external endpoint authorisation · not external-use authorisation. Staging or demo backups do not count as production recovery evidence.

Production Data Classification & MNPI Boundary Register

Classification level · MNPI posture · clean-team · access boundary · retention · residency · watermark · release authority

Holds every classification-dependent gate (production launch, regulator submission, external bundle release, data-room access activation, clean-team activation, watermarked export, retention / legal-hold lift, cross-border transfer, MNPI bridging review, board-pack release, investor-room release, customer / counterparty data-room release) at HOLD · NO-GO until each required classification / boundary control — public / internal / confidential / restricted / MNPI classification, clean-team boundary, board-pack boundary, regulator-pack boundary, investor-room boundary, client / customer data boundary, order / transaction data boundary, evidence-export boundary, audit-log boundary, personal data / privacy boundary, data-room access control, watermarking / classification labels, retention / legal hold, cross-border / data residency limitation, and release / go-no-go authority — is captured with owner + approval forum + classification level + MNPI posture + recipient class descriptor + access boundary rule + clean-team requirement (where applicable) + retention / legal-hold basis + residency / cross-border note + watermark / classification label + evidence reference + last-reviewed date. Staging or demo classifications do not count as production data classification or MNPI boundary evidence. Data classification never overrides an unresolved P0 blocker without explicit owner + approval forum + classification level + MNPI posture + access boundary rule + evidence. No real MNPI, client / customer / investor identity, regulator contact, clean-team identity, deal codename in flight, access log line, IP address, device fingerprint, room URL, signed URL, room token, OTP code, watermark salt body, board pack body, board minute body, regulator submission body, privileged legal advice text, privileged work-product, external counsel memo body, customer data, transaction / order data, confidential attachment contents, personal data subject identity, or live notification channel appears in this Centre, fixture, API, or commit.

Boundaries assessed
15

Classification · clean-team · board · regulator · investor · client · order · evidence · audit-log · privacy · room · watermark · retention · residency · release

Ready · internal
0

Owner + authority + classification + MNPI + access + clean-team + retention + residency + watermark + evidence captured

In review
0

Classification / boundary partially captured

Missing / blocked
0

Required classification / boundary evidence not captured

Classification missing
0

Classification level (public / internal / confidential / restricted / MNPI) not captured

MNPI boundary unresolved
0

MNPI posture (in-scope · out-of-scope · clean-team-isolated) not captured

Clean-team pending
0

Clean-team protocol (membership · isolation · ethical-wall) not captured

Access boundary unverified
0

Recipient class descriptor + entitlement rule + denial-by-default not captured

Retention · legal hold unverified
0

Retention schedule / legal-hold instrument not linked

Watermark · classification label missing
0

Per-release watermark · classification label control reference not captured

Residency · cross-border unresolved
0

UK / EEA / third-country safeguard not captured

Evidence missing
0

Classification / MNPI / clean-team / retention / residency / watermark evidence not linked

External use · boundary
HOLD · NO-GO

Until required external-use classifications / boundaries are ready-internal

Production launch · boundary
HOLD · NO-GO

Until required classification / MNPI / clean-team / access / retention / residency / watermark / release authority captured

Read-only fixture exposed via /api/data-classification-mnpi-boundary-register; reference NAMES, classification level labels, MNPI posture labels, recipient class descriptors, ownership, approval forum names, approval state, evidence reference IDs, access boundary rule class descriptors, clean-team requirement class descriptors, retention / legal-hold basis class descriptors, residency / cross-border class descriptors, watermark / classification label class descriptors, linked evidence / control / stakeholder / regulatory dependency endpoint paths, launch impact text, external-use impact text, and unlock criteria only. Cross-references the Counsel, Compliance & Board Approval Authority Register, the Production Risk Acceptance & Exception Register, the Stakeholder Evidence Distribution & External Bundle Release Gate, the Regulatory Submission & Supervisory Correspondence Evidence Gate, the Evidence-Pack Gate Validation, the Jurisdictional Permissions Matrix, the Security Operations · IAM · Zero-Trust Centre, the Final Production Launch Control Tower, the Regulatory Notification & Board Escalation Centre, the Strategic Risk Register & Scenario Planning Centre, and the Completeness Command Centre. No real MNPI, client / customer / investor identity, regulator contact, clean-team identity, deal codename in flight, access log line, IP address, device fingerprint, room URL, signed URL, room token, OTP code, watermark salt body, board pack body, board minute body, regulator submission body, privileged legal advice text, privileged work-product, external counsel memo body, customer data, transaction / order data, confidential attachment contents, personal data subject identity, or live notification channel is returned from any endpoint. Internal data-classification / MNPI boundary readiness posture only — not a data classification authorisation, not an MNPI boundary acceptance, not a privacy-compliance certification, not data residency authorisation, not a clean-team activation, not data-room authorisation, not legal advice, not an audit opinion, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not investor communication, not board approval, not capital / liquidity adequacy, not external endpoint authorisation, and not external-use authorisation. Staging or demo classifications do not count as production data classification or MNPI boundary evidence.

Boundary Category Classification MNPI Recipient class Owner · authority Access boundary Clean-team Retention Residency Watermark State Unlock
Loading data-classification / MNPI boundary readiness fixture…
Audit trail · evidence preservation

Every data-state change is timestamped, actor-named, evidence-hashed

Sample staging entries. Production audit-event capture still requires SIEM-forwarded audit events under Microsoft Entra OIDC.

Timestamp · event
Actor
Dataset · action · evidence · limitation · next step
Hash
2026-05-15 06:00Z
DG-INVENTORY
CISO · CCO
Data inventory v1.0 published · 11 datasets · owner / jurisdiction / purpose / retention captured · D+30 review.
hash:9a2c…
2026-05-15 07:30Z
DG-CLASSIFY
CISO
Classification scheme applied · 4 Restricted/MNPI · 3 Personal · 1 Sensitive · default deny on external distribution.
hash:7e11…
2026-05-15 09:00Z
DG-RETENTION
CCO · Legal Counsel
Retention schedule v1.0 published · counsel confirmation on statutory periods scheduled · 60d review cadence.
hash:bc40…
2026-05-15 09:42Z
DG-HOLD
CCO · Regulatory Affairs
Retention hold on regulator response binders · open exam stance · deletion blocked.
hash:5d8f…
2026-05-15 10:30Z
DG-TRANSFER
Legal Counsel · CISO
UK / EEA international-transfer review opened · IDTA / SCC + supplementary measures drafted · counsel opinion pending.
hash:e5d0…
2026-05-15 14:07Z
DG-PRIVACY-REVIEW
CCO · CISO
Data-room access ledger privacy review opened on MNPI policy-version binding pending · Counterparty DD pilot suspended.
hash:c2e9…
2026-05-15 15:15Z
DG-VENDOR
CCO · Founder Admin
Email / notifications vendor 60d review queued · counsel review on transfer safeguard outstanding.
hash:1f73…
2026-05-15 16:00Z
DG-DSAR
CCO · Legal Counsel
DSR / DSAR readiness panel published · counsel confirmation on deletion vs hold tension pending · 30d internal watch.
hash:38ab…
2026-05-15 17:14Z
DG-LINEAGE
CISO · Founder Admin
Lineage map v1.0 published · 7 source systems mapped to downstream artefacts + retention classes · audit event chain captured.
hash:0b6d…

Assumptions and limitations

This Data Governance, Retention & Privacy Centre is internal data-governance readiness workflow. All data shown is staging / simulated privacy data. It is explicitly not:

Internal watch windows quoted on the DSR / DSAR panel are not assertions of statutory deadlines; they drive when a counsel decision must be on file. All regulated activity on the platform remains simulated, partner-routed, locked, or production-regulated as defined in the OS Architecture and Completeness Command Centre. Production cutover still requires Microsoft Entra OIDC with Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events.