Control Packs · DAT-001 · v1.1.0
Sensitive Data Boundary
Keep sensitive data within an explicit boundary with purpose limitation, access control, retention, deletion, and controlled export.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Define data purpose, access, tenant scope, retention, deletion, export approval, and logging minimization before implementation.
- Sensitive data crosses an unclear boundarySensitive data is collected, retained, exported, or exposed without a confirmed purpose, scope, access rule, or deletion path.
Versioned applicability rule
{
"any": [
{
"characteristic": "SENSITIVE_DATA",
"equals": true
},
{
"characteristic": "DATA_EXPORT",
"equals": true
}
]
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- Which actors, components, and destinations may handle the sensitive data?The service must not infer a permitted data boundary from the feature request alone.DAT-001-Q1 · scope
Requirements for the coding agent
- DAT-001-R1Enforce purpose-limited access and export, isolate tenant data where applicable, define retention and deletion, and exclude sensitive values from operational logs.
Implementation recipe
Enforce one explicit data policy at collection, access, export, logging, retention, and deletion boundaries, with tenant scope included where applicable.
- Classify the data and record the confirmed purpose, actors, components, destinations, and tenant boundary.
- Authorize every read, write, and export against that policy at the server boundary.
- Allowlist export fields and destinations; require the confirmed approval state before release.
- Apply retention and deletion across primary, derived, indexed, and backup-handling paths.
- Minimize operational events so they identify the class and decision without containing the protected value.
const requestScope = { actor, purpose, dataClass, tenantId, destination };
if (!dataPolicy.allows(requestScope)) return denyDataAccess();
const result = await tenantScopedRepository(tenantId).read(recordId);
return redactForPurpose(result, purpose);- The recipe does not choose a retention period, permitted destination, or legal basis on the user's behalf.
Tests and evidence to retain
- DATA_BOUNDARY_TESTVerify access scope, tenant isolation, export approval, retention, deletion, and log minimization.
- DAT-001-V1 · Actor or tenant outside scopeThe server denies the request and returns no protected fields.Evidence: Authorization denial; Cross-tenant result check; Minimized DATA_ACCESS_EVENT
- DAT-001-V2 · Unapproved exportThe export is blocked before data leaves the boundary and the reason is reviewable.Evidence: Export-policy decision; Absence of outbound transfer; Review record
- DAT-001-V3 · Deletion and log minimizationThe defined copies are removed or recorded under the stated backup limitation, and logs contain classifications and outcomes rather than raw data.Evidence: Deletion result by storage location; Backup limitation or procedure; Telemetry field inspection
- configuration_or_policy
- implementation_location
- test_result
- operational_procedure
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- AC-3 · Access EnforcementNIST_SP_800_53_5_2_0 · partially addressesPurpose-limited access and export operationalize a defined access boundary; they do not establish complete access enforcement.
- AC-4 · Information Flow EnforcementNIST_SP_800_53_5_2_0 · partially addressesDestination and export boundaries constrain selected information flows; they do not cover all system flows.
- PT-3 · Personally Identifiable Information Processing PurposesNIST_SP_800_53_5_2_0 · partially addressesThe confirmed purpose requirement supports purpose limitation for this data boundary; it is not a privacy assessment.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Privacy FrameworkGUIDANCE_DATA_MINIMIZATION
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0