Control Packs · DAT-002 · v1.0.0

Controlled Data Export

Make export destinations, fields, approvals, and audit records explicit before data leaves its current boundary.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Limit exports by purpose, data class, recipient, destination, approval, and retention.

  • Data leaves its boundary without a confirmed purposeAn export includes excessive fields, an unapproved destination, or a recipient that cannot be tied to a confirmed purpose and access scope.
Versioned applicability rule
{
  "characteristic": "DATA_EXPORT",
  "equals": true
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • Which fields, destinations, and recipients are permitted for the export?An export boundary must be explicit before a system transmits data.DAT-002-Q1 · scope

Requirements for the coding agent

  • DAT-002-R1Allowlist export fields and destinations, require purpose and approval where material, minimize payloads, and record export outcomes without raw sensitive data.

Tests and evidence to retain

  • EXPORT_BOUNDARY_TESTVerify allowlisted fields, denied destination, approval, redaction, retry, and deletion behavior.
  • configuration_or_policy
  • implementation_location
  • test_result
  • operational_procedure

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • AC-4 · Information Flow EnforcementNIST_SP_800_53_5_2_0 · partially addressesAllowlisted fields and destinations enforce selected export flows; they do not cover every information flow.
  • PT-3 · Personally Identifiable Information Processing PurposesNIST_SP_800_53_5_2_0 · partially addressesPurpose and approval requirements support purpose limitation for exports; they do not establish privacy compliance.
  • AU-3 · Content of Audit RecordsNIST_SP_800_53_5_2_0 · partially addressesPrivacy-minimized export outcomes define focused record content; they do not cover the full audit-record requirement.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review