Control Packs · DAT-002 · v1.0.0
Controlled Data Export
Make export destinations, fields, approvals, and audit records explicit before data leaves its current boundary.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Limit exports by purpose, data class, recipient, destination, approval, and retention.
- Data leaves its boundary without a confirmed purposeAn export includes excessive fields, an unapproved destination, or a recipient that cannot be tied to a confirmed purpose and access scope.
Versioned applicability rule
{
"characteristic": "DATA_EXPORT",
"equals": true
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- Which fields, destinations, and recipients are permitted for the export?An export boundary must be explicit before a system transmits data.DAT-002-Q1 · scope
Requirements for the coding agent
- DAT-002-R1Allowlist export fields and destinations, require purpose and approval where material, minimize payloads, and record export outcomes without raw sensitive data.
Tests and evidence to retain
- EXPORT_BOUNDARY_TESTVerify allowlisted fields, denied destination, approval, redaction, retry, and deletion behavior.
- configuration_or_policy
- implementation_location
- test_result
- operational_procedure
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- AC-4 · Information Flow EnforcementNIST_SP_800_53_5_2_0 · partially addressesAllowlisted fields and destinations enforce selected export flows; they do not cover every information flow.
- PT-3 · Personally Identifiable Information Processing PurposesNIST_SP_800_53_5_2_0 · partially addressesPurpose and approval requirements support purpose limitation for exports; they do not establish privacy compliance.
- AU-3 · Content of Audit RecordsNIST_SP_800_53_5_2_0 · partially addressesPrivacy-minimized export outcomes define focused record content; they do not cover the full audit-record requirement.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Privacy FrameworkGUIDANCE_DATA_MINIMIZATION
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_AUDITABILITY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0