Complete implementation kit · KIT-LIBRARIES-001

Protect the freedom to read, search, ask, and remember.

Libraries protect cognitive liberty when people can seek knowledge without unnecessary observation, when vendors cannot repurpose reading records, when access restrictions are narrow and reviewable, and when records are deleted as soon as operational need ends. The implementation goal is not secrecy from every lawful process; it is a system in which private inquiry is the default, exceptions are specific and accountable, and no patron must prove innocence for asking a lawful question.

Direct implementation answer

Libraries protect cognitive liberty when people can seek knowledge without unnecessary observation, when vendors cannot repurpose reading records, when access restrictions are narrow and reviewable, and when records are deleted as soon as operational need ends. The implementation goal is not secrecy from every lawful process; it is a system in which private inquiry is the default, exceptions are specific and accountable, and no patron must prove innocence for asking a lawful question.

Bounded threat model

Name systems, protected activity, and credible failure paths.

Scope: The kit addresses routine systems and foreseeable incidents involving catalogs, discovery layers, library-management systems, digital lending, public computers, Wi-Fi, analytics, identity providers, access-control tools, school integrations, archives, and third-party vendors. It does not promise anonymity against every targeted lawful investigation, endpoint compromise, or physical observation.

Protected activity: Lawful reading, searching, browsing, borrowing, reference consultation, note-taking, research, archival access, and intellectual exploration by adults and minors.

KIT-LIB-TH-01Worldwide principle

Persistent inquiry histories

Catalog searches, borrowing records, digital-reading telemetry, reference questions, and workstation logs can become a durable map of unfinished thought when retained after operational need ends.

KIT-LIB-TH-02Operational practice

Vendor reuse and cross-context profiling

A service provider may combine library activity with advertising, identity, education, or commercial data unless contracts and architecture prevent secondary use.

KIT-LIB-TH-03Technical recommendation

Identity overcollection

Account design, age assurance, guest access, Wi-Fi portals, and single sign-on can collect more identity than the service needs, converting private inquiry into attributable behavior.

KIT-LIB-TH-04Worldwide principle

Overblocking without practical appeal

Filters and automated safety systems can block lawful health, identity, political, historical, or security research when context is reduced to keywords or risk labels.

KIT-LIB-TH-05Jurisdiction-specific legal question

Compelled or informal disclosure

Staff and vendors may receive demands for patron records, preservation requests, subpoenas, informal pressure, or emergency claims without a consistent escalation and minimization process.

KIT-LIB-TH-06Operational practice

Loss, tampering, and historical erasure

Archives and local collections can be deleted, altered, decontextualized, or made inaccessible through technical failure, political pressure, vendor withdrawal, or insufficient geographic redundancy.

Minimum safeguards

Build a rights-preserving floor before adding complexity.

These safeguards state the purpose that must survive local implementation. They are not a claim that every jurisdiction uses identical law or procedure.

KIT-LIB-SG-01Worldwide principle

Collect the minimum

Do not collect a patron identifier, query, reading event, location, device identifier, or demographic field unless a documented service function requires it. Prefer aggregate service counts over person-level histories.

KIT-LIB-SG-02Technical recommendation

Separate identity from inquiry

Where accounts are necessary, keep authentication data separate from searches, content requests, and analytics. Use short-lived, purpose-bound tokens and privacy partitioning instead of a universal activity identifier.

KIT-LIB-SG-03CognitiveLiberties.com policy proposal

Delete by design

Set automatic deletion for search logs, session data, completed borrowing histories, expired holds, and diagnostic events. Exceptions must be named, narrow, time-limited, and reviewable.

KIT-LIB-SG-04Operational practice

Make private use normal

Offer guest browsing, private research workstations, non-account discovery, and confidential reference channels where operationally feasible. Do not make privacy a special mode that stigmatizes the user.

KIT-LIB-SG-05CognitiveLiberties.com policy proposal

Prohibit behavioral monetization

Contracts must forbid advertising profiles, sale or sharing of patron activity, unrelated model training, cross-service identity graphs, and secondary use that is not necessary to provide the library service.

KIT-LIB-SG-06Worldwide principle

Keep restrictions narrow and reversible

Any content restriction must identify the harm, legal or policy authority, affected audience, scope, duration, review owner, and a practical route to restore access when the system is wrong.

KIT-LIB-SG-07Worldwide principle

Protect minors without universal surveillance

Use age-appropriate service design and staff support without assuming that parental visibility, government identification, or permanent age profiles are always safe or necessary.

KIT-LIB-SG-08Operational practice

Control vendor and subcontractor access

Name every processor and subprocesser, restrict staff roles, require breach notice, preserve library ownership and deletion authority, and make audit evidence available.

KIT-LIB-SG-09Jurisdiction-specific legal question

Require lawful-demand discipline

Adopt an escalation process that authenticates requests, checks jurisdiction and authority, narrows scope, records disclosures, challenges overbreadth where permitted, and notifies affected people when lawful and safe.

KIT-LIB-SG-10Technical recommendation

Preserve public memory redundantly

Maintain fixity checks, format migration, access controls, provenance, and geographically or institutionally independent copies for collections at risk, without publishing sensitive source identities by default.

Staged implementation

Move from visibility to enforceable controls to durable resilience.

First 30 daysKIT-LIB-STAGE-30

Map the data and stop avoidable collection

Outcome: The institution can explain what patron data exists, why it exists, who can reach it, when it is deleted, and which urgent exposures are already disabled.

  1. KIT-LIB-ACT-30-01Operational practice

    Name an accountable owner

    Assign a privacy and intellectual-freedom owner with authority across technology, vendors, records, public service, youth services, archives, and incident response.

  2. KIT-LIB-ACT-30-02Technical recommendation

    Create a data-flow inventory

    Map collection from search box to vendor, including identifiers, logs, analytics, backups, support exports, identity providers, public computers, Wi-Fi, and archive access systems.

  3. KIT-LIB-ACT-30-03CognitiveLiberties.com policy proposal

    Disable unnecessary histories

    Turn off optional reading-history, query-retention, behavioral analytics, session replay, and advertising integrations unless a documented, approved purpose survives review.

  4. KIT-LIB-ACT-30-04Operational practice

    Publish the immediate privacy boundary

    Tell patrons what is collected, what is not, which vendors receive data, how long data remains, and how to seek access, correction, deletion, or help.

Within 90 daysKIT-LIB-STAGE-90

Bind systems, vendors, and exceptions

Outcome: Retention, vendor use, access restrictions, lawful demands, incident response, and appeals operate under written controls rather than informal custom.

  1. KIT-LIB-ACT-90-01Operational practice

    Adopt retention schedules

    Set event-specific deletion periods, backup expiry, hold-release cleanup, account closure handling, and documented legal-hold exceptions.

  2. KIT-LIB-ACT-90-02Operational practice

    Amend vendor contracts

    Bind first parties and subprocessors to purpose limitation, security, deletion, auditability, incident notice, no sale, no advertising, no unrelated training, and return-or-destroy duties.

  3. KIT-LIB-ACT-90-03CognitiveLiberties.com policy proposal

    Create unblock and appeal paths

    Provide immediate staff-assisted review for access errors, record the category rather than the patron’s full inquiry where possible, and publish escalation times.

  4. KIT-LIB-ACT-90-04Operational practice

    Exercise the incident plan

    Run one tabletop exercise for a data breach, one for an overbroad disclosure demand, and one for a censorship or archive-tampering event.

Within 365 daysKIT-LIB-STAGE-365

Build durable private access and institutional resilience

Outcome: The institution can prove that private inquiry, correction, deletion, vendor accountability, and memory preservation survive staff turnover, platform change, and political pressure.

  1. KIT-LIB-ACT-365-01Technical recommendation

    Redesign identity boundaries

    Replace shared persistent identifiers with purpose-bound tokens or separated systems wherever practical, and test whether sensitive discovery can operate without account linkage.

  2. KIT-LIB-ACT-365-02CognitiveLiberties.com policy proposal

    Create a privacy-preserving measurement plan

    Measure service availability, deletion completion, appeal resolution, vendor compliance, and incident response without retaining patron-level query or reading histories.

  3. KIT-LIB-ACT-365-03Operational practice

    Establish redundant custody

    Identify at-risk collections, document provenance and access boundaries, maintain independent copies, and test restoration from verified backups.

  4. KIT-LIB-ACT-365-04CognitiveLiberties.com policy proposal

    Publish an annual accountability record

    Report aggregate demand categories, confirmed incidents, deletion performance, appeal outcomes, vendor exceptions, and unresolved risks without exposing readers or researchers.

Evidence and procurement checklist

Do not buy a promise. Require inspectable evidence.

A policy statement is not proof of system behavior. Require architecture, configuration, tests, contracts, logs with bounded retention, deletion evidence, and a remedy when the provider is wrong.

KIT-LIB-PROC-01Operational practice

Data inventory supplied

The vendor lists every field, event, identifier, log, derived inference, diagnostic record, backup, support export, and subprocesser involved in the service.

KIT-LIB-PROC-02CognitiveLiberties.com policy proposal

Purpose limitation is contractual

Each collected field is tied to a named service purpose; advertising, resale, unrelated analytics, profiling, and unrelated model training are prohibited.

KIT-LIB-PROC-03Operational practice

Retention is event-specific

The proposal states automatic deletion deadlines for searches, sessions, circulation events, logs, backups, support files, and closed accounts.

KIT-LIB-PROC-04Technical recommendation

Library controls deletion

The institution can delete patron records, verify completion across backups and subprocessors, and receive evidence when a legal hold prevents deletion.

KIT-LIB-PROC-05Worldwide principle

Anonymous or guest use assessed

The vendor documents which core functions work without an account and explains why identity is required for every remaining function.

KIT-LIB-PROC-06Technical recommendation

Identity and inquiry are separated

Architecture diagrams show whether authentication services, analytics, content requests, and recommendation systems share a persistent identifier.

KIT-LIB-PROC-07Technical recommendation

Filter behavior is testable

The institution can test false blocks, inspect categories, override errors, and obtain change records without exposing a patron’s identity or entire search history.

KIT-LIB-PROC-08Operational practice

Security evidence is current

Independent security testing, encryption boundaries, access controls, incident history, vulnerability handling, and breach-notice timing are documented.

KIT-LIB-PROC-09Jurisdiction-specific legal question

Government-request process is documented

The vendor describes how demands are authenticated, narrowed, challenged, logged, and disclosed in aggregate, subject to applicable law.

KIT-LIB-PROC-10Operational practice

Portability and exit are real

The contract guarantees usable exports, documented formats, migration support, deletion after exit, and continuity if the vendor is acquired or discontinued.

KIT-LIB-PROC-11Worldwide principle

Minor access does not become universal tracking

Age-related controls identify the minimum attribute needed, avoid permanent age dossiers, and include confidential-help pathways.

KIT-LIB-PROC-12Jurisdiction-specific legal question

No unsupported compliance claim

The vendor names the exact law, standard, certification, version, scope, and auditor behind every compliance statement. “Privacy compliant” alone is not accepted.

Common failure modes

Good intentions can still create cognitive surveillance.

KIT-LIB-FAIL-01Operational practice

Keeping everything “just in case”

Indefinite retention converts operations data into a surveillance asset and increases breach, disclosure, and misuse risk.

KIT-LIB-FAIL-02Operational practice

Treating vendor policy as proof

A privacy statement does not establish production behavior, subcontractor handling, deletion, or identity separation.

KIT-LIB-FAIL-03CognitiveLiberties.com policy proposal

Using individual histories to prove impact

Counting every reader’s journey may produce attractive dashboards while destroying the private inquiry the service exists to protect.

KIT-LIB-FAIL-04Worldwide principle

Making appeals humiliating or slow

A theoretical unblock process fails when patrons must explain sensitive research at a public desk or wait longer than the research need lasts.

KIT-LIB-FAIL-05Jurisdiction-specific legal question

Assuming parental visibility always equals safety

For some minors, private access to health, abuse, identity, or belief information is itself a safety measure. Local law still requires specific review.

KIT-LIB-FAIL-06CognitiveLiberties.com policy proposal

Letting emergency access become routine

An exceptional disclosure or logging mode can persist after the event unless expiration, review, and deletion are built into the process.

KIT-LIB-FAIL-07Technical recommendation

Archiving without provenance or redundancy

A single copy or unverified mirror can preserve corrupted, decontextualized, or altered material rather than trustworthy memory.

KIT-LIB-FAIL-08Worldwide principle

Importing one country’s legal answer worldwide

Privacy, public-records, education, labor, procurement, and disclosure rules differ. The global baseline should define rights and questions, not fabricate universal legal compliance.

Incident-response procedure

Contain concrete harm without multiplying exposure.

  1. KIT-LIB-IR-01Operational practice

    Protect people first

    Stop further exposure, preserve service access where safe, and avoid sending sensitive details through compromised or broadly shared channels.

  2. KIT-LIB-IR-02Technical recommendation

    Preserve bounded evidence

    Record system state, timestamps, affected data classes, access paths, and integrity evidence without copying unrelated patron histories into the incident file.

  3. KIT-LIB-IR-03Operational practice

    Classify the incident

    Distinguish breach, unauthorized secondary use, overbroad demand, false block, account-linking error, archive tampering, service loss, and staff misuse.

  4. KIT-LIB-IR-04Operational practice

    Activate independent review

    Escalate to the named privacy, legal, security, intellectual-freedom, youth-services, or archives owner based on the incident—not to a single unreviewed decision-maker.

  5. KIT-LIB-IR-05Technical recommendation

    Contain and revoke

    Disable exposed integrations, rotate credentials, suspend unauthorized exports, isolate affected hosts, and preserve a safe alternative access path.

  6. KIT-LIB-IR-06Jurisdiction-specific legal question

    Notify with specificity

    When legally permitted and safe, tell affected people what happened, what data was involved, what was not involved, what the institution did, and how to obtain help or remedy.

  7. KIT-LIB-IR-07CognitiveLiberties.com policy proposal

    Delete emergency copies

    After preservation and legal obligations end, delete investigation exports, temporary logs, screenshots, and replicated datasets created during response.

  8. KIT-LIB-IR-08CognitiveLiberties.com policy proposal

    Publish aggregate learning

    Record cause, control failure, remedy, recurrence prevention, and aggregate outcome without publishing identities or sensitive inquiry content.

Review cadence

Make safeguards operational rather than ceremonial.

KIT-LIB-REV-01Operational practice

Monthly deletion evidence

Review automated deletion failures, backup expiry, legal holds, exceptions, and unresolved vendor deletion tickets.

KIT-LIB-REV-02Technical recommendation

Quarterly access and filter test

Test guest access, identity separation, false blocks, override speed, role permissions, export paths, and data sent to subprocessors.

KIT-LIB-REV-03Operational practice

Semiannual vendor review

Recheck subprocessors, policy changes, breach history, analytics defaults, model-training terms, government-request process, and exit readiness.

KIT-LIB-REV-04CognitiveLiberties.com policy proposal

Annual public accountability

Publish aggregate privacy, incident, appeal, demand, deletion, and resilience results with methods and limitations.

KIT-LIB-REV-05Jurisdiction-specific legal question

Event-triggered legal review

Reassess jurisdiction-specific duties after new legislation, court decisions, regulator guidance, contracts, mergers, system redesigns, or material incidents.

Appeals and remedy

A safeguard is incomplete when no one can reverse a mistake.

KIT-LIB-REM-01CognitiveLiberties.com policy proposal

Immediate human review for blocked access

A patron can request prompt review without surrendering unrelated reading history or proving a socially approved purpose.

KIT-LIB-REM-02Operational practice

Private escalation channel

Provide a confidential route for sensitive health, abuse, identity, political, religious, or security research concerns.

KIT-LIB-REM-03Worldwide principle

Record access, correction, and deletion

People can learn what identifiable activity data exists, correct material errors, and request deletion subject to transparent legal limits.

KIT-LIB-REM-04Worldwide principle

Reasoned decisions

Denials and restrictions identify the rule, evidence category, decision owner, duration, and further review route without revealing security details that would create concrete harm.

KIT-LIB-REM-05CognitiveLiberties.com policy proposal

Independent second look

High-impact disputes involving minors, censorship, disclosure, discrimination, or archive removal receive review outside the original decision chain.

KIT-LIB-REM-06Operational practice

Restoration and practical remedy

When the institution is wrong, restore access or records, correct downstream data, notify relevant vendors, remove improper flags, and document recurrence prevention.

Data-deletion expectations

Delete the cognitive trail when the authorized need ends.

KIT-LIB-DEL-01CognitiveLiberties.com policy proposal

Search and discovery queries

Do not retain identifiable queries after the session unless the patron deliberately saves them. Aggregate operational metrics should be generated without preserving query-to-person links.

KIT-LIB-DEL-02Jurisdiction-specific legal question

Completed circulation events

Delete or de-identify completed borrowing histories after operational, dispute, and legal requirements end; saved reading history must be voluntary and independently erasable.

KIT-LIB-DEL-03Operational practice

Reference interactions

Do not place the substance of confidential reference questions into general patron profiles. Delete working notes when the request and any agreed follow-up are complete.

KIT-LIB-DEL-04Technical recommendation

Public-computer sessions

Clear local histories, temporary files, form data, authentication state, downloads, print queues, and session identifiers at logout or automatic session end.

KIT-LIB-DEL-05Jurisdiction-specific legal question

Wi-Fi and network logs

Use the shortest period compatible with documented security and legal needs; separate security events from browsing content and prohibit reuse for patron profiling.

KIT-LIB-DEL-06Technical recommendation

Backups and subprocessors

Retention schedules include backups, replicas, support exports, analytics warehouses, and every subprocesser—not only the production database.

KIT-LIB-DEL-07Operational practice

Incident-response artifacts

Delete temporary evidence copies when investigation, notice, remediation, and legal-preservation duties end; retain only the minimum aggregate learning record.

KIT-LIB-DEL-08CognitiveLiberties.com policy proposal

Archive access records

Separate collection-preservation needs from reader surveillance. Any security log for rare or fragile materials must have a named purpose, limited access, retention period, and independent review.

Measurable outcomes without dossiers

Measure systems, controls, response, and recovery—not what named people think.

No metric in this kit requires an identity-linked history of lawful questions, reading, research, beliefs, associations, or use of privacy tools.

KIT-LIB-OUT-01Operational practice

Collection necessity coverage

Percentage of data fields and events with a documented purpose, owner, recipient, retention period, and deletion method. Target: 100%.

Measurement boundary: Measure the data inventory, not individual patrons.

KIT-LIB-OUT-02Technical recommendation

Deletion completion

Percentage of scheduled deletion jobs completed and independently sampled on time, including backups and subprocessors.

Measurement boundary: Count jobs and exceptions; do not retain deleted content to prove deletion.

KIT-LIB-OUT-03Worldwide principle

Private-access availability

Share of core catalog, browsing, reference, and reading functions available without unnecessary account linkage.

Measurement boundary: Test functions with synthetic accounts and guest sessions, not histories of real readers.

KIT-LIB-OUT-04Operational practice

Appeal response time

Median and maximum time to human review for access blocks, privacy requests, and record corrections.

Measurement boundary: Track case timing and category; exclude the sensitive query from aggregate reporting.

KIT-LIB-OUT-05CognitiveLiberties.com policy proposal

Appeal correction rate

Aggregate proportion of reviewed restrictions or records that were corrected, with category and root cause.

Measurement boundary: Do not publish identities, titles read, or exact queries.

KIT-LIB-OUT-06Operational practice

Vendor compliance evidence

Percentage of vendors providing current data maps, subprocesser lists, security evidence, deletion proof, and contractual purpose limits.

Measurement boundary: Score contracts, audit artifacts, and deletion proof; do not score or retain patron behavior, searches, reading choices, or reference histories.

KIT-LIB-OUT-07Technical recommendation

Unnecessary identity reduction

Number of workflows that removed a persistent identifier, replaced it with a purpose-bound token, or added a guest path.

Measurement boundary: Measure system architecture changes; do not record who used a sensitive service, what they sought, or which lawful subject they explored.

KIT-LIB-OUT-08Operational practice

Incident containment and learning

Time to contain, notify, remediate, and close privacy, censorship, archive-integrity, or vendor incidents.

Measurement boundary: Publish aggregate timelines and controls; do not create a permanent dossier of affected inquiry.

KIT-LIB-OUT-09Technical recommendation

Resilience restoration test

Percentage of selected collections and essential services restored successfully from verified independent copies during exercises.

Measurement boundary: Measure fixity, completeness, and recovery time; do not use or retain person-level access, reading, search, or inquiry histories.

KIT-LIB-OUT-10CognitiveLiberties.com policy proposal

No generalized thought surveillance

Binary governance gate: the institution does not use identity-linked histories of lawful searches, reading, or reference questions as a routine performance, safety, discipline, or engagement metric.

Measurement boundary: Pass only when measurement can operate without a patron-level cognitive dossier.

Jurisdiction-specific legal review

Ask these questions locally before claiming compliance.

The worldwide baseline is a rights and architecture framework. Binding duties vary across constitutions, human-rights systems, privacy, consumer, education, press, labor, accessibility, cybersecurity, records, procurement, contracts, and court procedure.

Evidence basis and limits

Research, standards, law, technical guidance, and site proposals remain distinguishable.

Professional guidance, human-rights materials, technical standards, court records, and site proposals have different authority. The kit links them without treating professional ethics as binding law or one jurisdiction as the worldwide baseline.

Current law, vendor behavior, system configuration, and local risk must be independently rechecked before deployment. The exact 64-report archive remains preserved separately from this implementation derivative.

Questions institutions ask

What this kit does—and does not—require.

Is this kit legal advice?

No. It separates worldwide principles from jurisdiction-specific questions that require qualified local review.

Does privacy mean a library can ignore every lawful demand?

No. The kit calls for authentication, authority review, minimization, escalation, notice where permitted, and deletion after preservation duties end.

How can a library measure success without tracking what people read?

Measure system and governance outcomes such as deletion completion, private-access availability, appeal timing, vendor compliance, and restoration tests rather than patron-level inquiry histories.

Does the kit oppose all filtering or youth-safety controls?

No. It requires restrictions to be narrow, context-aware, reviewable, age-appropriate, and designed without universal identity or permanent inquiry dossiers.