Direct implementation answer
Libraries protect cognitive liberty when people can seek knowledge without unnecessary observation, when vendors cannot repurpose reading records, when access restrictions are narrow and reviewable, and when records are deleted as soon as operational need ends. The implementation goal is not secrecy from every lawful process; it is a system in which private inquiry is the default, exceptions are specific and accountable, and no patron must prove innocence for asking a lawful question.
Name systems, protected activity, and credible failure paths.
Scope: The kit addresses routine systems and foreseeable incidents involving catalogs, discovery layers, library-management systems, digital lending, public computers, Wi-Fi, analytics, identity providers, access-control tools, school integrations, archives, and third-party vendors. It does not promise anonymity against every targeted lawful investigation, endpoint compromise, or physical observation.
Protected activity: Lawful reading, searching, browsing, borrowing, reference consultation, note-taking, research, archival access, and intellectual exploration by adults and minors.
KIT-LIB-TH-01Worldwide principlePersistent inquiry histories
Catalog searches, borrowing records, digital-reading telemetry, reference questions, and workstation logs can become a durable map of unfinished thought when retained after operational need ends.
KIT-LIB-TH-02Operational practiceVendor reuse and cross-context profiling
A service provider may combine library activity with advertising, identity, education, or commercial data unless contracts and architecture prevent secondary use.
KIT-LIB-TH-03Technical recommendationIdentity overcollection
Account design, age assurance, guest access, Wi-Fi portals, and single sign-on can collect more identity than the service needs, converting private inquiry into attributable behavior.
KIT-LIB-TH-04Worldwide principleOverblocking without practical appeal
Filters and automated safety systems can block lawful health, identity, political, historical, or security research when context is reduced to keywords or risk labels.
KIT-LIB-TH-05Jurisdiction-specific legal questionCompelled or informal disclosure
Staff and vendors may receive demands for patron records, preservation requests, subpoenas, informal pressure, or emergency claims without a consistent escalation and minimization process.
KIT-LIB-TH-06Operational practiceLoss, tampering, and historical erasure
Archives and local collections can be deleted, altered, decontextualized, or made inaccessible through technical failure, political pressure, vendor withdrawal, or insufficient geographic redundancy.
Build a rights-preserving floor before adding complexity.
These safeguards state the purpose that must survive local implementation. They are not a claim that every jurisdiction uses identical law or procedure.
KIT-LIB-SG-01Worldwide principleCollect the minimum
Do not collect a patron identifier, query, reading event, location, device identifier, or demographic field unless a documented service function requires it. Prefer aggregate service counts over person-level histories.
KIT-LIB-SG-02Technical recommendationSeparate identity from inquiry
Where accounts are necessary, keep authentication data separate from searches, content requests, and analytics. Use short-lived, purpose-bound tokens and privacy partitioning instead of a universal activity identifier.
KIT-LIB-SG-03CognitiveLiberties.com policy proposalDelete by design
Set automatic deletion for search logs, session data, completed borrowing histories, expired holds, and diagnostic events. Exceptions must be named, narrow, time-limited, and reviewable.
KIT-LIB-SG-04Operational practiceMake private use normal
Offer guest browsing, private research workstations, non-account discovery, and confidential reference channels where operationally feasible. Do not make privacy a special mode that stigmatizes the user.
KIT-LIB-SG-05CognitiveLiberties.com policy proposalProhibit behavioral monetization
Contracts must forbid advertising profiles, sale or sharing of patron activity, unrelated model training, cross-service identity graphs, and secondary use that is not necessary to provide the library service.
KIT-LIB-SG-06Worldwide principleKeep restrictions narrow and reversible
Any content restriction must identify the harm, legal or policy authority, affected audience, scope, duration, review owner, and a practical route to restore access when the system is wrong.
KIT-LIB-SG-07Worldwide principleProtect minors without universal surveillance
Use age-appropriate service design and staff support without assuming that parental visibility, government identification, or permanent age profiles are always safe or necessary.
KIT-LIB-SG-08Operational practiceControl vendor and subcontractor access
Name every processor and subprocesser, restrict staff roles, require breach notice, preserve library ownership and deletion authority, and make audit evidence available.
KIT-LIB-SG-09Jurisdiction-specific legal questionRequire lawful-demand discipline
Adopt an escalation process that authenticates requests, checks jurisdiction and authority, narrows scope, records disclosures, challenges overbreadth where permitted, and notifies affected people when lawful and safe.
KIT-LIB-SG-10Technical recommendationPreserve public memory redundantly
Maintain fixity checks, format migration, access controls, provenance, and geographically or institutionally independent copies for collections at risk, without publishing sensitive source identities by default.
Move from visibility to enforceable controls to durable resilience.
KIT-LIB-STAGE-30Map the data and stop avoidable collection
Outcome: The institution can explain what patron data exists, why it exists, who can reach it, when it is deleted, and which urgent exposures are already disabled.
KIT-LIB-ACT-30-01Operational practiceName an accountable owner
Assign a privacy and intellectual-freedom owner with authority across technology, vendors, records, public service, youth services, archives, and incident response.
KIT-LIB-ACT-30-02Technical recommendationCreate a data-flow inventory
Map collection from search box to vendor, including identifiers, logs, analytics, backups, support exports, identity providers, public computers, Wi-Fi, and archive access systems.
KIT-LIB-ACT-30-03CognitiveLiberties.com policy proposalDisable unnecessary histories
Turn off optional reading-history, query-retention, behavioral analytics, session replay, and advertising integrations unless a documented, approved purpose survives review.
KIT-LIB-ACT-30-04Operational practicePublish the immediate privacy boundary
Tell patrons what is collected, what is not, which vendors receive data, how long data remains, and how to seek access, correction, deletion, or help.
KIT-LIB-STAGE-90Bind systems, vendors, and exceptions
Outcome: Retention, vendor use, access restrictions, lawful demands, incident response, and appeals operate under written controls rather than informal custom.
KIT-LIB-ACT-90-01Operational practiceAdopt retention schedules
Set event-specific deletion periods, backup expiry, hold-release cleanup, account closure handling, and documented legal-hold exceptions.
KIT-LIB-ACT-90-02Operational practiceAmend vendor contracts
Bind first parties and subprocessors to purpose limitation, security, deletion, auditability, incident notice, no sale, no advertising, no unrelated training, and return-or-destroy duties.
KIT-LIB-ACT-90-03CognitiveLiberties.com policy proposalCreate unblock and appeal paths
Provide immediate staff-assisted review for access errors, record the category rather than the patron’s full inquiry where possible, and publish escalation times.
KIT-LIB-ACT-90-04Operational practiceExercise the incident plan
Run one tabletop exercise for a data breach, one for an overbroad disclosure demand, and one for a censorship or archive-tampering event.
KIT-LIB-STAGE-365Build durable private access and institutional resilience
Outcome: The institution can prove that private inquiry, correction, deletion, vendor accountability, and memory preservation survive staff turnover, platform change, and political pressure.
KIT-LIB-ACT-365-01Technical recommendationRedesign identity boundaries
Replace shared persistent identifiers with purpose-bound tokens or separated systems wherever practical, and test whether sensitive discovery can operate without account linkage.
KIT-LIB-ACT-365-02CognitiveLiberties.com policy proposalCreate a privacy-preserving measurement plan
Measure service availability, deletion completion, appeal resolution, vendor compliance, and incident response without retaining patron-level query or reading histories.
KIT-LIB-ACT-365-03Operational practiceEstablish redundant custody
Identify at-risk collections, document provenance and access boundaries, maintain independent copies, and test restoration from verified backups.
KIT-LIB-ACT-365-04CognitiveLiberties.com policy proposalPublish an annual accountability record
Report aggregate demand categories, confirmed incidents, deletion performance, appeal outcomes, vendor exceptions, and unresolved risks without exposing readers or researchers.
Do not buy a promise. Require inspectable evidence.
A policy statement is not proof of system behavior. Require architecture, configuration, tests, contracts, logs with bounded retention, deletion evidence, and a remedy when the provider is wrong.
KIT-LIB-PROC-01Operational practiceData inventory supplied
The vendor lists every field, event, identifier, log, derived inference, diagnostic record, backup, support export, and subprocesser involved in the service.
KIT-LIB-PROC-02CognitiveLiberties.com policy proposalPurpose limitation is contractual
Each collected field is tied to a named service purpose; advertising, resale, unrelated analytics, profiling, and unrelated model training are prohibited.
KIT-LIB-PROC-03Operational practiceRetention is event-specific
The proposal states automatic deletion deadlines for searches, sessions, circulation events, logs, backups, support files, and closed accounts.
KIT-LIB-PROC-04Technical recommendationLibrary controls deletion
The institution can delete patron records, verify completion across backups and subprocessors, and receive evidence when a legal hold prevents deletion.
KIT-LIB-PROC-05Worldwide principleAnonymous or guest use assessed
The vendor documents which core functions work without an account and explains why identity is required for every remaining function.
KIT-LIB-PROC-06Technical recommendationIdentity and inquiry are separated
Architecture diagrams show whether authentication services, analytics, content requests, and recommendation systems share a persistent identifier.
KIT-LIB-PROC-07Technical recommendationFilter behavior is testable
The institution can test false blocks, inspect categories, override errors, and obtain change records without exposing a patron’s identity or entire search history.
KIT-LIB-PROC-08Operational practiceSecurity evidence is current
Independent security testing, encryption boundaries, access controls, incident history, vulnerability handling, and breach-notice timing are documented.
KIT-LIB-PROC-09Jurisdiction-specific legal questionGovernment-request process is documented
The vendor describes how demands are authenticated, narrowed, challenged, logged, and disclosed in aggregate, subject to applicable law.
KIT-LIB-PROC-10Operational practicePortability and exit are real
The contract guarantees usable exports, documented formats, migration support, deletion after exit, and continuity if the vendor is acquired or discontinued.
KIT-LIB-PROC-11Worldwide principleMinor access does not become universal tracking
Age-related controls identify the minimum attribute needed, avoid permanent age dossiers, and include confidential-help pathways.
KIT-LIB-PROC-12Jurisdiction-specific legal questionNo unsupported compliance claim
The vendor names the exact law, standard, certification, version, scope, and auditor behind every compliance statement. “Privacy compliant” alone is not accepted.
Good intentions can still create cognitive surveillance.
KIT-LIB-FAIL-01Operational practiceKeeping everything “just in case”
Indefinite retention converts operations data into a surveillance asset and increases breach, disclosure, and misuse risk.
KIT-LIB-FAIL-02Operational practiceTreating vendor policy as proof
A privacy statement does not establish production behavior, subcontractor handling, deletion, or identity separation.
KIT-LIB-FAIL-03CognitiveLiberties.com policy proposalUsing individual histories to prove impact
Counting every reader’s journey may produce attractive dashboards while destroying the private inquiry the service exists to protect.
KIT-LIB-FAIL-04Worldwide principleMaking appeals humiliating or slow
A theoretical unblock process fails when patrons must explain sensitive research at a public desk or wait longer than the research need lasts.
KIT-LIB-FAIL-05Jurisdiction-specific legal questionAssuming parental visibility always equals safety
For some minors, private access to health, abuse, identity, or belief information is itself a safety measure. Local law still requires specific review.
KIT-LIB-FAIL-06CognitiveLiberties.com policy proposalLetting emergency access become routine
An exceptional disclosure or logging mode can persist after the event unless expiration, review, and deletion are built into the process.
KIT-LIB-FAIL-07Technical recommendationArchiving without provenance or redundancy
A single copy or unverified mirror can preserve corrupted, decontextualized, or altered material rather than trustworthy memory.
KIT-LIB-FAIL-08Worldwide principleImporting one country’s legal answer worldwide
Privacy, public-records, education, labor, procurement, and disclosure rules differ. The global baseline should define rights and questions, not fabricate universal legal compliance.
Contain concrete harm without multiplying exposure.
KIT-LIB-IR-01Operational practiceProtect people first
Stop further exposure, preserve service access where safe, and avoid sending sensitive details through compromised or broadly shared channels.
KIT-LIB-IR-02Technical recommendationPreserve bounded evidence
Record system state, timestamps, affected data classes, access paths, and integrity evidence without copying unrelated patron histories into the incident file.
KIT-LIB-IR-03Operational practiceClassify the incident
Distinguish breach, unauthorized secondary use, overbroad demand, false block, account-linking error, archive tampering, service loss, and staff misuse.
KIT-LIB-IR-04Operational practiceActivate independent review
Escalate to the named privacy, legal, security, intellectual-freedom, youth-services, or archives owner based on the incident—not to a single unreviewed decision-maker.
KIT-LIB-IR-05Technical recommendationContain and revoke
Disable exposed integrations, rotate credentials, suspend unauthorized exports, isolate affected hosts, and preserve a safe alternative access path.
EvidenceSRC-ALA-LMS-PRIVACYKIT-LIB-IR-06Jurisdiction-specific legal questionNotify with specificity
When legally permitted and safe, tell affected people what happened, what data was involved, what was not involved, what the institution did, and how to obtain help or remedy.
KIT-LIB-IR-07CognitiveLiberties.com policy proposalDelete emergency copies
After preservation and legal obligations end, delete investigation exports, temporary logs, screenshots, and replicated datasets created during response.
KIT-LIB-IR-08CognitiveLiberties.com policy proposalPublish aggregate learning
Record cause, control failure, remedy, recurrence prevention, and aggregate outcome without publishing identities or sensitive inquiry content.
Make safeguards operational rather than ceremonial.
KIT-LIB-REV-01Operational practiceMonthly deletion evidence
Review automated deletion failures, backup expiry, legal holds, exceptions, and unresolved vendor deletion tickets.
KIT-LIB-REV-02Technical recommendationQuarterly access and filter test
Test guest access, identity separation, false blocks, override speed, role permissions, export paths, and data sent to subprocessors.
KIT-LIB-REV-03Operational practiceSemiannual vendor review
Recheck subprocessors, policy changes, breach history, analytics defaults, model-training terms, government-request process, and exit readiness.
KIT-LIB-REV-04CognitiveLiberties.com policy proposalAnnual public accountability
Publish aggregate privacy, incident, appeal, demand, deletion, and resilience results with methods and limitations.
KIT-LIB-REV-05Jurisdiction-specific legal questionEvent-triggered legal review
Reassess jurisdiction-specific duties after new legislation, court decisions, regulator guidance, contracts, mergers, system redesigns, or material incidents.
A safeguard is incomplete when no one can reverse a mistake.
KIT-LIB-REM-01CognitiveLiberties.com policy proposalImmediate human review for blocked access
A patron can request prompt review without surrendering unrelated reading history or proving a socially approved purpose.
KIT-LIB-REM-02Operational practicePrivate escalation channel
Provide a confidential route for sensitive health, abuse, identity, political, religious, or security research concerns.
KIT-LIB-REM-03Worldwide principleRecord access, correction, and deletion
People can learn what identifiable activity data exists, correct material errors, and request deletion subject to transparent legal limits.
KIT-LIB-REM-04Worldwide principleReasoned decisions
Denials and restrictions identify the rule, evidence category, decision owner, duration, and further review route without revealing security details that would create concrete harm.
KIT-LIB-REM-05CognitiveLiberties.com policy proposalIndependent second look
High-impact disputes involving minors, censorship, disclosure, discrimination, or archive removal receive review outside the original decision chain.
KIT-LIB-REM-06Operational practiceRestoration and practical remedy
When the institution is wrong, restore access or records, correct downstream data, notify relevant vendors, remove improper flags, and document recurrence prevention.
Delete the cognitive trail when the authorized need ends.
KIT-LIB-DEL-01CognitiveLiberties.com policy proposalSearch and discovery queries
Do not retain identifiable queries after the session unless the patron deliberately saves them. Aggregate operational metrics should be generated without preserving query-to-person links.
KIT-LIB-DEL-02Jurisdiction-specific legal questionCompleted circulation events
Delete or de-identify completed borrowing histories after operational, dispute, and legal requirements end; saved reading history must be voluntary and independently erasable.
KIT-LIB-DEL-03Operational practiceReference interactions
Do not place the substance of confidential reference questions into general patron profiles. Delete working notes when the request and any agreed follow-up are complete.
KIT-LIB-DEL-04Technical recommendationPublic-computer sessions
Clear local histories, temporary files, form data, authentication state, downloads, print queues, and session identifiers at logout or automatic session end.
KIT-LIB-DEL-05Jurisdiction-specific legal questionWi-Fi and network logs
Use the shortest period compatible with documented security and legal needs; separate security events from browsing content and prohibit reuse for patron profiling.
KIT-LIB-DEL-06Technical recommendationBackups and subprocessors
Retention schedules include backups, replicas, support exports, analytics warehouses, and every subprocesser—not only the production database.
KIT-LIB-DEL-07Operational practiceIncident-response artifacts
Delete temporary evidence copies when investigation, notice, remediation, and legal-preservation duties end; retain only the minimum aggregate learning record.
KIT-LIB-DEL-08CognitiveLiberties.com policy proposalArchive access records
Separate collection-preservation needs from reader surveillance. Any security log for rare or fragile materials must have a named purpose, limited access, retention period, and independent review.
Measure systems, controls, response, and recovery—not what named people think.
No metric in this kit requires an identity-linked history of lawful questions, reading, research, beliefs, associations, or use of privacy tools.
KIT-LIB-OUT-01Operational practiceCollection necessity coverage
Percentage of data fields and events with a documented purpose, owner, recipient, retention period, and deletion method. Target: 100%.
Measurement boundary: Measure the data inventory, not individual patrons.
KIT-LIB-OUT-02Technical recommendationDeletion completion
Percentage of scheduled deletion jobs completed and independently sampled on time, including backups and subprocessors.
Measurement boundary: Count jobs and exceptions; do not retain deleted content to prove deletion.
KIT-LIB-OUT-03Worldwide principlePrivate-access availability
Share of core catalog, browsing, reference, and reading functions available without unnecessary account linkage.
Measurement boundary: Test functions with synthetic accounts and guest sessions, not histories of real readers.
KIT-LIB-OUT-04Operational practiceAppeal response time
Median and maximum time to human review for access blocks, privacy requests, and record corrections.
Measurement boundary: Track case timing and category; exclude the sensitive query from aggregate reporting.
KIT-LIB-OUT-05CognitiveLiberties.com policy proposalAppeal correction rate
Aggregate proportion of reviewed restrictions or records that were corrected, with category and root cause.
Measurement boundary: Do not publish identities, titles read, or exact queries.
KIT-LIB-OUT-06Operational practiceVendor compliance evidence
Percentage of vendors providing current data maps, subprocesser lists, security evidence, deletion proof, and contractual purpose limits.
Measurement boundary: Score contracts, audit artifacts, and deletion proof; do not score or retain patron behavior, searches, reading choices, or reference histories.
KIT-LIB-OUT-07Technical recommendationUnnecessary identity reduction
Number of workflows that removed a persistent identifier, replaced it with a purpose-bound token, or added a guest path.
Measurement boundary: Measure system architecture changes; do not record who used a sensitive service, what they sought, or which lawful subject they explored.
KIT-LIB-OUT-08Operational practiceIncident containment and learning
Time to contain, notify, remediate, and close privacy, censorship, archive-integrity, or vendor incidents.
Measurement boundary: Publish aggregate timelines and controls; do not create a permanent dossier of affected inquiry.
KIT-LIB-OUT-09Technical recommendationResilience restoration test
Percentage of selected collections and essential services restored successfully from verified independent copies during exercises.
Measurement boundary: Measure fixity, completeness, and recovery time; do not use or retain person-level access, reading, search, or inquiry histories.
KIT-LIB-OUT-10CognitiveLiberties.com policy proposalNo generalized thought surveillance
Binary governance gate: the institution does not use identity-linked histories of lawful searches, reading, or reference questions as a routine performance, safety, discipline, or engagement metric.
Measurement boundary: Pass only when measurement can operate without a patron-level cognitive dossier.
Ask these questions locally before claiming compliance.
The worldwide baseline is a rights and architecture framework. Binding duties vary across constitutions, human-rights systems, privacy, consumer, education, press, labor, accessibility, cybersecurity, records, procurement, contracts, and court procedure.
KIT-LIB-LAW-01Jurisdiction-specific legal questionWhat records are legally confidential?
Identify statutes, constitutional rules, professional duties, public-records exceptions, education rules, and contractual promises that govern patron, student, archive, and network records.
KIT-LIB-LAW-02Jurisdiction-specific legal questionWhat can and must be deleted?
Determine mandatory retention, litigation hold, audit, accessibility, public-records, tax, safeguarding, and archival obligations before setting deletion periods.
KIT-LIB-LAW-03Jurisdiction-specific legal questionWhat process governs disclosure demands?
Define who may issue a valid demand, when judicial authorization is required, whether notice is allowed, how emergency requests are verified, and what challenge rights exist.
KIT-LIB-LAW-04Jurisdiction-specific legal questionHow do minors’ privacy and guardianship rules interact?
Review the rights of minors, parents or guardians, schools, mature adolescents, mandatory reporters, and confidential-help services without assuming one universal answer.
KIT-LIB-LAW-05Jurisdiction-specific legal questionWhich accessibility and equality duties apply?
Ensure privacy controls, identity alternatives, appeals, and digital services remain usable for people with disabilities, people without standard identity documents, and marginalized language communities.
KIT-LIB-LAW-06Jurisdiction-specific legal questionWhat procurement and worker rules constrain monitoring?
Assess public procurement, labor, collective bargaining, staff privacy, security, records, and audit requirements before deploying monitoring or automated decision systems.
Research, standards, law, technical guidance, and site proposals remain distinguishable.
Professional guidance, human-rights materials, technical standards, court records, and site proposals have different authority. The kit links them without treating professional ethics as binding law or one jurisdiction as the worldwide baseline.
Section-level evidence units
Current law, vendor behavior, system configuration, and local risk must be independently rechecked before deployment. The exact 64-report archive remains preserved separately from this implementation derivative.
What this kit does—and does not—require.
Is this kit legal advice?
No. It separates worldwide principles from jurisdiction-specific questions that require qualified local review.
Does privacy mean a library can ignore every lawful demand?
No. The kit calls for authentication, authority review, minimization, escalation, notice where permitted, and deletion after preservation duties end.
How can a library measure success without tracking what people read?
Measure system and governance outcomes such as deletion completion, private-access availability, appeal timing, vendor compliance, and restoration tests rather than patron-level inquiry histories.
Does the kit oppose all filtering or youth-safety controls?
No. It requires restrictions to be narrow, context-aware, reviewable, age-appropriate, and designed without universal identity or permanent inquiry dossiers.