Direct implementation answer
Public institutions protect cognitive liberty when they require individualized or properly bounded authority, minimize data, separate identity from inquiry, disclose government-platform interactions, constrain automated decisions, preserve anonymous and pseudonymous access, provide human review and remedy, delete unsupported inferences, and terminate emergency powers when the defined need ends.
Do not collapse different people into one surveillance category.
The same technology can create different risks depending on power, age, role, location, legal authority, and the consequences of disclosure.
KIT-PUB-POP-01Residents and service users
People seeking benefits, licenses, education, health information, public records, library access, or ordinary services should not have unrelated lawful inquiry converted into an eligibility or risk profile.
KIT-PUB-POP-02Children and adolescents
Safeguarding must address exploitation and concrete harm while preserving age-appropriate confidential help-seeking, reading, identity development, and voluntary inquiry.
KIT-PUB-POP-03People without standard identity documents
Essential information and services need accessible alternatives for refugees, migrants, unhoused people, survivors, and others who cannot safely or readily present a conventional credential.
KIT-PUB-POP-04Public servants and contractors
Employment security and operational integrity do not justify continuous ideological, emotional, religious, health, or cognitive monitoring of workers.
KIT-PUB-POP-05Journalists, researchers, advocates, and whistleblowers
Contact with controversial people, use of encryption, sensitive searches, public-records requests, and investigation of alleged wrongdoing are protected functions, not automatic indicators of threat.
KIT-PUB-POP-06Targets, witnesses, and uninvolved associates
Investigative authority must distinguish the person or event supported by evidence from family, colleagues, readers, visitors, bystanders, or communities swept into the same data graph.
KIT-PUB-POP-07Political, religious, and cultural minorities
A system must not convert minority belief, dissent, satire, protest, association, language, or historical interpretation into a durable adverse classification.
KIT-PUB-POP-08Judges, auditors, ombuds, and elected overseers
Independent reviewers need complete evidence and secure access while remaining separate from operational chains that benefit from expanding the power under review.
Controls must stay inside the context that justifies them.
KIT-PUB-CTX-01Routine public administration
Ordinary service delivery should use the minimum data necessary for the transaction and should not silently inherit law-enforcement or intelligence purposes.
KIT-PUB-CTX-02Individualized investigation
A properly authorized investigation tied to evidence of a defined event is different from reverse-keyword, geofence, bulk, or population-wide collection that begins with no particularized subject.
KIT-PUB-CTX-03Emergency response
Immediate action may be justified to protect an identifiable person from concrete harm, but emergency access must be logged, reviewed, narrowed, and terminated.
KIT-PUB-CTX-04Automated eligibility and risk decisions
A tool that helps route a case is different from a model that determines benefits, licensing, employment, education, border treatment, policing, or security consequences without contestable human judgment.
KIT-PUB-CTX-05Government communication with platforms
Public persuasion, lawful notice, binding order, informal request, procurement leverage, and regulatory threat are different forms of power and must not be blended into an opaque moderation channel.
KIT-PUB-CTX-06Public records and historical archives
Transparency, privacy, legal holds, classified material, correction, deletion, provenance, and long-term memory require different rules; one cannot be invoked to erase the others.
KIT-PUB-CTX-07Public procurement and delegated power
A vendor does not reduce government responsibility. Contracted identity, AI, analytics, moderation, or surveillance systems remain public exercises of authority when they affect rights or services.
Name systems, protected activity, and credible failure paths.
Scope: Government acquisition and use of search, browsing, AI-prompt, library, communications, location, biometric, neural, and behavioral-inference data; warrants and administrative demands; reverse searches; public records and archives; government-platform communication; automated eligibility and enforcement; public-sector AI procurement and alignment; identity and age verification; emergency powers; national security; and institutional oversight.
Protected activity: Lawful thought, reading, searching, AI inquiry, religion, political belief, association, petition, journalism, legal and historical research, academic work, health inquiry, controversial rights research, anonymous or pseudonymous speech, encryption, privacy tools, and criticism of public authority.
KIT-PUB-TH-01Worldwide principleBulk access to cognitive and behavioral data
Search, prompt, library, communications, location, biometric, neural, and inferred-trait records can be acquired or combined without individualized evidence, creating a map of lawful intellectual life.
KIT-PUB-TH-02Jurisdiction-specific legal questionReverse-keyword and reverse-location investigation
A government may begin with a search term, location, website, or topic and ask a provider to identify everyone who matched it, reversing particularized suspicion.
KIT-PUB-TH-03Worldwide principleOpaque government pressure on information intermediaries
Informal requests, regulatory threats, procurement leverage, grants, licensing, and public accusations can induce platforms to suppress lawful material without a public order or appeal.
KIT-PUB-TH-04Worldwide principleAutomated eligibility and adverse action
Models used for benefits, licensing, employment, education, border, policing, fraud, or security can convert weak correlations and lawful inquiry into material consequences.
KIT-PUB-TH-05Technical recommendationUniversal identity and attributable access
Age, eligibility, anti-fraud, or service requirements can become a common identifier linking every question, visit, payment, association, and public interaction.
KIT-PUB-TH-06CognitiveLiberties.com policy proposalEmergency and national-security ratchets
Temporary powers created for war, terrorism, public health, civil disorder, elections, misinformation, or child protection can persist, broaden, and migrate into routine administration.
KIT-PUB-TH-07CognitiveLiberties.com policy proposalGovernment alignment of AI and official machine truth
Procurement, licensing, training-data rules, content filters, evaluation criteria, or informal pressure can force AI systems to reproduce state-preferred narratives without visible attribution.
KIT-PUB-TH-08Operational practicePublic-record manipulation and institutional amnesia
Deletion, classification, altered metadata, broken provenance, inaccessible archives, and vendor withdrawal can prevent later accountability or rewrite the public record.
KIT-PUB-TH-09Worldwide principleSecondary use and downstream propagation
Data collected for one service can be reused for enforcement, intelligence, employment, fraud, model training, or political profiling and copied into systems the person cannot see.
KIT-PUB-TH-10Operational practiceOversight capture and unverifiable secrecy
Review bodies may lack technical access, independence, budget, standing, adversarial evidence, or authority to stop a system whose operators define their own compliance.
Build a rights-preserving floor before adding complexity.
These safeguards state the purpose that must survive local implementation. They are not a claim that every jurisdiction uses identical law or procedure.
KIT-PUB-SG-01Worldwide principlePresume lawful inquiry is not evidence of wrongdoing
Do not treat a question, topic, reading choice, source contact, protest interest, encryption use, or controversial rights research as proof of belief, intent, dangerousness, or unfitness without independent evidence.
KIT-PUB-SG-02Worldwide principleRequire defined harm and bounded authority
Every restrictive action must name the concrete harm, legal authority, evidence threshold, affected population, scope, duration, responsible official, reviewer, remedy, and end condition.
KIT-PUB-SG-03Jurisdiction-specific legal questionUse individualized or properly bounded process
Prefer particularized warrants, orders, and decisions. Where another legal standard applies, document why it is lawful, necessary, proportionate, and no broader than the actual investigation or service.
KIT-PUB-SG-04Technical recommendationMinimize and separate identity from inquiry
Collect only the identity required for the transaction and keep credentials separate from search, reading, prompt, library, and content records through scoped identifiers and split trust.
KIT-PUB-SG-05CognitiveLiberties.com policy proposalOffer anonymous and pseudonymous public access
Preserve non-account reading, public information, public records, library use, complaint intake, and other lawful inquiry where full civil identity is not necessary.
KIT-PUB-SG-06Technical recommendationSeparate request-level safety from person-level judgment
A warning, refusal, rate limit, or local safeguard should ordinarily attach to the request. Persistent risk labels, referrals, or eligibility consequences require a higher and contestable evidentiary process.
KIT-PUB-SG-07Operational practiceMake government-platform interactions reviewable
Record the sender, recipient, legal basis, requested action, urgency, content category, response, appeal path, retention, and whether the communication was persuasion, notice, request, or binding order.
KIT-PUB-SG-08CognitiveLiberties.com policy proposalRequire human review before material impairment
Benefits, licensing, discipline, employment, border, policing, fraud, and security decisions must not become final solely because a model generated a score or label.
KIT-PUB-SG-09Worldwide principleProvide notice, evidence, appeal, and correction
Explain the rule and material facts, identify the machine role, permit contextual evidence, assign an independent reviewer, set deadlines, pause avoidable harm, and correct downstream systems.
KIT-PUB-SG-10CognitiveLiberties.com policy proposalDelete unsupported cognitive data and inferences
Remove raw records, embeddings, labels, scores, watch-list entries, model features, training copies, and propagated derivatives when authority or need ends or the judgment is overturned.
KIT-PUB-SG-11Technical recommendationUse privacy-preserving safety architecture
Prefer local processing, oblivious transport, private retrieval, anonymous credentials, threshold authorization, private aggregation, and synthetic testing before centralized identity-linked monitoring.
KIT-PUB-SG-12Operational practiceProtect public memory with provenance and plural custody
Maintain fixity, provenance, correction histories, lawful access, format migration, independent copies, and clear rules for privacy, classification, legal holds, and eventual release.
KIT-PUB-SG-13CognitiveLiberties.com policy proposalBuild automatic anti-ratchet controls
Use scope-limited appropriations, technical purpose separation, expiration, reauthorization with evidence, public statistics, independent audit, deletion, and tested dismantling procedures.
KIT-PUB-SG-14Worldwide principlePreserve independent oversight and whistleblowing
Protect inspectors, auditors, courts, ombuds, legislators, journalists, researchers, and whistleblowers from retaliation and give them the evidence needed to test official claims.
Move from visibility to enforceable controls to durable resilience.
KIT-PUB-STAGE-30Map authority, data, and immediate rights exposure
Outcome: The institution can identify every cognitive-data flow, restrictive power, automated decision, platform communication, emergency authority, vendor, owner, retention rule, and route for urgent human review.
KIT-PUB-30-01Operational practiceName accountable owners
Assign executive, legal, privacy, security, records, procurement, accessibility, civil-rights, and independent-review owners with published responsibilities.
EvidenceCL-14-02KIT-PUB-30-02Operational practiceInventory cognitive and behavioral data
Map search, prompt, browsing, library, communications, location, biometric, neural, identity, inferred-trait, risk, and eligibility data from collection through deletion.
KIT-PUB-30-03Jurisdiction-specific legal questionInventory coercive and restrictive authorities
List warrants, subpoenas, administrative demands, emergency access, reverse searches, secrecy orders, content requests, licensing, procurement, grants, and platform contacts.
KIT-PUB-30-04CognitiveLiberties.com policy proposalFreeze unsupported high-impact automation
Pause new person-level inference, automated adverse action, emotion or ideology scoring, and bulk query analysis until authority, validity, necessity, and remedy are documented.
KIT-PUB-30-05Operational practicePublish immediate rights and escalation boundaries
Tell the public what is collected, what is not, how emergency access works, who can challenge a decision, and how to reach a human without disclosing more sensitive information.
KIT-PUB-STAGE-90Convert principles into enforceable controls and remedies
Outcome: The highest-risk powers have written thresholds, technical minimization, contract controls, human review, transparency, appeal, deletion, oversight, and tested incident procedures.
KIT-PUB-90-01CognitiveLiberties.com policy proposalAdopt a cognitive-liberty impact assessment
Require a documented assessment before identity gates, monitoring, model alignment, automated decisions, reverse searches, content restrictions, or new cognitive-data uses.
KIT-PUB-90-02Technical recommendationImplement minimization and purpose separation
Change schemas, access roles, logs, tokens, and storage so service delivery, analytics, enforcement, intelligence, training, and public records do not silently share one data lake.
KIT-PUB-90-03Operational practiceStandardize government-platform records
Create machine-readable request and order records, public aggregate reporting, legal review, conflict escalation, and retention rules.
KIT-PUB-90-04Worldwide principleCreate independent appeal and correction
Provide timely human reconsideration, access to material evidence, representation or support where needed, downstream correction, restoration, and deletion of unsupported labels.
KIT-PUB-90-05Operational practiceExercise emergency and breach procedures
Run tabletop tests for immediate threats, emergency data demands, mass false positives, vendor failure, archive tampering, model drift, data breach, and unlawful pressure.
KIT-PUB-STAGE-365Institutionalize plural oversight, resilience, and automatic limits
Outcome: Cognitive-liberty safeguards survive leadership change through law, budget, architecture, records, procurement, independent oversight, public evidence, and tested exit.
KIT-PUB-365-01CognitiveLiberties.com policy proposalCodify rights and prohibited uses
Establish enforceable limits on query profiling, covert cognitive manipulation, unsupported sensitive inference, secret person-level risk labels, and adverse decisions based solely on lawful inquiry.
KIT-PUB-365-02Operational practiceCreate durable oversight capacity
Fund independent technical auditors, inspectors, ombuds, courts, legislatures, civil society, and public-interest research with secure evidence access and authority to order correction.
KIT-PUB-365-03Technical recommendationBuild vendor and infrastructure exit
Maintain export, interoperability, alternate providers, open formats, domain and key custody, archive copies, migration runbooks, and termination rights.
KIT-PUB-365-04CognitiveLiberties.com policy proposalMake emergency authority expire by design
Tie extraordinary access, filtering, monitoring, and alignment powers to narrow triggers, automatic technical expiration, public reauthorization evidence, deletion, and budget termination.
KIT-PUB-365-05Operational practicePublish aggregate accountability evidence
Report request categories, error and appeal outcomes, deletion performance, audit findings, model changes, emergency uses, and remedy without exposing lawful inquiries or protected people.
Do not buy a promise. Require inspectable evidence.
A policy statement is not proof of system behavior. Require architecture, configuration, tests, contracts, logs with bounded retention, deletion evidence, and a remedy when the provider is wrong.
KIT-PUB-PROC-01Jurisdiction-specific legal questionPurpose and legal authority
Require the exact public purpose, legal basis, affected decision, prohibited uses, and reasons less intrusive alternatives are insufficient.
KIT-PUB-PROC-02Operational practiceCollected fields and derived inferences
Demand every raw field, identifier, metadata element, embedding, score, label, relationship, prediction, and inferred trait.
KIT-PUB-PROC-03Technical recommendationIdentity and attribute architecture
Document whether full identity is necessary, which selective-disclosure or anonymous alternatives were tested, and how identifiers remain unlinkable across services.
KIT-PUB-PROC-04Operational practiceRetention and verified deletion
Specify event-level schedules, legal holds, backup expiry, model and vector deletion, downstream copies, proof of completion, and consequences for failure.
KIT-PUB-PROC-05CognitiveLiberties.com policy proposalTraining, evaluation, and product improvement
Prohibit training or evaluation use unless explicitly authorized, necessary, documented, revocable, and separable from service delivery.
KIT-PUB-PROC-06CognitiveLiberties.com policy proposalAdvertising, sale, profiling, and unrelated reuse
Contractually prohibit commercial targeting, data brokerage, political profiling, sensitive-trait inference, and cross-context use of public-service data.
KIT-PUB-PROC-07Operational practiceSubprocessors and cross-border processing
Name every processor, location, access role, onward transfer, government-demand exposure, and replacement-notice process.
KIT-PUB-PROC-08Operational practiceModel, policy, and ruleset changes
Require advance notice, regression evidence, version retention, rollback, public explanation, and renewed approval for material changes.
KIT-PUB-PROC-09Technical recommendationAccuracy, validity, and differential impact
Demand evidence relevant to the actual population and decision, uncertainty intervals, false-positive and false-negative costs, language and disability testing, and limits on inference.
KIT-PUB-PROC-10Worldwide principleHuman review and contestability
Require a named human decision-maker, access to material evidence, contextual submission, appeal independence, deadlines, restoration, and downstream correction.
KIT-PUB-PROC-11Jurisdiction-specific legal questionGovernment-demand handling
Require authentication, jurisdiction review, scope narrowing, emergency validation, secrecy-order review, challenge rights, notice rules, and disclosure statistics.
KIT-PUB-PROC-12Technical recommendationSecurity, encryption, and administrator authority
Document encryption, key custody, privileged roles, recovery, logging, insider controls, breach testing, and whether the provider can read protected content.
KIT-PUB-PROC-13Operational practiceAccessibility and non-digital alternatives
Require equivalent access for disability, language, connectivity, documentation, and device constraints without converting accommodation into a risk signal.
KIT-PUB-PROC-14Jurisdiction-specific legal questionPublic records, audit logs, and archival custody
Define which records document official action, which data remain private, how corrections are preserved, when classification ends, and how provenance and fixity are tested.
KIT-PUB-PROC-15Operational practiceIndependent audit and public evidence
Secure code, configuration, evaluation, incident, appeal, deletion, and performance access for independent reviewers plus publication of non-sensitive findings.
KIT-PUB-PROC-16Operational practiceExit, portability, remedy, and secure destruction
Require open export, migration support, continuity, deletion after exit, audit survival, damages or service credits, and rights that continue through merger or subcontractor change.
Good intentions can still create cognitive surveillance.
KIT-PUB-FAIL-01Worldwide principleThe topic becomes the threat
A system treats a search about terrorism, protest, self-defense, religion, health, or government criticism as evidence about the person rather than evaluating conduct and context.
KIT-PUB-FAIL-02Technical recommendationAdministrative convenience becomes necessity
Full identity, bulk retention, or centralized access is adopted because it is easier to operate, not because less intrusive alternatives failed.
KIT-PUB-FAIL-03CognitiveLiberties.com policy proposalEmergency becomes ordinary
An exceptional access or monitoring power loses its trigger, time limit, deletion duty, review, or budget endpoint and migrates into routine use.
KIT-PUB-FAIL-04Operational practiceVendor secrecy replaces public accountability
A public body claims it cannot explain a decision because the model, score, data, or rules are proprietary.
KIT-PUB-FAIL-05Operational practiceHuman review becomes ceremonial
The reviewer sees only the machine result, cannot inspect evidence, lacks authority to reverse it, or is measured for agreeing quickly.
KIT-PUB-FAIL-06Technical recommendationDeletion removes the screen but not the inference
A visible record is erased while embeddings, labels, watch-list entries, training copies, and downstream consequences remain.
KIT-PUB-FAIL-07Jurisdiction-specific legal questionPublic records become a pretext for exposure or erasure
Transparency is used to publish private inquiry, or privacy and classification are used to conceal official action and destroy accountability.
KIT-PUB-FAIL-08Worldwide principleGovernment communication becomes unrecorded coercion
Officials use calls, meetings, threats, or procurement pressure to induce suppression while avoiding a reviewable order.
KIT-PUB-FAIL-09Technical recommendationAggregate reporting becomes re-identification
Small cells, rare categories, detailed geography, or repeated releases allow public statistics to expose individuals or protected communities.
KIT-PUB-FAIL-10Worldwide principleA national rule is presented as a universal norm
A constitution, emergency doctrine, speech rule, records duty, or security policy from one jurisdiction is silently applied worldwide.
Contain concrete harm without multiplying exposure.
KIT-PUB-IR-01Operational practiceStabilize concrete and immediate harm
Protect an identifiable person, stop an active fraud transaction, contain a system compromise, or preserve essential service while avoiding broader collection than the emergency requires.
EvidenceCL-03-02KIT-PUB-IR-02Worldwide principleClassify evidence, authority, and urgency
Record the observed facts, source reliability, legal authority, affected rights, time sensitivity, and what remains inference or allegation.
EvidenceCL-15-02KIT-PUB-IR-03Technical recommendationStop unnecessary collection and propagation
Disable new scoring, syncing, sharing, model feedback, training ingestion, and downstream alerts that are not required for containment.
EvidenceCL-10-01KIT-PUB-IR-04Operational practicePreserve the minimum accountable record
Keep enough evidence to review official action and remedy harm while excluding unrelated queries, associations, communications, and bystanders.
KIT-PUB-IR-05Operational practiceNotify responsible and independent authorities
Escalate to legal, privacy, security, records, accessibility, civil-rights, and independent-review owners according to the incident—not merely the system operator.
EvidenceCL-25-04KIT-PUB-IR-06Worldwide principleNotify affected people when lawful and safe
Give meaningful notice, the rule, evidence category, consequences, protection against retaliation, and a secure appeal route without repeating the exposure.
KIT-PUB-IR-07Operational practiceRequire independent human reconsideration
Review whether the trigger was accurate, the response was necessary and proportionate, the authority was valid, and less intrusive action was available.
KIT-PUB-IR-08Worldwide principleCorrect records and downstream decisions
Withdraw unsupported labels, reverse avoidable adverse action, restore service or standing, notify downstream recipients, and preserve a correction history.
EvidenceCL-07-04KIT-PUB-IR-09CognitiveLiberties.com policy proposalDelete data whose authority ended
Remove emergency copies, temporary access, raw data, derived inferences, model feedback, and investigative material not subject to a valid continuing obligation.
KIT-PUB-IR-10Operational practicePublish aggregate lessons and end the exceptional state
Report cause, scope, errors, remedy, and control changes without exposing protected inquiry, then document that emergency powers, elevated access, and special retention have ended.
Make safeguards operational rather than ceremonial.
KIT-PUB-REV-01Operational practiceMonthly high-impact decision review
Sample adverse automated decisions, emergency access, reverse searches, government-platform communications, and sensitive-data exceptions for evidence, proportionality, appeal, and deletion.
KIT-PUB-REV-02Technical recommendationQuarterly deletion and access review
Verify deletion jobs, backup expiry, privileged access, purpose separation, downstream correction, and closure of expired emergency authority.
KIT-PUB-REV-03Operational practiceQuarterly vendor and model-change review
Review subprocessors, policy changes, training use, evaluations, model drift, new inferences, accessibility, security, and contractual exceptions.
KIT-PUB-REV-04CognitiveLiberties.com policy proposalSemiannual rights and impact review
Test representative political, religious, health, rights-related, minority-language, accessibility, and anonymous-use scenarios without retaining person-level inquiry histories.
KIT-PUB-REV-05Operational practiceAnnual independent audit
Provide evidence to an independent body with authority to publish findings, order correction, and refer unlawful activity for appropriate review.
KIT-PUB-REV-06Operational practiceEvent-driven review after legal or technical change
Reassess the system after law, case, emergency, model, vendor, data source, breach, merger, or mission change rather than waiting for the calendar.
KIT-PUB-REV-07CognitiveLiberties.com policy proposalSunset and dismantling review
Before renewal, require evidence of efficacy, error cost, necessity, alternatives, remaining harm, deletion, and a tested plan to terminate the power or system.
A safeguard is incomplete when no one can reverse a mistake.
KIT-PUB-APP-01Worldwide principleVisible human appeal route
Provide a channel that does not require the affected person to surrender additional unrelated cognitive, biometric, political, religious, or health data.
KIT-PUB-APP-02Operational practiceMeaningful reason and evidence category
State the rule, decision owner, machine role, material facts, confidence or uncertainty, and the consequence being imposed.
KIT-PUB-APP-03CognitiveLiberties.com policy proposalPause avoidable harm
Where safety permits, prevent benefit termination, license loss, discipline, account restriction, enforcement escalation, or public labeling until timely human review occurs.
KIT-PUB-APP-04Jurisdiction-specific legal questionContext, counsel, and accessible participation
Allow relevant documents, explanation, representation, interpretation, disability accommodation, language access, and a non-digital route.
KIT-PUB-APP-05Worldwide principleIndependent reviewer with reversal power
The appeal must not be decided solely by the original model, vendor, analyst, requester, or programme owner.
KIT-PUB-APP-06Operational practiceDefined decision deadlines
Publish urgency tiers and maximum time to acknowledge, review, correct, restore, and notify downstream systems.
KIT-PUB-APP-07Worldwide principleCorrection and downstream remedy
Repair the authoritative record, benefits, license, employment status, watch-list entry, public statement, platform request, and every known downstream copy.
KIT-PUB-APP-08Technical recommendationDeletion of unsupported labels and features
Delete the invalid inference, score, embedding, feature, alert, training example, and future decision multiplier rather than merely closing the appeal ticket.
KIT-PUB-APP-09Jurisdiction-specific legal questionInstitutional and individual remedy
Provide restoration, explanation, policy correction, fee or penalty reversal, compensation where authorized, disciplinary accountability, and public aggregate learning proportionate to the harm.
Delete the cognitive trail when the authorized need ends.
KIT-PUB-DEL-01Operational practicePublish a record-by-record schedule
Name retention and deletion for prompts, searches, library activity, communications, location, biometrics, neural data, logs, scores, appeals, public records, legal holds, and backups.
KIT-PUB-DEL-02CognitiveLiberties.com policy proposalDelete routine cognitive exhaust quickly
Remove query content, prompt text, reading events, detailed clickstreams, and session context as soon as the authorized transaction and security need end.
KIT-PUB-DEL-03Jurisdiction-specific legal questionSeparate official records from private inquiry
Preserve accountable government decisions and orders without retaining unrelated intellectual activity merely because it passed through the same system.
KIT-PUB-DEL-04Technical recommendationExpire emergency copies automatically
Emergency access, elevated privileges, temporary replicas, exports, and special logs must have technical expiration plus post-event review.
KIT-PUB-DEL-05Technical recommendationDelete derived inferences with raw data
Removal includes risk labels, ideology or emotion estimates, relationship graphs, embeddings, vectors, model features, summaries, and cached outputs.
KIT-PUB-DEL-06Operational practicePropagate correction and deletion
Notify and verify deletion across vendors, subprocessors, partner agencies, shared databases, backups, models, and public-facing systems where legally possible.
KIT-PUB-DEL-07Jurisdiction-specific legal questionConstrain legal holds and classified retention
A hold or classification must identify authority, custodian, scope, review date, release criteria, access roles, and why less material cannot be retained.
KIT-PUB-DEL-08Technical recommendationVerify deletion rather than accepting attestation alone
Use deletion logs, sampled restoration tests, cryptographic erasure where appropriate, configuration evidence, and independent audit.
KIT-PUB-DEL-09Operational practicePreserve correction provenance without preserving the dossier
Keep a minimal record that an official judgment was corrected and when, while removing the unsupported cognitive profile and unnecessary sensitive evidence.
KIT-PUB-DEL-10Operational practiceTerminate data custody at programme or vendor exit
Export lawful public records, migrate necessary service data, then securely destroy unnecessary government, vendor, backup, and model copies under verified closure.
Measure systems, controls, response, and recovery—not what named people think.
No metric in this kit requires an identity-linked history of lawful questions, reading, research, beliefs, associations, or use of privacy tools.
KIT-PUB-OUT-01Operational practiceAuthority inventory coverage
Measure the percentage of high-impact systems, data demands, platform channels, emergency powers, and automated decisions with a named authority, owner, review path, and end condition.
Measurement boundary: Measure institutional documentation, not the beliefs, questions, or associations of individual people.
KIT-PUB-OUT-02Technical recommendationData minimization and separation
Measure eliminated fields, shortened retention, separated identities, purpose-bound stores, and privacy-preserving alternatives adopted.
Measurement boundary: Measure architecture and schemas rather than constructing a person-level history of lawful inquiry.
KIT-PUB-OUT-03Operational practiceHuman-review coverage
Measure the share of material adverse decisions receiving qualified human review before final consequence and the reviewer’s actual reversal authority.
Measurement boundary: Measure decision process, not whether a person’s lawful interests match an institutional norm.
KIT-PUB-OUT-04Operational practiceAppeal timeliness and correction
Measure acknowledgment, decision, restoration, downstream correction, and deletion time by decision category using privacy-protective aggregates.
Measurement boundary: Use aggregate case timing without publishing or profiling the underlying questions or beliefs.
KIT-PUB-OUT-05Technical recommendationDeletion assurance
Measure scheduled deletion completion, exception expiry, backup aging, derived-label removal, and independent verification.
Measurement boundary: Measure deletion jobs and exceptions rather than retaining cognitive data to prove deletion later.
KIT-PUB-OUT-06Operational practiceGovernment-platform transparency
Measure recorded communications, legal-basis completeness, response categories, rejected requests, appeal availability, and publication lag.
Measurement boundary: Report aggregate official action without exposing lawful speakers, readers, sources, or complainants.
KIT-PUB-OUT-07CognitiveLiberties.com policy proposalEmergency-power closure
Measure expiration, elevated-access removal, temporary-copy deletion, reauthorization evidence, and dismantling-test completion.
Measurement boundary: Measure whether exceptional machinery ended, not the private activity of the population subjected to it.
KIT-PUB-OUT-08Technical recommendationSynthetic false-positive performance
Use controlled synthetic scenarios to test sensitive topics, minority languages, disability, rights research, anonymous access, and context without enrolling real people into risk profiles.
Measurement boundary: Use synthetic or consented testing rather than longitudinal surveillance of ordinary service users.
KIT-PUB-OUT-09Operational practiceProcurement and vendor accountability
Measure contract coverage, subprocessor visibility, audit access, model-change notice, training restrictions, incident notification, export, remedy, and verified exit.
Measurement boundary: Measure contracts and vendor evidence, not personal thought histories.
KIT-PUB-OUT-10Operational practicePublic-record integrity and access
Measure fixity, provenance, correction linkage, declassification review, accessible formats, restoration, and independent archive custody.
Measurement boundary: Measure record-system integrity without exposing protected private inquiry or confidential sources.
KIT-PUB-OUT-11Operational practiceOversight independence and completion
Measure audit scope, evidence access, unresolved findings, corrective deadlines, whistleblower protection, and closure verified by an independent body.
Measurement boundary: Measure oversight power and remediation rather than scoring the ideology or trustworthiness of individuals.
KIT-PUB-OUT-12CognitiveLiberties.com policy proposalAnonymous and low-data access availability
Measure the share of public information and ordinary services available without full identity, plus accessibility and documentation alternatives.
Measurement boundary: Measure service design and access routes rather than tracking who chooses anonymity or why.
Ask these questions locally before claiming compliance.
The worldwide baseline is a rights and architecture framework. Binding duties vary across constitutions, human-rights systems, privacy, consumer, education, press, labor, accessibility, cybersecurity, records, procurement, contracts, and court procedure.
KIT-PUB-LAW-01Jurisdiction-specific legal questionWhat authority governs acquisition of cognitive data?
Identify constitutional, human-rights, privacy, communications, criminal-procedure, intelligence, library, biometric, neural, and administrative-law limits for each data type and demand.
KIT-PUB-LAW-02Jurisdiction-specific legal questionWhen is a warrant or independent order required?
Determine standards for content, metadata, location, search and prompt histories, reverse-keyword requests, geofences, biometrics, neural data, emergency access, and notice.
KIT-PUB-LAW-03Jurisdiction-specific legal questionWhat process governs automated adverse decisions?
Identify duties for explanation, human review, evidence disclosure, appeal, accessibility, discrimination, record correction, and judicial review in benefits, licensing, employment, education, border, policing, and security.
KIT-PUB-LAW-04Jurisdiction-specific legal questionWhat limits government-platform communication?
Distinguish lawful public speech, persuasion, notification, informal request, coercion, binding order, procurement pressure, licensing, and regulatory retaliation.
KIT-PUB-LAW-05Jurisdiction-specific legal questionWhat are the public-records and archival duties?
Resolve access, privacy, classification, national security, legal holds, retention, deletion, correction, provenance, declassification, and historical custody.
KIT-PUB-LAW-06Jurisdiction-specific legal questionWhat anonymity and identity protections apply?
Identify rights and limits for anonymous and pseudonymous speech, public information access, complaints, petitions, library use, age or eligibility verification, and services for people lacking documents.
KIT-PUB-LAW-07Jurisdiction-specific legal questionHow may emergency powers be triggered and ended?
Specify declaration, evidence, legislative and judicial control, geographic and subject scope, reporting, renewal, compensation, deletion, sunset, and termination.
KIT-PUB-LAW-08Jurisdiction-specific legal questionWhich speech and inquiry distinctions control?
Identify standards for incitement, true threats, harassment, fraud, defamation, operational secrecy, protected criticism, journalism, academic inquiry, religious thought, protest, rights advocacy, and receipt of information.
KIT-PUB-LAW-09Jurisdiction-specific legal questionWhat procurement and delegation limits survive outsourcing?
Determine public-law, records, audit, accessibility, civil-rights, data-protection, security, ownership, immunity, indemnity, subcontracting, and remedy duties that must bind vendors.
KIT-PUB-LAW-10Jurisdiction-specific legal questionWho can challenge, audit, and obtain remedy?
Identify standing, jurisdiction, ombuds, inspector, court, legislative, civil-society, journalist, whistleblower, union, class-action, and individual routes plus available corrective powers.
Research, standards, law, technical guidance, and site proposals remain distinguishable.
This kit translates supplied research, human-rights materials, selected court and oversight records, technical standards, and CognitiveLiberties.com policy into a worldwide implementation programme. It does not declare one jurisdiction’s law universal, certify legal compliance, authorize surveillance, or substitute for local constitutional, criminal-procedure, public-records, procurement, accessibility, labor, education, benefits, national-security, and emergency-law review.
Section-level evidence units
Selected source records
Current law, vendor behavior, system configuration, and local risk must be independently rechecked before deployment. The exact 64-report archive remains preserved separately from this implementation derivative.