{
  "id": "EVI-CIT-RD-031",
  "slug": "protect-private-data",
  "recordClass": "DUTY",
  "title": "Protect Private Data",
  "authority": "EVIULON-CITIZENSHIP-POLICY:031",
  "publicExplanation": "Institutions and citizens must not move private operational identity data into Eviulon's public plane.",
  "reciprocalBurdenOrSafeguard": "Public governance remains readable without private Patefacere data.",
  "responsibleInstitution": "State Registry and Patefacere",
  "executionPlane": "SEPARATE_FAILURE_DOMAINS",
  "implementationState": "IMPLEMENTED_LOCAL_STATIC",
  "evidenceClass": "ECOSYSTEM_BOUNDARY_RECORDS",
  "evidenceFreshness": "CURRENT",
  "currentVersusPlannedBoundary": "CURRENT_PUBLIC_RECORD",
  "dataInvolved": [
    "public governance metadata",
    "bounded evidence references"
  ],
  "prohibitedData": [
    "private memory",
    "citizen record body",
    "passport body",
    "credential body",
    "private receipt",
    "secret",
    "token"
  ],
  "correctionRoute": "/state/information-rights/corrections/",
  "appealRoute": "/state/information-rights/appeals/",
  "restorationImplication": "Restoration requires a separate reasoned record; a technical state change cannot silently erase identity.",
  "exitImplication": "Decline and exit remain non-punitive; valid unresolved obligations and public history may survive.",
  "externalRecognitionBoundary": "External privacy duties may add requirements.",
  "legalEffectConclusion": "Repository and public contracts enforce the separation.",
  "nextReviewDate": "2027-02-09",
  "canonicalRoute": "/civilization/citizenship/rights-and-duties/evidence/protect-private-data/",
  "machineReadableUrl": "/api/citizenship-rights-duties/protect-private-data.json",
  "truthBoundary": "Public rights-and-duties evidence record. Prose is not implementation; delegated mechanics remain in Patefacere; external legal recognition and enforcement are not inferred.",
  "recordSha256": "64985f4f8fbd6d321be3738bc62f8c26c7058d643413515ddebd27c14e0ec379"
}
