- Purpose limitation
- Data is processed for the purposes of disaster response, emergency care coordination and the accountability obligations arising from them. It is not repurposed for unrelated ends.
- Data ownership
- Deploying organisations retain ownership of their operational data. Data ownership concerns are named explicitly in the programme's own barrier analysis, and the answer is clear policy, robust security and ledger-based transparency rather than assertion.
- Separation of record and proof
- Personal, clinical and household data lives in governed storage. The distributed ledger holds integrity hashes, consent transitions and access anchors only. No personal data is written to the ledger.
- Residency and retention
- Data residency is configured per jurisdiction. Retention schedules are enforced by the system rather than left to operational memory.
- Access
- Role-based access control scoped by geography and incident, with least-privilege defaults, rapid revocation for surge staff, and attributable audit of every access.
- Research access
- Anonymised and aggregated data may be made available for epidemiological study and public health surveillance under governed access with ethical review requirements, respecting the consent basis under which it was collected.