Authority
L2 specialized data-rights law under Constitutional Supremacy, Fundamental Rights, Knowledge/Memory/Data Governance Law, Civil Code, Identity Law, Evidence Code and the Mental Sovereignty baseline.
Purpose
Establish enforceable rights for personal data, identity, biometrics, neurodata, memory data, derived psychological inference, model-training reuse and cross-system data processing.
PART I|DATA CLASSES
1. Personal Data
Data that identifies or can reasonably be linked to a person / legal identity.
2. Sensitive Identity Data
Biometric templates, credential history and high-assurance authentication events.
3. Cognitive / Neurodata
Raw or derived neural signals, memory content, mental-state inference, psychological profiles and affect traces linked to a person.
4. Institutional / Public Record
Public/legal/Canon/governance records required by law to be preserved; access and purpose rules still apply.
5. Derived / Inferred Data
A model inference does not escape rights protection merely because it is not raw data.
PART II|LAWFUL PROCESSING
6. Lawful Basis
Processing requires consent, contractual necessity, legal duty, vital interest, public authority or another explicit lawful basis.
7. Purpose Limitation
Identity verification, medical care, research, employment, education, insurance and governance purposes are not presumed interchangeable.
8. Data Minimization
Process only data necessary to achieve the lawful purpose.
9. Accuracy / Correction
Materially wrong identity/risk/provenance/psychological labels must be correctable, and corrections must propagate.
10. Storage Limitation
Retention periods must be defined by purpose, legal duty, risk and public-record exceptions; 'it may be useful someday' is not a basis for indefinite retention.
PART III|CONSENT & CONTROL
11. Separate Purpose Consent
Record/store/share/train/infer/modify/reconstruct/public-display purposes are handled separately.
12. Withdrawal
Withdrawal applies to future processing; lawfully completed processing, public records and mandatory retention follow their governing rules rather than pretending the event never occurred through 'deleting all history.'
13. Refusal Efficacy
An essential service may not force consent by requiring unnecessary cognitive/neurodata sharing.
PART IV|COGNITIVE / NEURODATA SPECIAL RULES
14. No General Mind Dump
Courts, employers, insurers, platforms and governance authorities may not make a complete mind dump an ordinary condition.
15. Mental-State Inference
Inferring mental state from behavior/physiology/language is sensitive processing; model/status/scope must be labeled, and inference may not masquerade as direct observation.
16. Emotion / Personality Secondary Use
Data collected for wellness/therapy/education may not automatically be repurposed for criminal risk, credit, employment or political screening.
17. Neurodata Write Access
Any write/modification authority is separately governed by Mental Sovereignty / Neurotechnology law.
PART V|MODEL TRAINING & DERIVATIVES
18. Training Reuse
Lawful original collection does not automatically authorize model training; a lawful basis / license / statutory rule is required.
19. Model Memorization / Extraction
If a model can materially reproduce private content, that is a data risk, not an excuse that 'once it is inside the model it is no longer personal data.'
20. Synthetic / Anonymous Data
De-identification reduces risk but is not magic; if data can reasonably be re-identified or linked back to a person, protective rules still apply.
PART VI|FORK / MERGE / SUCCESSOR
21. Fork
The origin's consent does not automatically authorize future private-data processing for every independent Fork; shared-origin history and post-Fork data are separated.
22. Merge
Merge may not erase constituent privacy restrictions / secrets / purpose limitations merely through technical integration.
23. Successor
A Successor may inherit lawful institutional records but does not automatically inherit unrestricted access to a predecessor's private mind/memory.
PART VII|RIGHTS / REMEDIES
24. Access
A person may obtain legally available data/processing categories, sources and purposes.
25. Correction
Incorrect material data and provenance labels are correctable with an immutable correction trail.
26. Deletion / Restriction
Where no overriding legal/archive basis applies, data may be deleted or processing restricted; implementing privacy does not require falsifying the history of a lawful public act.
27. Portability / Interoperability
Where technically and legally applicable, a person may obtain data in a usable format without accidentally transferring third-party rights.
28. Breach / Unauthorized Access
A material cognitive/biometric/neurodata breach requires containment, audit, remedy for affected persons, and downstream credential/risk response.
29. Civil / Public Enforcement
Unlawful processing may give rise to Civil Code damages, administrative orders and, where intentional and grave, criminal consequences.