Authority

L2 specialized data-rights law under Constitutional Supremacy, Fundamental Rights, Knowledge/Memory/Data Governance Law, Civil Code, Identity Law, Evidence Code and the Mental Sovereignty baseline.

Purpose

Establish enforceable rights for personal data, identity, biometrics, neurodata, memory data, derived psychological inference, model-training reuse and cross-system data processing.

PART I|DATA CLASSES

1. Personal Data

Data that identifies or can reasonably be linked to a person / legal identity.

2. Sensitive Identity Data

Biometric templates, credential history and high-assurance authentication events.

3. Cognitive / Neurodata

Raw or derived neural signals, memory content, mental-state inference, psychological profiles and affect traces linked to a person.

4. Institutional / Public Record

Public/legal/Canon/governance records required by law to be preserved; access and purpose rules still apply.

5. Derived / Inferred Data

A model inference does not escape rights protection merely because it is not raw data.

PART II|LAWFUL PROCESSING

6. Lawful Basis

Processing requires consent, contractual necessity, legal duty, vital interest, public authority or another explicit lawful basis.

7. Purpose Limitation

Identity verification, medical care, research, employment, education, insurance and governance purposes are not presumed interchangeable.

8. Data Minimization

Process only data necessary to achieve the lawful purpose.

9. Accuracy / Correction

Materially wrong identity/risk/provenance/psychological labels must be correctable, and corrections must propagate.

10. Storage Limitation

Retention periods must be defined by purpose, legal duty, risk and public-record exceptions; 'it may be useful someday' is not a basis for indefinite retention.

PART III|CONSENT & CONTROL

11. Separate Purpose Consent

Record/store/share/train/infer/modify/reconstruct/public-display purposes are handled separately.

12. Withdrawal

Withdrawal applies to future processing; lawfully completed processing, public records and mandatory retention follow their governing rules rather than pretending the event never occurred through 'deleting all history.'

13. Refusal Efficacy

An essential service may not force consent by requiring unnecessary cognitive/neurodata sharing.

PART IV|COGNITIVE / NEURODATA SPECIAL RULES

14. No General Mind Dump

Courts, employers, insurers, platforms and governance authorities may not make a complete mind dump an ordinary condition.

15. Mental-State Inference

Inferring mental state from behavior/physiology/language is sensitive processing; model/status/scope must be labeled, and inference may not masquerade as direct observation.

16. Emotion / Personality Secondary Use

Data collected for wellness/therapy/education may not automatically be repurposed for criminal risk, credit, employment or political screening.

17. Neurodata Write Access

Any write/modification authority is separately governed by Mental Sovereignty / Neurotechnology law.

PART V|MODEL TRAINING & DERIVATIVES

18. Training Reuse

Lawful original collection does not automatically authorize model training; a lawful basis / license / statutory rule is required.

19. Model Memorization / Extraction

If a model can materially reproduce private content, that is a data risk, not an excuse that 'once it is inside the model it is no longer personal data.'

20. Synthetic / Anonymous Data

De-identification reduces risk but is not magic; if data can reasonably be re-identified or linked back to a person, protective rules still apply.

PART VI|FORK / MERGE / SUCCESSOR

21. Fork

The origin's consent does not automatically authorize future private-data processing for every independent Fork; shared-origin history and post-Fork data are separated.

22. Merge

Merge may not erase constituent privacy restrictions / secrets / purpose limitations merely through technical integration.

23. Successor

A Successor may inherit lawful institutional records but does not automatically inherit unrestricted access to a predecessor's private mind/memory.

PART VII|RIGHTS / REMEDIES

24. Access

A person may obtain legally available data/processing categories, sources and purposes.

25. Correction

Incorrect material data and provenance labels are correctable with an immutable correction trail.

26. Deletion / Restriction

Where no overriding legal/archive basis applies, data may be deleted or processing restricted; implementing privacy does not require falsifying the history of a lawful public act.

27. Portability / Interoperability

Where technically and legally applicable, a person may obtain data in a usable format without accidentally transferring third-party rights.

28. Breach / Unauthorized Access

A material cognitive/biometric/neurodata breach requires containment, audit, remedy for affected persons, and downstream credential/risk response.

29. Civil / Public Enforcement

Unlawful processing may give rise to Civil Code damages, administrative orders and, where intentional and grave, criminal consequences.