E2 · Publication Volume 24

Sensitive and Licensed Data

access, licence, privacy and commercial constraints

Learning objectives

  • Explain why access, licence, privacy and commercial constraints require explicit semantic modelling.
  • Design identities, relations and constraints that preserve sensitive and licensed data across exchange.
  • Separate hard release gates from diagnostic metrics and interpretation choices.
  • Produce a policy-aware data package with classification, licence propagation and audited release from synthetic evidence.

The lesson is complete only when the learner can defend both the model and the release decision. A neat schema without evidence, tests or declared limitations is an unverified design. The assessed artefact must make assumptions visible and distinguish source assertions from derived conclusions.

Decision context

Classify data by content, context, jurisdictional obligations, agreements and decision consequence. Separate discovery metadata from protected content. Evaluate requested action, purpose, recipient role, location, time and licence terms. This tutorial supplies a design method, not legal advice; applicable obligations require qualified review.

Start with a decision record: name the intended use, the evidence required, the consequence of error, the accepted uncertainty and the role authorised to accept residual risk. Then ask whether the proposed model can answer the decision question without relying on filename conventions, row order, undocumented defaults or someone’s memory. This prevents technology selection from concealing a missing semantic requirement.

The same record may be fit for one use and unfit for another. A rapid exploratory view can tolerate conditions that a released exchange package cannot. Fitness is therefore stated against a use, contract version and quality gate rather than attached permanently to the data.

Core concept

Data sensitivity and licence conditions are properties of governed use, not excuses to erase provenance. A dataset may be discoverable but access-restricted, usable for one purpose but not another, or shareable only after spatial, personal or contractual risk is reduced. These constraints need explicit, versioned policy metadata.

The working scope is access, licence, privacy and commercial constraints. For each item in that scope, distinguish the thing itself, the label used by a source, the claim made about it and the record that carries the claim. Identity is not a display name; a value is not its unit; an observation is not a model; current is not the same as valid. These distinctions create explicit places for correction, uncertainty and competing interpretations.

A good semantic design can be explained as a set of sentences before it is encoded. Each sentence identifies a subject, a property or relationship, an object or result, and the context under which the claim holds. Physical tables and files are then projections of those sentences, not their source of meaning.

Semantic model

Attach a classification, policy identifier, lawful or contractual basis where applicable, permitted purposes, prohibited actions, duties, review date, retention state and responsible role to the dataset or finer-grained resource. Access decisions create auditable events without exposing protected content in the audit record.

Test every proposed record against seven questions: What has identity? What type is it? Which property or relationship is asserted? Which spatial and temporal context applies? Which state or qualifier modifies the assertion? Which evidence supports it? Which version and activity produced the stored representation? Missing answers become explicit contract gaps.

Normalisation is used to separate independent facts, not to maximise the number of tables. A compact nested object can be semantically sound if the same identities, constraints and provenance remain explicit. Conversely, a highly normalised database can still be ambiguous when relationships and units exist only in documentation or application code.

Constraints and invariants

| Invariant | Executable or review test | | --- | --- | | Classification has scope and reason | Avoid unqualified labels that apply forever to an entire repository. | | Least necessary access | Grant only the data, actions and duration needed for the approved purpose. | | Licence travels with derivatives | Record which terms continue, change or prohibit redistribution. | | Redaction is a derivation | Preserve method, source link, residual-risk review and released fingerprint. |

An invariant is a condition that must remain true across storage, export, correction and reprocessing. Implement it as close to the authoritative boundary as practical and repeat the check at exchange boundaries. Record rule identifier, version, severity, evaluated scope, observed value and outcome so a failure can be reproduced.

Hard gates protect identity, semantic validity, required provenance and authorised use. Diagnostic checks reveal unusual values or patterns but require interpretation. Never convert a diagnostic threshold into deletion or correction without a reviewed rule and preserved source evidence.

Quantitative reasoning

Measure decision coverage, overdue reviews, policy-resolution failures and denied requests by reason. For a released derivative, report a residual-risk assessment and utility tests rather than one universal anonymity score. Access success rate alone is unsafe because unrestricted access can increase the number while violating policy.

Every reported ratio states its numerator, denominator, exclusions and evaluation time. Stratify results by source, entity type, contract version or processing run where aggregation could hide a local failure. Counts accompany percentages so a seemingly large change based on a tiny denominator remains visible.

Precision is part of meaning. Do not add decimal places merely because a storage type permits them, and do not round identity, interval or coordinate fields without a declared tolerance and test. Quantitative summaries support a release decision; they do not replace semantic review.

Evidence and uncertainty

Evidence includes the applicable agreement or policy version, classification rationale, approval, requested purpose, enforcement result and release checks. Record uncertainty when licence inheritance or re-identification risk is unresolved and stop release until an authorised decision is made.

Build an evidence packet containing preserved source reference, acquisition or assertion context, applicable method, validation results, reviewer decision and links to derivatives. Classify uncertainty as observational, semantic, structural, parametric or policy-related where that distinction changes treatment. “Unknown” is a valid state when the evidence cannot justify a stronger claim.

Contradictory evidence remains available. The model may select one current assertion, but the reason, competing assertion and effective time are retained. This makes later reinterpretation possible without pretending the earlier evidence never existed.

Interfaces and storage

Return policy-aware responses: authorised content, redacted derivative, metadata-only record or structured denial. Do not reveal sensitive field names, geometry or row counts through error messages. Export manifests include policy and licence identifiers, permitted purpose, expiry and obligations without embedding confidential text unnecessarily.

Design an interface from the logical contract outward. Specify identifiers, types, cardinalities, units, value states, coordinate and time references, version negotiation, validation behaviour and structured errors before choosing a serialisation. The physical representation then declares its mapping to those logical elements.

Storage optimisation may partition, compress, index or cache data, but it must not change identity or silently remove context. A derived representation points to immutable inputs and a processing manifest. A cache carries freshness and contract-version information and is never treated as the only evidence copy.

Governance and access

Separate policy authorship, access approval, technical enforcement and audit review roles. Re-evaluate classification when purpose, content, agreement or risk changes. Emergency access has explicit scope, expiry and retrospective review. Deletion or retention actions preserve an audit event without retaining prohibited content.

Governance is expressed through named roles, review states and versioned decisions, not through references to a particular organisation. Define who may propose, validate, approve, supersede and withdraw each governed resource. The audit trail records the role and event while avoiding unnecessary personal data.

Apply least-necessary access to source evidence and derivatives. Access controls must not erase identifiers, lineage or quality metadata needed to understand an authorised release. When policy is unresolved, quarantine the output with a precise reason and escalation route.

Integration checkpoint

Classification and policy govern access, derivation and release
Classification and policy govern access, derivation and release

The diagram summarises the control flow for this lesson. Read it from source evidence through semantic structure and validation to a decision-ready artefact. Each arrow should correspond to a declared relationship or transformation; each boundary should have a contract; each released node should have an identity, version and provenance pointer.

Integrate the lesson by adding a policy-aware data package with classification, licence propagation and audited release to the evolving synthetic data package. Verify that earlier artefacts still resolve and that the new model does not overwrite observations, identifiers, values or versions introduced in previous lessons. Record every changed assumption.

Synthetic worked example

A synthetic dataset combines precise sample locations with contact notes and third-party reference data. The learner separates discovery metadata, classifies the three content groups, creates a generalised spatial derivative, removes direct personal fields, records licence propagation and issues a purpose-limited release after residual-risk review.

Work the example in four passes:

  1. Preserve the received records and write the intended decision without correcting anything.
  2. Identify entities, claims, context, uncertainties and policy constraints; mark every unresolved item.
  3. Apply the versioned rules, create derivatives and record the exact transformation plus validation evidence.
  4. Issue an accept, reject or quarantine decision and show how an independent reviewer can reproduce it.

Because the example is entirely synthetic, its values demonstrate method only. The important result is the chain from received evidence to justified decision. If a required fact is absent, the worked solution records the gap rather than manufacturing a plausible value.

Practice task

Create a policy matrix for a synthetic dataset with public, restricted and highly sensitive fields. Define roles, purposes, actions, expiry, redaction and denial behaviour. Produce one metadata-only record and one redacted derivative, then test that logs and errors do not leak protected content.

Use the following acceptance criteria:

  • All required identifiers and references resolve to declared types.
  • Every transformation preserves the received evidence and records its derivation.
  • Invalid, unknown and inapplicable states remain distinct and machine-testable.
  • The output identifies the contract, vocabulary and processing versions used.
  • A second reader can reproduce the validation result without private knowledge.

Submit the source snapshot, authored contract or model, validation output, derivative, manifest and a short decision record. A screenshot alone is insufficient because it cannot demonstrate the exact input, version or rule execution.

Common failure modes

  • A repository-wide confidential label has no scope or review date.
  • Sensitive content appears in logs or validation errors.
  • A derived export loses the source licence and purpose constraint.
  • Redaction is performed without provenance or residual-risk review.

These failures share a pattern: convenient representation is mistaken for verified meaning. Diagnose the earliest boundary at which an assumption became implicit. Correct by restoring source evidence, making the assumption a versioned field or rule, rerunning dependent transformations and superseding—not overwriting—the affected release.

Do not repair a failure by adding an undocumented default. A blocked result with a specific missing dependency is safer and more reusable than a complete-looking result whose meaning cannot be reconstructed.

Review questions

  1. How can metadata remain discoverable while content is restricted?
  2. Which context belongs in an access decision?
  3. Why is redaction a provenance-bearing derivation?
  4. When should unresolved licence risk stop release?

For each answer, identify the governing invariant, the evidence needed to evaluate it and the appropriate release behaviour when the invariant fails. A strong answer distinguishes scientific uncertainty from missing semantics and distinguishes a recoverable warning from a hard contract violation.

Sources and further reading