Minimize data first; transfer only with a lawful, documented route · Universal Apex Protected L-9.0 · 2026-07-23

Data Transfer, Residency and Localization Gate

Reference default. The standalone is designed for browser-local operation and does not require submission of personal, privileged, customer, worker, health, biometric, financial, export-controlled or security-sensitive data.

Before any collection or transfer

  1. Identify data elements, people, purposes, necessity, source and expected outputs.
  2. Determine controller, processor, joint-controller, service-provider and other legal roles.
  3. Map collection, access, storage, inference, onward transfer, backup, support and deletion locations.
  4. Select and document lawful authority, notices, consent where required and individual-rights procedures.
  5. Apply minimization, pseudonymization, access control, encryption, retention and deletion.
  6. Assess localization, transfer mechanism, supplementary safeguards and government-access risk.
  7. Review vendor terms, subprocessors, model training/feedback use and output rights.
  8. Complete applicable PIA/DPIA/AIA and professional sign-off before production.

Data classes blocked from the public reference edition

Sensitive personal data, privileged materials, credentials, private keys, customer secrets, export-controlled technical data, children’s data, health or biometric data, production security telemetry and any data whose disclosure would create legal or safety harm.

No notice by fiction. A generic privacy page does not replace the deploying operator’s real notice, data map, contracts, rights process, retention schedule, transfer analysis or incident plan.