Skip to content

Confidentiality

Version
v4 · 2026-08-30 · History
Prime #
1337
Origin domain
Law & Governance
Subdomain
information duties → Law & Governance
Aliases
Duty of Confidentiality, Nondisclosure Duty, Entrusted Information Protection
Related primes
Constraint

Core Idea

Confidentiality is a governed information relation in which an authorized holder may access protected information but is constrained in how it may use or disclose it. The obligation has a named subject or source, delimited protected content, a set of permitted purposes, a set of permitted recipients, release conditions, enumerated exceptions, and consequences attaching to the holder when the scope is exceeded. [1]

Four commitments are constitutive, and dropping any one dissolves the relation into something else. The content is designated protected relative to an identified subject rather than being merely obscure. The holder's access is legitimate, obtained by grant rather than by breach. A rule restricts downstream use and disclosure, not acquisition. And the restriction persists across transfer, binding the next holder until release, expiry, or an authorized exception discharges it. Confidentiality therefore binds use after access, the single sentence from which every other property of the prime follows. [2]

The operational consequence is a population identity. Because the duty attaches at legitimate receipt, the set of parties capable of breaching it is exactly the set entitled to hold it. No perimeter can be drawn around the failure, because the perimeter already contains everyone who could cause it. Everything upstream of receipt — who may be told, on what showing, through which channel — is a different question with different machinery, and confounding the two is the characteristic error the prime exists to prevent.

Structural Signature

Designated protected content + a holder with legitimate access + a bounded scope of permitted purposes and recipients + an enumerated release-and-exception set → any use or onward disclosure outside that scope is a breach attributable to the holder, and the scope travels with the content through transfer.

The signature is a relation among four terms, never a property of content alone. Sensitivity is not intrinsic: the same laboratory value is protected in a chart, unprotected in an aggregate incidence table, and protected again once rejoined to a person. An analysis supplying fewer than four terms has not identified the prime. [3]

Recurring features:

  • Designation relative to a subject. Content is protected because of whose it is or where it came from, not because it is hard to obtain. Widely known information can carry a duty; obscure information can carry none.
  • Legitimate acquisition by the constrained party. The holder was told, shown, or given the information under an entitlement. A party who took it is governed by other machinery entirely.
  • A scope with at least two axes. Permitted purposes and permitted recipients are specified independently, so disclosure to an approved recipient for an unapproved purpose is as much a breach as the reverse. Mature scopes add a third axis for form: identified, pseudonymous, aggregate, derived.
  • An enumerated exception and release set. Consent, compulsion, necessity, overriding duty, expiry, and defined declassification belong to the duty rather than defeating it. A duty with no stated exceptions has an implicit and unexamined one.
  • Persistence through transfer. When content moves within scope, the scope moves with it and the recipient becomes a holder on the same terms — what distinguishes a durable obligation from a one-time restraint on a single act.
  • Breach as an attributable act, not an outcome. The violation is the out-of-scope use, complete on performance. Harm may aggravate the consequence but is not an element of it, which is why a disclosure revealing nothing the recipient did not already know remains a breach. [4]
  • Substrate-neutral enforcement. The rule may be normative, professional, statutory, contractual, or mechanical; only remedy and detection latency change.

What It Is Not

The prime does not claim that protected information is unknown, rare, or hard to reach. A duty can attach to a fact thousands of people know and anyone could look up, because designation runs through the relation to the subject rather than through the scarcity of the content. The frequent objection that a disclosure was harmless because the information already circulated misidentifies what is protected: the constraint is on this holder's use, not on the world's ignorance. [3]

It does not claim the holder is suspect. The relation presupposes a party trusted enough to be given the information, and the duty is the price of that trust rather than a hedge against its absence. Reading the obligation as an accusation inverts its logic and reliably produces the wrong remedy — tighter gates in front of people already inside.

It does not claim the restriction is absolute. A duty that cannot be discharged by consent, cannot yield to compulsion, and cannot expire is not stronger but merely unspecified. The prime says nothing about which exceptions a regime should contain, only that a regime with none has left them implicit.

It does not settle ownership. The subject need not own the information, and the holder may own the medium, the record, and the derived analysis while remaining bound. Nor does it assign a winner between disclosure and restraint; it supplies no criterion for distinguishing a defensible confidence from a self-serving one.

Finally, it does not assert that enforcement exists. An entirely unenforced duty — no auditor, no remedy, no realistic prospect of detection — is still a confidentiality relation. The prime is a classification, not a guarantee.

Broad Use

The relation appears wherever a party must be told something to do useful work with it and must then be prevented from doing everything else with it. Clinical medicine binds the treating team to care and to defined public-health reporting; professional privilege binds counsel to representation and carves out crime-fraud; research governance binds investigators to an approved protocol and to a population that consented to that protocol and not the next one. Diplomatic practice attaches handling caveats that travel with a cable, so a recipient cleared to read it is still not cleared to repeat it. Commerce runs the relation through non-disclosure instruments, trade-secret doctrine, and staged data rooms whose tranches widen the permitted purpose. Financial institutions install barriers so an advisory team's knowledge cannot reach a trading desk otherwise entitled to it. Journalism inverts the direction, binding the publisher to the source. [1]

Engineered systems reproduce the shape without borrowing the vocabulary. Purpose limitation in data-protection regimes is a scope on use against an authorized processor. Capability tokens carry a scope string constraining what the bearer may do with what it may already read. Taint-tracking and information-flow type systems propagate a label from an input to every derived value, so the constraint follows the data rather than sitting at a gate. Contractual flow-down to subprocessors is the same persistence property in commercial language. What varies is the exception set and the remedy; the four roles are the invariant, and an analyst who can locate them moves between a hospital, a bank, and a service mesh without re-learning the problem. [5]

Clarity

The confusion the prime dissolves is the conflation of two failures that produce identical symptoms. Information turns up where it should not. Either someone without entitlement obtained it — a stolen credential, a misconfigured bucket, an unlocked cabinet — or someone with entitlement passed it on: a clinician mentioning a case at dinner, a vendor repurposing a dataset, an official briefing a friendly journalist. The observable is the same; the two have almost nothing in common underneath. [2]

Naming the second one confidentiality forces the split, and the split is worth a great deal, because the remedies do not overlap. Stronger gates, better keys, tighter segmentation, and more aggressive authentication address the first failure and are simply irrelevant to the second — every one of them assumes the violator is outside, and in the second case the violator was issued the key legitimately. What addresses the second failure is scope specification, purpose binding, per-holder attribution, flow-down obligations, and structural removal of the holder from the flow. Organizations that miss the distinction answer incidents of the second kind with controls for the first, and remain puzzled by the lack of improvement.

A commoner muddle also dissolves: the belief that a technical control discharges the duty. Encryption determines who can read and says nothing about what a party who is supposed to read may then do. A system can be flawlessly encrypted and have no confidentiality properties at all, because every constraint it enforces sits upstream of where the duty begins.

Manages Complexity

What the abstraction lets an analyst stop tracking is the transmission surface. Without it, protecting information means enumerating channels — mail, speech, screenshot, export, print, quotation, paraphrase, inference from an aggregate — and the enumeration is unbounded and always one novelty behind. Modelling the flow as a confidentiality relation replaces that open list with a closed object of four terms and a small exception set, against which any channel is tested by asking whether this use, to this recipient, for this purpose, falls inside the scope. The channel stops being a thing to inventory and becomes a thing to evaluate. [2]

Three further reductions follow. The holder's intentions drop out: because breach is constituted by the out-of-scope act rather than by motive, classification need not distinguish malice from carelessness, and can defer motive to the remedy stage where it belongs. Copy count drops out: the duty runs on the content and its scope, not on any instance, so a dataset replicated across forty systems presents one obligation rather than forty. And hop-by-hop rederivation drops out: because the scope travels, a downstream analyst inherits an answer rather than re-opening the question at every transfer, which is what makes long custody chains tractable at all.

Abstract Reasoning

The prime licenses a classification procedure executed in order, each step able to terminate the analysis with a different verdict.

First, name the four terms. If a subject, a protected body of content, a holder, and a scope cannot all be identified, the relation is absent and the analysis should be redirected.

Second, test the legitimacy of the holder's access. If the party obtained the information without entitlement, the case belongs to access control, and a confidentiality framing will produce useless recommendations.

Third, test whether a scope actually binds. If the holder may do whatever it likes with what it holds, no duty exists however sensitive the content feels. Sensitivity is not a scope.

Fourth, test persistence. Ask what governs the recipient after an in-scope disclosure. If the recipient is free, what was observed was a one-time restraint, which decides whether flow-down obligations are the right instrument.

Fifth, enumerate the exceptions in advance. An exception set assembled after an incident is a rationalization; the diagnostic value comes from writing the release, consent, compulsion, necessity, and expiry conditions while the duty is created.

The procedure supports a decisive counterfactual. Ask whether a use that caused no harm, reached no new recipient, and revealed nothing the recipient did not already know would still count as a violation. If yes, the constraint is genuinely on use. If no, the concern was harm or exposure and something else is doing the work. The test cleanly excludes a common near-miss: public data protected only against alteration has an integrity requirement, not a confidentiality requirement, because there is no scope on use to exceed. [6]

Knowledge Transfer

What moves intact between substrates is the four-term skeleton, the location of breach inside the authorized population, the persistence of scope through transfer, and the treatment of exceptions as part of the duty. An engineer who has implemented purpose-scoped tokens and a clinician trained in professional privilege are reasoning about the same object, and either can read the other's incident reports without translation. The diagnostic partition between an access failure and a use failure transfers with equal reliability, and is usually the first thing worth carrying into a new domain. [5]

What does not transfer is nearly everything with content in it. The exception set is domain-specific and frequently the whole substance of a dispute: mandatory reporting duties that override clinical confidence have no analogue in a non-disclosure instrument, and the crime-fraud exception has no analogue in either. Remedies range from professional sanction to statutory penalty to contractual damages to nothing at all. Duration does not transfer; trade-secret duties can be perpetual while embargoes run for hours. The identification of the subject does not transfer, and is contested precisely where transfer is most tempting — in a system holding derived artifacts, whose subject is a live question rather than a given. Nor does the default: some regimes bind by presumption and release by exception, others require the scope to be asserted at disclosure or it does not exist. Importing an intuition about defaults across that line is the most reliable way to get a transfer wrong while believing it succeeded.

Examples

Formal/abstract

Model the duty in an information-flow calculus, which forces every clause of the signature to become explicit. Label the protected input with a marker naming its subject, and let the marker propagate to every value computed from it, so a hash, a bucketed aggregate, a model gradient, and a printed string all inherit it. Attach to each output channel a set of permitted recipients and a purpose tag. The security condition is then a property of the whole execution trace rather than of any single operation: no observation available at a channel outside the permitted set may vary with the protected input, unless the value passed through a declassifier corresponding to an enumerated exception. [7]

Two features repay attention. Reads are unconstrained — the calculus never asks whether the program may load the protected value, because by hypothesis it may; the whole burden sits on what becomes observable afterwards. And breach is not an event: there is no instruction in the trace one can point to and call the violation, because the property relates two hypothetical executions differing only in the protected input. This is exactly why an access log — a record of who read what, when — cannot detect a confidentiality failure. Every read in the log was authorized. The log is a complete record of the wrong thing. [8]

Mapped back: the label is designation relative to a subject; unconstrained reads are legitimate access; the recipient set and purpose tag are the two scope axes; label propagation through derivation is persistence through transfer; and the declassifier is the exception set made explicit as a named operation rather than left to judgment. The trace-property character of the condition is the formal shadow of breach-as-act, and it explains why detection must be built into the flow in advance, since nothing in the aftermath distinguishes a compliant execution from a violating one by inspection.

Applied/industry

A hospital system engages an analytics vendor to reduce readmissions, granting a full extract of the clinical record under an agreement naming quality improvement as the permitted purpose. Eighteen months later the vendor proposes to train a general risk model on the accumulated corpus and license it to other health systems. No credential was misused, no system was breached, no record was seen by anyone not entitled to see it, and every audit log is clean. [9]

Run the procedure. The subject is the patient population; the content is the extract; the holder is the vendor; the scope names quality improvement for this system's patients, which does not cover a commercial product for third parties. The proposed use therefore exits the purpose axis immediately and the recipient axis at licensing. The exception set is where the argument actually happens: the vendor will invoke a research carve-out or a de-identification safe harbour, and whether either applies is a question about enumerated conditions, not about good faith. Persistence decides the downstream half — whether licensees inherit the scope depends on whether flow-down was written at the outset. [10]

The genuinely hard part is the derived artifact. Trained weights are not the extract, contain no retrievable record in the ordinary sense, and yet were computed from protected content and can under some conditions be induced to reveal it. Whether the duty travels into the weights is a live structural question posed by the persistence clause: if scope follows content through transformation, the boundary must fall somewhere between a verbatim copy and a published summary statistic, and no regime yet draws it crisply.

Mapped back: the case is unclassifiable without the prime and routine with it. The clean audit log is diagnostic rather than exculpatory, since the violator was issued the data legitimately and every access it made was authorized — the failure sits exactly where the prime says it must, inside the trusted population. The dispute concentrates on the exception set because that is the clause the structure makes load-bearing. And the derivative question is the persistence clause meeting a substrate the institutional vocabulary was never built to describe, which is what the transfer analysis predicts: the roles carry across, the content of the exceptions does not.

Structural Tensions

T1 — Exceptions are constitutive, and are where the duty is actually decided. Because release, consent, compulsion, necessity, and expiry belong to the obligation rather than defeating it, the exception set carries the practical weight while presenting as fine print. A regime that enumerates carefully looks weaker than one declaring an absolute duty, and is stronger, since the absolutist regime has merely left its exceptions unwritten and will improvise them under pressure. The tension is that the honest instrument reads as the compromised one, and drafters are rewarded for the opposite.

T2 — Expressiveness and enforceability pull in opposite directions. Mechanically enforceable constraints are crisp but almost always express access rather than use: a key, a gate, a capability check. Constraints that genuinely capture purpose — this analysis but not that one, this recipient's clinical need but not their curiosity — are stateable in language and largely uncheckable by machine. Hardening enforcement therefore tends to narrow what is enforced, so a system can grow measurably more rigorous about the wrong property while its actual duty degrades unobserved.

T3 — The threat population is the trusted population. Every party capable of breaching the duty was deliberately given the information, so the standard reflex of reducing attack surface is structurally unavailable: shrinking the holder set is the same operation as degrading the function the disclosure existed to serve. A clinician who cannot see the chart cannot treat; a vendor who cannot see the data cannot analyse. The tension is permanent rather than resolvable, and every control that eases it trades away some utility that motivated the disclosure.

T4 — Persistence through transfer versus provenance decay in derivatives. The scope is meant to follow the content, but content transforms: extracted, joined, aggregated, embedded, summarized, learned. Each step weakens the practical link between artifact and designation, until the obligation is asserted over something that no longer visibly contains what it protects. Drawing the boundary tightly frees every derived product; drawing it loosely encumbers any statistic downstream of protected data forever. The tension has no principled stopping point, and each regime picks a different arbitrary one.

T5 — Breach becomes visible only through the disclosure that constitutes it. The subject learns of the violation from its effects, and the holder has both the knowledge and the incentive to keep those effects small. Detection runs backwards from consequence to cause, which biases discovery toward breaches that happened to cause harm and leaves harmless ones structurally invisible though equally violations. Measured breach rates therefore track detectability rather than incidence, so the regimes that look best-behaved may simply be those whose failures surface last.

T6 — The scope is silent about whose interest it serves. The same four-term relation shields a patient's diagnosis and an institution's internal finding about its own misconduct, and nothing in the structure separates them: both have a subject, a legitimate holder, a bounded purpose, and an attributable breach. That neutrality is what lets the prime transfer across domains, and it is also what makes it available as an instrument of concealment. The tension cannot be resolved inside the prime, because the criterion that would distinguish the cases lies entirely outside the relation.

Structural–Framed Character

Confidentiality sits on the framed side of the structural–framed spectrum, labeled mixed-framed at an aggregate of 0.5, with all five diagnostics reading at half — a balanced grade rather than one criterion pulling the rest.

The skeleton that travels is a governed information relation: information designated protected relative to an identified subject; a holder authorized to know it but not thereby authorized to use or disclose it without limit; a duty specifying permitted recipients, purposes and forms of downstream use; explicit release, expiry, consent, necessity and overriding-duty exceptions; and breach attributable to the holder when use exceeds that scope. It binds use after access, which is why encryption, access control and anonymity are not substitutes. Medicine, law, research, diplomacy, commerce and system security preserve the holder-information-purpose-disclosure roles.

Institutional origin does the most work at its half weight, and the entry states the position exactly: institutions supply the rule, but the roles transfer intact. A duty must come from somewhere, and the listed sources are normative, professional, legal, contractual or technical, so no single institution is constitutive. Evaluative weight reads half, since duty, authorization and breach are normatively loaded even where enforcement is purely technical. Human-practice-bound is half: a holder who can be bound to a scope is presupposed, though that holder may be a system. Vocabulary travels at half, carrying legal and professional-ethics terms into engineering settings. Import-vs-recognize is half.

The grade means the prime transfers wherever the roles are real, but the rule's source and exception set have to be named. The prime supplies the shape, not the content.

Substrate Independence

Confidentiality is a highly substrate-independent prime — composite 4 / 5 on the substrate-independence scale. The travelling structure is a relation among four terms: content designated protected relative to a subject, a holder whose access was granted rather than taken, a bounded scope of permitted purposes and recipients with its enumerated exceptions, and a scope that moves with the content through transfer, so any out-of-scope use is a breach attributable to the holder. Medicine, law, research ethics, diplomacy, commercial dealing, and system security keep those roles intact, varying only the remedy and the detection latency. The residual domain commitment is what holds it at four: the relation needs some order capable of designating content and attaching consequence to a holder, so instances arise only where a rule-issuing institution exists.

  • Composite substrate independence — 4 / 5
  • Domain breadth — 4 / 5
  • Structural abstraction — 4 / 5
  • Transfer evidence — 4 / 5

Relationships to Other Abstractions

Local relationship map for ConfidentialityParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.ConfidentialityPRIMEPrime abstraction: Constraint — is a kind ofConstraintPRIMEDomain-specific abstraction: Born secret — is a kind ofBorn secretDOMAINDomain-specific abstraction: Quantum key distribution — is a kind ofQuantum keydistributionDOMAIN

Current abstraction Confidentiality Prime

Parents (1) — more general patterns this builds on

  • Confidentiality is a kind of Constraint Prime

    Confidentiality is the information-use species of constraint, restricting an authorized holder's admissible disclosures and downstream actions.

Children (2) — more specific cases that build on this

  • Born secret Domain-specific is a kind of Confidentiality

    Born Secret instantiates Confidentiality because it is a rule architecture for restricting information access, specialized by statutory subject-matter attachment from creation rather than only an official designation event.

  • Quantum key distribution Domain-specific is a kind of Confidentiality

    The proposed strict upward parent is prime:confidentiality.

Hierarchy path (1) — routes to 1 parentless root

Neighborhood in Abstraction Space

Confidentiality sits in a sparse region of abstraction space (86th percentile for distinctiveness): few abstractions share its structure, so a faithful description tends to retrieve it precisely rather than landing on a neighbor.

Family — Measurement, Attestation & Signal Weighting (14 primes)

Nearest neighbors

Computed from structural-signature embeddings · 2026-09-10

Not to Be Confused With

The nearest and most consequential confusion is with Access Control, which decides whether an actor may reach a resource at all. Access control is a predicate evaluated at a moment: given this principal, this object, and this operation, permit or deny. Confidentiality begins one instant later, on the far side of a permit, and governs what the now-lawful holder may do with what it has. The two are complementary rather than competing, and they fail independently: a system with impeccable access control and no purpose scope is wide open to every authorized party, while a system with a meticulously drafted scope and no gatekeeping never gets the chance to bind anyone, because the information reaches parties who were never made holders. The practical marker is which way the control faces. Access control faces outward at people trying to get in; confidentiality faces inward at people already there.

Closest in shape is Information Use License, which also transmits information under a durable agreement permitting some downstream uses and barring others. The difference lies in the source of the constraint and the standing of the parties. A use license is granted by a rights-holder over content it controls, and its scope is a term of trade negotiated between principals each acting for itself. Confidentiality attaches to a holder typically acting for or on behalf of the subject, and its scope is set by a duty rather than by a bargain — which is why it can arise without agreement, from a professional role or a statutory status, and why the subject usually cannot sell it. Where the two coincide, as in a commercial non-disclosure instrument, the license is the vehicle and the confidentiality relation is the cargo.

Information Hiding is a design discipline, not a duty. It conceals internal facts behind a stable public surface to control dependencies, and its beneficiary is the concealing module itself: hiding a representation frees the implementer to change it. Confidentiality's beneficiary is the subject, and its purpose is not modifiability but protection of an interest external to the holder. A well-encapsulated module owes nothing to the data it hides, and a bound holder gains no design freedom from the binding. The two even fail differently — a broken abstraction barrier shows up as coupling, a broken confidence shows up as exposure.

Information Asymmetry describes a state of the world in which parties hold unequal private knowledge, with no normative content whatever. Confidentiality is one of many mechanisms that produce and sustain asymmetry, and asymmetry is the ordinary condition in which confidentiality operates, but the asymmetry itself carries no scope, no exceptions, and no attributable breach. Someone who simply knows more than a counterpart has no duty by virtue of knowing; a holder who knows exactly what everyone else knows may still have one. Diagnosing an asymmetry tells you about bargaining positions and adverse selection; diagnosing a confidentiality relation tells you what a specific party may do next.

Trust is the willing acceptance of vulnerability to another party's future conduct under incomplete monitoring. Confidentiality makes that acceptance tractable in the information case, converting a diffuse hope about the holder's discretion into a bounded and articulable scope. The relationship is generative rather than definitional: trust often precedes and motivates the disclosure, and the duty then makes explicit what would otherwise be assumed. But confidentiality survives the collapse of trust — a holder nobody trusts is still bound — and trust reaches far beyond information, to competence, effort, and care. The duty is the structure; trust is one of several attitudes that lead parties to enter it.

Contract is a multi-party bundle of obligations, breach criteria, and remedies under an accepted enforcement regime. It is the commonest instrument for creating a confidentiality relation and is not the relation itself. The clearest evidence is that the duty arises without one: clinical and legal confidence attach to a role, statutory duties attach to a status, and a confidence reposed in a friend has no enforcement regime at all yet is unmistakably the same structure. Conversely, most contracts create no confidentiality whatever. Reading the two as identical produces the familiar mistake of treating an unenforceable duty as a non-existent one.

Two adjacent primes are best read as strategies rather than rivals. Minimum Necessary Disclosure and the Principle of Least Privilege both shrink what a party receives — at the source and by grant respectively — so less is available to misuse. Confidentiality governs whatever remains after that shrinking. They compose: minimization reduces the surface the duty must cover, and the duty covers what minimization could not remove without destroying the function. Substituting one for the other is a common design error, since no amount of minimization discharges a duty over the residue, and no duty makes an over-broad extract prudent.

Solution Archetypes

No catalogued solution archetypes reference this prime yet.

Notes

The prime's placement under constraint explains a persistent asymmetry in how organizations spend. Constraints on the already-authorized are harder to enforce than constraints on entry, because the enforcing system cannot tell a compliant use from a violating one by inspecting the operation. Budget and attention drift durably toward the gate. The prime does not fix that drift; it names it, which is the precondition for arguing about it.

References

[1] Bok, Sissela. Secrets: On the Ethics of Concealment and Revelation. Pantheon Books, 1982. Canonical treatment of confidentiality as a bounded duty running across professional, commercial, governmental and journalistic settings, with its premises and its enumerated limits. registry ↩a ↩b

[2] Lampson, Butler W. "A Note on the Confinement Problem". Communications of the ACM 16(10), 1973. Poses the problem of constraining what a program legitimately given data may afterwards do with it, and enumerates the open-ended set of leakage channels that makes the transmission surface impossible to inventory. registry ↩a ↩b ↩c

[3] Nissenbaum, Helen. Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford University Press, 2010. Argues that protection attaches to context-relative norms of information flow rather than to intrinsic sensitivity, so widely circulated content can still be governed and obscure content need not be. registry ↩a ↩b

[4] American Bar Association Standing Committee on Ethics and Professional Responsibility. "Formal Opinion 480: Confidentiality Obligations for Lawyer Blogging and Other Public Commentary". American Bar Association, 2018. Holds that Model Rule 1.6 provides no exception for information that is generally known or contained in a public record, so the out-of-scope disclosure is itself the violation without any showing of harm or novelty to the recipient. registry

[5] Barth, Adam, Anupam Datta, John C. Mitchell, and Helen Nissenbaum. "Privacy and Contextual Integrity: Framework and Applications". IEEE Symposium on Security and Privacy, 2006. Expresses the transmission norms of HIPAA, GLBA and COPPA in a single temporal logic, showing the same sender-recipient-subject-principle roles instantiated in clinical, financial and online settings and checkable by machine. registry ↩a ↩b

[6] Clark, David D., and David R. Wilson. "A Comparison of Commercial and Military Computer Security Policies". IEEE Symposium on Security and Privacy, 1987. Establishes integrity as a policy goal in its own right, separable from any restriction on disclosure. registry

[7] Sabelfeld, Andrei, and Andrew C. Myers. "Language-Based Information-Flow Security". IEEE Journal on Selected Areas in Communications 21(1), 2003. Surveys label propagation to derived values, the noninterference condition stated over whole executions, and declassification as an explicit named escape rather than a judgement call. registry

[8] Clarkson, Michael R., and Fred B. Schneider. "Hyperproperties". Journal of Computer Security 18(6), 2010. Establishes that information-flow conditions relate sets of executions rather than single ones, so no individual trace or access log can decide whether they were violated. registry

[9] Powles, Julia, and Hal Hodson. "Google DeepMind and healthcare in an age of algorithms". Health and Technology 7(4), 2017. Documents a purpose-scoped transfer of identifiable clinical records to a vendor and the ensuing dispute over uses beyond the stated purpose, with no unauthorised access alleged. registry

[10] U.S. Department of Health and Human Services, Office for Civil Rights. "Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule". U.S. Department of Health and Human Services, 2012. Sets out Safe Harbor's fixed identifier list and Expert Determination as the only two routes, so whether the de-identification exception applies turns on enumerated conditions rather than on the holder's good faith. registry