Control
An AI vendor shares, sells or uses data a customer agency sends it for processing beyond that customer's purposes
A vendor that processes a customer's data with AI (such as body-camera footage and reports for a law enforcement agency) uses it only for that customer's purposes, or under a court order, and for the limited service uses the law allows (troubleshooting, bias mitigation, accuracy improvement, system refinement); it does not share or sell it or use it for others.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Reach
Law in force in California (US-CA).
Trust and provenance
How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.
- This control
- Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
- Lanes
- Binding law — in force 1
- Verification
- Sources last verified 4 Oct 2026; each provision states how.
- Data release
- Data release 2026.10.04.3, data as of 4 Oct 2026, schema 0.3.10.
- Legal review
- None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
- Audit standard
- 1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
- 1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
The guard to add
Keep customer data sent for AI processing inside that customer's tenant and purposes: no third-party analytics, ads, brokers or partners, no cross-customer reuse.
Payloads to analytics, advertising and partner SDKs carry event names and counts only, never footage, transcripts or narratives; datasets and indexes are partitioned by customer id; any internal access for troubleshooting, bias mitigation, accuracy improvement or system refinement goes through a logged, purpose-tagged path; a court-order export is a separate, reviewed path.
Where it goes: 1 application source code, 2 data models, 11 CI/CD pipeline.
What reviewers look for: no report text, transcript or media fields in calls to analytics, ad, data-broker or partner clients; tenant ids on every dataset and index write; a purpose-tagged, logged path for the allowed internal uses.
Example (Python service + Segment), before:
analytics.track(user_id, 'report_drafted', {'narrative': narrative, 'transcript': transcript})After:
analytics.track(user_id, 'report_drafted', {'agency_id': agency.id, 'draft_seconds': elapsed}) # no report content leaves the tenantEngineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
Binding law — in force (1)
- California (US-CA)
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.