Name the information and consequence.
Identify personal information, sensitive personal information, business data, operational logs, credentials, content, model inputs, exports, and backups. Record why each category is needed and what harm or operational impact could follow misuse.
Draw every storage and access point.
Include browser, mobile device, application, database, object storage, analytics, email, support, monitoring, payment, AI services, administrative tools, backups, and US-based remote access.
Put a human owner beside every movement.
Name the organisation and responsible person for purpose, notice, consent or other approved basis, vendor, permission, transfer, retention, rights, security, incident, and any required assessment or filing.
Remove data and access that do not earn their risk.
Minimise fields, avoid unnecessary identity data, separate high-risk material, limit operator roles, use synthetic test data, and exclude production information from unapproved AI or support tools.
Implement the approved route.
Build notices, choices, permissions, audit evidence, encryption and secret handling, vendor boundaries, correction, deletion, retention, incident signals, and tested recovery. Do not encode an unresolved legal conclusion.
Treat change as a new gate.
A new dataset, purpose, model, processor, hosting location, remote administrator, feature, or audience may alter the decision. Review the route before release rather than after data has moved.
This microsite’s measurement is narrow but still part of the map.
The China site uses its own GA4 property and records voluntary phone and email link actions. Separate analytics identity improves attribution; it does not settle accessibility, availability, notice, consent, transfer, provider, retention, or rights questions for users in China. Advertising and profiling are not part of the stated setup.