# DHCP Supporting Evidence Package

Run: `0406b48c-b438-4b2f-bb2d-d495c1870333`  ·  Generated: 2026-08-09T20:56:29Z

Catalog: http://localhost:8080 (9 datasets)

Provenance: DHCP v0.1.0 · report schema v2.0.0 · evidence profiles `aicm` v1.1.0, `gdpr` v1.0.0, `hipaa` v1.0.1, `iso27001` v1.1.0, `iso42001` v1.1.1, `soc2` v1.5.0 · catalog SHA-256 `37cd51fd1dd2cce5d653aec6775ac92f6d7d05deaf3215118fc4691da3eff47b` · profile manifest SHA-256 `91cfaa84aa052371bca2b2efb2c35d2b0e908bf36fd61c34e50efd9c4ad0ddcf`

Report pair SHA-256: `d11579e72fd154923bcef96684dc92d8c4446e99bbc94dfe330e15d7db8d96a1`

> **Claim boundary:** Observation coverage describes catalog-visible metadata only. Profile mappings explain possible relevance and limitations; DHCP does not determine conformity with any objective.

## Posture brief

DHCP inspected the selected DataHub catalog snapshot and preserved exact observed and
not-observed asset sets. Coverage percentages below describe metadata presence only;
they are not framework grades or target thresholds.

| Catalog observation | Deterministic criterion | Observed | Not observed | Coverage |
|---|---|---:|---:|---:|
| Documented backup-requirement decision (`backup_requirement_coverage`) | The dataset has a controlled io.obsidiantek.dhcp.backupRequirement value: REQUIRED, NOT_REQUIRED, or CONDITIONAL. | 7/9 | 2/9 | 77.8% |
| Substantive dataset description (`documentation_coverage`) | The trimmed dataset description is at least 20 characters long. | 9/9 | 0/9 | 100.0% |
| Domain assignment (`domain_assignment`) | The dataset has a non-empty DataHub domain assignment. | 8/9 | 1/9 | 88.9% |
| Registered lineage (`lineage_presence`) | The dataset has at least one registered upstream or downstream lineage edge. | 8/9 | 1/9 | 88.9% |
| Assigned owner (`ownership_coverage`) | The dataset has at least one assigned DataHub owner. | 8/9 | 1/9 | 88.9% |
| Retention intent for identified personal information (`personal_information_retention_coverage`) | Among datasets with a schema field carrying a recognized PII, PHI, personal, personal-data, or personal-information label, the dataset has a non-empty io.acryl.privacy.retentionTime structured property. | 4/7 | 3/7 | 57.1% |
| Field sensitivity label (`pii_tag_coverage`) | At least one schema field has a tag or glossary term whose normalized name includes one of these exact tokens: PHI, HIPAA, PCI, financial, PII, GDPR, personal, sensitive, or confidential; explicitly non-sensitive labels do not count. | 7/9 | 2/9 | 77.8% |
| Documented retention intent (`retention_property_coverage`) | The dataset has a non-empty io.acryl.privacy.retentionTime structured property. | 6/9 | 3/9 | 66.7% |

## LangChain agent analysis

`claude-sonnet-4-6` · DataHub Agent Context Kit · read-only · 1 context lookup · narrative claim checks: accepted

Documentation catalog observation coverage is the strongest signal in this digest, with all 9 datasets carrying substantive descriptions, and ownership, domain assignment, and lineage each observed on 8 of 9 datasets. The weakest observations are retention_property_coverage, present on 6 of 9 datasets, and personal_information_retention_coverage, present on only 4 of the 7 datasets identified as carrying personal-information labels. The catalog lookup confirms that aic.compliance_reporting is the single dataset missing ownership, domain assignment, and a PII tag simultaneously, and that aic.ai_training_features, aic.clinical_features, and aic.encounter_events are the datasets whose retention intent has not been recorded in DataHub.

The most consequential review implications cluster around retention and classification. For GDPR Article 5(1)(e), SOC 2 P4.2, and DSP-16, the 3 datasets without a retention property and the 3 personal-information-labeled datasets without a retention record represent the highest-priority catalog gaps; however, the absence of a structured property does not prove that no retention policy exists outside DataHub, and accountable privacy counsel must confirm whether any period is legally appropriate and whether deletion is enforced.

*This optional analysis was drafted through LangChain from the deterministic
observation payload with 1 read-only
DataHub Agent Context Kit lookup. It cannot add evidence, change counts, or decide conformity.*

## Evidence profile mappings

Each mapping states the project's interpretation, why the DataHub observation may be
useful, and what it cannot establish. Consult the authoritative source and a qualified
reviewer before drawing a compliance conclusion.

### CSA AI Controls Matrix (AICM)

Profile `aicm` v1.1.0 · Reference: AICM v1.1.0 · [authoritative source](https://cloudsecurityalliance.org/artifacts/ai-controls-matrix)

Selected identifiers and titles are attributed to Cloud Security Alliance; interpretations and evidence statements are project-authored.

#### DSP-03 — Data Inventory

**Project interpretation.** A governed data inventory should make in-scope datasets discoverable, organized, and understandable.

**Catalog evidence.** `domain_assignment`, `documentation_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Domain assignment (`domain_assignment`) | 8/9 | 1/9 | 88.9% |
| Substantive dataset description (`documentation_coverage`) | 9/9 | 0/9 | 100.0% |

**Why it may help.** Domain assignments and substantive dataset descriptions provide catalog-visible inventory context for auditor review.

**What it cannot establish.** These observations do not establish that every in-scope data resource is cataloged or that inventory records are accurate and current.

**Suggested catalog action.** Assign missing DataHub domains and add substantive dataset descriptions.

**DataHub surfaces.** Domains, Dataset descriptions

#### DSP-04 — Data Classification

**Project interpretation.** Cataloged fields should carry explicit classification labels so reviewers can identify recorded sensitivity decisions.

**Catalog evidence.** `pii_tag_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |

**Why it may help.** A recognized sensitivity tag or directly assigned glossary term on at least one field provides catalog-visible evidence that selected data-classification decisions have been recorded for that dataset.

**What it cannot establish.** This observation does not establish classification completeness or correctness, coverage of data type or criticality, handling requirements, or operating effectiveness.

**Suggested catalog action.** Review unlabeled sensitivity candidates and apply confirmed field-level classifications through the governed catalog process.

**DataHub surfaces.** Schema field tags, Glossary terms

#### DSP-05 — Data Flow Documentation

**Project interpretation.** Data movement should be documented so reviewers can trace material upstream and downstream relationships.

**Catalog evidence.** `lineage_presence`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Registered lineage (`lineage_presence`) | 8/9 | 1/9 | 88.9% |

**Why it may help.** Registered DataHub lineage edges provide catalog-visible data-flow evidence.

**What it cannot establish.** Lineage presence does not establish that every transformation, transfer, system boundary, or external recipient is represented.

**Suggested catalog action.** Register and verify upstream and downstream lineage for datasets with no catalog-visible edges.

**DataHub surfaces.** Lineage

#### DSP-06 — Data Ownership and Stewardship

**Project interpretation.** Governed data assets should have a catalog-visible accountable party.

**Catalog evidence.** `ownership_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Assigned owner (`ownership_coverage`) | 8/9 | 1/9 | 88.9% |

**Why it may help.** Assigned DataHub owners provide direct metadata evidence that a dataset has a named accountable party.

**What it cannot establish.** Owner assignment does not establish role acceptance, authority, stewardship procedures, or operating effectiveness.

**Suggested catalog action.** Assign a technical or business owner to each dataset missing one.

**DataHub surfaces.** Ownership

#### DSP-16 — Data Retention and Deletion

**Project interpretation.** Retention intentions should be recorded in a structured form so lifecycle work can be identified and handed off.

**Catalog evidence.** `retention_property_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Documented retention intent (`retention_property_coverage`) | 6/9 | 3/9 | 66.7% |

**Why it may help.** A non-empty DataHub retention-time structured property provides evidence of documented retention intent.

**What it cannot establish.** The property does not prove that a period is legally appropriate, that deletion occurred, or that lifecycle enforcement is operating.

**Suggested catalog action.** Record the reviewed retention period in io.acryl.privacy.retentionTime for datasets where it is absent.

**DataHub surfaces.** Structured properties, Forms

#### DSP-17 — Sensitive Data Protection

**Project interpretation.** Sensitive-data review depends on catalog-visible identification of fields that may require protection.

**Catalog evidence.** `pii_tag_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |

**Why it may help.** An explicit sensitivity tag or glossary term on at least one field shows that field-level sensitivity labeling is present for that dataset.

**What it cannot establish.** This observation does not measure classification completeness, validate labels, or establish that any protection control is implemented.

**Suggested catalog action.** Review unlabeled sensitivity candidates and apply confirmed field-level labels through the governed catalog process.

**DataHub surfaces.** Schema field tags, Glossary terms

#### DSP-20 — Data Provenance and Transparency

**Project interpretation.** Reviewers should be able to understand a dataset's stated purpose and trace its catalog-visible origin or downstream use.

**Catalog evidence.** `documentation_coverage`, `lineage_presence`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Substantive dataset description (`documentation_coverage`) | 9/9 | 0/9 | 100.0% |
| Registered lineage (`lineage_presence`) | 8/9 | 1/9 | 88.9% |

**Why it may help.** Substantive descriptions and registered lineage provide complementary documentation and provenance evidence.

**What it cannot establish.** These observations do not establish end-to-end provenance completeness, source authenticity, transformation accuracy, or transparency to affected people.

**Suggested catalog action.** Document dataset purpose and source context, then register and verify material lineage edges.

**DataHub surfaces.** Dataset descriptions, Lineage

### GDPR

Profile `gdpr` v1.0.0 · Reference: Regulation (EU) 2016/679 · [authoritative source](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng)

Article identifiers anchor the official regulation; interpretations and evidence statements are project-authored and are not legal advice.

#### Article 30 — Records of processing activities

**Project interpretation.** A processing-activity review needs an accountable inventory with purpose, personal-data context, data flows, and retention intent.

**Catalog evidence.** `ownership_coverage`, `domain_assignment`, `documentation_coverage`, `pii_tag_coverage`, `lineage_presence`, `retention_property_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Assigned owner (`ownership_coverage`) | 8/9 | 1/9 | 88.9% |
| Domain assignment (`domain_assignment`) | 8/9 | 1/9 | 88.9% |
| Substantive dataset description (`documentation_coverage`) | 9/9 | 0/9 | 100.0% |
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |
| Registered lineage (`lineage_presence`) | 8/9 | 1/9 | 88.9% |
| Documented retention intent (`retention_property_coverage`) | 6/9 | 3/9 | 66.7% |

**Why it may help.** Owners, domains, descriptions, sensitivity labels, lineage, and retention properties provide reusable catalog evidence for assembling or testing parts of a record of processing activities.

**What it cannot establish.** A DataHub dataset is not a processing activity. These observations do not establish lawful basis, purposes, data-subject categories, recipients, transfers, security measures, completeness, or applicability of Article 30.

**Suggested catalog action.** Improve the catalog evidence, then have privacy counsel or the accountable privacy team reconcile it with the authoritative record of processing activities.

**DataHub surfaces.** Ownership, Domains, Dataset descriptions, Schema field tags, Glossary terms, Lineage, Structured properties

#### Article 5(1)(e) — Storage limitation

**Project interpretation.** Personal-data review should be able to identify the intended retention period associated with cataloged datasets.

**Catalog evidence.** `retention_property_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Documented retention intent (`retention_property_coverage`) | 6/9 | 3/9 | 66.7% |

**Why it may help.** A non-empty retention-time structured property provides reviewable evidence of documented retention intent.

**What it cannot establish.** The observation does not identify personal data, determine necessity, validate the period, account for exceptions, or prove deletion and enforcement.

**Suggested catalog action.** Have the accountable privacy team review and record retention intent for relevant datasets, then verify enforcement outside DHCP.

**DataHub surfaces.** Structured properties, Forms

### HIPAA

Profile `hipaa` v1.0.1 · Reference: 45 CFR Parts 160 and 164 · [authoritative source](https://www.hhs.gov/hipaa/for-professionals/index.html)

Citations anchor official HHS rules and guidance; interpretations and evidence statements are project-authored and are not legal advice.

#### 45 CFR 164.308(a)(1)(ii)(A) — Security risk-analysis scope · [official guidance](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html)

**Project interpretation.** Risk analysis begins with identifying all locations where electronic protected health information is created, received, maintained, or transmitted.

**Catalog evidence.** `ownership_coverage`, `domain_assignment`, `documentation_coverage`, `pii_tag_coverage`, `lineage_presence`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Assigned owner (`ownership_coverage`) | 8/9 | 1/9 | 88.9% |
| Domain assignment (`domain_assignment`) | 8/9 | 1/9 | 88.9% |
| Substantive dataset description (`documentation_coverage`) | 9/9 | 0/9 | 100.0% |
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |
| Registered lineage (`lineage_presence`) | 8/9 | 1/9 | 88.9% |

**Why it may help.** Catalog ownership, domain, documentation, field sensitivity labeling, and lineage observations can support scoping and data collection for ePHI risk analysis.

**What it cannot establish.** DHCP does not determine HIPAA applicability, identify all ePHI, assess threats or vulnerabilities, assign risk, evaluate safeguards, or perform the required risk analysis.

**Suggested catalog action.** Review catalog evidence and sensitivity candidates with the HIPAA security team, then incorporate confirmed systems and flows into the formal risk analysis.

**DataHub surfaces.** Ownership, Domains, Dataset descriptions, Schema field tags, Glossary terms, Lineage

#### 45 CFR 164.502(b) / 164.514(d) — Minimum-necessary review support · [official guidance](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/minimum-necessary-requirement/index.html)

**Project interpretation.** Reviewers need to identify categories of protected health information and their stated purpose before assessing minimum-necessary policies and access.

**Catalog evidence.** `pii_tag_coverage`, `documentation_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |
| Substantive dataset description (`documentation_coverage`) | 9/9 | 0/9 | 100.0% |

**Why it may help.** Field sensitivity labels and substantive dataset descriptions provide catalog evidence that can help scope minimum-necessary review.

**What it cannot establish.** These observations do not establish that data is PHI, whether an exception applies, who has access, the purpose of a use or disclosure, or whether minimum-necessary policies are effective.

**Suggested catalog action.** Confirm PHI classifications and purposes with the privacy team, then review role-based access, information categories, exceptions, and disclosure policies in the authoritative systems.

**DataHub surfaces.** Schema field tags, Glossary terms, Dataset descriptions

### ISO/IEC 27001

Profile `iso27001` v1.1.0 · Reference: ISO/IEC 27001:2022 Annex A · [authoritative source](https://www.iso.org/standard/27001)

Control identifiers are used for identification; titles, interpretations, and evidence statements are project-authored paraphrases.

#### A.5.9 — Inventory of information and associated assets

**Project interpretation.** Cataloged datasets should carry accountable ownership and sufficient context to support review of the information-asset inventory.

**Catalog evidence.** `ownership_coverage`, `domain_assignment`, `documentation_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Assigned owner (`ownership_coverage`) | 8/9 | 1/9 | 88.9% |
| Domain assignment (`domain_assignment`) | 8/9 | 1/9 | 88.9% |
| Substantive dataset description (`documentation_coverage`) | 9/9 | 0/9 | 100.0% |

**Why it may help.** Dataset ownership, domain assignment, and substantive descriptions provide catalog-visible evidence for reviewing inventory records, accountability, and context.

**What it cannot establish.** These observations do not establish that the inventory covers all information and associated assets, that records are maintained over time, that ownership assignments are appropriate or current, or that the full control is satisfied.

**Suggested catalog action.** Assign missing owners and domains, and add substantive dataset descriptions.

**DataHub surfaces.** Ownership, Domains, Dataset descriptions

#### A.5.12 — Information-classification records

**Project interpretation.** Cataloged datasets should expose reviewed field-level sensitivity classifications that support information-classification governance.

**Catalog evidence.** `pii_tag_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |

**Why it may help.** A recognized sensitivity tag or directly assigned glossary term on at least one field provides catalog-visible evidence that selected classification decisions have been recorded for that dataset.

**What it cannot establish.** This observation does not establish the organization's classification scheme or criteria, evaluate confidentiality, integrity or availability requirements, measure classification completeness, accuracy or currency, verify resulting handling controls, or satisfy the full control.

**Suggested catalog action.** Review unlabeled sensitivity candidates and record only authorized field-level classifications.

**DataHub surfaces.** Schema field tags, Glossary terms

#### A.5.13 — Labelling of information

**Project interpretation.** Fields with confirmed sensitivity classifications should carry explicit catalog labels so reviewers can see where information labelling has been implemented.

**Catalog evidence.** `pii_tag_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |

**Why it may help.** A recognized sensitivity tag or directly assigned glossary term on at least one field provides catalog-visible evidence that field-level labelling is present for that dataset.

**What it cannot establish.** This observation does not establish an organization-wide labelling procedure, alignment with the adopted classification scheme, label completeness, accuracy or currency, resulting handling rules, or satisfaction of the full control.

**Suggested catalog action.** Review unlabeled sensitivity candidates and apply only confirmed field-level labels.

**DataHub surfaces.** Schema field tags, Glossary terms

### ISO/IEC 42001

Profile `iso42001` v1.1.1 · Reference: ISO/IEC 42001:2023 Annex A · [authoritative source](https://www.iso.org/standard/81230.html)

Control identifiers are used for identification; titles, interpretations, and evidence statements are project-authored paraphrases.

#### A.4.3 — Documentation of data resources

**Project interpretation.** In-scope AI data resources should carry catalog documentation, provenance relationships, explicit field sensitivity classification, and documented retention intent.

**Catalog evidence.** `documentation_coverage`, `lineage_presence`, `pii_tag_coverage`, `retention_property_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Substantive dataset description (`documentation_coverage`) | 9/9 | 0/9 | 100.0% |
| Registered lineage (`lineage_presence`) | 8/9 | 1/9 | 88.9% |
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |
| Documented retention intent (`retention_property_coverage`) | 6/9 | 3/9 | 66.7% |

**Why it may help.** Substantive descriptions can carry intended-use context, registered lineage provides provenance inputs, reviewed field labels expose selected information categories, and retention properties record retention intent.

**What it cannot establish.** These observations do not identify the complete AI-system data-resource boundary or establish the data's last-update date, machine-learning role, labeling process, quality, disposal policy or enforcement, bias, preparation, or the completeness and accuracy of any documentation.

**Suggested catalog action.** For each in-scope AI data resource, document its intended use and known constraints, register material lineage, apply only reviewed sensitivity labels, and record reviewed retention intent.

**DataHub surfaces.** Dataset descriptions, Lineage, Schema field tags, Glossary terms, Structured properties

#### A.7.5 — Data provenance

**Project interpretation.** Cataloged AI data resources should expose traceable upstream or downstream relationships for provenance review.

**Catalog evidence.** `lineage_presence`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Registered lineage (`lineage_presence`) | 8/9 | 1/9 | 88.9% |

**Why it may help.** Registered DataHub lineage edges provide machine-readable provenance evidence for cataloged datasets.

**What it cannot establish.** Lineage presence does not prove end-to-end completeness, source authenticity, transformation accuracy, or that a dataset is used by an AI system.

**Suggested catalog action.** Register and independently review material lineage for in-scope AI data resources.

**DataHub surfaces.** Lineage

### SOC 2

Profile `soc2` v1.5.0 · Reference: 2017 Trust Services Criteria · [authoritative source](https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services)

Criterion identifier is used for identification; title, interpretation, and evidence statements are project-authored paraphrases.

#### CC2.1 — Quality information supporting internal control

**Project interpretation.** Cataloged descriptions, lineage, and field-level sensitivity labels support review of asset records, documented data flows, and information classification.

**Catalog evidence.** `documentation_coverage`, `lineage_presence`, `pii_tag_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Substantive dataset description (`documentation_coverage`) | 9/9 | 0/9 | 100.0% |
| Registered lineage (`lineage_presence`) | 8/9 | 1/9 | 88.9% |
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |

**Why it may help.** Substantive descriptions, registered lineage, and field-level sensitivity tags or glossary terms provide catalog-visible evidence of asset records, data-flow documentation, and information classification.

**What it cannot establish.** These observations do not establish inventory completeness, lineage completeness, classification accuracy or completeness, information quality, communication to responsible parties, operating effectiveness, or satisfaction of the full criterion.

**Suggested catalog action.** Add substantive dataset descriptions, register and verify material lineage, and apply only reviewed field-level sensitivity labels where evidence is absent.

**DataHub surfaces.** Dataset descriptions, Lineage, Schema field tags, Glossary terms

#### A1.2 — Backup-requirement decisions

**Project interpretation.** In-scope datasets should carry a governed decision recording whether backup is required.

**Catalog evidence.** `backup_requirement_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Documented backup-requirement decision (`backup_requirement_coverage`) | 7/9 | 2/9 | 77.8% |

**Why it may help.** A controlled dataset Structured Property provides catalog-visible evidence that an accountable backup-requirement decision has been recorded.

**What it cannot establish.** This observation does not establish that the decision is appropriate or current, that backups run or succeed, that copies are complete, protected, immutable or off-site, that restoration is tested, or that recovery objectives and infrastructure satisfy the full criterion.

**Suggested catalog action.** Have accountable owners review missing decisions and record REQUIRED, NOT_REQUIRED, or CONDITIONAL; verify backup operation and restoration outside DHCP.

**DataHub surfaces.** Structured properties, Forms, Ownership, Dataset documentation

#### C1.1 — Confidential-information retention review

**Project interpretation.** Confidential-information review should be able to identify cataloged sensitive datasets, their stated purpose or context, and their documented retention intent.

**Catalog evidence.** `documentation_coverage`, `pii_tag_coverage`, `retention_property_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Substantive dataset description (`documentation_coverage`) | 9/9 | 0/9 | 100.0% |
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |
| Documented retention intent (`retention_property_coverage`) | 6/9 | 3/9 | 66.7% |

**Why it may help.** Field-level sensitivity labels, substantive dataset descriptions, and retention Structured Properties provide complementary catalog evidence for identifying confidential-information retention decisions that need review.

**What it cannot establish.** These observations do not establish that every confidential dataset is identified, that labels or stated purposes are correct, that a retention period is necessary or legally appropriate, that exceptions are handled, or that deletion and lifecycle enforcement operate effectively.

**Suggested catalog action.** Review sensitivity labels and stated purpose, then have accountable owners record missing retention intent and verify necessity, exceptions, deletion, and enforcement outside DHCP.

**DataHub surfaces.** Dataset descriptions, Schema field tags, Glossary terms, Structured properties, Forms

#### C1.2 — Confidential-information disposition identification

**Project interpretation.** Cataloged sensitivity labels and documented retention intent provide inputs for identifying confidential datasets that may require disposition review when their retention period ends.

**Catalog evidence.** `pii_tag_coverage`, `retention_property_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Field sensitivity label (`pii_tag_coverage`) | 7/9 | 2/9 | 77.8% |
| Documented retention intent (`retention_property_coverage`) | 6/9 | 3/9 | 66.7% |

**Why it may help.** Field-level sensitivity labels and retention Structured Properties provide complementary catalog evidence for assembling an exact confidential-information population whose disposition requirements need accountable review.

**What it cannot establish.** These observations do not establish that every confidential dataset is identified, that retention metadata is correct or machine-evaluable, that a retention period has ended, that holds or exceptions were considered, that destruction was authorized or performed, or that the full criterion is satisfied.

**Suggested catalog action.** Review sensitivity labels and record missing retention intent, then identify expiration candidates and verify holds, exceptions, authorization, deletion, and destruction evidence outside DHCP.

**DataHub surfaces.** Schema field tags, Glossary terms, Structured properties, Forms

#### PI1.2 — System-input relationship records

**Project interpretation.** Cataloged lineage helps document declared upstream input relationships for in-scope datasets.

**Catalog evidence.** `lineage_presence`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Registered lineage (`lineage_presence`) | 8/9 | 1/9 | 88.9% |

**Why it may help.** Registered upstream and downstream lineage edges provide reviewable catalog records of declared system-input relationships, with raw dataset counts and exact observed and not-observed populations.

**What it cannot establish.** This observation does not establish that every input or input activity was recorded, that records are complete, accurate, or timely, that transactions or data inputs were validated, that related procedures operated effectively, or that the full criterion is satisfied.

**Suggested catalog action.** Register material upstream input relationships where lineage is absent, then have accountable reviewers verify the relationships and assess input-activity, completeness, accuracy, timeliness, and validation evidence outside DHCP.

**DataHub surfaces.** Lineage

#### P4.2 — Personal-information retention review

**Project interpretation.** Cataloged datasets identified as containing personal information should carry documented retention intent.

**Catalog evidence.** `personal_information_retention_coverage`

| Observation | Observed | Not observed | Coverage |
|---|---:|---:|---:|
| Retention intent for identified personal information (`personal_information_retention_coverage`) | 4/7 | 3/7 | 57.1% |

**Why it may help.** Reviewed PII, PHI, personal-data, or personal-information field labels define the catalog-identified population; a retention Structured Property on the same dataset records stated retention intent.

**What it cannot establish.** This observation does not establish that every personal-information dataset is identified, that labels or retention metadata are complete, accurate or current, that a period is appropriate or legally permitted, that exceptions are handled, that deletion or lifecycle enforcement operates, or that the full criterion is satisfied.

**Suggested catalog action.** Review personal-information identification separately, then have accountable owners record missing retention intent and verify purpose, necessity, legal requirements, exceptions, deletion, and lifecycle enforcement outside DHCP.

**DataHub surfaces.** Schema field tags, Glossary terms, Structured properties, Forms

## Complete observation inventory

The JSON companion contains both complete asset sets for every observation. This
Markdown view shows both sets and caps each at 20 rows for readability.

### Documented backup-requirement decision (`backup_requirement_coverage`)

**Criterion.** The dataset has a controlled io.obsidiantek.dhcp.backupRequirement value: REQUIRED, NOT_REQUIRED, or CONDITIONAL.

#### Observed (7)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_training_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_validation_set,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.clinical_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.encounter_events,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.patient_records,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.claims_billing,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.compliance_reporting,PROD)` |

#### Not observed (2)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_inference_inputs,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.consent_preferences,PROD)` |

### Substantive dataset description (`documentation_coverage`)

**Criterion.** The trimmed dataset description is at least 20 characters long.

#### Observed (9)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_inference_inputs,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_training_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_validation_set,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.clinical_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.consent_preferences,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.encounter_events,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.patient_records,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.claims_billing,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.compliance_reporting,PROD)` |

No dataset lacked this catalog observation.

### Domain assignment (`domain_assignment`)

**Criterion.** The dataset has a non-empty DataHub domain assignment.

#### Observed (8)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_inference_inputs,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_training_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_validation_set,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.clinical_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.consent_preferences,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.encounter_events,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.patient_records,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.claims_billing,PROD)` |

#### Not observed (1)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.compliance_reporting,PROD)` |

### Registered lineage (`lineage_presence`)

**Criterion.** The dataset has at least one registered upstream or downstream lineage edge.

#### Observed (8)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_inference_inputs,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_training_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_validation_set,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.clinical_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.encounter_events,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.patient_records,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.claims_billing,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.compliance_reporting,PROD)` |

#### Not observed (1)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.consent_preferences,PROD)` |

### Assigned owner (`ownership_coverage`)

**Criterion.** The dataset has at least one assigned DataHub owner.

#### Observed (8)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_inference_inputs,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_training_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_validation_set,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.clinical_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.consent_preferences,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.encounter_events,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.patient_records,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.claims_billing,PROD)` |

#### Not observed (1)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.compliance_reporting,PROD)` |

### Retention intent for identified personal information (`personal_information_retention_coverage`)

**Criterion.** Among datasets with a schema field carrying a recognized PII, PHI, personal, personal-data, or personal-information label, the dataset has a non-empty io.acryl.privacy.retentionTime structured property.

#### Observed (4)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_inference_inputs,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_validation_set,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.consent_preferences,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.patient_records,PROD)` |

#### Not observed (3)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_training_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.clinical_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.encounter_events,PROD)` |

### Field sensitivity label (`pii_tag_coverage`)

**Criterion.** At least one schema field has a tag or glossary term whose normalized name includes one of these exact tokens: PHI, HIPAA, PCI, financial, PII, GDPR, personal, sensitive, or confidential; explicitly non-sensitive labels do not count.

#### Observed (7)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_inference_inputs,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_training_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_validation_set,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.clinical_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.consent_preferences,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.encounter_events,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.patient_records,PROD)` |

#### Not observed (2)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.claims_billing,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.compliance_reporting,PROD)` |

### Documented retention intent (`retention_property_coverage`)

**Criterion.** The dataset has a non-empty io.acryl.privacy.retentionTime structured property.

#### Observed (6)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_inference_inputs,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_validation_set,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.consent_preferences,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.patient_records,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.claims_billing,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.compliance_reporting,PROD)` |

#### Not observed (3)

| Dataset URN |
|---|
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.ai_training_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.clinical_features,PROD)` |
| `urn:li:dataset:(urn:li:dataPlatform:showcase,aic.encounter_events,PROD)` |

---

*Supporting evidence derived from DataHub catalog metadata — not a legal or compliance determination, audit, assessment, or certification.*
