Constitutional Framework

Grounds of the Articles

11 min read

A constitutional safeguard is warranted when a durable condition of power creates a predictable failure of legitimacy and a defined institutional rule can prevent or repair that failure. The safeguard must address the condition directly, preserve room for lawful variation, and remain capable of administration and review. Each Article is therefore stated through its structural condition, legitimacy failure, minimum safeguard, partial legal analogue, and open calibration.

Article 1. Receipt

Article 1. Right to a receipt at the time of a coercive act.

Structural condition: Computational acts can occur faster than affected persons or public institutions can inspect them. Legitimacy failure: An unrecorded act leaves no stable object for contest, comparison, or cumulative audit. Minimum safeguard: The authority must issue a contemporaneous receipt identifying the Act, Authority, Bounds, Justification, and Appeal Path in an accessible human-readable form and, where independent verification requires it, an interoperable machine-readable representation. Partial legal analogue: GDPR Articles 13 and 14 impose scoped information duties, and Regulation Z requires disclosures in covered credit transactions.1 Open calibration: Schema details and emergency completion periods may vary, but the five functions and contemporaneous duty remain.

Article 2. Contest

Article 2. Right to contest through independent review.

Structural condition: An authority that controls both the act and its review can preserve the appearance of process while preventing correction. Legitimacy failure: A receipt becomes evidence of subjection if no independent institution can reverse, modify, or remand the act. The same failure recurs when recourse infrastructure controls admission, consolidation, precedent matching, or closure without review. Minimum safeguard: Review must be independent, timely in relation to the harm, empowered to grant an effective remedy, and available for material decisions governing access to recourse. Common procedure may decide common questions once but must preserve material individual differences. Partial legal analogue: GDPR Article 22 provides a qualified right against certain solely automated decisions and, in specified exceptions, safeguards including human intervention and contestation.2 Open calibration: Deadlines, interim relief, aggregation, and evidentiary procedure may vary by severity.

Article 3. Human Review

Article 3. Right to human review for material adverse actions.

Structural condition: High-volume delegation can leave a nominal human reviewer without time, competence, evidence, or authority to disagree, while a sequence of individually minor acts can produce a material deprivation. Legitimacy failure: Responsibility attaches to a signature while practical judgment remains with the computational system, or a severe aggregate effect escapes review because its components were classified separately. Minimum safeguard: Every material adverse action, assessed by cumulative effect across related acts, omissions, and delays, requires an independent human arbiter whose competence and exercise of judgment can be examined. Lower-severity acts require expedited reconsideration and statistically valid independent audit. Partial legal analogue: The EU AI Act imposes human-oversight duties for high-risk systems and assigns related duties to deployers within its statutory scope.3 Open calibration: Published severity thresholds and competence standards may vary by domain, but routine confirmation does not satisfy the right.

Article 4. Export

Article 4. Right to export data, credentials, and relational context.

Structural condition: Accumulated standing can make departure ruinous even when a service is nominally voluntary. Legitimacy failure: Lock-in converts consent and contest into dependence because the person must abandon identity, reputation, relationships, or transactional history to leave. Minimum safeguard: Export must preserve the usable structure and provenance needed for practical migration. Where migration is not practically available, nominal exit cannot substitute for voice and review. Partial legal analogue: GDPR Article 20 creates a scoped data-portability right, while the Digital Markets Act imposes specified portability and interoperability duties on designated gatekeepers and services.4 Open calibration: Formats, continuity, security controls, and protected third-party interests require technical and legal specification.

Article 5. Presentment

Article 5. Right to present portable credentials.

Structural condition: Export remains ineffective if the issuer controls every place where a credential may be used. Legitimacy failure: The credential becomes proof of continuing membership rather than portable standing. Minimum safeguard: A system implementing a published interface, or capable of evaluation through reasonable technical adaptation, must permit presentment without the issuer's permission. It may evaluate provenance, validity, relevance, and status under public rules, but a claimed incompatibility or rejection at a covered passage requires a receipt and review. Recourse records must remain portable enough that changing a registry does not extinguish a claim. Partial legal analogue: The W3C Verifiable Credentials Data Model supplies a technical model for portable attestations but does not compel acceptance.5 Open calibration: Trust registries and acceptance rules may vary if presentment and review remain available.

Article 6. Cross-Domain Composition

Article 6. Right against cross-domain composition without valid authority.

Structural condition: Separately lawful records and decisions can combine across domains into a durable restriction that no participant authorized as a whole. Legitimacy failure: The cumulative act affects a person's life while remaining invisible to every institution responsible for only one component. Minimum safeguard: Direct joins and functional proxies require explicit, informed, revocable consent or another independently reviewable authority that identifies domains, purpose, duration, and consequence. Partial legal analogue: The cited GDPR and DMA provisions regulate defined processing, portability, and automated-decision contexts without making every cumulative cross-domain effect a distinct object of review.6 Open calibration: Necessary fraud, safety, and public-law uses require narrow rules, records, and review.

Article 7. Temporal Jurisdiction

Article 7. Right to time-bounded personal records.

Structural condition: A true historical record may remain available long after its relevance to a present decision has weakened or ended. Legitimacy failure: Retained information acquires indefinite coercive authority and can make past conduct determine unrelated future access by default. Minimum safeguard: Occurrence, retention, access, and present adverse use are decided separately. Evidence that coercive authority acted remains durable, while personal information within or supporting that evidence remains subject to minimization, sealing, restricted access, and limits on later adverse use. Renewed adverse use after the applicable threshold requires a current domain-specific nexus, fresh justification, independent review, limited duration, and a receipt. Partial legal analogue: GDPR Article 17 supplies a qualified erasure right, and the FCRA limits reporting of specified adverse information subject to category-specific periods and exceptions.7 Open calibration: Schedules and exceptions vary by record, purpose, current evidence, safety, archival need, investigation, and adjudication. No universal deletion or machine-unlearning method is required.

Article 8. Knowable Rule

Article 8. Right to know the rule invoked.

Structural condition: A person cannot contest a decision when the operative rule cannot be named or evaluated. Legitimacy failure: Authority becomes secret in operation even if a general policy is public. Minimum safeguard: The receipt must identify the rule, procedure, and principles actually applied, with confidential access where legitimate privacy, security, or trade-secret interests prevent full public disclosure. Partial legal analogue: GDPR Articles 13, 14, and 15 require meaningful information about the logic involved in defined automated-decision cases. In Case C-203/22, the Court of Justice required an intelligible explanation of the procedure and principles actually applied rather than a complex formula or exhaustive technical account.8 Open calibration: Disclosure tiers and red-team exceptions must remain narrow, time-limited, and independently reviewable.

Article 9. Minimum Collection

Article 9. Right against excess data collection.

Structural condition: Information collected beyond a person's requested function or an independently authorized duty expands future power, creates cross-domain influence, and raises the cost of exit. Legitimacy failure: The Operator acquires authority that no present function requires and can later reuse the resulting asymmetry. Minimum safeguard: Collection is limited to the least data-intensive reasonably effective means of performing the specific function requested or the duty independently authorized by law. Partial legal analogue: GDPR Article 5(1)(c) states data minimization within a supervisory and remedial structure.9 Open calibration: Reasonable effectiveness depends on the function, risk, and lawful purpose, not technical convenience or speculative future use.

Article 10. Anti-Waiver

Article 10. No contractual waiver of the constitutional floor.

Structural condition: A person dependent on an unavoidable passage cannot bargain over standard terms on equal footing. Legitimacy failure: Every protection can be extinguished by the same click required to obtain the service. Minimum safeguard: Contract cannot waive Articles 1 through 9 or release the authority from the institutional duties attached to Articles 11 and 12. Partial legal analogue: Existing law contains targeted non-derogation and anti-waiver rules, including ECHR Article 15(2) and section 29(a) of the Securities Exchange Act.10 Open calibration: Stronger law remains available, and lawful settlements may resolve accrued claims without authorizing prospective waiver.

Article 11. Independent Record

Article 11. Right to an independent record.

Structural condition: An authority that controls the sole authoritative evidence of its own acts can revise, suppress, or selectively disclose the record under review. Legitimacy failure: Receipt and audit become conditional on the continued cooperation of the power they constrain. Recourse fails in the same manner if a registry can erase intake, routing, consolidation, or closure decisions. Minimum safeguard: Records of covered acts and material recourse decisions must be independently verifiable, resistant to unilateral revision or suppression, and secured by an external constraint whose defeat is publicly detectable and costly in proportion to the authority recorded. Integrity establishes provenance and history rather than the truth of every claim. Objections, corrections, superseding status, and adjudicated findings remain linked to the original entry. Partial legal analogue: The legal provisions surveyed for the other Articles do not supply the complete independent-record protection stated here.11 Open calibration: Independent custody, institutional replication, transparency logs, cryptographic commitments, multiparty attestation, and physically costly settlement may serve different threat models without making any named technology constitutionally required.

Article 12. Independent Audit

Article 12. Mandatory independent audit for coercive authorities above systemic significance.

Structural condition: Repeated acts and coordinated systems can reveal population-wide error, capture, evasion, or compositional effects that no individual contest can establish. Persons least able to complain may also be the least visible to a complaint-driven system. Legitimacy failure: Responsible entities can fragment the system while each remains the final judge of whether its own receipts, reviews, rules, and records satisfy the floor. Low complaint volume can then conceal missing notice, inaccessible recourse, or retaliation. Minimum safeguard: An independent Auditor must have access across material contributors, examine random samples and latent-exposure indicators, publish methods and findings subject to lawful redaction, and impose or recommend corrective action through an authorized process. Partial legal analogue: Sarbanes-Oxley created the PCAOB and imposed specified auditor-independence controls for public-company audits.12 Open calibration: Audit frequency, sampling, funding, access, and corrective authority vary with scale, severity, concentration, reversibility, and evidence of suppressed contest.

Notes

The legal comparisons are current through 18 July 2026. They identify partial analogues within their stated scopes.

1. GDPR Articles 13-14 specify information duties when personal data are collected from the data subject or obtained elsewhere, with limits and exceptions. Regulation Z, 12 C.F.R. Part 1026, prescribes disclosures for covered consumer-credit transactions; see, for example, §§ 1026.5 and 1026.17.

2. Under GDPR Article 22(1)-(3), the safeguards in paragraph 3 apply to the contract and explicit-consent exceptions in paragraph 2(a) and (c), not without qualification to every automated decision.

3. EU Artificial Intelligence Act, Articles 14 and 26(2). These duties concern high-risk AI systems within the Act's scope.

4. GDPR Article 20(1)-(4); Digital Markets Act, Articles 6(1), 6(9), and 7. The DMA duties attach to designated gatekeepers and the core platform services listed in the designation decision; Article 7 addresses number-independent interpersonal communications services.

5. W3C, Verifiable Credentials Data Model v2.0, W3C Recommendation, 15 May 2025. The technical model does not itself compel an institution to accept a credential.

6. The comparison is limited to GDPR Articles 5, 20, and 22 and DMA Articles 6-7. No exhaustive claim is made about every legal system or cause of action.

7. GDPR Article 17(1)-(3); Fair Credit Reporting Act, 15 U.S.C. § 1681c(a)-(b). The FCRA provisions include seven- and ten-year periods, category-specific treatment, and statutory exceptions.

8. GDPR Articles 13(2)(f), 14(2)(g), and 15(1)(h); Court of Justice of the European Union, Dun & Bradstreet Austria, Case C-203/22, ECLI:EU:C:2025:117, paragraphs 58-66. The judgment defines the explanation required in the case before it; it does not establish how often deficient explanations occur or what causes them. The EU AI Act Article 86 provides a separate and limited right to explanation for specified decisions based on outputs from covered high-risk systems.

9. GDPR Articles 5(1)(c), 58, 77-79, 82, and 83. Supervisory and judicial remedies vary in application, but the principle is not enforced by fines alone.

10. European Convention on Human Rights, Article 15(2); Securities Exchange Act of 1934, 15 U.S.C. § 78cc(a). The provisions operate in different domains and are cited as targeted models.

11. The comparison is bounded to the GDPR, AI Act, DMA, W3C Recommendation, FCRA, ECHR, Securities Exchange Act, and Sarbanes-Oxley provisions cited in these notes. No claim is made that every legal system lacks an analogous safeguard.

12. Sarbanes-Oxley Act of 2002, sections 101, 201, and 202. Section 101 establishes the PCAOB for public-company audits; sections 201-202 restrict specified non-audit services and require audit-committee preapproval.