Appendix I — Glossary, reader pathways, bibliography and change log
I.1 Reader pathways and source navigation
The role-based reader guide gives entry routes for boards, legal, product, engineering, procurement and sector owners. The contents links every chapter and appendix. The artifact index distinguishes blank templates, populated synthetic records, specifications and observed local output. References groups the exact source numbers and URLs by chapter; source numbers are document-local, not global.
The legal baseline was reviewed on 15 September 2026 and includes the December 2025 corrigendum. Read the bounded-update account before treating that date as current-law assurance. Publication, commencement, retrieval, review and fictional event dates must remain distinct. The vendor comparison’s September 2026 retrieval is not a November 2025 snapshot.
I.2 Working glossary
This is reader vocabulary, not a substitute for statutory definitions. Legal terms point to their owning chapter and the source lookup in Appendix A; engineering terms below are the book’s operating usage.
| Term | Working meaning / boundary | Owning chapter |
|---|---|---|
| Data Fiduciary / processor | Determine the role per activity, purpose and means; do not infer it from a vendor label | 3 and 17 |
| Data Principal / acting individual | Keep the data subject separate from a parent, guardian or nominee acting in a qualified role | 4, 12 and 13 |
| Consent Manager / consent tool | Statutory registered role versus ordinary enterprise software; neither is automatically an RBI Account Aggregator | 11 |
| SDF | Significant Data Fiduciary; actual designation and its conditions are distinct from voluntary readiness | 19 |
| Certain legitimate uses | The specified statutory routes, not a general business-interest or contract ground | 3 and 8 |
| Commencement | When the particular provision comes into force, not merely when the instrument was published | 2 |
| Scope / exemption | Activity-level applicability and precise provisions affected; not a company-wide shortcut | 3 and 5 |
| Cessation | Stopping the relevant processing under its applicable conditions; not necessarily deleting every retained copy | 10 |
| Retention / erasure | Why and how a scoped record remains or is disposed of; retained permission for one use does not reopen another | 14 |
| Nomination | A separate authority relationship; do not re-key the subject to the nominee | 12 |
| DPIA | Data protection impact assessment; statutory where applicable, voluntary assessment elsewhere; a signature cannot waive a legal stop | 20 |
| PDP / PEP | Proposed policy decision point / policy enforcement point; design components, not statutory entities | 15 and 18 |
| Authority frontier | The current captured history/version the example requires before it trusts a replay or a decision | 10, 14 and 35 |
| Outbox / idempotency | Proposed durable dispatch record / operation identity discipline; the local examples do not prove distributed atomicity | 18 |
| Tombstone / restore quarantine | Disposal/restriction history / isolated restoration boundary before reviewed promotion | 14 |
| ACK | A scoped acknowledgement; missing or unauthenticated ACK is not completion | 10 and 17 |
| SLO / SLA | Internal objective / agreed service commitment, unless a specific sourced legal clock is expressly identified | 12, 22 and 30 |
| PoV | Proof of value using predeclared inputs and acceptance criteria; not a supplier’s slide demonstration | 30 |
| TCO / FTE | Total cost of ownership / full-time-equivalent capacity under stated assumptions | 24 and 30 |
| BAU | Business-as-usual ownership after project handover, including unresolved work and source monitoring | 36 |
| Source grade / evidence tier | Provenance classification / capability-evidence assumption; they are not the same score | 25 and 30 |
| Local test / production evidence | Observed behavior of delivered code on supplied inputs / evidence from a real deployed scope; the first does not imply the second | 22 and 35 |
I.3 Stable IDs and editorial provenance
CASE, ENT, SUB, SYS, DS, FLOW, PUR and EVT identify the case, entity, subject, system, dataset, flow, purpose and event scene. NOTICE, CONSENT, WITHDRAW, RIGHTS, HOLD, INC, REM and RETEST name the associated work objects. Their actual definitions live in the fixed-ID contract and integrated ID register, not in guesses from their spelling. Scene IDs can contain multiple purpose-specific transport events.
OBL identifiers are operational aliases used by Chapter 2 and Appendix B. ACT/RULE/SCHED identifiers belong to the canonical source register. A control row can reference several legal rows and must preserve their different actors and dates. It is not a new statutory obligation number.
Q01–Q10 labels are book production/remediation phases, not regulators, legal instruments or enterprise roles. Q02 source views, Q03 workflow fragments, Q04 engineering fragments, Q05 assurance/economics, Q06 sector work, Q08 procurement and Q09 integrated dossier preserve version-specific evidence. Q07 is the independent legal/control review packet. Q10 is this editorial/navigation integration. These labels remain in filenames to preserve provenance; they do not convey current acceptance merely by appearing in a header.
I.4 Change history and reader status
| Revision layer | Durable record | Status distinction |
|---|---|---|
| Original content-quality review | Consolidated review | Historical findings, not a fresh description of every current file |
| Canonical baseline and fixed case | Provision register, case contract | Retained source interpretation and hypothetical identities |
| Independent legal/control review | Resumed acceptance record | Scoped review of its exact versions, not whole-book publication approval |
| Integrated case | Dossier manifest | Populated examples and identified actual local results |
| Editorial integration | Q10 change and verification | Appendices, navigation, promise accounting and current metrics; downstream independent review remains required |
No PDF/DOCX/EPUB acceptance is claimed here. Historical assemblies and progress records do not override current source files. The downstream release must use the manifest order, preserve local citation namespaces, include companion artifacts and verify actual rendering before declaring a reader edition accepted.