Skip to documentation content

R12 — UK legal, governance, and data protection

Status: Wave 1 research recommendation
Owns: Entity form recommendation; minimum public legal pack; GDPR classification and lawful-basis sketch; DPIA timing; OSA/UGC posture; staged launch checklist; founder decision list
Does not own: Solicitor-signed contracts; the controller identity and entity transition accepted in ADR-013; application code; TfL affiliation Must-read inputs: project-charter.md, 05-privacy-ethics.md, 11-funding-partnerships.md, ADR-011, ADR-013

Disclaimer: Operational guidance for founders and agents — not legal advice. Counsel should review before public beta. Material claims link to official UK sources.


1. Decision questions

  1. Start as informal project, company limited by guarantee (CLG), or CIC?
  2. What minimum legal documents are required before public beta?
  3. How should TUNES classify anonymous / pseudonymous / personal data and choose lawful bases?
  4. What risks do OAuth, hashes, IP controls, postcodes, comments, NLP, and UGC create?
  5. What gates apply at private prototype, limited beta, and public launch?

2. Entity recommendation

Decision (locked in ADR-013)

StageForm
Private prototype / early dogfoodInformal — named individual controller(s)
Limited beta (if any trigger) or public launch (latest)Private company limited by guarantee (CLG)
Later (optional)CIC only if funders need a statutory asset lock

Do not start as a CIC.

Why

Incorporation triggers (any one → incorporate)

  1. Dedicated bank account for grants/donations/sponsorship
  2. Contractors, project insurance, or hosting billed to the project
  3. Public dataset/map with meaningful defamation, IP, or data-subject exposure
  4. Public OAuth + comments/votes at scale (liability + Online Safety Act)
  5. University MoUs / ethics sponsorship / funders requiring a legal person
  6. Shared control among founders without a written ownership rule

Until incorporation: name one primary controller contact; if purposes/means are jointly determined, document a joint-controller split (ICO data sharing agreements).


Canonical drafts: ../governance/legal/. Consumers for web/ios: ../governance/legal/consumers/.

DocumentPurposeOfficial anchor
Privacy noticeArt 13 transparencyICO — what privacy information to provide
Terms / contributor rulesUse rules; non-affiliation; claim limitsCharter; ADR-011
Moderation policyWhat is removed; appealsPractical + OSA if U2U
Cookie / analytics noticePECR storage/accessICO PECR cookies; PECR exceptions
Takedown / reportingIllegal content, privacy, defamationOfcom illegal content duties; ICO right to erasure
Governance / ownershipWho owns what; independenceCharter; repos.md

Internal before beta: RoPA; Art 28 processor contracts (ICO contracts); LIA if using legitimate interests; DPIA; transfer mechanism for US processors (UK–US data bridge factsheet; ICO international transfers); ICO fee self-assessment.

Online Safety Act: User-to-user comments can make the service a regulated U2U service; comments only on provider content may be excluded from regulated UGC. Prefer pre-moderation or delayed comments until assessed (OSA explainer).


4. GDPR plan

4.1 Classification (ICO meanings)

ClassMeaningTUNES examplesUK GDPR?
Personal dataIdentified or identifiable personOAuth email/sub, IP, account ID, free text, precise tracksYes — What is personal data?
PseudonymousIdentifiers replaced; re-ID with separate keyContributor UUID + offline key; abuse hashesYes — Pseudonymisation
AnonymousNot identifiable by reasonably available meansSection aggregates with suppression; map tiles without contributor keysNo if effectiveAnonymisation

Map to R5 privacy tiers P0–P5. Never call hashed IDs anonymous.

4.2 Lawful bases (working recommendation)

Private/third-sector research: ICO typically points to legitimate interests for research processing; consent is high-bar (ICO research grounds; Lawful basis guide).

ProcessingBasisNotes
Account / OAuthConsent or contract + LI for securityUnbundle; Consent
Derived upload + open publicationConsent for upload (product honesty); counsel may prefer LI for research archive with LIAR5 preview + explicit opt-in
Abuse (IP, rate limits)Legitimate interests + LIAShort retention
Non-essential analytics cookiesPECR consentOr PECR statistical-purposes exception design
Health/pain perception itemsAvoid at launch; else Art 6 + Art 9 (usually explicit consent)Special category data
  • Accounts: active period + short wind-down (e.g. 30–90 days)
  • Derived contributions: integrity retention; withdrawal → tombstone / exclude from future releases (R5 §7); tell users open downloads cannot be recalled (Right to erasure)
  • Logs/IP: short TTL (e.g. 14–90 days) unless investigation hold
  • Consent records: see consent-record-fields.md
  • Raw/excerpt tiers: protocol TTL; default delete

4.4 DPIA

Complete a DPIA before limited public beta / public recruitment. Screening likely hits innovative tech, geolocation/behaviour tracking, highly personal data, vulnerable users, dataset matching (When do we need a DPIA?). Residual high risk that cannot be mitigated → consult ICO before processing.


5. Feature-specific risks

FeatureRiskControl
OAuthStable IDs; profile leakageMinimise scopes; DPA; deletion
Hashed IDsStill personal (pseudonymous)Per-purpose salts; never publish joinable hashes
IP abusePersonal data; false positivesLI + LIA; short TTL; human review before bans
PostcodeLocation over-collectionPrefer self-attest / discard after check / district only
Public commentsDefamation; OSA illegal contentPre-moderate at beta; report path; ADR-011
NLP on UGCSpecial-category inferencePrefer rules; disclose; DPIA; human review
UGC generallyLicence; third-party dataContributor licence; moderate free text out of open data

Processors (Supabase, Vercel, OAuth): Art 28 terms; UK Extension or IDTA/Addendum + TRA as applicable.


6. Staged checklist

A — Private prototype

  • Name controller(s) + contact
  • ICO fee self-assessment
  • Processor DPAs
  • Draft privacy notice + RoPA
  • Derived-only only; no public comments/open dataset
  • Non-affiliation + ADR-011 on demos
  • DPIA screening notes

B — Limited beta

  • Publish privacy, terms, cookies, governance
  • DPIA complete; LIAs for security
  • Consent records + withdrawal
  • Moderation + takedown; pre-moderate or delay comments
  • OSA illegal-content risk assessment if U2U
  • Incorporate if trigger fired; else schedule before launch
  • Invite-only; watch re-ID

C — Public launch

  • CLG in place (default)
  • Licences counsel-reviewed (ADR-012)
  • Open-release anonymisation assessment
  • Map honesty + claim checklist
  • Retention/erasure runbooks
  • Full CoC
  • CIC only if funders require asset lock

7. Founder decisions (pros / cons)

  1. Controller before incorporation — One named founder (clear / personal liability) vs joint (shared / needs written split).
  2. Incorporate now vs at trigger — Early liability shield / admin cost vs low overhead / personal exposure.
  3. CLG vs CIC first — Simpler duties vs funder asset-lock signal + CIC report.
  4. Consent vs LI for research uploads — Trust + preview UX vs ICO research fit + harder explanation.
  5. Comments at beta — Delay/pre-moderate (safer) vs open (engagement + OSA).
  6. Health/pain items — Exclude (avoid Art 9) vs include with explicit consent + DPIA.
  7. Analytics — First-party aggregate / PECR exception vs third-party + cookie consent.

Recommendation

  1. Stay informal until a trigger; incorporate CLG by public launch at latest.
  2. Ship the legal pack and sync web/ios consumers before limited beta.
  3. Treat hashed IDs as pseudonymous; DPIA before public recruitment.
  4. Agents implementing privacy-touching features must follow tunes-legal-privacy.
  5. Counsel review before public beta.

Confidence: High for entity sequencing and document set; Medium for exact lawful bases/retention until counsel; Low for OSA categorisation until product UGC shape is fixed.

Depends on experiment/legal/user-test? Legal (controller, DPIA, licences); user-test for consent/preview comprehension; ethics if raw/vulnerable campaigns.

Links: ../governance/legal/; 05-privacy-ethics.md; 11-funding-partnerships.md; ADR-013; humans ../../H11-legal-governance.md.