Independent DPDP educationSWARN is in development · educational, not legal adviceSource status: 30 Aug 2026
P08Assure

ARCHITECTURE PATTERN · SYNTHETIC REFERENCE

Guardian-verification boundary

Verify the necessary relationship and adulthood signal without centralising identity documents by default.

Engineering control

Engineering pattern
not a legal template

WHEN TO USE

Use only after applicability, age context and the verified legal status have been reviewed.

Start only after the relevant facts, source status and system boundary are understood.

SOURCE / STATUS BOUNDARY

Verify the legal status before implementation.

Engineering controlPattern verification pointers

These IDs are verification pointers to the primary-source ledger. They are not provision mappings, applicability findings or legal conclusions.

SEQUENCE DIAGRAM

Four accountable hand-offs.

  1. 01Product

    identifies the guarded processing boundary

    ARTEFACT · applicability record
  2. 02Verification service

    returns minimum necessary signals

    ARTEFACT · verification result
  3. 03Decision service

    binds result to purpose and expiry

    ARTEFACT · decision record
  4. 04Reviewer

    tests bypass, retention and recovery paths

    ARTEFACT · assurance result

TYPED JSON FIXTURE

Synthetic by design.

This example contains no real person, provider, incident or system data. It demonstrates record boundaries, not a production schema.

{
  "fixture": true,
  "schemaVersion": "1.0-demo",
  "pattern": "guardian-verification-boundary",
  "subjectRef": "synthetic-only",
  "payload": {
    "verificationRef": "verification_demo_09",
    "signalsRetained": [
      "outcome",
      "expiry"
    ],
    "rawDocumentStored": false
  }
}

EVIDENCE OUTPUTS

  • Applicability review
  • Data-minimised verification design
  • Expiry and deletion test
  • Bypass and recovery test

THREAT CONSIDERATIONS

  • Identity document collection
  • Child profiling
  • Guardian-account takeover

FAILURE MODES

  • A date-of-birth field is treated as complete verification
  • Raw documents are retained without a defined need
  • The boundary excludes or traps legitimate users

RESEARCH / RADAR CONNECTION

Keep implementation context attached.

A small organisation can begin with named owners, a compact inventory and a few tested lifecycle paths while avoiding unsupported readiness claims.

Read Privacy engineering for Indian MSMEs: where simplicity matters
Assess · R-07

Field-level encryption and tokenisation

Apply data-level protection where threat modelling supports it.

Context-dependent control · Review 2026-09-20Open radar rationale

LOCAL WORKSPACE NOTE

Give this work a next owner.

This browser only

Nothing is sent anywhere. Avoid names, personal data or confidential incident details.

No local note loaded.
NextReturn to pattern discovery