Altinn / Altinn/team-kitt

Define decision matrix for data classes vs tools (“traffic light”)

Open
#3 0 comments 0 reactions 1 assignee Assigned to @MrCarrera View on GitHub
status/draft
Dominant language
No language data
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

### Description

### Background

Policy distinguishes between:

- Data classes 1–3, and
- Tools: Digdir-procured vs private / non-approved.

We need a simple decision matrix that tells teams:

- When something is allowed
- When it must be escalated
- When it is not allowed

Norwegian justification:

> «KI-verktøy anskaffet av Digdir (enterprise)…»
> «KI-verktøy tatt i bruk privat… skal i praksis ikke brukes i arbeidssammenheng til jobbdata.»

### In scope

_No response_

### Out of scope

_No response_

### Additional Information

_No response_

### Tasks

- [ ] Design a “traffic light” table with:
- [ ] Columns: Data class (1, 2, 3), personal data (yes/no), tool type (Digdir vs private)
- [ ] Rows: Outcome (Allowed, Allowed with risk assessment, Escalate to info owner, Not allowed)
- [ ] Add clear rules, e.g.:
- [ ] Class 1–2 + Digdir-approved tool → OK within policy
- [ ] Class 3 → always “stop/clarify with information owner + risk assessment”
- [ ] Any job data + private tool → Not allowed
- [ ] Document this matrix in `/guides/decision-matrix-data-tools.md`.
- [ ] Align with security/privacy to avoid conflicts.

### Definition of Done

- [ ] Decision matrix is documented and easy to read in the repo.
- [ ] It is referenced from the use case checklist template.
- [ ] Security/privacy has reviewed and given a thumbs up (even informally).

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.