Define decision matrix for data classes vs tools (“traffic light”)
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
### Description
### Background
Policy distinguishes between:
- Data classes 1–3, and
- Tools: Digdir-procured vs private / non-approved.
We need a simple decision matrix that tells teams:
- When something is allowed
- When it must be escalated
- When it is not allowed
Norwegian justification:
> «KI-verktøy anskaffet av Digdir (enterprise)…»
> «KI-verktøy tatt i bruk privat… skal i praksis ikke brukes i arbeidssammenheng til jobbdata.»
### In scope
_No response_
### Out of scope
_No response_
### Additional Information
_No response_
### Tasks
- [ ] Design a “traffic light” table with:
- [ ] Columns: Data class (1, 2, 3), personal data (yes/no), tool type (Digdir vs private)
- [ ] Rows: Outcome (Allowed, Allowed with risk assessment, Escalate to info owner, Not allowed)
- [ ] Add clear rules, e.g.:
- [ ] Class 1–2 + Digdir-approved tool → OK within policy
- [ ] Class 3 → always “stop/clarify with information owner + risk assessment”
- [ ] Any job data + private tool → Not allowed
- [ ] Document this matrix in `/guides/decision-matrix-data-tools.md`.
- [ ] Align with security/privacy to avoid conflicts.
### Definition of Done
- [ ] Decision matrix is documented and easy to read in the repo.
- [ ] It is referenced from the use case checklist template.
- [ ] Security/privacy has reviewed and given a thumbs up (even informally).
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.