Skip to main content
Joy Repair
← Back to the report

Appendix 1 · Legal Register

Data Firewall Trust Charter

Mapleton Fall Creek Community Data Trust — Legal Structure for Resident Data Sovereignty

Preamble

Mapleton Fall Creek Community Data Trust is created to hold, protect, and govern all resident data, census records, and AI-generated insights generated by the Mapleton Fall Creek Neighborhood Narrative Data System. This Trust exists to ensure that resident data belongs to residents, not to any external institution, government body, or corporate entity. The Trust is a firewall between residents and coercive state power.

I. Legal Structure & Governance

Section 1.1: Trust Form

  • Mapleton Fall Creek Community Data Trust is established as a not-for-profit charitable trust under Indiana Code § 30-4-1 et seq.
  • The Trust does NOT hold a corporate charter. It is a trust, which means it is governed by trust law, not corporate law. This distinction is critical: a trust's fiduciary duty is to its beneficiaries (residents), not to external shareholders or state regulators.
  • The Trust is registered with the Indiana Attorney General as a charitable trust and operates under its own Charter. No external funder, partner institution, or neighborhood association holds authority over the Trust; the Trust answers to its beneficiaries and to the courts.

Section 1.2: Trust Beneficiaries

  • The sole beneficiaries of this Trust are residents of Mapleton Fall Creek who voluntarily provide data to the Neighborhood Narrative Data System.
  • "Resident" is defined as any person living in the geographic boundaries of Mapleton Fall Creek for any duration, documented or undocumented.
  • Beneficiaries retain all rights to their own data, including the right to withdraw consent, request deletion, or restrict use.

Section 1.3: Trustee Role & Fiduciary Duty

  • The Trustee is a single individual or entity (often an external civil-rights attorney, the ACLU, or a designated resident fiduciary) appointed by the Governance Board for a 3-year term, renewable once.
  • The Trustee's fiduciary duty is EXCLUSIVELY to the beneficiaries (residents), not to the Governance Board, the neighborhood association, Mapleton Fall Creek institution, or any external funder.
  • The Trustee's primary duty is to REFUSE any unlawful access to resident data, whether the request comes from law enforcement, a municipal agency, a funder, or the Governance Board itself.
  • The Trustee is indemnified against any legal liability that arises from refusal to disclose data. If a government body sues the Trustee for refusing to comply with a subpoena, the Trust Charter explicitly authorizes the Trustee to use Trust funds to retain external counsel (e.g., ACLU) to defend the refusal in court.

Section 1.4: Governance Board Relationship

  • The Governance Board of Mapleton Fall Creek Community Association does NOT own the Trust or control it directly.
  • The Governance Board appoints the Trustee but cannot remove the Trustee without cause (fiduciary breach, incapacity, death).
  • The Governance Board votes on data collection policies, but the Trustee retains veto power over any policy that would compromise resident privacy or violate this Charter.
  • If the Governance Board votes to collect data that the Trustee deems unlawful or privacy-violating, the Trustee can refuse to execute the policy. The dispute is then resolved via a neutral arbitrator (see Section IV).

II. Data Ownership & Encryption

Section 2.1: Resident Data Ownership

All data provided by residents belongs to residents. The data is NOT the property of:

  • The Governance Board
  • Mapleton Fall Creek Community Association
  • Any funder or philanthropic institution
  • Any AI model provider (Anthropic or otherwise)
  • IU Indianapolis or any institutional partner
  • The City of Indianapolis or any government body

Residents retain perpetual ownership. The Trust holds the data in custody on behalf of residents.

Section 2.2: Data Classification

All resident data is classified into three tiers:

  • Tier 1 (Highly Sensitive): Health data, financial data, immigration status, family relationships, mental health, sexual history. Encrypted with 256-bit AES encryption, keys held only by Trustee + Resident quorum.
  • Tier 2 (Sensitive): Housing tenure, employment status, civic participation, neighborhood decisions. Encrypted with 128-bit AES, keys held by Trustee + Data Steward.
  • Tier 3 (Public Aggregate): Anonymized, aggregated insights published for neighborhood decision-making ("347 households report housing instability"). Encrypted in transit, public at destination.

No data moves between tiers without explicit resident consent and Trustee approval.

Section 2.3: Encryption Key Management (Shamir's Secret Sharing)

  • All Tier 1 and Tier 2 data encryption keys are split into five shards using Shamir's Secret Sharing: 3-of-5 shards required to reconstruct the key.
  • Key shards are held by:
  1. Shard 1: Trustee (stored in a secure safe, accessible only by Trustee or designated successor).
  2. Shard 2: Mapleton Fall Creek Governance Board (stored in a fireproof safe at a neighborhood institution, e.g., IU Indianapolis, accessible by a 2-person quorum).
  3. Shard 3: External Civil-Rights Organization (ACLU, EFF, or Lawyers' Committee for Civil Rights; stored at their office).
  4. Shard 4: Neighboring Federated Community (e.g., Pendleton neighborhood Data Center; stored in their vault).
  5. Shard 5: Emergency Backup (stored in a safety deposit box at a credit union, accessible only by Trustee's designated successor).
  • No single entity holds 3 shards. This prevents the Trustee, the Governance Board, or any external entity from unilaterally decrypting resident data.
  • If any 2 shards are compromised or destroyed, the remaining 3 shards can be used to reconstruct keys, re-shard, and restore data from backup (see Section III).

Section 2.4: Key Rotation & Audit

  • Encryption keys are rotated every 12 months. All data is re-encrypted with new keys; old keys are cryptographically destroyed.
  • Quarterly, an independent cryptographic audit (performed by an external firm, paid from Trust funds) verifies that: all keys are securely stored in their designated locations; no unauthorized copies of keys exist; all encrypted data remains inaccessible without 3+ shards.
  • The audit report is made public (with technical details redacted for security).

III. Data Access & Disclosure Protocols

Section 3.1: Resident Access (Default Right)

  • Any resident may request access to their own data at any time. The Trustee must provide a copy within 5 business days.
  • Residents may request deletion of their data. The Trustee must delete within 30 days (except where legal hold or contractual obligation requires retention).
  • Residents may withdraw consent to future use of their data. All future processing stops immediately.

Section 3.2: Internal Use (Governance & Decision-Making)

Data is used internally by the Governance Board for three purposes only:

  1. Neighborhood census & continuous profiling (understanding who lives in MFC, what they need).
  2. Decision support (informing resident votes on policy questions: Should we expand clinic hours? Should we invest in affordable housing?).
  3. Outcome evaluation (did the street tree initiative improve air quality? Did the affordable housing project reduce displacement?).

No resident data is shared with external parties for these purposes without explicit resident consent.

Section 3.3: External Disclosure (Extraordinary Circumstances)

The Trustee may disclose resident data to external parties ONLY in the following narrow circumstances:

  1. Resident Explicit Consent: An individual resident consents in writing to disclosure of their data to a specific external party for a specific purpose.
  2. Legitimate Legal Order: A court issues a warrant or court order (not a subpoena, which can be challenged) based on probable cause that resident data is relevant to an active criminal investigation. Even then, the Trustee must: notify the resident immediately; publish the legal order publicly; seek a court ruling to narrow or quash the order; disclose only the minimum data necessary to comply with the order.
  3. Emergency Public Health/Safety: If resident data is necessary to prevent imminent serious harm to a person (e.g., a resident discloses suicidal ideation). The Trustee must document the emergency, notify the resident afterward, and publish the disclosure within 30 days.

Section 3.4: Subpoena Refusal Protocol

If a government body (local police, state authorities, federal agencies, IRS) issues a subpoena for resident data, the Trustee DOES NOT voluntarily comply. The Trustee's protocol:

  1. Immediate Notification: Within 24 hours, notify all residents and the Governance Board that a subpoena has been received.
  2. Public Disclosure: Publish the subpoena on the neighborhood website and social media, with a notice: "A [government body] has requested resident data. Here's what they asked for. Here's what we're doing about it."
  3. Legal Challenge: Retain external counsel (funded by Trust; budget $50K-$100K annually for legal defense) to file a motion to quash the subpoena on constitutional grounds: Fourth Amendment (data is collectively held by residents; disclosure violates collective privacy rights); First Amendment (data collection is a form of political/civic association; forced disclosure chills protected speech); Data Sovereignty (residents have a right to self-determination over their own information).
  4. Resident Vote: Before any voluntary disclosure or settlement, hold a special resident vote: "Should we comply with this subpoena?" A 2/3 majority of voting residents is required for voluntary compliance.
  5. Narrow Compliance: If compelled by a final court order after all appeals are exhausted, the Trustee complies — disclosing only the minimum data necessary and redacting all sensitive information not directly responsive to the order. The Trust does not defy a final order; it makes every lawful refusal available first, in public.

Section 3.5: No Cooperation with Immigration Enforcement

  • This Trust explicitly refuses to cooperate with any federal immigration enforcement activity (ICE, CBP, or state authorities acting on immigration matters).
  • If an immigration agency requests resident data or seeks to enter the neighborhood to access servers, the Trustee: refuses all requests and demands a judicial warrant; contacts external counsel immediately (ACLU has immigration defense programs); notifies all residents; does NOT facilitate any access to resident data or infrastructure.
  • The Trust Charter includes a "Sanctuary Clause": "This Trust will not participate in immigration enforcement. Residents, regardless of immigration status, are protected by this Trust."

IV. Governance & Amendment

Section 4.1: Trust Amendment Process

This Charter may be amended only via a two-step process:

  1. Trustee Approval: The Trustee must agree that any amendment does not compromise resident data protection.
  2. Resident Supermajority Vote: 2/3 of voting residents must approve the amendment at a special neighborhood assembly.

No external funder, government body, or non-resident entity can force an amendment.

Section 4.2: Trustee Succession

If the Trustee resigns, becomes incapacitated, or dies, a successor Trustee is appointed by a two-step process:

  1. Nomination: The Governance Board nominates 3-5 candidates for Trustee (preferably external civil-rights organizations or attorneys).
  2. Resident Election: Residents vote on the successor. A simple majority wins.

During the transition, the Key Shards held by other entities (Governance Board, Civil-Rights Org, Neighboring Community) remain inaccessible until a new Trustee is installed and briefed on the encryption system.

Section 4.3: Dispute Resolution

If the Governance Board and the Trustee disagree on a data access or disclosure decision, the dispute is resolved by:

  1. Mediation: A 30-day mediation period, facilitated by an external neutral mediator (paid from Trust funds).
  2. Arbitration: If mediation fails, binding arbitration before a retired judge or arbitrator (agreed upon by both parties).
  3. Resident Appeal: If either party disputes the arbitration outcome, the matter goes to a special resident vote for final resolution.

Section 4.4: Annual Public Reporting

The Trustee publishes an annual "Data Stewardship Report" that includes:

  • Number of residents whose data is in the Trust (aggregate).
  • Number of data access requests from residents (and response times).
  • Number of data deletion requests (and compliance rate).
  • Number of subpoenas received and the Trustee's response (compliance vs. refusal).
  • Number of encryption key audits conducted.
  • Any breaches, attempted breaches, or security incidents.

The report is public. Citizens can read it. Residents can hold the Trustee accountable.

V. Funding & Trustee Independence

Section 5.1: Trust Funding

The Trust operates on an annual budget of $50K-$75K:

  • $25K: Trustee salary (part-time, 20 hours/week).
  • $15K: External legal defense fund (for subpoena challenges, warrant fights).
  • $10K: Cryptographic audits and security infrastructure.
  • $5K-$10K: Contingency (emergency legal defense, key reconstruction if disaster strikes).

Funding comes from:

  • Primary: The Mapleton Fall Creek Community Association operational budget (guaranteed annual allocation).
  • Secondary: Community donations (residents and allies can contribute to the Trust directly).
  • Emergency: If a major legal challenge arises (e.g., defending a subpoena case), crowdfunding or emergency grant from civil-rights organizations.

Section 5.2: Trustee Independence from External Funders

  • The Trustee's salary and legal defense funds are NEVER dependent on external philanthropic funding (foundation or government grants).
  • If MFC receives external funding, a covenant is inserted into every grant agreement: "No portion of this grant shall be used to fund the Trustee, the cryptographic audits, or the legal defense of resident data. These functions are funded independently and are non-negotiable."
  • This ensures the Trustee is never beholden to external funders and can freely refuse funder requests for data access.

VI. Integration with Mapleton Fall Creek Governance

Section 6.1: Relationship to Community Association Charter

  • This Data Firewall Trust Charter is a SUBORDINATE document to the Mapleton Fall Creek Community Association Charter, but it is BINDING on all parties (Governance Board, Trustee, external partners).
  • In case of conflict between the Trust Charter and the Association Charter, the Trust Charter prevails on all matters relating to resident data protection and disclosure.

Section 6.2: Data Steward Relationship

  • The Data Steward (employed by the Community Association, $60K-$80K/year) manages day-to-day data operations: collection, cleaning, processing, storage.
  • The Trustee is NOT the Data Steward. The Trustee oversees the Data Steward and has the power to fire or restrict the Data Steward's access if they violate data protection protocols.
  • The Data Steward reports to both the Governance Board AND the Trustee (dual accountability).

Section 6.3: Institutional Partner Agreements

IU Indianapolis, health systems, nonprofits, and other institutions that provide data or receive insights from the Trust must sign an "Institutional Data Use Agreement" that:

  • Acknowledges resident data ownership.
  • Commits to no further sharing or sale of data.
  • Requires Trustee approval for any research use of aggregate data.
  • Includes audit rights (Trustee can audit institutional partners' use of data).
  • Specifies penalties for breach (data access revocation, legal liability, public notification).

VII. Effectiveness & Enforcement

Section 7.1: Enforcement of Resident Rights

If the Trustee or any party violates this Charter, a resident or group of residents may:

  1. File a complaint with the Trustee (if the Governance Board is the violator).
  2. File a complaint with the Governance Board (if the Trustee is the violator).
  3. Seek a court order to enforce the Charter (resident standing is automatic; residents have legal standing to sue to protect their own data).
  4. Remove the Trustee or board members via recall (see Governance Guardrails).

Section 7.2: Breach Notification

If resident data is compromised, stolen, or illegally accessed, the Trustee must:

  • Notify all affected residents within 48 hours.
  • Publish a public disclosure within 5 business days.
  • Document the breach, the scope, and the remediation measures.
  • Offer free credit monitoring or identity theft insurance (cost covered by Trust emergency fund).

Section 7.3: Sunset & Perpetuity

  • This Charter is perpetual. It continues even if MFC's data center shuts down, is damaged, or is replaced.
  • If MFC ceases to operate, the Trust and all resident data pass to a federated partner neighborhood (per pre-established agreement) or to an external civil-rights organization that commits to the same data protection principles.
  • The Trust never dissolves. Resident data protection is forever.

Signature & Adoption

This Charter is adopted by Mapleton Fall Creek Community Association on [DATE] and is binding on all parties effective immediately.

  • Governance Board Chair: __________________ [Signature]
  • Trustee: __________________ [Signature]
  • Resident Representative (Sortition): __________________ [Signature]
  • Resident Representative (Sortition): __________________ [Signature]