FDE ACADEMY · MODULE 01 · LESSON 03
Constraints are the design
Where the data may go, who may see it, what must be kept or deleted, and what it may cost. Four answers that decide the architecture before a single tool is chosen.
- Effort
- About an hour, most of it spent finding who is allowed to answer.
- Skills
- compliance-governance · change-management
Free and self-paced. No certification is offered.
Before you startYou have a first slice from lesson 02 and know what artefacts it touches.
01The four that change the architecture
Tooling preferences are noise. Four constraints are not, because each one can eliminate an entire class of solution: where the data may go, who may see it, how long it must be kept or how quickly it must be destroyed, and what it may cost to run.
Ask them in that order. The first has the largest blast radius: “no client documents may leave our tenancy” removes every hosted assistant from the shortlist, and it is better to learn that in week one than in the security review.
- Residency and egress — which systems may receive the data, and in which country it may rest.
- Access — who inside the organisation may see which material, and where that is currently enforced.
- Retention — what must be kept, for how long, and what must be provably destroyed on request.
- Cost — the recurring budget, and who signs for hardware as opposed to a subscription.
02Policy, obligation, or preference
Write next to every constraint where it comes from. A statutory obligation, a regulator’s published expectation, a clause in a client retainer, an internal policy, or one person’s preference. They are not the same and they do not survive pressure equally.
This site draws the same line in its data: a legal requirement, a recommended practice and our recommendation are stored as three different things, and the compliance pages label which is which. Copy that discipline into your notes and the difficult conversation in week three becomes short.
03The constraint nobody states
Confidentiality is usually the binding one and it is rarely on anyone’s list, because it is not a privacy question. A law firm’s files are confidential whether or not they contain personal data, and the duty comes from the retainer, the common law and professional rules rather than from a privacy ordinance.
If your customer is a professional-services firm, ask about the retainers and the professional rules explicitly. They will often be the reason a self-hosted stack is the only acceptable answer.
04Do this
PRACTICAL TASK
Build the constraints record and test it against a jurisdiction
Write the four constraints for your slice with a source next to each, then check them against the common enterprise issues published for your customer’s jurisdiction.
What you need
- Your first slice from lesson 02
- Access to whoever owns policy — usually not the person who briefed you
Steps
- 01
Write the four constraints as sentences with a subject: “client documents may not be transmitted to a third-party model provider”, not “data security is important”.
- 02
Label each one legal requirement, recommended practice, contractual, internal policy, or preference — and name the document it comes from.
- 03
Open the jurisdiction page for your customer and read the common enterprise issues. For each of the five, write whether you saw evidence of it in the room.
- 04
If your customer is elsewhere, use the jurisdiction index and read the framework section for the right one before you continue.
- 05
Mark any constraint you could not source. Those are the ones to resolve before design, because each one is a decision waiting to be reversed.
You are done when
- Four constraints, each a sentence with a subject, each labelled by where it comes from.
- You can say which single constraint eliminates the most options, and which class of solution it eliminates.
- You have read the common enterprise issues for the right jurisdiction and matched each against what you observed.
05Where these facts live
This lesson does not restate anything that is already recorded with its evidence elsewhere on the site. These are the pages it leans on.
- Hong Kong
Framework, regulators, the instruments in force, and the issues that recur in enterprise deployments.
- How we research
Why a legal requirement, a recommended practice and our recommendation are stored and labelled separately.
- Data residency is not compliance
Why a constraint a customer states as “keep it in Hong Kong” is rarely the constraint that actually binds the design.
Ticks are stored in your browser only. They are not sent anywhere, they are not attached to an account, and clearing your browser data removes them.