From d78cb6ea7c9145738d72dbdaff0404d8551ca409 Mon Sep 17 00:00:00 2001 From: Bilkee Date: Fri, 25 Sep 2026 10:53:35 +0100 Subject: [PATCH 1/4] feat(governance): add privacy notice policy --- Governance/domains/PRIVACY_NOTICE.md | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 Governance/domains/PRIVACY_NOTICE.md diff --git a/Governance/domains/PRIVACY_NOTICE.md b/Governance/domains/PRIVACY_NOTICE.md new file mode 100644 index 00000000..00b6c22a --- /dev/null +++ b/Governance/domains/PRIVACY_NOTICE.md @@ -0,0 +1,21 @@ +# Privacy Notice + +This document outlines the governance process for updating the privacy notice. + +## Disclosures + +The privacy notice must disclose the following: + +- What personal information is collected +- How personal information is used +- With whom personal information is shared +- How personal information is protected +- The rights of individuals regarding their personal information + +## Update Process + +Any changes to the privacy notice must be reviewed and approved by the legal team. + +## Versioning + +The privacy notice must be versioned. The version number must be incremented with each change. The version number must be displayed on the privacy notice. From d2c78f24f587e57a6bf49c8a1631fb5687ab9649 Mon Sep 17 00:00:00 2001 From: Bilkee Date: Fri, 25 Sep 2026 10:54:03 +0100 Subject: [PATCH 2/4] feat(governance): add analytics data-collection policy --- Governance/domains/ANALYTICS_DATA.md | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 Governance/domains/ANALYTICS_DATA.md diff --git a/Governance/domains/ANALYTICS_DATA.md b/Governance/domains/ANALYTICS_DATA.md new file mode 100644 index 00000000..a11c2ed5 --- /dev/null +++ b/Governance/domains/ANALYTICS_DATA.md @@ -0,0 +1,24 @@ +# Analytics Data Collection + +This document outlines the governance process for collecting analytics data. + +## Permitted Events + +Only the following events are permitted to be collected: + +- Page views +- Clicks +- Form submissions + +## PII-Exclusion Rule + +Personally Identifiable Information (PII) must not be collected. This includes, but is not limited to, the following: + +- Names +- Email addresses +- Phone numbers +- IP addresses + +## Opt-Out Mechanism + +Users must be able to opt out of analytics data collection. An opt-out mechanism must be provided on the website. From 6dff2adc7b723e64be7b9814d9e94ee0aa215889 Mon Sep 17 00:00:00 2001 From: Bilkee Date: Fri, 25 Sep 2026 10:54:23 +0100 Subject: [PATCH 3/4] feat(governance): add third-party script policy --- Governance/domains/THIRD_PARTY_SCRIPTS.md | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100644 Governance/domains/THIRD_PARTY_SCRIPTS.md diff --git a/Governance/domains/THIRD_PARTY_SCRIPTS.md b/Governance/domains/THIRD_PARTY_SCRIPTS.md new file mode 100644 index 00000000..71a7e3a0 --- /dev/null +++ b/Governance/domains/THIRD_PARTY_SCRIPTS.md @@ -0,0 +1,19 @@ +# Third-Party Scripts + +This document outlines the governance process for using third-party scripts. + +## Allowlist of Hosts + +Only scripts from the following hosts are permitted: + +- `*.google-analytics.com` +- `*.googletagmanager.com` +- `*.jsdelivr.net` + +## CSP Requirement + +A Content Security Policy (CSP) must be implemented to restrict the loading of scripts to the allowlist of hosts. + +## Review Before Adding Scripts + +Any new third-party scripts must be reviewed and approved by the security team before being added to the website. From a29dc423292acf477fe133f0cebeda928f6d4dbe Mon Sep 17 00:00:00 2001 From: Bilkee Date: Fri, 25 Sep 2026 10:56:10 +0100 Subject: [PATCH 4/4] feat(governance): add performance budget policy --- Governance/domains/PERFORMANCE_BUDGET.md | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100644 Governance/domains/PERFORMANCE_BUDGET.md diff --git a/Governance/domains/PERFORMANCE_BUDGET.md b/Governance/domains/PERFORMANCE_BUDGET.md new file mode 100644 index 00000000..5681cf6c --- /dev/null +++ b/Governance/domains/PERFORMANCE_BUDGET.md @@ -0,0 +1,19 @@ +# Performance Budget + +This document outlines the governance process for the performance budget. + +## Budget Thresholds + +The following performance budget thresholds must not be exceeded: + +- First Contentful Paint (FCP): 2 seconds +- Largest Contentful Paint (LCP): 3 seconds +- Cumulative Layout Shift (CLS): 0.1 + +## Measurement in CI + +The performance budget must be measured in Continuous Integration (CI). + +## Response When Exceeded + +If the performance budget is exceeded, the build must fail. The performance regression must be addressed before the build can be deployed.