Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions Governance/domains/ANALYTICS_DATA.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Analytics Data Collection

This document outlines the governance process for collecting analytics data.

## Permitted Events

Only the following events are permitted to be collected:

- Page views
- Clicks
- Form submissions

## PII-Exclusion Rule

Personally Identifiable Information (PII) must not be collected. This includes, but is not limited to, the following:

- Names
- Email addresses
- Phone numbers
- IP addresses

## Opt-Out Mechanism

Users must be able to opt out of analytics data collection. An opt-out mechanism must be provided on the website.
19 changes: 19 additions & 0 deletions Governance/domains/PERFORMANCE_BUDGET.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Performance Budget

This document outlines the governance process for the performance budget.

## Budget Thresholds

The following performance budget thresholds must not be exceeded:

- First Contentful Paint (FCP): 2 seconds
- Largest Contentful Paint (LCP): 3 seconds
- Cumulative Layout Shift (CLS): 0.1

## Measurement in CI

The performance budget must be measured in Continuous Integration (CI).

## Response When Exceeded

If the performance budget is exceeded, the build must fail. The performance regression must be addressed before the build can be deployed.
21 changes: 21 additions & 0 deletions Governance/domains/PRIVACY_NOTICE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Privacy Notice

This document outlines the governance process for updating the privacy notice.

## Disclosures

The privacy notice must disclose the following:

- What personal information is collected
- How personal information is used
- With whom personal information is shared
- How personal information is protected
- The rights of individuals regarding their personal information

## Update Process

Any changes to the privacy notice must be reviewed and approved by the legal team.

## Versioning

The privacy notice must be versioned. The version number must be incremented with each change. The version number must be displayed on the privacy notice.
19 changes: 19 additions & 0 deletions Governance/domains/THIRD_PARTY_SCRIPTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Third-Party Scripts

This document outlines the governance process for using third-party scripts.

## Allowlist of Hosts

Only scripts from the following hosts are permitted:

- `*.google-analytics.com`
- `*.googletagmanager.com`
- `*.jsdelivr.net`

## CSP Requirement

A Content Security Policy (CSP) must be implemented to restrict the loading of scripts to the allowlist of hosts.

## Review Before Adding Scripts

Any new third-party scripts must be reviewed and approved by the security team before being added to the website.
Loading