Data Protection Atlas

Depth tiers

method editorial

What Tier 1, 2 and 3 mean, and why the tier is printed on every page rather than hidden in an editorial policy.

Coverage here is deliberately uneven. Some jurisdictions carry a full instrument-level profile; most carry a few verified facts and a link to the source. Printing the tier on the page is the honest version of that: a thin entry should read as deliberately scoped, not abandoned or half-finished.

The three tiers

Tier 1 — full instrument profile

The instrument has been run through all ten points of the asymmetry checklist, with every point answered explicitly. It records criminal liabilityCriminal liabilityProsecution in the criminal courts, separate from a regulator's fine. Different prosecutor, different standard of proof, and it can attach to an individual rather than the organisation. separately from regulatory fines, names exemptions with their trigger conditions, and flags unsettled questions as unsettled rather than stating them as fact.

Realistic cost: 4–6 hours for a well-documented, English-language instrument with a good primary source. Treat that as a floor, not a typical case — an instrument in a less-covered jurisdiction or a language other than English should be expected to cost more, not less.

Tier 2 — verified summary

Status, principal law, regulator, breach rule, headline penalty figure, and one source link. Enough to answer “what regime am I in and who enforces it”, not enough to answer “what happens if we get this wrong”.

Tier 3 — pointer

Status, law name, regulator, source link. A signpost to the primary source, nothing more.

Depth is not the same as confidence

Tier answers “how much is here”. It does not answer “has anyone checked it”. Those are separate fields, because conflating them is how a detailed-looking page ends up trusted more than it has earned.

  • provenance: verified — checked against sources by a named person on a named date, which is what lastVerified and verifiedBy record.
  • provenance: seeded — carried over from the earlier single-file prototype. The structure is sound and the facts were reasonable when written, but nobody has re-checked them here. Seeded records say so on the page, in the directory, and in the file itself.

A seeded record is a starting point for verification, not a claim. Verifying one means confirming every field against a primary source, adding the source link, setting lastVerified and verifiedBy, and flipping provenance to verified — at which point it can also rise a tier if the depth is there.

Rules that apply at every tier

  • A verified record must carry a source. A Tier 3 entry is one fact and one link; it is not one fact and a guess. Seeded records may be missing sources, which is exactly why they are capped at Tier 3 and labelled.
  • Every verified record carries lastVerified. The schema enforces it, and the staleness automation flags anything not re-checked in twelve months — which only works if the date is real.
  • “None found — checked” is an answer. Silence is not. At Tier 1 the schema enforces this: an instrument with an unanswered checklist point fails the build.
  • Unsettled means unsettled. Where the legal position is genuinely contested or awaiting case law, it is flagged, not resolved by picking the more convenient reading.

Why the tier is a schema field

Because it is load-bearing. It drives what a page renders, what the build validates, and what the review automation checks. Editorial policy that lives only in a style guide gets quietly ignored; editorial policy that lives in a Zod schema fails the build.

Last verified 25 July 2026