# Lundy × Science — the data firewall

**LOCAL-APPROVAL — SIGNED at the DSL sitting, 2026-08-05.** Ledger row:
`quality/toolkits/PENDING_APPROVALS.md`. First recorded 2026-08-04 as Matt's confirmation of the
wording only, explicitly *not* a minuted sitting, because none had then occurred; **the sitting has
since happened and covered this row**, so the caveat is discharged rather than left standing. PR #33
merged on the same sitting (`e5d6aed`), and where this file and #33's outcome ever differ, **#33 wins
and this file is corrected.** The approval is a human read of the wording in this file, not of a
summary of it, and **no instrument witnessed it.**

**STATUS: draft · OWNER: Matt · Pass LL-S1, 2026-08-04 · review-by 1 September 2026**
**Intended users: staff-facing. No pupil-facing surface. Ledger row: `quality/toolkits/PENDING_APPROVALS.md`.**

> **This file asserts nothing that PR #33 has not settled.** #33 (`semh1-safeguarding`) is held on the
> DSL sitting, and the firewall wording and the unsaved *"safeguarding handoff made"* tick are on that
> agenda. Nothing below approves either, extends either, or presumes their outcome. Where this file and
> #33's outcome differ, **#33 wins and this file is corrected.**

**Extends, does not restate.** The estate's firewall already exists in
`quality/toolkits/DATA_GOVERNANCE.md` and `quality/SAFEGUARDING_CONTENT_GATE.md`. This file adds only
what is specific to Science evidence — captions, practical work, group data and photographs — and
defers everything else.

---

## The boundary, in one sentence

**A disclosure leaves the ordinary evidence workflow entirely.** It never enters a caption, a queue, a
board, a handoff note, a portfolio note, a moderation sample or a conversation about next steps. It
goes to the DSL by the school's safeguarding route, and the record lives in the safeguarding system —
not in Science evidence, not in an ordinary cloud folder, not in a pupil portfolio.

The wording that sits beside a free-text field is **already ruled and is used verbatim** from
`DATA_GOVERNANCE.md`:

> **Not for disclosures.** If a pupil tells you something that worries you, it goes to the DSL by the
> school's safeguarding route — never into this box.

## Statutory version gate — carried, with its owner

Carried verbatim from `quality/SAFEGUARDING_CONTENT_GATE.md` Gate 1, which is the **owning record**:

- **KCSIE 2025 is statutory until 31 August 2026.**
- **KCSIE 2026 is in force from 1 September 2026.**

A resource must not say "KCSIE 2026" without the effective date. These are marked in the owning record
as `supplied-by-audit 2026-08-04, review-by 2026-09-01, verify-live: Matt` — the agent environment has
no egress and cannot reach official sources, so **they are not independently verified here.**

## Science-specific: where a disclosure actually turns up

Named because these are the moments the general rule is hardest to apply, not because they are new rules.

| moment | the risk | what happens |
|---|---|---|
| **A written caption or evaluation** | a pupil writes something concerning while explaining their evidence | stop the evidence task; the disclosure does not become part of the artefact; DSL route |
| **Health, food, body or family content** | nutrition, digestion and health topics invite personal disclosure | keep routes fictional by default (`SAFEGUARDING_CONTENT_GATE.md` Gate 5); a pass is genuine |
| **A photograph** | faces, uniforms, backgrounds, other pupils | work not faces, unless consent is filed; a photo is never required where the sheet, table or drawing is stronger |
| **Group practical data** | one pupil's contribution identifies a wider circumstance | record the science; the pupil's role, not their situation |
| **A verbal aside during practical work** | said to an adult mid-task, never written | the safeguarding route is unchanged by the fact it was spoken |

## What no Science evidence artefact may contain

- a disclosure, a safeguarding narrative, or a wellbeing check-in;
- a diagnosis, a support-plan detail, or a reason-for-placement;
- a pupil's full name where an approved learner reference serves;
- an unapproved personal-device capture;
- **initials treated as anonymous** — in a small SEMH setting, initials plus a class plus a date can
  identify a child. **Pseudonymisation is not anonymisation** (`DATA_GOVERNANCE.md`).

## What this file does not decide

Deliberately out of scope, because deciding them here would assert what has not been settled:

- the approved platform, folder structure, learner-reference convention or filename pattern;
- retention and deletion schedules — proposed defaults live in `DATA_GOVERNANCE.md` and are
  **PENDING-LOCAL-APPROVAL (DPO/SLT)**;
- which roles may capture, review, upload, correct or delete;
- photo and video permission rules and the device estate;
- the wording or existence of any *"safeguarding handoff made"* state — **that is PR #33's**;
- whether any evidence route is approved at all. **No upload workflow is authorised by this file.**

## Standing rule

**A disclosure copied into an evidence export is a safeguarding failure wearing an evidence costume**
(`DATA_GOVERNANCE.md`). Nothing in Science evidence practice may make that easier to do by accident —
which is the whole reason the boundary is written as *leaves the workflow entirely* rather than
*is handled carefully*.
