Purpose before collection
Define why information is needed and collect only what is proportionate to that purpose.

Data Privacy & Responsible Technology
Public framework · September 6, 2026
Operating principles
This framework describes BAUS’s public commitments. Detailed controls are risk-based and engagement-specific. The framework is not a certification, audit report, warranty, or disclosure of confidential security architecture.
Define why information is needed and collect only what is proportionate to that purpose.
Assign accountable human owners for intake, access, decisions, retention, and incident response.
Limit information to authorized people and systems with a legitimate role in the work.
Separate public inquiry channels from authenticated client workspaces and engagement-specific controls.
Assess the role, access, security, retention, and contractual obligations of material technology providers.
Use automation to assist workflow—not to remove accountable human judgment from material advisory decisions.
Do not place client-confidential or restricted information into an AI system unless the use is authorized, appropriately governed, and covered by the engagement and provider terms.
Keep information for a defined business, contractual, security, or legal reason and dispose of it when that reason ends.
Maintain a process to identify, contain, assess, document, and respond to suspected privacy or security incidents.
Provide a channel for applicable privacy requests and improve controls as the business, technology, and legal environment change.
Engagement controls
Before sensitive information is exchanged, BAUS and the client can document roles, approved systems, access, retention, confidentiality, and any additional data-processing requirements in the engagement agreement.