Skip to the book

NOMOS GBO Audit Protocol

References

Download the free PDF

The sources below support particular technical and legal distinctions. They do not demonstrate that the NOMOS method has been tested, adopted or endorsed by these institutions. The book’s synthetic examples are not research findings drawn from these publications. Accessed on 9 September 2026.

This book is not a certificate of legal compliance. Obligations concerning data processing, record keeping, erasure, appeals and human review depend on the applicable law and the facts of the case. A country name, a language version or internal approval cannot replace that assessment. Europe must not be treated as a single jurisdiction.

[1] Choose Gmail API scopes

Google for Developers

https://developers.google.com/workspace/gmail/api/auth/scopes

The Gmail gmail.compose scope includes sending as well as draft management. The book’s proposal for a draft-only tool boundary does not claim that Google provides a draft-only scope.

[2] Secure Hash Standard FIPS 180-4

National Institute of Standards and Technology

https://csrc.nist.gov/pubs/fips/180-4/upd1/final

Cited for the role of cryptographic digests in detecting change. Reliable acquisition of the source, truth of the claim and selection of the authoritative record are assessed separately.

[3] Digital Signature Standard FIPS 186-5

National Institute of Standards and Technology

https://csrc.nist.gov/pubs/fips/186-5/final

Cited for the role of digital signatures in integrity and linkage to a signing key. An ordinary approval log, identity matching and organisational decision-making authority are not the same evidence.

[4] Special-Use Domain Names

Internet Assigned Numbers Authority

https://www.iana.org/assignments/special-use-domain-names

Synthetic domain names use .example and its subdomains. They are not addresses supplied for contacting real customers or testing a live system.

[5] OAuth 2.0 Token Revocation — RFC 7009

Internet Engineering Task Force

https://www.rfc-editor.org/rfc/rfc7009.html

An OAuth revocation response and loss of access across every resource are not the same observation. The client’s duty not to use a revoked token remains. Independent verification should use authorisation-server evidence or a separate controlled test.

[6] Data controller or data processor

European Data Protection Board

https://www.edpb.europa.eu/sme/learn-the-basics/data-controller-or-data-processor_en

The legal roles of controller and processor are distinguished from internal technical or operational titles. The actual role is assessed from the real processing activity.

[7] Process personal data lawfully

European Data Protection Board

https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en

Consent is one lawful basis under the GDPR. The book’s explicit-consent condition for particular voice and facial-use scenarios is not generalised as the sole basis for all processing.

[8] Veri Sorumlusu Kimdir?

Kişisel Verileri Koruma Kurumu

https://www.kvkk.gov.tr/Icerik/2032/Veri-Sorumlusu-Kimdir

The controller role under Turkish data-protection law is not equated with merely holding a dataset or managing a team.

[9] Özel Nitelikli Kişisel Verilerin İşlenmesine İlişkin Rehber — duyuru

Kişisel Verileri Koruma Kurumu

https://www.kvkk.gov.tr/Icerik/8184/Ozel-Nitelikli-Kisisel-Verilerin-Islenmesine-Iliskin-Rehber

The 2024 change concerning special-category personal data is taken into account. The availability of statutory conditions other than consent does not automatically authorise a particular audit test.

[10] HTTP Semantics — RFC 9110

Internet Engineering Task Force

https://www.rfc-editor.org/rfc/rfc9110.html

The HTTP response, requested operation and provider contract are read together. A 202 response does not guarantee completion. Preservation of an intended effect across repeated requests is distinguished from the mere existence of a transaction identifier. The example tools’ real uniqueness and external-outcome guarantees require separate verification.