The sources below support particular technical and legal distinctions. They do not demonstrate that the NOMOS method has been tested, adopted or endorsed by these institutions. The book’s synthetic examples are not research findings drawn from these publications. Accessed on 9 September 2026.
This book is not a certificate of legal compliance. Obligations concerning data processing, record keeping, erasure, appeals and human review depend on the applicable law and the facts of the case. A country name, a language version or internal approval cannot replace that assessment. Europe must not be treated as a single jurisdiction.
[1] Choose Gmail API scopes
Google for Developers
https://developers.google.com/workspace/gmail/api/auth/scopes
The Gmail gmail.compose scope includes sending as well as draft management. The book’s proposal for a draft-only tool boundary does not claim that Google provides a draft-only scope.
[2] Secure Hash Standard FIPS 180-4
National Institute of Standards and Technology
https://csrc.nist.gov/pubs/fips/180-4/upd1/final
Cited for the role of cryptographic digests in detecting change. Reliable acquisition of the source, truth of the claim and selection of the authoritative record are assessed separately.
[3] Digital Signature Standard FIPS 186-5
National Institute of Standards and Technology
https://csrc.nist.gov/pubs/fips/186-5/final
Cited for the role of digital signatures in integrity and linkage to a signing key. An ordinary approval log, identity matching and organisational decision-making authority are not the same evidence.
[4] Special-Use Domain Names
Internet Assigned Numbers Authority
https://www.iana.org/assignments/special-use-domain-names
Synthetic domain names use .example and its subdomains. They are not addresses supplied for contacting real customers or testing a live system.
[5] OAuth 2.0 Token Revocation — RFC 7009
Internet Engineering Task Force
https://www.rfc-editor.org/rfc/rfc7009.html
An OAuth revocation response and loss of access across every resource are not the same observation. The client’s duty not to use a revoked token remains. Independent verification should use authorisation-server evidence or a separate controlled test.
[6] Data controller or data processor
European Data Protection Board
https://www.edpb.europa.eu/sme/learn-the-basics/data-controller-or-data-processor_en
The legal roles of controller and processor are distinguished from internal technical or operational titles. The actual role is assessed from the real processing activity.
[7] Process personal data lawfully
European Data Protection Board
https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en
Consent is one lawful basis under the GDPR. The book’s explicit-consent condition for particular voice and facial-use scenarios is not generalised as the sole basis for all processing.
[8] Veri Sorumlusu Kimdir?
Kişisel Verileri Koruma Kurumu
https://www.kvkk.gov.tr/Icerik/2032/Veri-Sorumlusu-Kimdir
The controller role under Turkish data-protection law is not equated with merely holding a dataset or managing a team.
[9] Özel Nitelikli Kişisel Verilerin İşlenmesine İlişkin Rehber — duyuru
Kişisel Verileri Koruma Kurumu
https://www.kvkk.gov.tr/Icerik/8184/Ozel-Nitelikli-Kisisel-Verilerin-Islenmesine-Iliskin-Rehber
The 2024 change concerning special-category personal data is taken into account. The availability of statutory conditions other than consent does not automatically authorise a particular audit test.
[10] HTTP Semantics — RFC 9110
Internet Engineering Task Force
https://www.rfc-editor.org/rfc/rfc9110.html
The HTTP response, requested operation and provider contract are read together. A 202 response does not guarantee completion. Preservation of an intended effect across repeated requests is distinguished from the mere existence of a transaction identifier. The example tools’ real uniqueness and external-outcome guarantees require separate verification.

