Groundskeeper

Australian PII taxonomy and evidence model

Classification principles

Groundskeeper reports a hierarchical public category and may retain a concise detector-internal entity label. A number that merely matches a length is not automatically PII. Detection combines candidate shape, published structural validation where available, local/document context, correlated entities and reference data, and a versioned calibrated score.

Validation states are:

  • candidate — shape matched but corroboration is insufficient;
  • probable — contextual evidence supports the classification;
  • validated — a published checksum or authoritative reference validation succeeded.

validated means validly formed, not that the identifier belongs to a person.

Structured detector classes

Groundskeeper supports both classes approved in ADR 0010:

  • validated_structured uses an authoritatively published grammar and, where available, checksum. The class name describes the source quality of the detector definition; a runtime match is not automatically validation_state: validated.
  • context_bound_structured requires an approved exact issuer/document label or structured field plus jurisdiction where applicable. The same bare value must not produce a finding. A broad regex is candidate generation, not evidence.

The first pair, HPI-I (validated_structured) and the exact-labelled Victorian Student Number (context_bound_structured), is specified in the structured-detector micro-slice. They are implemented as experimental built-ins and are disabled by default. They are approved for observe and redact use only, up to G2, and must not be used for blocking or production enforcement before legal and privacy review and G3.

Confidence is calibrated separately. Validated-structured confidence measures local structural plausibility; context-bound confidence measures joint label/field, jurisdiction, and candidate support. Only a published checksum, reference validation, or approved authoritative lookup can produce validated.

The additional identifier inventory contains 59 sourced records and 54 authoritative sources. Its include records feed the validated-structured backlog (while retaining documented context gates), context_only records feed the context-bound backlog, and exclude records do not produce detectors. Inventory taxonomy IDs are catalogue IDs and require an explicit mapping to the public categories below before implementation.

Initial taxonomy

EntityPublic categoryInitial evidence posture
TFNprivacy.pii.tax_id.au.tfncontextual/format candidate; controlled validation decision open
ABNprivacy.pii.tax_id.au.abnpublished 11-digit mod-89 structural validation
ACNprivacy.pii.organization_id.au.acncandidate only until algorithm source is approved (OD-018)
Medicare numberprivacy.pii.health_id.au.medicarepublished ten-digit structure and mod-10 check
IHIprivacy.pii.health_id.au.ihi16 digits, 800360 prefix, Luhn validation
HPI-Iprivacy.pii.health_id.au.hpi_i (provisional)16 digits, 800361 prefix, Luhn validation; experimental built-in
Centrelink CRNprivacy.pii.government_id.au.crncontextual format: nine digits plus a letter
USIprivacy.pii.education_id.au.usicontextual format: ten allowed characters, never all numeric
Victorian Student Numberprivacy.pii.education_id.au.vic.vsn (provisional)context-bound: nine digits plus an exact issuer label or field; the bare VSN acronym without Victorian context is candidate only; never validated; experimental built-in
Director IDprivacy.pii.organization_id.au.director_idcontextual format: 15 digits beginning 036
Driver licenceprivacy.pii.driver_license.aucontextual/state refinement; DVS decision open
Passportprivacy.pii.passport.aucontextual format; DVS decision open
BSB and accountprivacy.pii.bank_account.aucorrelated/contextual only
Addressprivacy.pii.address.aumulti-token/context/reference evidence
Phoneprivacy.pii.phone_number.auparsed Australian format plus context

Generic categories also cover email, IP address, payment card, API key, access token, password, and private key. Taxonomy hierarchy is a public compatibility surface; detector implementation names are not.

Published structural validators

  • ABN: normalize permitted separators, require 11 digits, subtract one from the first digit, multiply by weights 10,1,3,5,7,9,11,13,15,17,19, and require the sum to be divisible by 89.
  • Medicare: require ten digits: eight-digit base, check digit, issue number; first digit 2–6; multiply the first eight digits by 1,3,7,9,1,3,7,9; the sum modulo 10 equals the ninth digit. This is structural, not entitlement checking.
  • IHI: require 16 digits with prefix 800360 and a valid Luhn check.

Implementations must cite and pin the authoritative source reviewed at coding time. Algorithms not established by current research are not inferred by analogy. Do not remotely test live credentials or identifiers to establish validity.

Contextual evidence

Evidence may include:

  • normalized shape and separators;
  • checksum/reference result and validator version;
  • nearby labels (for example, Medicare or ABN);
  • exact issuer/document labels and jurisdiction for context-bound detectors;
  • JSON Pointer or form-field name;
  • document type and protocol operation;
  • source and intended destination class;
  • nearby corroborating entities;
  • tenant-approved application schema;
  • negative terms such as invoice, order, build, and ticket;
  • reference dataset name and version;
  • calibrated scorer version.

Evidence is a typed descriptor, not a copy of the sensitive value. A keyed fingerprint may support false-positive review when operator-approved. A postcode or common nine-digit number in isolation cannot establish an address or TFN.

Australian addresses

Treat an address as a collection of components: unit/level, street number and name, street type, locality/suburb, state, postcode, and delivery forms such as PO Box, GPO Box, or Locked Bag. Australia Post and AS 4590 components inform parsing. A postcode regex alone is never an address detector.

G-NAF is the preferred open reference candidate where its current EULA permits the intended use. Keep it in a separately versioned PostgreSQL/PostGIS database or schema and atomically swap dataset versions. pg_trgm can retrieve fuzzy locality/street candidates. Commercial PAF use requires procurement. Legal review must confirm attribution, redistribution, update, and mail-generation obligations before deployment (OD-017).

Redaction and policy

Detectors return exact code-point spans and evidence. Policy separately decides whether to allow, block, redact, or record a finding. Overlapping redactions with the same replacement merge into their union. Overlapping redactions with different replacements fail closed: the evaluator blocks and reports a failed evaluation.modifications coverage entry instead of choosing one. Category-specific replacement and reversible tokenisation remain open decisions; examples must not imply that all identifiers have the same handling requirements.

On this page