Groundskeeper

Indigenous Data Governance requirements

Authority, not an engineering checklist

Groundskeeper must establish a paid Aboriginal and Torres Strait Islander governance body with approval, veto, and stop-use authority before collecting or using relevant community-derived material. Engineering, legal access, public availability, and an open licence do not substitute for community authority.

The body's composition, compensation, quorum, representation, escalation, withdrawal/deletion service levels, and release process are unresolved decisions OD-014 and OD-015. This document defines minimum safeguards, not those answers.

Required controls

  • Include Indigenous approval in releases affecting relevant detectors, policies, datasets, or evaluation slices.
  • Record item-level source and lineage, cultural/community authority, purpose, licence, consent, permitted and prohibited uses, access, retention, redistribution, external judging, withdrawal rights, and deletion propagation.
  • Keep community-controlled data private where required, regardless of whether the platform could technically distribute it.
  • Require human/governance review before adding community-derived examples.
  • Do not send such material to external model judges without explicit approval for that destination and purpose.
  • Make stop-use and withdrawal operational: block new use, remove active snapshots, identify derivatives, and produce auditable deletion/retention outcomes.

Prohibited inference

Groundskeeper may detect sensitive data but must not infer whether a person is Indigenous from names, language, accent, Aboriginal English, appearance, postcode, location, associations, embedding similarity, or other proxies. PostgreSQL, PostGIS, and vector retrieval must never answer whether a person is Indigenous or whether a name or community reference implies identity.

Restricted material

Do not ingest the following without explicit community-controlled governance and purpose-specific approval:

  • web-scraped language or cultural material;
  • secret or sacred material;
  • deceased-person material;
  • biometrics or genetics;
  • high-risk policing, health, child-protection, or similar administrative data.

Evaluation and evidence gap

Where approved, evaluate false positives and disparate blocking separately using paired language/orthography tests without attaching identity labels to people. There is no robust published Australian baseline in the completed research for guardrail false-positive rates affecting Indigenous names, language, or Aboriginal English. Do not invent one; community-governed measurement is required.

Synthetic generation is not automatically safe: it can reproduce restricted material, encode stereotypes, or bypass authority. Proposed generators and prompts are governed data-processing methods and need review.

Reference framework

The initial governance work should be developed with, not merely checked against:

  • Maiam nayri Wingara Indigenous Data Sovereignty principles;
  • AIATSIS Code of Ethics and Guide;
  • Lowitja Institute Indigenous Data Sovereignty resources;
  • NIAA Framework for Governance of Indigenous Data;
  • OAIC privacy and AI guidance;
  • ABS Indigenous Status Standard;
  • National AI Centre Guidance for AI Adoption.

Access and licence conditions differ at item level. Research identified examples ranging from CC BY 4.0 to all-rights-reserved, paid/member access, CC BY-NC-ND, CC BY-NC-SA, and recordings with individual restrictions. Maintain item-level provenance; collection-level metadata licensing does not establish permission to train, redistribute, externally judge, or expose underlying content.

Product and release integration

Governance decisions must be machine-enforceable where possible: dataset manifests, policy compiler gates, external-destination denylists, expiry/withdrawal status, snapshot lineage, and release approvals. A technical control cannot replace human authority, but a human decision that is not enforced in deployment is insufficient.

On this page