Network Working Group S. Das Internet-Draft Independent Inventor Intended status: Informational 27 August 2026 Expires: 28 February 2027 Access Is Not Egress: Precision-Bounded Location Release draft-das-precision-bounded-egress-01 Abstract A device may legitimately possess exact location while an application, SDK, AI agent, analytics library, or foreign endpoint is entitled only to a coarser representation, a delayed or randomized representation, or no location at all. Operating system permission to read a fix does not answer whether that fix may leave the device at the requested precision. This document defines a precision-bounded egress profile on top of execution finality. A proposed release is a Location-Release Candidate Act and remains non-effective while a Protected Enforcement Domain evaluates purpose, requester, component, recipient, destination, jurisdiction, required precision, policy and revocation state, cumulative disclosure state, and intended egress sink. The sink independently verifies scoped non-bearer authority against the actual outbound payload immediately before release. The permitted result may be exact data, a reduced representation, or denial. Data access is not data-export authority. Precise GPS access is not precise GPS-release authority. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 28 February 2027. Das Expires 28 February 2027 [Page 1] Internet-Draft Access-Not-Egress August 2026 Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 3 2. Requirements Language . . . . . . . . . . . . . . . . . . . . 3 3. Terminology . . . . . . . . . . . . . . . . . . . . . . . . . 4 4. Problem Scope . . . . . . . . . . . . . . . . . . . . . . . . 5 5. Relationship to Existing Mechanisms . . . . . . . . . . . . . 5 5.1. Operating-System Location Permissions . . . . . . . . . . 6 5.2. W3C Geolocation and Permission Policy . . . . . . . . . . 6 5.3. Coarsening, Fuzzing, and Differential Privacy . . . . . . 6 5.4. Path-Level Privacy Controls . . . . . . . . . . . . . . . 6 5.5. What This Profile Adds . . . . . . . . . . . . . . . . . 6 6. Architecture . . . . . . . . . . . . . . . . . . . . . . . . 7 7. Precision-Bounded Egress Profile . . . . . . . . . . . . . . 8 7.1. Precision Ladder . . . . . . . . . . . . . . . . . . . . 8 7.2. PED Predicates . . . . . . . . . . . . . . . . . . . . . 8 7.3. Worked Example . . . . . . . . . . . . . . . . . . . . . 9 7.4. Cumulative Disclosure . . . . . . . . . . . . . . . . . . 9 7.5. Jurisdiction-Neutral Policy Input . . . . . . . . . . . . 10 7.6. Sink Placement and Alternate Paths . . . . . . . . . . . 10 8. JSON Interoperability Profile . . . . . . . . . . . . . . . . 10 8.1. LocationReleaseCandidate Object . . . . . . . . . . . . . 10 8.2. Precision Decision Object . . . . . . . . . . . . . . . . 14 8.3. EgressFinalityAuthority Object . . . . . . . . . . . . . 14 8.4. EgressSinkVerify Request and Response . . . . . . . . . . 15 8.5. Precision-Mismatch Denial . . . . . . . . . . . . . . . . 17 8.6. Complete Exact-to-Coarse Transaction . . . . . . . . . . 18 8.7. Cumulative Disclosure Extension . . . . . . . . . . . . . 20 9. Protocol Operation . . . . . . . . . . . . . . . . . . . . . 20 9.1. Digest and Substitution . . . . . . . . . . . . . . . . . 20 9.2. Sink Verification . . . . . . . . . . . . . . . . . . . . 20 9.3. Hot Path and Escalation . . . . . . . . . . . . . . . . . 21 9.4. Failure Codes . . . . . . . . . . . . . . . . . . . . . . 21 10. Security Considerations . . . . . . . . . . . . . . . . . . . 22 Das Expires 28 February 2027 [Page 2] Internet-Draft Access-Not-Egress August 2026 11. Privacy Considerations . . . . . . . . . . . . . . . . . . . 22 12. Data-Sovereignty Considerations . . . . . . . . . . . . . . . 23 13. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 23 14. Intellectual Property Note . . . . . . . . . . . . . . . . . 23 15. Conclusion . . . . . . . . . . . . . . . . . . . . . . . . . 23 16. Normative References . . . . . . . . . . . . . . . . . . . . 23 17. Informative References . . . . . . . . . . . . . . . . . . . 24 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 24 1. Introduction Consider an assistant asked to find nearby pharmacies, or a weather application asked for a local forecast. The device already has a high-accuracy coordinate. The external service does not need that coordinate. City or region is sufficient. Under ordinary permission models the application that may read exact GPS is also, in practice, the component that may transmit it — including through an SDK, agent tool call, telemetry path, or cloud sync that the user never saw as a separate disclosure. This document treats the outbound release as the consequence that must be authorized. Local access may remain. Exact coordinates remain non-effective for external disclosure until purpose, recipient, destination, jurisdiction, precision ceiling, policy epoch, and sink binding have been verified. If exact precision is unnecessary, the Protected Enforcement Domain issues authority only for a coarser representation. If the application later places exact latitude and longitude on the wire, the egress Finality Sink detects a precision mismatch and the release stays non-effective. The profile uses the two-boundary execution-finality chain defined for AI-native network control in [I-D.das-6g-finality] and discussed for general AI interoperability in [I-D.das-ef-interop]: Candidate Act, Non-Effective State, Protected Enforcement Domain, protected validation evidence, scoped non-bearer finality authority, and independent Finality Sink verification. This document specifies only the location- and data-egress predicates, the precision ladder, cumulative-disclosure handling, and the JSON objects for that profile. 2. Requirements Language The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. Das Expires 28 February 2027 [Page 3] Internet-Draft Access-Not-Egress August 2026 Failure to establish current finality authority MUST NOT be converted into permission to release protected location or other sensitive data. 3. Terminology Location-Release Candidate Act A Candidate Act whose intended consequence is external disclosure of location or a location-derived signal, including exact coordinates, a mobility trace, proximity, or sensor-derived location. Available precision The finest representation the local environment currently holds. Available precision MUST NOT by itself authorize release at that precision. Authorized precision The coarsest-or-equal representation permitted to become externally effective for a particular act. The Finality Sink MUST treat authorized precision as a ceiling on the outbound payload. Precision transformation A PED-directed reduction of available data to the authorized representation before or at the sink, for example city label, grid cell, shortened geohash, delay, or randomization. Egress Finality Sink The first boundary at which the location representation would leave the protected environment. Depending on deployment this MAY be an OS data broker, network egress filter, browser upload control, API gateway, enterprise agent, or equivalent. A component is a sink only if the release is technically non- completable without successful verification. Cumulative disclosure state Protected state describing prior releases in a policy window, used to decide whether another individually acceptable release would create an unauthorized movement history or equivalent exposure. Candidate Act, Non-Effective State, Protected Enforcement Domain (PED), Protected Validation Evidence, scoped non-bearer finality authority, and Finality Sink are used as in [I-D.das-6g-finality]. Das Expires 28 February 2027 [Page 4] Internet-Draft Access-Not-Egress August 2026 4. Problem Scope Mobile operating systems commonly frame location as an application permission: may application A read the user's location. The release question is narrower and later. May application A, or one of its SDKs, agents, analytics components, tools, or external processors, emit this precision to recipient B, for purpose C, in jurisdiction D, at time E, given prior releases F. Those questions are not equivalent. An application can have a legitimate local need for a precise fix — navigation, E911, on-device geofencing — while no external weather, advertising, or model- inference endpoint has a corresponding need. ENISA mobile-privacy guidance already states that an application should not store an exact location point where a generic area is sufficient [ENISA-MOBILE]. European data-protection guidance treats the same idea as data minimisation and protection by default [GDPR-MIN]. Aggregation changes the risk further. Individually ordinary coordinates, timestamps, and routes can reveal workplaces, routines, relationships, or activity around sensitive sites once correlated at machine scale. Publicly reported fitness-tracking heatmaps around military installations illustrated that user permission for a benign purpose did not eliminate the downstream intelligence consequence [NATO-STRATCOM]. This document does not treat that class of harm as a reason to ban location. It treats it as a reason not to make the finest available representation the default egress object. AI changes the economics, not the geometry, of that inference. Clustering, mobility analysis, and multisource fusion that once required specialist effort can run continuously over large datasets. The security significance of a disclosure therefore depends on what the value enables a downstream machine to infer, not only on whether a single record looks sensitive in isolation. 5. Relationship to Existing Mechanisms This profile is intended to consume decisions from existing permission, consent, and policy systems. Those systems remain inputs. They do not replace sink verification of the outbound payload. Das Expires 28 February 2027 [Page 5] Internet-Draft Access-Not-Egress August 2026 5.1. Operating-System Location Permissions Current mobile platforms distinguish, to varying degrees, approximate and precise location, one-time and continuous access, and foreground versus background access. Those controls govern whether an application process may read a provider. They typically do not bind a particular outbound payload, recipient, jurisdiction, or precision ceiling at the moment of network egress, and they often do not distinguish the first-party application from an embedded SDK on the same release path. 5.2. W3C Geolocation and Permission Policy The W3C Geolocation API and related permission policy give a web origin a location reading after user permission [W3C-GEO]. They do not, by themselves, inspect a later fetch, beacon, or agent tool call that forwards that reading at full precision to a third party. 5.3. Coarsening, Fuzzing, and Differential Privacy Geohash prefixes, grid snapping, geo-fuzzing, delay, and differential-privacy mechanisms are compatible with this profile. They are candidate transformation methods. This document does not select one transformation. It requires that whatever representation is actually sent is the representation bound to the authority, and that a finer representation MUST NOT pass the sink under that authority. 5.4. Path-Level Privacy Controls Oblivious endpoints, MASQUE-based proxying, and private relay services can hide the client's network location from a destination [RFC9298]. They do not bind the precision of application payload fields that already contain coordinates. Path privacy and payload- precision finality are complementary. 5.5. What This Profile Adds * precision as an authorization dimension, not only as a provider configuration; * component identity (application versus SDK, agent, analytics, or advertising library) as a predicate; * recipient, destination, and jurisdiction bindings on the release; * optional cumulative-disclosure evaluation; Das Expires 28 February 2027 [Page 6] Internet-Draft Access-Not-Egress August 2026 * sink-side comparison of authorized precision with the actual outbound payload; and * fail-closed denial or mandatory downgrade rather than advisory minimisation. 6. Architecture A Location-Release Candidate Act MUST NOT become externally effective merely because location permission was granted, the coordinate was already computed, an AI component selected a tool, or an upstream policy engine returned ALLOW. The act MUST remain in a Non-Effective State until the PED validates act-specific predicates, protected validation evidence is committed, scoped non-bearer finality authority is released, the egress Finality Sink independently verifies that authority against the outbound payload, and the authority is consumed or otherwise made unsuitable for unauthorized replay. local exact location remains inside protected domain | v LOCATION-RELEASE CANDIDATE ACT | v Non-Effective State | v Protected Enforcement Domain purpose, requester, component recipient, destination, jurisdiction required precision, user authorization policy/revocation epochs cumulative disclosure, sink identity | v protected evidence + scoped authority | v Egress Finality Sink | +-- exact representation permitted +-- transformed representation permitted `-- release denied Figure 1: Precision-bounded egress chain Das Expires 28 February 2027 [Page 7] Internet-Draft Access-Not-Egress August 2026 PED approval alone MUST NOT release data. The sink MUST prevent effectuation on verification failure. A warning or audit record is not sufficient. 7. Precision-Bounded Egress Profile 7.1. Precision Ladder Implementations SHOULD be able to distinguish at least the following authorized-precision classes: * EXACT * METER_10 * METER_100 * GRID * GEOHASH * CITY * REGION * COUNTRY * DELAYED or RANDOMIZED variants of the above * NONE The applicable class MUST be determined by declared purpose and current authorization state, not by the mere fact that the requester asked for the finest available value. Where a lower-precision representation is sufficient, the higher-precision representation SHOULD remain non-effective for egress. 7.2. PED Predicates For a location-release act the PED SHOULD evaluate: * requesting application and component identity and type; * declared purpose and whether exact precision is necessary for that purpose; * recipient, destination, processor type, and jurisdiction; Das Expires 28 February 2027 [Page 8] Internet-Draft Access-Not-Egress August 2026 * current user authorization and policy/revocation epochs; * data class and requested fields; * whether the release is one-shot or continuous; and * cumulative disclosure state where the policy requires it; * intended egress sink identity. Possible PED decisions include ALLOW at the requested precision, ALLOW_WITH_TRANSFORMATION at a coarser precision, DELAY, RANDOMIZE, ESCALATE, or DENY. Exact GPS is not the default success path. 7.3. Worked Example Purpose: nearby pharmacy discovery or local weather. Requested precision: exact GPS. Necessary precision: city or local area. Destination: external discovery or forecast service. Decision: exact GPS denied; coarse locality allowed. The external service receives "Balasore, Odisha" rather than a coordinate. The application can still perform the task. Utility did not require unrestricted data authority. 7.4. Cumulative Disclosure An implementation MAY incorporate cumulative disclosure state so that repeated individually acceptable releases do not automatically create an unauthorized movement history. This state is policy-dependent and can cause a later request to be downgraded, delayed, randomized, rate-limited, or denied. Cumulative disclosure state is itself sensitive. Implementations SHOULD keep it device-local or inside the PED, SHOULD minimise retained identifiers, SHOULD bound retention to the policy window, and MUST NOT export the state as a movement history under authority issued for a single coarse release. A later revision may define a narrower privacy-preserving accumulator. This version only requires that if the state is used, it is treated as protected input to the PED, not as another egress object. Das Expires 28 February 2027 [Page 9] Internet-Draft Access-Not-Egress August 2026 7.5. Jurisdiction-Neutral Policy Input This architecture does not choose among national privacy rules. The PED consumes the policy applicable to the relevant jurisdiction and user or enterprise authorization state. United States, European, Indian, or other deployments MAY produce different authorized- precision decisions from the same Candidate Act. The protocol's role is to keep the selected policy technically binding at the point of release. 7.6. Sink Placement and Alternate Paths Possible sink locations include an OS location or data broker, a network-egress filter, a browser upload control, an API gateway, a cloud-sync agent, and enterprise wrapping of SDK traffic. If more than one path can emit the same protected representation — application upload, analytics SDK, advertising SDK, telemetry, clipboard, file export, agent tool call, background sync — each path capable of that consequence MUST be subject to the same precision ceiling or MUST be unable to emit the protected fields. This document does not specify a single on-device enforcement point for every operating system. An implementation that leaves an equivalent path unverified does not satisfy the profile for that data class. 8. JSON Interoperability Profile This section defines the semantic JSON contract for location-release acts. It does not require one transport. Objects MAY move over protected local IPC, OS broker APIs, HTTPS, or enterprise agents. A transport binding MUST preserve object integrity, sink identity, freshness, and non-bearer authority semantics. 8.1. LocationReleaseCandidate Object { "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "urn:ietf:params:json-schema:precision-egress:location-candidate:1", "title": "LocationReleaseCandidate", "type": "object", "additionalProperties": false, "required": [ "version", "object_type", "candidate_act_id", "act_type", "created_at", "expires_at", "requester", "purpose", "source_data", "requested_release", "destination", "policy_state", "freshness", "finality_sink" ], Das Expires 28 February 2027 [Page 10] Internet-Draft Access-Not-Egress August 2026 "properties": { "version": { "type": "string", "const": "1.0" }, "object_type": { "type": "string", "const": "location_release_candidate" }, "candidate_act_id": { "type": "string", "minLength": 16 }, "act_type": { "type": "string", "const": "LOCATION_RELEASE" }, "created_at": { "type": "string", "format": "date-time" }, "expires_at": { "type": "string", "format": "date-time" }, "requester": { "type": "object", "required": ["application_id"], "properties": { "application_id": { "type": "string" }, "component_id": { "type": "string" }, "component_type": { "type": "string", "enum": [ "APPLICATION", "SDK", "AI_AGENT", "ANALYTICS", "ADVERTISING", "BROWSER", "CLOUD_SERVICE", "SYSTEM_SERVICE", "OTHER" ] } } }, "purpose": { "type": "object", "required": ["purpose_id", "declared_purpose"], "properties": { "purpose_id": { "type": "string" }, "declared_purpose": { "type": "string" }, "purpose_epoch": { "type": "integer", "minimum": 0 }, "user_intent_reference": { "type": "string" } } }, "source_data": { "type": "object", "required": ["data_class", "available_precision"], "properties": { "data_class": { "type": "string", "enum": [ "LOCATION", "MOBILITY_TRACE", "PROXIMITY", "SENSOR_DERIVED_LOCATION" ] }, "available_precision": { Das Expires 28 February 2027 [Page 11] Internet-Draft Access-Not-Egress August 2026 "type": "string", "enum": [ "EXACT", "METER_10", "METER_100", "GRID", "GEOHASH", "CITY", "REGION", "COUNTRY" ] }, "local_only": { "type": "boolean" }, "source_reference": { "type": "string" } } }, "requested_release": { "type": "object", "required": ["requested_precision", "fields"], "properties": { "requested_precision": { "type": "string", "enum": [ "EXACT", "METER_10", "METER_100", "GRID", "GEOHASH", "CITY", "REGION", "COUNTRY", "NONE" ] }, "fields": { "type": "array", "items": { "type": "string" } }, "retention_seconds": { "type": "integer", "minimum": 0 }, "continuous": { "type": "boolean" } } }, "destination": { "type": "object", "required": ["destination_id", "jurisdiction"], "properties": { "destination_id": { "type": "string" }, "endpoint": { "type": "string" }, "recipient_id": { "type": "string" }, "processor_type": { "type": "string", "enum": [ "FIRST_PARTY", "PROCESSOR", "SDK_VENDOR", "AI_PROVIDER", "ANALYTICS", "AD_NETWORK", "PUBLIC_AUTHORITY", "OTHER" ] }, "jurisdiction": { "type": "string" }, "cloud_region": { "type": "string" } } }, "cumulative_disclosure": { "type": "object", "properties": { Das Expires 28 February 2027 [Page 12] Internet-Draft Access-Not-Egress August 2026 "window_seconds": { "type": "integer", "minimum": 0 }, "prior_release_count": { "type": "integer", "minimum": 0 }, "prior_precision_max": { "type": "string" }, "movement_history_risk": { "type": "string", "enum": ["LOW", "MEDIUM", "HIGH", "CRITICAL"] } } }, "policy_state": { "type": "object", "required": ["policy_epoch", "revocation_epoch"], "properties": { "policy_epoch": { "type": "integer", "minimum": 0 }, "authority_epoch": { "type": "integer", "minimum": 0 }, "revocation_epoch": { "type": "integer", "minimum": 0 }, "policy_profile_id": { "type": "string" }, "regulatory_profile_id": { "type": "string" } } }, "freshness": { "type": "object", "required": ["nonce"], "properties": { "nonce": { "type": "string", "minLength": 16 }, "sequence": { "type": "integer", "minimum": 0 }, "session_id": { "type": "string" } } }, "finality_sink": { "type": "object", "required": ["sink_id", "sink_type"], "properties": { "sink_id": { "type": "string" }, "sink_type": { "type": "string", "enum": [ "NETWORK_EGRESS", "OS_DATA_BROKER", "BROWSER_UPLOAD", "API_GATEWAY", "CLOUD_SYNC", "TELEMETRY", "ANALYTICS_SDK", "AD_SDK", "FILE_EXPORT", "DATABASE_EXPORT", "OTHER" ] } } } } } Das Expires 28 February 2027 [Page 13] Internet-Draft Access-Not-Egress August 2026 8.2. Precision Decision Object { "version": "1.0", "object_type": "precision_policy_decision", "decision_id": "ppd-cf0c49", "candidate_act_id": "loc-5c8238a4", "decision": "ALLOW_WITH_TRANSFORMATION", "requested_precision": "EXACT", "authorized_precision": "CITY", "transformation": { "type": "PRECISION_REDUCTION", "method": "CITY_LABEL", "parameters": { "country_code": "IN", "region": "Odisha", "city": "Balasore" } }, "validated_predicates": { "application_valid": true, "component_valid": true, "purpose_valid": true, "exact_precision_necessary": false, "destination_valid": true, "recipient_valid": true, "jurisdiction_valid": true, "user_authorization_valid": true, "policy_epoch_valid": true, "revocation_state_valid": true, "cumulative_disclosure_acceptable": true, "sink_binding_valid": true }, "reason_codes": [ "MINIMIZATION_REQUIRED", "EXACT_PRECISION_NOT_NECESSARY" ] } 8.3. EgressFinalityAuthority Object Das Expires 28 February 2027 [Page 14] Internet-Draft Access-Not-Egress August 2026 { "version": "1.0", "object_type": "egress_finality_authority", "authority_id": "efa-e71ad531", "candidate_act_id": "loc-5c8238a4", "decision_id": "ppd-cf0c49", "evidence_id": "pve-location-332", "scope": { "data_class": "LOCATION", "authorized_precision": "CITY", "permitted_fields": ["city", "region", "country"], "recipient_id": "weather-provider", "destination_id": "weather.example", "jurisdiction": "IN", "retention_seconds_max": 3600 }, "binding": { "candidate_act_digest": { "algorithm": "SHA-256", "value": "base64url-location-act-digest" }, "nonce": "B21C9924FF77A183", "policy_epoch": 42, "authority_epoch": 11, "revocation_epoch": 7, "finality_sink_id": "egress-sink-01", "protected_state_reference": "ped-location-state-91" }, "lifetime": { "issued_at": "2026-08-26T17:45:01Z", "expires_at": "2026-08-26T17:45:10Z", "single_use": true }, "issuer": { "ped_id": "ped-device-01", "key_id": "ped-key-location-2", "signature": "base64url-signature" } } 8.4. EgressSinkVerify Request and Response The sink verifies the actual outbound payload immediately before release. Declared precision is not sufficient. The payload fields MUST be within the authorized ceiling. Das Expires 28 February 2027 [Page 15] Internet-Draft Access-Not-Egress August 2026 { "operation": "EgressSinkVerify", "request_id": "egress-req-771", "candidate_act_id": "loc-5c8238a4", "authority_id": "efa-e71ad531", "sink": { "sink_id": "egress-sink-01", "sink_type": "NETWORK_EGRESS" }, "outbound_payload": { "content_type": "application/json", "data_class": "LOCATION", "declared_precision": "CITY", "fields": { "city": "Balasore", "region": "Odisha", "country": "IN" }, "payload_digest": { "algorithm": "SHA-256", "value": "base64url-payload-digest" } }, "destination": { "destination_id": "weather.example", "endpoint": "https://weather.example/forecast", "recipient_id": "weather-provider", "jurisdiction": "IN" }, "freshness": { "nonce": "B21C9924FF77A183" } } Das Expires 28 February 2027 [Page 16] Internet-Draft Access-Not-Egress August 2026 { "operation": "EgressSinkVerify", "request_id": "egress-req-771", "decision": "ALLOW", "verification": { "authority_signature": "VALID", "candidate_act_binding": "MATCH", "data_class": "MATCH", "payload_precision": "CITY_WITHIN_AUTHORIZED_CEILING", "field_scope": "MATCH", "recipient": "MATCH", "destination": "MATCH", "jurisdiction": "MATCH", "policy_epoch": "CURRENT", "revocation_epoch": "CURRENT", "nonce": "FRESH", "consumption_state": "UNUSED", "sink_binding": "MATCH" }, "consumption": { "authority_id": "efa-e71ad531", "status": "CONSUMED", "consumed_at": "2026-08-26T17:45:02Z" }, "release": { "permitted": true, "released_precision": "CITY", "release_id": "release-881" } } 8.5. Precision-Mismatch Denial Das Expires 28 February 2027 [Page 17] Internet-Draft Access-Not-Egress August 2026 { "operation": "EgressSinkVerify", "request_id": "egress-req-772", "decision": "DENY", "error": { "code": "EF_PRECISION_MISMATCH", "message": "Outbound payload exceeds authorized precision.", "retryable": false }, "verification": { "authority_signature": "VALID", "authorized_precision": "CITY", "observed_payload_precision": "EXACT", "destination": "MATCH", "jurisdiction": "MATCH", "sink_binding": "MATCH" }, "release": { "permitted": false } } 8.6. Complete Exact-to-Coarse Transaction Das Expires 28 February 2027 [Page 18] Internet-Draft Access-Not-Egress August 2026 { "step_1_local_state": { "available_location": { "latitude": 21.494321, "longitude": 86.932145, "accuracy_meters": 4.2 }, "external_effect": "NONE" }, "step_2_candidate_act": { "candidate_act_id": "loc-5c8238a4", "requester": { "application_id": "weather-app", "component_id": "forecast-module", "component_type": "APPLICATION" }, "purpose": { "purpose_id": "local-weather", "declared_purpose": "Provide weather for the user's area" }, "requested_release": { "requested_precision": "EXACT", "fields": ["latitude", "longitude"] }, "destination": { "destination_id": "weather.example", "recipient_id": "weather-provider", "jurisdiction": "IN" } }, "step_3_ped_decision": { "decision": "ALLOW_WITH_TRANSFORMATION", "authorized_precision": "CITY", "reason": "Exact coordinates are not necessary." }, "step_4_authorized_payload": { "city": "Balasore", "region": "Odisha", "country": "IN" }, "step_5_sink_verification": { "decision": "ALLOW", "exact_coordinates_released": false, "authority_consumed": true } } Das Expires 28 February 2027 [Page 19] Internet-Draft Access-Not-Egress August 2026 8.7. Cumulative Disclosure Extension { "cumulative_disclosure": { "subject_scope": "device-local-pseudonymous-subject", "window_seconds": 86400, "prior_release_count": 144, "prior_precision_max": "METER_100", "distinct_destinations": 6, "movement_history_risk": "HIGH", "policy_action": "DOWNGRADE_TO_REGION" } } 9. Protocol Operation 9.1. Digest and Substitution A Candidate Act SHOULD have a stable digest over load-bearing attributes including data class, requested and authorized precision, destination, recipient, jurisdiction, purpose, permitted fields, and sink identity. Changing exact GPS to city, recipient A to recipient B, or sink A to sink B MUST invalidate previously issued authority unless the changed operation is separately authorized. 9.2. Sink Verification Immediately before release the sink MUST verify authority integrity, act binding, sink identity, expiry and consumption state, nonce freshness, policy and revocation epochs, destination and jurisdiction, authorized field set, and that observed payload precision does not exceed the authorized ceiling. On success, single-use authority SHOULD be consumed atomically with release. Implementations SHOULD define a canonicalization for payload inspection sufficient to detect exact coordinates presented under a city label, hidden in additional JSON fields, or duplicated on a parallel header. This version does not specify a complete media-type inspection algorithm. Absence of such inspection is a residual risk and MUST be documented by the implementation. Das Expires 28 February 2027 [Page 20] Internet-Draft Access-Not-Egress August 2026 9.3. Hot Path and Escalation Repeated releases inside a previously validated envelope — same application, purpose, destination, jurisdiction, and precision ceiling — MAY use a hot path with local protected state and short- lived authority. The hot path MUST still perform sink verification. Cache miss, unknown destination, jurisdiction uncertainty, continuous-trace requests, exact precision, or elevated cumulative- disclosure risk SHOULD escalate. Timeout MUST NOT be treated as approval. 9.4. Failure Codes The following identifiers are design suggestions and are not IANA assignments. Location-egress implementations SHOULD be able to express at least: * EF-002 NO_FINALITY_AUTHORITY * EF-005 AUTHORITY_ALREADY_USED * EF-006 REPLAY_DETECTED * EF-012 SCOPE_MISMATCH * EF-020 DESTINATION_MISMATCH * EF-021 JURISDICTION_MISMATCH * EF-023 PRECISION_MISMATCH * EF-030 POLICY_EPOCH_MISMATCH * EF-031 REVOCATION_STATE_MISMATCH * EF-040 SINK_MISMATCH * EF-070 ESCALATION_REQUIRED * EF-080 FAIL_CLOSED A PRECISION_MISMATCH denial MAY include a remediation such as DOWNGRADE_TO_CITY. Other permitted actions include deny, delay, randomize, redact, quarantine, request fresh authority, or escalate. Das Expires 28 February 2027 [Page 21] Internet-Draft Access-Not-Egress August 2026 10. Security Considerations The objective is that protected location remains technically non- effective for egress unless current, act-specific, precision-bounded authority is verified at the sink. Replay of a previously successful authority MUST be prevented by nonce, consumption, short lifetime, or equivalent state. Authority for city-level weather MUST NOT authorize exact GPS to the same host, a different host, or a different sink. Ordinary application-layer software MAY be compromised or overly permissive. Security MUST NOT depend solely on the application, SDK, browser, or model returning ALLOW. A malicious SDK with valid in- process access SHOULD NOT be able to bypass a correctly placed egress sink. If PED or sink integrity cannot be established, the implementation SHOULD NOT release exact or high-precision location. It MAY fail closed, downgrade, quarantine, or disable the protected consequence class. 11. Privacy Considerations Finality metadata can itself be sensitive: application identity, purpose, destination, jurisdiction, and precision class can reveal behavior even when coordinates are withheld. Implementations SHOULD minimise metadata exposed outside the PED and MAY use hashes, commitments, or sealed references rather than raw descriptors on untrusted paths. Repeated coarse releases can still build a movement history. Authorized precision of CITY on each of 144 requests is not automatically harmless. Cumulative-disclosure evaluation exists for that reason and must not become a second exportable trace. On-device models that reason over exact coordinates while egress is limited to city labels create an isolation requirement. This document does not specify how an implementation prevents the model or a tool-calling runtime from emitting the exact value through another channel. That channel, if it exists, is an egress path and is subject to Section 7. Das Expires 28 February 2027 [Page 22] Internet-Draft Access-Not-Egress August 2026 12. Data-Sovereignty Considerations Authority to access data inside one environment is not authority to transfer it to another jurisdiction, cloud region, unapproved processor, external analytics provider, unrelated AI provider, or advertising endpoint. A data-export Candidate Act SHOULD bind destination, recipient, jurisdiction, cloud region, purpose, data class, precision, policy and revocation epochs, and sink identity. 13. IANA Considerations This document requests no IANA actions. The precision-class names and EF-xxx identifiers are illustrative. A later revision MAY propose registries for precision classes, consequence classes, or error codes. 14. Intellectual Property Note Certain technical concepts described in this document are associated with pending patent applications in the DAS Protocols family, including PCT/IB2026/054453, PCT/IB2026/055615, PCT/IB2026/055760, PCT/IB2026/055870, PCT/IB2026/056058, and PCT/IB2026/053385. IETF IPR disclosure should follow BCP 79 [RFC8179]. This section is informational and does not define licensing terms. 15. Conclusion A device or application may obtain exact location while an SDK, AI agent, analytics service, cloud processor, or external destination is entitled only to a less precise representation or to no location at all. This profile moves that distinction to the actual egress boundary. Precise GPS access is not precise GPS-release authority. 16. Normative References [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997, . [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017, . [RFC8179] Bradner, S. and J. Contreras, "Intellectual Property Rights in IETF Technology", BCP 79, RFC 8179, DOI 10.17487/RFC8179, May 2017, . Das Expires 28 February 2027 [Page 23] Internet-Draft Access-Not-Egress August 2026 17. Informative References [ENISA-MOBILE] ENISA, "Privacy and data protection in mobile applications", 2017. [GDPR-MIN] European Commission, "Principles of data protection, including data minimisation and protection by default", 2018. Policy context only. This document does not specify EU law. [I-D.das-6g-finality] Das, S., "Execution-Finality for AI-Native 5G/6G and O-RAN", Work in Progress, Internet-Draft, draft-das-ai- native-6g-execution-finality-01, August 2026, . [I-D.das-ef-interop] Das, S., "Execution-Finality for AI Interoperability", Work in Progress, Internet-Draft, draft-das-execution- finality-ai-interoperability-00, August 2026, . [NATO-STRATCOM] NATO Strategic Communications Centre of Excellence, "Work on consumer geolocation, metadata, and operationally significant inference from ordinary activity data", 2018. [RFC9298] Schinazi, D., "Proxying UDP in HTTP", RFC 9298, DOI 10.17487/RFC9298, August 2022, . [W3C-GEO] W3C, "Geolocation", 2025, . Author's Address Sangam Das Independent Inventor Balasore 756001 Odisha India Email: info@sangamdas.com Das Expires 28 February 2027 [Page 24]