Privacy
Minimal data collection subject to legitimate function, with measurement separated from surveillance by design.
Privacy
A digital layer capable of measuring more of the economy could, if designed carelessly, become extraordinarily intrusive. This architecture treats that risk as a first-order constraint, not a residual concern:
The key structural move is separating measurement from surveillance. Knowing aggregate virgin-material consumption for a product category, or aggregate electricity demand at a network node, does not require knowing what any specific household purchased or is doing at any specific moment. Aggregation, purpose limitation, access control, retention limits, and — where applicable — techniques that verify a fact without exposing the underlying data are treated as part of the architecture, not optional extras layered on afterward.
This is why "privacy" is one of the Design Decisions this Candidate Solution takes an explicit position on (see Design Decisions), with the position being architectural constraint rather than a secondary consideration or a compliance step performed after systems are already built. A design that cannot state what data it does not collect, and why, has not yet finished this part of the specification.