I would also be interested in seeing your RFC2119s and the test suite to support assertions of compliance.
What are the governance mechanisms that keep these from motivated reasoning? This is data *protection*, it has to be about facts not promises.