<?xml version="1.1" encoding="utf-8"?>
<article xsi:noNamespaceSchemaLocation="http://jats.nlm.nih.gov/publishing/1.1/xsd/JATS-journalpublishing1-mathml3.xsd" dtd-version="1.1" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"><front><journal-meta><journal-id journal-id-type="publisher-id">JERA</journal-id><journal-title-group><journal-title>Journal of Electronic Research and Application</journal-title></journal-title-group><issn>2208-3502</issn><eissn>2208-3510</eissn><publisher><publisher-name>Bio-Byword Scientific Publishing Pty. Ltd.</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.26689/jera.v10i5.15268</article-id><article-categories><subj-group subj-group-type="heading"><subject>Article</subject></subj-group></article-categories><title>Encoding Necessity for Standing Government Access to Platform-Held Data: A Three-Axis Model</title><url>https://artdesignp.com/journal/JERA/10/5/10.26689/jera.v10i5.15268</url><author>XiaLinglan</author><pub-date pub-type="publication-year"><year>2026</year></pub-date><volume>10</volume><issue>5</issue><history><date date-type="pub"><published-time>2026-06-29</published-time></date></history><abstract>Government access to platform-held data is increasingly implemented not through isolated requests but through durable interfaces: dashboards, periodic reporting pipelines and application programming interfaces. This shift changes the object of legality. A single request can be assessed by asking whether a stated purpose justifies the particular disclosure. A standing interface, by contrast, creates an ongoing access capability whose intrusiveness accumulates through repetition, aggregation and time. This article develops a three-axis model for encoding the requirement of minimum necessity at the configuration layer of such interfaces. The model treats data fields, extraction frequency and temporal persistence as the minimal auditable surface of standing access, while requiring purpose, recipients, selectors and onward sharing to be recorded in the same authorisation schedule. Using Chinese administrative interface governance as a stress test, especially health-code pipelines and ride-hailing supervisory feeds, the article shows how lawful or plausible access channels can drift through field accretion, cadence escalation and retention extension. EU and US materials are used as design exemplars rather than as complete solutions, illustrating the importance of reasoned requests, strict-necessity limits, duration sensitivity and auditable safeguards. The article concludes by proposing a procedural toolkit: reasoned authorisations, versioned parameter sheets, access logs, renewal triggers, independent audit and remedies for drift. Where feasible, a policy-as-code counterpart can make authorised limits executable at the gateway.</abstract><keywords/></article-meta></front><body/><back><ref-list><ref id="B1" content-type="article"><label>1</label><element-citation publication-type="journal"><p>Cohen J, 2019, Between Truth and Power: The Legal Constructions of Informational Capitalism, Oxford University Press.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B2" content-type="article"><label>2</label><element-citation publication-type="journal"><p>Regulation (EU) 2016/679 of the European Parliament and of the Council, General Data Protection Regulation.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B3" content-type="article"><label>3</label><element-citation publication-type="journal"><p>Nissenbaum H, 2009, Privacy in Context: Technology, Policy, and the Integrity of Social Life, Stanford University Press.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B4" content-type="article"><label>4</label><element-citation publication-type="journal"><p>Zhang X, 2022, Decoding China’s COVID-19 Health Code Apps: The Legal Challenges. Healthcare, 10(8): 1479.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B5" content-type="article"><label>5</label><element-citation publication-type="journal"><p>PRC CPC News Network, 2022, Zhengzhou Announces Investigation and Accountability for Red Health Code Assignment to Rural Bank Depositors, June 22, 2022.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B6" content-type="article"><label>6</label><element-citation publication-type="journal"><p>PRC Ministry of Transport, et al., 2022, Interim Measures for the Administration of Online Car-Hailing Operation Services.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B7" content-type="article"><label>7</label><element-citation publication-type="journal"><p>PRC Ministry of Transport, 2022, Measures for the Operation and Management of the Online Ride-Hailing Supervision Information Interaction Platform.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B8" content-type="article"><label>8</label><element-citation publication-type="journal"><p>Carpenter v United States, 138 S. Ct. 2206, 2018.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B9" content-type="article"><label>9</label><element-citation publication-type="journal"><p>Ohm P, 2010, Broken Promises of Privacy: Responding to the Surprising Failure of Anonymization. UCLA Law Review, 2010(57): 1701–1777.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B10" content-type="article"><label>10</label><element-citation publication-type="journal"><p>Koops B, 2021, The Concept of Function Creep. Law, Innovation and Technology, 13(1): 29–56.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B11" content-type="article"><label>11</label><element-citation publication-type="journal"><p>Dwork C, Roth A, 2014, The Algorithmic Foundations of Differential Privacy. Foundations and Trends in Theoretical Computer Science, 9(3–4): 211–407.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B12" content-type="article"><label>12</label><element-citation publication-type="journal"><p>Joined Cases C-511/18, C-512/18 and C-520/18, La Quadrature du Net and Others, EU:C:2020:791.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B13" content-type="article"><label>13</label><element-citation publication-type="journal"><p>Regulation (EU) 2023/2854 of the European Parliament and of the Council, Data Act.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B14" content-type="article"><label>14</label><element-citation publication-type="journal"><p>Regulation (EU) 2022/2065 of the European Parliament and of the Council, Digital Services Act.</p><pub-id pub-id-type="doi"/></element-citation></ref><ref id="B15" content-type="article"><label>15</label><element-citation publication-type="journal"><p>National Institute of Standards and Technology, 2020, Security and Privacy Controls for Information Systems and Organizations, Special Publication 800-53 Revision 5.</p><pub-id pub-id-type="doi"/></element-citation></ref></ref-list></back></article>
