Research question: What privacy controls are actually stated in the 12 current luxury real estate campaign drafts, what is missing, and what should be tested before replacement content is accepted?
Executive finding
The current 12-file campaign is structurally ready for publication review: every article exceeds the 600-word floor, all 12 use distinct level-two heading sequences, and none contains the rejected filler markers. Privacy-oriented vocabulary appears where a topic calls for it rather than as a repeated template. Five articles use the term consent, three use discretion, and one mentions retention, deletion, or disposal. Those are lexical observations, not evidence that an operational control is effective.
No audited body contains an email address or external body link, and the practical examples avoid presenting real client records. That reduces obvious exposure in this corpus but cannot prove confidentiality, authorization, access control, deletion, or incident readiness. This is a content audit, not an audit of brokerage systems, staff behavior, contracts, privacy notices, or legal compliance.
Scope and denominator
The denominator is the 12 Real Estate Luxury article slugs declared in lib/__tests__/campaign-content-quality.test.ts. The inspected unit is the body of each corresponding MDX file under content/articles in the repository snapshot reviewed for this report. Twelve expected files were found, so file-presence measures use a denominator of 12 rather than a sample.
The audit asks whether the files state editorial controls relevant to client privacy. It does not inspect forms, a CRM, email, cloud storage, analytics, listing syndication, vendor systems, authentication settings, or deleted records. No client records or transaction data were opened. Results therefore characterize only these 12 public-content drafts at one point in time.
Method and rubric
The review used a repeatable structural pass and a bounded lexical pass. The structural pass applied the campaign tokenizer, extracted ordered H2 sequences, checked the 600-word floor, and searched for prohibited filler markers. The lexical pass counted each file once when its body contained consent; discretion; or retention, deletion, or disposal. “Disposition” was excluded because its uses in the campaign describe editorial status rather than data handling. The pass also scanned for email-address patterns and HTTP or HTTPS Markdown destinations.
These counts show where vocabulary is present, not whether a policy exists. An article can discuss safe handling without every listed word, and repetition does not create compliance. A manual read confirmed that examples are generalized or explicitly fictional and client- or property-specific decisions go to an accountable professional. No private records, CRM data, messages, contracts, or analytics were opened.
Measured audit results
| Measure | Rule | Observed result | Bounded interpretation |
|---|---|---|---|
| Expected files present | File exists for each campaign slug | 12 of 12 | The full campaign set was inspected. |
| Substantive word span | Apply the campaign body-token rule | 750-899 words | All files contain topic-specific working detail. |
| Files meeting 600-word floor | Substantive body is at least 600 words | 12 of 12 | Length passes; length alone is not quality. |
| Distinct H2 sequences | Compare complete ordered H2 sequences | 12 across 12 | No two articles use the same architecture. |
| Consent signal | Body uses the term consent | 5 of 12 | Validity and scope are not measured. |
| Discretion signal | Body uses the term discretion | 3 of 12 | This is not a confidentiality test. |
| Explicit retention, deletion, or disposal term | Body mentions retention, deletion, or disposal | 1 of 12 | Presence of a term does not establish a control or schedule. |
| Public contact or link exposure | Body contains an email address or external Markdown link | 0 of 12 | No such exposure was found. |
What the current audit supports
The rewritten articles now separate their workflows and include concrete handling boundaries instead of repeating one privacy paragraph. Where a process involves client preferences, showing details, maintenance records, or approvals, the virtual assistant organizes minimum necessary detail and routes authority-sensitive decisions to the responsible agent, broker, property manager, or qualified professional.
Generalized examples remain safer than client names, occupancy patterns, access instructions, travel dates, security details, financial capacity, negotiation positions, or private contact information. Consent is not a universal override; actual operations still need to identify who may authorize disclosure, what material and channel are covered, and when a changed instruction requires review.
Retention is distinct from secrecy. Access controls reduce who can view material while held; retention rules address how long it remains. The one-file lexical result supplies no universal period and does not show that the other files lack appropriate controls outside this vocabulary. Legal duties, contracts, dispute holds, platform constraints, and business needs can differ, so actual schedules require qualified review.
Data sources and references
Ten topic-owned official sources were checked for reachability and for the propositions summarized below. They inform a control model; they do not all govern every brokerage, location, record, or vendor.
- The FTC guide to protecting personal information organizes data security around taking stock, scaling down, locking information, properly disposing of what is no longer needed, and planning for incidents. That supports an inventory-to-disposal editorial checklist.
- The FTC's Start with Security guide addresses sensible access, authentication, secure storage and transmission, service-provider practices, and ongoing vulnerability work. It supports access and vendor questions, not proof that a particular system is secure.
- The FTC data breach response guide advises organizations to secure operations, correct vulnerabilities, and determine appropriate notifications after a breach. It supports an escalation path; notice duties still require situation-specific review.
- The NIST Privacy Framework is a voluntary tool for identifying and managing privacy risk while protecting individuals. It supports a risk-based workflow rather than a claim of compliance or certification.
- NIST Special Publication 800-122 explains protection of personally identifiable information confidentiality and connects PII handling with access control, accountability, authentication, media protection, and risk assessment. It was written to assist federal agencies, so this report uses it as technical guidance, not as a claim that its scope automatically covers a brokerage.
- The NIST Cybersecurity Framework helps organizations understand and improve management of cybersecurity risk. It supports assigning governance and protection work around editorial systems but cannot establish the state of those systems without evidence.
- NIST Special Publication 800-88 Rev. 1 provides media-sanitization guidance and distinguishes disposal from techniques intended to make access to target data infeasible. It supports assigning a documented disposal step without prescribing this site's retention period.
- NIST Special Publication 800-61 Rev. 3 integrates incident-response recommendations with cybersecurity risk management. It supports naming an escalation and response owner, not a claim that a public article proves readiness.
- NIST Special Publication 800-63B defines technical requirements for remote authentication at three authentication assurance levels. It supports evidence-based account-control review, although its government-system scope does not automatically set a brokerage's obligations.
- The California Attorney General's CCPA overview describes rights that include knowing about collected information, deletion subject to exceptions, and opting out of sale or sharing. It demonstrates why rights handling belongs in the review map; applicability and exceptions must be assessed by qualified counsel.
Taken together, the sources support six editorial questions: what is collected, why it is needed, who can access it, what may be disclosed, when it is disposed of, and how an incident or rights request is escalated. They do not prescribe one universal retention period or authorize publication of any client fact.
Limitations and inference boundary
This is a first-party repository measurement with a complete denominator for the declared campaign set, but it remains a snapshot. The rules favor explicit language and may not capture a control expressed with unexpected terminology. The retention criterion records only whether one of three bounded terms appears; it does not evaluate a trigger, action, implementation, or separate records schedule. Word count is a structural signal, not a measure of usefulness, truth, privacy, or reader value.
The ten external sources have different scopes. Some are voluntary frameworks or general business guidance; one describes California consumer rights; one NIST publication was designed for federal agencies. This report does not decide which laws apply, whether a person has given effective consent, whether information is legally required to be retained, or whether a security measure is reasonably implemented.
The inference boundary is therefore strict. The measured results establish what appears in the 12 inspected files and nothing more. They cannot establish actual privacy compliance, confidentiality, cybersecurity, client trust, valid authorization, successful deletion, legal sufficiency, search ranking, conversion, valuation, transaction success, or any other outcome. No privacy, legal, security, ranking, or commercial guarantee is made.
Release interpretation and follow-up
The replacement set passes the deterministic campaign content contract, but that pass is not a privacy certification. Release review must still confirm valid MDX, rendered pages without unintended identifiers, and professional ownership of client- or property-specific decisions.
Future revisions should rerun the same denominator and tokenizer, preserve the maximum similarity pair, scan rendered output for sensitive examples, and recheck this report's external sources. Real client or property records belong in controlled systems with documented access, retention, disposal, and incident procedures. Unresolved authority or exposure questions should fail closed.
Conclusion
The current campaign meets its structural and originality controls while avoiding obvious email or external-link exposure in article bodies. Privacy-related terms appear selectively rather than as template filler. These results establish only what is visible in the audited files; they cannot establish actual privacy compliance, valid authorization, secure systems, successful deletion, search performance, or any client outcome.