SEO / Portfolio / Public Site
Designing a Who Cares Wizard for 2IA.org
Report summary
A strong “Who Cares Wizard” for 2IA should not behave like a chatbot, a lead-generation form, or a confession box. It should act as a privacy-first, rights-navigation layer that helps people identify the next lawful, practical channel: a records request, an appeal, a correction path, a regulator, a
Key topics
- SEO / Portfolio / Public Site
- SEO
- Portfolio
- Public Site
- AI
- WordPress
- Runtime
- Privacy
- Semantic Systems
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
Source availability: 46 citation markers in the source export have no recoverable source links. Those markers are omitted from this reader; any supplied bibliography and ordinary links remain. Check the original sources before relying on the cited claims.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
Executive summary
A strong “Who Cares Wizard” for 2IA should not behave like a chatbot, a lead-generation form, or a confession box. It should act as a privacy-first, rights-navigation layer that helps people identify the next lawful, practical channel: a records request, an appeal, a correction path, a regulator, a civil-rights body, or a trusted support organization. That is the most faithful interpretation of 2IA’s own public posture, which emphasizes civil-liberties research, lawful public intelligence, minimization, visible corrections, privacy-by-default, and ordinary public contact that is truthful, brief, respectful, and non-automated.
I recommend a rules-based, editorially auditable wizard with 20 levels and 20 end nodes. Levels 1–10 should identify the domain of concern. Levels 11–19 should tailor the route by jurisdiction, record type, complaint type, privacy needs, evidence available, contact preference, and accessibility/language needs. Level 20 should show the best-fit outcome page, plus one or two adjacent routes when the signal is ambiguous. This structure fits both 2IA’s correction-driven publication method and public-sector UX guidance that favors one question per screen, explicit headings, and visible step progress for longer flows.
The wizard should live on the homepage as an entry card, but after the first answer it should continue on a dedicated route such as /who-cares/step/1. That approach preserves the homepage’s existing search and archive functions, avoids a heavy modal experience, and better matches 2IA’s no-tracker, no-third-party-embed privacy posture. 2IA already exposes a briefing search, archive pages, issue hubs, a public-records path, a corrections path, and a methodology page; the wizard should complement those assets, not replace them.
The first release should be treated as U.S.-first because the strongest official contact ecosystem surfaced here is overwhelmingly U.S. federal and state-oriented, and 2IA’s own public-records framing is explicitly FOIA-centric. I also assume that target languages are not yet specified, that user technical literacy ranges from low to advanced, and that 2IA’s public site is probably running on a theme/plugin CMS, likely WordPress-style, because the site publicly references its theme and future plugins and exposes archive/category structures; that CMS assumption should be verified before engineering begins.
What 2IA already signals
2IA’s homepage, Start Here page, and About page define the site as independent civil-liberties research on surveillance, identity, AI inference, false positives, public records, and lawful public understanding. The site argues that records, metadata, algorithms, and institutional claims should be made legible “without turning curiosity into collateral damage,” and its “fast version” already points readers toward metadata, surveillance systems, AI harm, public records, lawful contact, and corrections. That means the wizard should inherit 2IA’s existing issue map rather than invent a generic help taxonomy.
Methodologically, 2IA says publication should be built around source notes, confidence labels, minimization, AI-use disclosure, right of reply, and visible corrections. That matters because a decision tree is not only a UX component here; it is an editorial system. A deterministic, inspectable branching model is easier to correct, audit, and update than a free-form generative assistant, which makes it a better fit for a site that explicitly treats corrections as editorial infrastructure and AI as subordinate to human review.
2IA’s privacy and contact pages are even more decisive. The site says the theme does not add analytics, tracking pixels, external fonts, CDN assets, or unnecessary cookies by default. It also warns that future forms, newsletter tools, analytics packages, embeds, and plugins should be treated as policy changes requiring review for purpose, consent, retention, access, deletion, and opt-out. On contact, 2IA tells users not to send classified material, private personal data, exploit details, threats, or material they do not have the right to share, and it states that public contact is not a secure drop box. Those statements strongly argue for a wizard with closed-choice questions, minimal free text, no third-party survey scripts, and clear warnings before any outbound handoff.
2IA’s Lawful Contact and Public Records pages also shape the tone of the experience. 2IA urges users to use official public channels for their intended purpose, to keep outreach non-automated, and to document dates and responses carefully. It frames public records as lawful leverage and emphasizes that narrow requests are easier to search, answer, appeal, and publish. So the wizard should route users toward specific, dated, documented actions, not broad “tell us your story” intake.
Finally, 2IA’s volunteer page is unusually useful for persona design. It explicitly names research assistants, editors, designers, accessibility reviewers, translators, public-records trackers, legal reviewers, and technical maintainers as legitimate contribution roles. That means the wizard should not treat “visitor seeking help” as the only audience; it should also recognize volunteers, researchers, and policymakers as first-class users.
Personas and editorial logic
Visitor seeking help. This persona is likely stressed, uncertain which institution matters, unsure whether the issue is “privacy,” “discrimination,” “records,” or “AI,” and often worried about saying the wrong thing. For them, the wizard should ask what happened at the level of a system or decision, not at the level of blame, motive, or self-disclosure. 2IA’s public guidance repeatedly prefers narrow, lawful, documented action over drama or ambiguity, which is exactly the posture this persona needs.
Volunteer. A 2IA volunteer is not a vigilante. The site explicitly rejects targeting private people, bypassing access controls, gathering secrets, provoking systems, or unauthorized investigation. That means the volunteer persona should be offered bounded roles such as accessibility testing, translation, records tracking, editing, document review, or technical maintenance, with methodology and privacy obligations shown before any sign-up prompt.
Researcher. This persona needs provenance, confidence states, source classes, and route-specific documentation. 2IA’s methodology is already written for them: separate confirmed facts from inference, preserve source context, and treat AI as subordinate. For these users, the wizard should expose “Why this result?” and “What evidence should I gather?” modules, not just contact cards.
Policymaker. This persona is less likely to need a complaint form and more likely to need procurement, audit, retention, due-process, deletion, and correction questions. 2IA’s own dossiers explicitly single out contracts, data-sharing clauses, audit rights, vendor claims, retention limits, due process, and downstream repair. So policymaker copy should be available as a secondary tab on every result page, and as a dedicated end route when the user indicates they are trying to improve an institution rather than solve a personal incident.
Question phrasing should therefore follow a simple rule: ask about the system, the effect, and the next action, not fault. Good examples are “Which system or decision affected you?”, “What information do you already have, if any?”, and “Would you like an official route, a research route, or both?” Bad examples are “Who targeted you?”, “Do you have proof?”, or “Do you want to escalate?” This matches 2IA’s insistence on truthful, non-theatrical contact and minimization.
Fallback logic should be generous. Every screen should include Back, Skip for now, I’m not sure, and Browse all routes. If the user skips three or more classification questions, the system should stop narrowing aggressively and show the best three likely routes with a note that the match is broad. For urgent paths, the wizard should compress optional questions and surface the official hotline, complaint portal, or redress form earlier. This is especially important because a 20-step flow is long enough that users need visible progress and low-friction exits. GOV.UK explicitly recommends one question per page, and USWDS recommends a visible step indicator with “step of total” text and brief step labels.
Decision-tree architecture
The safest design is a rules-based classifier with editorial content objects, not a free-form conversational engine. The wizard should compute a candidate set of end nodes after each answer, pruning aggressively only when the user gives firm signals. The first half of the flow should classify the problem; the second half should personalize the result page, reorder contact cards, and attach warnings about what the next site will collect. That split fits 2IA’s privacy stance and makes the system easier to maintain under a corrections policy.
flowchart TD
A[Homepage Who Cares card] --> B{Broad issue area}
B --> C[Records and transparency]
B --> D[Identity and data errors]
B --> E[Surveillance and institutional decisions]
B --> F[Speech, journalism, and organizing]
B --> G[Contribute, research, or change policy]
C --> C1[Federal FOIA]
C --> C2[State or local records]
C --> C3[Appeal or mediation]
C --> C4[Procurement and vendor research]
D --> D1[Correction, access, deletion]
D --> D2[Identity theft]
D --> D3[Credit report]
D --> D4[Housing or tenant screening]
E --> E1[Employment screening]
E --> E2[Workplace monitoring]
E --> E3[Student privacy]
E --> E4[Health privacy]
E --> E5[Government surveillance]
E --> E6[Biometrics]
E --> E7[Automated decisions]
E --> E8[Border or travel]
E --> E9[Telecom privacy]
F --> F1[Journalism and source protection]
F --> F2[Activist digital security]
G --> G1[Volunteer, research, or policy collaboration]
One important refinement is that the wizard should not ask for open-ended narratives until the very end, and even then the field should be optional. 2IA explicitly says not to invite sensitive material, and official complaint portals vary a great deal in what they require: DOJ allows a report without email or phone but warns it cannot provide follow-up in that case; HHS OCR states that it does not investigate unnamed complaints and also offers language assistance and alternative formats; CFPB requires name, email, phone, and address to create a secure account, forwards the complaint to the company, may publish de-identified complaint data, and retains complaints under federal records rules. So the 2IA wizard should preview those privacy consequences before the user leaves the site.
The question stack below assumes one question per page, neutral wording, and no blame language. It also assumes that result pages can reorder official contacts, NGO contacts, and research modules based on the answers given.
| Level | Example question text | Expected answer type | Branching rule | Sample end-node IDs |
|---|---|---|---|---|
| 1 | Which broad issue area fits best today? | Single select | Routes to records, identity/data, surveillance/decisions, speech/civic, or collaboration families | WC-01..WC-04, WC-05..WC-08, WC-09..WC-17, WC-18..WC-19, WC-20 |
| 2 | Which role best describes you right now? | Single select | Does not change family yet; changes copy, examples, and optional sidebars | WC-01..WC-20 |
| 3 | Which institution or system is involved? | Single select | Government, employer, school, landlord, health provider, telecom/platform, mixed, or unknown | WC-01, WC-09, WC-11, WC-12, WC-13, WC-16, WC-17 |
| 4 | What are you trying to do first? | Single select | Get records, fix an error, file a complaint, get expert support, learn, or contribute | WC-01..WC-05, WC-18..WC-20 |
| 5 | Is this mainly about a decision, a record, or ongoing monitoring? | Single select | “Decision” biases to housing, employment, AI, border; “record” to FOIA/correction; “monitoring” to surveillance, biometrics, telecom | WC-03, WC-05, WC-08, WC-09, WC-13, WC-14, WC-15, WC-16, WC-17 |
| 6 | How urgent is this? | Single select | Urgent answers suppress optional screens and raise hotline or complaint options sooner | WC-06, WC-13, WC-16, WC-18, WC-19 |
| 7 | Whose rights or records are affected? | Single select | Me, child/student, worker, tenant, newsroom, community, organization | WC-08, WC-09, WC-10, WC-11, WC-18 |
| 8 | What kind of concern fits best? | Multi-select, max 2 | Privacy, discrimination, false match/error, retaliation, speech, safety, access to records | WC-03, WC-05, WC-08, WC-09, WC-10, WC-12, WC-13, WC-14, WC-15, WC-17, WC-18 |
| 9 | Which technology or data source is involved, if known? | Single select | Background check, biometrics, AI score, school records, health records, phone/location data, unknown | WC-07, WC-08, WC-09, WC-11, WC-12, WC-14, WC-15, WC-17 |
| 10 | Do you know the organization or agency name? | Yes/No + optional short text | Enables organization-specific routing and prefilled contact cards | WC-01..WC-20 |
| 11 | Is the main target federal, state/local, private-sector, or mixed? | Single select | Splits FOIA versus state records and official complaint pathways | WC-01, WC-02, WC-03, WC-13, WC-16 |
| 12 | Do you need records before you can act? | Yes/No/Not sure | Adds or foregrounds records sidecar on any route | WC-01..WC-04, WC-13, WC-15, WC-20 |
| 13 | Do you need to correct information about you? | Yes/No/Not sure | Pulls toward correction, credit, tenant, employment, student, or health paths | WC-05, WC-07, WC-08, WC-09, WC-11, WC-12 |
| 14 | Do you want an official complaint route, an advice route, or both? | Single select | Orders official regulators before NGOs, or vice versa | WC-08..WC-19 |
| 15 | Do you want to stay as anonymous as practical? | Yes/No/Need advice | Warns when official routes require PII and promotes low-disclosure options where appropriate | WC-13, WC-16, WC-18, WC-19 |
| 16 | What evidence do you already have, if any? | Multi-select | Builds the preparation checklist on the final page | WC-01..WC-19 |
| 17 | Which contact method works best for you? | Single select | Reorders phone, email, web form, or mail contacts on final page | WC-03, WC-06, WC-12, WC-16, WC-18, WC-19 |
| 18 | Do you need accessibility or language support? | Multi-select | Adds alternate-format notes, translated resources, and phone options | WC-01..WC-20 |
| 19 | How much detail do you want right now? | Single select | Shows either a short checklist or a deep packet with prep notes and legal context | WC-01..WC-20 |
| 20 | Which next step feels most useful now? | Dynamic choice from top 1–3 cards | Locks to final result, while still exposing adjacent routes when confidence is low | One primary leaf from WC-01..WC-20 |
End-node catalog
Every end-node page should use the same shell: a one-paragraph summary, a “Why this route?” note, a “Prepare before contacting” checklist, official contacts first, then NGO/support contacts, then a compact “Research / Volunteer / Policy” drawer. Result pages should also include a leave-site notice when the next destination is likely to collect personal information. That matters because official portals have materially different privacy expectations.
WC-01 Federal FOIA request. Issue. Use this when the user needs federal agency records about surveillance programs, contracts, policies, audits, training, or retention rules. Contacts. FOIA.gov, How to make a FOIA request, Agency search, MuckRock request form, 2IA Public Records. Blurb. This is the default route when the institution is federal and the first task is to get records rather than argue conclusions. Next steps. Search public pages first, identify the agency, ask for a dated and narrow record category, then save your confirmation number. Final-page snippet. “Start with the record, not the theory. Ask for contracts, policies, emails, audits, or retention schedules tied to a named office and time period.”
WC-02 State or local public-records request. Issue. Use this when the records sit with a state, county, city, transit agency, public school, sheriff, police department, or local board. Contacts. NFOIC State FOI resources, NFOIC sample letters, RCFP Open Government Guide, MuckRock request form. Blurb. State and local records laws are not the same as federal FOIA, so the first problem is almost always choosing the right law and the right office. Next steps. Pick the jurisdiction, identify the records officer, adapt a state-specific request letter, and track deadlines from the day you submit. Final-page snippet. “Use the law that actually governs the office you are contacting. Local requests fail most often because the wrong office or wrong statute was used.”
WC-03 FOIA appeal or mediation. Issue. Use this when a records request was denied, delayed, over-redacted, or ignored. Contacts. OGIS assistance request, OGIS contact page, ogis@nara.gov, 202-741-5770, 1-877-684-6448, FOIA agency search. Blurb. Appeals are part of the records process, not an edge case. OGIS exists specifically to help resolve some federal FOIA disputes after you have tried the agency directly. Next steps. Keep the original request, denial or status notice, claimed exemption, and any correspondence together before asking for mediation or filing an appeal. Final-page snippet. “Document what you asked for, what was withheld, which exemption was cited, and what narrower relief could still work.”
WC-04 Surveillance-vendor or procurement research. Issue. Use this when the user wants to find out which vendor, contract, software, or data-sharing agreement sits behind a surveillance or AI system. Contacts. 2IA Public Records, FOIA.gov, RCFP federal FOIA guide, NFOIC State FOI resources, MuckRock request form. Blurb. 2IA’s own framing is direct here: contracts often decide civil liberties before the public notices the program exists. Next steps. Ask for contracts, statements of work, renewals, privacy reviews, audit provisions, training materials, and data-sharing clauses tied to a named vendor and date range. Final-page snippet. “Ask what was bought, who can query it, what data goes in, how long it stays, and what audit or termination rights exist.”
WC-05 Record correction, access, or deletion. Issue. Use this when the user knows something is wrong in a file or profile but is not yet sure which sector-specific path applies. Contacts. 2IA Corrections, CFPB complaint portal, HHS OCR complaint portal, student privacy complaint page, FTC consumer contact. Blurb. This is the broad “fix the file” route. It should help the user identify the sector and then pivot into the more specific credit, housing, employment, health, or education branch when possible. Next steps. Get a copy of the record if possible, mark the specific field or sentence that is wrong, note the date and source, and preserve any denial or notice you already received. Final-page snippet. “Name the file, the specific error, and the correction you want. Repair should travel as far as the error did.”
WC-06 Identity theft recovery. Issue. Use this when someone used the person’s identity, accounts, tax information, or credit in their name. Contacts. IdentityTheft.gov, IdentityTheft.gov assistant, ReportFraud.ftc.gov, FTC contact page, 1-877-FTC-HELP, AnnualCreditReport.com. Blurb. The federal government’s identity-theft workflow is already packaged as a recovery plan, which makes it a better first step than ad hoc internet advice. Next steps. Start the recovery plan, place fraud protections where appropriate, gather the list of affected accounts, and save every reference number or letter. Final-page snippet. “Start the recovery plan first. Then work account by account with a written trail of what changed, when, and who confirmed it.”
WC-07 Credit-report or consumer-report error. Issue. Use this when the problem is an inaccurate credit report, credit file, or consumer reporting entry. Contacts. CFPB complaint portal, credit and consumer reporting notice, FTC FCRA page, AnnualCreditReport.com. Blurb. CFPB is explicit that consumers should generally dispute inaccurate information with the reporting company first; if that fails, the CFPB complaint route becomes much stronger. Next steps. Pull the report, dispute the specific item directly with the reporting company, keep copies, and escalate to CFPB if the error is not corrected. Final-page snippet. “Dispute the exact item, not the whole file. Keep the report, your dispute, and the company’s response together.”
WC-08 Tenant-screening or housing denial. Issue. Use this when a housing application was denied because of a tenant-screening report or because the user suspects housing discrimination. Contacts. CFPB tenant screening guide, CFPB complaint portal, 1-855-411-2372, HUD housing discrimination form, HUD FHEO regional offices. Blurb. Housing denials often sit at the intersection of inaccurate screening data and unlawful discrimination, so both routes should be visible. Next steps. Ask for the screening report and adverse-action notice, dispute specific errors, and file with HUD if disability, race, sex, familial status, retaliation, or similar protected grounds are involved. Final-page snippet. “Get the report, get the notice, and identify whether the problem is bad data, discrimination, or both.”
WC-09 Employment screening or AI hiring issue. Issue. Use this when an employer used a background report, social-media review, or hiring technology in a way that seems inaccurate, unfair, or discriminatory. Contacts. EEOC Public Portal, EEOC portal overview, FTC background-check rights, CFPB complaint portal, EFF legal assistance. Blurb. EEOC is the official route when the concern is employment discrimination; FTC and CFPB are relevant when the problem also involves background-report accuracy and consumer-reporting practices. Next steps. Save the notice, the report if you have it, the date of the hiring decision, and any evidence that the tool or screening process relied on inaccurate or discriminatory data. Final-page snippet. “Separate the decision from the data. Was the problem the employer’s judgment, the report’s accuracy, the tool’s design, or all three?”
WC-10 Workplace surveillance or retaliation. Issue. Use this when the user is dealing with workplace monitoring, surveillance, or retaliation connected to protected workplace rights. Contacts. NLRB charge guidance, NLRB regional offices, publicinfo@nlrb.gov, EEOC Public Portal, EFF legal assistance. Blurb. The NLRB is often the official destination when monitoring intersects with protected concerted activity, while EEOC becomes relevant if the monitoring or retaliation also reflects discrimination. Next steps. Write down the monitoring practice, who imposed it, what right or activity came before the retaliation, and whether a discipline or termination notice exists. Final-page snippet. “Describe the monitoring and the consequence separately. Then explain what protected workplace activity came before it.”
WC-11 Student privacy or school monitoring. Issue. Use this when the user is concerned about education records, school monitoring, or a student-privacy violation. Contacts. FERPA information page, File a complaint, FERPA complaint form, DOJ civil-rights report. Blurb. FERPA is the core federal route for education-records problems, and the Department of Education says complaints must be timely and fact-specific. Next steps. Gather the student notice, the policy or vendor name, the dates of disclosure or monitoring, and any written request you already made to the school. Final-page snippet. “Start with the record, disclosure, or monitoring event that concerns you. Then add the date, school, and decision-maker.”
WC-12 Health privacy or medical-data misuse. Issue. Use this when the problem involves a covered provider, health plan, health clearinghouse, or related misuse of health information. Contacts. HHS OCR complaint page, HHS OCR complaint process, OCR complaint portal, OCRComplaint@hhs.gov, OCRMail@hhs.gov, 1-800-368-1019. Blurb. HHS OCR is the official federal route for many health-information privacy complaints and says it can investigate covered entities and their business associates. Next steps. Keep the provider or plan name, dates, notices, screenshots, and the shortest factual description of the alleged disclosure or misuse. Final-page snippet. “Use the smallest accurate story: who held the data, what happened, when it happened, and why you believe it violated your privacy rights.”
WC-13 Government surveillance or policing complaint. Issue. Use this when the concern is government monitoring, police surveillance, intelligence sharing, watchlisting, or a related civil-rights issue outside the travel-redress context. Contacts. DOJ civil-rights report, 1-855-856-1247, 202-514-3847, FOIA.gov, 2IA Public Records, ACLU state affiliates, EFF legal assistance. Blurb. This route should combine official complaint options with a records route, because surveillance concerns are often impossible to understand without the contract, policy, or records trail behind them. Next steps. Decide whether your first move is a complaint, a records request, or both, and keep the record clean: dates, agencies, technologies, and notices. Final-page snippet. “If you cannot yet prove the system, ask for the policy, vendor, or data-sharing record that would show it exists.”
WC-14 Biometric or facial-recognition concern. Issue. Use this when face, voice, fingerprint, gait, or other biometric matching appears to be part of the problem. Contacts. DOJ civil-rights report, FTC consumer contact, ReportFraud.ftc.gov, ACLU state affiliates, EFF legal assistance. Blurb. This is a good route when the user knows biometrics are involved but does not yet know whether the most useful lever is consumer protection, civil-rights enforcement, or litigation support. Next steps. Identify who used the system, where it was used, whether consent was requested, what decision followed, and whether a record or notice can be requested. Final-page snippet. “Treat the biometric system like a decision system: who used it, what it matched, what it triggered, and how you can challenge the result.”
WC-15 Automated decision or benefits-screening challenge. Issue. Use this when an algorithm, risk score, automated triage system, or AI-assisted decision affected benefits, services, healthcare, or another high-stakes determination. Contacts. DOJ civil-rights report, HHS OCR complaint portal, CFPB complaint portal, 2IA Public Records, NIST AI RMF. Blurb. 2IA’s own framing is that if a model affects reputation, services, investigation, work, travel, or benefits, people need reasons, human review, appeal, deletion, and accountable ownership. Next steps. Ask for the notice, the stated reason, the source data, the human-review option, and any policy or contract that explains how the tool is used. Final-page snippet. “Ask what data fed the decision, what rule or model was used, who can review it, and how a mistake gets repaired.”
WC-16 Border, watchlist, or travel redress. Issue. Use this when the person repeatedly encounters screening problems at airports, borders, or related transportation hubs. Contacts. DHS TRIP portal, DHS TRIP information page, TRIP@tsa.dhs.gov, ACLU state affiliates. Blurb. DHS describes TRIP as the single point of contact for people who commonly face difficulties during travel screening or at U.S. borders, which makes it the default official route here. Next steps. File the redress inquiry, save the redress control number, and note the dates, airports, border crossings, carriers, and exact screening issue you experienced. Final-page snippet. “Use one clean timeline: date, airport or border point, carrier if relevant, what happened, and whether it has happened before.”
WC-17 Telecom or carrier privacy complaint. Issue. Use this when the concern involves communications services, unwanted calls/texts, or carrier handling of sensitive telecom data such as CPNI. Contacts. FCC complaint center, FCC privacy complaints, FTC consumer contact, EFF legal assistance. Blurb. FCC is the official consumer complaint entry point for communications services, and its privacy materials explicitly discuss carrier duties regarding customer proprietary network information. Next steps. Save the call logs, screenshots, account notices, and the name of the carrier or provider before filing. Final-page snippet. “Name the provider, the service, and the data or call event involved. Screenshots and account notices help more than long narratives.”
WC-18 Journalism, source protection, or online-speech support. Issue. Use this when the person is a journalist, media lawyer, source-protection advocate, or someone facing a press-freedom or online-speech issue that needs specialist support. Contacts. RCFP Legal Hotline, 1-800-336-4243, Freedom of the Press contact, info@freedom.press, FPF service request, EFF legal assistance, info@eff.org. Blurb. RCFP is the official specialist hotline in this catalog for journalists and media lawyers, while Freedom of the Press Foundation provides digital-security services and general contact routes for journalists and newsrooms. Next steps. Use the hotline first if there is an imminent legal deadline or arrest risk, and do not send sensitive information through a general contact form unless the receiving organization explicitly supports it. Final-page snippet. “Separate the legal problem from the security problem. You may need both a hotline and a digital-security support route.”
WC-19 Protester, organizer, or activist digital-security support. Issue. Use this when organizers, activists, civil-society groups, or protesters are worried about targeted digital attacks, account compromise, or spyware. Contacts. Access Now Helpline, help@accessnow.org, +1 (888) 414-0100, Amnesty Security Lab Get Help, share@amnesty.tech, EFF legal assistance, ACLU state affiliates. Blurb. Access Now’s helpline is a 24/7 technical support route for civil society; Amnesty’s Security Lab provides surveillance-abuse and forensic support for at-risk civil-society members, but it also notes capacity limits for some public forensic requests. Next steps. Save notifications, suspicious messages, device details, and the date the concern began before contacting anyone. Final-page snippet. “If you think your accounts or devices are targeted, document first, change as little as necessary, and contact a specialist support route quickly.”
WC-20 Volunteer, research, or policy collaboration with 2IA. Issue. Use this when the user is not trying to solve a personal incident first, but wants to help, research, translate, audit, or draft policy. Contacts. 2IA Volunteer, 2IA Contact, 2IA Methodology, 2IA Public Records, NIST Privacy Framework, privacyframework@nist.gov, NIST AI RMF, aiframework@nist.gov. Blurb. This route should explicitly support volunteer roles, researcher workflows, and policy design. 2IA already names useful roles such as accessibility review, translation, records tracking, research, and technical maintenance, and NIST’s privacy and AI frameworks provide policy-side scaffolding. Next steps. Read methodology first, choose a bounded contribution, and propose a narrow deliverable: an accessibility review, translation pass, records tracker, vendor-contract audit, or appeal/correction checklist. Final-page snippet. “Bring a bounded contribution. The fastest useful help is a narrow, reviewable piece of work.”
UX, accessibility, privacy, multilingual, and CMS integration
The core UX recommendation is simple: one question per screen, with the label or legend doubling as the page heading, and a visible “Step X of 20” indicator above it. GOV.UK explicitly recommends one question per page because it helps users focus, and notes that using the label or legend as the heading helps screen-reader users hear the question only once. USWDS recommends separate headings, visible progress, short labels, semantic headings, and accessibility testing in the real implementation, not just in isolated components. Placeholder text should not carry meaning that belongs in a label. WCAG 2.2 should be the baseline target.
The wizard should therefore avoid: multi-question accordion pages, modals that trap navigation, unlabeled icon-only answers, placeholder-only prompts, or free-text-heavy screens. Each screen should include a short hint line, an “I’m not sure” option, and a quiet “Browse all routes” escape hatch. Because the flow is 20 levels long, users should also be able to choose a brief result or detailed packet near the end rather than being forced to read the same amount of content. That is especially important for distressed users and for mobile users.
Privacy and consent deserve first-class UI treatment. 2IA’s own privacy and contact pages, plus NIST and ICO guidance, support a very strict pattern: data minimization by default, purpose-specific consent, no pre-ticked choices, and no vague bundling of consent into general terms. The wizard should show a short interstitial before the first question, and a second, route-specific interstitial before any outbound handoff to an official complaint form. The first notice should say not to enter secrets, passwords, private third-party data, or material the sender lacks the right to share. The second should summarise what the destination site will likely collect and retain.
A model consent note for the wizard is:
Before we continue: use this tool for ordinary, lawful, non-sensitive questions. Do not paste passwords, classified material, medical details, or private third-party data. We do not save your answers unless you choose Save on this device. External complaint sites may collect and retain your information under their own rules.
That text is justified by both 2IA’s own warnings and the different privacy postures of official portals. DOJ allows complaints without email or phone but cannot provide updates in that case; HHS OCR says it will not investigate unnamed complaints and also offers alternative formats, relay services, and language assistance; CFPB says users need name, email, phone, address, and a secure account, forwards complaints to companies, may publish de-identified complaint data, and retains complaints under federal records rules.
Multilingual support should be implemented as real content parity, not cosmetic translation theater. W3C requires correct language declaration in HTML and discourages using meta declarations for language. USWDS recommends a consistent language selector and says users with limited English proficiency are more successful when they can work in their preferred language, especially under stress. It also distinguishes between a full-language selector when all content is translated and a “selected multilingual content” pattern when only parts of the site exist in other languages. For 2IA, that means the first release should architect for translations but should not imply full-language parity until every wizard step and every end-node page is translated. The language selector should sit above navigation and respect right-to-left layouts when needed.
From a CMS standpoint, the public evidence strongly suggests a theme/plugin CMS, probably WordPress-style, though that remains an inference. If that inference is right, the cleanest implementation is a custom page template or block tied to three core content objects: questions, contacts, and end nodes. Each end node should store the title, concise issue summary, blurb, organization/contact cards, phone/email/form links, preparation checklist, persona-specific notes, source URLs, last_reviewed, and correction_log. Each contact card should also store data_disclosure_note, language_support, accessibility_support, and official_or_ngo, because those differences are material for user consent. That content model also ports cleanly to any other server-rendered CMS if the WordPress-style assumption proves wrong.
The implementation should be server-rendered first, progressively enhanced with lightweight first-party JavaScript, and should preserve a no-JS fallback that shows a browseable index of all 20 routes. That recommendation follows directly from WCAG’s testability expectations and 2IA’s privacy-first posture. Avoid third-party form builders, analytics pixels, customer-data platforms, or embed-heavy survey tools unless they are self-hosted and explicitly reviewed against 2IA’s published privacy criteria.
A practical homepage wireframe set would look like this:
HOMEPAGE HERO / ENTRY CARD
+--------------------------------------------------------------+
| WHO CARES? |
| Find the next lawful step for a records, privacy, identity, |
| AI, speech, or surveillance concern. |
| |
| [ Start the wizard ] [ Browse all issue areas ] |
| |
| Privacy-first: no tracking scripts by default. |
| Do not enter sensitive material. |
| |
| Existing 2IA search stays visible below or beside this card. |
+--------------------------------------------------------------+
QUESTION SCREEN
+--------------------------------------------------------------+
| Step 4 of 20 |
| Which institution or system is involved? |
| |
| ( ) Government or police |
| ( ) Employer or hiring system |
| ( ) School or university |
| ( ) Landlord or tenant-screening company |
| ( ) Healthcare or insurer |
| ( ) Telecom or communications provider |
| ( ) I am not sure |
| |
| Hint: pick the place that made the decision or holds record. |
| |
| [ Back ] [ Skip for now ] [ Browse all routes ] |
+--------------------------------------------------------------+
FINAL RESULT PAGE
+--------------------------------------------------------------+
| Result: Student privacy / school monitoring |
| Why you landed here |
| 2IA route summary in 2 sentences |
| |
| First three actions |
| 1. Get the policy or notice |
| 2. Save dates and screenshots |
| 3. Choose an official or support route |
| |
| OFFICIAL CONTACTS |
| [ DOE / FERPA ] [ DOJ Civil Rights ] |
| |
| SUPPORT CONTACTS |
| [ 2IA Public Records ] [ EFF / ACLU if relevant ] |
| |
| Before you click out |
| This next site may ask for your contact information. |
| |
| Related tabs: Research | Volunteer | Policy |
+--------------------------------------------------------------+
The highest-value UI details are small but consequential: keep the existing 2IA search visible on the homepage, use plain-language answer cards, expose a low-emphasis route to all 20 outcomes from every page, and show a quiet footer line that says “This is not a secure drop box.” That line is not ornamental; it is one of the clearest ways to translate 2IA’s existing ethics, privacy, and lawful-contact commitments into interface behavior.