I agree that this is very important and it's good that you explicitly draw data/compute privacy and compartmentalisation into the design.
If not yet, I'd encourage you to harmonise your architecture with Trust Over IP emergent standards, https://trustoverip.org/, and possibly with existing data privacy / data ownership protocols (like Solid, but unfortunately it looks more dead than alive to me at the moment, or is this a wrong perception?)