(A.) Policy and legislation
(A.1) Policy objectives
Digital technologies are transforming the economy and society, and data is at the centre of this transformation. Data-driven innovation has the potential of bringing enormous benefits for citizens and organisations, for example in support to health, mobility, and sustainability. The key role of data is reflected in many chapters of the rolling plan outlining the respective sector specific aspects. On top of that, and addressed in this chapter, data is of foundational and horizontal relevance.
As stated in the Communication “A European strategy for data”, the aim is to “create a single European data space – a genuine single market for data, open to data from across the world – where personal as well as non-personal data, including sensitive business data, are secure and businesses also have easy access to an almost infinite amount of high-quality industrial data, boosting growth and creating value, while minimising the human carbon and environmental footprint ... [and] where EU law can be enforced effectively, and where all data-driven products and services comply with the relevant norms of the EU’s single market”.
The following aspects are being addressed in the policy initiatives:
- Availability of data
- Imbalances in market power
- Data interoperability
- Data quality
- Data governance
- Data infrastructures and technologies
- Data lifecycle: collection, record keeping, archival and long-term preservation of information
- data space interoperability
Looking at each of the policy initiatives in more detail:
Two foundational laws establish common ground rules that apply to all data being shared in the EU . Wherever personal data is concerned, the General Data Protection Regulation (GDPR) sets the ground rules. The GDPR sets out detailed requirements for companies and organisations on collecting, storing and managing personal data. It applies to organisations based in the EU as well as organisations outside the EU that deal with personal data related to individuals in the EU. For non-personal data, the Regulation on a framework for the free flow of non-personal data in the European Union contributes to the free movement of data in the EU by limiting the situations in which data localisation requirements can be imposed by Member States.
The Data Governance Act (DGA) provides a framework to enhance trust in voluntary data sharing for the benefit of businesses and citizens. The Data Governance Act is a cross-sectoral instrument that aims to make more data available by regulating the re-use of publicly held, protected data, by enhancing trust in data sharing through data intermediaries and in the sharing of data for altruistic purposes. See the Data Governance Explained for more information.
The European Data Innovation Board (EDIB), announced in the DGA, started its work at the end of 2023. The goals of the EDIB are to facilitate the sharing of best practices, in particular on data intermediation, data altruism and the use of public data that cannot be made available as open data, as well as on the prioritisation of cross-sectoral interoperability standards.
To harness the value of data for the benefit of the European economy and society, the Commission supports the development of common European data spaces in strategic economic sectors and domains of public interest. Common European data spaces bring together relevant data infrastructures and governance frameworks in order to facilitate data pooling and sharing. Coordination & Support Actions (Horizon Europe) and Deployment Projects (Digital Europe) are helping to make the common European data spaces a reality. The “Data Spaces Support Centre” (DSSC) is a Digital Europe project that aims to facilitate data sharing and link the expertise of data sharing practitioners and researchers. The Commission Staff Working Document on Common European Data Spaces published in 2022 provided a first overview of the state of play. An update was provided in the Second staff working document on data spaces, published in 2024.
The European Commission is committed to ensuring fairness in how the value from using data is shared among businesses, consumers and accountable public bodies. The Data Act is addressing the fairness aspect, and includes measures related to the access to data on smart devices and related services, measures to provide protection from unfair contractual terms, measures to enable customers to switch between data processing services, and various other measures. See the Data Act Explained for more information.
Open data, including data from public institutions, is the final pillar in the European Strategy for Data. As stated in the EU Data Strategy, “Opening up government-held information is a long-standing EU policy. This data has been produced with public money and should therefore benefit society.” Open public sector data should be Findable, Accessible, Interoperable and Reusable (FAIR). The revised Open Data Directive (2019) aims to ensure that the public sector leads by example when it comes to sharing data. The High-Value Data Sets implementing act takes it a step further by specifying the data elements and level of granularity for six categories of open public sector data.
Public institutions also possess sensitive data, not suitable for sharing as open data. The Data Governance Act includes rules on the way such data can be shared in a trusted manner.
In summary, the European data economy - a European single market for data - is a foundational driver, built on European values and governed by European law. The EU data policies establish the general conditions for the trusted sharing of data, including data access rights and the fair allocation of value generated through the re-use of data. Where applicable, the horizontal legislation will be enhanced with vertical legislation to address sector-specific challenges.

(A.2) EC perspective and progress report
Interoperability standards for data and data sharing services will be key enablers for the single market for data. Standards will enable the cost-efficient sharing of data and also provide common mechanisms for organisations to comply with the European law.
The chapter 3.1.3 Data interoperability (RP2024) provides more detail on the data and data spaces interoperability requirements and supporting standards.
This section provides more background on the data sharing scenarios that will need to be supported.
European data portals
Open data from public institutions can effectively be shared via data portals. The data.europa.eu portal provides a central point of access to European open data from international, European Union, national, regional, local and geodata portals. By making the metadata available in a standard format, Member States can make data sets from their local portals findable, accessible and reusable to citizens and organisations.
Data portals enable the Findability and Accessibility of data sets, the first two elements of the FAIR principles.
The other two elements, Interoperability and Reusability, can further be enhanced by the use of common data standards for the data sets and by applying good data governance practices, in particular to ensure data quality.
Interoperability aspects:
- harvesting of catalogues
- open data licences
- metadata
Common European Data Spaces
To harness the value of data for the benefit of the European economy and society, the Commission supports the development of common European data spaces in strategic economic sectors and domains of public interest. Common European data spaces bring together relevant data infrastructures and governance frameworks in order to facilitate trusted sharing.
They:
- deploy data-sharing tools and services for the pooling, processing and sharing of data by an open number of organisations, as well as federate energy-efficient and trustworthy cloud capacities and related services;
- include data governance structures, compatible with relevant EU legislation, which determine, in a transparent and fair way, the rights concerning access to and processing of the data;
- improve the availability, quality and interoperability of data – both in domain-specific settings and across sectors.
Specific aspects related to the set-up of data spaces that will require standardisation:
- data governance principles (cross-domain)
- infrastructure requirements (cross-domain)
- data interoperability requirements (cross-domain)
- facilitate cross-sectoral interoperable frameworks for common standards and practices
Data Intermediation
Article 2(11) of the Data Governance Act defines a ‘data intermediation service’ as a service aiming to establish commercial relationships for data sharing between an undetermined number of individuals or companies on the one hand and data users (both individuals or entities) on the other. This can be done through technical means (platforms/apps where data can be stored), legal or other means.
Details regarding the understanding of “data intermediation services” are outlined in Data Governance Act explained | Shaping Europe’s digital future (europa.eu).
Specific aspects that may require standardisation:
- interoperability between data intermediation services
- methods for efficient exchange of information relating to the notification procedure for data intermediation services providers.
Industrial data / data from connected devices
The Data Act establishes data access and data rights for the users of connected devices. This is expected to unlock innovations in many areas:
- When you buy a ‘traditional’ product, you acquire all parts and accessories of that product. However, when you buy a connected product that generates data, it is often not clear who can do what with the data. By empowering users to transfer (‘port’) their data more easily, the Data Act will give both individuals and businesses more control over the data they generate through their use of smart objects, machines and devices, thereby allowing them to enjoy the advantages of the digitisation of products.
- By having access to the relevant data, aftermarket services providers will be able to improve and innovate their services and compete on an equal footing with comparable services offered by manufacturers. Therefore, users of connected products could opt for a cheaper repair and maintenance provider – or maintain and repair it themselves. This way, they would benefit from lower prices on that market. This could extend the lifespan of connected products, thus contributing to the Green Deal objectives.
- Availability of data about the functioning of industrial equipment will allow for factory shop-floor optimisation: factories, farms and construction companies will be able to optimise operational cycles, production lines and supply chain management, including based on machine learning.
- In precision agriculture, IoT analytics of data from connected equipment can help farmers analyse real-time data like weather, temperature, moisture, prices or GPS signals and provide insights on how to optimise and increase yield. This will improve farm planning and help farmers make decisions about the level of resources needed.
For the sharing of such user-generated data, data spaces and data intermediation services will play an important role.
Specific aspects that may require standardisation:
- data portability
- protection of trade secrets
- protection of personal data
- data usage rights
Data Altruism
Data altruism is about individuals and companies giving their consent or permission to make available data that they generate – voluntarily and without reward – to be used for objectives of general interest.
Entities that make available relevant data based on data altruism will be able to register as ‘data altruism organisations recognised in the Union’. Such entities must comply with a Rulebook, which will lay down certain requirements. In addition, the Commission will develop a European data altruism consent form to allow the collection of data across Member States in a uniform format.
Specific aspects that may require standardisation:
- tools for obtaining and withdrawing consent
- data privacy and consent metadata
- methods for registration and monitoring of recognised data altruism organisations
Re-use of protected data held by public sector bodies
The Open Data Directive regulates the re-use of publicly available information held by the public sector. However, the public sector also holds vast amounts of protected data (e.g. personal data and commercially confidential data) that cannot be re-used as open data but that could be re-used under specific EU or national legislation.
The DGA includes rules that enable the sharing of such protected data, which apply to the following categories of data (held by public sector bodies):
- commercially confidential data such as trade secrets or know-how,
- statistically confidential data,
- IPR protected data of third parties, and
- personal data.
Other than with open data, the sharing of restricted data is on request and bilateral. The request conditions must be non-discriminatory, transparent, proportionate and objective, and they shall not be used to restrict competition.
Specific aspects that may require standardisation:
- single access points
- findability of data (data catalogue)
- data protection
- anonymisation
- data aggregation
- secure processing environment
Switching between data processing services
The Data Act includes rules setting the right framework conditions for customers to effectively switch between different providers of data-processing services to unlock the EU cloud market. These will also contribute to an overall framework for efficient data interoperability.
Specific aspects that may require standardisation:
- portability of data assets
-
eArchiving
The European Interoperability Framework (EIF) recommends that a long-term preservation policy is formulated for records and information in electronic form held by public administrations for the purpose of documenting procedures and decisions, to keep their legibility, reliability and integrity for as long as need be accessed.
Data lifecycle, including data collection, record keeping, archival and - when necessary - long term preservation of information, supports society’s demand for trustworthy records and legal certainty associated with Data Strategy key instruments and application of AI algorithms. Important information should be kept accessible and reusable for years to come, regardless of the system used to store it. eArchiving (in the Digital Europe Programme eArchiving) provides core specifications, software, training and knowledge to help people preserve and reuse information over the long-term.
Smart contracts
Smart contracts are mentioned in several places as a way to automate aspects of trusted data sharing agreements, for example related to the management of consent. Smart contracts are listed under needs since they cut across legal, organisational, semantic and technical layers. See Smart contracts and the digital single market through the lens of a “law plus technology” approach | Shaping Europe’s digital future (europa.eu) for more background.
Open source software
Open source software is expected to play an important role in establishing trusted data sharing connections. Projects such as the EU-funded SIMPL project aim to help establish the infrastructure. To ensure interoperability, a close alignment between standardisation developments and open source developments will be needed.
(A.3) References
This section provides relevant references related to sections A.1 and A.2.
- Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act)
- Regulation (EU) 2024/903 of the European Parliament and of the Council of 13 March 2024 laying down measures for a high level of public sector interoperability across the Union (Interoperable Europe Act)
- COM(2020) 66 final Communication from the Commission “A European strategy for data”
- Proposal for a Regulation concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (Regulation on Privacy and Electronic Communications)
- Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Regulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union
- Regulation (EU) 2019/881 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act)
- Directive (EU) 2019/1024 on open data and the re-use of public sector information
- Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance (Data Governance Act)
- Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act)
- Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act)
- Decision (EU) 2015/2240 on interoperability solutions and common frameworks for European public administrations, businesses and citizens (ISA2 programme) as a means for modernising the public sector (ISA2)
- COUNCIL RECOMMENDATION of 14 November 2005 on priority actions to increase cooperation in the field of archives in Europe:
-
(B) Requested actions and progress in standardisation
(B.1) Requested actions
The actions proposed focus on fields where ICT standardisation can support horizontal and high-level policy objectives in the area of data economy. Actions that address sector specific needs and objectives are included in the respective chapters addressing the different sectors and technology areas.
Action 1: SDOs to support the work on a European trusted data framework
Action 2: Stock-taking and collaboration:
Action 2.1: SDOs to identify, map and inform about standards that are available or under development that are of relevance in supporting the scenarios listed in section A2 above. StandICT.eu to contribute to this activity.
Action 2.2: SDOs to collaborate on addressing standardisation needs around all the data lifecycle, from data collection to record keeping, archiving and long term preservation of information and start the respective standardisation activities, including taking into account the results of ISA2 program, the privacy by design principles, and other relevant activities (see for example section C.2).
Action 2.3: Following an analysis of standards available or under development (Action 1 above) and of possible standardisation needs (Action 2 above), SDOs to develop, in collaboration when appropriate, specific standards in support of the scenarios outlined in section A.2 above, taking into account EU legislation.
Action 3: In the context of the MSP, start an analysis on the role of open source software complementing standardisation in the support of the scenarios listed in section A.2 above, e.g. with APIs, protocols, service delivery and other applications.
Action 4: In collaboration with the Data Spaces Support Centre (DSSC), and considering the policy objectives outlined in the chapter on Data Interoperability as well as the work of the EU High-Level Forum, stakeholders to address the topic of gathering and processing data from different sources across domains and develop proposals for respective standardisation projects.
Action 5: Coordinate and support the standardization of data spaces by identifying cross-sectoral and cross-border projects, use cases, and pilots that implement data spaces extending beyond domain and geographic boundaries. This will help define and test the interoperability standards for data spaces
Action 6: SDOs to establish an exchange with relevant open source foundations for identifying open source technologies that are available or under way and that can be of relevance for supporting the upcoming EU Data Act and EU policy objectives around the EU data strategy.
(C) Activities and additional information
(C.1) Related standardisation activities
CEN & CENELEC
CEN/CLC JTC 25 ‘Data management, Dataspaces, Cloud and Edge’ was established in September 2024 to address standardization in these areas including:
- Data governance, data quality and data lifecycle management
- Interoperability, portability and switchability
- Organizational frameworks and methodologies, including IT management systems
- Processes and products evaluation schemes
- Guidelines
- Smart technology, objects, distributed computing devices, data services
The JTC 25 is structured into four Working Groups:
- WG 1: Advisory Group
- WG 2: Dataspaces
- WG 3: Data Management and Governance
- WG 4: Cloud and Edge
The committee aims to identify and develop standards that support the European data strategy implementation and, in particular, the Data Act standardization activities, working in close connection with the CEN Workshop ‘Trusted Data Transactions’, that developed and published CEN/CWA 18125 :2024 “Trusted Data Transaction”. It took over the activities of the CEN/CLC Focus Group on Data, Dataspaces, Cloud and Edge, which was disbanded on December 31, 2024
CEN/TC 468 ‘Preservation of digital information’ works on standardisation of the functional and technical aspects of the preservation of digital information.
This committee is developing a TR ‘Mapping of existing standardisation deliverables on European digital archiving and preservation’ and a TS ‘Policy and functional requirements for the electronic archiving services’.
The TC has established WG 1 ‘General concepts for preservation of digital information’.
CEN-CLC/WS DS ‘Digital sovereignty’
The CEN-CLC Workshop on Digital Sovereignty has produced a CWA (CWA 17995) that defines the concept of digital sovereignty with its associated terminology and framework of components, capabilities and capacities. Transforming the CWA into one or more standards is under consideration.
Eclipse Foundation
The Eclipse Dataspace Components (EDC) is a comprehensive framework (concept, architecture, code, samples) providing a basic set of features (functional and non-functional) that dataspace implementations can re-use and customize by leveraging the framework’s defined APIs and ensure interoperability by design. It is powered by the specifications of the Eclipse Dataspace Protocol (with IDSA as project lead) and the Eclipse Conformity Assessment Policy and Credential Profile (a pivotal part of the Gaia-X AISBL Trust Framework is now).
In addition, a number of relevant activities take place within the Eclipse Dataspace WG. A comprehensive list of the projects is available on the dataspace website of the Eclipse Foundation.
ETSI
TC ESI works on smart contracts for data sharing in support of the Data Act regulation and has developed the following standards supporting long term data preservation:
- ETSI TS 119 511 Electronic Signatures and Infrastructures (ESI); Policy and security requirements for trust service providers providing long-term preservation of digital signatures or general data using digital signature techniques
- ETSI TS 119 512 Electronic Signatures and Infrastructures (ESI); Protocols for trust service providers providing long-term data preservation services
ISG CIM (Industry Specification Group on cross-cutting Context Information Management) has published Group Specifications (GSs) for an interface and underlying information model called NGSI-LD.
- ETSI GS CIM 009 V1.7.1 NGSI-LD enables applications to publish, discover, update and access context information for a broad range of application areas.
- ETSI GS CIM 006 V1.2.1 NGS-LD is based on a high-level information model for capturing the structure of physical environments as. a graph which can be efficiently serialized as linked data.
NGSI-LD provides a common basis for interoperable data and it provides an interface for implementing data sharing services to exchange data across different sector and domains.
ISG PDL (Industry Specification Group on Permissioned distributed ledgers, and Distributed Ledger technology) has published Group Reports and Specifications (GRs & GSs) for smart contracts and a GS for DAOs (Distributed Autonomous Organisations) among other subjects’ non-repudiation, redactability, digital identity, etc… these have many Security and integrity related matters:
- ETSI GR PDL 004v1.1.1 - PDL Smart Contracts System Architecture and Functional Specification.
- ETSI GS PDL 011v2.1.1 - Specification of Requirements for Smart Contracts’ architecture and security.
- ETSI GR PDL 014v1.1.1 Study on non-repudiation techniques.
- ETSI GS PDL 015v1.1.1 Reputation Management.
- ETSI GS PDL 026v1.1.1 Settlement of usage-based services
- ETSI GR PDL 017v1.1.1 eIDAS2, in cooperation with TC ESI.
- ETSI GS PDL 018v1.2.1 Redactable Distributed Ledgers.
- ETSI GR PDL 019v1.1.1 PDL Services for Identity and Trust Management.
- ETSI GR PDL 020v1.1.1 Wireless Concensus
- ETSI GR PDL 021v1.1.1 3GPP use cases
- ETSI GS PDL 023v1.1.1 DID - Decentralized identifiers Framework
- ETSI GS PDL 024v1.1.1 3GPP/native telecom Architecture
- ETSI GS PDL 027v1.1.1 SSI in Telecom Networks (draft)
- ETSI GR PDL 028v1.1.1 PDL in ineM2M IoT standards (draft)
- ETSI GS PDL 029v1.1.1 Distributed Autonomous Organization (in approval)
- ETSI GR PDL 030v1.1.1 Trust in Telecom System (draft)
- ETSI GS PDL 031v1.1.1Energy Consumption Data Sharing based on PDL Service (draft)
ISG CIM (Industry Specification Group on cross-cutting Context Information Management) : please change:
- ETSI GS CIM 009 V1.7.1 to ETSI GS CIM 009 V1.8.1; and
- ETSI GS CIM 006 V1.2.1 to ETSI GS CIM 006 V1.3.1
IEEE
IEEE has developed the “Report: Big Data Governance and Metadata Management: Standards Roadmap.” IEEE has a collection of related standards that are active or under development, including:
- Standard for a Reference Architecture for Big Data Governance and Metadata Management (IEEE 2957)
- Cryptographic Protection Of Data (IEEE 1619)
- Data-Trading Systems (IEEE P3800)
- Standard Taxonomy for Responsible Trading of Human-Generated Data (P2895)
- Standard For Open Data: Open Data Ontology (P2896)
- Recommended Practice For Data Engineering With Heterogeneous Ecosystems And Data Sources For Efficient Data Processing, Management, And Consumption (P3131)
- Standard On Child And Student Data Governance (IEEE P7004)
- Standard On Employer Data Governance (IEEE 7005)
- Standard for Data & AI Literacy (IEEE P7015)
These pre-standardization activities support work in the Digital Economy:
- Open Data
- Synthetic Data
- Enabling a Smart and Equitable Agriculture Ecosystem with Accessible Tech and Data Tools
For more information, see: https://ieee-sa.imeetcentral.com/eurollingplan/.
IETF
The Building Blocks for HTTP APIs (httpapi) Working Group will standardise HTTP protocol extensions for use when HTTP is used for machine-to-machine communication, facilitated by HTTP APIs. Output can include the following:
- Specifications for HTTP extensions that relate to HTTP APIs (typically, new HTTP header and/or trailer fields)
- Specifications for new message body formats, or conventions for their use in HTTP APIs (e.g., patterns of JSON objects)
- Best practices and other documentation for HTTP API designers, consumers, implementers, operators, etc.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-301-data-economy
IDSA
Dataspace Protocol - The Dataspace Protocol is a set of specifications designed to facilitate interoperable data sharing between entities governed by usage control and based on Web technologies. These specifications define the schemas and protocols required for entities to publish data, negotiate Agreements, and access data as part of a federation of technical systems termed a Dataspace. See the protocol: https://docs.internationaldataspaces.org/ids-knowledgebase/v/dataspace-protocol
ISO
ISO 14721:2012 Space data and information transfer systems — Open archival information system (OAIS) — Reference model
ISO 20614:2017 Information and documentation — Data exchange protocol for interoperability and preservation
ISO 15489 Information and documentation — Records management (multipart)
ISO 20104:2015 Space data and information transfer systems — Producer-Archive Interface Specification (PAIS)
ISO 20652:2006 Space data and information transfer systems — Producer-archive interface — Methodology abstract standard
ISO 16363:2012 “Space data and information transfer systems — Audit and certification of trustworthy digital repositories”
ISO 24143:2022 “Information and documentation — Information Governance — Concept and principles”
ISO/IEC 19987 - EPC Information Services
ISO/IEC 15459 - Information technology — Automatic identification and data capture techniques — Unique identification
ISO/CD TR 24332 Blockchain and Distributed Ledger Technology in relation to authoritative records, records systems, and records management (Joint activity between ISO/TC 46/SC11 and ISO/TC 307)
ISO/IEC JTC 1
ISO/IEC JTC 1/SC 31 - Automatic identification and data capture techniques
ISO/IEC JTC 1/SC 32 Data management and interchange
Standards for data management within and among local and distributed information systems environments
ISO/IEC JTC 1/SC 7 Software and systems engineering
ISO/IEC 25012 “Data quality model” defines a quality model for data in structured format, which can be used to establish requirements, to define measures or to plan and perform data quality assessments. The concept of “data quality” refers to the usefulness of the information derived from data.
ISO/IEC JTC 1/SC 40 IT Service Management and IT Governance
Published standards:
ISO/IEC 38500:2015 Information technology - Governance of IT for the Organization
ISO/IEC TS 38501:2015 Information technology - Governance of IT - Implementation Guide
ISO/IEC TR 38502:2017 Information technology - Governance of IT - Framework and Model
ISO/IEC TR 38504:2016 Governance of information technology — Guidance for principles-based standards in the governance of information technology
ISO/IEC 38505-1:2017 Information technology — Governance of data — Part 1: Application of ISO/IEC 38500 to the governance of data
ISO/IEC 38505-2:2018 Information technology — Governance of data — Part 2: Implications of ISO/IEC 38505-1 for data management
Standards under development:
ISO/IEC FDIS 38503 Information technology — Governance of IT — Assessment of the governance of IT
ISO/IEC PRF TS 38505-3 Information technology — Governance of data — Part 3: Guidelines for data classification
ISO/IEC WD TS 38508 Information technology— Governance of IT— Governance implications of the Use of Shared Digital Service Platform among Ecosystem Organizations
ISO/IEC JTC 1/SC38 - WG 5 – Data in Cloud Computing and related technologies
AWI 20151 Dataspaces. Dataspace concepts and characteristics
ISO/IEC TS 10866 - Organizational Autonomy and Digital Sovereignty. Covers Use Cases which describe the need for organisational autonomy and digital sovereignty.
ISO/IEC JTC 1 SC 27 WG 4 Security controls and services
Published standards:
ISO/IEC 20547-4:2020 “Big data reference architecture — Part 4: Security and privacy”
Addresses the privacy and security issues in the context of big data
Standards under development:
ISO/IEC NP 27045 “Big data security and privacy — Guidelines for data security management framework” Guides data strategy and management with respect to security
ISO/IEC PWI 5181 “Data Provenance – Security and privacy” Highlights security and privacy issues with respect to data provenance
ISO/IEC PWI 6109 “Data life cycle log audit guidelines” Supports data strategies with respect to audit
ISO/IEC JTC 1 SC 27 WG 5 Identity management and privacy technologies: Please see the chapter on cybersecurity
Relevant standards for data security and privacy are developed. Please see the respective chapters on cybersecurity and on ePrivacy in this Foundational Drivers section.
ITU
ITU-T SG20 approved several Recommendations and Technical Report relevant to data in the context of smart cities and communities, which will influence digital transformation of sectors in smart cities, for example: Recommendation ITU-T Y.4472 “Open data application programming interface (APIs) for IoT data in smart cities and communities”, Recommendation ITU-T Y.4498 “Framework for city-level energy data sharing and analytics among buildings”, Recommendation ITU-T Y.4488 “Requirements and functional architecture of data services provided via IoT-based technologies for the safety of manufacturing-related working environments” and Recommendation ITU-T Y.4505 “Minimal Interoperability Mechanisms for smart and sustainable cities and communities”.
ITU-T SG20 also approved by Technical Report ITU-T YSTR.DataModelling-Agri “Data processing, management and analytics with AI for digital agriculture”
Additionally, ITU-T is also progressing draft Recommendations in this field, including a Draft Recommendation ITU-T Y.AIoT-dpsm “Requirements and framework of data processing for smart manufacturing with Artificial Intelligence of Things” and Draft Recommendation ITU-T Y.Evaluation-dfp “Quality evaluation framework of data as a factor of production for smart sustainable cities”
More info: https://itu.int/go/tsg20 / https://u4ssc.itu.int/
ITU-T SG11 approved several new ITU-T Recommendations and Technical Report related to requirements for signalling protocols and testing with regard to data exchange and/or its management, including Recommendation ITU-T Q.3648 “Signalling architecture of data channel enhanced IMS network”; Recommendation ITU-T Q.3742 “Signalling requirements and data models for SD-DCI service”; Recommendation ITU-T Q.5029 “Data management interfaces in digital twin smart aquaculture system with intelligent edge computing”; Recommendation ITU-T Q.5030 “Data management interfaces for intelligent edge computing-based flowing-water smart aquaculture system”;Recommendation ITU-T Q.4104 “Hybrid peer-to-peer communications: Signalling requirements for data streaming service”.
Currently, there are eight ongoing data-related work items within ITU-T SG11.
More info: https://itu.int/go/tsg11
ITU-T FG-AI4AD finalized its mandate and reported to ITU-T SG16 the suggestion to study an automated driving (AD) safety data protocol, specifically designed for post-hoc monitoring of driving behavior. The specification (draft provided in FGAI4AD-TR01) defines the minimum set of data elements and data frames required for analyzing the safe interaction of road users over space and time. It provides a standardized way for automated and assisted driving systems to expose data required for safety monitoring in an open, interoperable manner. This study is currently underway as H.ADSDP-spec.
More info:
https://itu.int/go/FGAI4AD
OASIS
The OASIS Open Data Protocol (Odata) standards support querying and sharing and re-use of data across disparate applications and multiple stakeholders. OASIS OData standards have been approved as ISO/IEC 20802-1:2016 and ISO/IEC 20802-2:2016.
The OASIS ebXML RegRep standards define service interfaces, protocols and information model for an integrated registry and repository. The repository stores digital content while the registry stores metadata that describes the content in the repository.
W3C
Selected List:
Data Catalog Vocabulary (DCAT) - Version 3 (2024-08-22) Recommendation
JSON-LD 1.1 (2020-07-16)
Open Digital Rights Language (ODRL) Version 2.2. (2018-02-15)
Shapes Constraint Language (SHACL) (2017-07-20)
Web Annotation Data Model (2017-02-23)
Data on the Web Best Practices (2017-01-31)
Provenance (Overview with links to standards of the provenance familiy 2013-04-30)
Data Privacy Vocabularies and Controls CG
RDF-DEV CG developing RDFstar extends RDF with a compact way of annotating triples (and creates interoperability with property graphs)
See Data Activity Page for an overview.
(C.2) Other activities related to standardisation
The European Interoperability Framework (EIF)
The European Interoperability Framework (EIF) adopted on 23 March 2017 provides specific guidance on how to set up interoperable digital public services. EIF is undertaken in the context of the Commission priority to create a Digital Single Market in Europe. It offers public administrations 47 concrete recommendations on how to improve governance of their interoperability activities, establish cross-organisational relationships, streamline processes supporting end-to-end digital services, and ensure that both existing and new legislation do not compromise interoperability efforts.
A related on going framework is under development i.e. the Smart Cities and Communities European Interoperability Framework (EIF4SCC). EIF4SCC aims to support local administrations and other actors with challenges that relate to providing interoperability services to citizens and businesses. The Framework intends to support primarily local administrations and, in particular, local policy makers. This work in progress is jointly managed by DG DIGIT as part of the ISA² Programme (2016-2020), and by DG CONNECT in the framework of the Living-in.eu movement.
DILCIS Board
The Digital Information LifeCycle Interoperability Standards Board (DILCIS Board) develops, publishes and supports standards which provide practical interoperability in digital archiving. SIARD (Software Independent Archiving of Relational Databases) v2.2, August 31, 2021) https://dilcis.eu/content-types/siard
eArchiving initiative
Based on the outcomes of the E-ARK project (2014 - 2017) and the eArchiving Building Block (2018-2021) the eArchiving Initiative provides core specifications, software, training and knowledge for information preservation and reuse over the long-term.
More information: https://digital-strategy.ec.europa.eu/en/activities/earchiving
FAIR
Project on FAIR data principes ,
SWIPO
SWIPO (Switching Cloud Providers and Porting Data), is a multi-stakeholder association facilitated by the European Commission, in order to develop voluntary Codes of Conduct for the proper application of the EU Free Flow of Non-Personal Data Regulation / Article 6 “Porting of Data”. See https://swipo.eu
GAIA-X
Gaia-X is the European Association for Data and Cloud AISBL founded with the goal to develop technical solutions and regulatory frameworks and ensure that necessary central facilities as well key federation services to guarantee the envisaged data infrastructure are made available. See https://www.gaia-x.eu/