In a comment on my last post (via LinkedIn), someone mentioned that one of the defining characteristics of a data space is the fact that it sets the rules and legal agreements that allow it to govern itself, which creates the trust necessary for two or more participants to share data. This aligns with my brief discussion of the governance authority, but the missing element for this thinker is that I do not mention the legal agreements explicitly. (Though, in my defense, the words ‘legal framework’ do appear!)
This set me thinking about the legal agreements that should form the basis for the data exchanges taking place within a data space. The fact that legal agreements should exist to share data is not new or unique to data spaces. What would make this unique is if a data space has a specific legal form and framework for this rule creation.
To explore what this means, I find it instructive to explore existing organizational forms and the (legal) structures and obligations that they create for organizations.
A limited liability company, for example, follows particular norms when it comes to rule setting and organizational structure. While these rules can differ by Member State, they are set out by law and give a limited liability company a clearly identifiable form.
The organisational clarity of a limited liability company
A limited liability company requires articles of association or similar founding documents that must be registered with the appropriate authorities. These articles outline governance rules, capital contributions, profit distribution, and transfer restrictions. Many jurisdictions require a minimum share capital.
Some basic elements about how these types of companies are governed are also mandated. A limited liability company typically must hold at least one general meeting every year to approve accounts and address member resolutions. Important decisions are documented in minutes, which are also publicly available.
On reporting, most European limited liability companies must also file annual accounts with a commercial register, making basic financial information publicly available. Depending on company size, these may need to be audited. Many jurisdictions also require a register of members and, increasingly, a register of beneficial owners for anti-money laundering purposes.
Limited liability companies still have a lot of leeway in how they choose to operate and manage themselves. Nonetheless, there are commonalities between all limited liability companies that are embedded in the law.
Data spaces, as defined by the Data Spaces Support Centre, lack this organisational clarity
Returning to the data space, it lacks any kind of law or convention around how it needs to govern itself to be defined as a data space. If I read the building block labelled as organizational form and governance authority from the Data Spaces Support Centre (DSSC), I see decision trees that give many options: in fact, one of the forms for the governance authority that should represent the data space is a limited liability company. But the data space and its governance authority can assume other legal forms as well, including:
- A European Digital Infrastructure Consortium (EDIC), a special legal form which resembles European Research Infrastructure Consortium (ERIC), which support cross-border organisations that are largely publicly funded.
- A European Cooperative Society, which is a non-profit with characteristics of a cooperative and public limited company.
- A European Economic Interest Grouping, which is a non-profit legal entity similar to general partnerships, where members share unlimited liabilities, which flow through to the founding entities.
Each of these forms has specific rules around how they are organized, including how rules are formed and key decisions are made.
At the same time, the building block informs me that a data space can also be unincorporated, without legal form, where rules around rule-making are going to be decided according to an agreement between the various parties that are running the data space. Yet another organisational form that a data space can assume.
The DSSC ‘design principles’ do not help formalise how a data space is governed
Yes, the DSSC also provides a set of high-level ‘design principles‘, describing aspirations (not obligations) on transparency and inclusivity, among other principles. There are brief mentions of rulebook designs by organisations like the International Data Space Association (IDSA) and Sitra, but these are not requirements.
More importantly, there are inherent tensions in some of the principles whose resolution will be determined according to the legal shape of the data space. For example, governance authorities in data spaces are often composed of voting members, which is likely a small subset of the participants in the data space. Because their interests may not reflect all participants equally, there is a structural tension between full transparency and representative decision-making.
Without explicit mechanisms for inclusive representation or conflict resolution, how this tension is resolved likely depends on the legal form of the governance authority. If that’s a limited-liability company, the stated principle of full transparency will likely suffer.
As data spaces evolve, I would expect a clearer organizational form to develop
This ‘long walk’ leads me back to my original definition of the data space, which is the fact that a governance authority sets the rules for the data space in some form; however, this rule-setting function isn’t (yet) defined by law or convention, excepting the rules around the legal form that the governance authority may end up assuming. The fact that a data space has a governance authority remains a defining characteristic, but how those rules are established and enforced is very much an individual decision at the moment.