What is a data space?

David Regeczi
David Regeczi
5 min read

I have been working with the Data Spaces Support Centre as an expert for around two years. How is it that I still don’t know what a data space truly is? If I stand in a parking lot, I can differentiate between a car, a truck, and a motorcycle. But give me a list of sites claiming to be data spaces, and I couldn’t tell you the difference between a platform and a data space.

Normally, I’m used to the social scientists embracing this kind of definitional fuzziness, debating concepts and splitting proverbial hairs in countless ways. But, in conversations with some leading experts, I find that it is the technical people that blur my vision.

Now, when I say that I don’t understand the definition of a data space, this isn’t strictly true. I know how I define it, and for me, there’s clear technical criteria that makes a data space what it is and makes it different from a data platform.

My (technical) definition of a data space

At its most basic level, a data space could consist of two entities that hold and exchange data via the data space protocol. The data space protocol, which is the connective tissue between the data holders, consists of two layers:

  • The transport layer defines how data is transmitted—typically using standard web protocols like HTTPS or MQTT—while supporting authentication, encryption, and message integrity.
  • The control layer manages data access, usage, and policy enforcement, ensuring that data exchanges comply with agreed-upon rules.

In the diagram below, we have two organisations looking to share data: one with CVs for potential employees and another with job openings.

The simplest of data spaces

What’s important to see in the diagram is that the data space has no central repository where data resides. There is no centralised data centre, and the data remains with the data holder. No party makes a copy of the data, but rather enters an environment where they can gain access to it.

From a data sovereignty perspective, this should give a data holder confidence that they retain full control over at least where their data is housed. When working with cloud providers, one needs to work on faith that data will always physically reside where that provider has promised.

Of course, IT departments have consciously moved away from maintaining their own server rooms, and there’s certainly added complexity to storing and securing data that you look to share. Witness the many (many) data breaches that happen on a daily basis. Nonetheless, this is the fundamental element of the data space.

But two servers don’t make a data space: the role of a service provider

Data spaces become more robust environments when they include service providers that analyse the data made available by the data holders. In essence, they make something more out of the data. They do the interesting stuff that people want to see: making maps that give us directions, showing us progress on health goals, or helping us find a job.

In the expanded example below, the service provider provides a matching service to the two data holders. This means that neither data holder has access to sensitive personal data but has what they want—namely a match of CVs and job opportunities. Yet more data sovereignty! Let the EU rejoice.

More of a data space
The final piece: the governance authority

Data spaces can become a complex web of data holders and service providers (among other entities). To keep the data space functioning well, it can adopt a legal form and be run by a governance authority.

This governance authority creates the rules by which data holders and service providers interact, and governs the data space to ensure that those rules are followed. This can include the following elements:

  • Policy and Rule Definition. Establishes the legal, ethical, and operational framework for participation, including data usage policies, consent mechanisms, and compliance with regulations such as the GDPR.
  • Certification and Onboarding. Manages participant admission by verifying their compliance with governance standards, issuing trust credentials, and maintaining registries of verified participants and services.
  • Monitoring and Enforcement. Oversees adherence to the established rules, audits data transactions, and enforces corrective actions or sanctions when violations occur to maintain ecosystem integrity.

But what do the technical people say?

Having spoken with three leading technical experts that have been designing specifications around data spaces, the definition that they provide is decidedly less technical. In general, their answer to ‘what is a data space’ comes down to a number of concepts:

  • Decentralised. Here there is alignment between how I think about data spaces and what the technical people have been telling me. The only difference is that I’m told I’m too hung up on the use of the data space protocol as a defining characteristic.
  • Sovereign. More alignment, though for me, data sovereignty is more of an outcome of the technical infrastructure than a defining characteristic in and of itself.
  • Non-discriminatory or participant autonomy. This is where the governance authority comes into play. The technical people say that the governance authority has obligations to ensure that the data space is governed without a central, controlling actor. Some go further as to argue that a data space cannot discriminate against data holders or service providers.
  • Interoperable. Finally, a data space needs to be interoperable. Whether they mean within the data space or across different data spaces is a point of debate.

While I have no problem with these definitions, when they aren’t anchored in technical boundaries, it becomes difficult to distinguish between a data space and other forms of data sharing. A data-sharing partnership or federated research collaboration could meet these criteria, for example. Without the technical elements, any kind of structured data collaboration could claim to be a data space.

More importantly for me is that some elements–namely around being non-discriminatory or promoting participant autonomy–are clearly points of debate on which experts aren’t agreeing. It seems clear that the data space serves the interests of the governing authority, which is essentially its founding members. But how far can that governance authority go in settings terms and conditions?

Leave a Reply

Your email address will not be published. Required fields are marked *