General Information

Abstract

This document provides the foundational concepts and essential characteristics of dataspaces. This document is applicable to all organizations.

Status
Not Published
Current Stage
5020 - FDIS ballot initiated: 2 months. Proof sent to secretariat
Start Date
25-Aug-2026
Completion Date
25-Aug-2026

Buy Documents

Draft

ISO/IEC FDIS 20151-1 - Cloud computing and distributed platforms — Dataspaces — Part 1: Concepts and characteristics

Release Date:11-Aug-2026
English language (23 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC FDIS 20151-1 - Cloud computing and distributed platforms — Dataspaces — Part 1: Concepts and characteristics

Release Date:11-Aug-2026
English language (23 pages)
sale 15% off
sale 15% off

Overview

ISO/IEC FDIS 20151-1:2026, "Cloud computing and distributed platforms - Dataspaces - Part 1: Concepts and characteristics" is an international standard developed by ISO/IEC JTC 1/SC 38. This standard introduces the foundational concepts and essential characteristics of dataspaces, which are collaborative environments that enable trusted, scalable, and interoperable data sharing between organizations. Applicable to all types of organizations, ISO/IEC FDIS 20151-1 provides the conceptual basis for establishing data governance, control, and interoperability in cloud computing and distributed platform scenarios.

Dataspaces facilitate secure data sharing by leveraging agreed governance frameworks, policies, semantic models, and communication protocols. This supports organizations in managing data use, privacy, and compliance while fostering innovation and cross-organizational collaboration.

Key Topics

  • Dataspace Definition: An environment enabling trusted data sharing between participants, underpinned by governance agreements, policies, protocols, and semantic models.
  • Trusted Data Sharing: Mechanisms for organizations to share and access data securely, with clear data use and rights agreements, including data sharing contracts.
  • Governance Frameworks: Structures and policies that define participant roles, data policies, rights, and obligations to ensure compliance, transparency, and accountability.
  • Organizational Autonomy: Participating organizations retain control over their own data, deciding how, when, and with whom the data is shared.
  • Interoperability: Assurance of consistent data exchange and integration through alignment in policy, semantic models, syntactic protocols, and transport mechanisms.
  • Key Characteristics:
    • Maintaining control over data and its use
    • Establishing and building trust among participants
    • Enabling data discovery, negotiation, and contract management
    • Supporting advanced auditing and additional services

Applications

ISO/IEC FDIS 20151-1 is relevant for any organization that needs scalable, secure, and automated methods for data collaboration. Practical applications include:

  • Supply Chain Management: Streamlining data sharing between manufacturers and suppliers to support secondary trade and logistics, while ensuring each party retains necessary data control.
  • Industry Marketplaces: Facilitating data-driven trading and collaboration among competing and cooperating organizations, with clear data use policies and contractual arrangements.
  • Academic Collaboration: Enhancing research partnerships by enabling secure sharing of research data, while clarifying embargoes, usage rights, and data provenance.
  • Government Data Sharing: Improving interdepartmental or intergovernmental data exchange, allowing for compliance with privacy regulations and jurisdictional requirements.
  • Healthcare Consortia: Enabling hospitals, pharmaceutical companies, and research institutions to securely share patient and clinical data for improved outcomes.
  • Vehicle Telemetry and IoT: Supporting collaboration between automotive stakeholders to share performance and maintenance data, driving innovation in smart and connected vehicles.

By adopting the dataspaces approach, organizations can automate and enrich data sharing agreements, track data usage, and leverage new business opportunities while upholding privacy, intellectual property, and compliance requirements.

Related Standards

Organizations looking to implement ISO/IEC FDIS 20151-1 for cloud computing and distributed platform dataspaces should also consult these related standards for comprehensive data governance and interoperability:

  • ISO/IEC 22123-1: Information technology - Cloud computing - Vocabulary
  • ISO/IEC 23751: Specifies requirements for data sharing agreements in the context of cloud computing
  • ISO/IEC 5140: Addresses multi-cloud concepts and interoperability approaches
  • ISO/IEC 38505-1: Provides guidance on governance of data in organizations
  • ISO/IEC 19941: Describes interoperability facets for cloud computing environments
  • Other relevant ISO and IEC standards on data security, privacy, and IT governance

Conclusion

ISO/IEC FDIS 20151-1 provides a standards-based foundation for organizations aiming to establish trusted, interoperable, and well-governed dataspaces. By implementing these concepts, organizations enhance their capabilities to share data securely and efficiently in the evolving landscape of cloud computing and distributed platforms.

Relations

Effective Date
29-Jul-2026

Buy Documents

Draft

ISO/IEC FDIS 20151-1 - Cloud computing and distributed platforms — Dataspaces — Part 1: Concepts and characteristics

Release Date:11-Aug-2026
English language (23 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC FDIS 20151-1 - Cloud computing and distributed platforms — Dataspaces — Part 1: Concepts and characteristics

Release Date:11-Aug-2026
English language (23 pages)
sale 15% off
sale 15% off

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

NYCE

Mexican standards and certification body.

EMA Mexico Verified

Sponsored listings

Frequently Asked Questions

ISO/IEC FDIS 20151-1 is a draft published by the International Organization for Standardization (ISO). Its full title is "Cloud computing and distributed platforms — Dataspaces — Part 1: Concepts and characteristics". This standard covers: This document provides the foundational concepts and essential characteristics of dataspaces. This document is applicable to all organizations.

This document provides the foundational concepts and essential characteristics of dataspaces. This document is applicable to all organizations.

ISO/IEC FDIS 20151-1 is classified under the following ICS (International Classification for Standards) categories: 35.210 - Cloud computing. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/IEC FDIS 20151-1 has the following relationships with other standards: It is inter standard links to CEN/CLC/TS 18331:2026. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

ISO/IEC FDIS 20151-1 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


FINAL DRAFT
International
Standard
ISO/IEC
FDIS
20151-1
ISO/IEC JTC 1/SC 38
Cloud computing and distributed
Secretariat: ANSI
platforms — Dataspaces —
Voting begins on:
2026-08-25
Part 1:
Concepts and characteristics
Voting terminates on:
2026-10-20
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
ISO/IEC FDIS 20151­1:2026(en) © ISO/IEC 2026

FINAL DRAFT
International
Standard
ISO/IEC
FDIS
20151-1
ISO/IEC JTC 1/SC 38
Cloud computing and distributed
Secretariat: ANSI
platforms — Dataspaces —
Voting begins on:
Part 1:
Concepts and characteristics
Voting terminates on:
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
ISO/IEC FDIS 20151­1:2026(en) © ISO/IEC 2026

© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms . 3
5 Trusted data sharing using dataspaces . 3
5.1 General .3
5.2 Features and examples . .4
5.2.1 Features .4
5.2.2 Examples .4
5.3 Operation .5
5.3.1 General .5
5.3.2 Interaction phases .6
5.4 Organizational autonomy .7
5.5 Data governance .7
5.6 Organizational interoperability .8
6 Dataspace concepts and related characteristics . 9
6.1 General .9
6.2 Maintain control .9
6.2.1 Concept . .9
6.2.2 Characteristics of maintaining control .9
6.3 Establish trust . 12
6.3.1 Concept . . 12
6.3.2 Characteristics of establishing trust . 12
6.4 Discover data .14
6.4.1 Concept . .14
6.4.2 Characteristics of discovering data .14
6.5 Negotiate data sharing contracts . . 15
6.5.1 Concept . . 15
6.5.2 Characteristics of negotiating data sharing contracts . 15
6.6 Orchestrate data sharing and data use .16
6.6.1 Concept . .16
6.6.2 Characteristics of orchestrating data sharing and data use .16
6.7 Observe actions .16
6.7.1 Concept . .16
6.7.2 Characteristics of observing actions .17
6.8 Provide interoperability .17
6.8.1 Concept . .17
6.8.2 Characteristics of providing interoperability .17
6.9 Optional services .18
7 Dataspace functional components . 19
7.1 General .19
7.2 Multi-level policies .19
7.3 Semantic models . 20
7.4 Communication protocols . 20
7.5 Processes and rules .21
Bibliography .23

© ISO/IEC 2026 – All rights reserved
iii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 38, Cloud computing and distributed platforms.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.

© ISO/IEC 2026 – All rights reserved
iv
Introduction
The use of data is now part of every aspect of the organization and the ecosystems in which it operates –
such as supply chains, marketplaces and regulatory jurisdictions. As such, the value derived from the use of
data is an important part of most economies.
When an organization itself generates data, it can govern, manage and extract the appropriate value from
that data. However, much of the data used by an organization comes from others – along with possible
restrictions on its use. Similarly, some of the data the organization generates can, with agreement, be used by
others. To facilitate this use of data across multiple organizations – and to respect the rights and obligations
associated with data while doing so – a method of trusted data sharing is needed.
Dataspaces provide a scalable and more automated approach to organizational agreements, and supporting
software services that together enable trusted data sharing.
By providing clarity on the description of the data that is available to be shared as well as the agreed uses for
the shared data, both the data provider and data recipient can make clear choices about data and improve its
operational management as well as its overall governance and value.
This document provides an overview and concepts of dataspaces and their essential and optional
characteristics. It builds on other cloud computing and distributed platforms documents such as
[1] [2] [3]
ISO/IEC 22123-1 , ISO/IEC 23751 and ISO/IEC 5140 which describe cloud computing, data sharing
agreements and multi-cloud concepts.

© ISO/IEC 2026 – All rights reserved
v
FINAL DRAFT International Standard ISO/IEC FDIS 20151-1:2026(en)
Cloud computing and distributed platforms — Dataspaces —
Part 1:
Concepts and characteristics
1 Scope
This document specifies the foundational concepts for dataspaces and their essential characteristics. This
document is applicable to all organizations.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 22123-1, Information technology — Cloud computing — Part 1: Vocabulary
3 Terms and definitions
For the purposes of this document, the following terms and definitions given in ISO/IEC 22123-1, and the
following apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
dataspace
data space
environment (3.14) enabling trusted data sharing (3.6) between participating parties, based on an agreed
governance framework (3.13), along with an agreed set of policies, semantic models, standardized protocols,
processes, and facilitating services
3.2
dataspace participant
participant
party that is acting in a dataspace participant role (3.3)
Note 1 to entry: By being accepted to be a participant in the dataspace, the party agrees to the governance
arrangements and therefore the policies of the dataspace.
3.3
dataspace participant role
participant role
set of activities within a dataspace (3.1) for the purpose of data sharing (3.6) or related activities
Note 1 to entry: Related activities can include auditing or observing roles that do not include data sharing or
governance activities.
© ISO/IEC 2026 – All rights reserved
3.4
dataspace governance authority role
DSGA role
set of activities provided by one or more parties that establishes, governs, manages and enforces the
technical policies and business rules of a dataspace (3.1)
3.5
data policy
human and machine-readable set of rights and obligations regarding access and use of data
3.6
data sharing
access to the same data by more than one authorized entity
Note 1 to entry: Use of the data can be synchronous or asynchronous.
Note 2 to entry: Data can be shared, for example, (i) by allowing access to, or the execution of operations over, the
original dataset, or (ii) by giving a copy of the data to the interested entity.
Note 3 to entry: The way in which data is shared fundamentally influences the available controls and the statements
needed in a data sharing agreement.
[4]
[SOURCE: ISO/IEC 23751:2022 , 3.7, modified - removed 'or processing of']
3.7
data sharing contract
formal and legally binding agreement between dataspace participants (3.3) containing policies, terms and
conditions for data sharing (3.6)
Note 1 to entry: Data sharing contracts usually contain information about access to data, including its metadata, and
data use.
Note 2 to entry: A data sharing contract is usually much more specific than a data sharing agreement which is often
broader and often at an organizational level.
3.8
data use
handling or dealing with data for a specific purpose
[5]
[SOURCE: ISO/IEC 5207:2024 , 3.30, modified – Note 1 to entry removed]
3.9
trust
assumption that a product, service or entity will behave as expected for a given circumstance
3.10
trust anchor
well-defined, shared authority that creates assurances (3.11)
Note 1 to entry: The authority is shared in the sense that its services are used by multiple parties.
Note 2 to entry: The trust anchor can be relied on without the use of other parties.
3.11
assurance
grounds for justified confidence that a claim has been or will be achieved
[6]
[SOURCE: ISO/IEC/IEEE 15026-1:2019 , 3.1.1]
3.12
governance
human-based system comprising directing, overseeing and accountability
[7]
[SOURCE: ISO/IEC 38500:2024 , 3.3]

© ISO/IEC 2026 – All rights reserved
3.13
governance framework
strategies, policies, decision-making structures and accountabilities through which the organization’s
governance (3.12) arrangements operate
[8]
[SOURCE: ISO/IEC TR 38502:2017 , 3.1]
3.14
environment
context determining the setting and circumstances of all influences upon a system
Note 1 to entry: The environment of an entity of interest includes external entities that can have various influences
upon an entity, such as developmental, technological, business, operational, organizational, political, economic, legal,
regulatory, ecological and social influences as well as external physical effects such as electromagnetic radiation,
charged particles, gravitational effects, and electric and magnetic fields.
Note 2 to entry: A label attached as a qualifier to the term environment identifies a particular context within another
context, such as development environment, test environment, and operational environment.
[9]
[SOURCE: ISO/IEC/IEEE 42010:2022 , 3.13]
4 Abbreviated terms
API application programming interface
DSGA dataspace governance authority
DTF dataspace trust framework
5 Trusted data sharing using dataspaces
5.1 General
The rapidly increasing demand for data across various industries has created a pressing need for a solution
that facilitates secure, scalable, and trusted data sharing.
Many organizations (including government departments, academic research groups and businesses) have
high level data sharing agreements at the organization level. Such agreements often take a long time to create
and are then not detailed enough to be usefully enforced or automated. Further they do not describe the
details of particular sets of data to be shared - such as expected quality, time and conditions of use. A more
detailed, more automated approach to negotiating, enacting and enforcing agreements at the organizational
level down to the data level is often needed so organizations can confidently share data.
Traditional data sharing methods often involve centralized repositories (such as a data lake of shared data)
or direct exchanges (e.g. File Transfer Protocol (FTP) or email). Applying these methods at scale among
independent parties can cause difficulties in managing interoperability as well as raise data governance
concerns such as fair value, data use and provenance of data.
Dataspaces offer a novel approach to these challenges by enabling a decentralized and interoperable
ecosystem where organizations can collaborate and share data while maintaining an appropriate level of
control. By establishing a trustworthy environment for data sharing, dataspaces help overcome the barriers
that hinder data-driven innovation and collaboration across different sectors.
At the heart of dataspaces lies the principle of trusted data sharing, which is crucial for fostering collaboration
among participants. Participants in a dataspace can share data knowing that their rights are protected,
and that the data is used in accordance with mutually agreed-upon terms. This trustworthiness is further
reinforced by the ability to enforce data use policies and manage access rights, ensuring that all participants
adhere to the agreed set of policies, semantic models, protocols and processes. As a result, dataspaces not

© ISO/IEC 2026 – All rights reserved
only facilitate data sharing but also create a trustworthy environment where organizations can explore new
business opportunities, innovate, and collaborate.
Dataspaces enable the trusted sharing of data at scale while upholding the rights and obligations associated
with that data. This is achieved through participant collaboration to adopt agreed governance and technical
frameworks. Additionally, by examining characteristics within the dataspace, such as the governance
agreements and claims, organizations can decide to trust the dataspace, other participants and the shared
data.
5.2 Features and examples
5.2.1 Features
Some features of dataspaces that can be helpful in understanding the purpose and goals of dataspaces are:
a) An environment that enables organizations to have the trust to share data in such a way that as a
provider of such data, they can:
1) Easily publish descriptions of the data and its attributes, such as cost, quality, age, refresh rate etc
to those that might be interested (and have the required permissions to access such metadata) in
receiving such data;
2) Negotiate how their data can be used;
3) Create value from the use of their data by trusted dataspace participants;
4) Take steps to ensure their rights associated with the data (e.g. privacy, confidentiality, copyright)
are respected by those with whom they share it
b) The recipient of the data can:
1) Find the data descriptions, including the cost, relevant attributes and data use obligations;
2) Negotiate a contract regarding the transfer, requirements, costs, processing jurisdictions (where
applicable) and other relevant terms.
c) Both participants (provider and recipient) can, via this metadata sharing:
1) Negotiate a contract containing all the relevant policies;
2) Be able to monitor the progress of all relevant activities, including conformance to contracts.
d) Some dataspaces can also (optionally) provide additional services such as:
1) Auditing and other observations of various actions within the dataspace;
2) Escrow or intermediary services to assist in negotiating, orchestration or other data sharing
activities.
5.2.2 Examples
These examples highlight how dataspaces can drive innovation across different sectors, including industry,
academic and government, by enabling secure and trusted data sharing while upholding the rights and
obligations associated with this data:
— Supply chain, where data is shared between organizations in order to facilitate a ‘secondary trade’ such
as machinery etc. In these cases, data, money and physical goods might be traded.
— Industry marketplaces. These are similar to the supply chain, but with multiple vendors and consumers
to choose from. Dataspaces are particularly useful in this case because the participants in the dataspaces
are competing, and only partially collaborating – so ‘trust’ is limited to certain actions, obligations and
subsequent contractual arrangements.

© ISO/IEC 2026 – All rights reserved
— Academic research and collaboration. Academic research collaborations often involve sharing data
collected by member organizations, typically after an agreed embargo period, allowing for further
analysis. Agreements governing data access and sharing are meticulously managed, especially when
specialized and costly research instruments are involved, to address various aspects of data ownership
and usage.
— Government to Government. Having verifiable use of data across difference governments, e.g. different
local, state or national governments, could be very useful and encourage further sharing of such data.
— Interdepartmental sharing of data. This is particularly important in government departments where
employees are reluctant to share data today because they don’t know how it will be used by other
departments. With the right application of policies around use, government employees can know they
are following the appropriate guidelines for data use and data sharing. This scenario is just as important
for large organizations, such as a large multinational corporation that needs to understand data use
across its various divisions.
— Collaborative work, such as multi-vendor projects, cross-organizational committees, training,
diplomatic exchanges, etc.
— Healthcare consortium. In this case multiple hospitals, research institutions, and pharmaceutical
companies collaborate within a dataspace. In this scenario each participant can share de-identified
patient data (e.g. blood test results), clinical trial results, and research findings securely, contributing to
faster medical advancements and more personalised healthcare solutions.
— Vehicle telemetry, where manufacturers, suppliers, and service providers share data related to vehicle
performance, maintenance, and customer preferences. This enables the development of smarter, safer
vehicles.
5.3 Operation
5.3.1 General
A dataspace operates as a distributed system with decentralized decision-making, allowing participants to
retain control over their data while collaborating within a shared framework - and then sharing data in a
peer-to-peer manner.
© ISO/IEC 2026 – All rights reserved
Key
Dataspace dashed circles
Organization Letters (e.g. "E")
Agreements Straight lines
Figure 1 — Dataspaces
Figure 1 shows a logical concept of two dataspaces. Dataspace 01 includes seven participants (A,B,C,D,E,F,H),
while Dataspace 02 includes three participants (G,B,F).
B and F are participants in both dataspaces. This allows them to exercise intra-dataspace interoperability as
well as cross-dataspace interoperability (see 6.8.2.1). Organization K is not in either dataspace, but this does
not preclude it from having a private agreement with organization E.
5.3.2 Interaction phases
5.3.2.1 General
The interaction process between participants within a dataspace is divided into two distinct phases:
the control phase and the data sharing orchestration phase. The control phase is completed before the
commencement of the data sharing orchestration phase.
5.3.2.2 Control phase
During the control phase, participants engage in the following activities:
a) Data publication and discovery: Participants decide what information about their data should be
made discoverable and to which other participants within the dataspace. Information about their data
can include a semantic model to be used to describe the shared data contents and the format to be used
for publication.
b) Negotiation of data sharing contracts: Participants negotiate the terms and conditions of data sharing
contracts.
© ISO/IEC 2026 – All rights reserved
Completion of these activities is necessary before initiating the data sharing orchestration phase. The
processes involved in the control phase are agreed within the dataspace and rely on uniform mechanisms,
remaining independent of specific deployment models and implementation choices.
5.3.2.3 Data sharing orchestration phase
The data sharing orchestration phase is initiated only after the successful completion of the control phase.
The protocols and semantic models employed during this phase are contingent upon the requirements of the
participants and may be defined within the dataspace or through individual data sharing agreements.
This document does not describe any specific requirements regarding the protocols and semantic models
utilized during the actual data sharing which is outside the scope of a dataspace. Note that the data sharing
mechanisms themselves could include any form of data transfer, but could also include a data stream, an API
or other means of the recipient using the data.
5.4 Organizational autonomy
Organizational autonomy is the concept that an organization has sufficient independence to achieve its goals
[10]
(See ISO/IEC TS 10866 ). Note that the term “organization” can include part of a legal entity, such as a
department, or a group of entities, or any other groupings of individuals that have a combined purpose.
A key tenet of a dataspace is that each participant retains organizational autonomy to make decisions
regarding the use of their data, as well as agency to independently act on – and potentially enforce via
technology or contract – those decisions. Examples of such decisions can include “store data in Germany” or
“publicly publish only summary data”.
Organizational autonomy regarding dataspaces enables organizations to extract appropriate value from the
data they generate. This value – and subsequent value generation across the data supply chain – helps create
and maintain “conditions for the trusted sharing of data, including data access rights and the fair allocation
1)
of value generated through the re-use of data” , sometimes called a ‘data economy'.
Within a dataspace, parties exercise their autonomy through their data sharing choices, and in some cases,
through participation or representation in the DSGA role.
While no organization is completely autonomous, the decentralized design of dataspaces allows for such
autonomy. Organizations can decide to forego some degree of autonomy if necessary. For example, to reduce
management costs or infrastructure risks, an organization can decide to host their identity credentials with
a third party, or use a marketplace or intermediary to assist with dataspace management or data sharing.
5.5 Data governance
Good governance of data assists governing bodies in ensuring that the use of data throughout an organization
contributes positively to the performance of the organization.
[12]
ISO/IEC 38505-1 highlights that: “Data is a key asset to any organization. It is used to keep track of the
business (such as people, accounting, inventory and so on) and as a raw material for knowledge, innovation
and insight. The accountability for data and its use rests with the governing body of the organization.”
But the obligations relating to data extend beyond the data that the organization itself generates. Today
many organizations have difficulty answering the following questions:
a) What externally sourced data is the organization using?
b) What is the provenance of the data?
c) Is the data of sufficient quality and certainty, including reliability and collection methodology of its
sourcing, to meet the organization’s needs?
[11]
1) Rolling Plan 2024 for ICT Standardization .

© ISO/IEC 2026 – All rights reserved
d) What are the organization’s obligations and restrictions regarding the use of that data? For example:
1) Does it contain Personally Identifiable Information (PII) (see , ) and does the organization have the
relevant consent to use that data in the manner that the organization is using it – such as in Artificial
Intelligence (AI) systems or in additive manufacturing?When should this data be deleted?
2) How long can the organization use this data for?
3) Are there Intellectual Property Rights (IPR) obligations to consider?
e) What data has the organization shared with other organizations?
1) What rights does the organization have to that data and do those rights include sharing the data
with other organizations?
2) What obligations and restrictions did the organization impose on the recipient of that data?
3) Does the organization know that those rights are being correctly upheld?
4) What jurisdiction is that data now residing in?
Organizations can use their participation in dataspaces to help to answer many of these questions and
thereby improve their overall data governance.
5.6 Organizational interoperability
Interoperability between organizations allows them to “exchange information and to mutually use the
[1]
information that has been exchanged” (see ISO/IEC 22123-1 ).
[13]
The interoperability facet model (See ISO/IEC 19941 ) describes five facets on interoperability for cloud
computing (see Figure 2). But these facets apply equally to dataspaces and are the basis for trusted data
sharing between organizations.
Figure 2 — Facets of interoperability from ISO/IEC 19941
The ability to share data between organizations requires that interoperability can occur at all 5 facets. This
facets approach maps to similar approaches. In dataspaces, the mapping occurs as described in Table 1.

© ISO/IEC 2026 – All rights reserved
Table 1 — Mapping of interoperability facets
ISO/IEC 19941 Facets model Dataspaces interoperability
Policy Policy (see 7.2)
Behavioural Policy includes Behavioural (see 7.2 and 7.5)
Semantic Data Semantic Models (see 7.3)
Syntactic Communication Protocol (see 7.4)
Transport Transport (e.g. REST, HTTP/S) (see 7.4)
See 6.8 for further details on interoperability. Examples of good practices for interoperability include the
[14] [15]
IDSA Rulebook , the European Interoperability Framework and the Ouranos Ecosystem Dataspaces
[16]
Reference Architecture Model .
6 Dataspace concepts and related characteristics
6.1 General
Key characteristics refers to the fundamental properties or features of dataspaces that differentiate it from
other Information Technology paradigms. Each key characteristic covers specific properties or features
that are needed by participants in dataspaces. The key characteristics of dataspaces provide a high-level
statement of the distinguishing features of dataspaces. The key characteristics are decomposed in order to
understand the concepts of dataspaces for typical data sharing scenarios.
The analysis of a key characteristic is not always definitive because the requirements for sharing data can
vary depending on the participants of the dataspace. All the involved parties in the use of dataspaces benefit
from a verifiable statement describing what the characteristic means.
While all dataspaces share these characteristics, some dataspaces may choose to implement additional
optional services. Examples of such services are described in 6.9.
The governance framework and facilitating services of a dataspace are described in this clause. The agreed
set of policies, semantic models, protocols and processes are described in Clause 7.
6.2 Maintain control
6.2.1 Concept
A key characteristic of dataspaces is that participants are able to maintain control of the use of their data
and have a high degree of autonomy regarding where, how and with whom that data is shared. Additionally,
when the data is shared, the provider of that data is able to describe the obligations that go with the use of
the data.
6.2.2 Characteristics of maintaining control
6.2.2.1 General
Dataspaces use claims management, roles, rules and an organizational structure in order to maintain
adequate control of the data that is being shared.
Participants involved in data sharing can, through written agreements, establish in advance the general
terms of the data to be shared and the conditions for its handling. For example, a dataspace data sharing
agreement could reference an existing agreement between the participants.

© ISO/IEC 2026 – All rights reserved
6.2.2.2 Claims management
Claims are attributes of an entity such as its identity, statement of quality, conformity to standards, legal
status, location and so on. They form an important part of the set of verifiable evidence that can be used to
form trust.
Identity is an important attribute and claims regarding identity can allow the ability to describe the
organization’s identity and to accurately describe the identity of others. In a dataspace, it is necessary to
uniquely and clearly identify each participant as well as the resources of dataspace including metadata and
the data itself.
Note that claims management is necessary for dataspaces to function, but that does not mean that a dataspace
needs to actually store any of the associated credentials of these claims. For example, a centralized identity
system would reduce the autonomy of participants because they would no longer control their identity
credentials.
Some claims can be asserted by participants, but it is likely that some fundamental claims will be supported
through the use of a trust anchor and associated framework and credentials (which can be external to the
dataspace). The trust anchor is a trusted and easily verified entity, such as a government department, that
issues credentials to the participant. The use of a trust anchor allows transitive trust across entities to
simplify trust statements.
One of the important aspects of dataspaces is the ability to scale the sharing of data. To achieve this, policies
and claims are in machine-readable format and the ongoing claims verification and their reconciliation to
policies is automated.
6.2.2.3 Roles
6.2.2.3.1 General
While a party can play one or more roles, there are two distinct roles in dataspaces. These are the dataspace
governance authority (DSGA) role and the dataspace participant role.
6.2.2.3.2 Dataspace governance authority (DSGA) role
The DSGA role is a human decision-making role (not technology) which includes activities for the purpose of
governing the dataspace. This role can include responsibility for the following activities:
— Establishing the dataspace;
— Governing the dataspace;
— Managing the dataspace;
— Establishing and enforcing the technical policies and business rules of the dataspace. For example,
recommending or selecting common semantic data models (for understanding data, policies or claims).
The dataspace is governed by the DSGA role, but the role does not represent a central infrastructure or
platform. In some cases, the DSGA role can represent multiple participants of a dataspace, but alternatively
can represent just one party, such as a corporate entity, regulatory authority or government entity.
The decisions of the DSGA role can be implemented by humans (e.g. lawyers writing contracts) or by
technical mechanisms as appropriate.
The decisions of the DSGA role can be implemented by dataspace service providers – however the DSGA role
retains governance (human decision making) control over the services being provided.
A participant is always free to decide for themselves whether to trust another, and to trust those acting as
the DSGA role for a dataspace, however for some dataspaces this will be a "take it or leave it" decision where

© ISO/IEC 2026 – All rights reserved
many participants not acting in the DSGA role will have no real influence on DSGA decisions that will affect
their participation.
EXAMPLE A large industrial organisation uses a dataspace to link members of their industrial supply chain, and
by design they are the only particpant acting as DSGA. Suppliers to the organisation have to accept the polices of the
organisation if they want to participate in the dataspace as a supplier.
6.2.2.3.3 Dataspace participant role
The dataspace participant role includes activities for the purpose of data sharing or related activities that
are distinct from that of the DSGA role. Activities for the participant role can include:
— Publishing information about data to be shared;
— Discovering data that can be shared;
— Negotiating data sharing contracts;
— Orchestrating the sharing of data;
— Controlling data;
— Processing data.
The dataspace participant role can act in many sub-roles, including:
— Data provider;
— Data recipient;
— Data holder;
— Optional sub-roles such as Assistant or Observer.
Example activities for these sub-roles are given in Table 2.
Table 2 — Example sub-roles and associated activities of dataspace participant role
Sub-roles of dataspace participant role Example activities
Data provider Publish metadata relating to the data to be shared
Determine access to published information
Negotiate data sharing contract
Orchestrate data sharing
Data recipient Discover data to be
...


ISO/IEC DISFDIS 20151-1
ISO/IEC JTC 1/SC 38
Secretariat: ANSI
Date: 2026-05-0608-10
Cloud computing and distributed platforms — Dataspaces —
Part 1:
Concepts and characteristics
DISFDIS stage
VVVVoooottttiiiing bng bng bng beeeegigigiginsnsnsns o o o on:n:n:n: 202 202 202 2025555----07070707----21212121
VoVoVoVotintintintingggg t t t tererererminminminminatatatateseseses o o o onnnn::::  2222000022225555----11110000----13131313

ISO/IEC DISFDIS 20151-1:2026(en)
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
at the address below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
E-mail: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 20252026 – All rights reserved
ii
ISO/IEC DISFDIS 20151-1:2026(en)
Contents
Foreword . iii
Introduction . iii
Scope . iii
Normative references . iii
Terms and definitions . iii
Abbreviated terms . iii
Trusted data sharing using dataspaces . iii
General . iii
Features and examples . iii
Operation . iii
Organizational autonomy . iii
Data Governance . iii
Organizational interoperability . iii
Dataspace concepts and related characteristics . iii
General . iii
Maintain control . iii
Establish trust . iii
Discover data . iii
Negotiate data sharing contracts . iii
Orchestrate data sharing and data use . iii
Observe actions . iii
Provide interoperability . iii
Optional services . iii
Dataspace functional components . iii
General . iii
Multi-level policies . iii
Semantic models . iii
Communication protocols . iii
Processes and rules . iii
Bibliography . iii
Foreword . v
Introduction . vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms . 3
5 Trusted data sharing using dataspaces . 3
5.1 General . 3
5.2 Features and examples . 4
5.3 Operation . 5
5.4 Organizational autonomy . 7
5.5 Data governance . 8
5.6 Organizational interoperability . 9
6 Dataspace concepts and related characteristics . 10
© ISO/IEC 20252026 – All rights reserved
iii
ISO/IEC DISFDIS 20151-1:2026(en)
6.1 General . 10
6.2 Maintain control . 10
6.3 Establish trust . 13
6.4 Discover data . 16
6.5 Negotiate data sharing contracts . 16
6.6 Orchestrate data sharing and data use . 18
6.7 Observe actions . 18
6.8 Provide interoperability . 19
6.9 Optional services . 20
7 Dataspace functional components . 21
7.1 General . 21
7.2 Multi-level policies . 21
7.3 Semantic models . 22
7.4 Communication protocols . 23
7.5 Processes and rules . 24
Bibliography . 25

© ISO/IEC 20252026 – All rights reserved
iv
ISO/IEC DISFDIS 20151-1:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types of
document should be noted. This document was drafted in accordance with the editorial rules of the ISO/IEC
Directives, Part 2 (see www.iso.org/directives or
www.iec.ch/members_experts/refdocs).www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the use of
(a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any claimed
patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not received
notice of (a) patent(s) which may be required to implement this document. However, implementers are
cautioned that this may not represent the latest information, which may be obtained from the patent database
available at www.iso.org/patents and https://patents.iec.ch.www.iso.org/patents and https://patents.iec.ch.
ISO and IEC shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.www.iso.org/iso/foreword.html. In the IEC, see
www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 38, Cloud computing and distributed platforms.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.htmlwww.iso.org/members.html and
www.iec.ch/national-committees.
© ISO/IEC 20252026 – All rights reserved
v
ISO/IEC DISFDIS 20151-1:2026(en)
Introduction
The use of data is now part of every aspect of the organization and the ecosystems in which it operates – such
as supply chains, marketplaces and regulatory jurisdictions. As such, the value derived from the use of data is
an important part of most economies.
When an organization itself generates data, it can govern, manage and extract the appropriate value from that
data. However, much of the data used by an organization comes from others – along with possible restrictions
on its use. Similarly, some of the data the organization generates can, with agreement, be used by others. To
facilitate this use of data across multiple organizations – and to respect the rights and obligations associated
with data while doing so – a method of trusted data sharing is needed.
Dataspaces provide a scalable and more automated approach to organizational agreements, and supporting
software services that together enable trusted data sharing.
By providing clarity on the description of the data that is available to be shared as well as the agreed uses for
the shared data, both the data provider and data recipient can make clear choices about data and improve its
operational management as well as its overall governance and value.
This document provides an overview and concepts of dataspaces and their essential and optional
characteristics. It builds on other cloud computing and distributed platforms documents such as ISO/IEC
[1] [4] [3]
22123-1,ISO/IEC 22123-1 , ISO/IEC 23751ISO/IEC 23751 and ISO/IEC 5140ISO/IEC 5140 which
describe cloud computing, data sharing agreements and multi-cloud concepts.
© ISO/IEC 20252026 – All rights reserved
vi
ISO/IEC DISFDIS 20151-1:2026(en)
Cloud computing and distributed platforms — Dataspaces —
Part 1:
Concepts and characteristics
1 Scope
This document specifies the foundational concepts for dataspaces and their essential characteristics. This
document is applicable to all organizations.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 22123-1, Information technology — Cloud computing — Part 1: Vocabulary
3 Terms and definitions
For the purposes of this document, the following terms and definitions given in ISO/IEC 22123-1, and the
following apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— IEC Electropedia: available at http://www.electropedia.org/
— ISO Online browsing platform: available at http://www.iso.org/obphttps://www.iso.org/obp
— IEC Electropedia: available at https://www.electropedia.org/
3.1
dataspace
data space
environment (3.14) enabling trusted data sharing (3.6) between participating parties, based on an agreed
governance framework (3.13), along with an agreed set of policies, semantic models, standardized protocols,
processes, and facilitating services
3.2
dataspace participant
participant
party that is acting in a dataspace participant role (3.3)
Note 1 to entry: By being accepted to be a participant in the dataspace, the party agrees to the governance arrangements
and therefore the policies of the dataspace.
3.3
dataspace participant role
participant role
set of activities within a dataspace (3.1) for the purpose of data sharing (3.6) or related activities
Note 1 to entry: Related activities can include auditing or observing roles that do not include data sharing or governance
activities.
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)
3.4
dataspace governance authority role
DSGA role
set of activities provided by one or more parties that establishes, governs, manages and enforces the technical
policies and business rules of a dataspace (3.1)
3.5
data policy
human and machine-readable set of rights and obligations regarding access and use of data
3.6
data sharing
access to the same data by more than one authorized entity
Note 1 to entry: Use of the data can be synchronous or asynchronous.
Note 2 to entry: Data can be shared, for example, (i) by allowing access to, or the execution of operations over, the original
dataset, or (ii) by giving a copy of the data to the interested entity.
Note 3 to entry: The way in which data is shared fundamentally influences the available controls and the statements
needed in a data sharing agreement.
[4]
[SOURCE: ISO/IEC 23751:2022,ISO/IEC 23751:2022 , 3.7, modified - removed 'or processing of']
3.7
data sharing contract
formal and legally binding agreement between dataspace participants (3.3) containing policies, terms and
conditions for data sharing (3.6)
Note 1 to entry: Data sharing contracts usually contain information about access to data, including its metadata, and data
use.
Note 2 to entry: A data sharing contract is usually much more specific than a data sharing agreement which is often
broader and often at an organizational level.
3.8
data use
handling or dealing with data for a specific purpose
[5]
[SOURCE: ISO/IEC 5207:2024(en),ISO/IEC 5207:2024 , 3.30, modified – Note 1 to entry removed]
3.9
trust
assumption that a product, service or entity will behave as expected for a given circumstance
3.10
trust anchor
well-defined, shared authority that creates assurances (3.11)
Note 1 to entry: The authority is shared in the sense that its services are used by multiple parties.
Note 2 to entry: The trust anchor can be relied on without the use of other parties.
3.11
assurance
grounds for justified confidence that a claim has been or will be achieved
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)
[6]
[SOURCE: ISO/IEC/IEEE 15026-1:2019,ISO/IEC/IEEE 15026-1:2019 , 3.1.1]
3.12
governance
human-based system comprising directing, overseeing and accountability
[7]
[SOURCE: ISO/IEC 38500:2024,ISO/IEC 38500:2024 , 3.3]
3.13
governance framework
strategies, policies, decision-making structures and accountabilities through which the organization’s
governance (3.12) arrangements operate
[8]
[SOURCE: ISO/IEC TR 38502:2017,ISO/IEC TR 38502:2017 , 3.1]
3.14
environment
context determining the setting and circumstances of all influences upon a system
Note 1 to entry: The environment of an entity of interest includes external entities that can have various influences upon
an entity, such as developmental, technological, business, operational, organizational, political, economic, legal,
regulatory, ecological and social influences as well as external physical effects such as electromagnetic radiation, charged
particles, gravitational effects, and electric and magnetic fields.
Note 2 to entry: A label attached as a qualifier to the term environment identifies a particular context within another
context, such as development environment, test environment, and operational environment.
[9]
[SOURCE: ISO/IEC/IEEE 42010:2022,ISO/IEC/IEEE 42010:2022 , 3.13]
4 Abbreviated terms
API application programming interface
DSGA dataspace governance authority
DTF dataspace trust framework
5 Trusted data sharing using dataspaces
5.1 General
The rapidly increasing demand for data across various industries has created a pressing need for a solution
that facilitates secure, scalable, and trusted data sharing.
Many organizations (including government departments, academic research groups and businesses) have
high level data sharing agreements at the organization level. Such agreements often take a long time to create
and are then not detailed enough to be usefully enforced or automated. Further they do not describe the details
of particular sets of data to be shared - such as expected quality, time and conditions of use. A more detailed,
more automated approach to negotiating, enacting and enforcing agreements at the organizational level down
to the data level is often needed so organizations can confidently share data.
Traditional data sharing methods often involve centralized repositories (such as a data lake of shared data) or
direct exchanges (e.g. File Transfer Protocol (FTP) or email). Applying these methods at scale among
independent parties can cause difficulties in managing interoperability as well as raise data governance
concerns such as fair value, data use and provenance of data.
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)
Dataspaces offer a novel approach to these challenges by enabling a decentralized and interoperable
ecosystem where organizations can collaborate and share data while maintaining an appropriate level of
control. By establishing a trustworthy environment for data sharing, dataspaces help overcome the barriers
that hinder data-driven innovation and collaboration across different sectors.
At the heart of dataspaces lies the principle of trusted data sharing, which is crucial for fostering collaboration
among participants. Participants in a dataspace can share data knowing that their rights are protected, and
that the data is used in accordance with mutually agreed-upon terms. This trustworthiness is further
reinforced by the ability to enforce data use policies and manage access rights, ensuring that all participants
adhere to the agreed set of policies, semantic models, protocols and processes. As a result, dataspaces not only
facilitate data sharing but also create a trustworthy environment where organizations can explore new
business opportunities, innovate, and collaborate.
Dataspaces enable the trusted sharing of data at scale while upholding the rights and obligations associated
with that data. This is achieved through participant collaboration to adopt agreed governance and technical
frameworks. Additionally, by examining characteristics within the dataspace, such as the governance
agreements and claims, organizations can decide to trust the dataspace, other participants and the shared
data.
5.2 Features and examples
5.2.1 Features
Some features of dataspaces that can be helpful in understanding the purpose and goals of dataspaces are:
a) An environment that enables organizations to have the trust to share data in such a way that as a provider
of such data, they can:
1) Easily publish descriptions of the data and its attributes, such as cost, quality, age, refresh rate etc to
those that might be interested (and have the required permissions to access such metadata) in
receiving such data;
2) Negotiate how their data can be used;
3) Create value from the use of their data by trusted dataspace participants;
4) Take steps to ensure their rights associated with the data (e.g. privacy, confidentiality, copyright) are
respected by those with whom they share it
b) The recipient of the data can:
1) Find the data descriptions, including the cost, relevant attributes and data use obligations;
2) Negotiate a contract regarding the transfer, requirements, costs, processing jurisdictions (where
applicable) and other relevant terms.
c) Both participants (provider and recipient) can, via this metadata sharing:
1) Negotiate a contract containing all the relevant policies;
2) Be able to monitor the progress of all relevant activities, including conformance to contracts.
d) Some dataspaces can also (optionally) provide additional services such as:
1) Auditing and other observations of various actions within the dataspace;
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)
2) Escrow or intermediary services to assist in negotiating, orchestration or other data sharing activities.
5.2.2 Examples
These examples highlight how dataspaces can drive innovation across different sectors, including industry,
academic and government, by enabling secure and trusted data sharing while upholding the rights and
obligations associated with this data:
— Supply chain, where data is shared between organizations in order to facilitate a ‘secondary trade’ such
as machinery etc. In these cases, data, money and physical goods might be traded.
— Industry marketplaces. These are similar to the supply chain, but with multiple vendors and consumers
to choose from. Dataspaces are particularly useful in this case because the participants in the dataspaces
are competing, and only partially collaborating – so ‘trust’ is limited to certain actions, obligations and
subsequent contractual arrangements.
— Academic research and collaboration. Academic research collaborations often involve sharing data
collected by member organizations, typically after an agreed embargo period, allowing for further
analysis. Agreements governing data access and sharing are meticulously managed, especially when
specialized and costly research instruments are involved, to address various aspects of data ownership
and usage.
— Government to Government. Having verifiable use of data across difference governments, e.g. different
local, state or national governments, could be very useful and encourage further sharing of such data.
— Interdepartmental sharing of data. This is particularly important in government departments where
employees are reluctant to share data today because they don’t know how it will be used by other
departments. With the right application of policies around use, government employees can know they are
following the appropriate guidelines for data use and data sharing. This scenario is just as important for
large organizations, such as a large multinational corporation that needs to understand data use across its
various divisions.
— Collaborative work, such as multi-vendor projects, cross-organizational committees, training, diplomatic
exchanges, etc.
— Healthcare consortium. In this case multiple hospitals, research institutions, and pharmaceutical
companies collaborate within a dataspace. In this scenario each participant can share de-identified patient
data (e.g. blood test results), clinical trial results, and research findings securely, contributing to faster
medical advancements and more personalised healthcare solutions.
— Vehicle telemetry, where manufacturers, suppliers, and service providers share data related to vehicle
performance, maintenance, and customer preferences. This enables the development of smarter, safer
vehicles.
5.3 Operation
5.3.1 General
A dataspace operates as a distributed system with decentralized decision-making, allowing participants to
retain control over their data while collaborating within a shared framework - and then sharing data in a peer-
to-peer manner.
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)

Key
Dataspace dashed circles
Organization Letters (e.g. "E")
Agreements Straight lines
Figure 1 — Dataspaces
Figure 1 shows a logical concept of two dataspaces. Dataspace 01 includes seven participants (A,B,C,D,E,F,H),
while Dataspace 02 includes three participants (G,B,F).
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)
B and F are participants in both dataspaces. This allows them to exercise intra-dataspace interoperability as
well as cross-dataspace interoperability (see 6.8.2.1). Organization K is not in either dataspace, but this does
not preclude it from having a private agreement with organization E.
5.3.2 Interaction phases
5.3.2.1 General
The interaction process between participants within a dataspace is divided into two distinct phases: the
control phase and the data sharing orchestration phase. The control phase is completed before the
commencement of the data sharing orchestration phase.
5.3.2.2 Control phase
During the control phase, participants engage in the following activities:
a) Data publication and discovery: Participants decide what information about their data should be made
discoverable and to which other participants within the dataspace. Information about their data can
include a semantic model to be used to describe the shared data contents and the format to be used for
publication.
b) Negotiation of data sharing contracts: Participants negotiate the terms and conditions of data sharing
contracts.
Completion of these activities is necessary before initiating the data sharing orchestration phase. The
processes involved in the control phase are agreed within the dataspace and rely on uniform mechanisms,
remaining independent of specific deployment models and implementation choices.
5.3.2.3 Data sharing orchestration phase
The data sharing orchestration phase is initiated only after the successful completion of the control phase. The
protocols and semantic models employed during this phase are contingent upon the requirements of the
participants and may be defined within the dataspace or through individual data sharing agreements.
This document does not describe any specific requirements regarding the protocols and semantic models
utilized during the actual data sharing which is outside the scope of a dataspace. Note that the data sharing
mechanisms themselves could include any form of data transfer, but could also include a data stream, an API
or other means of the recipient using the data.
5.4 Organizational autonomy
Organizational autonomy is the concept that an organization has sufficient independence to achieve its goals
[10]
(See ISO/IEC TS 10866).ISO/IEC TS 10866 ). Note that the term “organization” can include part of a legal
entity, such as a department, or a group of entities, or any other groupings of individuals that have a combined
purpose.
A key tenet of a dataspace is that each participant retains organizational autonomy to make decisions
regarding the use of their data, as well as agency to independently act on – and potentially enforce via
technology or contract – those decisions. Examples of such decisions can include “store data in Germany” or
“publicly publish only summary data”.
Organizational autonomy regarding dataspaces enables organizations to extract appropriate value from the
data they generate. This value – and subsequent value generation across the data supply chain – helps create
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)
and maintain “conditions for the trusted sharing of data, including data access rights and the fair allocation of
1)
value generated through the re-use of data” , sometimes called a ‘data economy'.
Within a dataspace, parties exercise their autonomy through their data sharing choices, and in some cases,
through participation or representation in the DSGA role.
While no organization is completely autonomous, the decentralized design of dataspaces allows for such
autonomy. Organizations can decide to forego some degree of autonomy if necessary. For example, to reduce
management costs or infrastructure risks, an organization can decide to host their identity credentials with a
third party, or use a marketplace or intermediary to assist with dataspace management or data sharing.
5.5 Data Governancegovernance
Good governance of data assists governing bodies in ensuring that the use of data throughout an organization
contributes positively to the performance of the organization.
[12]
ISO/IEC 38505-1ISO/IEC 38505-1 highlights that: “Data is a key asset to any organization. It is used to keep
track of the business (such as people, accounting, inventory and so on) and as a raw material for knowledge,
innovation and insight. The accountability for data and its use rests with the governing body of the
organization.”
But the obligations relating to data extend beyond the data that the organization itself generates. Today many
organizations have difficulty answering the following questions:
a) What externally sourced data is the organization using?
b) What is the provenance of the data?
c) Is the data of sufficient quality and certainty, including reliability and collection methodology of its
sourcing, to meet the organization’s needs?
d) What are the organization’s obligations and restrictions regarding the use of that data? For example:
1) Does it contain Personally Identifiable Information (PII) (see , ) and does the organization have the
relevant consent to use that data in the manner that the organization is using it – such as in Artificial
Intelligence (AI) systems or in additive manufacturing?When should this data be deleted?
2) How long can the organization use this data for?
3) Are there Intellectual Property Rights (IPR) obligations to consider?
e) What data has the organization shared with other organizations?
1) What rights does the organization have to that data and do those rights include sharing the data with
other organizations?
2) What obligations and restrictions did the organization impose on the recipient of that data?
3) Does the organization know that those rights are being correctly upheld?
4) What jurisdiction is that data now residing in?

1)
Rolling Plan 2024 for ICT Standardization.

© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)
Organizations can use their participation in dataspaces to help to answer many of these questions – and
thereby improve their overall data governance.
5.6 Organizational interoperability
Interoperability between organizations allows them to “exchange information and to mutually use the
[1]
information that has been exchanged” (See ISO/IEC 22123-1).see ISO/IEC 22123-1 ).
[13]
The interoperability facet model (See ISO/IEC 19941)ISO/IEC 19941 ) describes five facets on
interoperability for cloud computing (see Figure 2). But these facets apply equally to dataspaces and are the
basis for trusted data sharing between organizations.

Figure 2 — Facets of interoperability from ISO/IEC 19941
The ability to share data between organizations requires that interoperability can occur at all 5 facets. This
facets approach maps to similar approaches. In dataspaces, the mapping occurs as described in Table 1.
Table 1 — Mapping of interoperability facets
ISO/IEC 19941 Facets model Dataspaces interoperability
Policy Policy (see 7.2)
Behavioural Policy includes Behavioural (Seesee 7.2 and 7.5)
Semantic Data Semantic Models (see 7.3)
Syntactic Communication Protocol (see 7.4)
Transport Transport (e.g. REST, HTTP/S) (see 7.4)
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)
See 6.8 for further details on interoperability. Examples of good practices for interoperability include the IDSA
[15] [14] [16] [15]
Rulebook , the European Interoperability Framework and the Ouranos Ecosystem Dataspaces
[17] [16]
Reference Architecture Model .
6 Dataspace concepts and related characteristics
6.1 General
Key characteristics refers to the fundamental properties or features of dataspaces that differentiate it from
other Information Technology paradigms. Each key characteristic covers specific properties or features that
are needed by participants in dataspaces. The key characteristics of dataspaces provide a high-level statement
of the distinguishing features of dataspaces. The key characteristics are decomposed in order to understand
the concepts of dataspaces for typical data sharing scenarios.
The analysis of a key characteristic is not always definitive because the requirements for sharing data can vary
depending on the participants of the dataspace. All the involved parties in the use of dataspaces benefit from
a verifiable statement describing what the characteristic means.
While all dataspaces share these characteristics, some dataspaces may choose to implement additional
optional services. Examples of such services are described in 6.9.
The governance framework and facilitating services of a dataspace are described in this clause. The agreed set
of policies, semantic models, protocols and processes are described in Clause 7.
6.2 Maintain control
6.2.1 Concept
A key characteristic of dataspaces is that participants are able to maintain control of the use of their data and
have a high degree of autonomy regarding where, how and with whom that data is shared. Additionally, when
the data is shared, the provider of that data is able to describe the obligations that go with the use of the data.
6.2.2 Characteristics of maintaining control
6.2.2.1 General
Dataspaces use claims management, roles, rules and an organizational structure in order to maintain adequate
control of the data that is being shared.
Participants involved in data sharing can, through written agreements, establish in advance the general terms
of the data to be shared and the conditions for its handling. For example, a dataspace data sharing agreement
could reference an existing agreement between the participants.
6.2.2.2 Claims management
Claims are attributes of an entity such as its identity, statement of quality, conformity to standards, legal status,
location and so on. They form an important part of the set of verifiable evidence that can be used to form trust.
Identity is an important attribute and claims regarding identity can allow the ability to describe the
organization’s identity and to accurately describe the identity of others. In a dataspace, it is necessary to
uniquely and clearly identify each participant as well as the resources of dataspace including metadata and
the data itself.
Note that claims management is necessary for dataspaces to function, but that does not mean that a dataspace
needs to actually store any of the associated credentials of these claims. For example, a centralized identity
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)
system would reduce the autonomy of participants because they would no longer control their identity
credentials.
Some claims can be asserted by participants, but it is likely that some fundamental claims will be supported
through the use of a trust anchor and associated framework and credentials (which can be external to the
dataspace). The trust anchor is a trusted and easily verified entity, such as a government department, that
issues credentials to the participant. The use of a trust anchor allows transitive trust across entities to simplify
trust statements.
One of the important aspects of dataspaces is the ability to scale the sharing of data. To achieve this, policies
and claims are in machine-readable format and the ongoing claims verification and their reconciliation to
policies is automated.
6.2.2.3 Roles
6.2.2.3.1 General
While a party can play one or more roles, there are two distinct roles in dataspaces. These are the dataspace
governance authority (DSGA) role and the dataspace participant role.
6.2.2.3.2 Dataspace governance authority (DSGA) role
The DSGA role is a human decision-making role (not technology) which includes activities for the purpose of
governing the dataspace. This role can include responsibility for the following activities:
— Establishing the dataspace;
— Governing the dataspace;
— Managing the dataspace;
— Establishing and enforcing the technical policies and business rules of the dataspace. For example,
recommending or selecting common semantic data models (for understanding data, policies or claims).
The dataspace is governed by the DSGA role, but the role does not represent a central infrastructure or
platform. In some cases, the DSGA role can represent multiple participants of a dataspace, but alternatively
can represent just one party, such as a corporate entity, regulatory authority or government entity.
The decisions of the DSGA role can be implemented by humans (e.g. lawyers writing contracts) or by technical
mechanisms as appropriate.
The decisions of the DSGA role can be implemented by dataspace service providers – however the DSGA role
retains governance (human decision making) control over the services being provided.
A participant is always free to decide for themselves whether to trust another, and to trust those acting as the
DSGA role for a dataspace, however for some dataspaces this will be a "take it or leave it" decision where many
participants not acting in the DSGA role will have no real influence on DSGA decisions that will affect their
participation.
EXAMPLE A large industrial organisation uses a dataspace to link members of their industrial supply chain, and by
design they are the only particpant acting as DSGA. Suppliers to the organisation have to accept the polices of the
organisation if they want to participate in the dataspace as a supplier.
© ISO/IEC 20252026 – All rights reserved
ISO/IEC DISFDIS 20151-1:2026(en)
6.2.2.3.3 Dataspace participant role
The dataspace participant role includes activities for the purpose of data sharing or related activities that are
distinct from that of the DSGA role. Activities for the participant role can include:
— Publishing information about data to be shared;
— Discovering data that can be shared;
— Negotiating data sharing contracts;
— Orchestrating the sharing of data;
— Controlling data;
— Processing data.
The dataspace participant role can act in many sub-roles, including:
— Data provider;
— Data recipient;
— Data holder;
— Optional sub-roles such as Assistant or Observer.
Example activities for these sub-roles are given in Table 2.
Table 2 — Example sub-roles and associated activities of dataspace participant role
Sub-roles of dataspace participant Example activities
role
Data provider Publish metadata relating to the data to be shared
Determine access to published
...