# Korea's Data Space Initiative (K-Data Space)

- NIA Digital & AI Insights, #2

## Table of Contents

- 01. Concept and Necessity of Data Space
- 02. Global Practices and Standardization
- 03. Korea's Data Space Initiative
- 04. Strategy for Advancing Korea's Data Spaces

## Executive Summary

- Data Space is a decentralized data sharing framework that ensures data sovereignty, interoperability, and trust-based exchange, emerging as an alternative to overcome the limitations of centralized platforms
- The EU is expanding data spaces across regional and industrial sectors, starting with publicly-led Common Data Spaces and through the Gaia-X initiative
- Governance and technical standards are being established to realize data sovereignty, interoperability, and trust-based exchange
  - Including participant authentication, standard metadata, smart contract-based data exchange, and audit trail management
- Early outcomes of data spaces are being generated across public and private sectors within the EU
  - Such as joint responses to climate change (Green Deal Data Space) and supply chain management optimization (Catena-X)
- Japan is also establishing its own domestic data space model (Ouranos Ecosystem)
  - Embarking on data innovation to respond to EU environmental regulations and expand its domestic data sharing ecosystem
- A reference model and key components for building a Korean version of Data Space have been derived by synthesizing overseas data space cases and standardization trends
- The model is structured across three layers:
  - Governance Layer: data sovereignty assurance, consensus-based governance, federated frameworks, trust, and interoperability
  - Business Layer: use case-oriented domain design, participant registration, role and contract management, data access, and settlement and value creation mechanisms
  - Technical Layer: federated catalogs, identity management, policy and contract modules, clearing, and digital tokens
- A new data governance strategy is now needed — one that eliminates barriers to cross-sector data sharing accumulated over time, and creates utilization-driven added value

## 1. Concept and Necessity of Data Space

### 1.1 Concept of Data Space

- Data Space is a framework designed to enable the safe distribution and transaction of data among various participants within a specific organization or country
  - Built upon a policy-based and technical foundation of trust
  - Achieved through decentralized data sharing that guarantees data sovereignty, interoperability, and trust-based exchange
- Rather than relying on a centralized platform, the federation-based distributed structure allows participants to directly control their own data
  - Participants can configure and automatically enforce usage conditions, access rights, sharing history, and more through policy-based mechanisms (IDSA, Gaia-X, etc.)

### 1.2 Background and Necessity of Promoting Data Spaces

- Laying the Technical Foundation to Secure Data Sovereignty
  - Issues with Securing Data Sovereignty at the National and Individual Level

- National Level — Risk of Data Sovereignty Infringement
  - The U.S. CLOUD Act allows U.S. government agencies (e.g., law enforcement) to access data stored on U.S. cloud companies' servers, even if the data belongs to another country
  - This has the potential to technically neutralize the data sovereignty of other nations
- National Level — Efforts and Limitations in Establishing Norms
  - The European Union (GDPR), Japan (DFFT initiative), and South Korea (Personal Information Protection Act, etc.) are promoting cross-border data controls and the establishment of international norms
  - However, most of these efforts remain at the level of legal declarations or policy measures (John D. Dale et al., 2024 / Son Hyeong-seop, 2025)
- National Level — Limitations in Technical Control
  - In centralized overseas cloud environments, data is stored on foreign servers, making practical protection under domestic laws and policies difficult and weakening control at the national level
- Individual Level — Lack of Individual Control
  - Institutionally (e.g., via the Personal Information Protection Act), individuals are guaranteed the right to access, delete, and transfer their data
  - In reality, the structure allows service providers (platforms, cloud companies) to dictate the conditions for data utilization
  - There is a need for the widespread adoption of technical means that allow individuals to directly control the scope of their data's use, whether it is provided to third parties, and its storage location

### Application of Technologies to Secure Data Sovereignty via Data Spaces

- To secure practical data sovereignty, a structure where the data provider can technically control the entire data utilization process is essential, necessitating the introduction of "Data Spaces"
- ① Granular Access Control and Policy-Based Automated Enforcement
  - Data owners can specify and automatically enforce "who" can access the data, "when," and "under what conditions"
- ② Transparent Tracking and Auditing of Data Usage History (Log & Traceability)
  - Enables the management of a history detailing when, for what purpose, and by whom the data was utilized
- ③ Linkage with Usage-Based Compensation Systems
  - Allows for the design of a structure where compensation is delivered to the provider based on data usage history and contracts
- ④ Legal and Regulatory Compliance Verification
  - Supports the automatic verification of the regulatory frameworks of relevant countries and institutions throughout the entire data utilization process
- ⑤ Implementation of a Decentralized Data Processing and Utilization System within a Federated Data Ecosystem
  - Technically controls access and utilization according to predefined policies, allowing consumers to utilize only the processed results within their local environments

### Strengthening Data-Driven Industrial Competitiveness through Interoperability and Reliability

- The increasing demand for high-quality industrial data to support AI Transformation (AX) has exposed structural limitations in current data ecosystems
  - Fragmented data formats, poor interoperability, and isolated data silos hinder efficient data utilization
  - Concerns over confidentiality, data sovereignty, and the inability to transparently manage data access and usage discourage organizations from sharing data across institutional and industrial boundaries

- Issues with Current Industrial Data Distribution and Utilization — Poor Data Interoperability
  - While securing high-quality, specialized data is essential to driving AI Transformation (AX) across manufacturing, robotics, and healthcare, actual industrial sites face inconsistent data formats and structures, resulting in significant time and cost spent refining and standardizing data
  - Consequently, the "data silo" phenomenon — where data accumulates in isolation across departments, organizations, and industries — is intensifying, compromising the interoperability required for integrating heterogeneous data or utilizing it in AI models
- Issues with Current Industrial Data Distribution and Utilization — Concerns Over Industrial Data Leakage
  - Sharing and utilizing data require procedures such as combination, processing, cleansing, anonymization, and pseudonymization; during these processes, concerns arise regarding the external exposure of sensitive information or corporate secrets
  - Because the structure makes it difficult to track who accesses the data, its purpose of use, and its distribution history once provided, many companies experience amplified psychological resistance to data sharing

- Data spaces provide a strategic foundation for overcoming fragmented data ecosystems by combining interoperability, trusted governance, and provider-controlled data sharing
  - Through automated data standardization, policy-based access control, and secure exchange of verified data, they enable organizations to collaborate without relinquishing data sovereignty
  - This trusted data ecosystem supports large-scale utilization of industry-specific data, laying the foundation for Vertical AI development and accelerating AI Transformation (AX) across the industrial sector

- Ensuring Interoperability and Reliability Through Data Spaces
  - The adoption of data spaces is necessary to enable trust-based integration through secure data sharing, control, and automated standardization
- ① Automatic Standardization of Heterogeneous Data and Securing Interoperability
  - Based on technologies such as AAS (Asset Administration Shell) and data harmonization, the system automatically aligns data of different formats into an agreed-upon common standard, reducing the time and cost of standardization and enhancing interoperability
- ② Granting Provider-Centric Control over Data Sharing
  - Provides a structure where data providers can approve or reject cross-industry linkage requests and specify data usage conditions in advance, maintaining control over their data even after sharing
- ③ Establishing a secure exchange system limited to verified data
  - Only data that has undergone technical verification is shared and utilized; distribution is limited to data meeting security and quality standards, minimizing the risk of sensitive information exposure
- ④ Expanding Vertical AI and Creating a Foundation for Industry-Wide AX Innovation
  - Establishes a data ecosystem that supports training of advanced AI models by aggregating and linking industry-specific data, and promotes AI-driven business innovation (AX)

### Securing Federated Governance through Consensus-Based Rules and Autonomous Operation

- Limitations of Existing Centralized Platforms — Rigid Operational Standards and Rules
  - In centralized data platforms, a central institution unilaterally sets and manages standards and rules, including data formats, access procedures, scope of data openness, quality standards, and personal information processing rules
  - Since providers must unilaterally comply with the standards set by the central authority or platform, it is difficult to reflect industry-specific needs and respond flexibly to new technologies and policy changes
- Limitations of Existing Centralized Platforms — Lack of Incentives for Participation
  - Data providers find it difficult to participate in the design process for standards and rules, and must bear legal and security risks, weakening their motivation to share and utilize data and participate in the ecosystem

- Centralized ⇨ Federated Structure, Securing Participant-Centric Flexible Governance
  - It is necessary to overcome the limitations of existing rigid data policies, operational structures, and centralized platforms by building Data Spaces with a federated governance structure that operates autonomously based on participant consensus and ensures interoperability
- ① Establishing a Purpose-Based Collaboration Structure through Federated Governance
  - Data Spaces support purpose-driven, autonomous data collaboration by forming a federation comprising data providers, consumers, platform operators, and technology developers
  - Participants collaboratively define and execute policies, operational rules, transaction terms, and access rights, allowing the ecosystem to operate on flexible, mutually agreed-upon norms rather than rigid external regulations
- ② Consensus-based Establishment of Common Standards and Contractual Rules
  - By independently establishing and managing core elements for data exchange — data standardization, sharing/trading protocols, and technical integration methods — it secures practical interoperability and a trust-based trading structure among participants
- ③ Creating an Open and Fair Data Ecosystem
  - Data Spaces are designed on a decentralized structure where participants share equal rights and responsibilities, rather than depending on a specific company or platform, overcoming closed monopolistic structures and realizing a fair and open governance system

## 2. Global Practices and Standardization

### 2.1 EU Common Data Spaces

- EU Common Data Spaces were launched (February 2020) to strengthen data sovereignty within Europe and facilitate secure data sharing and utilization across industries
  - Strategically based on "A European Strategy for Data"
  - Legally grounded in the Data Governance Act (DGA) and the Data Act

- Core Pillars of the EU Common Data Space
  - Business — Business Model: Designing the business model and operational structure of the data space
  - Business — Use Case Development: Discovering and disseminating practical use cases for value creation
  - Business — Data Product Development: Defining data product templates, establishing provisioning policies, and building network effects
  - Business — Intermediaries: Defining the role of data intermediaries and supporting governance decisions
  - Governance — Regulatory Compliance: Establishing a governance framework to ensure compliance with EU regulations
  - Governance — Contractual Framework: Laying a contractual foundation that defines the rights and obligations among participants
  - Technology — Data Models: Managing common semantic frameworks (ontology) and metadata (vocabulary)
  - Technology — Data Exchange: Providing standards-based APIs and data exchange tools
  - Technology — Provenance & Traceability: Mechanisms for tracking data transaction history and providing proof
  - Technology — Access & Usage Policies: Defining policy-based access and usage conditions (Policy as Code)
  - Technology — Identity Management: Supporting participant identification and authentication systems (e.g., VC, DID) and onboarding

- Multi-layered Operational Structure
  - Overseen by the European Commission, operated by public-private consortiums for each data space, and supported in implementation by technology alliances such as Gaia-X and the Data Spaces Support Centre (DSSC)
- Current Scope
  - The EU is currently establishing a total of 72 data spaces across 14 domains: health, agriculture, manufacturing, energy, mobility, finance, public administration, media, cultural heritage, language, research, tourism, the Green Deal, and skills

- Key Technical Standards: The EU Common Data Space proposes a minimum of three key technical standards and specifications that data spaces must comply with to secure interoperability
- ① Verifiable Credentials (VC)
  - A specification developed by the W3C that supports the creation, sharing, and verification of digital credentials
  - Enables confirmation of authenticity and integrity, along with tamper resistance and cryptographic verification, without relying on a central authority
  - Defines methods for issuing, storing, and presenting credentials to ensure verifiability by all involved parties
  - Various protocols for issuance and verification are under development; OpenID4VC and W3C DCP (Decentralized Messaging Protocol) are cited as primary examples
  - OpenID4VC is a protocol being standardized by the OpenID Foundation, encompassing VC Issuance (OID4VCI), VC Presentation (OID4VP), and Self-Issued OpenID Provider (SIOPv2), managed directly by the user
  - Integrated with the EU's EUDI Wallet architecture and the eIDAS 2.0 framework, with plans to support all EU citizens and legal entities in securely storing digital identities in the EUDI Wallet by 2026
- ② DCAT (Data Catalog Vocabulary) v3
  - Enables organizations to describe datasets consistently, making it easier for users to find and use needed data; designed to be extensible so organizations can add their own properties and classes
  - Includes classes and properties describing datasets and their relationships, creating rich metadata for effective indexing and searching, and supporting data integration, analysis, and reuse across platforms and domains
- ③ Open Digital Rights Language (ODRL)
  - A policy expression language developed by the W3C that specifies permissions, prohibitions, and duties related to digital assets; an essential tool for digital rights and license management, used to express access and usage policies for datasets
  - Includes permissions (allowed actions), prohibitions (forbidden actions), and duties (required actions); can incorporate constraints such as time or location restrictions, as well as duties like fees to exercise a specific right

- The IDSA has developed the Dataspace Protocol
  - Defines methods for distributing datasets as DCAT catalogs, establishing ODRL-based usage control policies, electronically negotiating data usage contracts, and accessing data through transfer protocols
  - Note: This protocol only specifies the common elements; the actual APIs for data exchange are implemented differently for each specific data space
- The EU has developed the Data Spaces Conceptual Model (via the DSSC) to provide guidelines for the configuration and operation of sector-specific data spaces

- ① Conceptual Model for Data Product Registration and Provisioning
  - (Source) DSSC, Data Spaces Blueprint v1.0, Conceptual Model – Data Products and Offerings
  - Data products are classified into Technical Data Products (TDP) and Business Data Products (BDP), which encompass the former
  - A Technical Data Product includes the actual datasets, data services, and derived resources provided, defined through a DCAT-based Metadata Catalog
  - This catalog includes structural definitions for each data resource plus ODRL-based policies (Usage Policies, Access Policies) defining access control and conditions of use, enabling providers to automatically evaluate and provision data according to service conditions
  - A Business Data Product adds operational processes — such as customer support, claims processing, and provisioning procedures — on top of the technical product
  - Based on this, the owner configures Data Product Offerings, which include various Service Levels, Pricing Models, and terms of use
  - A data offering is linked to one or more Smart Contract Templates; customers use these to proceed with contract negotiation and execution, integrating data provisioning and legal contracts within the Data Space
- ② Conceptual Model of Data Product Transactions
  - (Source) DSSC, Data Spaces Blueprint v1.0, Conceptual Model – Data Transactions
  - The EU DSSC's model defines the exchange of data products not merely as a technical transfer, but as a process founded on a contract-driven trust structure and technical infrastructure
  - A data transaction begins with a contract negotiation between a 'Data Product Customer' and a 'Data Product Provider,' based on one of several predefined data product contract templates
  - Once the contract is concluded, both parties enter a legally binding relationship and simultaneously designate an 'Agent' as the technical execution entity
  - These agents are primarily implemented as Data Space Connectors, which execute the actual data transfer, access control, policy enforcement, and catalog referencing
  - The connector utilizes a DCAT-based metadata catalog to provide structural descriptions, codifies access rights and usage conditions using ODRL-based policy language (Policy as Code), and includes built-in Traceability and Provenance mechanisms to track usage history and policy compliance, ensuring transaction transparency and accountability
  - The provider pre-configures and deploys settings (policies, catalog links, data endpoints) to the technical agent; the customer-side agent receives and utilizes the data in the technically contracted manner, implementing the contract–policy–technology linkage and enabling automated contract execution and policy-based control

### EU Data Space Case Study (Green Deal Data Space)

- Overview
  - The Green Deal Data Space (GDDS) is a common data space that integrates various industrial, public, and citizen data in high quality and makes it available in an interoperable manner to support the EU's Green Deal priorities (e.g., climate change response, circular economy, biodiversity, zero pollution)
  - Interfaces include the Green Deal Data Space Portal and the Green Deal Data Space Marketplace
- Key Activities
  - Demonstrating and scaling use cases of data spaces in the Green Deal sector through Lighthouse Projects, R&D projects, and more
- Lighthouse Projects — presenting data space demonstrations and success models in specific industrial domains
  - (Supply Chain Radar) Providing data infrastructure support for supply chain management AI within the PAIRS project, which develops an AI-based solution to predict corporate crisis situations
- R&D Projects — designed to support the execution and market launch of data-driven innovations
  - (CIRCMAN 5.0) Enhancing product modeling and simulation pipelines and assessing environmental sustainability in the manufacturing of photovoltaic (PV) products
  - (SPELL) Providing AI-based decision support to execute crisis prevention, emergency assistance, and response measures — such as for natural disasters and large-scale blackouts — more rapidly and accurately
- Main Data
  - Integration and sharing of environment and climate-centric data provided by EU institutions, member state public agencies, research institutes, private companies, and civil society
- GDDS Data Transaction Procedures
  - A transaction structure where a data provider registers data with specified conditions, and once a user discovers it and agrees to those conditions, the data is securely transferred based on principles of security and transparency
  - Data Provider Listing: Defines data assets and creates transaction conditions for the provider's dataset
  - Data Consumer Purchase Request: The consumer searches the data catalog, reviews the transaction conditions, and accepts them (Smart Contract)
  - Data Asset Transfer and Usage: Once conditions are met, the provider transfers the data to the consumer (Connector)

### 2.2 Gaia-X Data Space

- Overview of Gaia-X
- Purpose of Launch
  - A project launched in 2020, spearheaded by the EU, Germany, and France, aimed at securing data sovereignty within Europe and creating a federated, trust-based data infrastructure ecosystem
  - A strategic attempt to reduce dependence on the cloud and data markets dominated by transnational big tech companies from the US and China, and to establish Europe's own data value chain
- Objectives
  - Rather than building a single centralized platform, the goal is to provide a technical foundation based on a federated structure, allowing various providers and consumers to share data in a trustworthy manner through data spaces and maintain control over their own data
- Gaia-X Framework
  - Operates standards such as common technical architectures and operational policies, along with programs to discover best practices, ensuring data spaces can operate equipped with federation and trust

- Gaia-X Framework Components
  - Technical Standards & Requirements — Gaia-X Architecture Document: Defines the technical structure and design principles for implementing data spaces
  - Technical Standards & Requirements — Data Exchange Document: Defines interoperable data exchange procedures and format standards between providers and consumers
  - Technical Standards & Requirements — Access Management Document: Policies and standards for identity and access management, such as participant authentication and permission settings
  - Technical Standards & Requirements — Ontology: Defines common concepts and semantic systems to enable meaning-based (semantic) linkages between data
  - Technical Standards & Requirements — Reference Toolkit: A set of tools supporting participants in verifying technical compatibility and implementation
  - Compliance — Gaia-X Label Criteria (Level 1~3): Evaluates and specifies by tier that data and services are trustworthy and policy-compliant
  - Compliance — Digital Clearing House (GXDCH): A core trust infrastructure that monitors and verifies data usage history, access rights, and policy violations in real-time
  - Certification Program — Outstanding Data Space Certification Program: Designates excellent data space implementation cases, providing criteria to verify scalability and technical/policy feasibility
  - (Source) Reconstructed based on the Gaia-X Framework

- Gaia-X Ecosystem Common Components
  - Data Ecosystem — Smart Services, Data Spaces: A service space that creates added value using actual data, where higher-layer data-driven services operate
  - Federation Services — Federated Identity Management, Trust and Access Management: Secures trust for data sovereignty-based operations, such as authenticating data subjects and participants, setting trust levels, and establishing an integrated authentication system
  - Federation Services — Federated Catalog (Self-Description, Service Governance, Catalog Management): A catalog based on Self-Descriptions detailing participants' assets (data, services), supporting mutual search and linkage
  - Federation Services — Sovereign Data Exchange (Policy & Usage Condition Setup, Logging & Data Contract Management): Defines policies for sovereign data exchange, sets usage conditions, logs history, and provides contract services
  - Federation Services — Compliance (Defining Rights & Obligations between Providers/Consumers, Certification & Onboarding): Defines and verifies responsibilities, obligations, and rights among participants; certifies compliance and provides onboarding
  - Infrastructure Ecosystem — Compute, Storage, Network, Software Assets (Node, Software Asset, etc.): Physical and virtualized computing resources and the network/storage-based infrastructure components that connect them
  - Governance — Gaia-X Policy Rules, Gaia-X Architecture: Defines the technical and policy operational principles and the standard structure of the data space

- Gaia-X Data Spaces
- Overview
  - Gaia-X supports the demonstration of Lighthouse Data Spaces that meet Gaia-X standards at the technical, operational, and security levels through its Lighthouse projects
- Operational Status
  - As of July 2025, a total of 28 data space demonstrations are underway across sectors including agriculture, manufacturing, and construction
  - Based on their level of compliance with Gaia-X criteria, they are categorized into 3 Qualified Projects, 21 Lighthouse Projects, and 4 Lighthouse Data Spaces

- Key Gaia-X Data Spaces
  - Lighthouse Data Space — Automotive — Catena-X: Key participants BMW, Mercedes-Benz, SAP, Siemens, Fraunhofer; standardized data ecosystem for the entire automotive supply chain, from OEMs to suppliers
  - Lighthouse Data Space — Aerospace — COOPERANTS: Key participants AIRBUS, DLR, Fraunhofer, neusta; heterogeneous data sharing across systems and smart service operations in the aerospace sector
  - Lighthouse Projects — Manufacturing — EuProGigant: Key participants deltaDAO, CONCIRCLE, HELLER, eit Manufacturing; Austro-German joint project aimed at preventing accidents in manufacturing companies
  - Lighthouse Projects — Agriculture — AgrospAI: Key participants I+Porc, FEMAC, GrupoTragsa, TEF; agri-food demonstration project linked with the Common European Agricultural Data Space (CEADS)
  - Qualified Projects — Cloud — FAIR Data Spaces: Key participants Fraunhofer, National Research Data Infrastructure; cloud-based data space for sharing research data between industry and academia
  - Qualified Projects — Construction — DigitalGEO-X: Key participants Cerema, DAWEX, egis, eurostep; creation of a sustainable data sharing environment across the built environment
  - (Source) Reconstructed based on the Gaia-X Lighthouse projects list

- Catena-X is presented as a representative data space case within Gaia-X, implementing data interoperability and trust-based collaboration across the entire value chain of the automotive industry
- Overview of Catena-X
  - An automotive industry-specific data space centered in Germany, establishing a transparent and trustworthy data exchange system across the entire automotive production value chain
  - Participating Entities: Manufacturers, suppliers, and research institutions including BMW, Mercedes-Benz, Volkswagen, ZF Friedrichshafen, Robert Bosch GmbH, SAP, Siemens, T-Systems, Fraunhofer Institute, German Aerospace Center (DLR), etc.
- Key Functions (Catena-X)
  - Carbon Footprint Tracking: Calculates and tracks carbon emissions per product at the battery and component level
  - Battery Passport: Issues a digital ID containing battery production history, usage conditions, recycling information, etc.
  - Supply Chain Risk Analysis: Automatic detection and monitoring of risks for specific suppliers or regions within the supply chain
  - Component Traceability: Manages the lifecycle history from production to installation and disposal of specific components within a vehicle (Digital Twin-based)
- Operating Organization
  - Operating committees and expert groups are active to expand the Catena-X network and achieve common goals

- Catena-X Thematic Committees and Expert Groups
  - Architecture Management: Designs the architecture to ensure Catena-X strategies and goals are realized as actual technology
  - Data Space Operations Committee: Refines operating methods and establishes criteria for releasing and deploying new versions for efficient management
  - Ecosystem Activation Committee: Coordinates regional hubs and drives strategies to expand overseas users
  - Industry Core Committee: Creates core components and broadens the use of standards for application in other industries
  - Internationalization Committee: Promotes global expansion by establishing hubs in key locations like North America, Spain, and China
  - Network Services Committee: Establishes plans for developing common services such as member registration, data search, and identity management
  - Sustainability Committee: Manages standards, roadmaps, and cooperation for implementing Product Carbon Footprints (PCF) and Digital Product Passports (DPP)
  - Supply Chain & Quality Committee: Formulates joint strategies to improve supply chain quality and enhance crisis response capabilities
  - Technical Committee for Modelling: Conducts quality checks on data models before their adoption as international standards
  - Technical Committee for Standardization: Reviews candidates and manages technical procedures when creating new standards

- Catena-X Standards
  - A technical and policy standard framework designed to implement data interoperability and trust-based data exchange within the automotive industry, based on Gaia-X and IDS (International Data Spaces) principles
- Key Catena-X Standards
  - Data Modeling — AAS (Asset Administration Shell): A metadata structure that represents industrial data in the form of a digital twin
  - Identity & Trust Management — VC (Verifiable Credentials): A verifiable representation of participant trust information and asset authentication information
  - Data Exchange & Policy — Usage Policy: Specifies data usage conditions, contract terms, retention periods, etc., in a machine-readable format
  - Data Exchange & Policy — Smart Contract: A contract mechanism that automatically executes conditions, costs, and durations during data exchange
  - Connection / Integration Tech — Dataspace Connector: A standard interface for secure communication between providers and consumers
  - Certification & Compliance — Catena-X Compliance, Gaia-X Labelling Criteria: Technical and policy compliance criteria for participating in the Catena-X ecosystem

- Catena-X Data Space Data Flow
  - ① Identity Identification & Trust Verification: Verifies the participant's identity based on DID and validates the trust level through certificates or VCs — Component: Identity Wallet
  - ② Asset Metadata Registration: Structures assets (products, components) into AAS-based digital representations and registers them in the registry — Components: AAS, AAS Server, Registry
  - ③ Data Provision Preparation: Performs internal system data provisioning (cleansing, formatting) to enable actual provision — Component: Data Provisioning
  - ④ Catalog Search & Connection Request: Searches for the counterpart's data offering in the Federated Catalogue and requests a connection — Component: EDC (Connector)
  - ⑤ Policy Negotiation & Contract Execution: Negotiates and concludes usage conditions, purposes, access restrictions — Component: Smart Contract
  - ⑥ Data Transfer Execution: Securely transmits and receives actual data according to contract terms (using secure protocols like TLS) — Component: Data Transfer (EDC ↔ EDC)
  - ⑦ Application Integration & Utilization: The received data is linked to Enablement Services and business applications for utilization — Components: Enablement Services, Business Applications
  - (Source) Reconstructed based on Catena-X Standards: Framework of Data Exchange

- Gaia-X Digital Clearing House
  - The Gaia-X Digital Clearing House (GXDCH) is a platform that monitors and verifies the reliability of transactions and adherence to common compliance within data spaces

- Operational Status of Gaia-X Digital Clearing House (GXDCH)
  - Aire Networks (Spain): Provides telecommunications infrastructure and cloud solutions; operates a GXDCH instance in the Spanish hub
  - ARSYS (Spain): Specializes in web hosting and cloud services; provides a GXDCH instance in Spain
  - ARUBA (Italy): Italy's largest cloud infrastructure provider; established the initial GXDCH in Italy
  - deltaDAO (Germany): Develops open-source and decentralized data infrastructure; provides a Web3/decentralized GXDCH environment
  - Neusta (Germany): Digital transformation consulting and IT services company; serves as the official GXDCH node for the German technology hub
  - OVHcloud (France): Europe's leading hyperscale cloud company; France-based GXDCH provider
  - Pfalzkom (Germany): Provides data center and network infrastructure; operates as a regional-based GXDCH node
  - Proximus (Belgium): Belgium's leading telecommunications company, actively investing in digital transformation; established and began operating the first GXDCH in Belgium
  - T-Systems (Germany): A global IT services company affiliated with Deutsche Telekom, leading the design and execution of Gaia-X infrastructure

- Key Services of the Gaia-X Digital Clearing House (GXDCH)
  - Mandatory (Free) — Gaia-X Compliance Service: Issues Verifiable Credentials (VC) after confirming compliance status
  - Mandatory (Free) — Gaia-X Registry: Manages the list of trusted credential issuers (Trust Anchors)
  - Mandatory (Free) — Gaia-X Notarization Service: Validates corporate identity prior to issuing VCs
  - Mandatory (Free) — Credential Event Service: Provides distributed storage and synchronization of credentials (VC)
  - Mandatory (Free) — IPFS Node: Decentralized file system nodes that connect GXDCH instances
  - Mandatory (Free) — Logging Service: Provides service record management functions to coordinators (federators)
  - Optional (Paid) — Wizard / User Interface (UI): GUI-based tools for creating and deploying VCs
  - Optional (Paid) — Catalog: Acts as a federated catalog filter for discovering related services
  - Optional (Paid) — Digital Wallet: A digital wallet for securely storing and managing VCs
  - Optional (Paid) — Key Management System (KMS): Provides key lifecycle management for customers' cryptographic materials
  - Optional (Paid) — Policy Decision Point (PDP): Derives conclusions calculated based on multiple policies and input data
  - Optional (Paid) — Data Exchange Service: Provides supplementary data exchange functionalities
  - (Source) Gaia-X Digital Clearing Houses (GXDCH): Gatekeeper of the data economy

- Gaia-X Digital Clearing House Operational Model — GXDCH ↔ Data Space Data Flow
  - Step 1 — Data Space Data Provider (Credential Issuance): Obtains Verifiable Credentials (VC) for data provision and legal entity status — Components: Digital Wallet, Verifiable Credential (VC)
  - Step 2 — Data Provider → Clearing House (Data Registration & Verification): Requests verification to confirm registered data meets Gaia-X compliance standards — Component: Clearing House
  - Step 3 — Data Space Data Buyer (Submission of Intent to Use): Registers and submits the desired data usage purpose and conditions to the Wallet — Component: Digital Wallet
  - Step 4 — Clearing House (Policy Compliance Judgment): Automatically verifies whether the buyer's conditions are compatible with the provider's policies — Component: Usage Policy Verification Engine
  - Step 5 — Clearing House → Data Catalog (Service Search Based on Conditions): Selects data providers from the catalog matching the purpose of use — Component: Data Catalog Metadata Broker
  - Step 6 — Data Catalog → Buyer (Provision of Search Results): Delivers a list of providers satisfying the policy conditions to the consumer — Component: Data Catalog
  - Step 7 — Clearing House (Identifier Generation & History Management): Saves contract execution and data transfer history; tracks policy implementation based on smart contract conditions — Components: Smart Contract, DID Registry, Digital Token

### 2.3 Japan's Ouranos Ecosystem

- Overview and Core Principles of the Ouranos Ecosystem
  - With the goal of ensuring Data Free Flow with Trust (DFFT) and forming a common paradigm for cross-domain data interoperability, industry, academia, and government collaboratively developed and promoted the "Ouranos Ecosystem Initiative" in 2023, led by Japan's Ministry of Economy, Trade and Industry (METI)
  - While the Japanese manufacturing sector improved amid growing pressure for Digital Transformation (DX), industry-wide optimization and data sharing/collaboration across the value chain remained insufficient, prompting the Ouranos Ecosystem concept
  - By enhancing data interoperability across industries, companies, and national borders, the initiative aims to resolve social challenges in Japan — such as labor shortages, climate change, and disaster response — and to accelerate industry-wide DX while strengthening supply chain competitiveness, particularly in manufacturing

- Core Principles of the Ouranos Ecosystem Data Space
  - ① Ensuring Data Sovereignty: A decentralized ecosystem where providers can lead data utilization and business
  - ② Common Policies & Rules: Clear operational standards through a multi-layered governance framework
  - ③ Trust-based Transactions: Secure data utilization based on security by design
  - ④ Interoperability & AI Readability: Securing semantic compatibility and AI usability through schema flexibility
  - ⑤ Service Diversity: Allowing open services that encompass both existing and new services
  - ⑥ Democratic Community: Operating an open community with free participation and withdrawal
  - ⑦ Practical Problem Solving: Emphasizing social value creation, as well as scalable simplicity and practicality
  - (Source) METI, Whitepaper: Ouranos Ecosystem Dataspaces Reference Architecture Model

- Ouranos Ecosystem Data Space Reference Architecture Model (ODS-RAM)
  - METI developed the ODS-RAM to present common elements to consider when establishing the nation's data spaces
  - ODS-RAM is a reference architecture aimed at ensuring the interoperability and reliability of data spaces
  - It consists of 4 layers (①Data, ②Transaction, ③Authentication, ④Semantics) and 4 perspectives (①Service, ②Governance, ③Security, ④Trust)
  - (Layers) Layers that structurally divide the data space by role and function
  - (Perspectives) Directions provided within the data space structure for delivering services to users, operating rules, and securing trust

- Layers and Perspectives of the Ouranos Ecosystem Data Space Reference Model
  - Data Layer (Ensuring data sovereignty, integrity, and quality)
    - Service: Provide storage and retrieval services
    - Governance: Reflect quality management rules and meta-identifiers
    - Security: Encryption and integrity verification during transmission and storage
    - Trust: Secure reliability of data quality and sovereignty
  - Data Transaction Layer (Controlling and verifying data transmission in various formats and methods)
    - Service: Support data exchange, transactions, payments, and settlements
    - Governance: Apply exchange rules and operational standards
    - Security: Secure protocols, integrity verification
    - Trust: Secure reliability of transactions and exchanges
  - Authentication Layer (Identity management responsible for authentication, authorization, and access control)
    - Service: Identity and access management services
    - Governance: Apply access control policies
    - Security: Security design for authentication and authorization
    - Trust: Secure participant reliability and transparency
  - Semantics Layer (Ensuring interoperability through metadata and semantic interpretation)
    - Service: Meaning-based services, search support
    - Governance: Semantics and standardization management
    - Security: Protection of semantic integrity
    - Trust: Secure reliability of data interpretation
  - (Source) Reconstructed based on the Ouranos Ecosystem Dataspaces Reference Architecture Model

- Ouranos Ecosystem Dataspaces Protocols
  - To provide the functionalities required to ensure interoperability between data spaces, the Ouranos Ecosystem Dataspaces Protocols are presented
  - In the reference model, a 'protocol' serves as an interaction rule for the actual implementation and operation of the reference model — a convention ensuring the diverse service functions are consistently integrated and utilized across entities
  - Consists of Fundamental Protocols (mandatory for compliance) and Complementary Protocols (selectively applied to enhance participation convenience)
  - (Fundamental Protocol) Conventions that must be adopted for the Ouranos Data Space to operate at a minimum level
  - (Complementary Protocol) Optional conventions that can be expansively and supplementarily adopted to facilitate easy participation

- Ouranos Ecosystem Dataspaces Protocols (list)
  - Fundamental — Versioning: Management of protocol version information
  - Fundamental — Logging: Recording and observation of historical information
  - Fundamental — Monitoring: Activity management, anomaly detection, and operational optimization
  - Fundamental — Sovereignty: Self-determination and guarantee of data usage conditions
  - Fundamental — Data Trust Assessment: Integrity assessment and provision of results
  - Fundamental — Data Trustworthiness and Quality Assessment: Quality assessment and provision of results
  - Fundamental — Transaction: Control of the data transmission process
  - Fundamental — Identity and Trust: Management of participant identity, authentication, and authorization
  - Fundamental — Metadata Exchange: Sharing and processing of schemas and ontologies
  - Complementary — Discovery and Search: Semantics-based information search and discovery
  - Complementary — Heuristic Contracting: Support for electronic contract execution
  - Complementary — Clearing and Payments: Clearing, payment, and billing for service usage
  - Complementary — Marketplace: Management of data purchases and sales
  - (Source) METI, Whitepaper: Ouranos Ecosystem Dataspaces Reference Architecture Model

- Ouranos Ecosystem Data Space Service Sequence Model
  - Presents the step-by-step data flow, from metadata collection, identity and credential verification, and contract execution, to data exchange, usage logging, and clearing
  - 1. Metadata Collection (Semantics Crawler): Crawls metadata (e.g., RDF) published by providers to collect semantic descriptions of the data of interest
  - 2. Metadata Visualization & Comprehension (Semantics Viewer): Visualizes collected metadata as ER (Entity-Relationship) diagrams or tables, helping consumers grasp its meaning and structure
  - 3. Service Integration Code Generation (Semantics Compiler): Automatically generates API integration modules based on semantic descriptions, supporting rapid adaptation when service versions update
  - 4. Discovery & Search (Discoverer & Discovery Finder): Searches for data or services desired by the consumer and identifies discovery endpoints
  - 5. Data Request (Request Initiation): The consumer initiates a data request for a specific dataset/service (authentication and policy verification run in parallel)
  - 6. Identity & Trust Establishment (Identity Component): Performs mutual authentication between provider and consumer, verifying credentials and attributes
  - 7. Dataspace Connector Initialization (ODS-FDC): The connector receiving the request activates the Control Plane and Data Plane nodes
  - 8. Transmission Routing Setup (Control Plane Orchestrator): Dataplane Selector selects the suitable transmission module; Dataplane Controller instructs start/suspend/terminate; Mutual Authentication re-verifies with the counterpart connector
  - 9. Data Transmission Execution (Dataplane Modules): Executes transmission through the selected module (Web API, Stream, File/Bulk, Media Stream)
  - 10. Data Termination (Terminate): After transmission completes, the control plane issues a Terminate command to end the session; the consumer can resume with a new request if needed
  - 11. Auxiliary Functions Execution: Logging records and aggregates transmission history; Authentication Federation checks the user's authentication status; Managers integrate with Credential, Semantics, and DCS functions
  - (Source) METI, Whitepaper: Ouranos Ecosystem Dataspaces Reference Architecture Model

- Ouranos Data Space Case Study: ABtC (Battery Carbon Footprint Tracking)
  - Overview: As disclosure of the Carbon Footprint (CFP) for EV batteries sold in Europe becomes mandatory from the second half of 2025 under EU battery regulations, this initiative supports compliance while protecting confidentiality; it also aims to resolve social challenges such as carbon neutrality and resource circulation, and strengthen competitiveness through cross-industry cooperation
  - Participants: Automotive OEM manufacturers including ISUZU, HONDA, YAMAHA, and SUZUKI
  - Key Data: Carbon footprint data generated from battery components and manufacturing processes
  - Service: Accurate and transparent calculation, verification, and sharing of product carbon footprint and Due Diligence (DD) information across all stages of the battery supply chain
  - Key Process: Tracking and aggregating carbon footprint across the battery lifecycle → Management based on data sovereignty → Submission to third-party certification bodies → Securing EU regulatory compliance certification → Ensuring continued EV sales in Europe
  - (Source) Project Certification of Ouranos Ecosystem – Ouranos Ecosystem Leading Project

- Battery CFP (Carbon Footprint) Management and EU Regulation Response Process
  - Integration of CFP Calculation Applications: Integrates apps from CFP calculation app providers to aggregate CO₂ emissions across the entire battery lifecycle (raw material procurement → manufacturing → use → disposal/recycling)
  - Ensuring Data Sovereignty: The CFP data provider directly controls the scope of data disclosure and the recipients (including trade secrets)
  - Submission to Third-Party Certification Bodies: Submits the aggregated CFP values as evidentiary data to obtain EU regulatory compliance certification
  - Disclosure to the European Market: Discloses the CFP value along with certification data upon the launch of the battery pack

### 2.4 Data Space Standardization Trends

- IDSA, Promoting Standardization of Data Space Reference Architecture Model
  - IDSA (International Data Space Association) is a global consortium established in 2016 under the leadership of the Fraunhofer Institute in Germany, responsible for developing and operating data space standardization and governance frameworks
  - IDSA developed the Data Space Reference Architecture Model (IDS-RAM) to provide a standard structure supporting trust-based data exchange between companies and institutions
  - It provides a practice-oriented guide for designing and implementing data space architectures; its core structure consists of 5 Layers and 3 Perspectives
  - IDSA independently established the concept of data spaces and is expanding it into ISO/IEC AWI 20151 international standardization in 2024, driving global consensus and institutionalization through the launch of an official working group
  - IDSA's data space model is utilized as a core reference framework ensuring trust and interoperability in Gaia-X, the EU Common Data Space, and Japan's Ouranos Ecosystem

- IDSA Reference Architecture Model (IDS-RAM) Layer·Perspective Matrix
  - Business Layer
    - Security: Defines security requirements in contracts & protection conditions based on data usage purposes
    - Certification: Requires certification of the reliability of participants & organizations
    - Governance: Participation rules, role definitions, contracts & dispute resolution mechanisms
  - Functional Layer
    - Security: Designs access control & policy enforcement functions
    - Certification: Certifies whether connector & service functions comply with standards
    - Governance: Ensures rule compliance during function execution & operates monitoring systems
  - Process Layer
    - Security: Ensures integrity & confidentiality during data request & response processes
    - Certification: Conducts process conformity verification & audits
    - Governance: Secures process transparency & dispute response procedures
  - Information Layer
    - Security: Applies data integrity, anonymization & encryption
    - Certification: Certifies that data format & quality standards are met
    - Governance: Metadata management rules & data management/utilization governance
  - System Layer
    - Security: Applies encryption, authentication-based communication, identity management, & hardware security modules
    - Certification: Certifies IDS Connectors & system components
    - Governance: Operational rules, audit/log management, & system-level governance
  - (Source) Reconstructed based on IDS-RAM 4.0

- The IDSA defines the Data Space Protocol to facilitate trusted data discovery, exchange, and usage by enabling identity verification among participants and contract-based policy enforcement

- IDSA Data Space Process & System Components
  - ① Data Discovery: Consumers search for necessary data resources and verify metadata — Components: Broker, Catalog Service, Self-Description Repository
  - ② Identity & Access Verification: Verifies participant identity and validates data access permissions — Components: Identity Provider (IdP), DAPS (Dynamic Attribute Provisioning Service), Certificate Management (CA/PKI), VC/DID
  - ③ Contract Negotiation & Policy Application: Confirms and agrees data usage terms, enforcing contract-based policies — Components: Contract Negotiation Service, Policy Engine (PDP/PEP)
  - ④ Data Transfer: Executes the actual data exchange according to agreed conditions — Components: Data Connector, Secure Channels (TLS, mTLS), Data Adapters (DB, File, IoT, etc.)
  - ⑤ Usage Control: Continuously applies usage conditions even after transfer — Components: Usage Control Module, Policy Enforcement Point (PEP), Internal Data Apps within the Connector
  - ⑥ Logging & Clearing: Records data exchange and usage history to ensure traceability — Components: Clearing House, Audit Log Service, Blockchain-based Distributed Ledger Technology (DLT)
  - (Source) Reconstructed based on IDS-RAM 4.0

- Germany: Standardization of the Data Space Connector for Trusted Data Exchange
  - The German Institute for Standardization (DIN), in collaboration with IDSA and Fraunhofer AISEC, established the standard for "Security Gateway (Connector) Requirements and Reference Architecture for Industrial Data and Service Exchange" (DIN SPEC 27070, February 2020)
  - Connectors must include fundamental security functions such as Encryption, Integrity Verification (detecting data tampering), and Mutual Authentication (identity verification)
  - Depending on the security level (Base, Trust, Trust+), additional requirements — such as isolated execution environments and prevention of administrator privilege abuse — are mandated

- DIN SPEC 27070 Connector Security Levels (3 Stages)
  - Base: Guarantees basic safety by meeting the minimum security requirements (encryption, mutual authentication, etc.) necessary for inter-enterprise data exchange
  - Trust: Provides enhanced reliability by preventing data tampering and breaches through container isolation and integrity verification
  - Trust+: Ensures the highest level of data sovereignty and safety by applying top-tier security capable of defending even against malicious administrator attacks
  - This connector standard serves as the benchmark for all connector development within the IDSA reference model, and is used as the core framework for verifying standard compliance in EU flagship projects such as Catena-X and Manufacturing-X

- Japan: Standardizing Trust-Based Data Transaction Models
  - The Data Society Alliance (DSA) of Japan, in cooperation with the IEEE, established the IEEE P3800-2024 standard (2024), which defines the reference model and object framework for trust-based data distribution and transaction architecture
  - By adopting this standard, Japan aims to establish a principle-based data transaction reference model as an international standard to ensure interoperability and trust during cross-domain data transactions
  - The framework defines the roles, relationships, and responsibilities of Data Providers, Data Consumers, and the Data Marketplace
  - It models the data transaction workflow from registration and discovery to contracting, data exchange, and settlement
  - Through IEEE P3800, Japan seeks to lead global standards for data transaction systems, pursuing a strategy to secure international influence via a path distinct from the EU's Gaia-X/IDSA models

### Reference. Summary of Global Data Space Cases

- Gaia-X Data Space
  - Overview: A federated data infrastructure project aimed at securing European digital sovereignty (operates 28+ industry-specific "Lighthouse" projects)
  - Key Features: Adheres to IDSA reference models and international standards; federated structure with Self-Description metadata-based catalogs; VC/DID-based identity and policy management; Clearing House for usage logging and settlement tracking
  - Implications: There is a need to design interoperable data spaces by adopting federated architectures that guarantee data sovereignty and trust/settlement systems via Clearing Houses
  - Use Cases: Catena-X (Automotive) — supply chain traceability, Product Carbon Footprint (PCF), quality management, and ESG monitoring
- EU Common Data Spaces
  - Overview: Driven by the "European Strategy for Data," focusing on building 72 data spaces across 14 sectors throughout the EU
  - Key Features: Industry-level implementation of EU data policies; based on EU common standards (DCAT-AP, ODRL, eIDAS); works complementarily with industry implementations like Gaia-X; provides API specifications and toolboxes (common technology, standards, guidelines); data exchange based on smart contracts and usage tracking
  - Implications: Government-led policies and standards must be clearly defined, providing industry-specific toolboxes to help the public and private sectors expand data spaces without excessive cost or time burdens
  - Use Cases: Green Deal Data Space (ESG) — analysis of climate change and biodiversity using satellite, sensor, and urban data
- Japan: Ouranos Ecosystem
  - Overview: A Japanese-style data space initiative led by METI to link manufacturing supply chains
  - Key Features: Benchmarks EU Gaia-X/IDSA models but adapted for Japan's manufacturing and supply chain characteristics; modular design allows combining data spaces to meet specific industry needs; operations based on a sequence model (Registration → Verification → Contract → Exchange → Logging); proprietary authentication for participant registration and policy-based access control
  - Implications: It is necessary to develop customized data space models that reflect domestic industry specifics, ensuring compliance with international standards while remaining practical for real-world industrial application
  - Use Cases: ABtC (Battery) — sharing of battery carbon footprint, raw materials, and supply chain info; interoperable certification systems

### 2.5 Data Space Reference Model Based on Global Case Studies

- By synthesizing international case studies, the common essential components required to implement data spaces across various domestic sectors have been identified
  - The proposed reference model consists of three layers: Governance, Business Layer, and Technical Layer

- Governance Layer
  - By integrating the core principles of the EU, Gaia-X, and Japan's Ouranos, common elements are derived focused on guaranteeing data sovereignty, applying a federated framework based on agreed common rules, ensuring trust, security, and interoperability, and securing transparency, governance flexibility, and participant autonomy
- Common Components of the Data Space Governance Layer
  - Gaia-X case studies: Federated structure & decentralization principles; guarantee of data sovereignty; consensus-based governance; ensuring interoperability; transparency & participant autonomy; trust-based data exchange environment
  - EU Common Data Spaces case studies: Incentive & revenue-sharing systems; securing transparency; guarantee of reliability & security; guarantee of data sovereignty; consensus-based governance & federation; ensuring interoperability; ensuring data reusability & quality
  - Japan Ouranos Ecosystem case studies: Guarantee of data sovereignty; decentralized data exchange structure; federated service operation; consensus-based operation & federation; securing transparency & trust
  - Derived Common Components: Guarantee of Data Sovereignty; consensus-based governance; federated operational structure (common rules among participants); trust-based data exchange and service model operation; ensuring interoperability; securing transparency; governance flexibility and federated participation

- Business Layer
  - The Business Layer encompasses the service and business models of the data space, defining the roles and responsibilities of participants, the value flow of data products and services, and operational mechanisms such as contracting and settlement
  - Through these, it realizes economic and social impacts while ensuring the sustainability of the ecosystem
- Common Components of the Data Space Business Layer
  - Gaia-X case studies: Sector-specific use case development and management; data product definition and permission management; participant registration management (onboarding); role definition and collaborative operation; transparent, policy-based contract management; payment and settlement functions; value creation and ecosystem networking
  - EU Common Data Spaces case studies: Provision of business, organizational, and technical components; data exchange and access rule setting; contract and usage tracking functions; data product and service development; stakeholder-demand-based use case development; definition of roles and responsibilities; cost and revenue model configuration
  - Japan Ouranos Ecosystem case studies: Promotion of sector-specific use cases through cross-industry collaboration; provision of industry-digital collaboration business domains; data sharing and transaction functions; participant registration and qualification verification; rule-based access control; value creation and socio-environmental contribution based on real industrial data
  - Derived Common Components: Participant registration, role, and contract management; development of domain-specific use cases; value creation and incentive design; data access rights and usage policy setting; provision of data products and services; usage logging and settlement/clearing functions
  - By synthesizing the business components of Gaia-X, the EU, and Japan, common elements are derived including domain-centered use case development, participant registration management (onboarding), role/contract management, data access and usage policy setting, settlement functions, and value creation and incentive design

- Technical Layer
  - The Technical Layer defines the underlying technologies, standards, and components that enable the registration, discovery, transfer, management, and settlement of data within a data space
  - It provides the technical infrastructure to ensure that the service models and value flows defined in the Business Layer can be practically implemented and operated
- Common Components of the Data Space Technical Layer
  - Gaia-X case studies: Federated Catalogue; Self-Description Metadata; Identity & Trust Management (DID/VC, Federated Trust Anchor); Policy-as-Code exchange modules; Data Connectors (IDS/EDC Connector); Clearing House; Electronic payments and Token (NFT)/Coin-based settlement
  - EU Common Data Spaces (DSSC) case studies: DCAT-based Metadata Broker; Common Data Models and Reference APIs; Electronic Signature-based identity authentication; Data Connectors (Optional); Policy & Contract Management (ODRL-based, etc.); Smart Contracts & Usage Tracking/Logging modules; Euro (EUR)-based electronic payments
  - Japan Ouranos Ecosystem case studies: Federated Catalog and Metadata Hub; Lightweight Connectors (integration with existing ERP/IoT systems); Sequence-based exchange pipelines; Transaction management and Logging/Clearing modules; Semantic Interoperability Engine; Heuristic Contract-based electronic payments
  - Derived Common Components: Federated Catalog (registration of data products/services based on standardized metadata); Metadata Broker (discovery of data products); Standard APIs & Data Connectors (secure, trust-based data transfer); Identity & Trust Management (DID, VC, eIDAS, etc.); Policy & Contract Management (Policy-as-Code, ODRL, etc.); Usage Logging & Clearing (Clearing House); Electronic Payment & Digital Tokens (NFTs, Stablecoins, etc.)
  - By synthesizing the technical components of Gaia-X, the EU, and Japan, common data technologies are identified, including Metadata Brokers, Federated Catalogs, Data Connectors, DID/VC-based Identity Management, Policy/Contract Management modules, Clearing Houses, and standards like DCAT
  - This reference model serves as the essential set of components for designing and operating data spaces and functions as a guiding framework to facilitate data exchange and utilization across regions and industries, ultimately aiming to align with global standards to secure international interoperability and trust

## 3. Korea's Data Space Initiative

### 3.1 Current Status of Domestic Data Ecosystem

- Insufficient Tangible Effects of Existing Data Systems
  - Despite establishing a legal foundation through the "Framework Act on the Promotion of Data Industry and Use" — which includes standardized contracts, data valuation, and licensing types — these systems have not gained significant traction in actual data trading and utilization fields
  - Lack of Dynamic Settlement: Current domestic data marketplaces and platforms lack a system where settlement and pricing are determined based on actual usage volume or patterns, failing to provide clear compensation for providers and preventing a rational cost structure for consumers
  - Absence of Execution Monitoring: While standardized contracts exist, there is no operational system or consensus body to monitor, track, or prevent unauthorized use (use beyond intended purpose) during contract execution; consequently, disputes rely on reactive legal action or administrative sanctions
  - Data spaces establish a fair compensation system by systematically integrating and managing contract terms and usage history, and provide a trust-based environment by automatically detecting and blocking use beyond the agreed purpose

- Structural Constraints of Centralized Platforms
  - Currently, the 21 sector-specific big data platforms operate on a centralized model where data is aggregated into a single repository, resulting in loss of control for providers and limiting voluntary participation of consumers
  - This structure creates barriers to autonomous cross-industry analysis and data fusion between participants across sectors; the supplier-centric delivery model makes it difficult to produce and distribute high-quality data that meets high market demand
  - Data spaces leverage federated governance and decentralized data exchange structures to connect and utilize data at its source, enabling seamless data fusion and distribution of high-quality data while ensuring providers maintain full control

- Limits of Data Collaboration and Business Model Creation
  - Current domestic data marketplaces and platforms lack a functional collaboration mechanism between providers and consumers, forcing providers to manually seek out and onboard consumers, making sustainable data-driven business model creation difficult
  - High-value data, such as high-quality AI training datasets, remains restricted due to regulatory burdens and ambiguities in current laws (e.g., Copyright Act, Personal Information Protection Act); despite being the area of highest demand, this data does not circulate effectively in the market
  - Most data platforms and marketplaces focus on functions centered around data processing and sales, such as providing raw data or processed outputs (e.g., reports)
  - Platforms generally operate in a unidirectional (Provider → User) structure, with almost no cases of project-based collaboration aimed at creating new services or business models
  - The Data Space Solution: Data spaces facilitate collaboration between providers and consumers, allowing autonomous development of business models; beyond secure utilization of high-value data, they support the creation of a virtuous data ecosystem spanning production and creation to distribution
  - Despite establishing and officially announcing common standardized terminology for domestic data platforms, field adoption remains insufficient; data formats and terms vary by institution, and inconsistent quality control makes it difficult to ensure data integrity and consistency
  - From the providers' perspective, there is a hesitant stance due to fear of losing rights and control over their data once provided (NIA, 2024)

- Improvement Directions for Domestic Data Platforms (AS-IS Big Data Platforms → TO-BE Data Space)
  - Primary Function: AS-IS — Collecting and aggregating public/private data to provide services via processing and analysis; TO-BE — Trust-based data sharing and creation of innovative services through collaboration
  - Storage & Management: AS-IS — Institutions and companies migrate and aggregate data to a central platform; TO-BE — Data stays at source (retained/managed by each entity) with distributed/federated access control
  - Operational Model: AS-IS — Led by the platform operating agency; TO-BE — Consensus-based operation involving providers, consumers, and operators
  - Demand Creation: AS-IS — Providers must manually discover consumers; TO-BE — Joint participation of providers and consumers to co-discover business models and collaboration opportunities
  - Revenue & Settlement: AS-IS — Centered on fixed-fee or one-time contracts, difficult to reflect actual usage or post-trade conditions; TO-BE — Automated settlement and profit distribution based on Smart Contracts and Clearing Houses

### 3.2 Government Initiatives to Establish and Scale Data Spaces in Korea

- ① Ministry of Science and ICT (MSIT)
  - To overcome the limitations of fragmented data utilization caused by data asset protection–centric environments, MSIT is promoting the adoption of data spaces as a foundational framework for accelerating AI Transformation (AX) across sectors
  - Beginning with the healthcare sector, MSIT plans to gradually expand the data space model, enabling each organization to retain ownership of its original data while allowing authorized use whenever necessary
  - Launch of the Korea's Medical Data Space (June 2026)
  - To address the fragmentation between existing public-private big data platforms and emerging data spaces, MSIT launched the National Data Infrastructure (NDI) initiative in 2024
  - The initiative aims to provide a unified gateway for discovering and linking public and private data while strengthening interoperability among data spaces through a federated data catalog and common compliance framework
  - Model for the National Data Infrastructure (NIA, 2025)

- ② Ministry of Trade and Industry (MOTIE)
  - MOTIE regards industrial data spaces as a key enabler for AI-driven manufacturing transformation and compliance with evolving global regulations
  - It defines industrial data spaces as a trusted infrastructure supporting data exchange, sharing, verification, and transactions throughout the entire supply chain
  - MOTIE is promoting the development and demonstration of a standardized industrial data space model through the Manufacturing AI Transformation Alliance (M.AX Alliance)
  - MOTIE is also pursuing international cooperation, including interoperability with Germany's Manufacturing-X initiative to establish a trusted data exchange ecosystem
  - It seeks to strengthen data-driven regulatory compliance in response to expanding global supply chain regulations, such as the EU Digital Product Passport (DPP)
  - Hosting Korea-Germany Industrial Dataspace Forum (Oct 2025)

- ③ Policy Implications
  - The policy directions of both MSIT and MOTIE demonstrate a shared recognition that expanding AI adoption and responding to global regulatory changes require more than individual projects or standalone digital platforms
  - Both ministries emphasize the importance of establishing structural national- and industry-level foundations that enable trusted data utilization
  - MSIT focuses on strengthening data connectivity and utilization through sector-specific data spaces and the National Data Infrastructure
  - MOTIE is advancing industrial data spaces as trusted infrastructures for data exchange, verification, and transactions across supply chains while promoting international collaboration
  - Together, these initiatives indicate an emerging policy consensus that future AI competitiveness will depend not only on the capabilities of individual organizations, but also on trusted data-sharing mechanisms, interoperable data ecosystems, and governance frameworks that enable secure and scalable data collaboration

### 3.3 Korea's Data Space Reference Model

- Major international data space reference models — including IDSA IDS-RAM, DSSC Data Space Reference Architecture, and the Ouranos Reference Architecture Model (RAM) — primarily define common building blocks that enable data exchange and utilization among participants, such as data catalogs, identity and access management, and connector-based interoperability
  - However, capabilities supporting AI-driven analytics and services, as well as data trading and settlement, are only partially addressed
- Building upon these international reference models, the Korean Data Space Reference Model reorganizes data space building blocks into two domains: Governance and Architecture
  - These building blocks are further classified into Common Building Blocks (essential capabilities) and Extended Building Blocks (optional capabilities) to provide a more systematic and scalable framework
- To address the limited coverage of AI utilization in existing reference models, the Korean model introduces AI infrastructure components as extended building blocks
  - This enables data spaces to evolve beyond secure data exchange into comprehensive platforms supporting AI model development, distributed analytics, and AI-enabled service creation

- Korea's Data Space Governance Building Blocks
  - The Korea's Data Space governance model is designed as a federated collaboration ecosystem centered on shared trust and consensus for data and AI utilization, rather than on specific technologies or platforms
  - A data space is not a centrally controlled environment; it enables providers and consumers to participate while retaining sovereignty over their own data, with collaboration established through agreed common policies, rules, and operational procedures
  - Governance functions not merely as a collection of operational rules, but as the core operating mechanism that continuously defines, coordinates, and enforces what is permitted, how responsibilities are allocated, and how trust is established across the entire lifecycle of data access, integration, AI training, and service deployment
  - Through this governance framework, the Korean Data Space extends beyond secure data exchange to provide an environment where AI models and data-driven services can be safely developed, validated, and scaled under agreed rules, while ensuring fair value distribution and fostering an autonomous yet accountable ecosystem for data and AI collaboration

- Korea's Data Space Reference Architecture Building Blocks
  - The Korean Data Space Reference Architecture presents a trust-based, federated architecture that enables data providers and consumers to securely connect, exchange, and utilize data through standardized data connectors while preserving their respective systems and data sovereignty

- Korea's Data Space Reference Architecture Model
  - The model presents a trust-based, federated architecture enabling organizations to securely connect, exchange, and utilize data while maintaining ownership of both their data and underlying systems
  - Rather than relying on centralized data collection, the architecture allows providers and consumers to collaborate through standardized data connectors, ensuring interoperability, data sovereignty, and policy-driven access control across heterogeneous environments
  - The model integrates governance, common services, and technical building blocks into a unified architecture that supports trusted data collaboration at scale
  - (Source) Korea's Data Space Reference Architecture Model (NIA, 2026); Korea's Data Space Reference Model Ver 1.0 (NIA, 2026)
  - Unlike existing international reference models, which primarily focus on secure data exchange and interoperability, the Korean model is designed to support the entire data value creation lifecycle
  - In addition to core functions such as metadata management, identity and access management, connectors, and policy enforcement, the architecture incorporates capabilities for data contracts and settlement, AI-ready data processing pipelines, audit logging, and federated service integration
  - This enables data spaces to evolve from simple data-sharing infrastructures into platforms that facilitate continuous collaboration, value creation, and sustainable ecosystem growth
  - The architecture extends conventional data space capabilities by incorporating an AI Lab Workspace and an ontology-based semantic framework
  - The AI Lab provides a shared execution environment supporting capabilities such as Compute-to-Data (C2D), AI model training and fine-tuning, GPU computing resources, MLOps, model registry, validation, and data preprocessing, enabling participants to develop and utilize AI models while maintaining data sovereignty
  - The ontology framework provides a common semantic foundation enabling consistent interpretation of concepts, relationships, and contextual information across heterogeneous datasets and domains
  - Together, these capabilities support interoperable data utilization, AI-driven analytics, and the development of data-driven services within a trusted and federated data space environment
  - The architecture defines a standardized end-to-end workflow for trusted data sharing and utilization, integrating participant onboarding, federated data exchange, policy enforcement, contract management, secure data utilization, lifecycle auditing, and AI-ready capabilities including Compute-to-Data (C2D), federated learning, and semantic interoperability

- Korea's Data Space Standard Data Flow
  - 1. Onboarding: Establish trusted participation through participant identification, authentication, and onboarding — Key Technologies: Decentralized Identifier (DID), Verifiable Credential (VC), Digital Wallet, Level of Assurance (LoA)
  - 2. Data Space Connector Connection: Establish a federated data connectivity environment between organizational systems and the data space — Key Technologies: Connector as a Service (CaaS), Self-hosted Connector, Data Space Protocol (DSP)
  - 3. Data & Service Registration and Validation: Register metadata in the federated catalog and validate data quality, schema, and publication requirements — Key Technologies: Self-Description, ODRL-based Usage Policy, Schema & Metadata Validation
  - 4. Data & Service Discovery: Discover available datasets and services through federated catalogs — Key Technologies: Federated Catalog, Semantic Hub, Ontology-based Mapping
  - 5. Access Authorization & Policy Verification: Verify access rights and usage conditions according to provider-defined policies — Key Technologies: PDP/PEP/PIP Architecture, ODRL Policy Evaluation, Attribute-Based Access Control (ABAC)
  - 6. Data Contract Establishment: Negotiate and establish contractual agreements between providers and consumers — Key Technologies: Peer-to-Peer Data Contract, Payment Mechanism Integration
  - 7. Data Preparation: Prepare and transform data according to contractual and policy requirements before utilization — Key Technologies: Data Profiling, De-identification, Data Standardization, Semantic Mapping
  - 8. Data Access & Utilization: Execute secure data exchange and AI-enabled utilization under agreed policies and contracts — Key Technologies: Data Exchange, Compute-to-Data (C2D), Federated Learning, API-based Exchange
  - 9. Data Lifecycle Logging & Auditing: Record and manage the complete lifecycle of data usage for traceability and compliance — Key Technologies: W3C PROV-based Provenance, Audit Logging, Traceability
  - 10. Settlement, Dispute Resolution & Post-Operation Management: Manage settlement, revenue distribution, dispute resolution, and post-transaction operations — Key Technologies: Revenue Sharing, Usage-based Settlement, Dispute Resolution

## 4. Strategy for Advancing Korea's Data Spaces

- ① Phased Development and Expansion of Data Spaces
  - In the initial stage, multiple small-scale data spaces will be established at the industry and service levels, taking into account legal, regulatory, and technical considerations
  - Through diverse pilot projects, interoperability among standards, contractual and policy frameworks, and technical building blocks will be validated
  - Based on pilot results, the ecosystem will be progressively expanded by increasing participants, broadening the scope of data, and enhancing service capabilities
  - Federation among individual data spaces will ultimately enable the development of a scalable and interconnected data ecosystem
- ② Expanding Data Spaces Beyond Regulatory Compliance Toward Vertical AI
  - While Europe has primarily adopted data spaces as a means of regulatory compliance, their industrial utilization and business value creation remain relatively limited
  - Korea aims to move beyond compliance-oriented adoption by actively identifying and scaling Vertical AI use cases across industries
  - By establishing a virtuous cycle connecting data provision, data utilization, and AI-driven service creation, Korea's data spaces will foster business opportunities and strengthen AI competitiveness across industrial sectors
- ③ From Government-Led Demonstration to a Private Sector–Driven Ecosystem
  - During the initial phase, the government will lead the establishment and operation of data spaces by defining core foundations — standards, technical architectures, and contract and settlement models — while generating reference implementations through pilot projects
  - As the ecosystem matures, responsibility will gradually shift to the private sector, enabling organizations to autonomously provide and utilize data, develop value-added services, and establish a sustainable, market-driven data ecosystem
- ④ Improving Accessibility Through Data Space as a Service (DaaS)
  - In the long term, core data space capabilities — including connectors, data registration and discovery, contract management, and policy management — will be provided as Data Space as a Service (DaaS)
  - This enables organizations to participate in data spaces without deploying dedicated technical infrastructures
  - The approach will lower entry barriers for SMEs and a broader range of stakeholders, promote creation of new data-driven services and value-added business opportunities, and encourage wider participation across the entire data space ecosystem

## Glossary

- Data Space: A decentralized data-sharing space where various participants can securely and reliably share and utilize data while maintaining data sovereignty within a distributed infrastructure environment
- VC (Verifiable Credential): A digital credential issued and verified to reliably prove a participant's identity or data usage rights
- DID (Decentralized Identifier): A unique digital identifier directly controlled by individuals or organizations without a central authority, used to identify the issuer or subject within a VC
- Data Connector: A technical component that exposes data or services hosted on an organization's IT infrastructure to the Data Space environment, supporting actual data access in connection with a catalog platform
- Metadata Broker: An intermediary service that collects, manages, and provides metadata between providers and consumers, supporting data discovery and utilization in conjunction with a data catalog
- Smart Contract: An automated contract executing on a blockchain, where terms are automatically performed when specific conditions are met, enabling trust-based automated transactions without intermediaries
- Token Economy: An economic system that designs economic value and incentives using tokens; within a Data Space, tokens can be used to trade data or adjust access privileges
- Policy as Code: A method of defining policies in code form to enable automated processing and execution; advantageous for consistency and automation, as policies can be version-controlled, automatically deployed, and tested like software code
- Policy Engine: The central component that evaluates policies and makes decisions; receives requests from a Policy Enforcement Point (PEP), interprets the policy, and issues an approve or deny decision
- PEP (Policy Enforcement Point): The component that actually enforces policies in a policy-based access control system; forwards user requests to the Policy Decision Point (PDP) and allows or blocks access based on the result
- ODRL (Open Digital Rights Language): A W3C standard language developed to express rights, obligations, and restrictions regarding digital assets in a machine-readable format; in a Data Space, it is used to automatically interpret and execute policies set by providers
- IDSA (International Data Spaces Association): A non-profit organization established in 2016 under German law that plays a key role in establishing a standardized data exchange framework by defining the Reference Architecture Model (IDS-RAM), Rulebook, and Data Space Protocol (DSP); over 140 global companies and institutions participate as members
- Data Catalog: A system or tool that systematically collects and manages metadata for data assets, empowering users to easily search, explore, understand, and utilize data
- Digital Clearing House: A platform that mediates transactions, payments, and settlements between providers and consumers, performing tasks such as data license management, payment processing, and access right coordination
- Self Description: A mechanism for providing a description of an entity independently; e.g., a document or structure in which a system component or service self-describes its own functions, policies, and identification information
- DAPS (Dynamic Attribute Provisioning Service): A service that dynamically provisions and verifies credentials or attributes; in environments like Data Spaces, used as a necessary component for participant authentication and attribute-based access control
- Onboarding: The formal procedure through which a new participant enters a Data Space, undergoes identity registration and authentication, and officially joins the network
- Ontology: A knowledge representation framework that formally defines concepts and relationships within a specific domain; in a Data Space, it ensures semantic interoperability by providing a common semantic framework among participants
- W3C PROV: A W3C recommended standard for describing the provenance, creation process, and responsible entities of data and processes; used to secure data reliability and traceability
- AAS (Asset Administration Shell): A core concept of Industry 4.0; an international standard data structure designed to realize digital twins by representing physical assets — such as machines, equipment, and products — as digital information for advanced utilization
- DFFT (Data Free Flow with Trust): A global data governance principle proposed by Japan at the 2019 G20 Osaka Summit; ensures free flow of data while safeguarding privacy, security, and intellectual property rights; widely used as a core keyword in international discussions at the OECD, WTO, and EU
- GDPR (General Data Protection Regulation): The EU's personal data protection regulation, enforced since May 2018; applies strict standards for the processing of personal information and guarantees user rights
- GAIA-X: A European data and cloud infrastructure project launched in 2020, led by Germany and France; aims to build a safe, reliable data-sharing ecosystem through open standards and common specifications to secure data sovereignty and enhance interoperability
- DSSC (Data Spaces Support Centre): An institution supported by the European Commission, established to facilitate the development and ensure the interoperability of various Data Spaces within Europe; develops common frameworks, technical reference architectures, and guidelines
- Compute-to-Data: A mechanism where providers do not directly export data externally; instead, algorithms are sent to the data's location to perform computations, and only results are shared, protecting data sovereignty and privacy while allowing external researchers to derive value
- Data Silos: A phenomenon where data becomes isolated and disconnected within organizational units, preventing sharing and utilization across other systems; can lead to data duplication and reduced consistency and operational efficiency
- DAO (Decentralized Autonomous Organization): A decentralized digital organization operated through blockchain and smart contract-based governance; members participate in decision-making via blockchain-based voting mechanisms
- eIDAS: A legal and institutional framework enacted to mutually recognize and guarantee electronic identification (eID) and trust services for electronic signatures and transactions across the EU

## References

- Data Spaces Support Centre (2025), Blueprint v2.0 — https://dssc.eu/space/BVE2/1071251457/Data+Spaces+Blueprint+v2.0+-+Home
- European Commission (2025), Common European data space — https://digital-strategy.ec.europa.eu/en/policies/data-spaces
- Green Deal Dataspace (2025) — https://green-deal-dataspace.eu/
- ADVANEO Data Marketplace (2025) — https://www.advaneo-datamarketplace.de/en/#
- Gaia-X Framework (2025) — https://docs.gaia-x.eu/#/framework
- Gaia-X (2025), Gaia-X Architecture Document — https://docs.gaia-x.eu/technical-committee/architecture-document/25.05/
- Gaia-X (2025), Gaia-X Lighthouse Projects — https://gaia-x.eu/community/lighthouse-projects/
- Catena-X (2025), Catena-X Expert Groups & Committees — https://catena-x.net/association/expert-groups-committees/
- Catena-X (2025), Catena-X Standardization — https://catena-x.net/association/standardization/
- Gaia-X (2025), Gaia-X Digital Clearing House (GXDCH) — https://gaia-x.eu/services-deliverables/digital-clearing-house/
- Gaia-X (2024), Gaia-X and Catalogues — https://gaia-x.eu/gaia-x-and-catalogues/
- METI (2025), Ouranos Ecosystem
- METI (2025), Ouranos Ecosystem Dataspaces Reference Architecture Model
- Automotive and Battery Traceability Center (ABtC) — https://abtc.or.jp/en
- IDSA (2025) — https://internationaldataspaces.org/
- International-Data-Spaces-Association, IDS-RAM 4.0 — https://github.com/International-Data-Spaces-Association/IDS-RAM_4_0/tree/main/documentation/3_Layers_of_the_Reference_Architecture_Model
- IDSA (2025), Data Space Protocol — https://internationaldataspaces.org/offers/dataspace-protocol/
- Ministry of Science and ICT (2025), One-Window — https://www.data1window.kr/
- National Information Society Agency (NIA) (2024), Concept and Implementation Strategy for National Data Infrastructure
- Kim, Geon-wook, Daegu Digital Innovation Promotion Agency (DIP) (2025), Implementation of a Mobility Data Exchange and Transaction System Based on a Decentralized Data Space
- Alexander Bott et al (2025), Challenges in Implementing Gaia-X for Industrial Applications, 2025
- Catena-X (2025), Business Areas in the Catena-X Ecosystem — https://catena-x.net/overview-use-case-cluster/
- John D. Dale et al (2024), "Data Free Flow with Trust": Japan's struggle to integrate democracy and human rights into digital trade policy
- Son, Hyeong-seop (2025), A Comparative Study of the Revised Personal Information Protection Act and Japanese Law – Focusing on the Domestic and International Transfer of Data
- Oh et al (2026), Korea's Data Space Reference Model Ver 1.0, 2026
- European Data Protection Board (2025), International Data Transfers — https://www.edpb.europa.eu/sme-data-protection-guide/international-data-transfers_en

## Publication Information

- NIA Digital & AI Insights Series
- Korea's Data Space Initiative (K-Data Space)
- Published by: National Information Society Agency (NIA); Hyung Chul Kim, President
- Original Authors
  - AI Policy Department — Young Joo Lee, Executive Principal
  - AI Data Department — Daehoon Oh, Principal Manager
- English Edition Prepared by: Department of Global ICT Cooperation
  - Yoon-seok Ko, Vice President
  - Hyang-nae Jeon, Director
  - Sora Jeong, Senior Manager
  - Won Ko, Manager
