Governance and Regulatory Compliance
Participating in DEDOMENA.AI's data space means accepting a common rulebook — the Data Space Governance Framework (DSGF): who can join, what's required of them, what they can do with the data they consume, and what happens if they don't comply. This governance framework is what allows participants who don't know each other to exchange data with confidence.
Who Governs the Data Space?
-
Governance Authority: DEDOMENA.AI defines and publishes the data space's rules (DSGF), together with its own self-description as a data space (DSSD, Data Space Self-Description), which sets out the accepted trust mechanisms. It is responsible for ensuring these rules are applied equally to all participants.
-
Data Space Operator: DEDOMENA.AI operates the core services: identity, catalog, and the connector (a standard component based on the Eclipse Dataspace Connector (EDC)) that every participant uses to verify and recognize the identity and privileges of other participants (even those from other data spaces) before negotiating and executing any data exchange.
-
Data or Service Provider: freely sets the price, usage policies, and restrictions on their own data, and is responsible for its lawfulness and quality.
-
Data or Service Consumer: accepts and complies with the provider's policies for every piece of data they consume.
The same organization can hold several roles at once; all of them remain subject to the same data space rules.
How a New Participant Is Onboarded
When registering on the DEDOMENA.AI platform, the user's own data (email and password) is required, along with the fiscal data of the entity they belong to (name, tax ID), the representative (name, national ID, position), and billing information. This information must be valid and verifiable against official trust sources (the accepted trust anchors are defined in DEDOMENA.AI's DSSD).
With acceptance of the governance framework, the DSGF (Data Space Governance Framework) and the Adhesion and Services Agreement documents are presented and digitally signed upon acceptance, generating a document with a unique signature identifier.
Next comes the issuance of participant credentials: a digital certificate, a participant self-description (PSD), and a decentralized identifier (DID) are generated automatically, and together they establish the participant's identity within the data space.
With service activation, the catalog, dataset publishing, and the rest of the contracted modules are enabled.
This information is held and managed by DEDOMENA.AI. Users always have access to it from the Cortex module, in the "My Resources" section.

DEDOMENA.AI is a "Certification Authority," which empowers it to grant, verify, and manage certified, distributable identifiers and credentials for its participants, making them recognizable in any associated data space through a public API for validation.
For every data exchange, DEDOMENA.AI's connectors obtain a DAT (Data Access Token), temporary and limited to the specifications of that particular transaction. This scope is verified through a DAPS, which issues the participant's DAT and verifies the validity of the other party.
What Policies Apply to Each Data Exchange
No data is transferred without a prior agreement between provider and consumer. That agreement always carries the policies the provider selected when publishing their data (see the Marketplace section, organized into three types:
Permissions — what the consumer can do with the data:
-
Use: the most basic permission; consume the data free of charge (can be combined with other policies that restrict it).
-
Buy: a limited, non-exclusive, non-sublicensable, non-transferable license to use a copy of the data.
-
Distribute: permission to share the data with third parties.
-
Train: permission to use the data to train machine learning, AI, or other smart-system algorithms.
-
Synthesize: permission to generate synthetic data from the data (only applies if the original data isn't already synthetic).
Prohibitions — what's expressly forbidden to the consumer:
-
No Distribute: prohibits redistributing the data to third parties.
-
No Resell: prohibits reselling the data.
-
No Public Display: prohibits publicly displaying the data.
-
No Results Public Display: prohibits publicly disclosing results, analyses, or reports obtained from the data.
-
No Train: prohibits using the data to train machine learning, AI, or other smart-system algorithms.
Obligations — what the consumer must comply with once they access the data:
-
Log: an obligation to record access to and use of the data.
-
Notify: an obligation to notify the provider of any security breach involving the data.
-
Publication: an obligation to notify the provider if results, reports, insights, AI models, or products created from the data are made public.
-
Violation: an obligation to notify the provider of any breach of a permission, prohibition, or restriction.
-
Delete: an obligation to delete the data after twelve (12) months.
The provider combines these policies into the package they choose when publishing (for example, "Public Dataset," "Commercial," or "Proprietary"), and the consumer must expressly accept them before being able to access the data.
Data published in the space is also classified by its sensitivity level (public, commercial/confidential, personal, proprietary/highly sensitive); the higher the sensitivity, the stricter the policies the provider typically requires.
The Policy Definition (grouping the selected policies) is set by the provider when publishing an asset, and it becomes a Contract Definition once it's linked to the asset and accepted by the consumer.
Regulatory Compliance
The data space's design takes into account the European regulatory framework applicable to data sharing:
-
GDPR: each participant acts as a controller or processor for the personal data they handle; sensitive data is anonymized or synthesized before publication.
-
Data Governance Act (DGA): obligations specific to neutral data intermediation.
-
Data Act: fair access to data and interoperability between data spaces.
-
AI Act: traceability and documentation of the data used to train or feed artificial intelligence systems.
In Case of Non-Compliance
Non-compliance is handled progressively: a warning, temporary suspension of catalog visibility, revocation of credentials, and, ultimately, termination of participation. Disputes are first resolved through direct negotiation between the parties and, failing agreement, through mediation.