Abstract
The use of data is paramount both to inform individual decisions and to address major global challenges. Data are the lifeblood of the digital economy, feeding algorithms, currencies, artificial intelligence, and driving international services trade, improving the way we respond to crises, informing logistics, shaping markets, communications and politics. But data are not just an economic commodity, to be traded and harvested, they are a personal and social artifact. They contain our most personal and sensitive information – our financial and health records, our networks, our memories, and our most intimate secrets and aspirations. With the advent of digitalization and the internet, our data are ubiquitous - we are the sum of our data. Consequently, this powerful treasure trove needs to be protected carefully. This paper presents arguments for an international data governance framework, the barriers to achieving such a framework and some of the costs of failure. It also articulates why the United Nations is uniquely positioned to host such a framework, and learning from history, the opportunity available to solve a global problem.
‘The world isn't run by weapons anymore, or energy, or money. It's run by ones and zeros - little bits of data. It's all electrons. There's a war out there, a world war. It's not about who has the most bullets. It's about who controls the information - what we see and hear, how we work, what we think. It's all about information.
Cosmo – Sneakers (1992)
Introduction
The use of data is paramount both to inform individual decisions and to address major global challenges. Data are the lifeblood of the digital economy, feeding algorithms, currencies, artificial intelligence, and driving international services trade, improving the way we respond to crises, informing logistics, shaping markets, communications and politics. 1 But data are not just an economic commodity, to be traded and harvested, they are a personal and social artifact. They contain our most personal and sensitive information – our financial and health records, our networks, our memories, and our most intimate secrets and aspirations. With the advent of digitalization and the internet, our data are ubiquitous - we are the sum of our data. 2 Data also lie at the core of human development and planetary wellbeing and are essential to humanitarian aid.
There are many types of data: personally identifiable or PII / non-PII; sensitive / non-sensitive; public / private; personal / non-personal to list a few dichotomies. Data are being generated every second of every day by our myriad social and economic interactions: our spending and travel patterns, our online search queries and shopping decisions, our reading habits, our television and movies choices, our social media posts. Satellite imagery, surveillance cameras, smart meters, the financial markets – literally everything we do generates data. These data, and their derivative statistics, provide the fuel for economies, facilitate innumerable social interactions, and contribute to the evidence needed to formulate and assess regional, national and international policies and programmes e.g., Agenda2030 and the Sustainable Development Goals. They are used to allocate public services, understand population trends and to redistribute political representation. They can be merged with other data to derive new data and new data products, and if used responsibly, can generate economic value and social benefit.
A growing recognition of the need for international data governance
There has been a steadily growing interest in the twin subjects of digital and data governance over the past decade (see Figure 1) (See also Online Annex 1 that details some of the debate around data and digital governance). This general interest has been paralleled by a growing number of calls from across the private-public spectrum for both global digital and data governance frameworks.3,4 This growing interest has been provoked by a range of issues, from the growing numbers of reported data breaches (In the European Union alone, between May 25, 2018 (the date GDPR was introduced) and August 2022 (the date of the cited report) there were 160,921 reported data breaches.
5
Reliable global estimates are harder to come by but one security company, Surfshark, estimates that in 2022 alone, there were some 310.8 million data breaches globally.
6
), misuse of data for electoral or political advantage (This can range from the manipulation of official statistics for political advantage
7
- a highly publicized example of this was the falsification of Greek public finance statistics8,9 - to the alleged weaponization of data to manipulate to electoral processes themselves.10–12) to more extraordinary events, such as the sale of an entire populations genetic code to a biotech company by their own government.
13
Many of the regulatory data frameworks developed to date by countries have focused on privacy and data protection, open data or localization measures.
14
Now there are calls for greater technical and legal interoperability that balances the demands of individual rights and local values with the need to move and share data.
Source
15
– google search of key phrase ‘data governance’, January 2004 – October 2023.
In recognition of the importance of data and data governance globally, the United Nations System Chief Executives Board for Coordination (CEB) https://unsceb.org/about endorsed the position paper International Data Governance – Pathways to Progress 1 in May 2023. Over two years in development, the report was the culmination of significant discussion prompted by a call for global data governance in the 2021 World Bank's World Development Report: Data for Better Lives, 16 which called for a new Social Contract for data, to enable the use and re-use of data to create economic and social value in a way that fosters equitable opportunities and trust. The World Bank report also included a call for action from the Committee for the Coordination of Statistical Activities (CCSA), the body responsible for the coordination of statistical programmes between international agencies, (see https://unstats.un.org/unsd/ccsa/), which highlighted the need for a new global consensus on data. Later that same year the UNCTAD Digital Economy Report 2021: Cross-border data flows and development: For whom the data flow 17 called for a multilateral consensus, and for digital and data governance, noting the importance of data as strategic assets for the creation of both private and social value. Both of these reports highlighted the importance of engaging lower- and middle-income countries. The Committee of Chief Statisticians of the UN System (CCS-UN) (https://unstats.un.org/unsd/unsystem/) had also published several blogs3,18 and papers 4 highlighting the need for international data governance.
The Data Strategy of the Secretary-General for Action by Everyone, Everywhere 19 (UN, 2020) also demonstrated the importance of data governance across the UN system itself. With a vision to build 'a whole-of-UN data ecosystem that maximizes the value of our data, we unlock our full potential: We make better decisions and deliver stronger support to people and planet – in the moments that matter most’, the strategy set out clearly the importance of data for the UN mission while reaffirming that data must be used responsibly and in a way consistent with UN values and human rights. It highlighted the need for improved data governance, and robust data protection and privacy, but also improved data accessibility, sharing, and interoperability. The need to provide an adaptive governance framework was emphasized so that data can be managed as a strategic asset across the UN. The strategy built on 12 data principles (asset; excellence; data protection and privacy; agency; fairness; accountability; transparency; ownership; stewardship; security; inventory; and optimization.) and made a number of priority recommendations with regard to data governance, including that UN entities each develop a data strategy, a data governance framework and appointing a chief data officer.
There is no straightforward answer to this question. In the drafting of the CEB paper, the authors took the broadest view possible, so in principle, all data are within scope. All data, irrespective of who generated it (public or private sector), how it was produced (survey, administrative, passive etc.), whether it is sensitive or non-sensitive, or in what form it is held (digital or analog; aggregate or individual; processed or raw; private or public). However, as the CEB paper is only a position paper to inform deliberations, and UN member states have yet to formally mandate progress on this issue, it remains to be seen what data might remain in scope if any international data governance framework were to be agreed.
Aside from the scope issue noted above, it is also worth exploring what is meant by data more generally. There are many definitions of data to choose from. The Cambridge English dictionary defines data as ‘information, especially facts or numbers, collected to be examined and considered and used to help decision-making, or information in an electronic form that can be stored and used by a computer’ (https://dictionary.cambridge.org/dictionary/english/data). This definition is interesting as it limits data to digital data and excludes analog. The European Union too has introduced this limitation into their definition of data, defining data as ‘any digital representation of acts, facts or information and any compilation of such acts, facts or information, including in the form of sound, visual or audiovisual recording’.20,21 There is no question that following the digital and information technology revolutions, the concept of data has undergone a dramatic broadening to include audio, visual and text information 22 and that the bulk of data being generated today are digital. Nevertheless, not all data are digital and analog data remain hugely important, especially in many low- and middle-income countries. 23 The World Bank in their World Development Report 2021 also made this point, noting ‘some data are still collected on paper in many countries. Processing these data—digitizing them and entering them in a spreadsheet or database—allows them to be more easily analyzed, but a digital format is not necessarily an attribute of data’ 16 p. 24.
In the conceptual framing of the CEB paper, all data were considered in scope, not just digital data. Thus, the UNECE definition 24 that ‘data is the physical representation of information in a manner suitable for communication, interpretation, or processing by human beings or by automatic means’ is more in line with the CEB conceptualization of data. A modified version of the EU definition could be proposed ‘data are basic, often unprocessed analog or digital elements, characteristics or representations of facts or information, including any compilation or aggregation of such acts, facts or information, numeric or otherwise, including any form of text, sound, visual or audiovisual recording’.
One final postscript on this topic, regarding the distinction between data and statistics. In common parlance, data and statistics are used as synonyms. While the terms are frequently used inter-changeably, they are in fact two very different things. Data can be thought of as the basic elements or single pieces of information whereas statistics are numerical data that have been organized through mathematical operations in line with conceptual frameworks. 25 Thus, statistics are a subset of the data universe.
What is data governance?
In their book ‘Why Nations Fail’, Acemoglu and Robinson 26 identify lack of institutions, property rights and rule of law as being key factors contributing to State failure. They further argue that inclusive governance bring prosperity, whereas extractive models, that serve an elite, bring only poverty. Similar arguments apply to the creation and use of data. Data, the fuel for our modern economies and societies, must be put to productive use to yield value, to stimulate innovation, but in an inclusive way, where there is equity of access and where everyone has the opportunity to benefit. A governance framework should safeguard data as a shared or common resource, ensure equity of access, and protect data for the public good (and some data as public goods) so that not all data are not trapped as private property, as proprietary goods in the concentrated hands of a few.
An immediate difficulty in explaining the meaning of data governance arises from the lack of a universally agreed or unique definition. In broad terms however, data governance refers to the exercise of authority and control over data management. 27 It embraces a wide range of concepts and elements, ranging from data privacy issues to data quality concerns. Davis 28 p. 12, using a data lifecycle lens, defines data governance as ‘the rules, processes and behaviors related to the collection, management, analysis, use, sharing and disposal of data - personal and/or non-personal. Good data governance should promote benefits and minimize harms at each stage of relevant data cycle’. Increasingly scholars are adapting Weill and Ross's definition of IT governance 29 to describe data governance as a framework that assigns decision-making authority and accountability. The World Bank, 16 emphasizing the link between data governance and the social contract around data, describes a well-designed data governance framework as a mechanism that allows the full economic and social value of both public intent and private intent data to be leveraged as well as the synergies between them. Coyle notes too, given our conventional approach to property rights, the growing interest in forms of data governance that can deliver trustworthy access to data. 30 The UN Secretary General's Data Strategy defines data governance and strategy oversight to ‘mean orchestrating people, processes & technology to ensure we use and manage data based on our principles – at global, regional or country level’ 31 p. 32. The report also notes that staff must ‘discard notions of individual “data ownership” and embrace a “data stewardship” culture’ i.e., where data are recognized as an institutional rather than divisional, departmental, unit or personal assets.
Thus, in broad strokes, data governance is a framework or mechanism that builds and maintains trust in data (and the institution producing and holding the data) by managing transparently the access, use and re-use (including matching and linking), quality and security of those data to maximise the net benefits i.e., sets out the policies, procedures and standards for managing data across all levels of a system in a consistent, transparent and secure manner. One might define data governance framework as setting out the mandate, principles, rules, processes, ethical and quality standards for collecting, accessing, using and re-using, processing, storing, sharing and disseminating data and statistics. However, it must again be emphasized, the CEB paper did not propose a particular model of data governance but set out the arguments why data governance are important and some of the options available. From an international perspective; where some international agreement is required (i.e., where national data governance is insufficient) is regarding cross-border data flows and the subsequent use or re-use of data in jurisdictions other than their origin. Obviously, the more aligned national data governance, the easier properly managed data flows will be.
Why do we need a global approach?
The ease with which digital data can be stored, shared, exchanged, and copied challenges the logic of national and regional solutions only. Digital data are a global, sharable resource; one that requires a global governance framework.
Today, there are a variety of data governance models adopted around the world. To safeguard privacy, to protect basic human rights, norms and standards, laws and incentives, some sort of shared approach – an international governance framework(s) will be required. National data governance alone is insufficient as many of these data are being exchanged internationally. The case for greater digital cooperation and for a Global Digital Compact has been articulated by the UN. 32 The importance of data protection and privacy has been acknowledged in this work, as has the need to empower citizens to access and use their own data. There is also recognition that data may require a distinct governance mechanism (not just a chapter in a digital framework) – specifically, a Global Data Compact; data too may require one or several specialized institutions to set out explicitly what data flows are permitted, under what circumstances, and what behaviours are encouraged or discouraged.
Fragmented and differing regional approaches pose significant challenges. Consequently, many key players, who understand the globalized nature of data, recognise the need for a globally coordinated approach. In recent years, there have been several calls from across the private-public spectrum for both global digital and data governance frameworks. To avoid a ‘tragedy of the data commons’, where every player uses data for their own self-interest irrespective of the harm it causes to other, a global approach to data governance is urgently required.
Barriers to international data governance
The CEB report identified a number of roadblocks to achieving international data governance. First and foremost, already fragmented regulatory environments (For example, privacy, data protection, localization, trade, digital policy and intellectual property) pose a significant hurdle. 33 Data governance, such as it exists, has evolved along quite different paths in different parts of the world. In some regions the focus centres on the protection of individual data, in others on the monetization of data and in others using data to control societies in the name of state interests and national security.17,34 Gao 35 calls this the ‘three digital kingdoms’ of individual sovereignty, firm sovereignty and state sovereignty. He argues that these ideologies reflect differing regional interests. The US promotes firm sovereignty (or self-regulation) and the free flow of data as US firms trade heavily in digital products. China, where firms still largely deal in physical goods, on the other hand promotes state sovereignty, no free flow of data and heavy government intervention. Europe, with no major digital firms, has developed a regulatory framework with strong human rights at its core (individual sovereignty). In Africa, the recent African Union Data Policy Framework 36 appears to have adopted a European type model, with strong controls proposed for consent, limitations of use and accountability.
Not unrelated to the fragmentation noted above, asymmetric concentrations of data 37 combined with uneven access, expertise and data protection, pose risks of abuse, manipulation and inequalities.38–40 For example the report ‘A World that Counts’ has highlighted the importance of access to data, arguing that uneven access to data might be considered as a new frontier of inequality. 41 These risks are being amplified by AI; models consume massive volumes of data, both to train and run. The outcomes of this may inadvertently hardwire errors, biases or inequalities into model results and subsequent outcomes. The growing proportion of private data, a significant portion of which are personally identifiable and sensitive, present some challenges for providing data for the public good. Unregulated access to such data poses risks of breaching individuals’ right to privacy. The counter argument of course is that they can be of great value to the public. The fragmented situation outlined above means that varying, and sometimes countervailing, incentives exist in different jurisdictions and regions, all of which mitigates against reaching a consensus on how to manage data internationally.
Another possible barrier is that the private sector, the largest data generators and holders may not see any benefit to any data governance framework, national or international, other than their own. It is not clear that this is the case however, as some tech CEOs at least have been vocal in the need for some sort of governance mechanism, be it Brad Smith calling for a Digital Geneva Convention 42 or Tim Cook warning of the dangers of weaponizing data and the ‘Data-Industrial Complex’. 43 Perhaps counter-intuitively, a principles based international data governance framework may offer very important incentives for the private sector, who must navigate their way through multiple regulatory and legal systems.
What is the cost of not having an international data governance framework?
For modern economies, the opportunity cost of ungoverned data and data flows is a loss of trade, a loss of innovation, and a loss of economic and human potential. For societies, arguably the opportunity costs will be greater, as an absence of governance will/may facilitate greater inequalities, poverty, and the continued undermining of longstanding social contracts, and human rights, leaving peoples and communities misinformed, divided, destabilized and vulnerable. For governments and international organizations, unable to access data, the costs of uninformed or poorly informed decisions will impact on everything from the provision of social services, environmental protection, humanitarian action and disaster management. For global development, an absence of data governance may cement or exacerbate existing North-South fault lines, undermining decades of effort.
Of particular concern is the asymmetric concentration of data. Many datasets are locked behind proprietary systems, limiting access for researchers, policymakers, and organizations that could leverage this data for social, economic, and environmental progress. There are vast disparities in data generation, availability, and quality across regions. Developed countries often have better data infrastructure, while developing nations often lack data collection and analysis capabilities, which leads to data asymmetries that hinder global progress.45,46 Paradoxically, ubiquity of data does not mean data are available or easy to access. In his farewell address, in 1961, US President Eisenhower prophetically warned of the dangers of being captive to a ‘scientific-technological elite’. 44 Today, despite these warnings the bulk of the world's data are controlled by a few. 40 This concentration of data holdings introduces obvious risks of abuse and manipulation. Estimates of data volumes, much speculated on, are a distraction. Definitional differences make quantifying the data deluge difficult. Consequently, there are a wide variety of estimates. Market intelligence company IDC, seemingly the most cited, estimate that by 2025 there will be 175 zettabytes (i.e. 10 21 or 1,000,000,000,000,000,000,000 bytes) of data globally. 47 Djuraskovic 48 forecasts 180 ZB. There are many more estimates, the veracity of which is anyone’s guess. Irrespective of which definition one choses, the underlying message is clear, massive volumes of digital data now exist. 22 More informative metrics might focus on the velocity of data – how much data are being moved, shared, transported and by how many? And who controls and has access to those data. Many of the data that exist today are proprietary and inaccessible to all but a few.
The future of privacy itself, as a concept, as a reality, is also at stake. Without data governance, without a new social contract for the digital era, data can be used to track, target and harm anyone.16,17 No one's past can be deleted or digitally forgotten. Everyone's data can be stored, matched and linked. Used selectively, unrepresentative AI, unsupported by ethical guidelines, may hardcode and amplify biases, imposing unjust decisions on an unsuspecting and defenseless public. 49 In an era of governance by numbers, of quantification, it is important that peoples and communities retain control of their data, benefit from their data, and are not dictated to by a small, data elite.
United Nations architecture
The CEB report also highlights a knotty challenge, within the context of the United Nations architecture, for the achievement of global data governance. This challenge stems from two issues. The first arises from an already polarized data world, noted above, where different approaches to data governance have emerged in different regions of the world17,34 which will make it difficult for a global consensus to emerge, particularly in an era where multilateralism appears to be faltering, and where Member States do not seem to have an appetite for ambitious consensus. The second challenge arises from the traditional Member States-centric approach to defining global agreements and commitments at the United Nations. This poses a challenge for a globalized product like digital data, where states are not the dominant players in the Dataverse but where non-government agents are the ones pushing the frontiers of data creation and use.
Today the private sector arguably holds the keys to the data kingdom and consequently has, in reality, more decision-making leverage over how data are collected, processed and used than most Governments. Citizens and civil society actors, who in some schools of thought own much of these data (or at least generate much of it), are expressing concerns over the volume of data held by the private sector 22 and have been promoting a data agenda that embraces responsibility, accountability, equity and transparency. How do these two critically important stakeholder groups get a voice at the table?
This challenge is not unique to data – progress towards a digital cooperation faces similar challenges. The UN Road map for Digital Cooperation 50 para 69 and 70 notes ‘…This is not something that any country, company or institution can achieve alone. Digital cooperation is a multi-stakeholder effort and, while Governments remain at the centre, the involvement of the private sector, technology companies, civil society and other stakeholders is essential. It is vital to engage with the private sector, the technical community and civil society from the beginning if realistic and effective decisions and policies are to be made.’
The role of the private sector is critical, not only because they possess large amounts of data but because many of these data are of global public interest, and thus they hold a very special responsibility. Engaging the private sector in global data governance is important not only because of the benefits it might unleash but also to avoid the potential negative impacts of not sharing important data or allowing harmful data concentrations owing to the absence of regulatory frameworks. The private sector has pioneered many data innovations, and there is much to be learned regarding good data governance models and practices. Civil society and data other communities have also an important crucial role to play. Governments and civil society organizations can work together to agree responsible data accountability frameworks, helping to improve transparency, data localization and inclusive participation in data governance processes.
There are some examples of global instruments that could serve as inspiration for multi-stakeholder mechanisms for data governance e.g., the International Union for Conservation of Nature (https://www.iucn.org/about-iucn), the World Summit on the Information Society Forum (https://www.itu.int/net4/wsis/forum/2023/en) or the Intergovernmental Panel on Climate Change (https://www.ipcc.ch/)). Perhaps too, some existing global fora, such as the World Economic Forum (https://www.weforum.org/), the World Government Summit (https://www.worldgovernmentsummit.org/) or the Internet Governance Forum (https://www.intgovforum.org/en), which already convene large and important segments of the private sector, could also serve as effective multi-stakeholder networks to discuss and promulgate global data governance. Even within the UN system, there are some models that may show the way, not least the UN Committee of Experts on Global Geospatial Information Management (https://ggim.un.org/) where member states and private sector already meet together, although there is still a clear distinction between participants and observers. The CEB report highlights this issue, further outlining some model options, such as (1) a global Member States-led process; (2) civil society initiatives that promote a responsible approach to data; or (3) a group of like-minded countries where other Member States can join.
Attempting to forge an international agreement without including the private sector, the tech sector and civil society will in all probability not achieve an optimal or lasting solution. The UN has several stakeholder consultation and decision making models to take inspiration from.
An opportunity
Scientists assessing existential threats to humanity every year update the ‘Domesday clock’. Since 2020, those scientists, have added to the traditional threats of nuclear war, pandemics and climate change, two new critical threats – cyber enabled information warfare and the erosion of international political infrastructure. Data are at the centre of the former, being weaponized in this information war51–54 (Although as DJ Patil, quoted in Lewis, 55 remarks ‘Everyone is focused on how data is a weapon. Actually, if we don't have data we're screwed.’) and opportunities to reach a consensus on international data governance will be affected by the latter. The World Economic Forum's 2024 Global Risks Report 56 has also identified information warfare as a key risk. In fact, for 2024, this global super year of elections, they have identified ‘misinformation and disinformation’ as their number one risk.[1] It is also noteworthy that AXA, in their 2023 Future Risks Report, for the first time, report that experts have placed ‘risks related to AI and Big Data’ in their top 5 global risks – ranked 4th after climate change, cyber security and geopolitical instability. 57
Challenging as this situation is, it provides the United Nations with an opportunity to show leadership, by decommissioning data as a weapon, and reinvigorating the international political infrastructure by proposing and promoting a global data governance architecture. History provides some guidance on how this might be done. In the late 1940's and subsequent decade the world had to learn how to manage and govern a new power – atomic energy. The challenges posed by digital data have some parallels. Like atomic energy, digital data are a double-edged sword, offering enormous benefits if managed wisely but if left unchecked and ungoverned, enormous danger. Niels Bohr, discussing atomic power, noted that unless ‘some agreement about the control of the use of the new active materials can be obtained in due time, any temporary advantage, however great, may be outweighed by a perpetual menace to human security’ 58 p. 273. If he were alive today, he might well say the same about data. Part of the solution proposed and adopted by the atomic community was what Oppenheimer described as the ‘partial renunciation of sovereignty’. 58 Perhaps this is something that data communities will also need to consider. Of course, the opportunity being presented to the UN is contingent on it being able to embrace and include a wide set of stakeholders, not just member states.
The CEB paper answers that opportunity by setting out a number of incremental steps towards achieving improved international data governance. The first is to articulate a set of universal data principles – these principles would outline the aspirations for any subsequent compact. The UN High Level Committee on Programmes (HLCP) has already developed a proposed set of principles. Specifically the HLCP Working Group on International Data Governance published their ‘Draft Normative Foundations for an International Data Governance Framework: Goals and Principles CEB/2023/HLCP46/CRP.3. It should be noted that these data principles provide the normative basis for international data governance and are distinct from the general data principles articulated in the UN Secretary Generals Data Strategy noted in Section 2.). Following consultations on these principles and data governance more broadly in 2024 at the 55th session of the UN Statistical Commission (https://unstats.un.org/UNSDWebsite/events-details/un55sc-23022024-SM-data-governance/) and at the 27th Commission on Science and Technology for Development, an updated proposal is currently being considered by the HLCP. In summary, this proposal is comprised of three goals: value; trust; and equity. Three principles are proposed to maximise the value of data: Enabling Environment for Data Use and Reuse; Interoperability; and Mutuality and Solidarity. Four principles are proposed to enable trust: a human rights-based approach to data; enhance accountability; ensure data quality; and safeguarding data security and infrastructure protection. A further four principles are proposed to promote data equity: recognize digital self-determination; promote fairness and non-discrimination; ensure governance is people centred; and encourage data stewardship.
Following an adoption of a set of data principles by the HLCP, preparation for the development of a Global Data Compact could be envisaged. Here the term compact is used loosely to describe a global agreement that is yet to be considered, negotiated or agreed. Generally, within the UN context, a compact is a call to align and take actions around a particular issue. Typically, it is non-binding and is less onerous than a convention. Such an agreement or compact would be non-binding but would articulate the elements of an international data governance framework that actors could adopt voluntarily. A compact could also be a standalone agreement or a chapter within another compact, such as the Global Digital Compact that is currently being negotiated. With time, as cooperation with the data compact builds and matures, a more robust, binding system or convention could be put in place. Critically, parties to such a convention would include not only member states but also private sector entities and communities. It should be stressed, the arguments for a global data governance framework, are positive. In the same way that basic rules of the road, seat belts and brakes allow us to drive faster and safer, some basic data governance will facilitate greater exchange of data, not less.
The bureau of the Statistical Commission is considering how to take these issues forward. The CSTD has already agreed 59 para xix ‘To consider establishing a dedicated working group within the CSTD that would engage in a comprehensive and inclusive multi stakeholder dialogue on the fundamental principles of data governance at all levels, as relevant for development under the auspices of the United Nations taking into account the conclusion of the negotiations on the outcomes of the Summit of the Future including the Global Digital Compact.’ The working group of the UNESCO Broadband Commission for Sustainable Development on ‘Data Governance in the Digital Age: Policies for a sustainable, equitable and inclusive future’ began work in June 2024, examining ‘how can governments encourage data-driven sustainable development while ensuring the protection and privacy of individual data, trustworthy data flows and exchanges in a fragmented regulatory environment? Furthermore, how can policies be designed to harmonize global data governance frameworks, promoting inclusion and ensuring that the benefits of data governance are equitably distributed across all sectors of society, regardless of a country's stage of development? 60 They intend to develop a Data Governance Toolkit to help policymakers and regulators to navigate today's complex digital data environment. Their contribution will be critical as their membership includes representatives from the private sector. The challenge going forward will be bringing all of these different work streams, with different mandates and perspectives, together into a coherent plan of action.
This paper has presented an overview of the many activities underway across the UN system with regard to data governance. As yet, much of this work can be described as scoping or preparatory. These are the essential first steps in what will be a long and complex journey. As much of this work is preparatory, or in some cases, speculative, definitive definitions and boundaries cannot as yet be described with any certainty. The complexity of data (definitions, scope, regulatory boundaries) will present challenges. Reaching consensus will require a broader set of constituents than the UN has been traditionally comprised. Despite the current architectural limitations, the UN remains arguably the best organization to progress this issue. One way that might achieve this is to support the High-Level Advisory Board on Effective Multilateralism 61 recommendation for a UN political declaration calling for International Decade for Data. The UN has used international decades to promote coordination between States, the private sector, technical and scientific communities, academia, and civil society organizations on specific issues of global concern. As of 2023, the UN has implemented 52 international decades on a variety of issues, ranging from road safety to disaster risk reduction. 62 A high degree of multi-stakeholder cooperation has been a hallmark of previous international decades. This call has been supported by a T20 Policy Brief which advocates for an international decade of data under G20 sponsorship. 62 This would create space for convergence on difficult data governance issues 63 by incentivizing partnerships and networks, and efficiently directing resources toward a common goal. 46 In this unprecedented moment, the power, promise and peril of data cannot be underestimated. It is time to be creative, time to act.
Supplemental Material
sj-pdf-1-sji-10.1177_18747655251325830 - Supplemental material for ATowards an international framework for data governance
Supplemental material, sj-pdf-1-sji-10.1177_18747655251325830 for ATowards an international framework for data governance by Steve MacFeely, Angela Me, Rachael Beaven, Joseph M Costanzo, Conor Flavin, David Passarelli, Friederike Schuur, Malarvizhi Veerappan and Stefaan Verhulst in Statistical Journal of the IAOS
Footnotes
The authors received no financial support for the research, authorship, and/or publication of this article.
Conflicting interests
The authors declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Supplemental material
Supplemental material for this article is available online.
References
Supplementary Material
Please find the following supplemental material available below.
For Open Access articles published under a Creative Commons License, all supplemental material carries the same license as the article it is associated with.
For non-Open Access articles published, all supplemental material carries a non-exclusive license, and permission requests for re-use of supplemental material or any part of supplemental material shall be sent directly to the copyright owner as specified in the copyright notice associated with the article.
