OpenEuroLLM / OpenEuroLLM/Taskboard
Define Data Compliance Governance Strategy
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 3
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
Summary
This task is primarily about establishing governance rather than implementing technical changes. The objective is to define what compliance means for our data pipeline, make our decisions explicit, and document the rationale behind them. Any resulting technical work should be driven by these governance decisions.
Goal
- Define what compliance means for our project and agree on its scope.
- Establish realistic compliance objectives for data at our scale, recognising that "ensuring compliance" is not a practical goal. Instead, define:
- The boundaries we set for ourselves.
- What we consider acceptable risk.
- How we demonstrate that we have taken reasonable and proportionate measures.
- Document the governance decisions so they can be consistently applied and justified.
Areas to Define
- Data collection requirements
Document the policies governing data collection, including topics such as:
- Accepted licence types.
- Dataset inclusion/exclusion criteria.
- Provenance requirements.
- Any other collection constraints.
- Data processing requirements
Document how we handle sensitive data and the reasoning behind our approach. For example:
- Our current PII strategy (e.g. not masking names).
- Whether this is an intentional policy decision.
- The rationale behind the decision, such as balancing privacy considerations against data quality.
- Any accepted limitations or trade-offs.
As part of this work, we may also assess our current PII strategy against the latest EDPB anonymisation guidelines to understand where our approach aligns or diverges, and document the reasoning.
Dependencies
Safeguards
Identify and document any organisational or technical safeguards that support the overall governance strategy.
Expected Outcomes
- A documented compliance governance strategy.
- Clear documentation of current policies, assumptions, and justifications.
- Identified gaps between the current implementation and the agreed governance.
- A prioritised list of technical changes required to align the data pipeline with the agreed policies.
Notes
Governance comes first, but it will naturally result in technical work. For example, decisions to revise licence policies, strengthen provenance requirements, or update the PII strategy will likely require changes to the data pipeline.
The priority for this task is not to redesign the pipeline immediately, but to clearly document our current approach and ensure we can consistently explain and justify our decisions if they are challenged.
Once the governance framework is established, future data iterations should largely consist of verifying that the pipeline continues to adhere to the agreed policies, with only incremental updates as needed.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No repository files, tests, or entry points are identified. Start by organizing the stated areas—data collection, data processing, safeguards, and the PII strategy—then document the agreed scope, risks, assumptions, rationale, gaps, and prioritized follow-up changes as the governance strategy.
Written by the indexing model from the issue text.
Assessment
- Domain
- data, documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100