OpenEuroLLM / OpenEuroLLM/Taskboard

Define Data Compliance Governance Strategy

Open
#360 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

WP3
Dominant language
No language data
Stars
3
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Summary
This task is primarily about establishing governance rather than implementing technical changes. The objective is to define what compliance means for our data pipeline, make our decisions explicit, and document the rationale behind them. Any resulting technical work should be driven by these governance decisions.

Goal

  1. Define what compliance means for our project and agree on its scope.
  2. Establish realistic compliance objectives for data at our scale, recognising that "ensuring compliance" is not a practical goal. Instead, define:
  • The boundaries we set for ourselves.
  • What we consider acceptable risk.
  • How we demonstrate that we have taken reasonable and proportionate measures.
  1. Document the governance decisions so they can be consistently applied and justified.

Areas to Define

  1. Data collection requirements
    Document the policies governing data collection, including topics such as:
  • Accepted licence types.
  • Dataset inclusion/exclusion criteria.
  • Provenance requirements.
  • Any other collection constraints.
  1. Data processing requirements
    Document how we handle sensitive data and the reasoning behind our approach. For example:
  • Our current PII strategy (e.g. not masking names).
  • Whether this is an intentional policy decision.
  • The rationale behind the decision, such as balancing privacy considerations against data quality.
  • Any accepted limitations or trade-offs.

As part of this work, we may also assess our current PII strategy against the latest EDPB anonymisation guidelines to understand where our approach aligns or diverges, and document the reasoning.

Dependencies

Safeguards
Identify and document any organisational or technical safeguards that support the overall governance strategy.

Expected Outcomes

  • A documented compliance governance strategy.
  • Clear documentation of current policies, assumptions, and justifications.
  • Identified gaps between the current implementation and the agreed governance.
  • A prioritised list of technical changes required to align the data pipeline with the agreed policies.

Notes
Governance comes first, but it will naturally result in technical work. For example, decisions to revise licence policies, strengthen provenance requirements, or update the PII strategy will likely require changes to the data pipeline.

The priority for this task is not to redesign the pipeline immediately, but to clearly document our current approach and ensure we can consistently explain and justify our decisions if they are challenged.

Once the governance framework is established, future data iterations should largely consist of verifying that the pipeline continues to adhere to the agreed policies, with only incremental updates as needed.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No repository files, tests, or entry points are identified. Start by organizing the stated areas—data collection, data processing, safeguards, and the PII strategy—then document the agreed scope, risks, assumptions, rationale, gaps, and prioritized follow-up changes as the governance strategy.

Written by the indexing model from the issue text.

Assessment

Domain
data, documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.