· Marcel Hahn · Security & Sovereignty

Sovereign Data Spaces in Industry

How federated data spaces enable industrial data exchange without giving up data sovereignty and authorship. Insights from GRIPSS-X and Wind-X.

Sovereign Data Spaces in Industry

How Companies Share Data Without Losing Control

Industrial value creation rarely occurs within a single company. Manufacturers, operators, service partners, suppliers, and software providers need data to operate facilities, analyze errors, and develop new services.

At the same time, these data are strategically sensitive.

Machine data can provide insights into utilization, production volume, or technical weaknesses. Maintenance reports contain experiential knowledge. Operational data can form the basis of new business models.

Companies therefore face a conflict of objectives:

They must share data to create value together. However, they must not lose control over usage, context, and authorship.

Sovereign data spaces are intended to resolve this conflict.

Why Traditional Data Exchange Models Reach Their Limits

Traditionally, data exchange occurs via individual interfaces, file transfers, or central platforms.

These models work technically but often create new problems:

  • Each bilateral interface must be developed and maintained separately.
  • Data models differ between companies.
  • Usage rights remain unclear.
  • A central platform operator gains a strong position of control.
  • Data are copied without their later use being traceable.
  • Context and origin are lost during exports.

The more partners involved, the greater the complexity becomes.

A sovereign data space therefore aims not only to transfer data technically. It should include rules, identities, usage conditions, and professional contexts in the exchange.

What a Sovereign Data Space Is

A data space is not a single central database.

It is a shared infrastructure and a set of rules through which multiple participants can control and use data.

Typical components are:

  • unique identities,
  • defined data models,
  • standardized interfaces,
  • rules for data usage,
  • traceability of accesses,
  • technical connectors,
  • and agreements on governance and responsibility.

In a federated or decentralized model, data remain as much as possible at their respective source. They are not necessarily permanently copied to a central platform.

The data provider can determine who may use which data for what purpose.

Data Sovereignty Instead of Data Isolation

Data sovereignty does not mean withholding data in principle.

It means being able to consciously control their use.

A company should be able to answer:

  • What data do we provide?
  • Who is allowed to access it?
  • For what purpose is the use permitted?
  • How long is the release valid?
  • May the data be passed on?
  • How is the origin documented?
  • Can usage rights be changed later?

Only when these questions are technically and organizationally clarified does reliable collaboration arise.

Without sovereignty, data exchange either leads to loss of control or does not occur at all.

The Role of Federated Architectures

Federated architectures connect multiple independent systems without fully centralizing them.

Participants retain their own data sources and systems. Common standards ensure that information becomes findable, understandable, and usable.

Advantages are:

  • less dependency on a central platform,
  • better control over sensitive data,
  • gradual integration of existing systems,
  • and the ability to connect different operating models.

The challenge lies in coordination. A federated data space requires clear standards, reliable identities, and shared governance.

Decentralized does not mean without rules.

What GRIPSS-X Has Shown

The GRIPSS-X research project focused on infrastructures for secure and sovereign data exchange in industrial value networks.

A key goal was to reduce barriers to cross-company co-creation. Companies should be able to use data and digital services together without completely relinquishing their ability to act to a central authority.

The central insight is:

Collaboration and control are not opposites when technical architecture, usage rights, and governance are considered together.

This is particularly relevant for industrial applications. A machine manufacturer, operator, and service partner can jointly benefit from technical data. However, data sovereignty, access, and responsibility must be traceably regulated.

Wind-X as an Application in the Wind Industry

Wind-X applies this logic to the wind industry.

The goal is a federated, decentralized data space based on a cloud-edge infrastructure. Companies should be able to exchange data and develop new business models without giving up control and authorship.

The wind industry particularly highlights the problem:

  • Operators need reliable operational data.
  • Manufacturers have technical models and service knowledge.
  • Independent service companies need access for maintenance and error analysis.
  • Marketing and energy systems need current status and production data.

If data remain locked in proprietary systems, dependencies and inefficient handovers arise.

A sovereign data space cannot automatically dissolve these silos. However, it creates a common basis for controlled exchange.

From SCADA Data to Usable Asset History

In many industrial and energy companies, relevant data are located at multiple levels:

  • SCADA and sensor data,
  • ERP and maintenance data,
  • technical documents,
  • maintenance reports,
  • condition assessments,
  • and technicians’ experiential knowledge.

Simply connecting these sources is not enough. Data must be professionally assigned and brought into a traceable context.

A digital lifecycle file can, for example, assign events, documents, sensor values, and measures to an asset. This creates a common view without having to replace every source system.

The data space regulates the sovereign exchange between participants. The professional platform makes the information usable in the specific process.

Both levels complement each other.

What Conditions Companies Must Create

Common Data Models

Data must not only be transferred but also understood equally by all participants.

Clear Usage Rights

Technical access does not replace contractual and organizational regulation.

Reliable Identities

It must be clear which company and which role accesses data or services.

Traceability

Accesses, changes, and transfers should be documented.

Integration Capability

Existing ERP, SCADA, cloud, and edge systems must be able to be connected step by step.

Economic Use Case

A data space is not an end in itself. It requires a clear benefit, such as better maintenance, automated billing, or new services.

Suitable Initial Use Cases

A sensible entry point is a clearly defined data exchange between a few participants.

Examples:

  • Transmission of selected status data to a service partner,
  • joint use of maintenance and spare part information,
  • automated provision of production data,
  • exchange of standardized asset master data,
  • or building a common error and action history.

The use case should be measurable. Only when benefits, rights, and technical processes work should the data space be expanded.

Sovereign Data Spaces and Enterprise Software

The principles of sovereign data spaces apply not only between companies.

Even within an organization, applications should be designed so that data, processes, and knowledge are not unnecessarily locked in individual systems.

Open interfaces, documented data models, and clear usage rights create the same basic capability:

  • Information can be shared,
  • systems remain interchangeable,
  • and collaboration does not automatically lead to loss of control.

Thus, the data space becomes a strategic principle for a connected industry.

Conclusion

Industrial companies must share data to work more efficiently and develop new services.

The alternative to the central platform is not isolation. It is federated structures with clear rules.

Sovereign data spaces combine collaboration and control. They create a foundation on which companies can use data without giving up their ability to act.

Data sovereignty does not arise by leaving data untouched. It arises by keeping their use controllable, traceable, and changeable.

    Share:
    Back to Blog