Questionnaire and Survey Results: Design and Technical Requirements for Data Trustees Michael Steinert Fraunhofer Institute for Software and Systems Engineering ISST, Dortmund, Germany michael.steiner[email protected]er.de Daniel Tebernum Fraunhofer Institute for Software and Systems Engineering ISST, Dortmund, Germany
[email protected] Abstract This document presents the complete questionnaire and the survey results obtained in an expert study on data trustees. The questionnaire comprises Likert-scale questions and multiple-answer questions covering themes such as trust and transparency, data protection, monetization, algorithm provision, data sharing, technical requirements, security, usage policies, and data spaces. Survey responses are visualized using bar charts to facilitate a direct comparison of agreement levels and selection frequencies. 1. Introduction Data trustees have emerged as critical intermediaries for ensuring secure and compliant data sharing in today’s data-driven environments. This document presents the complete questionnaire and the aggregated results from an expert survey focused on their design and technical requirements. The structure of our questionnaire is based on the taxonomy of data intermediation services proposed by J. Schweihoff et al., 2024. This taxonomy is an extension of the authors’ earlier work, which was based on a systematic literature review (J. C. Schweihoff et al., 2023). The updated 2024 framework is empirically grounded in an analysis of 86 companies, organizing services into three tiers of importance: mandatory (found in 100% of cases), essential (>80%), and optional (<80%). While this taxonomy provides a robust theoretical foundation, its categorization has not yet been validated from the perspective of practitioners. Our expert survey addresses this gap by empirically testing whether these predefined categories align with the practical needs and priorities of data trustee experts. Furthermore, our survey seeks to uncover emerging requirements and operational challenges not captured in the existing framework. Targeting experts with both practical and theoretical experience, the survey was disseminated to 135 data trustee experts across industry, academia, and other sectors. It was administered via the open-source LimeSurvey platform on a self-managed server, ensuring data privacy and regulatory compliance, and remained open for four weeks (November 26, 2024, to December 20, 2024). Although 62 responses were received, only 35 complete responses were considered in the analysis to prevent partial submissions from skewing the results for individual questions. Regarding respondents’ experience with the topic, most participants (21) reported having worked with data trustees for one to three years, followed by seven respondents with more than three years of involvement and seven who had been engaged for less than one year. In terms of their main professional context, the majority indicated they were active in research and development (24) or research activities (13), with a smaller number from consulting (7) and corporate data management (1). When asked about their role in implementing data trustees, many participants identified research (25) as their primary focus, followed by technical expertise (13), consulting (11), decision-making (8), and operational application (6). A few respondents (4) indicated additional roles beyond these categories. The questionnaire is presented in thematic blocks, and the corresponding survey results are visualized through bar charts, providing a clear and concise representation of the collective expert insights.
2. Questionnaire and Results Block 1 “Trust & Transparency” (G02Q04) G02Q04 (Likert): “Rate the following statements regarding data trustees.” •G02Q04-1: Data trustees create a high level of trust/transparency. •G02Q04-2: They ensure compliance with data protection standards. •G02Q04-3: They promote data exchange between stakeholders. •G02Q04-4: They improve efficiency in data management. •G02Q04-5: They are necessary in certain areas (e.g., healthcare). Block 2 “Anonymization & Data Protection” (G03Q05–G03Q08, G04Q09) G03Q05 (Likert): “Rate the following statements about data anonymization.” •G03Q05-1: Anonymization techniques are essential for data trustees to comply with data protection requirements. •G03Q05-2: Data trustees should use standardized anonymization methods. •G03Q05-3: The anonymization of data reduces its usefulness for analytical purposes. •G03Q05-4: There is a need for new technologies to effectively anonymize data. •G03Q05-5: Anonymized data should be made freely accessible. G03Q06 (Multiple Answer): “Which challenges do you see in data anonymization?” •G03Q06-a: Loss of data quality and accuracy. •G03Q06-b: Complexity in the technical implementation of anonymization techniques. •G03Q06-c: Regulatory requirements and compliance. •G03Q06-d: Lack of standardization for anonymization methods. •G03Q06-e: Risk of re-identification of anonymized data. •G03Q06-f: None. G03Q07 (Likert): “Do you agree with the following statements on data anonymization and data protection?” •G03Q07-1: The anonymization of data is sufficient to meet data protection requirements. •G03Q07-2: It is necessary to implement additional data protection measures beyond anonymization. •G03Q07-3: Anonymization techniques should be regularly reviewed for their effectiveness. •G03Q07-4: Data trustees should continuously assess re-identification risks. •G03Q07-5: Combining anonymization and encryption offers a higher level of protection for sensitive data. •G03Q07-6: Aggregating data is equivalent to anonymization. G03Q08 (Multiple Answer): “Which technologies or methods do you consider effective for data anonymization?” •G03Q08-a: k-anonymity. •G03Q08-b: Differential privacy. •G03Q08-c: Pseudonymization techniques. •G03Q08-d: Data masking. •G03Q08-e: Generative models (e.g., synthetic data). •G03Q08-f: Not familiar with all technologies. G04Q09 (Likert): “Do you agree with the following statements on the trustworthiness of data trustees?”
•G04Q09-1: Open-source software increases confidence in the security of data trustees. •G04Q09-2: A good reputation and recognition of the software development process foster trust in data trustees. •G04Q09-3: Certifications are a decisive factor in building trust. •G04Q09-4: Transparency regarding software and processes is more important than the type of software used. •G04Q09-5: Independent audits increase trust in the data trustee. •G04Q09-6: The option to submit and view reviews increases trust. Block 3 “Monetization” (G05Q10–G06Q12) G05Q10 (Likert): “Rate the following statements on the monetization of data by data trustees.” •G05Q10-1: Micropayments per transaction are an effective way to monetize data. •G05Q10-2: Data trustees should offer flexible billing models for data transactions. •G05Q10-3: Monetizing data promotes data exchange between different stakeholders. •G05Q10-4: Monetization should be integrated into the governance structure of data trustees. G05Q11 (Multiple Answer): “Which challenges do you see in implementing data monetization for data trustees?” •G05Q11-a: Technological complexity in integrating payment systems. •G05Q11-b: High transaction fees. •G05Q11-c: Regulatory uncertainties regarding financial transactions. •G05Q11-d: User acceptance. •G05Q11-e: Lack of standardized payment protocols. •G05Q11-f: None. 24 20 13 12 26 1 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G03Q06‐a G03Q06‐b G03Q06‐c G03Q06‐d G03Q06‐e G03Q06‐f (a) G03Q06 10 12 8 10 10 15 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G03Q08-a G03Q08-b G03Q08-c G03Q08-d G03Q08-e G03Q08-f (b) G03Q08 10 9 16 25 10 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G05Q11-a G05Q11-b G05Q11-c G05Q11-d G05Q11-e (c) G05Q11 Figure 1: Grouped bar charts for Blocks 2 and 3. G06Q12 (Likert): “Do you agree with the following statements on the impacts of data monetization?” •G06Q12-1: Monetization strengthens trust among data providers and users. •G06Q12-2: Financial incentives improve data quality and timeliness. •G06Q12-3: Paywalls may hinder smaller players from accessing data. •G06Q12-4: Monetization can create data protection risks. •G06Q12-5: Transparent pricing models are crucial for success. Block 4 “Provision of Algorithms” (G06Q13–G06Q15) G06Q13 (Likert): “Do you agree with the following statements on providing algorithms via data trustees?” •G06Q13-1: Data trustees should offer algorithms for data processing.
•G06Q13-2: Using one’s own algorithms increases the value of the data trustee’s services. •G06Q13-3: Security concerns create barriers to adopting algorithms offered by data trustees. •G06Q13-4: Data trustees should host a platform for third-party algorithms. •G06Q13-5: Algorithms for sensitive data must be reviewed and certified. G06Q14 (Multiple Answer): “Which types of algorithms or services should data trustees provide?” •G06Q14-a: Anonymization techniques. •G06Q14-b: Data analytics tools. •G06Q14-c: Encryption techniques. •G06Q14-d: Data quality tools. •G06Q14-e: Machine learning models. •G06Q14-f: None. G06Q15 (Multiple Answer): “Which challenges affect the provision of algorithms by data trustees?” •G06Q15-a: Security risks from unknown algorithms. •G06Q15-b: Compatibility with existing systems. •G06Q15-c: Lack of transparency regarding algorithm functionality. •G06Q15-d: Regulatory and compliance requirements. •G06Q15-e: Development and implementation costs. •G06Q15-f: None. 29 24 27 31 17 1 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G06Q14-a G06Q14-b G06Q14-c G06Q14-d G06Q14-e G06Q14-f (a) G06Q14 24 21 26 21 24 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G06Q15-a G06Q15-b G06Q15-c G06Q15-d G06Q15-e (b) G06Q15 Figure 2: Grouped bar charts for Block 4. Block 5 “Data Sharing between Data Trustees” (G07Q16–G07Q18) G07Q16 (Multiple Answer): “What are the advantages of data sharing between data trustees?” •G07Q16-a: Improved data quality and consistency. •G07Q16-b: Increased data availability. •G07Q16-c: More efficient data management. •G07Q16-d: Strengthening trust in data trustees. •G07Q16-e: Better regulatory compliance. •G07Q16-f: None. G07Q17 (Multiple Answer): “Which challenges exist in data sharing between data trustees?” •G07Q17-a: Data protection concerns. •G07Q17-b: Complex governance structures. •G07Q17-c: Security risks from additional systems.
•G07Q17-d: Lack of trust among different data trustees. •G07Q17-e: Regulatory uncertainties. •G07Q17-f: None. G07Q18 (Multiple Answer): “Which data trustee hierarchy architectures are appropriate?” •G07Q18-a: Centralized architecture (one data trustee manages others). •G07Q18-b: Federated architecture (autonomous data trustees collaborate). •G07Q18-c: Decentralized architecture (equal data trustee status). •G07Q18-d: Hybrid architecture (mix of centralized and decentralized). •G07Q18-e: None. 21 24 17 14 12 4 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G07Q16-a G07Q16-b G07Q16-c G07Q16-d G07Q16-e G07Q16-f (a) G07Q16 19 22 21 17 26 2 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G07Q17-a G07Q17-b G07Q17-c G07Q17-d G07Q17-e G07Q17-f (b) G07Q17 7 20 20 16 2 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G07Q18-a G07Q18-b G07Q18-c G07Q18-d G07Q18-e (c) G07Q18 Figure 3: Grouped bar charts for Block 5. Block 6 “Technical Requirements & Data Management” (G08Q19–G08Q21) G08Q19 (Likert): “How do you assess the relevance of the following technical measures in the data management of data trustees?” •G08Q19-1: Encryption and access controls. •G08Q19-2: Authentication and identity management. •G08Q19-3: Data backups and redundancy. •G08Q19-4: Monitoring and logging. •G08Q19-5: Anonymization and pseudonymization. •G08Q19-6: Data erasure (e.g., user deletion requests). G08Q20 (Likert): “Do you agree with the following statements on technical aspects?” •G08Q20-1: Transparency in the data deletion process is important. •G08Q20-2: Traceability of data anonymization must be ensured. •G08Q20-3: Anonymized data should be treated as deleted data. •G08Q20-4: Data trustees should support Green IT. •G08Q20-5: Unified EU standards are needed in data management. •G08Q20-6: Decentralized data management is essential. G08Q21 (Multiple Answer): “Which methods are effective in data management?” •G08Q21-a: Encryption for archiving. •G08Q21-b: Anonymization techniques. •G08Q21-c: Automated data classification. •G08Q21-d: Traceability technologies. •G08Q21-e: Software for data erasure.
•G08Q21-f: None. Block 7 “Security, Trust & Compliance” (G09Q22–G09Q23) G09Q22 (Likert): “How do you assess the relevance of the following measures to ensure data protection and security?” •G09Q22-1: Use of encryption technologies. •G09Q22-2: Regular audits and controls. •G09Q22-3: Implementation of access controls. •G09Q22-4: Automated logging. •G09Q22-5: Use of data deletion procedures. •G09Q22-6: Training of employees. G09Q23 (Likert): “Do you agree with the following statements on security measures?” •G09Q23-1: Encrypting data is essential for data protection. •G09Q23-2: Vulnerability scans and updates should be carried out regularly. •G09Q23-3: Access controls and authentication are crucial for data protection. •G09Q23-4: Secure data erasure is vital for confidential data. •G09Q23-5: Monitoring and incident response are necessary in data management. Block 8 “Data Usage Policies & Consent” (G10Q24–G10Q26) G10Q24 (Multiple Answer): “Which method do you prefer for communicating your needs and requirements as data providers?” •G10Q24-a: Free text (natural language). •G10Q24-b: Structured form or questionnaire. •G10Q24-c: Advisory meetings. •G10Q24-d: Predefined templates or standard models. •G10Q24-e: None. G10Q25 (Likert): “Do you agree with the following statements on the creation of data usage policies?” •G10Q25-1: A structured form makes requirement communication easier. •G10Q25-2: Natural language communication helps detail specific needs. •G10Q25-3: Predefined usage policies are sufficient. •G10Q25-4: Flexibility is more important than standardization. •G10Q25-5: Data trustee support is important. G10Q26 (Multiple Answer): “Which information belongs in data usage policies?” •G10Q26-a: Purpose of data usage. •G10Q26-b: Duration of data storage. •G10Q26-c: Access rights (specific users or groups). •G10Q26-d: Security measures and safeguards. •G10Q26-e: Conditions for onward sharing (third parties). •G10Q26-f: Data deletion and anonymization options. •G10Q26-g: None.
20 28 21 24 19 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G08Q21-a G08Q21-b G08Q21-c G08Q21-d G08Q21-e (a) G08Q21 13 17 17 19 1 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G10Q24-a G10Q24-b G10Q24-c G10Q24-d G10Q24-e (b) G10Q24 34 34 32 28 33 32 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G10Q26-a G10Q26-b G10Q26-c G10Q26-d G10Q26-e G10Q26-f (c) G10Q26 Figure 4: Grouped bar charts for Block 6 and 8. Block 9 “Tools, Models & Methods” (G11Q27–G11Q29) G11Q27 (Multiple Answer): “Which specific tools do you feel are missing in the data management of data trustees?” •G11Q27-a: Data anonymization. •G11Q27-b: Long-term archiving. •G11Q27-c: Data erasure. •G11Q27-d: Uniform compliance models. •G11Q27-e: None. G11Q28 (Multiple Answer): “Do you see a need for new models, methods, or technologies for data management?” •G11Q28-a: Yes, in data anonymization. •G11Q28-b: Yes, in long-term archiving. •G11Q28-c: Yes, in secure data erasure. •G11Q28-d: No current need. G11Q29 (Multiple Answer): “Which data management processes are most complex?” •G11Q29-a: High archiving standards. •G11Q29-b: Data erasure complexity. •G11Q29-c: Traceability. •G11Q29-d: Lack of anonymization. •G11Q29-e: None. 14 6 9 13 10 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G11Q27-a G11Q27-b G11Q27-c G11Q27-d G11Q27-e (a) G11Q27 16 9 9 9 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G11Q28-a G11Q28-b G11Q28-c G11Q28-d (b) G11Q28 5 11 21 14 3 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G11Q29-a G11Q29-b G11Q29-c G11Q29-d G11Q29-e (c) G11Q29 Figure 5: Grouped bar charts for Block 9. Block 10 “Data Spaces” (G12Q30–G12Q33) G12Q30 (Likert): “How important is the role of data trustees in data spaces?” G12Q31 (Multiple Answer): “Which challenges arise in the technical implementation of data trustees within data spaces?”
•G12Q31-a: Regulatory uncertainties. •G12Q31-b: Technological complexity. •G12Q31-c: High costs. •G12Q31-d: Integration issues. •G12Q31-e: Need for interoperability. •G12Q31-f: None. G12Q32 (Multiple Answer): “Which approaches suit unified data management in data spaces?” •G12Q32-a: Centralized architecture (one central authority). •G12Q32-b: Federated architecture (autonomous collaboration). •G12Q32-c: Decentralized architecture (equal management). •G12Q32-d: Uniform EU standards (common legal and regulatory requirements). •G12Q32-e: Hybrid architecture (mix of centralized and decentralized). •G12Q32-f: None. 21 20 10 22 25 1 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G12Q31-a G12Q31-b G12Q31-c G12Q31-d G12Q31-e G12Q31-f (a) G12Q31 7 22 16 23 14 0,0% 20,0% 40,0% 60,0% 80,0% 100,0% G12Q32-a G12Q32-b G12Q32-c G12Q32-d G12Q32-e (b) G12Q32 Figure 6: Grouped bar charts for Block 10. G12Q33 (Likert): “Do you agree with the following statements on the further development of data spaces?” •G12Q33-1: Monetization increases value. •G12Q33-2: Anonymization support is crucial. •G12Q33-3: Data spaces should focus on core functions and leave specialized features to third parties. •G12Q33-4: Data protection and security are top priorities. Other Block G12Q34 (Likert): “Rate the following statements about other aspects of data management.” •G12Q34-1: Green IT is important for data trustees. •G12Q34-2: Transparency in data deletion is essential. •G12Q34-3: Traceability of data anonymization is crucial. •G12Q34-4: Cost-effectiveness in data management is important. •G12Q34-5: A hierarchy of data trustees improves data management.
3. Likert Results Visualization 1 2 1 2 1 3 3 6 5 13 16 1 10 1 1 3 2 5 6 1 11 4 7 6 2 6 3 7 3 1 1 6 6 7 1 1 1 1 1 1 2 2 1 1 1 19 16 17 9 10 15 17 12 13 6 5 22 13 14 15 8 14 22 15 14 18 15 14 20 13 17 9 15 21 11 19 14 21 14 11 16 11 9 13 8 17 14 7 7 9 1 9 20 16 10 1 8 5 8 9 11 3 2 7 3 3 2 6 5 2 11 3 6 4 5 13 -80% -60% -40% -20% 0% 20% 40% 60% 80% 100% G02Q04-1 G02Q04-2 G02Q04-3 G02Q04-4 G02Q04-5 G03Q05-1 G03Q05-2 G03Q05-3 G03Q05-4 G03Q05-5 G03Q07-1 G03Q07-2 G03Q07-3 G03Q07-4 G03Q07-5 G03Q07-6 G04Q09-1 G04Q09-2 G04Q09-3 G04Q09-4 G04Q09-5 G04Q09-6 G05Q10-1 G05Q10-2 G05Q10-3 G05Q10-4 G06Q12-1 G06Q12-2 G06Q12-3 G06Q12-4 G06Q12-5 G06Q13-1 G06Q13-2 G06Q13-3 G06Q13-4 G06Q13-5 % Responses (n=35) Strongly disagree Disagree Neutral Agree Strongly agree (a) Divergent bar chart for Blocks G02 to G06. 1 13 2 3 6 1 3 5 9 5 1 6 4 5 1 9 1 2 2 11 1 8 1 1 1 1 1 1 1 10 11 19 18 12 14 19 20 3 9 19 12 14 24 10 16 21 18 17 17 11 20 17 18 18 5 16 26 14 13 12 16 10 9 24 23 20 6 25 24 11 16 18 17 12 10 2 3 5 21 10 25 15 10 14 15 17 24 11 17 7 4 3 1 2 11 5 12 3 17 1 6 7 -80% -60% -40% -20% 0% 20% 40% 60% 80% 100% G08Q19-1 G08Q19-2 G08Q19-3 G08Q19-4 G08Q19-5 G08Q19-6 G08Q20-1 G08Q20-2 G08Q20-3 G08Q20-4 G08Q20-5 G08Q20-6 G09Q22-1 G09Q22-2 G09Q22-3 G09Q22-4 G09Q22-5 G09Q22-6 G09Q23-1 G09Q23-2 G09Q23-3 G09Q23-4 G09Q23-5 G10Q25-1 G10Q25-2 G10Q25-3 G10Q25-4 G10Q25-5 G12Q30 G12Q33-1 G12Q33-2 G12Q33-3 G12Q33-4 G12Q34-1 G12Q34-2 G12Q34-3 G12Q34-4 G12Q34-5 % Responses (n=35) Strongly disagree Disagree Neutral Agree Strongly agree (b) Divergent bar chart for Blocks G08 to G12. Figure 7: Divergent bar charts visualizing Likert-scale responses.