scieee AI-readable full text Open interactive document viewer

D1.2 COBALT Data Management Plan

Karamitsiani, Sofia

Abstract

The Data Management Plan (DMP) for the COBALT project outlines a structured methodology for managing essential data obtained and created during the project, emphasizing the improvement of data accessibility and reusability. This plan is organised according to the Horizon Europe DMP format, which is relevant for projects handling research data, and complies with the FAIR guidelines and open access mandates stipulated by Horizon Europe. The document sets the data management principles, strategies, tools, types of data, ownership, and protocols for intellectual property and access. It details the methods for the collection, storage, access, distribution, safeguarding, retention, and disposal of data, aligning with the European Union's standards as outlined in both the Grant and Consortium Agreements. This plan provides a clear perspective on how the COBALT consortium means to fulfil data management, protection, and security obligations in the present phase of the project. In adherence to the EU Open Access policies, the COBALT project commits to providing unrestricted online access to its scientific outputs, thus fostering extensive dissemination and influence of its research outcomes. The commitment to open access for publishing papers and articles is confirmed in the agreements, ensuring that these materials are available and beneficial to external entities. Operating as a guide, the DMP of the COBALT project details diverse methodologies and policies for the handling of data throughout the lifespan of the project. It is an essential element that supports the project's primary aim, showcasing the consortium's dedication to practised data management and the facilitation of data accessibility both during and beyond the duration of the project.

Full text

D 1.2 Data Management Plan Work package WP1: Project Management Task Task 1.1: Project Coordination Editor G. Xylouris (NCSRD) Authors S. Karamitsiani (NCSRD) Dissemination level PU Status Draft Due date 30/04/2024 Document date 30/04/2024 Version number 1.0 Reviewers S. Karageorgiou, T. Christofides (eBOS) Co-funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union. Neither the European Union nor the granting authority can be held responsible for them. Ref. Ares(2024)3173657 - 30/04/2024 Deliverable D1.2 – Data Management Plan © COBALT Consortium 2 REVISION AND HISTORY CHART Version Date Main author Summary of changes 0.1 21/03/2024 NCSRD First draft 0.2 00/00/2024 NCSRD Pre Final 1.0 30/04/2024 NCRD Final submitted version Deliverable D1.2 – Data Management Plan © COBALT Consortium 3 TABLE OF CONTENTS REVISION AND HISTORY CHART .................................................................................................... 2 TABLE OF CONTENTS .................................................................................................................... 3 INDEX OF FIGURES ....................................................................................................................... 4 INDEX OF TABLES ......................................................................................................................... 5 GLOSSARY OF TERMS ................................................................................................................... 6 LIST OF ABBREVIATIONS AND ACRONYMS..................................................................................... 6 EXECUTIVE SUMMARY ................................................................................................................. 7 1 INTRODUCTION .................................................................................................................... 7 1.1 PURPOSE AND SCOPE ............................................................................................................. 7 1.2 STRUCTURE OF THE DOCUMENT ................................................................................................ 8 2 BRIEF PRESENTATION OF COBALT PROJECT............................................................................. 9 3 COBALT DATA MANAGEMENT PLAN OVERVIEW ................................................................... 10 3.1 RESEARCH DATA MANAGEMENT AND MANAGEMENT OF RESEARCH OUTPUTS ................................... 10 3.2 GUIDING PRINCIPLES ............................................................................................................ 11 3.3 DATA MANAGEMENT STRATEGY AND DATA TYPES ....................................................................... 11 3.4 COBALT DATA SUMMARY..................................................................................................... 12 3.4.1 PURPOSE OF DATA COLLECTION/GENERATION AND ITS RELATION TO THE OBJECTIVES OF THE PROJECT .12 3.4.2 RE-USE OF EXISTING DATA THROUGH COBALT ...........................................................................12 3.4.3 TYPES AND FORMATS OF DATA GENERATED/COLLECTED, USE OR REUSE ..........................................13 3.4.4 PURPOSE OF DATA GENERATION, USE OR RE-USE THEIR RELATION WITH THE PROJECT .......................13 3.4.5 EXPECTED SIZE OF THE DATA .....................................................................................................14 3.4.6 ORIGIN/PROVENANCE OF THE DATA ..........................................................................................14 3.5 PARTICIPATION IN THE PILOT ON OPEN RESEARCH DATA ................................................................ 14 3.5.1 DATA AVAILABILITY .................................................................................................................14 3.5.2 OPEN ACCESS TO SCIENTIFIC PUBLICATIONS ................................................................................15 3.5.3 OPEN ACCESS TO RESEARCH DATA .............................................................................................15 3.6 EXPLOITATION, AVAILABILITY OF DATA, RE-USE AND ARCHIVE ........................................................ 15 4 COBALT DATA ...................................................................................................................... 17 4.1 DATA SET 1: COBALT ADMINISTRATIVE DATA ............................................................................ 18 4.2 DATA SET 2: COBALT PLATFORM TECHNICAL DATA ..................................................................... 18 4.3 DATA SET 3: COBALT PILOT DATA........................................................................................... 18 Deliverable D1.2 – Data Management Plan © COBALT Consortium 4 5 FAIR DATA ........................................................................................................................... 20 5.1 MAKING DATA FINDABLE, INCLUDING PROVISIONS FOR MORE DATA................................................ 21 5.1.1 ADMINISTRATIVE DATA ............................................................................................................21 5.1.2 PLATFORM TECHNICAL DATA/USE CASE DATA .............................................................................21 5.2 MAKING DATA ACCESSIBLE .................................................................................................... 21 5.2.1 ADMINISTRATIVE DATA ............................................................................................................21 5.2.2 PLATFORM TECHNICAL DATA/USE CASE DATA .............................................................................21 5.3 MAKING DATA INTEROPERABLE .............................................................................................. 21 5.3.1 ADMINISTRATIVE DATA ............................................................................................................22 5.3.2 PLATFORM TECHNICAL DATA/USE CASE DATA .............................................................................22 5.4 INCREASE DATA RE-USE ........................................................................................................ 22 5.4.1 ADMINISTRATIVE DATA ............................................................................................................22 5.4.2 PLATFORM TECHNICAL DATA/USE CASE DATA .............................................................................22 6 ALLOCATION OF RESOURCES ............................................................................................... 23 7 DATA SECURITY ................................................................................................................... 24 7.1 ADMINISTRATIVE DATA ......................................................................................................... 24 7.2 PLATFORM TECHNICAL DATA .................................................................................................. 24 8 LEGAL DATA PROTECTION AND ETHICAL ASPECTS................................................................. 25 8.1 PERSONAL DATA IN COBALT ................................................................................................. 25 8.2 PRINCIPLES OF THE PROCESSING OF PERSONAL DATA.................................................................... 25 8.2.1 LAWFULNESS AND LEGAL BASIS .................................................................................................26 8.2.2 DATA MINIMIZATION ...............................................................................................................27 8.2.3 ACCURACY.............................................................................................................................27 8.2.4 STORAGE LIMITATION ..............................................................................................................27 8.2.5 CONFIDENTIALITY, INTEGRITY, AND DATA SECURITY ......................................................................27 8.2.6 ACCOUNTABILITY ....................................................................................................................28 8.3 DATA SHARING ................................................................................................................... 28 8.3.1 RESPONSIBILITIES OF THE CONTROLLER AND PROCESSOR AND JOINT CONTROLLERS ...........................29 8.4 DATA PROTECTION IMPACT ASSESSMENT (DPIA) ........................................................................ 29 8.5 RECORDS OF DATA PROCESSING ACTIVITIES ............................................................................... 30 8.6 PRIVACY / DATA PROTECTION AND SECURITY BY DESIGN AND BY DEFAULT ......................................... 30 8.7 INFORMED CONSENT TO PARTICIPATE IN THE RESEARCH PROJECT .................................................... 31 8.8 OPEN DATA ....................................................................................................................... 31 9 CONCLUSION ...................................................................................................................... 34 INDEX OF FIGURES Figure 1: Figure caption, centred, below the figure 10 Deliverable D1.2 – Data Management Plan © COBALT Consortium 5 INDEX OF TABLES Table 1: Table caption, center justified, above the table 10 Deliverable D1.2 – Data Management Plan © COBALT Consortium 6 GLOSSARY OF TERMS LIST OF ABBREVIATIONS AND ACRONYMS Deliverable D1.2 – Data Management Plan © COBALT Consortium 7 EXECUTIVE SUMMARY The Data Management Plan (DMP) for the COBALT project outlines a structured methodology for managing essential data obtained and created during the project, emphasizing the improvement of data accessibility and reusability. This plan is organised according to the Horizon Europe DMP format, which is relevant for projects handling research data, and complies with the FAIR guidelines and open access mandates stipulated by Horizon Europe. The document sets the data management principles, strategies, tools, types of data, ownership, and protocols for intellectual property and access. It details the methods for the collection, storage, access, distribution, safeguarding, retention, and disposal of data, aligning with the European Union's standards as outlined in both the Grant and Consortium Agreements. This plan provides a clear perspective on how the COBALT consortium means to fulfil data management, protection, and security obligations in the present phase of the project. In adherence to the EU Open Access policies, the COBALT project commits to providing unrestricted online access to its scientific outputs, thus fostering extensive dissemination and influence of its research outcomes. The commitment to open access for publishing papers and articles is confirmed in the agreements, ensuring that these materials are available and beneficial to external entities. Operating as a guide, the DMP of the COBALT project details diverse methodologies and policies for the handling of data throughout the lifespan of the project. It is an essential element that supports the project's primary aim, showcasing the consortium's dedication to practised data management and the facilitation of data accessibility both during and beyond the duration of the project. 1 Introduction 1.1 Purpose and Scope The purpose of this document is to present the main Data Management Plan (DMP) for the COBALT project. This plan primarily addresses the handling of three types of data: Administrative, Technical, and Use Case. The objectives of the project are dual: a) to maximize the utility of data that is generated and collected, and b) to ensure broad dissemination of the scientific findings of COBALT. This document has been prepared in compliance with the Guidelines for Open Access 1 to Scientific Publications and Research Data under Horizon Europe, as well as the General Data Protection Regulation (GDPR), in line with the FAIR Data Management principles encouraged by Horizon Europe. This deliverable provides foundational principles and detailed insights into the use case data descriptions, setting the stage for their integration into the final DMP upon the completion of the project. It creates feedback received from all participating project partners, detailing the contributions to the dataset from each partner. Furthermore, this document elaborates on the measures for ensuring data security, adherence to FAIR principles, and addressing legal and ethical considerations in data management. 1 https://research-and-innovation.ec.europa.eu/strategy/strategy-2020-2024/our-digital-future/openscience_en Deliverable D1.2 – Data Management Plan © COBALT Consortium 8 1.2 Structure of the document Section 2: Brief presentation of COBALT project Section 3: COBALT Data Management Plan Overview Section 4: COBALT Data Section 5: Fair Data Section 6: Allocation of Resources Section 7: Data Security Section 8: Legal, Data Protection and Ethical Aspects Deliverable D1.2 – Data Management Plan © COBALT Consortium 9 2 Brief Presentation of COBALT Project The defining step towards a more secure and robust ICT integration across different sectors is the adoption of a homogenized and agile certification method for cybersecurity. ICT innovation and tools have been key enablers in the operation and acceleration of the Industry 4.0 (I4.0) and Quantum industries and shape new directions and objectives. The integration of different modules and technologies always creates security discrepancies and discontinuities which need to be monitored in a seamless and agile manner, and as a final step lead to the underlying system certification. However, the existence of different standards from different industries often leads to the multi-certification of common-root processes and tools. This can lead industries and manufacturers to deploy resources in an inefficient manner, due to the lack of a unified certification model for cybersecurity in ICT. COBALT proposes the introduction of a Common Certification Model (CCM) for European industries, leveraging existing standards and composing a unified cybersecurity namespace for ICT processes. The proposal will uphold the paradigm of Digital Twinning (DT) via the creation of Digital Threads and extend it in a vertical agnostic approach across different industries, including Quantum computing (involving FHG’s Quantum Computer) and I4.0. The COBALT DT will explore technology disruption mainly focusing on AI and High-Performance Computing (HPC) via the analysis and certification of Quantum Processing Oracles (a Quantum Computer exposure operation that is used as input to another algorithm), and how different enablers of these paradigms can be certified in a vertical agnostic manner. Quantum is destined to play a pivotal role in Europe’s AI and Computing sovereignty, thus protecting such infrastructure and its relevant processes (Quantum Oracles), should be of top priority. Along with common information models, COBALT acknowledges the importance of trusted information exchange a critical feature for an effective certification process across different industries, especially regarding cybersecurity. Therefore, COBALT will focus on the integration of International Data Spaces (IDS) primitives as a basis for the data sharing platform across different stakeholders. IDS currently proposes different models and procedures to share information and data across different spaces in a trusted manner between two parties, this can facilitate the process to build a trusted end-toend certification framework across different industry stakeholders. Finally, COBALT aims to build a decentralized solution to further accelerate technology adoption and harmonization for the different use cases to be adopted. For the proposed CCM to function as a long term and sustainable European solution for certification, it needs to adapt and flex according to different environment conditions. This can be achieved by following a decentralized approach where different industries will share certification process data and feedback, but not be always dependent on a centralized entity, which can lead to time and resource consuming scenarios. A key aspect in this step will be the development of the modelling, verification, testing process in a Web 3.0 compatible manner, building a flexible and future-proof environment for industry experts and stakeholders. Deliverable D1.2 – Data Management Plan © COBALT Consortium 16 The COBALT project's vision within its strategic implementation is focused on maximizing impact by broadening the awareness of its innovations and managing the exchange of value with all involved stakeholders efficiently. The initiative is driven by objectives such as fostering dynamic ecosystem frameworks, executing detailed dissemination and communication plans, safeguarding project deliverables, and liaising with pertinent standardization authorities. EXPLOITATION STRATEGY: COBALT is committed to constructing and executing a detailed exploitation plan to ensure widespread adoption of its deliverables and to establish a lasting legacy for the project. This plan emphasizes assessing market readiness, developing a precise 'go-to-market' strategy, and maintaining rigorous management of knowledge and intellectual property rights. This strategic process will be orchestrated collaboratively by COBALT's exploitation manager and the consortium partners. DATA AVAILABILITY: The COBALT project is dedicated to transparently disseminating its research results and advancements. The consortium initiates to adhere to open access mandates for all disseminated research materials, with due consideration for the confidentiality and restrictions mandated by proprietary rights and data protection statutes as outlined in the General Assembly and Consortium Agreement. Dissemination strategies will undergo continuous enhancement to remain in sync with the project's timelines and activities. ARCHIVING AND ACCESS CONTROL: To uphold data privacy and confidentiality, access to classified data sets will be strictly limited to authorized COBALT consortium members. Mechanisms such as access logs and backup systems will be implemented by the project coordinator to monitor and control data access. Procedures governing data collection, storage, access, distribution, safeguarding, retention, and eventual disposal will strictly comply with protocols agreed upon in the General Assembly and Consortium Agreement. These commitments by COBALT to its strategic exploitation, transparent data handling, and stringent archiving protocols underscore the project’s holistic approach towards achieving its overarching objectives, ensuring transparency, enhancing security, and advocating for responsible data stewardship throughout the lifespan of the project and beyond. Deliverable D1.2 – Data Management Plan © COBALT Consortium 17 4 COBALT Data This section categorizes data that emerges, is generated, or collected within the COBALT project. The data, regardless of its source or creation method, will be organized into distinct categories as outlined in the figure below. Data Sets 1. Administrative Data Personal Data Non-Personal Data 2. Platform Technical Data Non-Personal Data Personal Data No personal data foreseen. 3. Use Cases European Cybersecurity Certification of Industrial AI Applications Quantum Cybersecurity Certification Figure 2: Data Deliverable D1.2 – Data Management Plan © COBALT Consortium 18 4.1 Data Set 1: COBALT Administrative Data In the COBALT project, administrative data refers to information used for organization, management, transactions, and record-keeping. This dataset includes various types of information, such as partner contacts, project planning details, communication records, deliverable templates, financial data, and marketing information. It's intended for internal use and will be retained throughout the project. The data is stored in formats like PDF, Word, Excel, and PowerPoint, and is kept in a shared project repository on COBALT's private cloud (accessible only to consortium members), as well as on partners' servers and the EC Portal. Access is limited to authorized personnel from consortium partners. Consortium members can access the data through the repository provided by NCSRD for data reproducibility. The exact volume and speed of this dataset cannot be accurately estimated at this stage and will be further evaluated for the final Data Management Plan (DMP). Pre-existing data for COBALT may include publicly available templates, reports from similar projects, legal acts, and relevant ethical guidelines. 4.2 Data Set 2: COBALT Platform Technical Data In the COBALT project, technical data is also produced during the development of the COBALT platform. This type of non-personal data includes several sub-categories: • The source code of developed components and services • Data resulting from the analysis of cutting-edge technologies • Much like administrative data, technical data serves internal purposes, and its accessibility to the public is contingent upon the discretion of the owners of the respective technical components. As the project progresses, details such as the size, format, velocity, and reproducibility of this data will be precisely determined and documented in the final version of the Data Management Plan. This stage (M7) marks an intermediate milestone in the technical work packages (WP2-6) of the COBALT project. 4.3 Data Set 3: COBALT Pilot Data Related to use case 1 “EU Certification of Industrial AI Applications”, the relevant data will include the following categories: • Documental information of the EU certification schemes to implement (including conformity assessment processes, and catalogues of requirements). Take for example the EU certification schemes for Cloud Services (EUCS), as published by ENISA on their webpage 3 . Additionally, this information might be complemented with the proprietary standards needed to achieve the certification’s goals (e.g., CEN/TS 18026:2024 4 ), and the relevant works for the topic of AI cybersecurity certification from ENISA 5 . • Machine-readable definitions of associated Metrics and corresponding Assessment Rules, which are maintained on the repositories part of the COBALT architecture (see WP2). The Metrics should become part of the open-source catalogue to be contributed by the project, 3 Please refer to https://www.enisa.europa.eu/publications/eucs-cloud-service-scheme 4 Please refer to https://genorma.com/en/standards/cen-ts-18026-2024-1 5 To be published Q3/2024. Deliverable D1.2 – Data Management Plan © COBALT Consortium 19 whereas the assessment rules are on the expected outcomes from the project (to be further discussed during the following months). • Technical evidence to be gathered by the framework’s Evidence Collectors, which is based on synthetic data from Bosch’s testbed and can be used for the pilot’s purposes. Although this is a topic to be further detailed in subsequent iterations from WP5, this data will be always keep inside the Bosch’s trust boundaries to mirror the assessment processes from human auditors, • Derived data resulting from COBALT’s Work Flows as applied to the use case (e.g., risk assessment results, and generated certificates). This data (and the respective flows) will be provided from the different components in the architecture (see WP2). Please notice that given the nature of this specific use case, data related to the AI-specific features (e.g., AI model training datasets) will be made available to the COBALT framework only as needed by its purposes. Furthermore, access to the data used for this validation use case will be given in full alignment to the Consortium Agreement and respecting the audit practice of the applied certification schemes. Related to the use case 2 “Quantum Process Certification”, the relevant data will include the following categories: • A collection of Test Cases to be used by the Quantum Evidence Collector • High-level code (Qrisp) and low-level representation (e.g. QASM) for Quantum Algorithms (and the corresponding Quantum Oracles) to be evaluated on a system under test • Technical and organizational evidence gathered by the framework’s Evidence Collectors • Machine-readable definitions of Metrics and Assessment Rules for evaluation of evidences • Derived data resulting from the COBALT Work Flows as applied to the use case (e.g., risk assessment results, and generated certificates) Deliverable D1.2 – Data Management Plan © COBALT Consortium 20 5 Fair Data COBALT attempts to introduce an innovative approach for the efficient and dependable development of high-quality data solutions and datasets. The project's success depends not only on speed but also on the quality of input data. COBALT advocates for collaborative, cross-functional efforts, and automation to rapidly build robust data pipelines. The three key pillars of innovation include Strengthening Collaboration, Crafting Dependable Data Solutions, and Implementing Testing and Monitoring Automation. COBALT integrates both technological and social innovations to facilitate secure and sustainable data operations, aligning with responsible principles. The project employs a co-development approach as a foundational methodology. COBALT proposes a secure-by-design Federated Platform in harmony with the EU data strategy (COM (2020) 66) and major EU reference architectures (EOSC). The platform ensures interoperability for cross-border scenarios and scales various applications through open APIs, aspiring to position the EU as a secure and trustworthy data hub. Utilizing an innovative homomorphic approach, COBALT ensures user-friendly, secure, compliant, fair, transparent, accountable, and sustainable collection, storage, processing, querying, and delivery of data. All consortium partners commit to ensuring that the data produced, collected, and processed align with the FAIR Principles 6 , making them findable, accessible, interoperable, and reusable. The Data Management Plan (DMP) outlines aspects such as data discoverability, identifiability, naming conventions, search keywords, versioning, and metadata standards. COBALT emphasizes making data openly accessible, addressing restrictions, specifying access methods, and providing details on data, metadata, documentation, and code deposition. For interoperability, COBALT specifies data and metadata vocabularies, standards, and methodologies, considering interdisciplinary interoperability. The project documents data reusability by specifying licensing terms, duration of reusability, and data quality assurance processes. The COBALT platform promotes trustworthy, green, and responsible data management through valuebased digital technologies, compliance, privacy homomorphic encryption, and preservation. The platform ensures FAIR communication with open data silos and platforms (EOSC) in alignment with EU data policies. COBALT follows Software Oriented Architecture to allow future evolution, prioritizing secure sharing and manipulation of data with homomorphic encryption. The project integrates social innovation and privacy impact assessment, optimizing processing at the edge, resilience, transfer, and storage in line with responsible principles. To support a range of functionalities, the platform incorporates existing domain knowledge and related services, adhering to Software Oriented Architecture. While recognizing that approaches may evolve, COBALT addresses data management issues for each data type, with decisions to be made collaboratively within the consortium. Throughout the project's life cycle, FAIR principles will be upheld for data, ensuring compliance with national and European legal frameworks, data protection regulations, and ethical standards. This section aligns with the guidelines for effective data management provided by the European Commission 7 for Horizon Europe projects. 6 Wilkinson, M., Dumontier, M., Aalbersberg, I. et al. The FAIR Guiding Principles for scientific data management and stewardship. Sci Data 3, 160018 (2016). https://doi.org/10.1038/sdata.2016.18, https://www.nature.com/articles/sdata201618 7 https://webgate.ec.europa.eu/funding-tenders-opportunities/display/OM/Online+Manual Deliverable D1.2 – Data Management Plan © COBALT Consortium 21 5.1 Making Data Findable, Including Provisions for More Data In pursuit of making data findable and ensuring provisions for handling more data, the initial step involves addressing administrative data and use case data. 5.1.1 Administrative Data The first step in the FAIRification process is to make it simple to discover information within large data collections. This involves making sure that both metadata and data can be easily identified by both people and computers. All project deliverables will be carefully listed on the COBALT website (https://horizon-cobalt.eu). Ways to access the project's results will be shared through different channels, including social media, to increase the visibility of our work. For public deliverables, a direct connection will be set up between the project website and the appropriate open repositories where the data is stored. 5.1.2 Platform Technical Data/Use Case Data As COBALT progresses, decisions about whether technical data will be made available to the public and how it can be accessed will be made by the owners of the technical components involved. 5.2 Making Data Accessible This principle focuses on making it easy for users to get to the data, which might involve steps like verifying who they are and giving them permission. Since some data in the COBALT project might be private, there will be rules about how it can be used. Access to personal data, especially sensitive information mentioned in Article 9(1) of the GDPR, will follow data protection rules. Private data will only be shared according to the confidentiality terms in the project's Grant Agreement and Consortium Agreement. 5.2.1 Administrative Data To make sure that the results and scientific papers meet high-quality standards, they'll be reviewed before starting to collect data. Also, other project-related information will be available to COBALT consortium members through a special cloud system provided by the coordinator (NCSRD) for internal use. 5.2.2 Platform Technical Data/Use Case Data As COBALT progresses, decisions about whether technical and use case data will be available to the public will be made by the owners of the relevant technical components. Along with this, the details of how data can be accessed will be explained more thoroughly. 5.3 Making Data Interoperable To make sure data can work together efficiently: Deliverable D1.2 – Data Management Plan © COBALT Consortium 22 5.3.1 Administrative Data For sharing administrative data, COBALT members will set common rules and formats. They'll put this information on a cloud storage system provided by the coordinator. Each partner can make important changes and share them with others in the COBALT group. They'll also swap data through email when needed. If they use existing data or templates, they'll clearly say so in their reports and files. These will be kept in the coordinator's local data storage to meet the group's needs. 5.3.2 Platform Technical Data/Use Case Data As part of this effort, COBALT members will also work on ensuring that technical and use case data can be easily accessed and used by everyone involved. As COBALT moves forward, decisions about sharing technical and use case data with the public will be made by the owners of the technical parts. 5.4 Increase Data Re-Use To make data more reusable: 5.4.1 Administrative Data The project's information that everyone can access will be shared on Zenodo, following the open data strategy. The way this information is organized and standardized will follow specific rules laid out in certain documents. Making sure these shared documents are up to the standards set for Horizon Europe projects and agreed upon by scientists will involve using the quality checks outlined in D1.1, "Project Handbook." These documents, available for anyone to use, are meant to be easy to access and free to use by people outside the project, making sure they're still useful even after the project ends. 5.4.2 Platform Technical Data/Use Case Data As COBALT moves forward, decisions about who can see and use technical and use case data will be made by the owners of those parts. The main goal of the FAIRification process is to make data more reusable. To achieve this, it's important to have detailed descriptions of both metadata and data, along with the right licensing, so that the data can be used or copied in different situations. Deliverable D1.2 – Data Management Plan © COBALT Consortium 23 6 Allocation of Resources It's expected that there won't be any costs associated with making the COBALT datasets FAIR. This is because Zenodo, a repository supported by the EU, provides its services for free. However, some private repositories, such as the one supported by the coordinator, might require a fee. The partners in the COBALT project will cover these fees from their own budgets. Oversight of how data is managed in the project will be handled by the coordinator and technical manager, following the instructions in the handbook. All partners must ensure that their work complies with the relevant laws and regulations for the project. Deliverable D1.2 – Data Management Plan © COBALT Consortium 24 7 Data Security 7.1 Administrative Data The COBALT consortium members will keep administrative data sharing within the consortium. The project coordinator, NCSRD, has set up a shared space for collaboration using SharePoint, along with a mailing list on a local cloud and data repository. This special area acts as a document store only accessible to consortium partners. It allows them to access and swap research and project documents, including results, presentations, internal papers, and other important information. 7.2 Platform Technical Data The data sets related to the COBALT project, as well as the software code for different components outlined in WP2 and WP3, will be securely stored in a cloud infrastructure accessible only to authorized members of the consortium. A comprehensive backup strategy will be developed and put into action using a secure storage server. If the data needs to be stored in an external certified repository, compliance with the security standards of that repository will be ensured. Additionally, the system architecture will incorporate privacy by design principles, and we will establish secure communication protocols. Deliverable D1.2 – Data Management Plan © COBALT Consortium 25 8 Legal Data Protection and Ethical Aspects Ensuring ethical compliance is crucial for all research endeavors supported by the European Union. Therefore, ethical evaluation is integral from the conceptual stage of the proposal, and activities within the Horizon Europe Framework must consistently align with ethical principles throughout their lifecycle. For projects like COBALT, adherence to legal, data protection, and ethical considerations is imperative. The main objective of this document is to identify potential issues that could impact data sharing within the COBALT consortium. In Deliverables D1.3, under WP1, the legal and ethical requirements pertaining to the design and development of the COBALT platform, as well as those for future platform users, will be comprehensively addressed. 8.1 Personal Data in COBALT The COBALT project strictly follows a set of rules for handling personal data, as outlined in the General Data Protection Regulation (GDPR) of the European Union 8 . According to the GDPR, personal data includes any information about a person that can identify with them, covering various aspects of their identity like physical, genetic, or social traits. The GDPR protects the rights of individuals, including employees, by distinguishing between personal and non-personal data. COBALT makes sure to separate personal data from anonymous data and doesn't collect any personal information. The GDPR applies to organizations within the EU that handle personal data, whether they're processors or controllers. It also affects companies outside the EU under certain circumstances, like offering goods or services to EU residents 9 or monitoring their behavior. Since COBALT has partners based in the EU, it falls under GDPR regulations. The project is dedicated to meeting legal and ethical standards for safeguarding personal data. 8.2 Principles of the Processing of Personal Data Article 5 of the GDPR outlines seven key principles that guide the processing of personal data. Adhering to these principles not only ensures compliance with legal data protection requirements but also maintains accountability and protects the rights of individuals. The following principles are particularly important in the COBALT project: Lawfulness, Fairness, and Transparency: Personal data processing must be legal, fair, and transparent to the individuals involved. This includes informing them about the processing, as required by Articles 12 to 14 of the GDPR. Purpose Limitation: Personal data can only be processed for the purposes originally stated at the time of collection, and any further processing must align with those purposes. 8 Regulation (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation). 9 GDPR, Art 3. Deliverable D1.2 – Data Management Plan © COBALT Consortium 32 Data Directive, refers to the utilization of documents 19 held by public sector bodies or public undertakings for purposes other than their original intent 20 , whether commercial or non-commercial. Member State Transpositions: The transpositions of the Open Data Directive by Member States must always be taken into account when considering this directive. Regarding the research data associated with the COBALT project, held by Consortium partners who could be considered as public sector bodies or public undertakings, it is crucial to consider the regulations outlined in the Open Data Directive. While the national policies of Member States concerning the publication of research data funded by public funds are also pertinent, COBALT partners may align their approach with the principles of the directive 21 and its conditions for the re-use of datasets. This includes enabling free-ofcharge re-use of documents and ensuring documents are accessible in open, machine-readable, findable, and reusable formats for the benefit of the scientific community and beyond. COBALT aims to comply with the Open Data Directive and other relevant legislation mandating public sector data to be released in open and free formats. COBALT recognizes the importance of adhering to the directive on open data by providing open and trusted services for data silos and facilitating the use and reuse of information, including public and protected information, as well as metadata, using common rules within an expanding European market for government-held and federated data. The Open Data Directive sets out several key principles that are relevant to COBALT, including releasing non-personal data in open formats and standards, making data available in real-time and via APIs where possible, promoting free reuse, particularly in terms of commercialization and exploitation, focusing on reusing publicly funded research data, discouraging exclusive arrangements and data lockin, and allowing the reuse of data held by public undertakings, such as public utilities and transport providers. COBALT also monitors efforts related to high-value datasets, such as those in geospatial, earth observation, environment, meteorological, statistics, companies, and company ownership fields. The re-use of high-value datasets, defined as documents, is associated with significant societal and economic benefits. They are subject to a separate set of rules ensuring their availability free of charge, in machinereadable formats. COBALT is positioned between these datasets and their use, leveraging specific Application Programming Interfaces (APIs), and will explore the potential of using its SSI framework to enhance their thematic scope of value. Commission's Recommendation on Scientific Information Access: EU Member States are encouraged to appoint a National Point of Reference tasked with reporting on the implementation of open access within their respective territories. This recommendation forms part of a series of measures aimed at improving access to scientific information generated in Europe and aligning with the Commission's Horizon 2020 policy objectives 22 . The introduction of Recommendation 2012/417/EU on access to and preservation of scientific information underscores this commitment. Recommendation C(2018)2375: The recommendation takes into account advancements in various fields, including research data management, the integration of FAIR data principles (data that is 19 Documents, according to Article 2(6) of the Directive, can be any content regardless of their medium (i.e. paper or electronic form) or any part of their content. 20 Open Data Directive, Article 2(11). 21 https://digital-strategy.ec.europa.eu/en/policies/legislation-open-data 22 http://ec.europa.eu/research/openscience/pdf/openaccess/background_note_open_ access.pdf#view=fit&pagemode=none Deliverable D1.2 – Data Management Plan © COBALT Consortium 33 Findable, Accessible, Interoperable, and Reusable), Text and Data Mining (TDM), technical standards promoting re-use, and incentive programs. It also considers ongoing developments at the EU level, particularly those related to the European Open Science Cloud, and recognizes the growing importance of data analytics in research. Additionally, it distinguishes between two key aspects: the implementation of reward systems to encourage researchers to share data and participate in open science practices, and the skills and competencies required by researchers and staff in research institutions. Overall, COBALT is committed to following these guidelines and ensuring that the data it deals with is accessible and user-friendly for everyone. Deliverable D1.2 – Data Management Plan © COBALT Consortium 34 9 Conclusion This document provides an initial overview of the Data Management Plan (DMP) for the COBALT project, outlining the specific datasets identified for collection and generation and their potential alignment with FAIR data principles. It offers thorough information regarding the content and intended use of the datasets. In order to maintain data security, the project will utilize secure data storage and implement both technical and organizational measures to guarantee the secure handling of data. Deliverable D1.2 – Data Management Plan © COBALT Consortium 35 Deliverable D1.2 – Data Management Plan © COBALT Consortium 36 Copyright © 2023. All rights reserved. The Members of the COBALT Consortium: Contact: Disclaimer Co-funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union. Neither the European Union nor the granting authority can be held responsible for them.