Data sharing is central to innovation, yet compliance and trust remain key barriers. Emerging concepts such as data trusts and data trust frameworks (DTFs) aim to bridge this gap, providing legally and technically consistent methods for sharing data safely and fairly.
The concept of a data trust, first highlighted in the UK’s Hall/Pesenti “Growing the UK AI Industry” report in 2017, envisions a repeatable, compliant framework that governs how data is shared between parties. The Open Data Institute (ODI) later defined a data trust as a legal structure providing independent stewardship of data, identifying six essential features: (i) clear purpose, (ii) legal structure, (iii) defined rights and duties, (iv) decision-making processes, (v) benefit-sharing mechanisms and (vi) sustainable funding.
In practice, however, creating a separate legal entity may not always be feasible. Many organisations instead adopt a contract-based framework, agreeing common operating rules and technical specifications without establishing a formal trust structure. These frameworks, when aligned with standards such as ISO/IEC 38505-1 and 19944, can manage acquisition, use, sharing and deletion in a structured, compliant way.
Legislative initiatives in both the EU and UK are now accelerating this evolution. The EU Data Act (effective September 2025) introduces mandatory fairness rules for data-sharing agreements and seeks to establish common European data spaces in sectors such as health, finance and energy. Meanwhile, the UK Data (Use and Access) Act 2025 paves the way for “smart data schemes,” offering a similar model for regulated, interoperable data exchange.
Together, these developments signal a shift toward data ecosystems built on trust, accountability and interoperability, where compliant sharing becomes a driver of innovation rather than a constraint.
This article is compiled using insights from our recent white paper: Legal Aspects of Data – Governance and Management.