Every day, researchers across Europe increasingly need to combine datasets to answer urgent societal questions about education, health, income, or inequality. The data often exists, but getting access to it can be a slow and complicated process.

Most datasets come with access conditions: rules about who can use the data, for what purpose, and under what circumstances. These conditions are typically written in legal or policy language, which can differ between data holders. As a result, research administrators often have to review applications manually, communicate with applicants and coordinate approvals. This takes months, and when a research project requires data from multiple organisations the process can become even more complicated.

A new study, published in the International Journal of Population Data Science (IJPDS), proposes a way to make this process more efficient by turning data access conditions into a format that computers can read and interpret.

The researchers use an international open standard called ODRL (Open Digital Rights Language) to express conditions such as structured digital information. Instead of relying solely on documents containing legal or policy text, the rules governing access can be represented in a form that can be processed automatically.

The proposed framework has two main components. The first is a library of reusable access condition templates, which provide standardised building blocks that data holders can combine and adapt to describe their specific requirement. The second is a Data Access Broker: a service that reads these machine-readable conditions and automates the access process, checking whether a researcher meets the requirements and coordinating approvals across multiple data holders simultaneously.

Crucially, the framework does not replace human judgment or legal oversight. Data holders remain in control of decisions about access to their data. Instead, the aim is to automate routine administrative tasks, flag cases that require human review, and create a transparent record of decisions.

The framework was developed in the context of the Dutch social science research infrastructure ODISSEI, where data holders have been grappling with exactly these challenges. But the researchers say that fragmentation, inconsistent access conditions and administrative burdens are common across Europe and beyond. The approach could therefore support wider initiatives such as the European Open Science Cloud (EOSC) and the European Health Data Space (EHDS).

A concrete implementation is already publicly available through the ODISSEI Five Safes License, which provides both a human-readable and a machine-readable ODRL version of a widely used access framework.

Lead author, Lucas van der Meer said: "Researchers lose months to paperwork that computers could handle in seconds. Our framework doesn't cut corners on governance — it makes governance work smarter, so that the rules that protect sensitive data can also be the rules that unlock it."

 

Click here to read the full article

Lucas van der Meer, ODISSEI, Erasmus University Rotterdam, Netherlands

Van Der Meer, L. (2026) “Standardizing Access to Sensitive Data with Machine-Actionable Access Conditions”, International Journal of Population Data Science, 11(1). doi: 10.23889/ijpds.v11i1.3454.