Inventory and purpose
Identify authoritative datasets, source systems, derived data, purpose, sensitivity, records status, consumers, dependencies, and known quality limitations.
Connect data ownership, quality, access, interoperability, privacy, retention, migration, and exit requirements into one operating model instead of separate documentation exercises.
Regulatory and interoperability requirements change. Treat dated research as publication context and verify current obligations and technical specifications at the authoritative source.
A data strategy becomes operational when ownership, purpose, quality, access, movement, retention, evidence, and disposition are clear enough to test.
Identify authoritative datasets, source systems, derived data, purpose, sensitivity, records status, consumers, dependencies, and known quality limitations.
Separate business ownership, technical custody, privacy/security responsibilities, quality stewardship, and approval authority so decisions have accountable owners.
Define identity, authorization, interfaces, schemas, contracts, lineage, validation, versioning, and downstream-use expectations instead of relying on informal exports.
Specify retention, legal holds, archival, deletion, export, migration, evidence preservation, and provider-exit requirements before the data becomes trapped in a workflow.
Policies are easier to defend when the organization can show who approved access, how quality is measured, where data moved, and what happened when requirements changed.
Capture the users, data classes, interfaces, constraints, evidence needs, risks, and unknowns for a data platform or workflow decision.
Build the briefRequire evidence for access, encryption, data handling, logging, vulnerability management, incident response, resilience, and subprocessors.
Use the security questionnaireData-driven portals, dashboards, forms, and generated interfaces still need usable and testable accessibility evidence.
Review accessibility evidenceWeight governance, interoperability, quality, portability, security, operations, and cost before demonstrations shape the criteria.
Use the scorecardUse these for the legal, standards, product, and interoperability context available at publication. Verify current law, regulator guidance, specifications, and product behavior before making a present-day decision.
Use current official sources to confirm legal scope, version status, and implementation requirements.
For sector-specific interoperability requirements, use the responsible regulator or standards body for the exact jurisdiction and workflow. See editorial standards for source hierarchy and historical-content handling.