Full text
LUMI AI Factory Service Center Empowering Europe’s AI Ecosystem
D5.4 Connectors for Common European Data Spaces 2 D5.4 Connectors for Common European Data Spaces
D5.4 Connectors for Common European Data Spaces 3 Project Title LUMI AI Factory Service Center Project Acronym LUMI-AIF Project Number 101234208 Type of Action HORIZON-JU-RIA Topic HORIZON-JU-EUROHPC-2025-AI-01-IBA-01 Starting Date of Project 01.03.2025 Ending Date of Project 29.02.2028 Duration of the Project 36 months Website lumi-ai-factory.eu Work Package WP5 – Data access and integration Task T5.6: Connection to Common European Data Spaces and other data repositories Lead Authors Heidi Laine (CSC) Contributors Jarno Laitinen (CSC), Susanna Repo (CSC) Peer Reviewers Martin Matthiesen (CSC), Tuuli Randver (UT), Magnus Valgre (UT) Version 1.0 Due Date 31.10.2025 Submission Date 31.10.2025 Dissemination level X PU: Public SEN: Sensitive – limited under the conditions of the Grant Agreement EU-RES. Classified Information: RESTREINT UE (Commission Decision 2005/444/EC) EU-CON. Classified Information: CONFIDENTIEL UE (Commission Decision 2005/444/EC) EU-SEC. Classified Information: SECRET UE (Commission Decision 2005/444/EC)
D5.4 Connectors for Common European Data Spaces 4 Version History Revision Date Editors Comments 0.5 15.10.2025 Heidi Laine Ready for internal review 0.2 30.10.2025 Heidi Laine Reviewers’ comments incorporated 0.3 31.10.2025 Heidi Laine Final version sent to the PMO for quality check. 1.0 31.10.2025 Anna Luoma Final quality check performed by the PMO, sent to review Declaration on the Use of AI Assistance This report has been prepared with the support of GPT-5-enabled Microsoft Copilot, which was used to assist in drafting text, checking language, gathering background information, and for creating the glossary of terms. All content has been thoroughly reviewed, fact-checked, and edited by the authors to ensure accuracy and alignment with the objectives of the report. Glossary of Terms Term Definition AI-on-Demand A European platform providing access to AI resources, tools, and services for research and industry. Auditability The capability to track and verify data transactions and policy compliance through immutable logs and reports. Common European Data Spaces Federated ecosystems enabling trusted and interoperable data sharing across sectors in compliance with EU regulations. Connector A software component that facilitates secure, policy-compliant data exchange between systems or data spaces. Data Sovereignty The principle that data owners retain control over their data, including how and by whom it is used. Dataspace Protocol (DSP) A standardized protocol for secure data exchange between connectors, separating control and data planes. DSSC (Data Spaces Support Centre) An EU-backed organization providing blueprints, standards, and guidance for building and operating data spaces. Eclipse Data Space An open-source framework implementing IDS and Gaia-X principles for sovereign data exchange.
D5.4 Connectors for Common European Data Spaces 5 Connector (EDC) EOSC (European Open Science Cloud) An EU initiative providing a federated environment for sharing research data, tools, and services. European Health Data Space (EHDS) An EU initiative enabling secure and compliant use of health data for research, innovation, and policymaking. European Language Data Space A sector-specific data space focused on multilingual language resources for AI and language technology development. Federated Identity A system that allows users to access multiple services using a single set of credentials across trusted domains. Gaia-X A European initiative promoting federated cloud and data infrastructure based on openness, transparency, and interoperability. IDS (International Data Spaces) A reference architecture and standard for secure and sovereign data exchange developed by the International Data Spaces Association. Interoperability The ability of different systems, organizations, or data spaces to work together seamlessly through standardized protocols. LDS The European Language Data Space LUMI AIF LUMI AI Factory Policy Enforcement Mechanisms embedded in connectors to ensure that data usage complies with agreed-upon terms and regulations. REMS (Resource Entitlement Management System) A system for managing access to sensitive datasets through entitlement workflows and license enforcement. SPE (Secure Processing Environment) A controlled infrastructure for processing sensitive data, ensuring compliance with privacy and security regulations. Simpl Middleware European Commission’s open-source middleware for interoperability and trust across Common European Data Spaces.
D5.4 Connectors for Common European Data Spaces 6 Executive Summary This deliverable presents the initial strategy and technical foundation for integrating the LUMI AI Factory (LUMI AIF) with Common European Data Spaces through standardized connector components. These connectors are essential for enabling secure, policy-compliant, and interoperable data exchange between LUMI AIF and external data ecosystems, in alignment with the European Data Strategy. The report outlines the architectural principles, component selection criteria, and deployment roadmap for connectors that support data sovereignty, trust, and interoperability. It emphasizes the role of connectors as operational enablers of governance logic, capable of enforcing usage policies, managing identity, and facilitating dynamic contract negotiation across heterogeneous systems. Three key connector technologies are evaluated: • REMS, for entitlement workflows and access governance in sensitive domains like health and genomics. • Eclipse Data Space Connector (EDC), for standardized, sovereign data exchange across research and language data spaces. • Simpl middleware, for scalable integration with multiple European data spaces and support for semantic interoperability and policy enforcement. The report identifies high-value data spaces for initial integration, including the European Open Science Cloud (EOSC), European Language Data Space (LDS), and the European Health Data Space (EHDS). It also highlights the strategic relevance of REMS in EHDS and its operational use in the Genome Data Infrastructure. A phased deployment plan is proposed, starting with sandbox environments and MVP connectors for EOSC and LDS, followed by regulated integrations using Secure Processing Environments and REMS. The plan includes technical baselines, governance mechanisms, and operational models to ensure compliance with evolving European standards such as IDS-RAM, Gaia-X, DSSC blueprints, and the Data Act. Looking forward, the report recommends expanding connector coverage, enhancing compliance tooling, and aligning with strategic initiatives like Exa4Mind and the EuroHPC Federation Platform. These efforts will position LUMI AIF as a federated, trusted node in the European AI and HPC ecosystem, supporting scalable, responsible, and innovation-driven data use.
D5.4 Connectors for Common European Data Spaces 7 Table of Contents 1. Introduction ............................................................................................................... 9 1.1 Purpose and scope of the report 9 1.2 LUMI AIF objectives for European data spaces 9 2. Background and Context ........................................................................................... 10 2.1 Overview of the Common European Data Spaces initiative 10 2.2 Role of connectors in data sharing and interoperability 11 2.3 Relevant standards and reference architectures 12 3. Criteria for component selection ............................................................................... 14 3.1 Criteria for identifying high-value data spaces 14 3.2 Data Spaces relevant to LUMI AIF 15 3.2.1 European Open Science Cloud 16 3.2.2 European Language Data Space 17 3.2.3 European Health Data Space 18 3.2.4 Data spaces in the fields of manufacturing and communication technologies 20 4. Connector Components Overview ............................................................................. 20 4.1 General architecture of connectors 20 4.2 Architectural Evaluation: REMS, EDC, and Simpl 21 4.3 Technology stack and dependencies 23 4.3.1 Core Technology Stack Components 23 4.3.2 Dependencies and Integration Points 24 5. Connector deployment plan...................................................................................... 24 5.1 Establishing Preliminary Agreements for Data Space Connectors in LUMI AIF 24 5.1.1 Purpose and Scope of Preliminary Agreements 25 5.1.2 Requirements for Agreement Design 25 5.1.3 Implementation Steps for LUMI AIF 25 5.1.4 Technical deployment 26
D5.4 Connectors for Common European Data Spaces 8 6. Conclusions and Next Steps ...................................................................................... 29
D5.4 Connectors for Common European Data Spaces 9 1. Introduction 1.1 Purpose and scope of the report The purpose of this deliverable report is to present the initial iteration of data space connector solutions for LUMI AI Factory (LUMI AIF) designed to enable interoperability and secure data exchange between LUMI AIF and data spaces. These connectors form the foundation for standardized, trusted, and efficient data sharing across domains and platforms in alignment with the European Data Strategy 1 . In the strategy, common and interoperable data spaces and the data pools from key European sectors that they form are a way of implementing the single market for data in the EU. In this report we • Introduce the first LUMI AIF analysis on connector components for high-value Common European Data Spaces. • Describe the underlying architecture, functionalities, and integration approach. • Outline the methodology for selecting, developing, and validating connectors. • Define the strategy for continuous growth and evolution of the connector ecosystem as project requirements and stakeholder needs mature. • Present how to ensure alignment with relevant standards, security, and data protection principles. This deliverable represents an early stage of development. The components and processes described here will be refined, extended, and validated further as the project progresses, incorporating feedback from real-world use cases and evolving requirements. 1.2 LUMI AIF objectives for European data spaces The overarching goal is to establish a robust and scalable mechanism for seamless data exchange and integration across heterogeneous sources, thereby enhancing the accessibility and utility of AI resources within high performance computing (HPC) workflows. At the core of this deliverable is the concept of the data space connector, a service component that facilitates secure, policy-compliant data sharing between systems. In the context of European data spaces, connectors are essential for operationalizing the principles of data sovereignty, interoperability, and trust. They allow the LUMI AIF users and customers to interact with external data ecosystems, and vice versa, without compromising control over data usage or violating regulatory constraints. The deliverable aims to guide implementation of connectors that are compatible with the architectural and governance models defined by European initiatives such as the Simpl, International Data Spaces Association (IDSA), Gaia-X, and the Data Spaces Support Centre (DSSC). These connectors must support 1 https://commission.europa.eu/strategy-and-policy/priorities-2019-2024/europe-fit-digital-age/european-datastrategy_en
D5.4 Connectors for Common European Data Spaces 16 Figure 3, which is based on a IDSA figure about fundamental concepts of a data space 9 , gives a high-level description of key roles and responsibilities for data space connector use cases in the LUMI AIF context. LUMI AIF users can use integrated data space connector solutions and frameworks for getting data from data space to the environment. LUMI AIF will provide the necessary technical deployment and agreement process paths with high-value data spaces, but individual users need to form the binding agreements with the data spaces / data space participants (depending on the data space governance in place) based on the data specific policies. Figure 3 Main LUMI AIF data space connector use case In the next sub-chapters, we will examine some of the data spaces that have been recognized as especially relevant for LUMI AIF and our users and customers. The list is not definite nor final, as the landscape of European data spaces continues to develop dynamically. 3.2.1 European Open Science Cloud The European Open Science Cloud (EOSC) is the European Union’s flagship initiative to create a federated, trusted, and multidisciplinary environment for sharing research data, tools, and services. Recognized as the common European data space for science, research, and innovation, EOSC is designed to mobilize and align digital resources across Europe, enabling researchers to publish, find, and reuse data in accordance with the FAIR principles, Findability, Accessibility, Interoperability, and Reusability. EOSC is not a single platform but a “system of systems,” federating national and institutional data repositories, research infrastructures, and scientific service providers into a cohesive network. The launch of the EOSC EU Node in October 2024 marked a significant milestone, providing a reference implementation and a gateway for researchers to access interoperable services across Europe. EOSC’s 9 https://internationaldataspaces.org/wp-content/uploads/dlm_uploads/IDSA-Data-Space-Connector-Report1_October_2025-1.pdf
D5.4 Connectors for Common European Data Spaces 17 architecture supports machine-actionable data, cross-disciplinary collaboration, and reproducible science, while its tripartite governance, comprising the European Commission, Member States, and the EOSC Association, ensures strategic coordination and long-term sustainability. For the LUMI AIF, EOSC represents a high-value data space that aligns with its mission to integrate world-class computing, high-quality data, and top-tier AI expertise. EOSC offers access to a vast array of research datasets, including those from life sciences, environmental sciences, social sciences, and physics, domains where AI applications are rapidly evolving. EOSC’s federated architecture complements LUMI AIFs distributed computing model. The ability to access data across borders and disciplines without centralizing it aligns with LUMI’s emphasis on data sovereignty and compliance. EOSC’s governance and policy frameworks provide a structured environment for responsible data use, which is critical for LUMI AIF’s engagement with sensitive or regulated datasets. Simpl 10 is the European Commission’s open-source smart middleware designed to support interoperability and trust across Common European Data Spaces, including EOSC. It provides modular components for identity management, policy enforcement, semantic interoperability, and cloud-toedge federation. Simpl is being integrated into EOSC through feasibility studies and pilot deployments, with the goal of enabling seamless data exchange between EOSC nodes and other sectoral data spaces. For EOSC, Simpl offers a technical foundation for connector development, service orchestration, and cross-space interoperability. It supports the deployment of EOSC services in heterogeneous environments, including HPC infrastructures like LUMI. Simpl’s architecture allows EOSC to scale its federation model, integrate with external data spaces (e.g., health, language, public procurement), and maintain compliance with European data legislation. In the context of LUMI AIF, Simpl enables the development of connector components that link LUMI to EOSC in a secure, policy-aware, and scalable manner. This integration supports the broader goal of embedding LUMI into the European research data ecosystem, facilitating AI-driven research and innovation across disciplines. 3.2.2 European Language Data Space The European Language Data Space (LDS) 11 is one of the sector-specific initiatives under the broader framework of Common European Data Spaces, as outlined in the European Data Strategy. Its primary objective is to facilitate the sharing, reuse, and valorisation of multilingual language resources across Europe, supporting both public and private actors in developing language technologies that reflect the linguistic diversity of the continent. This data space is particularly focused on enabling access to highquality datasets, models, and services that support translation, speech recognition, natural language processing (NLP), and other language-based AI applications. The relevance of the LDS to the LUMI AI Factory is both strategic and technical. Strategically, it aligns with the European Union’s commitment to digital sovereignty and linguistic inclusivity. By participating 10 https://digital-strategy.ec.europa.eu/en/policies/simpl 11 https://language-data-space.ec.europa.eu/index_en
D5.4 Connectors for Common European Data Spaces 18 in this data space, LUMI AIF can contribute to and benefit from a federated infrastructure that supports the development of AI models in all official EU languages, including less widely spoken ones such as Finnish or Estonian. This is especially important for ensuring that AI systems deployed in Europe are culturally and linguistically adapted, avoiding biases that arise from training on predominantly Englishlanguage datasets. Technically, the European Language Data Space provides a structured environment for accessing curated language resources through standardized connectors and governance frameworks. Through LDS, LUMI AIF can integrate with repositories such as the Finnish Language Bank and other national or institutional language archives. LDS supports the development of open-source tools and services that can be deployed within highperformance computing environments. This includes pre-trained models, annotation tools, and semantic resources that are essential for building robust NLP pipelines. By connecting to this data space, LUMI AIF can accelerate the development of multilingual AI applications, support cross-border research collaborations, and contribute to the European AI-on-Demand ecosystem. The LDS Connector 12 is the central technical component of this data space. It is based on the Eclipse Dataspace Connector (EDC) and extended through community-driven implementations such as TractusX and Sovity. Key features include: • Peer-to-peer architecture: LDS connectors operate in a decentralized manner, allowing participants to publish, discover, and exchange language assets directly. • Metadata and policy management: Each data offering includes metadata and usage policies, which are negotiated and enforced through the connector. • Contract negotiation and data transfer: The connector supports automated contract conclusion and secure data exchange, including financial transactions where applicable. • Multilingual support: The LDS connector includes specifications for multilingual asset descriptions, enabling semantic interoperability across European languages. 3.2.3 European Health Data Space The European Health Data Space (EHDS) is a flagship initiative under the European Data Strategy, designed to facilitate the secure and efficient use of health data across the European Union. It aims to empower individuals with control over their personal health data while enabling researchers, policymakers, and innovators to access high-quality datasets for secondary use in a legally compliant and technically robust manner. EHDS is not a single platform, but a federated ecosystem composed of national infrastructures, common services, and harmonized governance frameworks. At the core of EHDS is the concept of Secure Processing Environments (SPEs). These are controlled technical infrastructures where sensitive health data can be accessed and processed without compromising privacy or violating legal constraints. SPEs must meet stringent requirements for data protection, identity management, auditability, and policy enforcement. They are designed to support 12 https://ec.europa.eu/newsroom/lds/items/818143/en
D5.4 Connectors for Common European Data Spaces 19 pseudonymized or anonymized data access, with mechanisms for dynamic consent, usage logging, and secure computation. For the LUMI AIF, EHDS represents a strategically important data space for several reasons. First, health data is among the most valuable and complex datasets for AI development, particularly in domains such as medical imaging, genomics, epidemiology, and personalized medicine. Access to EHDS datasets through SPEs would enable LUMI AIF to support high-impact research and innovation in these areas, leveraging its high-performance computing capabilities to train models on large-scale, heterogeneous health data. The EHDS is a sector-specific data space focused on enabling both primary use (clinical care) and secondary use (research, innovation, policymaking) of electronic health data across the EU. While the EHDS regulation defines the legal and governance framework, its technical implementation relies on Secure Processing Environments (SPEs) and interoperable connector components. Connector solutions for EHDS are still emerging, but some architectural directions can be assumed: • SPE-integrated connectors: These connectors are embedded within secure environments that meet EHDS specifications for privacy, auditability, and policy enforcement. They facilitate controlled access to pseudonymized or anonymized health data for secondary use. • Compliance with EHDS standards: Connectors must support interoperability with electronic health record (EHR) systems, enforce usage conditions, and integrate with the HealthData@EU infrastructure. This includes support for identity federation, consent management, and logging mechanisms. Whether any of the existing architectures and solutions can be adjusted for EHDS is still difficult to know for certain. Based on information received through EHDS development projects, such as TEHDAS2 13 , the newly developed eDelivery 14 will not be adequate for EHDS, nor the Simpl. The Commission is currently soliciting suggestions from stakeholders for protocols to use. X-road 15 , developed by Estonia and Finland has been suggested as one of the potential, currently existing and functional options. CSC’s REMS (Researcher’s Access Management System), while not a data space connector, plays a strategically important role in the context of the European Health Data Space (EHDS), providing a mature and scalable solution for managing controlled access to sensitive health data, particularly for secondary use in research. REMS enables transparent and auditable permit workflows, ensuring that data access complies with ethical, legal, and organizational requirements. This aligns closely with EHDS objectives to facilitate trustworthy data sharing across borders and sectors. REMS also supports interoperability across technical and governance layers, making it a valuable reference model for EHDS implementation. Its relevance is further underscored by its use in the Genome Data Infrastructure (GDI), where REMS helps manage access to genomic datasets across European countries, demonstrating its capacity to operate in complex, multi-stakeholder environments with high data protection standards. 13 https://tehdas.eu/ 14 https://ec.europa.eu/digital-building-blocks/sites/spaces/DIGITAL/pages/467110114/eDeliverTEHDAS 15 https://x-road.global/
D5.4 Connectors for Common European Data Spaces 20 3.2.4 Data spaces in the fields of manufacturing and communication technologies As of late 2025, manufacturing-related data spaces in Europe are moving from planning to deployment. Supported by the Digital Europe Programme and national initiatives, projects like SM4RTENANCE and UNDERPIN are piloting real-world applications such as predictive maintenance and dynamic asset management. 16 These efforts are guided by Gaia-X and International Data Spaces (IDS), and at least SM4RTENANCE is relying on the Eclipse Data Space Connector (EDC) for data interactions. Key challenges for manufacturing data spaces include fragmented data landscapes, standard harmonization, and SME onboarding. European commission doesn’t identify communication technologies as a specific data space domain, nor does the IDSA Data Spaces radar 17 so it’s more difficult to recognize the relevant and mature data spaces for that field. However, it is likely that they too will rely on some of the widely used standards and architectures, see chapter 2.3. It is also likely that as the LUMI AIF industry engagement expands and evolves, more insight into the communication technologies data space landscape will be accumulated, and LUMI AIF data space connector plans and solutions can be adjusted accordingly. 4. Connector Components Overview 4.1 General architecture of connectors In general, the architecture of data space connectors reflects the need to balance data sovereignty, interoperability, and trust in decentralized data ecosystems. These connectors are not monolithic systems, but modular components designed to mediate secure and policy-compliant data exchange between autonomous entities, whether organizations, platforms, or services, within and across data spaces. At the core of most data space connector architectures is a dual-plane design: the control plane and the data plane. The control plane handles metadata exchange, identity verification, policy negotiation, and contract enforcement. It ensures that data sharing agreements are respected and that access is granted only under predefined conditions. The data plane, by contrast, is responsible for the actual transmission of data, often using secure and auditable channels. Architectures such as the Eclipse Data Space Connector (EDC) and Simpl middleware follow this separation explicitly, enabling flexible integration with various identity providers, policy engines, and data catalogs. These connectors often support federated discovery mechanisms, allowing participants to locate and evaluate data offerings across distributed environments. They also implement usage control frameworks, which go beyond access control by enforcing how data can be used after it has been shared. A key architectural feature is extensibility. Connectors are typically built to be modular, allowing integration with different protocols (e.g. HTTP, MQTT, S3), storage systems, and semantic models. This 16 https://digital-strategy.ec.europa.eu/en/policies/data-spaces 17 https://internationaldataspaces.org/wp-content/uploads/dlm_uploads/The-Data-Spaces-Radar-Version-4.pdf
D5.4 Connectors for Common European Data Spaces 21 modularity is essential for adapting to sector-specific requirements and for evolving alongside emerging standards such as the Dataspace Protocol (DSP) and Gaia-X compliance frameworks. Another architectural consideration is compliance and auditability. Connectors must support logging, monitoring, and policy enforcement mechanisms that align with European regulations such as the GDPR, Data Governance Act, and Data Act. This often involves embedding trust services, such as certification authorities and registries, into the connector architecture. 4.2 Architectural Evaluation: REMS, EDC, and Simpl The relevance of REMS, Eclipse Data Space Connector (EDC), and Simpl middleware to the LUMI AIF stems from their complementary roles in enabling secure, interoperable, and policy-compliant access to data—each addressing different layers of the data space ecosystem and aligning with both technical and strategic goals of LUMI AIF and the European Data Strategy. REMS is particularly valuable for LUMI AIF in contexts where access to sensitive or restricted datasets must be governed through formal workflows. Its architecture supports entitlement management, federated identity, and license enforcement, which are essential for research infrastructures dealing with controlled data. For LUMI AIF, which may need to integrate datasets from research domains such as genomics, social sciences, or health, REMS provides a mature and auditable mechanism for managing who can access what data, under which conditions. While REMS is not a data space connector, it complements connector-based architectures by handling the governance and authorization layer that connectors must respect. Eclipse Data Space Connector is directly aligned with the European data space architecture and is being tested in the European Language Data Space and the Finnish Language Bank. This makes it highly relevant for LUMI AIF, especially in multilingual AI model development and natural language processing (NLP) tasks. EDC supports federated data exchange, policy enforcement, and identity management, all of which are critical for integrating LUMI into broader European data ecosystems. Its modular architecture allows LUMI to connect with other data spaces using standardized protocols, facilitating access to language resources, annotated corpora, and pre-trained models while ensuring compliance with usage policies. Simpl middleware, developed under the Data Spaces Support Centre (DSSC), provides the foundational infrastructure for connecting to Common European Data Spaces. It is designed to support interoperability, trust, and value creation across sectors. For LUMI AIF, Simpl offers a scalable and standards-compliant way to integrate with multiple data spaces, including those in domains such as mobility, energy, and public administration. Its architecture supports semantic interoperability, identity federation, and policy negotiation, making it suitable for high-performance AI workflows that require access to diverse and distributed data sources. Together, these three solutions form a layered and complementary stack for LUMI AIF: • REMS governs access to sensitive datasets. • EDC enables standardized, sovereign data exchange across language and research domains. • Simpl provides the middleware backbone for connecting to multiple European data spaces in a scalable and policy-aware manner.
D5.4 Connectors for Common European Data Spaces 22 Their combined use supports LUMI AIF’s mission to become a federated, interoperable, and legally compliant AI infrastructure embedded within the European data space ecosystem. REMS (Resource Entitlement Management System) REMS is a domain-specific access management system developed by CSC, primarily used for managing access to research datasets. Its architecture is layered and modular, consisting of three main tiers: • API Layer: Handles HTTP requests, performs coarse-grained access control, and transforms requests into service layer calls. It includes Swagger-based documentation and lives in the rems.api.* namespaces. • Service Layer: Encapsulates business logic and orchestrates operations across multiple database namespaces. It manages workflows, licensing, user settings, and asynchronous command processing. This layer avoids circular dependencies and is designed for modular expansion. • DB/External Layer: Manages data persistence and external integrations. It includes domainspecific logic for serialization, schema coercion, and database queries. External services (e.g., EGA) are accessed via dedicated namespaces (rems.ext.*). [github.com] REMS is tightly coupled to its internal data model and access workflows. While it supports federated login and API-based integration, it is not designed as a general-purpose data space connector. Its architecture prioritizes consistency, auditability, and fine-grained entitlement management over cross-domain interoperability. Eclipse Data Space Connector (EDC) EDC is a general-purpose, open-source framework for sovereign, inter-organizational data exchange. It is designed to implement the International Data Spaces (IDS) and Gaia-X reference architectures. Its architecture includes: • Connector Core: Acts as the endpoint for data exchange, enforcing usage policies and managing data flows. • Federated Catalog: Enables discovery of data offerings across organizations. • Identity Hub: Manages authentication and authorization using standards like OAuth2 and decentralized identity systems. • Policy Enforcement and Monitoring: Ensures compliance with data usage agreements and provides audit capabilities. • Extensibility Layer: Supports integration with various data transfer protocols, storage systems, and cloud environments. [projects.eclipse.org], [newsroom.eclipse.org] EDC is modular and designed for reuse across sectors. It supports both control and data planes, enabling dynamic negotiation of data contracts and secure data transmission. Its architecture is aligned with European data space principles, emphasizing interoperability, data sovereignty, and trust. Simpl Middleware Simpl is a European Commission-backed middleware solution developed under the Data Spaces Support Centre (DSSC). It provides foundational components for building and connecting data spaces. Its architecture is structured around three pillars:
D5.4 Connectors for Common European Data Spaces 23 • Data Interoperability: Includes semantic models, data formats, and APIs for enabling crossdomain data exchange. • Data Sovereignty and Trust: Provides identity management, policy enforcement, and traceability mechanisms. • Data Value Creation: Supports data discovery, marketplace functionality, and monetization features. [dssc.eu] Simpl connectors serve as endpoints for data space participation, integrating with shared registries and services such as trust registries, data catalogs, and observability tools. The architecture distinguishes between control and data planes, and is designed to be extensible and compliant with evolving European standards (e.g., Data Act, Gaia-X, IDS). 4.3 Technology stack and dependencies The technology stack and dependencies of data space connectors in the European context are shaped by a convergence of open standards, modular software components, and governance frameworks designed to ensure interoperability, data sovereignty, and trust across federated ecosystems. These connectors are not standalone applications, but integrated suites of services deployed within controlled environments, such as cloud-native infrastructures or on-premises systems. 4.3.1 Core Technology Stack Components Connector Frameworks The most prominent implementations include the Eclipse Dataspace Connector (EDC) and the FIWARE Data Space Connector, both of which follow the IDS Reference Architecture Model (IDS-RAM). These frameworks are modular and extensible, allowing organizations to integrate them into existing IT landscapes. They support the Dataspace Protocol (DSP), which defines schemas and communication protocols for publishing data, negotiating usage agreements, and accessing data within federated systems. Identity and Trust Services Connectors will on identity verification mechanisms such as OAuth2, OpenID Connect, and decentralized identity frameworks. Many of these frameworks have not yet been rolled out, but are being developed. Trust services include remote attestation, legal identity verification, and compliance checks. These are essential for enforcing participation rules and ensuring that data sharing occurs within a trusted environment. Policy Enforcement and Contract Management Usage control is implemented through policy engines that interpret and enforce data usage agreements. These may be based on standards like XACML or custom rule-based systems. Contract negotiation and enforcement are core to the control plane of the connector architecture. Metadata and Semantic Interoperability
D5.4 Connectors for Common European Data Spaces 24 Metadata management is supported through APIs and vocabularies that enable semantic alignment. Initiatives like Smart Data Models, NGSI-LD, and SAREF provide domain-specific ontologies that help connectors interpret and transform data consistently across sectors. Data Exchange APIs and Protocols Connectors expose endpoints for data access, often using RESTful APIs, GraphQL, or MQTT for streaming data. The transport layer must support secure communication (e.g., TLS) and may include adapters for cloud storage (e.g., S3, Azure Blob) or edge devices. Deployment and Runtime Environments Most connectors are designed to run in containerized environments (e.g., Docker, Kubernetes) to support scalability and orchestration. This allows organizations to deploy connectors in hybrid cloud setups or edge computing scenarios. Logging and Observability Connectors include logging mechanisms for auditability and monitoring. These are essential for compliance with European regulations such as the GDPR and the Data Act, and for ensuring transparency in data transactions. 4.3.2 Dependencies and Integration Points External Registries and Catalogs: Connectors often integrate with federated data catalogs and trust registries to discover data offerings and verify participant credentials. Semantic Mapping Tools: Dependencies include tools for mapping between different data models and serialization formats (e.g., JSON-LD, RDF). Governance Frameworks: Connectors must align with governance models defined by initiatives like IDSA, Gaia-X, and DSSC, which specify participation rules, certification criteria, and compliance mechanisms. 5. Connector deployment plan The goal is to deploy and operate a set of standards-aligned data space connectors that let LUMI AIF users and customers discover, negotiate, and access external data and AI assets in a policy-compliant way, with clear governance, observability, and lifecycle management. The plan builds on D5.4’s intent to align as much as possible with relevant reference architectures and standards such as IDS/GaiaX/DSSC, to prioritize high-value European data spaces, and to maintain connectors as first-class components of the LUMI AIF platform. 5.1 Establishing Preliminary Agreements for Data Space Connectors in LUMI AIF A foundational requirement for deploying data space connectors within the LUMI AI Factory is the establishment of preliminary agreements that define the principles of access and use. These agreements serve as the legal, ethical, and technical scaffolding upon which trusted data exchange can occur.
D5.4 Connectors for Common European Data Spaces 25 Without them, connectors risk becoming mere technical conduits, lacking the governance mechanisms necessary to ensure responsible and compliant data and model usage. 5.1.1 Purpose and Scope of Preliminary Agreements Preliminary agreements are not merely formalities; they are operational instruments that: • Define licensing terms for datasets and models, including permissible use cases, redistribution rights, and attribution requirements. • Embed ethical guidelines, such as restrictions on sensitive data processing, bias mitigation obligations, and transparency expectations. • Specify technical constraints, including data format standards, access protocols, and resource usage limits. These agreements must be adaptable to the evolving nature of AI development and data governance, particularly in a federated and multi-stakeholder environment like LUMI AIF. 5.1.2 Requirements for Agreement Design To be effective, preliminary agreements should meet the following criteria: Requirement Description Modularity Agreements should be composed of reusable clauses that can be tailored to specific connectors or use cases. Machinereadability Terms must be encoded in a format that connectors can interpret and enforce automatically. Policy versioning Agreements should support version control to track changes and ensure backward compatibility. Interoperability Agreements must align with European and international standards (e.g., Gaia-X, EOSC, IDSA). Auditability Usage conditions and enforcement actions should be logged for compliance verification. 5.1.3 Implementation Steps for LUMI AIF To establish these agreements within LUMI AI Factory, the following process is recommended: 1. Stakeholder Mapping Identify data providers, model developers, service operators, and end-users. Clarify their roles and responsibilities. 2. Template Development Create agreement templates based on existing frameworks (e.g., IDSA Usage Policies, EOSC Rules of Participation). 3. Legal and Ethical Review Engage legal and ethics experts to validate the templates against applicable regulations (e.g., GDPR, AI Act).