UNESCO Data Governance Toolkit

AI governance is data governance applied to a specific kind of system. 4Ps that are useful to think with: Purpose, Principles, People and processes, Practices.

This is the position advanced by the UNESCO Broadband Commission's Data Governance Toolkit (July 2025), which synthesises benchmarking research by Sara Marcucci et al. at The Governance Lab (2023).

The four-part approach, Purpose, Principles, People and processes, Practices, is useful as it provides you a model to think through your data governance.

If you cannot say why you are collecting the data, which principles govern its use, who is accountable, and what practices apply across its lifecycle, you do not have data (AI) governance. You have a model deployment.

Two extensions I would add, based on my perspective as an anthropologist and operational AI Officer working with Swiss organisations at the intersection of revDSG, EU AI Act, GDPR, and Article 321 professional secrecy:

First, a Data Diagnostic stage between Purpose and Principles. Before Principles can tell you which obligations apply, you need to answer three questions with precision: what data do we actually hold, what sensitivity category does it fall into, and what changes if it crosses a jurisdiction. That answer determines which Principles path you are on: compliance, where law sets the floor, or ethics, where you set it. Most organisations skip this. They cannot say what the vendor will access. They assume internal data is fine. They have no inventory. Then Principles becomes theoretical.

Second, and most importantly, a fork under Principles. Compliance and ethics are not one stage. This is the difference between legal and ethical AI. Compliance work is set by law: GDPR, EU AI Act, revDSG, sector-specific regulations. Ethics work begins where law stops: vendor trust, sustainability implications, dependency risks, organisational guidelines. Most implementations treat Principles as a single question and end up either compliance-conscious but ethically thin, or ethically ambitious but legally exposed.

The approach in five stages:

- Purpose: Why are we collecting this data, and what outcome are we targeting?
- Data Diagnostic: What data do we actually hold, how sensitive is it, and whose jurisdiction covers it?
- Principles: Which rules govern its use? Compliance where law sets the floor, ethics where you set it.
- People & Processes: Who is accountable, and what happens when something goes wrong?
- Practices: Are our policies, routines, and technical systems actually aligned?


#AIGovernance #EUAIAct #AIEthics #ResponsibleAI #UNESCO

https://www.linkedin.com/posts/tjftrojer_unesco-data-governance-in-the-digital-age-ugcPost-7478131601823076352-JhVz/?rcm=ACoAAASR4OoBVSrqLiAkMowmFRkidHk4zKQ1LYQ