DATUM · Technical architecture

Architecture and components of the service

A technical view of the components that form DATUM Data Space Gateway, their responsibilities and how they work together to enable governed sharing of data products.

Technical components
7
Components with unique responsibility
0
Overlaps or circular dependencies
100%
Internal governance preserved
Service components

Seven components, one coherent architecture

Each component has a unique and explicit responsibility. No overlap, no circular dependencies.

01
Foundation
DATUM Core

Internal platform for governance, DataOps and publication. Manages metadata, quality, ownership, lineage and internal data products. It is the foundation on which the Gateway operates.

02
Discovery
External catalogue

Registry of externally published assets. Contains public metadata, access conditions and available versions of each shared data product.

03
Control
Policy layer

Layer for definition, negotiation and enforcement of usage policies. Manages who can access, for what, for how long and under what restrictions.

04
Interoperability
Connector / Federated Gateway

Technical interoperability component. Implements federated sharing protocols, aligned with the Eclipse Dataspace Protocol, technically decoupling publisher and consumer.

05
Audit
Agreement and evidence registry

Immutable store of all agreements, accesses and usage conditions. Foundation of audit, compliance and real sovereignty of shared data.

06
Operations
DataOps integration

DATUM's DataOps circuit feeds the Gateway with certified assets and receives validated external assets. Integration is bidirectional and governed.

07
Consumption
Governed entry of external assets

Process of receiving, validating and assimilating external assets into DATUM. Ensures that consumed data meets internal quality and traceability standards.

The product

Technical components are not the product.

The product is the capacity to govern through them.

Responsibilities

Who manages what in the operational model

RoleResponsibility
Data OwnerAuthorises which assets may be published and under what usage conditions
Data OfficeManages the backlog of sharing initiatives and validates policy compliance
Data ArchitectDesigns the integration between DATUM Core and the Gateway, and defines the external catalogue model
Platform SMEsConfigure and operate the Gateway, the federated connector and the agreement registry
IT / SecurityManage infrastructure, federated identity and technical access to the Gateway
Data CommitteeApproves sharing policies and exceptions affecting critical or sensitive assets
Why this architecture

Five technical differentiators of the Gateway

01
Native DATUM capability, not bolt-on

The Gateway is built on the same components that govern data inside: catalog, metadata, quality, lineage. It is not an additional module with its own model.

02
Declarative policy model

Policies are expressed as usage rules, not technical permissions. This allows translating commercial contracts and regulatory obligations to applied control, not documented.

03
Structured evidence by design

Every operation —publication, consumption, policy modification— leaves trace in standardized auditable format. Traceability is system output, not later construction.

04
Standard ecosystem connectors

Compatible with Eclipse Dataspace Protocol and Data Spaces Support Centre components. No rewriting integration when the dominant standard changes.

05
Operation independent from DATUM Core

The Gateway updates, scales and evolves without touching internal operation. Changes to the federated edge do not compromise Core operation.

What this architecture delivers

Four demonstrable technical metrics

Policy coverage on published assets

Every asset in the external catalog has its usage policy applied. No orphan assets remain at the federated edge.

100% assets with policy
Evidence latency

From when the operation occurs until the evidence is available for audit. Controlled and monitorable time.

Near real-time evidence
Stable P95 operation

The Gateway responds within the agreed SLA on the 95th percentile of requests. Predictable performance for scaling.

P95 within SLA
Compatibility with European standards

Operational adherence to Eclipse Dataspace Protocol and European frameworks without overpromising unimplemented compatibilities.

Verified standards
Keep exploring

Connect with the rest of the capability

dsg.arquitectura.related.lead

Next step

Want to go deeper into how this is implemented in your organisation?