Strengthening Community-Led Data Governance: Reflections from CoRE Stack’s Community of Practice
Sep 2026
As the CoRE Stack ecosystem grows, so does the importance of ensuring that data generated with and by communities is governed responsibly. Community resource mapping, natural resource management (NRM) demands, planning information and Detailed Project Reports (DPRs) can strengthen local planning and decision-making—but this requires clear processes for how data is collected, used, shared and published.
In August 2026, the CoRE Stack Community of Practice (CoP) brought partners together for two sessions focused on community-led data governance and the CoRE Stack Data Sharing and Governance Norms. These discussions built on the 11th CoP session held on 31 July 2026, which explored practical questions around community consent, personal information, data publication and accountability.
The discussions have culminated in the adoption of the CoRE Stack Partner Data Governance & Data Sharing Agreement, providing partners with a shared framework for responsible data governance across the CoRE Stack ecosystem.
A shared commitment to community-led data governance
The adopted framework recognises that data generated through community processes is not simply a technical resource. It is created through the participation of communities and must therefore be governed in ways that respect community decision-making and rights.
The agreement is guided by six principles:
- Community first: Community-generated data should serve the interests of the communities from whom it is collected.
- Transparency: Communities should understand what data is being collected, why it is collected, how it may be used and who may access it.
- Purpose limitation: Data should be used for the purposes communicated to the community, unless additional consent or another lawful basis applies.
- Privacy by design: Privacy considerations should be incorporated into digital tools, workflows and publication processes.
- Accountability: Organisations participating in the CoRE Stack ecosystem share responsibility for responsible data governance.
- Open by default for non-personal data: Where appropriate, non-personal data can be made openly available for research, planning and public benefit.
Together, these principles establish a common basis for partners to make decisions about data while recognising that different types of information require different levels of access and protection.
Clarifying ownership, stewardship and technical custody
One important outcome of the CoP discussions was the need to distinguish clearly between data ownership, stewardship and technical custody.
Under the adopted framework, communities, represented through the Gram Sabha or another locally recognised institution, retain decision-making authority over the sharing and publication of community-generated primary data. Implementation partners are responsible for obtaining informed consent, maintaining supporting documentation and ensuring that communities understand how their data will be used.
CommonsTech Foundation, as the technical custodian of the CoRE Stack infrastructure, is responsible for maintaining the platform, security safeguards and backups, and for implementing decisions taken in accordance with the governance framework.
This distinction is fundamental: technical custody does not imply ownership of community-generated data.
Making consent part of the data journey
The agreement establishes consent as an ongoing part of the data lifecycle rather than a one-time administrative requirement.
The Community Consent Workflow begins with the Landscape Steward explaining the purpose of data collection, the types of information being collected, intended uses, community rights and possible sharing or publication. Consent is then recorded before resource mapping and related data collection activities begin.
The broader process follows:
Community awareness → Consent → Resource mapping and DPR preparation → Community review and prioritisation → Publication or sharing → Periodic review
The framework also allows consent and data-sharing permissions to be reviewed when circumstances change—for example, at the beginning of a new project phase, when the intended use of data changes, or through periodic review. Communities can also request modification or withdrawal of previously granted permissions through the implementation partner, subject to the applicable governance and legal requirements.
This approach ensures that consent remains connected to how data is used over time.
Building an evidence trail for community decisions
The CoP discussions also highlighted the importance of maintaining evidence of community decisions.
The adopted framework recognises different forms of documentation, including digital consent, Gram Sabha resolutions, approved DPRs, signed consent forms and other locally accepted records.
Commons Connect can support this process by enabling partners to:
- record community consent before resource mapping;
- upload community-approved DPRs;
- upload photographs or other records of Gram Sabha meetings where plans were reviewed and approved; and
- maintain relevant consent and approval records alongside planning information.
Maintaining this evidence helps establish a clear link between community decision-making and subsequent use or publication of the information.
A differentiated approach to data sharing
The agreement distinguishes between primary community data, secondary data, derived data and personal data, recognising that each category requires different governance considerations.
Primary community data, such as resource mapping, NRM demands, DPRs and Gram Sabha resolutions, is governed by community permissions and the applicable access arrangements.
Secondary datasets, including government and open datasets relating to rainfall, land use and land cover, watersheds, MGNREGA assets, soil and aquifers, are subject to the licences and conditions governing their use.
Derived outputs, such as dashboards, analytics, reports, landscape indicators and maps, may be shared where they do not disclose personal information or restricted community data and where the permissions applicable to the underlying data allow such use.
This approach seeks to balance the value of open data with community control and responsible data use.
Protecting personal information
Responsible data governance also requires careful consideration of personal information.
The adopted norms provide that detailed personal information, such as phone numbers and Khasra numbers, should not be publicly disclosed through CoRE Stack outputs. Where identifying information such as names is retained for legitimate purposes, its use and publication must be considered in the context of transparency, community permissions and applicable requirements.
The framework also recognises the importance of complying with applicable data protection requirements, including the Digital Personal Data Protection Act, 2023, where applicable.
The objective is therefore not simply to determine whether information can be published, but to consider what information is necessary for transparency and what should remain protected.
Extending consent to Landscape Stewards
The governance framework also covers the individuals who collect and facilitate data through CoRE Stack.
The Steward Consent Workflow provides for consent during steward registration, secure recording of that consent and publication only of information for which the Landscape Steward has agreed. Stewards can subsequently request review, modification or withdrawal of their consent, subject to applicable processes.
This is particularly relevant where steward profiles include photographs, educational background, skills or contact information.
From shared discussions to an adopted framework
The adoption of the CoRE Stack Partner Data Governance & Data Sharing Agreement marks an important step in establishing a common approach to data governance across the partner ecosystem.
The agreement is supported by four practical annexures:
- Annexure 1 – Community Consent Workflow
- Annexure 2 – Community Consent Form
- Annexure 3 – Steward Consent Workflow
- Annexure 4 – Data Sharing & Access Matrix
Together, these provide partners with both the principles and practical mechanisms needed to implement responsible data governance in field programmes and digital workflows.
For a community-led digital public infrastructure such as CoRE Stack, data governance is inseparable from how technology is used in communities. The adoption of this framework reflects a shared commitment among partners to ensure that communities understand their rights, participate meaningfully in decisions about their data, and that organisations have clear responsibilities for its responsible use and sharing.