Data Management Plan
This document presents the Data Management Plan (DMP) for the COW project, implemented under the Internal Security Fund (ISF). It constitutes the first version of the DMP and defines the framework for managing data throughout the full lifecycle of the Action, including data collection, generation, processing, storage, sharing, and deletion.
The COW project processes heterogeneous data assets, including open-source intelligence (OSINT), network and technical datasets, derived analytical data, synthetic datasets, software artefacts, and administrative data. Due to the project’s focus on supporting law enforcement capabilities, certain datasets may contain personal data or be sensitive in nature, particularly where they could reveal investigative methods, technical capabilities, or operational approaches.
Data management is implemented through proportionate technical and organisational measures aligned with the security requirements of the Action. A common data classification framework (Public, Internal, Sensitive, Restricted) is applied across the consortium to ensure consistent handling of data. Responsibilities for data management are distributed across partners, with each partner acting as data owner for the data they generate or process, while the project coordinator ensures overall consistency and alignment with project requirements. Oversight is provided through project governance structures, including the Project Board where relevant.
Compliance with the DMP and applicable legal and regulatory requirements is supported through ongoing monitoring and review within the project governance framework. This may include internal checks, reporting mechanisms, and, where appropriate, reviews at project level to ensure that data management practices remain aligned with project objectives and regulatory obligations.
All data processing activities comply with Regulation (EU) 2016/679 (GDPR) and, where applicable, Directive (EU) 2016/680, as well as relevant national legislation. Appropriate safeguards are implemented to ensure confidentiality, integrity, availability, and accountability of data, and to mitigate risks related to unauthorised access, misuse, or unintended disclosure.
The project applies the FAIR principles (Findable, Accessible, Interoperable, Reusable) in a proportionate manner, taking into account legal, ethical, and operational constraints. FAIR principles are implemented through structured documentation, standardised formats, and controlled access mechanisms. Open access is limited to non-sensitive results, while sensitive and operational data remain restricted. Any sharing of data with external stakeholders will be subject to prior assessment, applicable legal constraints, and approval by the relevant data owners.
The DMP is a living document and will be updated throughout the project lifecycle to reflect changes in data processing activities, technical developments, and regulatory requirements. The DMP will be reviewed periodically and updated when significant changes occur.