Blockchain technology enables immutable and decentralized data management and has been widely adopted across industries. However limited attention has been given to the design phase of blockchain oriented software engineering. This paper proposes a blockchain integrated Software Development Life Cycle (SDLC) framework with a focus on healthcare systems handling sensitive patient data. Emphasizing security and privacy by design (PbD) principles the framework embeds protective mechanisms from the early design stage. The results highlight that integrating security and privacy throughout the SDLC enhances the robustness, reliability, and trustworthiness of blockchain-based healthcare applications.
Agricultural data governance faces a persistent dual challenge: low and uneven adoption of FAIR (Findable, Accessible, Interoperable, Reusable) data principles, and systemic trust deficits between farming communities and the broader agri-data ecosystem. Empirical audits of European data repositories reveal that fewer than half achieve compliance with most FAIR facets, with provenance documentation and domain-relevant community standards recording zero compliance across sampled repositories. Concurrently, research on Irish agricultural stakeholders shows that data sharing is experienced as a contested, power-laden process defined by ownership ambiguity, surveillance risk, and the structural absence of trusted intermediaries. Despite these convergent findings, the operational interdependence of FAIR and trust in agri-data governance remains empirically unmapped. This paper applies a Design Science Research (DSR) methodology to construct and iteratively refine the Trust-FAIR Nexus Method - a governance artefact that makes this interdependence explicit. Two empirical techniques are embedded within the DSR cycle: a structured survey of Irish farmers measuring trust perceptions and awareness of FAIR-aligned practices, and semistructured interviews with agri-tech stakeholders across Ireland, Greece, and Sweden, analyzed thematically to surface Trust-FAIR enablers and barriers. Findings indicate that FAIR principles operationalise specific trust dimensions in empirically traceable ways - and that trust functions as a structural precondition for meaningful FAIR adoption in practice. This paper presents the core empirical findings towards the first empirically grounded mapping of FAIR principles to trust dimensions in the agri-data context, with emerging implications for agri-data space design, governance policy, and digital farming infrastructure.
This review examines the legal, voluntary, and technical mechanisms that govern the ownership of nonpersonal agricultural data generated by IoT-enabled farm machinery, sensors, and related systems. Given that this data is not subject to personal data protection legislation such as General Data Protection Regulation (GDPR), its governance presents distinct challenges requiring alternative governance approaches. Drawing on 63 peer-reviewed studies published over the last decade, this review proposes an integrated conceptual framework comprising legal enforcement, voluntary governance, and technical enforcement mechanisms. A distinctive contribution of the study is to show that data ownership in agriculture becomes meaningful at the moment of data sharing, where rights claims are made visible, contested, or constrained, and that these three governance pathways must be understood jointly rather than in isolation. The analysis demonstrates that although farmers generate vast quantities of nonpersonal data, no existing legal framework explicitly grants them ownership, leaving ownership to be ambiguously allocated or de facto transferred through contracts in ways that limit their ability to contest access or downstream use. Technical mechanisms promise automated enforcement and accountability but risk codifying existing power asymmetries when the encoded rules reflect opaque or exclusionary terms. We argue for a shift from “ownership” to “data sovereignty” understood as the sustained capacity to define, monitor, and revoke conditions of data use. Achieving this requires three interlinked pillars: enforceable baseline access and use rights for farmers, accessible and preferably open-source technical infrastructure, and participatory governance arrangements.
This paper examines how technical architecture enables data sovereignty over shared data, in commercial platforms, with a focus on the critical challenges posed by Internet of Things (IoT) data flows. Analysing four EU-based platforms (TomTom, Dawex, Skywise, Nallian) from the European Commission's 2018 study on business data sharing, we investigate how technical mechanisms operationalise sovereignty where contractual governance faces limitations of scale, speed, and complexity. Through cross-case analysis applying Lawrence Lessig's “Code is Law” framework, we identify distinct architectural enforcement patterns across the platforms. TomTom's API-centric model achieves preemptive control by terminating misuse in milliseconds, enabling real-time intervention. Dawex's blockchain-backed policy engine enables dynamic governance, translating licensing terms into executable cross-border constraints. Skywise's access silos structurally contain data usage, making unintended reuse architecturally implausible through purpose-bound design. Nallian's rights-granting engine delivers granular sovereignty, enabling field-level control. From these findings, we develop a four-mode Architectural Sovereignty Framework, conceptualizing enforcement mechanisms along two dimensions: timing (real-time vs. ex-post) and resolution (macro-level structural vs. micro-level granular). The framework identifies Preemptive, Adaptive, Structural, and Granular sovereignty as distinct modes through which code operationalises control in IoT data sharing contexts.
This study examines AI-driven solutions for agricultural data interoperability through a combined empirical–theoretical approach, integrating stakeholder input with peer-reviewed research comprising two stakeholder workshops, one involving 28 participants and another involving 50 participants (encompassing agri-tech, farming professionals, policymakers, researchers, professors and industry experts), alongside a literature review of 50 peer-reviewed publications. The workshop revealed that structural incompatibility, semantic mismatches, and reliance on manual processes are major operational bottlenecks. Using thematic analysis of workshop discussions and literature synthesis, we identify five critical interoperability stages: Data Ingestion, Standardization, Ontology Alignment, Integration, and Access/Sharing. By systematically reviewing literature, we identified AI techniques, such as anomaly detection, semantic mapping, and rule-based automation, that directly address these stakeholder-validated challenges, forming the foundation of a sequential AI-driven framework. Findings highlight the need for adaptive AI tools to automate processes like schema alignment and ontology mapping, to reduce preprocessing time. This work bridges theoretical frameworks with practical needs, offering actionable insights for scalable smart farming solutions.
As artificial intelligence (AI) systems become increasingly prevalent across diverse industries, robust compliance frameworks are essential to ensure responsible and ethical AI development and deployment. The European Union's proposed AI Act seeks to provide a harmonized regulatory framework for AI systems, emphasizing transparency, accountability, safety, and human oversight. In this paper, we introduce an automated compliance evaluation method that aligns with the AI Act's requirements for real-world AI systems. Our approach leverages natural language processing (NLP) techniques to extract compliance-related information from system documentation and compare it against the AI Act's provisions. The resulting data is then integrated into a compliance knowledge graph, which facilitates the automated detection of potential gaps and the generation of compliance reports. By harnessing novel tools and technologies, this architecture streamlines the compliance evaluation process, reduces manual workloads, and supports ongoing compliance monitoring for AI systems.
Medical data sharing offers clinical organizations a more comprehensive view of patient medical histories, ultimately improving patient care. Integrating access control into healthcare systems further enhances data security and privacy by empowering individuals through a Dynamic Consent Management System (DCMS). However, issues such as unauthorized access and misuse of personal records often remain unaddressed by privacy legislation alone. Although regulations like the EU's General Data Protection Regulation (GDPR) mandate informed consent, ambiguities in these rules can make compliance challenging. In response, this paper proposes a Privacy-by-Design (PbD) enabled DCMS aimed at granting data subjects (DS) greater control over their information. The proof-of-concept solution is a user-friendly, web-based platform that illustrates the interactions among key stakeholders (data subjects, data requesters, and data controllers), details consent policies, and demonstrates privacy-by-design principles. Users can customize their level of consent at any time, choosing to grant, revoke, enable, or disable permissions as needed. A brief case study, design results, and comparative analyses are presented to demonstrate the system's efficacy. By leveraging PbD, this solution seeks to address critical gaps in data privacy and ensure regulatory compliance.
Electronic health record transmission and storage involve sensitive information, requiring robust security measures to ensure access is limited to authorized personnel. In the existing state of the art, there is a growing need for efficient access control approaches for the secure accessibility of patient health data by sustainable electronic health records. Locking medical data in a healthcare center forms information isolation; thus, setting up healthcare data exchange platforms is a driving force behind electronic healthcare centers. The healthcare entities access rights like subject, controller, and requester are defined and regulated by access control policies as defined by the General Data Protection Regulation (GDPR). In this work, we have introduced a blend of policy-based access control (PBAC) system backed by blockchain technology, where smart contracts govern the intrinsic part of security and privacy. As a result, any Subject can know at any time who currently has the right to access his data. The PBAC grants access to electronic health records based on predefined policies. Our proposed PBAC approach employs policies in which the subject, controller, and requester can grant access, revoke access, and check logs and actions made in a particular healthcare system. Smart contracts dynamically enforce access control policies and manage access permissions, ensuring that sensitive data is available only to authorized users. Delineating the proposed access control system and comparing it to other systems demonstrates that our approach is more adaptable to various healthcare data protection scenarios where there is a need to share sensitive data simultaneously and a robust need to safeguard the rights of the involved entities.
The agricultural sector is becoming more digitalised, where data is crucial for decision-making to improve food security and sustainability. Thus, making successful decisions dependent on high data quality (DQ). However, the quality of agricultural data (agri-data) faces numerous challenges that stem from the complex interaction between social and technical approaches. This study presents an integrated socio-technical view of challenges affecting the quality of agri-data. We identified the following social challenges: (1) digital and data literacy limitations; (2) trust and data sharing, (3) knowledge and cultural resistance, (4) organisational challenges; and technical challenges: (5) systems interoperability and integration, (6) infrastructure and scalability, (7) temporal and spatial data validation complexity, (8) data heterogeneity and standardisation, (9) data sovereignty. The findings reveal that socio-technical challenges are interconnected. In order to create effective solutions, it is required to address DQ of agri-data through a holistic view that considers people, organisational and technical aspects equally, with regard to their data collection, validation, sharing and use. This integrated perspective offers valuable insights for researchers, policymakers and technology providers working to enhance the DQ and trustworthiness of data ecosystems in agriculture.
Cinzia Cappiello合作论文数Polytechnic University of Milan,Department of Electronics, Information and Bioengineering5