data placement and governance planning

Designs and documents data placement and governance architectures, policies, and operational processes that determine where data may be stored, processed, and transferred to meet legal, regulatory, and organizational residency requirements. Builds and assesses controls and mechanisms — including classification and metadata schemes, contractual and vendor controls, geo‑location or region restrictions, encryption and access policies, monitoring and audit tooling, and compliance assessment processes — to enforce residency constraints and demonstrate ongoing compliance across infrastructures and service providers.

dataplacementandgovernance

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.25
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$196K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This study addresses the challenges posed by divergent and conflicting data protection regulations across jurisdictions, which hinder the early identification of compliance requirements in software development and often lead to costly rework and legal risks. Drawing on interviews with 70 legal experts from G20 and other countries, the research employs systematic content analysis and deductive qualitative methods to distill, for the first time from a legal expert perspective, both commonalities—such as consent—and key divergences—such as the right to be forgotten—across global data protection laws. These insights are innovatively operationalized into a comprehensive set of Data Protection Officer (DPO) user stories mapped to each phase of the software development lifecycle and enterprise architecture layers, significantly enhancing the actionable integration of compliance requirements into early-stage software engineering practices.

data protection regulationsprivacy complianceregulatory data protection requirements

This study addresses the sequential decision-making challenge firms face under stringent regulatory regimes when balancing compliance costs against data value in cross-border data flows. The authors propose a regime-anchored decision support system that translates regulatory requirements into computable minimal compliance mappings and models weekly corporate decisions via a finite-horizon Markov decision process, treating compliance as a hard constraint rather than a penalty term. Innovatively integrating masked deep reinforcement learning with counterfactual path advantage analysis, the framework enables efficient optimization and interpretable decision-making while supporting transferability across jurisdictions. Experimental results demonstrate that the learned policies outperform baseline approaches, exhibit high interpretability and auditability, and uncover key behavioral patterns such as an “absorb–adjust” effect and dynamic shifts in localization boundaries.

compliance decisionscross-border data flowsdata governance

This work addresses the limitations of existing data governance tools, which struggle to dynamically adapt to emerging regulations such as India’s Digital Personal Data Protection (DPDP) Act and often lack transparency and explainability, leading to inadequate compliance. To bridge this gap, the paper introduces the first goal-driven agent framework specifically designed for data compliance. The framework integrates a KYU Agent and a Compliance Agent that jointly leverage semantic understanding, user trust modeling, and data sensitivity reasoning, embedding regulatory logic directly into the system to ensure auditable and interpretable decisions. It incorporates anonymization strategies—including masking, pseudonymization, and generalization—and demonstrates significant improvements in DPDP compliance across ten domains, including healthcare, education, and e-commerce, enabling transparent, efficient, and cross-domain adaptive data governance.

compliancedata governanceDPDP Act

Existing Web data storage platforms struggle to meet the demands of decentralized, semantically rich, and legally compliant data usage control. This work proposes a novel approach that integrates the User-Managed Access (UMA) authorization framework with the W3C Open Digital Rights Language (ODRL) policy language to replace Solid’s native access control mechanism, thereby decoupling authorization from storage. For the first time within the Solid ecosystem, this integration advances access control from mere permission management toward legally aware usage control. The authors also design a policy evaluation mechanism tailored for non-standardized semantic environments. A prototype implementation demonstrates that the proposed method maintains compatibility with Solid while enabling flexible, interoperable, and legally aligned data governance.

access controldata governancedecentralized data ecosystems

This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.

governance frameworklarge language modelsLLM systems

Latest Papers

What's happening recently
View more

In multi-stakeholder platforms, software architecture decisions often implicitly entrench conflicting requirements without systematic support for mapping governance principles to technical design. This work proposes the first governance-architecture alignment framework, explicitly linking five core governance principles to the space of architectural decisions, thereby rendering implicit governance stances identifiable and contestable. The framework also exposes how default technical choices can obscure underlying value commitments. Feasibility is preliminarily demonstrated through a constructive case study of a pig-farming knowledge platform in Rwanda. Future work will employ pre- and post-intervention user judgment studies to evaluate the framework’s impact on actual governance outcomes.

architectural decisionsgovernancemulti-stakeholder platforms

This study addresses the mismatch between temporary inter-organizational talent supply and demand, along with associated legal, ethical, and data governance risks, by proposing a privacy-preserving cross-enterprise workforce leasing framework (BWLS). Grounded in governance-by-design principles, the framework employs locally deployed connectors and a lightweight central coordination layer to enable enterprises to anonymously publish and discover skills, negotiate tasks, and record agreements. It innovatively reconceptualizes the platform as a governance-oriented digital infrastructure that integrates consent mechanisms, auditability, role-based access control, data minimization, and institutional accountability. Drawing on socio-technical governance, enterprise architecture, and privacy-by-design principles, the work yields a structured governance framework and a set of design artifacts suitable for expert review, stakeholder deliberation, prototyping, and compliance analysis, though it has not yet been empirically deployed.

data governanceinter-firm collaborationlabor market inefficiency

Current AI systems rely heavily on manual auditing and documentation, which hinders scalable governance for automated services. This work proposes Ontological Knowledge Blocks (OKBs), a novel framework that formalizes regulatory obligations as quintuples comprising ontologies, SHACL rules, evidence requirements, and provenance links. By leveraging RDF/OWL modeling, PROV-O for provenance tracking, and an intermediate representation–driven deterministic compiler, the approach enables dynamic switching of governance configurations without modifying service code. Evaluation in an AI-assisted HPC scheduling scenario demonstrates that compliance checks are configuration-sensitive, violations accumulate strictly additively, SHACL validation incurs only 12.6–100.3 milliseconds of latency, and the Combined configuration provides the most comprehensive coverage.

AI governanceautomated verificationcompliance

Hot Scholars

JZ

Jialu Zhang

Assistant Professor at University of Waterloo
Programming LanguagesSoftware EngineeringLLM for EducationAI for Education
DD

Dezun Dong

Professor, School of Computer Science, National University of Defense Technology
computer architecturehigh performance computinginterconnection networksmachine learning systems
FX

Felix Xiaozhu Lin

UVA. DO NOT TRUST GOOGLE'S PAPER LIST. Check my homepage instead.
Systems software
ZR

Zhiyuan Ren

Michigan State University
Machine LearningArtificial IntelligenceComputer Vision
AB

Afsara Benazir

Computer Science PhD student @UVa
SystemsMachine LearningOn-device learningResource Efficiency