UTC --:--:--
The Sustainability Register · Research

Research data governance

The governance charter for a consent-based research programme built from de-identified operational outcomes contributed by participating tenants. It governs if, how and when any data becomes a research release.

01
The charter

What this document governs

This is the governance charter for Goable's consent-based research programme: a programme built from de-identified operational outcomes contributed by participating tenants. It sets out who decides if, how and when operational data becomes a research release, and the controls every release must pass first.

It is a framework of commitments, not a record of audited fact. The roles and processes below are the programme's stated policy. Where something does not exist yet, this page says so plainly rather than implying a maturity the programme has not reached.

The governing rule

Nothing becomes a research release until consent, minimisation, disclosure control and committee approval have each been met.

02
Roles

Controller, processor, and the research dataset

The role split depends on the data context. For operational and analytics data the tenant is the controller and Goable is its processor. For a research release, the position is stated as policy, not asserted as a settled legal conclusion.

ContextControllerProcessor
Operational dataTenant (controller)Goable (processor)
Tenant analyticsTenant (controller)Goable (processor)
De-identified research datasetGoable (stated position)Not applicable
03
Purposes, separated

Four distinct purposes, one release path

Service delivery, model calibration, tenant analytics and research are distinct purposes with distinct legal bases. Operational audit records stay tenant-scoped; only eligible, consented and de-identified derivatives can ever enter a research release.

PurposeCan feed a public release?
Service deliveryNo. Stays tenant-scoped.
Model calibrationNo. Internal to model quality.
Tenant analyticsNo. Visible only to that tenant.
Research releaseYes, only when consent and disclosure-control thresholds are met.
04
Consent

Opt-in by default off, and revocable

1

Default off

research_consent defaults false on every tenant. By default, no operational record is a research candidate.

2

Tenant opts in

Only the tenant, as controller of its operational data, can set research_consent to true. Goable does not set it on a tenant's behalf.

3

Eligible rows become candidates

From opt-in onward, consented and de-identified eligible outcomes become candidates for a future release, subject to every downstream control.

4

Revocation

The tenant can revoke at any time. Revocation stops future candidacy and removes rows not yet released. It cannot always recall an anonymous aggregate already published in a versioned release, and we say so plainly.

The honest limit sits in the last step: revocation reaches future candidacy and unreleased rows, but an anonymous aggregate already published in a versioned release cannot always be recalled.

05
Minimisation

What an eligible outcome is, and is not

An eligible outcome is a consented, de-identified session outcome. The minimisation schema strips identifying and commercial detail at the tenant boundary, so only a generalised derivative can leave it.

Dropped at the boundary
  • Exact coordinates, generalised to a grid cell
  • Precise timestamps, reduced to a coarse period
  • Operator and business identity
  • Customer identity and any personal data
  • Free-text notes and attachments
  • Exact prices and commercial demand
  • Raw provider payloads
Retained in an eligible outcome
  • Generalised grid cell
  • Activity family
  • Coarse time bucket
  • Forecast summary that preceded the decision
  • Ran or cancelled outcome
  • Declared equipment category, where supplied
Illustrative eligible outcome, after minimisation
{
"grid_cell": "1km:31TDG76",
"activity_family": "marine",
"period": "2026-Q1",
"forecast": {
"suitability": 0.62,
"horizon_h": 24
},
"outcome": "ran",
"equipment_declared": "electric",
"contributors_in_cell": 14
}

Illustrative shape only. Values are placeholders to show the structure, not a real record.

06
Disclosure control

Documented controls, assessed per release

The measures below are disclosure-control controls applied before a release, not a claim that released data is unconditionally anonymous. Each release is assessed on its own residual re-identification risk; the programme does not treat any dataset as automatically out of scope.

De-identification controls
1 km² grid

Coordinates are generalised to a grid before release; no exact spot is disclosed.

k ≥ 10

Minimum distinct contributors behind any released cell; cells below threshold are suppressed.

90-day lag

Releases trail real time so no live commercial signal is exposed.

Per release

Each release carries a documented residual re-identification risk assessment before publication.

These controls reduce re-identification risk; they do not guarantee anonymity by default. The residual risk assessment is documented per release and reviewed before publication.

07
Standing policy

Retention, DSAR and the standing commitments

The commitments below are stated as policy and documented in detail in the data processing agreement. Where a precise figure would depend on the data category, this page points to that document rather than asserting a single number.

08
Data access committee

Who decides what may be released

The programme's data access committee reviews and approves what may be released. It is a governance body defined by this charter; its membership is not published on this page. Its remit is fixed below.

Approve releases

No dataset is published until the committee has reviewed and approved it against the consent and disclosure-control thresholds.

Review re-identification risk

The committee reviews each per-release residual risk assessment and can require additional generalisation, higher thresholds or suppression.

Manage conflicts of interest

Members declare interests; anyone conflicted on a given release recuses from that decision.

Approve publications

Papers and derived analyses built on a release are reviewed before submission.

Handle errata and retractions

The committee manages corrections, errata and, where necessary, retraction of a release or a finding.

09
Release and publication

When a release is permitted, and its status today

A public release is permitted only when consent, sample-size and disclosure-control thresholds are met and the data access committee has approved it. Each release is versioned and carries a DOI so it can be cited and corrected.

Status: no public release yet

The first release has not been published. When it is, each release will carry a version and a DOI.

Until the first dataset meets the stated consent, sample-size and disclosure-control thresholds and is approved for release, there is no dataset to cite, and this page carries no DOI to link. We say so plainly rather than imply otherwise.