DBT Smart Data
The Department for Business and Trade is drafting a cross-sector Smart Data Guidebook — a Preamble plus five chapters — that will shape how every UK Smart Data scheme (open banking, open energy, property) is expected to operate under the Data (Use and Access) Act 2025. This section tracks each document as DBT circulates it, and — the reason the section exists — works out which of its asks the SPDTF scheme draft may need to address.
Why this matters to OPDA
The Guidebook is advisory today. It says of itself that schemes "may, over time, be expected to align with its principles more formally". That is soft law hardening: what is not contested now becomes a de facto requirement later.
OPDA is not a bystander. Its Chair sits on DBT's Smart Data Council and chairs the Smart Property Data delivery group within DPMSG. OPDA is on the review distribution for every chapter. And the Guidebook names us: the Preamble's source wording cites Open Property and the bare “PDTF” (source wording) as a Smart Data initiative, Chapter 2 puts a hard "must" on the property sector over Property ID governance, and the Chapter 2 liability scoping paper names "property–finance: digital property packs for home buying" as the first of only two use cases it will examine in detail.
Chapter 5 — review and input by Friday 24 July 2026. DBT is also running a Call for Evidence on Chapter 5 (research, standards, frameworks or reports it should consider). See Ch.5 — Security, risk & fraud.
The distinction the Guidebook does not make
Every chapter addresses its asks to "schemes" and "participants", and never separates two very different kinds of obligation:
| Obligation on a… | Means | Example from the Guidebook |
|---|---|---|
| scheme operator | something an organisation must do at runtime | Run FAPI-grade APIs; authenticate participants; operate incident response; publish a dashboard |
| data standard | something a vocabulary must be able to say | Encode a consent grant, a delegated-authority chain, an accreditation status, the provenance of a computed output |
The PDTF schema is the existing Digital Property Pack schema. SPDTF is a scheme, so conflating a data standard with a scheme operator either overstates OPDA's obligations (implying SPDTF must ship a security stack) or understates them (implying consent is "just UX, not our problem"). Both readings are wrong. Holding the two apart, ask by ask, is what the overlap analysis does — and it is the only thing in this section that DBT has not already written for us.
DBT's Smart Data is a cross-sector government programme under the Data (Use and Access) Act. The PDTF schema is the existing Digital Property Pack schema. SPDTF is the first property scheme draft being authored collaboratively across industry and stakeholders. They are not two views of one thing, and SPDTF is not bound by the Guidebook — it does not "conform" to it and cannot "fail" it.
The relationship is conditional: if and when property becomes a designated Smart Data scheme, SPDTF participants would need to decide how to address certain things the Guidebook assumes, using the PDTF schema and its separately derived ontology as evidence. Everything in this section is therefore framed as a capability question, never as non-compliance. Read the gap register in that light.
OPDA has also taken on an internal, prospective role in property accreditation criteria and 'scheme' standards. No property Smart Data scheme has been designated and this work does not confer government approval or statutory scheme-body status. So Chapters 1 and 2 land on OPDA at both analytical layers. The separation above is an analytical device to be applied per ask — not a blanket "we're only a standard" defence.
The corpus
All 30 files (9 rendered to PDF for in-site reading, originals retained as
.docx) are archived under
source/02-policy-and-positioning/dbt-smart-data-guidebook/.
Every draft version is kept, not just the latest — the drift between drafts is itself
evidence of where DBT's position is unsettled (Chapter 1 is on its seventh draft; Chapter 2
its fifth).
| Document | Latest draft | Status |
|---|---|---|
| Preamble — Introductory principles and good practice | V5 | 10 principles · 8 risk categories |
| Ch.1 — Digital Identity, Roles and Trust Frameworks | V7 | Deepest overlap with existing OPDA evidence |
| Ch.2 — Governance, Compliance and Legal Framework | V5 | + liability scoping paper |
| Ch.3 — User Lifecycle and Experience | V1 | + Which? consumer response |
| Ch.4 — Data Stewardship, Privacy and Ethics | V2 | Richest modelling obligations |
| Ch.5 — Security, Risk and Fraud Management | V1 | Review due 24 Jul 2026 |
The shared chapter template
Chapters 1–5 all follow the same six-part spine, which makes them directly comparable — and makes it easy to see which section of each chapter carries the data-modelling weight (usually §3 Design principles and §6 Model text):
- Introduction and scope — terminology, problem statement.
- Legislative context — DUA Act 2025, UK GDPR/DPA 2018, the DVS Trust Framework.
- Design principles — the normative core: what schemes should decide and do.
- Sector comparisons — Open Banking, Energy, Property; then international.
- Interoperability considerations — what breaks when schemes meet.
- Model text / template — non-prescriptive draft clauses. Watch these. They are the only text concrete enough to become scheme regulation.
The Preamble is the exception — it carries the cross-cutting principles, the risk taxonomy, and the rules by which DBT governs the Guidebook itself.
Explore this section
What the Guidebook could mean for SPDTF
The layer separation applied ask by ask across all six documents — including where an ask creates no data-modelling obligation at all.
Gap register
What the PDTF schema and separate schema-derived ontology do not currently encode, and what SPDTF may need to model; ontology claims are checked against the committed TTL corpus.
Preamble
Ten cross-cutting principles, an eight-category risk taxonomy, and how DBT governs the Guidebook.
Ch.1 — Identity, roles & trust
Minimum Viable Identity, the six-stage lifecycle, trust registries, and the role-model collision with the PDTF schema and its derived ontology.
Ch.2 — Governance & legal
The five-layer governance model, the UKAS accreditation bar, and the liability question OPDA has no answer to.
Ch.3 — User lifecycle
Consent, withdrawal and delegation as a data problem, not a UI one. Plus the Which? response.
Ch.4 — Stewardship & ethics
Source vs derived data, lineage, and AI-decision disclosure — the chapter that is almost entirely ontology territory.
Ch.5 — Security, risk & fraud
Five DBT positions on security standards, continuous assurance and dynamic trust. Input due 24 July 2026.
Related
- Departments & bodies — DBT — DBT's other Smart Data workstreams (Council, Roadmap, Challenge).
- Data security framework — separately published security controls produced alongside the PDTF schema. Chapter 5 sits alongside this, not above it.
- Legislation & policy — the Data (Use and Access) Act 2025.
- Meetings & decisions — the Guidebook working sessions.
Comments
Loading comments…
Sign in to post a comment