Chapter 2 — Governance, Compliance and Legal Framework
The institutional layer: who has authority, how participants are accredited and held to account, and how sector rules meet cross-sector expectations. This is the chapter that lands on OPDA hardest — because OPDA has taken on an internal, prospective role in property scheme accreditation criteria; no property Smart Data scheme has been designated, and this does not confer government approval or statutory scheme-body status. Most asks are on OPDA the organisation, not on the PDTF schema vocabulary.
The scoping paper names "property–finance: digital property packs for home buying" as the first of only two cross-sector use cases it will examine in detail — "tests data accuracy, provenance, reliance, and redress where outcomes are legally consequential". Its stated output is template clauses. There is an unusually clear invitation here to write the property accountability map rather than receive one.
The five-layer governance model
| Layer | Governs | Who holds it for property? |
|---|---|---|
| 1. Policy | Statutory basis, scheme scope, permitted activities | Not OPDA — DBT/MHCLG. Currently undefined for property. |
| 2. Governance | Scheme rule-setting, accreditation, trust-registry oversight, liability standards | OPDA's prospective/internal role — not statutory authority. |
| 3. Implementation | Interface body operation, onboarding, conformance tooling, technical standards | OPDA's current programme work — the existing PDTF schema, separate supporting material and collaborative SPDTF development; not government approval. |
| 4. Operational | Day-to-day functioning by ATPs, data holders, issuers | OPDA's members. |
| 5. Enforcement | Investigation, sanctions, appeals | OPDA — property has no statutory Smart Data regulator. |
The chapter permits this concentration, via one sentence that is the most consequential in the document for OPDA:
"In sectors without a statutory regulator, enforcement functions may be exercised through contractual or scheme-rule mechanisms operated by the implementation authority, provided that powers, escalation routes and safeguards are clearly defined."
So OPDA may hold layers 2, 3 and 5 simultaneously — but only on that condition. Meanwhile the chapter's own prohibitions forbid "governance bodies operating without transparency or accountability", and its first design principle requires role separation "to avoid conflicts of interest".
Chapter 2 assumes a scheme where the interface body is not the trade association of the participants. OPDA is a membership organisation that now writes the standard, sets accreditation criteria, runs conformance, signs the trust registry, and enforces against non-compliant members — while being funded by those members. Every layer except policy runs through one member-funded body.
Brazil's "regulator + industry association hybrid" — which the chapter praises — works precisely because the central bank sits above the association. Property has no equivalent. OPDA should decide deliberately whether to (a) invite MHCLG/a regulator into the policy layer above it, (b) create genuine internal separation with an independent appeals function, or (c) argue proportionality. Doing none of these and hoping the carve-out holds is the weakest option — and it is better to surface this first, with a mitigation, than to have a reviewer find it.
The accreditation bar
Chapter 2 says accreditation "would be likely to cover":
Security posture · risk-based permissions · organisational and personnel checks · technical conformance · API performance · fraud controls · liability acceptance · insurance requirements · governance obligations, reporting and dispute-resolution commitments.
And equivalence "should normally be anchored in certification issued by UKAS-accredited conformity assessment bodies".
Does OPDA's conformance scheme meet this?
OPDA's scheme is a three-reviewer panel with an 80% pass mark. Measured against Chapter 2 it falls short on three distinct grounds:
- Scope. An 80% technical conformance review answers roughly one line of the list above. Liability acceptance, insurance, fraud controls and personnel checks are absent. Fixable — extend the criteria.
- Independence. Three reviewers drawn from the membership judging fellow members is peer assessment, not third-party conformity assessment. But note the word "normally" — it is the hook for a proportionality argument. Property's participant base is thousands of small conveyancers and estate agents; a UKAS-CAB audit each would be disproportionate and would breach the chapter's own SME-burden prohibition. OPDA's strongest move is to pre-empt this: publish a documented equivalence rationale explaining why peer conformance plus a signed registry is proportionate, and what it would escalate to UKAS-anchored assessment for. Do not wait to be asked.
- The 80% mark itself. A percentage pass implies up to 20% of a conformance suite may fail. For data "with legal effects" — the chapter's own words about property — that is very hard to defend. Which 20%? Consider criticality-weighted must-pass assertions instead of a flat percentage.
Accountability and liability
Chapter 2's liability text is acknowledged as inadequate; the scoping paper is the patch. Its position to be tested:
"Accountability should, in principle, follow the specific decision or processing activity being undertaken, rather than remaining with one organisation 'down the chain'."
Operationalised as: "Issuers of trust signals (e.g. accreditation status and permissions) remain accountable for their accuracy, while relying parties are accountable for executing required status and revocation checks." And, bluntly:
"Failures of governance design or operation (e.g. ineffective controls, monitoring, audit trails, oversight or escalation) can themselves be relevant to regulatory enforcement and legal exposure."
OPDA's Articles cap members' liability to the company at £1 — a standard company-limited-by-guarantee provision. It is orthogonal to the exposures the scoping paper identifies:
- OPDA as issuer. OPDA's Governance Authority signs the OPDA-internal Trust Registry. If OPDA asserts a firm is accredited when it is not — or fails to reflect a suspension "promptly across all relying parties" — the exposure is OPDA's. This is not a government designation, and the guarantee cap does nothing about it.
- OPDA as governance body. Governance-design failure is itself in the liability chain, per the quote above.
The cap survives, because it was never the relevant instrument. The real finding is that OPDA has no articulated liability position at all for either role. That silence is the risk — and the answer is probably insurance plus a stated liability position in the scheme rules, not amending the Articles. See Risk & liability.
What this could mean for SPDTF
Most of Chapter 2 is not a data-modelling problem. The data-standard residue is on the overlap page; the sharpest items:
- Signed, provenance-rich computed results retaining "issuer, inputs, methods, timestamps and purpose". A property pack is exactly this. If the pack is wrong but every source claim was right, who is accountable? The schema-derived ontology models source claims well and derived claims not at all — a question for SPDTF (gap SD4), simultaneously OPDA's largest modelling gap and its largest liability gap.
- Liability needs evidence, not a verdict. SPDTF does not necessarily need
a
liablePartyproperty — Clause D allocates liability by rule. What the scheme model must supply is what the rule operates on: who issued a signal, when, at what assurance, and whether a status check happened. Encode the evidence, not the verdict. - Property ID. The chapter uses a hard "must", aimed by name at our sector: where identifiers like Property ID "are not yet included in DVS, schemes must define interim governance and trust-anchor arrangements". There is no reading in which this is someone else's job.
Open questions this chapter raises
- Does the DUA Act even reach property? Its powers apply only to data from a trader–customer relationship, and the Act "does not provide a general power to mandate sharing of public-sector data unless those bodies act in a commercial function". Much of a property pack originates from HM Land Registry and local authorities. Large parts may sit outside DUAA powers entirely. Nobody has done this analysis publicly.
- No ombudsman for property. Open Banking escalates to the Financial Ombudsman; energy to Ofgem. A Smart-Data-specific harm (bad data in a pack) has no obvious destination. OPDA cannot fix this alone but must not stay silent on it.
- Cross-scheme revocation. If a firm is suspended in property, should it lose access in finance? Either answer is expensive. Have a view before you are given one.
- Consent is the wrong frame for property — and the chapter half-admits it ("data sharing may rely on multiple legal bases"). Property runs on contract, professional duty and statutory obligation far more than consumer consent. Its "no re-validation by data holders" rule sits badly with a conveyancer's professional duty to check. OPDA has standing to push back here.
Comments
Loading comments…
Sign in to post a comment