By Magdalena Gad-Nowak (Timelex)
The increasing use of data-driven technologies in healthcare research has transformed data governance from a peripheral compliance topic into a central operational challenge for research consortia across Europe. This is particularly visible in Horizon Europe projects operating at the intersection of health, artificial intelligence, diagnostics, clinical research and digital innovation.
One example is the Horizon Europe ONCOSCREEN project, which aims to develop a European “shield” against colorectal cancer through more precise, affordable and risk-based screening methods. The project combines novel diagnostic technologies, AI-supported analytical tools, behavioural and socio-economic data, mobile health applications and decision-support environments to enable earlier and more personalised colorectal cancer screening and prevention strategies.
The ONCOSCREEN ecosystem integrates multiple types of retrospective and prospective data, including clinical, behavioural, environmental and lifestyle information, while involving a large multi-partner consortium composed of clinical sites, universities, technical partners, public authorities, patient organisations, scientific societies and supporting organisations across Europe.
The project further combines several interconnected digital, AI-enabled and data-intensive components supporting different stages of the colorectal cancer screening and prevention pathway. These range from novel screening technologies and risk stratification tools to AI-assisted analytics, patient-facing applications, data integration environments and decision-support tools for healthcare planning and policy-making. Together, they create a highly interconnected ecosystem that spans prevention, early detection, data analysis and population-level screening optimisation. Further information about the ONCOSCREEN project, its objectives, technologies and clinical validation activities is available on the ONCOSCREEN website.
Such projects frequently involve large-scale processing of sensitive health data, integration of heterogeneous datasets, cross-border collaboration between multiple organisations, and increasingly complex digital and analytical infrastructures. At the same time, they are expected to comply with increasingly demanding requirements relating not only to data protection and cybersecurity, but also to research ethics, AI governance, interoperability, open science, transparency and responsible innovation.
In practice, however, data governance in collaborative EU research projects is still frequently underestimated. Governance activities are sometimes still perceived primarily as administrative obligations linked to project deliverables, ethical approvals or regulatory compliance documentation. Yet the operational reality of large collaborative research projects demonstrates that governance rapidly becomes an ongoing and evolving process extending throughout the project lifecycle.
Drawing on practical experience from Horizon Europe health research projects, including ONCOSCREEN, this article explores some of the key governance challenges emerging in collaborative research ecosystems and explains why governance documentation should not be treated as a static compliance exercise.
Beyond “paper compliance”
Many Horizon Europe projects begin with a strong scientific and technical vision, but comparatively limited reflection on the operational complexity of data governance. During proposal preparation, governance considerations are often reduced to ethics requirements, informed consent procedures and the future preparation of a Data Management Plan (DMP). While these elements are undoubtedly important, they represent only the beginning of governance work rather than its conclusion.
In practice, governance quickly evolves beyond “paper compliance”. As projects mature, consortia are required to address increasingly operational questions concerning pseudonymisation, data access, data sharing, interoperability, AI governance, allocation of responsibilities, long-term retention, secondary use and security architecture.
This evolution is particularly visible in collaborative health projects involving multiple clinical sites, technical partners, universities, SMEs and supporting organisations operating across different jurisdictions. Such projects often combine retrospective clinical datasets, newly generated research data, behavioural information, socio-economic data, environmental information and outputs generated through AI-supported analysis tools.
As a result, governance cannot realistically remain static. Data flows evolve, technical architectures become more sophisticated, additional datasets may be integrated, consortium structures may change, and new regulatory or ethical questions may emerge throughout implementation.
Consequently, governance documentation prepared during the first months of a project rarely remains sufficient in its original form until project completion.
The operational complexity of collaborative health ecosystems
The governance challenges associated with Horizon Europe health projects are closely linked to the complexity of the ecosystems themselves.
Projects involving AI-enabled diagnostics or personalised medicine frequently require the integration of heterogeneous datasets originating from multiple sources and stakeholders. These may include electronic health records, data generated through clinical studies, imaging data, laboratory results, wearable device information, behavioural data collected through mobile applications, or socio-economic and environmental datasets used for risk stratification.
From a technical perspective, such projects increasingly rely on interconnected infrastructures including data lakes, dashboards, AI models, federated environments, cloud-based systems and mobile applications. Data may travel between clinical sites, analytical tools, visualisation environments and decision-support systems through multiple layers of processing.
From a governance perspective, however, this creates a highly dynamic environment where multiple stakeholders contribute to different aspects of data collection, management, analysis and decision-making. Ensuring clear governance arrangements, effective coordination and a shared understanding of responsibilities therefore becomes just as important as addressing the underlying legal qualification of processing activities.
In many collaborative research projects, multiple partners contribute to determining the purposes and essential means of processing, even where not every partner directly accesses personal data. Clinical partners may collect and pseudonymise data, while technical partners develop analytical tools or process datasets within controlled research environments. Other partners may support governance, dissemination or ethics oversight without participating directly in operational data processing.
This creates governance structures that differ significantly from the more straightforward data processing arrangements commonly encountered in traditional commercial relationships.
Joint controllership arrangements, access management rules, data sharing procedures and governance workflows therefore become essential operational instruments rather than purely formal legal documents.
Importantly, these arrangements often need to evolve over time. Research activities may expand, additional validation studies may be introduced, new tools may be integrated into the ecosystem, and consortium composition may evolve as partners leave or join the project. Governance mechanisms must therefore remain sufficiently flexible to accommodate scientific and organisational evolution while preserving accountability and legal certainty.
The Data Management Plan as a living governance instrument
One of the most underestimated governance tools in Horizon Europe projects is the Data Management Plan (DMP). Under Horizon Europe, projects are expected to develop and maintain a DMP early in the implementation phase and update it as the project evolves, including towards project completion. This reflects a broader recognition by the European Commission that effective data governance is not a one-off compliance exercise but an ongoing process requiring continuous review and adaptation throughout the project lifecycle.
Yet DMPs are still sometimes perceived primarily as administrative deliverables prepared to satisfy funding requirements. In reality, a meaningful DMP does considerably more than list categories of datasets or storage locations. It maps how data move within the ecosystem, identifies governance responsibilities, documents applicable safeguards, addresses interoperability and FAIR data considerations, and creates a common governance framework shared across the consortium.
This governance framework cannot realistically remain static. As projects evolve, DMP updates may be required to reflect new datasets, evolving technical architectures, modifications to data flows, integration of AI functionalities, changes in consortium composition, revised access management procedures, updated retention strategies, emerging interoperability requirements, developments linked to open science obligations, or evolving security and pseudonymisation measures.
Maintaining an operationally meaningful DMP therefore often requires continuous interaction between legal experts, technical teams, clinical partners, cybersecurity specialists and project coordinators. Governance becomes inherently multidisciplinary, extending far beyond the preparation of a single project deliverable.
Moreover, the value of the DMP frequently extends beyond the project itself. In many cases, it becomes a key reference point for sustainability planning, long-term preservation strategies, future data access frameworks and post-project exploitation activities.
This longer-term perspective is becoming increasingly important in light of broader European initiatives aimed at facilitating responsible data sharing and re-use. As research projects generate valuable health datasets and analytical resources, questions relating to future access, secondary use, interoperability and data stewardship often extend well beyond the formal duration of the project. Establishing clear governance arrangements early on may therefore help organisations prepare for future data-sharing opportunities while ensuring that any re-use remains consistent with applicable legal, ethical and regulatory requirements.
This becomes even more important in the context of AI-enabled health research. Increasingly, governance documentation is not only relevant from a GDPR or research ethics perspective, but also from the perspective of emerging AI governance obligations. The EU AI Act places considerable emphasis on issues such as data governance, data quality, traceability, documentation, human oversight and risk management throughout the AI lifecycle. While Horizon Europe research projects may not always directly fall within the scope of all regulatory obligations applicable to commercial AI systems, they increasingly function as environments where future governance expectations are already being operationalised in practice.
As a result, data governance frameworks prepared during collaborative research projects may ultimately play an important role far beyond the lifespan of the project itself, including in future validation, regulatory, deployment or commercialisation phases.
DPIAs in dynamic research environments
Similar observations apply to Data Protection Impact Assessments (DPIAs).
In large-scale health research projects involving sensitive data and AI-supported analytics, DPIAs are not merely formal GDPR obligations. They are risk assessment tools intended to identify, assess and mitigate risks to the rights and freedoms of individuals arising from evolving processing activities.
This is particularly important in projects combining multiple categories of sensitive data with advanced analytical environments. Clinical data, behavioural information, wearable device outputs, socio-economic datasets and AI-generated outputs may all interact within a single research ecosystem. Such combinations can create complex risk scenarios involving identifiability, unauthorised access, profiling, excessive data collection, insufficient transparency, discrimination, security vulnerabilities or misuse of sensitive information.
Importantly, these risks do not necessarily emerge simultaneously at project launch. Many become visible progressively as data flows become more clearly defined, technical tools mature, integration between systems increases, and governance arrangements are operationalised in practice.
As projects move from proposal preparation to implementation and validation, a more detailed understanding of datasets, technical architectures, access requirements, partner responsibilities and interoperability needs begins to emerge. New risks may be identified, existing risks may evolve, and additional safeguards may become necessary.
For this reason, DPIAs should not be treated as static snapshots frozen at a single moment in time. The GDPR envisages DPIAs as living risk management instruments that should be reviewed and updated whenever changes to processing activities affect the nature or level of the associated risks. In complex and evolving research environments, this often necessitates periodic reassessment throughout the implementation phase.
This also reflects a broader shift in how accountability should be understood within collaborative research ecosystems. Accountability increasingly depends not only on identifying risks at a single point in time, but also on demonstrating ongoing oversight and the effectiveness of measures implemented to mitigate those risks throughout the project lifecycle.
In practice, insufficient governance structures may ultimately delay research activities, complicate data sharing between partners, create uncertainty around responsibilities, or significantly increase the effort required to adapt project infrastructures to evolving legal, technical or regulatory expectations. In certain cases, governance shortcomings may also expose organisations to legal and regulatory risks, particularly where they result in non-compliance with applicable requirements relating to data protection, AI governance, cybersecurity, research ethics or other sector-specific regulatory frameworks.
The growing convergence between data governance and AI governance
Another important development concerns the increasingly close interaction between data governance, technical architecture and AI governance requirements. In projects involving AI-enabled tools, decisions relating to data collection, quality, access, interoperability and oversight often have implications that extend beyond traditional data protection compliance and become relevant to the governance of the AI systems themselves.
This is particularly visible in collaborative health research projects where AI models rely on complex and heterogeneous datasets originating from multiple sources and stakeholders. Questions concerning dataset quality and provenance, traceability, human oversight, access management, auditability, interoperability and documentation are therefore no longer purely technical matters. They form part of the broader governance and accountability framework within which AI-enabled systems are designed, developed and validated.
The AI Act further reinforces this evolution by placing increasing emphasis on lifecycle governance, documentation and risk management surrounding AI-enabled systems. In practice, organisations developing or validating AI-supported tools may increasingly need to demonstrate not only technical robustness, but also governance maturity through appropriate documentation, data governance measures, traceability, accountability and human oversight.
Once technical architectures and data pipelines become operational, implementing additional governance measures or modifying existing governance arrangements may become significantly more difficult and resource-intensive. For that reason, governance considerations should ideally be integrated from the earliest phases of project design rather than addressed only after systems and processes have already been established.
The increasing importance of “privacy by design”, “security by design” and, increasingly, “governance by design” approaches reflects this growing convergence between legal, technical and AI governance considerations.
Looking ahead: increasing governance expectations
The governance challenges observed in Horizon Europe health projects are unlikely to diminish in the coming years. On the contrary, the regulatory and policy landscape surrounding health data, artificial intelligence and digital health continues to evolve at a rapid pace.
Initiatives such as the European Health Data Space (EHDS), the AI Act and an increasing emphasis on cybersecurity, interoperability and responsible innovation are likely to place even greater importance on effective governance frameworks throughout the research and innovation lifecycle. At the same time, public expectations regarding transparency, accountability and the responsible use of health data continue to grow.
For research consortia, this means that governance can no longer be viewed solely as a compliance requirement associated with a limited number of project deliverables. Increasingly, it must be embedded within the design, implementation and long-term sustainability of research activities and digital infrastructures.
Importantly, robust governance should not be viewed as an obstacle to innovation. Well-designed governance frameworks can facilitate collaboration, enable responsible data sharing, support regulatory preparedness and foster trust among project partners, research participants, healthcare professionals and the wider public.
The experience of many Horizon Europe projects demonstrates that governance is most effective when it is treated not as a separate workstream operating alongside scientific and technical activities, but as an integral component of the project ecosystem itself.
Conclusion
Collaborative Horizon Europe health projects increasingly operate in highly complex environments involving sensitive health data, advanced analytics, AI-enabled technologies and large multi-partner ecosystems. In such contexts, governance rapidly becomes more than a legal formality.
Data Management Plans, DPIAs and related governance frameworks should therefore not be viewed merely as compliance documentation prepared for regulatory or funding purposes. In practice, they often become central operational instruments supporting accountability, coordination, risk management and sustainable collaboration throughout the project lifecycle.
The experience of projects such as ONCOSCREEN demonstrates that effective governance cannot be reduced to a one-off compliance exercise completed at the beginning of a project. Rather, it is an ongoing process that must evolve alongside the data, technologies, partnerships and research activities it is intended to support.
As European research ecosystems continue moving towards greater interoperability, data sharing and AI integration, the ability to embed governance into the day-to-day operation of research and innovation activities will become increasingly important for ensuring both regulatory compliance and long-term project success.
