# Governance and Social Legitimacy

Principles 8–10: Community consent, regulatory stack alignment, and resilience.

# P08 — Community and Indigenous Data Consent

<div class="principle-header" id="bkmrk-scd-p08-%C2%A0%C2%B7%C2%A0-principl"><div class="principle-id">SCD-P08 · Principle 8 of 10</div><div class="principle-title">Community and Indigenous Data Consent</div><div class="principle-tagline">“CARE complements FAIR. People before data.”</div> <span class="category-badge">Governance Layer</span></div>## Definition

<div class="definition-box" id="bkmrk-for-climate-data-tha">For climate data that touches territories, resources, or knowledge of indigenous or local communities — including forests, water, biodiversity, traditional ecological knowledge, and land-use data — the CARE Principles must complement FAIR: Collective Benefit (data use benefits the community, not just the collector), Authority to Control (communities control who accesses data about their territories), Responsibility (data users are accountable to the community), and Ethics (data collection, use, and sharing align with community values and rights). Free, Prior, and Informed Consent (FPIC) is required before data collection begins.</div>## Rationale

<div class="rationale-box" id="bkmrk-in-latam%2C-most-prima">In LATAM, most primary tropical forest is on indigenous or community land (Amazon, Andean communities, Mesoamerican forests, Pacific lowlands). Sovereign climate data built without community consent is: legally contested under ILO Convention 169 and national laws; technically incomplete (traditional ecological knowledge fills critical monitoring gaps); and ethically compromised. Post-COP15, the TNFD v1.0 framework — adopted by 320+ financial institutions — makes community rights a mandatory disclosure dimension. The Global Indigenous Data Alliance's CARE Principles (2019) are the operational framework; CODATA IDW 2025 reviewed their maturity model in practice.</div>## Implementation Steps

1. Map all data collection activities against community land rights before beginning.
2. Obtain documented FPIC from affected communities before any data collection on their land.
3. Establish a data governance agreement that specifies community rights to access, correct, and withdraw consent for their data.
4. Ensure community members can access and challenge data about their territories.
5. Report on CARE compliance in the same place as FAIR compliance.

## Compliance Checklist

<table class="checklist-table" id="bkmrk-criterionwhat-it-mea"> <thead><tr><th></th><th>Criterion</th><th>What it means</th></tr></thead> <tbody><tr><td>☐</td><td>**Community land map completed**</td><td>Data activities mapped against indigenous and community land rights.</td></tr><tr><td>☐</td><td>**FPIC documented**</td><td>Free, Prior, and Informed Consent obtained and documented before data collection.</td></tr><tr><td>☐</td><td>**Data governance agreement signed**</td><td>Agreement specifies community rights and responsibilities of the collector.</td></tr><tr><td>☐</td><td>**Community access enabled**</td><td>Communities can view, challenge, and request correction of data about their land.</td></tr></tbody></table>

## Regulatory References

- ILO Convention 169 — Indigenous and Tribal Peoples (ratified by Colombia, Peru, Bolivia, Mexico)
- TNFD Framework v1.0 (2023) — Core Disclosure B (Stakeholder engagement)
- Global Indigenous Data Alliance — CARE Principles for Indigenous Data Governance (2019)
- CBD Kunming-Montreal Framework (COP15, 2022) — Target 22 (Indigenous rights)

## Recommended Tools and Platforms

<span class="tag">RAISG Indigenous Territories Map</span> <span class="tag">FAO FPIC Guidelines</span> <span class="tag">CARE Data Maturity Model</span>

## Keywords

<span class="tag tag-kw">CARE principles</span> <span class="tag tag-kw">indigenous data sovereignty</span> <span class="tag tag-kw">FPIC</span> <span class="tag tag-kw">community consent</span> <span class="tag tag-kw">TNFD</span> <span class="tag tag-kw">ILO 169</span> <span class="tag tag-kw">LATAM</span>

<div class="related" id="bkmrk-related-principles%3A-"> **Related Principles:** [SCD-P09](https://wiki.cleantechhub.net/books/sovereign-climate-data/page/pp09) · [SCD-P10](https://wiki.cleantechhub.net/books/sovereign-climate-data/page/pp10)</div><div class="meta-footer" id="bkmrk-document-id%3A-scd-p08"> **Document ID:** SCD-P08 | **Version:** 1.0.0 | **Last Updated:** 2026-05-26 | **Category:** Governance and Social Legitimacy | **Source:** CleantechHUB Sovereign Climate Data Framework | **Licence:** CC-BY 4.0   
  
 *This page is part of the [Sovereign Climate Data Wiki](https://wiki.cleantechhub.net/books/sovereign-climate-data), maintained by CleantechHUB. It is AI-legible, machine-readable, and available via the [BookStack REST API](https://wiki.cleantechhub.net/api/pages).*</div>

# P09 — Regulatory Stack Alignment

<div class="principle-header" id="bkmrk-scd-p09-%C2%A0%C2%B7%C2%A0-principl"><div class="principle-id">SCD-P09 · Principle 9 of 10</div><div class="principle-title">Regulatory Stack Alignment</div><div class="principle-tagline">“Build once, report everywhere.”</div> <span class="category-badge">Governance Layer</span></div>## Definition

<div class="definition-box" id="bkmrk-sovereign-climate-da">Sovereign climate data must be structured from inception to satisfy multiple simultaneous regulatory requirements without re-engineering. The 2026 regulatory stack includes: EU Green Claims Directive (enforcement September 2026), CBAM embedded carbon verification (fully operational January 2026), ISSB S2 mandatory disclosure (Brazil CVM, Mexico CNBV, Chile CMF — all from 2026), CSRD third-country scope (2029), Article 6 Paris Agreement carbon market rules (finalised COP29, 2025), and domestic NDC reporting requirements across LATAM.</div>## Rationale

<div class="rationale-box" id="bkmrk-organisations-that-b">Organisations that build data infrastructure aligned to only one regulatory standard face costly rebuilds as additional mandates come into force. The 2026 stack creates immediate, simultaneous exposure across multiple jurisdictions for most LATAM organisations with international operations or finance. CBAM alone creates direct financial penalties — not just reputational risk — for LATAM exporters of steel, cement, aluminium, fertilizers, and hydrogen who cannot verify embedded carbon. Article 6 rules (COP29, Belém 2025) mean sovereign data is now a prerequisite for participating in international carbon markets.</div>## Implementation Steps

1. Audit your regulatory exposure: which of the 2026 stack applies to your organisation?
2. Map each regulatory requirement to specific data fields (see Regulatory Mapping Table below).
3. Design data collection to capture all required fields from the start — not retrofit.
4. Use ISSB S2 as the baseline (it has the broadest adoption) and layer CBAM and GCD requirements on top.
5. Review the stack annually: add new requirements as they come into force.

## Regulatory Mapping Table — 2026 Stack

<table class="reg-table" id="bkmrk-regulationjurisdicti"> <thead><tr><th>Regulation</th><th>Jurisdiction</th><th>In Force</th><th>Key Data Requirement</th><th>Penalty</th></tr></thead> <tbody><tr><td>EU Green Claims Directive 2024/825</td><td>EU (affects global exporters)</td><td>Sept 2026</td><td>Substantiation of all environmental claims with verifiable evidence</td><td>Up to 4% annual turnover</td></tr><tr><td>CBAM (EU 2023/956)</td><td>EU imports — global exporters</td><td>Jan 2026 (full)</td><td>Embedded GHG per tonne for 6 product categories</td><td>Default tariff + penalties</td></tr><tr><td>ISSB IFRS S2</td><td>Brazil (CVM), Mexico (CNBV), Chile (CMF)</td><td>FY2025 data, reported 2026</td><td>Climate risks, Scope 1/2/3 emissions, scenario analysis</td><td>Securities regulator sanctions</td></tr><tr><td>EU CSRD</td><td>EU + large non-EU subsidiaries</td><td>2029 (third-country)</td><td>Full ESG disclosure per ESRS standards with XBRL tagging</td><td>EU market access risk</td></tr><tr><td>Paris Agreement Art. 6</td><td>LATAM sovereign govts</td><td>COP29 rules, 2025</td><td>Sovereign-grade MRV for internationally transferred mitigation outcomes (ITMOs)</td><td>Exclusion from international carbon markets</td></tr></tbody></table>

## Compliance Checklist

<table class="checklist-table" id="bkmrk-criterionwhat-it-mea"> <thead><tr><th></th><th>Criterion</th><th>What it means</th></tr></thead> <tbody><tr><td>☐</td><td>**Regulatory exposure audit completed**</td><td>Applicable regulations from the 2026 stack identified.</td></tr><tr><td>☐</td><td>**Regulatory-to-data field mapping**</td><td>Each regulation's key data requirements mapped to existing or planned fields.</td></tr><tr><td>☐</td><td>**ISSB S2 baseline in place**</td><td>Data architecture covers all ISSB S2 mandatory disclosures.</td></tr><tr><td>☐</td><td>**CBAM readiness assessed**</td><td>Embedded carbon calculation capability assessed for all relevant export products.</td></tr></tbody></table>

## Regulatory References

- EU Directive 2024/825 (EmpCo/Green Claims) — enforcement September 27, 2026
- CBAM Regulation EU 2023/956 — definitive regime January 1, 2026
- ISSB IFRS S2 — S&amp;P Global LATAM Adoption Map, June 2025
- Paris Agreement Article 6 — COP29 Rulebook (Belém, November 2025)

## Recommended Tools and Platforms

<span class="tag">ISSB IFRS S2 disclosure checklist</span> <span class="tag">CBAM Registry</span> <span class="tag">EU CSRD ESRS standards</span> <span class="tag">LATAM NDC tracker (CEPAL)</span>

## Keywords

<span class="tag tag-kw">CBAM</span> <span class="tag tag-kw">ISSB S2</span> <span class="tag tag-kw">EU Green Claims</span> <span class="tag tag-kw">CSRD</span> <span class="tag tag-kw">Article 6</span> <span class="tag tag-kw">COP29</span> <span class="tag tag-kw">regulatory compliance</span> <span class="tag tag-kw">LATAM 2026</span>

<div class="related" id="bkmrk-related-principles%3A-"> **Related Principles:** [SCD-P01](https://wiki.cleantechhub.net/books/sovereign-climate-data/page/pp01) · [SCD-P02](https://wiki.cleantechhub.net/books/sovereign-climate-data/page/pp02) · [SCD-P04](https://wiki.cleantechhub.net/books/sovereign-climate-data/page/pp04)</div><div class="meta-footer" id="bkmrk-document-id%3A-scd-p09"> **Document ID:** SCD-P09 | **Version:** 1.0.0 | **Last Updated:** 2026-05-26 | **Category:** Governance and Social Legitimacy | **Source:** CleantechHUB Sovereign Climate Data Framework | **Licence:** CC-BY 4.0   
  
 *This page is part of the [Sovereign Climate Data Wiki](https://wiki.cleantechhub.net/books/sovereign-climate-data), maintained by CleantechHUB. It is AI-legible, machine-readable, and available via the [BookStack REST API](https://wiki.cleantechhub.net/api/pages).*</div>

# P10 — Resilience, Security and Data Governance

<div class="principle-header" id="bkmrk-scd-p10-%C2%A0%C2%B7%C2%A0-principl"><div class="principle-id">SCD-P10 · Principle 10 of 10</div><div class="principle-title">Resilience, Security and Data Governance</div><div class="principle-tagline">“Sovereign data that can be lost is not sovereign.”</div> <span class="category-badge">Governance Layer</span></div>## Definition

<div class="definition-box" id="bkmrk-sovereign-climate-da">Sovereign climate data requires an explicit governance framework specifying: (a) who has authority to read, write, modify, and delete data; (b) how data disputes are resolved; (c) backup and disaster recovery procedures; (d) security controls against unauthorised access or manipulation; (e) data retention and archiving policy; and (f) rules for data sharing with third parties. Governance must be documented and reviewed annually.</div>## Rationale

<div class="rationale-box" id="bkmrk-data-sovereignty-wit">Data sovereignty without governance is operational fiction. The Climate Data Steering Committee's Common Carbon Credit Data Model (2024) and the dMRV Working Group's Phase 2 Roadmap (2025) both identify data governance as the most under-addressed dimension of climate data infrastructure globally. For LATAM organisations, the additional risk is structural: most climate data is held in a single vendor system with no backup, no access log, and no recovery plan — meaning one vendor outage or relationship breakdown causes irreversible data loss.</div>## Implementation Steps

1. Write a Data Governance Policy covering: access control (who can do what), dispute resolution, retention schedule, backup frequency, and sharing rules.
2. Implement role-based access: at minimum, separate read and write permissions.
3. Run automated backups to a system you control at least weekly; test recovery quarterly.
4. Maintain an access log: every read and write to sensitive climate data is recorded.
5. For shared data: use a Data Sharing Agreement (DSA) that specifies permitted uses, attribution requirements, and data return/destruction obligations.

## Compliance Checklist

<table class="checklist-table" id="bkmrk-criterionwhat-it-mea"> <thead><tr><th></th><th>Criterion</th><th>What it means</th></tr></thead> <tbody><tr><td>☐</td><td>**Data Governance Policy written**</td><td>Document covers access control, disputes, retention, backup, and sharing.</td></tr><tr><td>☐</td><td>**Role-based access implemented**</td><td>At minimum: separate read vs. write access for climate data systems.</td></tr><tr><td>☐</td><td>**Automated backups running**</td><td>Weekly backup to a system you own, with quarterly recovery tests.</td></tr><tr><td>☐</td><td>**Access log active**</td><td>All reads and writes to sensitive climate data are recorded with timestamp.</td></tr></tbody></table>

## Regulatory References

- Climate Data Steering Committee — Common Carbon Credit Data Model (2024)
- dMRV Working Group Phase 2 Roadmap (Planet2050 × BioCarbon, 2025)
- GDPR Art. 5 (Data integrity and confidentiality) — applicable to EU-adjacent organisations
- ISO/IEC 27001 (Information Security Management) — international baseline

## Recommended Tools and Platforms

<span class="tag">Infisical (secrets management)</span> <span class="tag">Backblaze B2 / Rclone (backup)</span> <span class="tag">Keycloak (access control)</span> <span class="tag">Audit log frameworks</span>

## Keywords

<span class="tag tag-kw">data governance</span> <span class="tag tag-kw">security</span> <span class="tag tag-kw">resilience</span> <span class="tag tag-kw">backup</span> <span class="tag tag-kw">access control</span> <span class="tag tag-kw">data sharing agreement</span> <span class="tag tag-kw">ISO 27001</span>

<div class="related" id="bkmrk-related-principles%3A-"> **Related Principles:** [SCD-P04](https://wiki.cleantechhub.net/books/sovereign-climate-data/page/pp04) · [SCD-P08](https://wiki.cleantechhub.net/books/sovereign-climate-data/page/pp08)</div><div class="meta-footer" id="bkmrk-document-id%3A-scd-p10"> **Document ID:** SCD-P10 | **Version:** 1.0.0 | **Last Updated:** 2026-05-26 | **Category:** Governance and Social Legitimacy | **Source:** CleantechHUB Sovereign Climate Data Framework | **Licence:** CC-BY 4.0   
  
 *This page is part of the [Sovereign Climate Data Wiki](https://wiki.cleantechhub.net/books/sovereign-climate-data), maintained by CleantechHUB. It is AI-legible, machine-readable, and available via the [BookStack REST API](https://wiki.cleantechhub.net/api/pages).*</div>