# P10 — Resilience, Security and Data Governance

<div class="principle-header" id="bkmrk-scd-p10-%C2%A0%C2%B7%C2%A0-principl"><div class="principle-id">SCD-P10 · Principle 10 of 10</div><div class="principle-title">Resilience, Security and Data Governance</div><div class="principle-tagline">“Sovereign data that can be lost is not sovereign.”</div> <span class="category-badge">Governance Layer</span></div>## Definition

<div class="definition-box" id="bkmrk-sovereign-climate-da">Sovereign climate data requires an explicit governance framework specifying: (a) who has authority to read, write, modify, and delete data; (b) how data disputes are resolved; (c) backup and disaster recovery procedures; (d) security controls against unauthorised access or manipulation; (e) data retention and archiving policy; and (f) rules for data sharing with third parties. Governance must be documented and reviewed annually.</div>## Rationale

<div class="rationale-box" id="bkmrk-data-sovereignty-wit">Data sovereignty without governance is operational fiction. The Climate Data Steering Committee's Common Carbon Credit Data Model (2024) and the dMRV Working Group's Phase 2 Roadmap (2025) both identify data governance as the most under-addressed dimension of climate data infrastructure globally. For LATAM organisations, the additional risk is structural: most climate data is held in a single vendor system with no backup, no access log, and no recovery plan — meaning one vendor outage or relationship breakdown causes irreversible data loss.</div>## Implementation Steps

1. Write a Data Governance Policy covering: access control (who can do what), dispute resolution, retention schedule, backup frequency, and sharing rules.
2. Implement role-based access: at minimum, separate read and write permissions.
3. Run automated backups to a system you control at least weekly; test recovery quarterly.
4. Maintain an access log: every read and write to sensitive climate data is recorded.
5. For shared data: use a Data Sharing Agreement (DSA) that specifies permitted uses, attribution requirements, and data return/destruction obligations.

## Compliance Checklist

<table class="checklist-table" id="bkmrk-criterionwhat-it-mea"> <thead><tr><th></th><th>Criterion</th><th>What it means</th></tr></thead> <tbody><tr><td>☐</td><td>**Data Governance Policy written**</td><td>Document covers access control, disputes, retention, backup, and sharing.</td></tr><tr><td>☐</td><td>**Role-based access implemented**</td><td>At minimum: separate read vs. write access for climate data systems.</td></tr><tr><td>☐</td><td>**Automated backups running**</td><td>Weekly backup to a system you own, with quarterly recovery tests.</td></tr><tr><td>☐</td><td>**Access log active**</td><td>All reads and writes to sensitive climate data are recorded with timestamp.</td></tr></tbody></table>

## Regulatory References

- Climate Data Steering Committee — Common Carbon Credit Data Model (2024)
- dMRV Working Group Phase 2 Roadmap (Planet2050 × BioCarbon, 2025)
- GDPR Art. 5 (Data integrity and confidentiality) — applicable to EU-adjacent organisations
- ISO/IEC 27001 (Information Security Management) — international baseline

## Recommended Tools and Platforms

<span class="tag">Infisical (secrets management)</span> <span class="tag">Backblaze B2 / Rclone (backup)</span> <span class="tag">Keycloak (access control)</span> <span class="tag">Audit log frameworks</span>

## Keywords

<span class="tag tag-kw">data governance</span> <span class="tag tag-kw">security</span> <span class="tag tag-kw">resilience</span> <span class="tag tag-kw">backup</span> <span class="tag tag-kw">access control</span> <span class="tag tag-kw">data sharing agreement</span> <span class="tag tag-kw">ISO 27001</span>

<div class="related" id="bkmrk-related-principles%3A-"> **Related Principles:** [SCD-P04](https://wiki.cleantechhub.net/books/sovereign-climate-data/page/pp04) · [SCD-P08](https://wiki.cleantechhub.net/books/sovereign-climate-data/page/pp08)</div><div class="meta-footer" id="bkmrk-document-id%3A-scd-p10"> **Document ID:** SCD-P10 | **Version:** 1.0.0 | **Last Updated:** 2026-05-26 | **Category:** Governance and Social Legitimacy | **Source:** CleantechHUB Sovereign Climate Data Framework | **Licence:** CC-BY 4.0   
  
 *This page is part of the [Sovereign Climate Data Wiki](https://wiki.cleantechhub.net/books/sovereign-climate-data), maintained by CleantechHUB. It is AI-legible, machine-readable, and available via the [BookStack REST API](https://wiki.cleantechhub.net/api/pages).*</div>