Lesson 8.2Lesson 8.2 · People, Governance & Ethics
Data Governance & Ownership
A city twin concentrates a city's knowledge of itself in one place - so the questions of who owns that data, who governs access to it, and whether it is locked inside a vendor's platform are not technicalities but the foundations of whether the twin serves the public at all
When a city builds a twin of itself, who actually owns the city's knowledge of itself - and what happens if the answer turns out to be a private company on a renewable contract?
A city twin is, at bottom, an enormous act of data-gathering. To build and feed it, a city pulls together its maps and cadastre, its buildings and utilities, its traffic and transit, its sensors and cameras, its energy and water, and increasingly data from private platforms - ride-hailing, telecoms, delivery networks. The result is something a city has never had before: a single, integrated, living model of itself, the most complete picture of the place that has ever existed. That is precisely why it is powerful. It is also precisely why the question of who owns and governs it is the most consequential question in this whole module.
Because here is the uncomfortable thing: the twin that makes a city legible to itself also makes the city legible to whoever controls the twin. If that controller is the public, accountable to citizens and bound by law, the twin can be a public good. If that controller is a vendor whose platform holds the data in formats only it can read, on terms set by a contract, then the city has quietly handed its own self-knowledge to a private party - and may find it cannot leave, cannot audit, and cannot truly govern the model that now governs so many decisions about it. Data governance and ownership sound like dry, back-office topics. They are nothing of the kind. They decide whether a twin is infrastructure for the public or a dependency on a landlord.
A twin is the city's knowledge of itself in one place. Own it, or rent it from a landlord. Open standards are the exit door.
Ownership, custodianship and stewardship: not the same thing
The first step to thinking clearly is to separate three ideas that get muddled. Ownership is the question of who holds rights over the data - who can licence it, sell it, restrict it or give it away. Custodianship is the question of who physically holds and maintains the data and is responsible for its accuracy, security and upkeep - the custodian is not necessarily the owner. Stewardship is the broader duty of care: governing the data responsibly over time in the interest of those it concerns and those who depend on it. A city twin involves all three, and a great deal of confusion and risk comes from assuming they are held by the same party when they are not.
Consider a concrete tangle. A city's cadastral and survey data has an official custodian with legal authority over it (in India, bodies such as the Survey of India and state revenue departments). Traffic data might be owned by a transport authority but physically held on a vendor's cloud. Mobility data might be owned by a private ride-hailing firm and only licensed to the city under terms. Sensor data might be generated by devices a contractor installed and operates. When all of this flows into one twin, who owns the integrated whole? Who may grant access to it, and to whom? Who is responsible when it is wrong? These are not answered by the technology; they must be answered by explicit governance - agreements, licences, custody arrangements and accountability structures - and if they are left implicit, the defaults tend to favour whoever built the platform.
This is why mature thinking about city data treats it as a governed asset, much like a spatial data infrastructure (SDI): a framework of data, standards, policies and institutional arrangements that make geospatial data shareable and usable across an organisation or a nation, with clear custodians and rules. A twin without that scaffolding is not just technically fragile; it is a governance vacuum, and vacuums get filled by whoever has the most commercial interest in filling them. The designer's role here is not to draft the contracts - defer that to the authorities and legal counsel - but to understand that behind every layer of a convincing twin sits a question of who owns it, who holds it, and who is accountable for it, and to ask those questions out loud before the model is trusted.
Owner != custodian != steward. Who can licence it? Who holds it? Who cares for it over time? Ask all three.
Public or private, open or proprietary
Two axes shape who a city twin serves, and they are often confused with each other. The first is public versus private control: is the twin owned and governed by a public body accountable to citizens, or by a private company accountable to shareholders? The second is open versus proprietary: are the data and the platform built on open standards and (where appropriate) open data that anyone can inspect and reuse, or on closed formats and restricted data that only the vendor can fully read? These are separate questions - you can have a publicly owned twin built on proprietary software, or a private platform publishing some open data - and both axes matter.
Open data is the principle that certain data should be freely available for anyone to use and republish, without restrictive licensing. For a city twin, a commitment to open data where privacy and security allow has real public value: it lets researchers, civic technologists, journalists, start-ups and citizens build on the city's data, audit it, find errors, and create value the city never imagined. It also guards against the twin becoming a black box. But open data is not a simple good to be maximised - the whole of Module 8 turns on the fact that some urban data is deeply sensitive, and publishing movement, occupancy or individual-level data openly can enable surveillance and harm. The honest position is open by default for non-sensitive data, carefully governed or closed for the rest, with the line drawn by law and privacy assessment, not convenience.
Open standards are a different and, for governance, even more fundamental matter. A twin built on open, interoperable standards - CityGML for city models, open APIs, documented formats - means the city's data can move between tools and vendors and be read far into the future. A twin built on a vendor's proprietary formats means the data is only as accessible as the vendor allows. This is where public and private interests most often diverge: a vendor has a commercial incentive to keep formats closed so the city cannot easily leave, while the public interest is almost always served by openness and interoperability. A city that insists on open standards keeps the power to switch providers, to audit its own model, and to own its knowledge of itself regardless of who built the software. A city that does not can find its self-knowledge effectively privatised - which is the subject of the next section.
The real danger: a city's self-knowledge locked in a vendor's platform
Here is the peril this lesson exists to name: vendor lock-in of a city's model of itself. Building a city twin is expensive and complex, so cities naturally turn to specialist vendors and platforms. That is reasonable - the problem is not using a vendor, it is the terms. If the twin is built on proprietary formats, if the data lives only inside a platform the city does not control, if the integrations and models and configurations are trapped in one company's system, then over time the city's knowledge of itself becomes inseparable from that vendor. The city cannot easily move to another provider, because migration would mean rebuilding everything and may be technically impossible. It cannot fully audit the model, because it cannot see inside. And it cannot walk away, because the twin now underpins how the city is planned and run. The vendor has become a landlord of the city's self-knowledge, and the renewal contract is a negotiation the city cannot afford to lose.
The consequences compound. Cost: a locked-in city has little bargaining power, so prices can rise with every renewal. Fragility: if the vendor raises prices unacceptably, changes direction, is acquired, or simply fails, the city's twin - and the decisions depending on it - are at risk. Accountability: a model the public cannot inspect cannot be democratically governed; officials end up deferring to a black box they do not control. Sovereignty: at national scale this becomes a question of data sovereignty - whether a country's data about its own cities is subject to its own laws and control, or sits on infrastructure and in formats governed by a foreign company. None of these are hypothetical; they are the ordinary failure modes of large public-technology procurement, and a city twin concentrates the exposure because it concentrates the data.
The defences are knowable, and a designer should be able to name them even while deferring the contracting to procurement and legal experts. Insist on open standards and data portability so the city can always export its model and move it elsewhere. Keep ownership of the data explicitly with the public body, with the vendor as a processor or custodian under contract, not the owner. Require interoperability so no single vendor holds the only key. Retain in-house capability so the city understands its own twin rather than being wholly dependent on a supplier. Build governance structures - clear custodianship, audit rights, exit clauses - before the platform, not after. The underlying principle is simple and worth stating plainly: a city should never cease to own, understand and be able to leave its own model of itself. A twin that the public cannot leave is not public infrastructure; it is a private dependency dressed as one.
If the city can't export it, audit it, or leave - it doesn't own its twin, the vendor does. Open standards are the exit.
Governance structures, accountability and the Indian context
What does sound governance of a city twin actually require? At minimum, a set of explicit answers to questions that are too often left implicit. Who owns each data layer and the integrated whole? Who is the custodian of record for each - responsible for accuracy, security and upkeep? Who may access what, under what rules and for what purposes, and how is that logged and audited? Who is accountable when the model is wrong, or when data is breached or misused? What standards keep the data portable and the city able to leave? A twin with clear, documented answers to these is a governed public asset. A twin without them is an accident waiting to happen, however impressive the graphics. Good practice tends to crystallise into a data-governance framework - a defined set of roles (data owners, stewards, custodians), policies, quality and access rules, and accountability - layered over the technical platform and treated as seriously as the platform itself.
Accountability deserves special emphasis because it is where governance meets democracy. A city twin influences real decisions about real lives, so the public must be able to ask who decided, on what data, with what assumptions, and to challenge the answer. That requires the twin's data, models and assumptions to be inspectable by those accountable to citizens - which is impossible if the whole thing is a proprietary black box. Governance and openness are not separate concerns; openness is part of what makes accountability possible. This is the thread that connects this lesson to the next two: data ownership and governance are the ground on which privacy, equity and democratic control all stand or fall.
In the Indian context, several things make this urgent. India has a rich but fragmented geospatial-data landscape with official custodians (the Survey of India, state and municipal bodies) whose authority and data of record must be respected - a twin's working layers never replace the authoritative source. India's evolving data-protection regime, centred on the Digital Personal Data Protection Act, 2023, increasingly shapes lawful handling of personal data, and questions of data sovereignty - keeping Indian data under Indian law and control - are live national issues. At the same time, large smart-city and urban-data programmes create real risk of procurement outpacing governance: expensive platforms bought before the ownership, custodianship and exit questions are settled, leaving cities locked in. The honest guidance for a designer is to treat governance as prior to technology, to respect the official custodians and the governing law, and to defer the binding legal and contractual decisions to the authorities, data custodians and legal counsel - while always asking, out loud, who owns this, who can leave, and who is accountable. A city that cannot answer those questions does not really govern its twin - its twin, and whoever built it, governs the city.
Spatial data infrastructure (SDI) & data-governance framework
Treating city data as a governed asset
Data, standards, policies and roles (owners, stewards, custodians) that make geospatial data shareable and accountable. The scaffolding a twin needs; illustrative framework, adapt to context.
Official data custodians (incl. Survey of India)
Authoritative survey, cadastral and boundary data
The legally authoritative geospatial and boundary data of record belongs to the official custodians and surveyors, never to a twin's working layers. Defer to the custodians of record.
Open standards & data portability (e.g. CityGML, open APIs)
Keeping the city able to audit and leave
Open, interoperable formats let a city export, inspect and migrate its model - the practical defence against vendor lock-in. Best practice, not a legal mandate; insist on it in procurement.
Data-protection law (incl. India's DPDP Act, 2023) & data sovereignty
Lawful ownership and handling of data
Who may own, hold and process data - especially personal data - is governed by the applicable law. Defer lawful-data and sovereignty decisions to the governing law and legal counsel.
Workshop - map the ownership and exit of a city twin
The skill here is seeing the governance behind the graphics. In this workshop you take a real or proposed city twin and map who owns its data, who governs access, and whether the city could ever leave - the three questions that decide who it really serves.
A city-twin or urban-data-platform case you can read about, this lesson, and the two figures. No software - this is governance reasoning, not modelling.
Goal: a governance map that exposes ownership, custodianship and lock-in risk Inputs: a real or proposed city twin / smart-city data platform you can read about + this lesson + the two figures Time: ~45 minutes
- 1List the data layers: for your chosen twin, name the main data layers (cadastre, buildings, traffic, sensors, mobility, utilities) and, for each, note who likely owns it, who holds it, and who maintains it - flagging where these differ.
- 2Place it on the two axes: is the twin publicly or privately controlled, and is it built on open or proprietary standards and data? Plot it and note what that position implies for who it serves.
- 3Test for lock-in: could the city export its whole model in an open format and move to another provider? If not, name where the lock-in sits (formats, hosting, integrations) and what it would cost to leave.
- 4Find the accountability: can the public inspect the twin's data, models and assumptions? Who is accountable if it is wrong or breached? Where is the black box, if there is one?
- 5Write the verdict: in one paragraph, judge whether this twin is governed public infrastructure or a private dependency, and name the single governance change (open standards, explicit public ownership, exit clause) that would most improve it - framed as reasoning, with binding contracts left to the authorities and counsel.
You’ll walk away with
A one-page governance map: data layers with owner/custodian/steward, the public-private and open-proprietary position, the lock-in risk, the accountability gap, and one decisive fix. Keep it - governance underlies the privacy and control lessons that follow.
Three altitudes on the same idea
Read the band that fits you — or all three.
When your work feeds the city twin - your building models, site data, survey - you are contributing to a governed public asset, and the terms matter. Ask how your data will be owned, held and reused before you hand it over, and prefer open, interoperable formats (CityGML, open APIs) so your contribution does not disappear into a proprietary black box. On larger commissions you may advise clients and authorities on twin-related procurement; there, champion open standards, data portability, public ownership of the data and clear exit rights, because these protect the public interest and your own future access. Respect the official custodians - the authoritative survey and cadastral data of record is theirs, not the twin's working layers. Defer the binding contracts, licences and lawful-data decisions to procurement and legal counsel; own the professional judgement that a city should always be able to own, audit and leave its own model.
Building-scale twins nest inside the city twin, and the same ownership questions apply to the data you generate and consume. When a building twin captures occupancy, energy, comfort and use data, ask who owns it, where it lives, and on what terms it flows upward to district and city models - and insist that sensitive data about how people use occupied space is governed, not simply harvested. Favour open, portable formats so a building's model is not trapped in one facilities-management vendor's platform, leaving the owner unable to switch or audit. Your data-governance instinct protects clients from lock-in at building scale just as it protects cities at urban scale. Coordinate the binding data-handling and contractual decisions with the engineers, owners and legal counsel; your contribution is to ensure the data serves the building's occupants rather than merely enriching a platform.
Learn to ask three questions of any city twin: who owns the data, who governs access, and can the city ever leave? Separate ownership (who holds the rights), custodianship (who holds and maintains the data) and stewardship (the duty of care) - they are often held by different parties, and confusing them hides real risk. Understand the two axes that decide who a twin serves: public versus private control, and open versus proprietary standards and data. And grasp the central peril - vendor lock-in, where a city's knowledge of itself gets trapped in a platform it cannot audit or leave, with costs, fragility and loss of accountability and sovereignty following. You are not expected to negotiate a data contract; you are expected to see that governance is prior to technology, to value open standards and open data (with privacy limits), and to ask who really controls a city's model of itself.
“Once a city has built a digital twin, it obviously owns and controls it - it is the city's model of the city, after all. The ownership and data questions are back-office technicalities that the IT department and the vendor can sort out; what matters is the capability the twin provides.”
Do it yourself
No tools needed - reason it through.
- 1Explain the difference between ownership, custodianship and stewardship of city data, with an example of each being held by a different party.
- 2What are the two axes (public vs private, open vs proprietary) that shape who a twin serves, and why are they separate questions?
- 3What is vendor lock-in of a city twin, and why is it so damaging to cost, accountability and sovereignty?
- 4Name four defences a city can use to avoid having its self-knowledge trapped in a vendor's platform.
- 5Why is openness part of what makes democratic accountability of a twin possible?
The one line to carry out
Peer-reviewed journals & authoritative standards
- 01Data governance — Wikipedia - Data governance, 2026.
- 02Open data — Wikipedia - Open data, 2026.
- 03Data sovereignty — Wikipedia - Data sovereignty, 2026.
- 04Spatial data infrastructure — Wikipedia - Spatial data infrastructure, 2026.
- 05Survey of India — Wikipedia - Survey of India, 2026.
Governance and ownership set the terms, but the sharpest ethical stakes appear when the data in question is about people - their movements, their homes, their lives. Next we confront the gravest concerns head-on: privacy, surveillance, bias and equity, and the city the twin cannot see.
The author
Amogh N P
Architect, interior designer, and creative polymath. Studio Matrx began in his notebooks — his vision of design made honest, useful, and open to everyone. Its Academy is written and taught in his memory, and free, forever.
More about Amogh →