The automation challenge in data spaces
Data spaces are built on a principle: data holders should control the conditions under which their information is shared. Yet as these ecosystems mature from theory into working systems, a persistent problem emerges. How can organisations verify that a potential partner meets access requirements—proving location, certification status, or compliance—without manual intervention, while keeping data private and systems interoperable?
Manufacturing, energy, healthcare and mobility sectors all face this problem. They need to exchange data across organisational lines without relying on prior relationships. Proof of eligibility, enforcement of governance rules and compliance demonstration must all be transparent, auditable and machine-readable.
A research contribution from Gaia-X Lab Tech Lead Yassir Sellami, titled "Policy-Driven Data Space Contract Negotiation using the ODRL Verifiable Credential Profile and OpenID4VP", offers a standards-based answer. The work weaves together policy reasoning, Verifiable Credentials, OpenID for Verifiable Presentations, and the Dataspace Protocol into a single negotiation flow. Data providers can express access rules as machine-readable policies; consumers can automatically prove they meet those rules using credentials held in digital wallets.
The approach operationalises core principles of the Gaia-X Trust Framework: trust, interoperability, verifiability, data sovereignty and compliance-by-design.
Why manual verification limits scale
Data spaces rest on the idea that access should depend not just on who you are, but on whether you meet specific eligibility criteria set by the data holder.
A provider might restrict sharing to:
- Organisations in particular jurisdictions
- Certified members of recognised ecosystems
- Companies holding specific compliance certifications
- Entities bound by particular contractual terms
Such requirements are routine, yet enforcing them consistently remains difficult. Policies describe what must be proven, but rarely specify how proof should be requested, presented and validated in a way that works across different systems.
The gap between policy definition and enforcement is substantial. Many organisations fall back on manual checks, custom integrations or proprietary identity systems. These approaches do not scale and undermine a core goal of data spaces: enabling automated interactions between previously unknown parties.
The proposed protocol closes this gap by linking policy requirements directly to verifiable digital evidence.
Verifiable Credentials as the foundation
The Gaia-X Trust Framework establishes a shared baseline for trust, governance and interoperability across participating ecosystems. It relies on Verifiable Credentials and machine-readable claims to enable trustworthy digital interactions. Rather than depending on centralised authorities or proprietary trust models, Gaia-X promotes a federated approach in which trust is established through cryptographically verifiable assertions.
The framework explicitly identifies Verifiable Credentials as a cornerstone technology. They allow organisations to prove attributes, certifications and compliance claims in a verifiable, decentralised manner.
The protocol in the paper aligns with this vision. Instead of requesting documents or manual onboarding, a provider can request cryptographically verifiable evidence matching policy requirements. Negotiation becomes an exercise in automated trust evaluation.
ODRL: making governance machine-readable
The W3C Open Digital Rights Language (ODRL) forms a key element of the approach. It enables organisations to express permissions, prohibitions, obligations and constraints in machine-readable form. Both the Data Spaces Support Centre and Gaia-X recognise ODRL as central to expressing usage conditions and governance requirements.
Standard ODRL alone, however, does not specify how to verify claims about participants. This gap led to the creation of the Gaia-X ODRL Verifiable Credential Profile, which extends ODRL by allowing policy constraints to directly reference claims within Verifiable Credentials.
A provider can now specify that access is permitted only when a credential contains a country code matching France, Belgium or Spain. The policy no longer refers to abstract concepts but to verifiable data within credentials themselves. ODRL transforms from a policy language into a practical attribute-based access control mechanism for modern data spaces.
Automatic translation from policy to proof
A major innovation in the paper is the automatic conversion of policy constraints into credential requests. The protocol establishes a deterministic mapping between ODRL-VC policies and the Digital Credentials Query Language, a standard from the OpenID ecosystem.
The negotiation flow works as follows:
- A provider publishes an ODRL Offer containing VC-based constraints
- A consumer starts contract negotiation
- The provider extracts all policy constraints
- These constraints are automatically converted into a DCQL query
- The consumer's wallet receives the request
- Matching credentials are selected
- The wallet presents only the required claims
- The provider verifies the credentials and evaluates the policy
- If all conditions are satisfied, a binding agreement is issued
This eliminates manual configuration and keeps the proof request aligned with governing policy. When a policy changes, the credential request changes automatically. The result is reduced operational complexity and fewer configuration errors.
OpenID4VP: bridging governance and identity
OpenID4VP allows a verifier to request credentials from a digital wallet and receive cryptographically protected presentations in return. The proposed protocol positions the data provider as an OpenID4VP verifier. During contract negotiation, the provider generates a credential request derived from the policy and sends it to the consumer.
The consumer's wallet performs credential matching and presents only the information needed to satisfy the policy. This creates a seamless connection between governance rules and identity technologies.
Privacy and sovereignty by design
A significant strength of the protocol is its alignment with privacy and sovereignty principles. Gaia-X holds that participants should control their data and decide when and under what conditions it is shared. The Trust Framework emphasises transparency, control and compliance as fundamental requirements.
The protocol supports these goals through selective disclosure. Rather than sharing an entire credential, a participant reveals only the claims explicitly required by the policy. If a policy requires proof of location in France, the wallet discloses only the country code claim, not the full organisational profile.
This approach satisfies GDPR data minimisation requirements while reducing information exposure. From a sovereignty angle, the consumer retains control over disclosure. The wallet presents information only after explicit consent, and the participant knows exactly what is being shared. This represents a substantial improvement over traditional onboarding that often demands excessive information disclosure.
Integration with the Dataspace Protocol
The paper also addresses integration with the Dataspace Protocol, which already defines how providers and consumers negotiate agreements, exchange offers and establish contractual relationships. DSP does not, however, prescribe how credential-based eligibility verification should occur during negotiation or how such policies should be expressed in a common way.
The proposed protocol fills that gap. The authors define a fourteen-step sequence that integrates Verifiable Credential presentation directly into the DSP contract negotiation state machine. Eligibility verification becomes a native part of contract negotiation rather than a separate external process. This matters for Gaia-X Data Exchange initiatives and future Data Usage Agreement implementations, where contractual obligations and policy compliance must be evaluated before data access is granted.
Governance remains separate from protocol
The protocol deliberately separates policy evaluation from trust framework governance. The ODRL-VC Profile defines what claims are required, but governance authorities must still determine which issuers are trusted, which credential schemas are accepted, how revocation is managed and which trust registries are authoritative.
This separation matters for Gaia-X. The Gaia-X Trust Framework provides the governance foundation to answer these questions. By combining the proposed protocol with Gaia-X trust services and governance rules, ecosystems gain a complete end-to-end model for trustworthy and interoperable access control.
Connecting the pieces
The paper arrives at a pivotal moment for data spaces. The industry has largely solved policy expression. Progress has been made in digital identity standards, Verifiable Credentials and wallet technologies. What has been missing is a standardised mechanism connecting these pieces into an operational workflow.
By combining ODRL, Verifiable Credentials, OpenID4VP, DCQL and DSP, the proposed protocol shows how policy-driven contract negotiation can become fully automated while remaining interoperable and compliant with governance requirements.
For Gaia-X, the implications are substantial. The approach offers a concrete path toward automated trust establishment, machine-verifiable compliance and privacy-preserving access control. It operationalises the principles of sovereignty and interoperability that have guided Gaia-X from the start and provides a blueprint for future data space implementations in which access decisions are driven by verifiable evidence and transparent policy evaluation rather than manual processes.
As data spaces continue to develop, solutions that bridge governance, identity and automation will grow increasingly vital. This work represents a meaningful advance toward that future, bringing the Gaia-X vision of trusted and sovereign digital ecosystems closer to practical implementation.



