- Public sector data sharing is crucial for complex problem-solving.
- Balancing data utility with privacy risks is a persistent challenge.
- Modern frameworks emphasize separating policy from platform for scalability.
- Attribute-based access control (ABAC) is key for dynamic environments.
In an era of unprecedented data generation and complex societal challenges, public sector agencies face a critical dilemma: how to leverage vast datasets for public good while rigorously protecting sensitive information. This session, featuring Dave Thomas from Deloitte and Danny Holloway from Immuta, dives into the intricacies of implementing effective data security and policy frameworks, transforming traditional 'need to know' paradigms into dynamic 'need to share' capabilities.
The imperative for data sharing is starkly illustrated by issues like homelessness, which require a confluence of health, economic, housing, and mental health data from diverse agencies. However, this data is often highly sensitive, containing personally identifiable information (PII) and protected health information (PHI). The consequences of mishandling such data are not just hypothetical; they are real, tangible, and can lead to a profound erosion of public trust.
Historically, data sharing involved manual processes like emailing spreadsheets or using FTP sites, governed by human-adjudicated 'need to know' principles. This approach is no longer viable given the massive scale, speed, and machine-to-machine nature of modern data exchange. The speakers highlight how regulatory frameworks like GDPR and CCPA, while originating in the private sector, reflect a growing public awareness of data privacy, an area where the federal government has often been a reluctant pioneer.
To navigate this complex landscape, a new foundation is required. This includes robust data platforms with adequate storage and compute resources, a clear process for establishing governance, and a skilled workforce capable of operating in a dynamic data environment. A key recommendation is the separation of policy from platform, allowing for consistent enforcement across multiple clouds, technologies, and data types. This shift enables policies to be defined once, centrally audited, and applied universally, moving beyond hard-coded logic in siloed applications.
The benefits of such a framework are transformative: enabling more effective interagency data sharing, accelerating the integration of new datasets, and providing crystal-clear clarity on who has access to what data and why. By embracing attribute-based access control (ABAC) and leveraging automated metadata for classification, agencies can ensure that individuals receive precisely the information they need, precisely when they need it, adapting dynamically to changing roles and missions. This proactive approach mitigates risk, builds trust, and unlocks the full potential of data to serve critical public sector missions.
“Data has become democratized and the tools have lowered that barrier to the point where we now have more actors that that have problems that they can address with the right tech technologies and the right rules around the information they have.”




