ownership smart city data

Who owns smart city data?

Who owns the data a smart city collects? Too often a platform vendor. What municipal data ownership means in practice, and how cities take it back.

Poya Shad 2 min read

A city collects data every minute: indoor climate in schools, air quality at traffic points, energy use in public buildings, water flow in the network. Legally, the city owns this data. Practically, the only usable copy often sits inside a vendor’s platform, in that vendor’s format, behind that vendor’s API terms.

Ownership on paper and ownership in practice are different things. The practical version has four parts.

The data model

Whoever defines the data model decides what the data means. If the model lives inside the platform, your buildings, sensors, and readings are described in the vendor’s terms. Moving to another system means translating everything, and translation loses history.

A city that owns its data model can describe a school, a pump, or an air quality sensor once, and every system reads the same description.

The export path

Ownership includes the ability to take a complete copy, at any time, in a documented format. Many platforms offer an export that covers raw readings but skips metadata: units, locations, calibration history, quality flags. The readings alone are worth little without the context that makes them interpretable.

The test is simple. Ask for a full export of one building’s five-year history, and hand it to an analyst who has never used the platform. If the analyst can work with it, the export path is real.

The retention policy

Municipal data has legal retention periods, and different data types have different rules. When retention is configured inside a vendor platform, the city depends on that vendor to meet its own legal obligations. When retention is policy on storage the city controls, compliance is verifiable at any time.

The contract clauses

Ownership fails or holds in the contract. Three clauses decide it:

  • All data, including derived data and metadata, is the city’s property.
  • A complete export is available at any time during the contract, in a documented open format, at no additional cost.
  • On termination, the supplier delivers a final full export and deletes its copies after a confirmed handover.

Without the third clause, the first two expire exactly when they matter most.

Taking it back

Cities that already run vendor platforms do not need a big-bang migration. The practical path starts with the export path: get a complete copy into storage the city controls, in an open format, on a schedule. From that point, history accumulates outside the platform, and every future decision gets easier.

NIS2 adds a second reason to do this now. The directive’s reporting and continuity obligations assume you can see and reconstruct your own data. Our guide to NIS2 for IoT platforms covers what that means for a sensor estate. For the contractual side, see our post on writing IoT procurement requirements.

Poya Shad
written by
Poya Shad

Founder of Zero46. Builds sovereign IoT platforms for cities and utilities.

// talk to us

Building something that has to survive production?

Book a 30-minute call and tell us what you're working on. If it fits, we follow with a two-hour working session: architecture sketch, honest scope, no invoice.

Book 30 min