Early in my career, I helped run a focus group in a community that had every reason to distrust people like me.
They showed up anyway. They told us things that were hard to say out loud. Someone cried. Someone else stayed late to make sure we understood a point that mattered to her. We took notes, thanked everyone, packed up the easel pads, and left.
The findings went into a report. The report went to the funder. The funder was satisfied.
The community never saw any of it.
Nobody decided that. There was no meeting where we agreed to take people’s stories and not bring them back. It just wasn’t in the workplan, and the workplan is what got done.
I have been part of that ritual more times than I want to count. If you work in evaluation, research, or nonprofit data, so have you.
The Ledger Only Runs One Way
Here is the standard shape of community data in our sector.
A community holds information: experiences, outcomes, stories, numbers. An organization collects it, usually because a funder or a statute requires evidence. The data flows up: from community to organization, from organization to funder, sometimes from funder to a dashboard nobody reads.
Now trace the value flowing back down. The funder gets accountability. The organization gets its next grant. The evaluator gets paid. And what does the community get, exactly? A thank-you? A commitment that their data will be “stored securely on a password-protected server”?
I’ve written that sentence. It answers a question nobody in the community asked. They didn’t want to know whether the server had a password. They wanted to know what we were going to do with what they gave us, and whether they’d ever benefit from having given it.
We have a word for arrangements where value gets pulled out of a community and the returns accrue somewhere else. The word is extraction. We usually reserve it for mining companies. We should be slower to exempt ourselves.
And to be fair, because the fairness is the point, nobody in that chain is a villain. The consent forms get signed. The review boards approve. The data really is de-identified. Everyone is doing their job with reasonable care, under deadline, on a budget with no line item for going back. That’s exactly what should worry us. Extraction doesn’t require bad intentions. It only requires a system whose defaults point one direction, and ours do. The question who governs this data? rarely gets asked, so it gets answered by default. And the default answer is: whoever holds it last.
The Word Is in the Room
Which is why something that happened this week caught my attention.
I was in a data strategy meeting for a state agency that serves families, and I heard a word I didn’t used to hear in government buildings.
Sovereignty.
Nobody flinched. Nobody asked for a definition. It was just in the room, being used, specifically about tribal nations as contributors to the agency’s data. And the questions that followed were not the usual ones about storage and logins. They were: if communities are giving us data, how do we make sure they have not just access to it, but useful access? Why would they want to give us data at all? What is the reciprocity? How will it be used, and does the data sharing agreement say so?
I’m hearing this more lately, and I’m grateful for it. I also want us to know what we’re saying when we say it. Because sovereignty is a word that can transform a data system, or get laminated onto one that works exactly the way it always has.
Sovereignty Is Not a Metaphor
When tribal nations are at the table, sovereignty is not a value statement. It is a political and legal reality. Tribal nations are governments. Data about their citizens is not a resource an agency happens to hold, and the frameworks for exercising authority over it already exist. They were built by Indigenous communities, who are among the most studied and least served peoples in the world.
In Canada, the First Nations Information Governance Centre established the OCAP® principles: Ownership, Control, Access, Possession. Regular readers have met OCAP here before: as a challenge to how AI governance disguises taking as sharing, as a reminder that the knowing belongs to communities, not the evaluators who surface it, and as a framework tested to its limits when documentation itself becomes a risk. I keep coming back to it because of what it refuses to soften. The principles don’t say communities should be consulted about their data. They say communities own it. Control how it’s collected and used. Access it whenever they want. Physically possess it, or decide who does.
Globally, the CARE Principles for Indigenous Data Governance (Collective benefit, Authority to control, Responsibility, Ethics) were built as a deliberate complement to FAIR, the open-data framework that wants data Findable, Accessible, Interoperable, and Reusable. I leaned on CARE when I made the case for AI governance from below. FAIR asks: how do we make data easy to use? CARE asks the question FAIR skips: easy for whom, and to whose benefit?
The challenge underneath these frameworks reaches past their origins, to every community that has ever handed its information to an institution: sovereignty is not a feeling of being respected. It is the actual authority to decide.
Most of what our sector calls data governance is really data custody: rules about storage, security, and permissions among professionals. Governance is about authority. A community can have its data encrypted to military standards and still have no say in anything that matters.
Useful Access
The phrase from that meeting I keep turning over is useful access, because it names a gap our sector loves to paper over.
Access is a portal login. Access is a raw export and a data dictionary written for analysts. Access is technically true and practically worthless, the data-system equivalent of a legal notice printed in six-point font. You can check the box marked “transparency” without transferring an ounce of capability.
Useful access means the data comes back in a form that supports the community’s own decisions, on the community’s own questions. It might be a briefing instead of a table. It might be the analyst’s time, not just the analyst’s output. It might mean the community defines the indicators that matter to them and the system reports on those, not only on what the statute requires.
The test is simple: after access is granted, can the community do something they couldn’t do before? If not, you’ve handed them a key to a locked room with the lights off.
Reciprocity, or: Why Would They Want To?
The other question from that meeting deserves to be printed on the wall of every data office: why do they want to give us data?
Not “how do we get them to.” Why would they want to.
If the honest answer is “nothing in it for them, but we need it,” then what you have is not a data partnership. It’s extraction with paperwork. And it will behave like extraction does: trust erodes, participation drops, the data gets thinner and more grudging every year, and everyone wonders why response rates are falling.
Reciprocity means the arrangement is worth it from both sides of the table. Data flows in; value flows back: analysis they can use, their questions answered, capacity built, decisions influenced. This is where data sharing agreements earn their keep. I wrote recently about moving decisions from personalities to agreements. Same move here, one step further: the agreement shouldn’t just govern security and permitted uses. It should name what the contributing community gets, who has authority to say no, how data comes back, and what happens when the community wants something changed. Communities can be parties to data agreements, not subjects of them.
A data sharing agreement that only describes obligations flowing one way is just the ledger again, notarized.
Four Questions That Find the Truth Fast
Strip away the policy language and governance comes down to four questions. Ask them about any dataset you work with.
Who decided what got collected? If the funder’s indicators drove the instrument, the community’s priorities weren’t governing anything. The community was just being measured against someone else’s theory of their lives.
Who can say no? Not on the consent form at intake. Now. If a community wanted a question retired, a dataset deleted, an analysis stopped, is there a door they could knock on? If there’s no mechanism for no, the yes was decoration.
Where does it live, and who can walk in? Possession sounds like a technicality until you notice that whoever holds the data holds every future decision about it.
Who benefits from its use? Follow the data’s working life. Every report it feeds, every grant it supports, every decision it informs. How many of those land back where the data came from?
I have projects in my own portfolio that fail three of these four. This is not a purity test. It’s a diagnostic, and the first patient is the mirror.
Still Theirs
The focus group from the beginning of this piece is years gone. The easel pads are landfill. The report is in a drawer, or wherever reports go. But somewhere in a system, some of what those people said that night is probably still sitting in a row. Data outlives workplans.
What gives me hope is the distance between that room and the one I sat in this week, a room where the questions got asked at the design stage, while the defaults are still wet cement. That’s the moment. Once a system is built, its assumptions about who decides get very expensive to change.
So if you’re anywhere near a data conversation right now: say the word. Ask the reciprocity question out loud. Put useful access in the requirements, not the appendix.
Because the question was never really whether the data is secure.
The question is whether it’s still theirs.
Anthralytic is where mission-driven, resource-constrained organizations can get guidance with impact strategy, measurement, and reporting. If your data sharing agreements only describe obligations flowing one way, I’d love to help you rewrite them.

