Our research group presented a paper at the 36th Australasian Conference on Information Systems (ACIS 2025) in Moreton Bay, Australia. Arnold F. Arz von Straussenburg presented the paper, which addresses the design of roles and rights management for Data Trusts and contributes to our ongoing research on secure and trustworthy data sharing.

ACIS - Australasian Conference on Information Systems

ACIS is the premier conference for Information Systems research in the Australasian region. It brings together researchers and practitioners to discuss current developments and challenges in the Information Systems discipline. The 36th edition took place at the University of the Sunshine Coast in Moreton Bay, Australia, from December 3 to 5, 2025, under the theme "The State of the Information Systems Discipline: Challenges and Opportunities."

Academic Exchange in Brisbane and Moreton Bay

An invitation to Queensland University of Technology (QUT) in Brisbane provided a valuable opportunity for academic exchange. The discussions with colleagues at QUT allowed us to explore shared research interests, reconnect with familiar colleagues and consider possible directions for future cooperation. Encounters such as these are an important part of international conference visits, as they connect the presentation of current research with longer-term academic relationships.

The University of the Sunshine Coast was a wonderful host and created a welcoming environment for presenting and discussing research. Beyond the conference program, the visit to Australia helped strengthen existing contacts and establish new ones. We hope that these conversations will provide a foundation for future collaborations with research groups in Brisbane and the wider Australian Information Systems community.

Paper Abstract

Roles and Rights Management for Data Trusts

Authors: David Acev, Arnold F. Arz von Straussenburg, Florian Rieder, Timon T. Aldenhoff, Sankalp Biyani, Dennis M. Riehle & Maria A. Wimmer

In a Data Trust ecosystem, data flows between different actors and must therefore be carefully observed and managed. Secure and trustworthy data sharing requires a comprehensive framework for data access that clearly defines the necessary management components and their relationships. However, existing research provides little guidance on how roles, rights and access-control mechanisms should be combined in Data Trusts.

Following an echeloned Design Science Research approach, the paper identifies requirements for roles and rights management and develops a conceptual framework for Data Trust ecosystems. The framework integrates identity management, consent and authorization management, trust management, and access control management. It also incorporates several access-control models and demonstrates their interaction through two data-sharing workflows. The resulting framework provides a foundation for regulating data access and supporting secure, transparent and reliable exchanges between data providers, data owners and data consumers.

Funding and Acknowledgements

This research was conducted within the EG-DAS and KOOP-DAS projects. It was supported by the Federal Ministry of Research, Technology and Space (BMFTR), Germany, under research grants 16DTM218 and 16DTM411A as part of the European Union's NextGenerationEU program.

The feedback received at ACIS 2025 will inform the continued development and practical evaluation of the framework. We thank the conference organizers, the University of the Sunshine Coast and all colleagues we met during the visit for their hospitality, thoughtful discussions and openness to future collaboration.