Skip to content

6. Gaia-X Compliance Criteria for General Digital Services

A Gaia-X Digital Service Offering (DSO) is a general digital service available for order, described through the Gaia-X Digital Service Offering ontology, offered by a Gaia-X Participant, which fulfills the conformity criteria defined in this section and which is described and verified through the Gaia-X Compliance Engine.

Note

We use the term ‘Provider’ throughout this section as the short denominator for the Digital Service Provider, i.e., the Gaia-X participant who provides Digital Service Offerings in the Gaia-X ecosystem. We use the term ‘Consumer’ in this section to denominate the digital service Consumer, i.e., the Gaia-X participant who consumes a Digital Service Offering from a Provider. The term ‘Consumer’ is equivalent to the term ‘Customer’ used in other parts of the document, but better reflects non-commercial relationships within Gaia-X ecosystems.

Note

We use the abbreviation ‘DSO’ throughout this section for the Digital Service Offering and related to the Gaia-X Credential describing the Digital Service Offering according to the Gaia-X Digital Service Offering Ontology. The Digital Service Offering class inherits all attributes from the Gaia-X Service Offering class . Wherever attributes are referenced in this section, the Digital Service Offering class is the authoritative reference.

Note

The compliance criteria in this section focus on the presence and validity of ontology attributes in the DSO Credential. Each criterion validates that a mandatory attribute is declared, resolvable, and conformant to the Gaia-X Ontology. The rationale for the mandatory character of each attribute is documented alongside the respective criterion, as these attributes constitute the minimal transparency, accountability, and interoperability baseline required for a trusted digital service in the Gaia-X ecosystem.

Note

The compliance criteria are listed using a hierarchical numbering system, prefixed by “DS” to indicate Digital Service targeted criteria. The hierarchical numbering allows to assign stable numbers to criteria, also when future additions or deletions are made.

6.1 Assessment procedures

The Gaia-X Standard Compliance for DSO Credentials is issued by accredited Gaia-X Digital Clearing Houses (GXDCH) and the respective Gaia-X Compliance Services. The Gaia-X Digital Clearing Houses (GXDCH) operate these instances of the Gaia-X Compliance Service.

The technical validation of the claims and availability of evidences is performed by the Gaia-X Compliance service. The claims and evidences are described using the Gaia-X Ontology which is available via the Gaia-X Registry services.

All compliance criteria in this section are designed to be machine executable by the Gaia-X Compliance Engine. For each criterion, the Compliance Engine validates:

  1. the presence of the mandatory attribute in the DSO Credential, depending on conditions;
  2. the conformity of the attribute value against the Gaia-X Ontology (type, cardinality, permitted values);
  3. where the attribute is a reference to another Gaia-X Credential, the resolvability of the reference and the validity of the signature of the referenced credential and the conformance with the Gaia-X Ontology.

6.2 Criteria

6.2.1 Service Identification


Criterion DS1.1.1: The Provider declares a human readable name for the DSO through the name attribute of the DSO Credential.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: The DSO Credential contains the name for the DSO through the name attribute according to the Gaia-X Digital Service Offering ontology.

Permissible Standards:N/A

Example Standards:N/A

Note

The name attribute is mandatory because it is the primary human-readable identifier of the Digital Service Offering. Without a name, a service cannot be unambiguously presented in catalogues, referenced in contracts, or distinguished by Consumers during service selection.


Criterion DS1.1.2: The Provider declares a version number for the Digital Service Offering as part of the DSO Credential.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: A version number is present within the version attribute of the DSO Credential.

Permissible Standards:N/A

Example Standards:N/A

Note

The version attribute is mandatory because Digital Service Offerings evolve over time. A declared version number enables Consumers and the Compliance Engine to associate a compliance attestation with a specific, immutable state of the service description, and to detect when a re-assessment is required after a service changed. The version attribute also allows to link previous versions for comparision and detection of relevant changes. This is important for automated compliance checks.

6.2.2 Service Provider


Criterion DS1.2.1: The Provider responsible for the Digital Service Offering is a Gaia-X Participant, declared in accordance with the Gaia-X Compliance Criteria for Participants, and referenced through the corresponding attribute of the DSO Credential. Furthermore the Gaia-X Participant must declare a human readable name of the legal entity responsible for the service.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: 1. The Provider provides a Gaia-X compliant identity through the providedBy attribute of the DSO Credential. 2. The Provider declares the human readable name of the organization, as provided in the company registration documents, within the name attribute of the LegalPerson Credential.

Permissible Standards:N/A

Example Standards:N/A

Note

The declaration of an identifiable, legally registered and accountable Provider is the foundation of trust in the Gaia-X ecosystem. Without a verified Gaia-X Participant associated with the Digital Service Offering, no legal accountability, contractual capacity, or enforcement of the Gaia-X Terms & Conditions can be established. A name of the organization must be provided to allow the display of the name in catalogues.


Criterion DS1.2.2: The Provider declares its contact information relating to the DSO through the Gaia-X Ontology and links it in the DSO Credential.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: The Gaia-X contact information is provided with the DSO Credential and contains the contact information for this DSO and Provider.

Permissible Standards:N/A

Example Standards:N/A

Note

Contact information is mandatory to guarantee that Consumers, Federators, and supervisory bodies have a reachable point of contact for service inquiries, incident handling, and the exercise of legal rights. An unreachable Provider undermines the accountability principle of the Gaia-X ecosystem.

6.2.3 Contractual Transparency


Criterion DS1.3.1: The Provider documents the Terms and Conditions applying to the Digital Service Offering through the TermsAndConditions attribute and link them in the DSO Credential. This document contains the terms and conditions that apply to the provider and define how the supplier can use the data related to the Consumer usage of the service offering.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: A link to the Terms and Conditons document for the DSO is available through the Terms and conditions attribute alongside a SHA-256 hash of that document for content integrity verification.

Permissible Standards:N/A

Example Standards:N/A

Note

The Terms and Conditions are mandatory because they constitute the contractual baseline between the Provider and the Consumer. The inclusion of a message digest allows verification of the referenced content at any later time, including in cases of dispute resolution.


Criterion DS1.3.2: The Provider documents the Usage Terms and Conditions through the Usage Terms and Conditions attribute in the DSO Credential. The Usage Terms and Conditions describe the conditions that apply to the Consumer.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: The DSO Credential contains the Usage Terms and Conditions attribute with a resolvable link to the Usage Terms and Conditions document and a SHA-256 hash of that document. The document and hash may be identical to the Terms and Conditions declared under DS1.3.1.

Permissible Standards:N/A

Example Standards:N/A

Note

The separation of general, service-specific, and usage-specific Terms and Conditions enables Providers to differentiate between the contractual framework of the offering itself and the conditions governing its actual usage. Where no such differentiation exists, referencing the same document is explicitly permitted, so that the attributes remain machine-validatable without imposing artificial contractual fragmentation on the Provider and Consumer.


Criterion DS1.3.3: The Provider declares the provision type of the Digital Service Offering according to the Gaia-X Provision Type in the DSO Credential.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: The DSO Credential contains the provision type within the designated attribute Gaia-X Provision Type.

Permissible Standards:N/A

Example Standards:N/A

Note

The provision type is mandatory because it informs the Consumer about the fundamental delivery model of the service. As an enumerated value, it is directly machine-validatable and enables automated filtering and matching of Service Offerings in federated catalogues.

6.2.4 Data Protection and Data Sovereignty


Criterion DS1.4.1: The Provider documents the Personal Data Protection Regime applicable to the Digital Service Offering in the DSO Credential according to the Gaia-X Ontology.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: The applicable data protection regime is declared according to the Gaia-X Ontology through the Personal Data Protection Regime attribute.

Permissible Standards:N/A

Example Standards:N/A

Note

The declared Personal Data Protection Regime is mandatory because it determines which legal framework governs the processing of personal data within the service. It is also the discriminating attribute for conditional criteria in this section (see DS1.4.4), and therefore a prerequisite for the machine executability of the compliance validation.


Criterion DS1.4.2: The Provider documents the Data Protection Measures through the Gaia-X Data Protection Regulation Measures attribute and links the document in the DSO Credential as legal document.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: The DSO Credential contains a resolvable link to a Gaia-X Data Protection Regulation Measures documentation conformant to the Gaia-X ontology.

Permissible Standards:N/A

Example Standards:N/A

Note

The documentation of Data Protection Measures is mandatory to allow Consumers a transparent and educated assessment of the technical and organisational measures protecting their data, prior to ordering the service.


Criterion DS1.4.3: The Provider declares the means for Data Account Export through the Gaia-X Data Account Export ontology and links them in the DSO Credential.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: The DSO Credential contains a resolvable link to at least one Gaia-X Data Account Export ontology instance conformant to the Gaia-X ontology.

Permissible Standards:N/A

Example Standards:N/A

Note

The purpose of the Data Account Export declaration is to enable the participant ordering the service to assess the feasibility of exporting its personal and non-personal data out of the service. This export covers account data - e.g., account holder’s billing information, information on the PII held - but also data provided previously to the service by the user. This attribute is a cornerstone of data sovereignty and prevents Consumer lock-in.


Criterion DS1.4.4: If the declared Personal Data Protection Regime (DS1.4.1) is GDPR, the Provider declares Data Portability through the Gaia-X Data Portability ontology and link it in the DSO Credential.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: If the personal data protection regime attribute of the DSO Credential contains GDPR2016, the DSO Credential contains a resolvable link to a DataPortability instance conformant to the Gaia-X Data Portability ontology.

Permissible Standards:N/A

Example Standards:N/A

Note

Data Portability is a right of the data subject under Article 20 GDPR. Where GDPR is the applicable regime, the declaration of the portability means is therefore not optional but a legal transparency obligation, and its presence is machine-validatable based on the declared regime.

6.2.5 Semantic Interoperability


Criterion DS1.5.1: All Gaia-X Credentials referred to in the DSO Credential must pass the Gaia-X Ontology and signature checks.

Standard Compliance Label Level 1 Label Level 2 Label Level 3
declaration N/A N/A N/A

Proof of compliance: All referenced Gaia-X Credentials can be successfully verified being compliant with the Gaia-X Ontology and signed with keys controlled by an entity identified by an Gaia-X accepted Trust Anchor.

Permissible Standards:N/A

Example Standards:N/A

Note

Semantic interoperability is the precondition for the machine executability of all criteria in this section. A DSO Credential referencing unresolvable, non-conformant, or unsigned credentials cannot be validated by the Gaia-X Compliance Engine and therefore cannot be trusted by any other participant in the Gaia-X ecosystem. This criterion is validated recursively over the full reference graph related to the DSO Credential.

Consistency rules

  • The keys used to sign the DSO Credential and the Participant description, linked through providedBy should be from the same keychain.

  • A DSO always “falls back” to the minimum level of Gaia-X Compliance of any of its dependencies to indicate the “weakest link” in the service composition, in accordance with the Inheritance mechanism.

Note

For General Digital Services only Gaia-X Standard Compliance is avaiable as of now. Additional Gaia-X Label can be developed by members to comply with specific regulations and permissable standard as it has been done for cloud services.

Note

These are the minimum criteria for the entry in the Gaia-X ecosystem of ecosystems. Mature services are expected to enable more transparency through the optional attributes of the Digital Service Offering Credential. For highly mature services or services in regulated environments further information on Provenance of data or Software Bills of Material (SBOM) can be expected.

Suggest a modification