
Today we’re publishing our EU policy white paper: From Data Governance to Evidence Governance: Building Verifiable Evidence Chains for European Life Sciences. It’s a contribution to a conversation already under way inside European institutions, not a pitch for our own platform, and it makes a fairly narrow argument: Europe has done the hard work of deciding who may access data. It has not yet done the equivalent work for what must survive once that data becomes a claim.
Data governance asks whether data may be used — who may access it, under what legal basis, with what safeguards. Evidence governance is a different, later question: once data have been transformed into an analysis, an analysis into a result, and a result into a regulatory or public-health decision, can an authorised reviewer still trace that claim back to the source artefacts, transformations, software versions and analytical choices it actually depended on?
Those are not the same problem, and the difference is not academic. A secure processing environment can control who touches a dataset. It says nothing about whether the report that leaves that environment still carries a verifiable link back to the permit, the data sources and the processing context that produced it. In a genuinely federated system — and Europe’s emerging health and research infrastructure is deliberately federated — that gap is where scientific and regulatory claims quietly lose their history.
The timing isn’t incidental. The European Health Data Space applies in general from 26 March 2027, and the technical specifications that will determine what a secure processing environment records — and what travels with an approved output when it leaves one — are being settled now, not in 2029. The proposed European Biotech Act, currently in the ordinary legislative procedure, would underpin its “data quality accelerators” with datasets it describes as provenance-verified, without yet defining what verified provenance actually means. Both files are open. Provenance conventions adopted at this stage cost far less than provenance reconstructed after the fact.
The core recommendation is a European minimum evidence record: nine conceptual elements — persistent identifier, parent artefacts, responsible actor or process, time, method, material version information, integrity reference, governance context and derived artefacts — small enough to travel between domains, expressive enough to support real verification. It’s deliberately technology-neutral. The paper is explicit about what it is not asking for: no central European database, no mandatory disclosure of sensitive data, no blockchain requirement, no automation of scientific judgement. The practical route proposed is a staged pilot programme across three streams — genomic evidence, distributed real-world evidence in the style of DARWIN EU, and cross-border outbreak investigation — evaluated before anything becomes mandatory.
We’re building a demonstrator using ancient DNA and other public scientific datasets to test whether persistent evidence provenance can actually be represented end to end, in the open, on real and messy scientific material. Ancient DNA is public, versioned and computationally transformed through long pipelines in ways that are structurally identical to the pilot streams the paper proposes — without the governance complications of clinical data, which means it can be shown to anyone. It is not offered as proof that one architecture should become a European standard. It exists to test what actually breaks when you try to make evidence lineage travel across systems, not just to describe it in a diagram.
The full paper runs to eighteen sections plus a European minimum evidence record model, a staged pilot proposal and detailed policy recommendations, fully referenced against primary EU sources. Read the complete text of the paper here, or download the formatted PDF from our Resources page. The nine-field specification behind its central recommendation is published separately as The Minimum Evidence Record, v0.1.
Data governance asks whether data may be used. Evidence governance asks a later question: once data have been transformed into an analysis and a conclusion, can an authorised reviewer still trace that claim back to the source artefacts, transformations and analytical choices it depended on?
No. It’s a policy contribution aimed at European institutions and the technical specifications they are currently drafting. Where The BioChain appears, it’s as a worked demonstrator testing whether the proposal is practical, not as a product recommendation.
The EHDS implementing acts and the technical specifications that will determine what a secure processing environment records are due by 26 March 2027 — years before the commonly cited 2029 and 2031 dates when secondary use for most data categories actually begins.
The complete text is published as a free-to-read article, here, alongside a downloadable, formatted PDF on our Resources page.
If your organisation generates, manages, analyses or governs biological evidence and would be interested in participating in a UK or European provenance demonstrator, The BioChain would welcome the conversation.
Get in touch
Regulatory developments, technical notes and platform news — sent occasionally, straight to your inbox.