The OCAP Principles: A Comparative Framework
The OCAP principles (Ownership, Control, Access, and Possession) represent one of the most influential Indigenous data governance models in the world. Developed by the First Nations Information Governance Centre in Canada, OCAP reframes data governance as an exercise of self-determination rather than solely an issue of privacy or administrative regulation. This Playbook references OCAP frequently because it offers a mature, tested framework that tribes in the United States can learn from, adapt, and build upon.
This page provides a detailed analysis of each OCAP principle, how it maps to the U.S. tribal context, and where significant gaps remain, particularly in the era of artificial intelligence.
Overview of the Four Principles
Section titled “Overview of the Four Principles”OCAP recognizes that data concerning Indigenous peoples is not simply a commercial or technical asset, but an extension of Indigenous sovereignty, cultural identity, and collective governance.1
Ownership recognizes that Indigenous communities collectively own information about themselves in much the same way that individuals own personal information. In the U.S. tribal context, cultural knowledge, tribal records, and traditional ecological knowledge are communal tribal assets tied to sovereignty rather than merely individual privacy interests.2
Control affirms that First Nations maintain the right to direct and oversee all aspects of research and information management processes affecting their communities. Although U.S. tribal law does not explicitly codify an equivalent principle, many tribes increasingly use tribal research codes, memoranda of understanding, and data governance agreements to regulate the conduct of outside researchers, federal agencies, and private entities.3
Access provides that First Nations must be able to access information and data concerning their communities regardless of where that information is physically held. This principle is particularly significant because much Indigenous data historically has been collected and maintained by external governments, universities, and corporations.
Possession refers to the physical custody and storage of data and functions as the mechanism through which First Nations can assert and enforce ownership rights over their information.1
Where OCAP Aligns with U.S. Tribal Law
Section titled “Where OCAP Aligns with U.S. Tribal Law”Both OCAP and U.S. tribal sovereignty frameworks are grounded in the understanding that Indigenous nations retain inherent governing authority. In the U.S., tribal sovereignty supports tribal authority over research approvals, data-sharing agreements, and information governance within tribal jurisdictions.4 Both systems recognize that Indigenous communities possess a legitimate and continuing interest in how information about their peoples, lands, and resources is collected and used.
The ownership component of OCAP mirrors the U.S. tribal context closely. Cultural knowledge, tribal records, and traditional ecological knowledge are understood as communal tribal assets tied to sovereignty, not as individual data points subject only to privacy law.
The control principle aligns with the growing practice among U.S. tribes of establishing tribal research codes and data governance agreements. These mechanisms, while not yet universal, serve the same function as OCAP’s control principle: ensuring that research and data collection affecting tribal communities is conducted under tribal authority and on tribal terms.
Where Gaps Remain
Section titled “Where Gaps Remain”Despite these parallels, significant gaps exist in both the U.S. tribal context and within OCAP implementation itself.
In the United States, the federal government continues to maintain control and possession over significant amounts of data about Native populations, including health, environmental, criminal justice, and demographic data. Much of this information is collected and stored by federal or state agencies rather than by tribes themselves.5 This limits meaningful tribal control even where sovereignty is formally recognized.
U.S. law generally lacks robust recognition of collective Indigenous ownership rights in data. Federal privacy frameworks emphasize individual privacy protections that do not account for the communal nature of Indigenous identity, culture, and traditional knowledge.6
On the OCAP side, the framework was developed before the widespread emergence of generative AI, algorithmic decision-making, biometric surveillance, and large-scale machine learning systems.7 As a result, OCAP does not yet directly address the extraction and use of Indigenous data in AI training datasets, the unauthorized digitization of cultural knowledge, or the commercialization of Indigenous languages, art, and traditional ecological information through automated technologies.
Adapting OCAP for the AI Era
Section titled “Adapting OCAP for the AI Era”Several areas present opportunities for extending OCAP-style protections into the AI context. These are open questions that the Playbook identifies for further development by tribal law scholars, technologists, and governance experts:
How should the ownership principle apply when tribal data is ingested into a machine learning model? The data may no longer exist in its original form within the model, but the model’s outputs are shaped by it. Ownership in this context may need to extend beyond data custody to encompass the outputs and derivatives produced by AI systems trained on tribal information.
How should the control principle operate when AI vendors process tribal data through proprietary systems where the tribe has no visibility into the underlying algorithms? Control may require not just data governance agreements but also algorithmic transparency requirements and audit rights.
How should access work when data has been aggregated, anonymized, or transformed by AI processing to the point where the original tribal source is obscured? Tribes may need mechanisms to trace the provenance of AI-processed data back to its origins.
How should possession be understood when data exists in distributed cloud systems across multiple jurisdictions? Physical possession may give way to cryptographic or contractual controls, but the underlying principle of tribal custody must be preserved.
These questions are explored further in the Playbook’s sections on Technical Architecture and Contract and Data Custody Frameworks.
Detailed Analysis: OCAP in the U.S. Tribal Context
The OCAP principles (Ownership, Control, Access, and Possession) have become one of the most influential Indigenous data governance models in the world. Developed by the First Nations Information Governance Centre, OCAP recognizes that data concerning Indigenous peoples is not simply a commercial or technical asset, but an extension of Indigenous sovereignty, cultural identity, and collective governance. In this sense, OCAP reframes data governance as an exercise of self-determination rather than solely an issue of privacy or administrative regulation.1
The OCAP principles are similar to U.S. tribal law in that both frameworks are grounded in the understanding that Indigenous nations retain inherent governing authority. In the U.S., tribal sovereignty supports tribal authority over research approvals, data-sharing agreements, and information governance within tribal jurisdictions.4 Both systems therefore recognize that Indigenous communities possess a legitimate and continuing interest in how information about their peoples, lands, and resources is collected and used.
Specifically, the ownership component of OCAP recognizes that Indigenous communities collectively own information about themselves in much the same way that individuals own personal information. This mirrors the U.S. tribal context, where cultural knowledge, tribal records, and traditional ecological knowledge are communal tribal assets tied to sovereignty rather than merely individual privacy interests.2 The control principle further affirms that First Nations maintain the right to direct and oversee all aspects of research and information management processes affecting their communities. Similarly, although U.S. tribal law does not explicitly codify equivalent principles, many tribes increasingly utilize tribal research codes, memoranda of understanding, and tribal data governance agreements to regulate the conduct of outside researchers, federal agencies, and private entities.3
The access principle provides that First Nations must be able to access information and data concerning their communities regardless of where that information is physically held.1 This principle is particularly significant because much Indigenous data historically has been collected and maintained by external governments, universities, and corporations. Finally, possession refers to the physical custody and storage of data and functions as the mechanism through which First Nations can assert and enforce ownership rights over their information.
Despite these similarities, substantial gaps remain within the U.S. tribal context and even within existing OCAP implementation. In practice, the United States continues to maintain control and possession over significant amounts of Native populations’ health, environmental, criminal justice, and demographic data, much of which is collected and stored by federal or state agencies rather than by tribes themselves.5 This limits meaningful tribal control, even where tribal sovereignty is formally recognized. Additionally, U.S. law generally lacks robust recognition of collective Indigenous ownership rights in data, instead emphasizing individual privacy protection that fails to account for the communal nature of Indigenous identity, culture, and traditional knowledge.6
The rapid development of artificial intelligence and large-scale digital data systems further exposes gaps in both domestic tribal law and existing OCAP protections.8 While OCAP provides a strong foundation for Indigenous data sovereignty, it was developed prior to the widespread emergence of generative AI, algorithmic decision-making, biometric surveillance, and large-scale machine learning systems.7 As a result, the framework could be expanded to more directly address the extraction and use of Indigenous data in AI training datasets, the unauthorized digitization of cultural knowledge, and the commercialization of Indigenous languages, art, and traditional ecological information through automated technologies.
References
Section titled “References”Footnotes
Section titled “Footnotes”-
First Nations Information Governance Centre, OCAP Principles. https://fnigc.ca/ocap-training/ ↩ ↩2 ↩3 ↩4
-
Canada School of Public Service, Indigenous Data Sovereignty. https://www.csps-efpc.gc.ca/tools/articles/indigenous-data-sovereignty-eng.aspx ↩ ↩2
-
See generally Weave Pulse, Tribal Data Sovereignty overview. https://www.weavepulse.com/grants/tribal/data-sovereignty ↩ ↩2
-
Hartley, J. and Carroll, S.R., “OCAP and Indigenous Data Sovereignty in the U.S. Context,” International Indigenous Policy Journal, Vol. 11, No. 1 (2020). https://ojs.lib.uwo.ca/index.php/iipj/article/view/7511/6155 ↩ ↩2
-
Native Land Information System, Data Sovereignty resources. https://nativeland.info/about/data-sovereignty/ ↩ ↩2
-
Carroll, S.R. et al., “Indigenous Data Sovereignty and Policy,” PMC (2023). https://pmc.ncbi.nlm.nih.gov/articles/PMC10192690/ ↩ ↩2
-
First Nations Information Governance Centre, History. https://fnigc.ca/about-fnigc/our-history/ ↩ ↩2
-
FNIGC, Barriers and Levers for the Implementation of OCAP. https://fnigc.ca/wp-content/uploads/2021/08/Barriers-and-Levers-for-the-Implementation-of-OCAP.pdf ↩