Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Government Administration And Elections topic
No spam. Unsubscribe anytime.
Connecticut advances secure enterprise data sharing: p21/Datalink CT policies and a cloud enclave
Summary
The Data Board heard progress on modernizing p21 (soon Datalink CT): new governance policies, an enterprise memorandum of understanding, and development of a cloud-based secure data enclave to reduce data movement and improve auditing and security for interagency research.
Get email alerts on the Government Administration And Elections topic
No spam. Unsubscribe anytime.
Connecticut state leaders told the Data Board on Tuesday they have drafted a comprehensive policy framework and are building a secure cloud enclave to modernize how agencies link and analyze approved data for policy research under the state longitudinal data system, p21 (to be renamed Datalink CT).
Katie Breslin (Outreach and Engagement Coordinator), who manages p21, said the program aims to combine a federated and centralized architecture so data remain at agencies until an approved request is authorized, and then an auditorily monitored environment will allow researchers to work without unnecessary off-state data transfers. “The goal is to combine a federated and centralized model … keeping it inside of the state using a cloud system,” Katie said.
Why it matters: advocates and board members said a modernized system will reduce risk from manual file transfers, provide better auditing, and streamline approvals while preserving legal and privacy protections.
Policy work and governance
- New policies: in the past six months p21’s governance has adopted a data-quality policy, a data-classification policy, an expanded security policy and a new data-privacy policy. Staff said these policies are intended to create clearer expectations for agencies and shorten the time to negotiate data-sharing agreements.
- Governance structure: p21’s executive board authorized modernization; a data-governing board with agency representatives plus legal, privacy and security subcommittees met monthly to draft policies. Katie said existing enterprise memoranda of understanding and data-sharing agreements will reference these policies so that agency-level agreements are shorter and more standardized.
Technical implementation: secure enclave
- Secure Data Enclave development: Adrianna Sanchez Domenici, project manager for the enclave, said the team is building the environment in partnership with the state’s BITS cloud-compute team and plans a phased implementation. Short-term goals include an enclave that can host approved p21 datasets with protections for personally identifiable information; longer-term goals include agency-hosted preapproved datasets and audit logs.
- Integration and tools: technical work focuses on connecting the state’s secure file-transfer system (Axway) to an Azure cloud environment, migrating the data-matching tool (Data Ladder) into the cloud, and building strict access-management controls so users see only the data they are authorized to use.
- Testing and timeline: the team said they are in an agile development cycle with frequent testing and twice-weekly meetings with BITS. Implementation and broader rollout steps are planned for later in the summer.
Discussion, FOI and written agreements
Board members asked whether the new framework would eliminate interagency MOUs. Katie and Scott said enterprise MOUs would still exist but be shorter and standardized by the policy framework; federal law and good practice still require written agreements. Members emphasized the importance of including FOI considerations in agreements so requesters seeking records linked across agencies are handled consistently.
Ending
Board members praised the pace of recent progress and asked staff to return with draft enterprise-MOU language and an implementation schedule. Staff said the policy framework is intended to be adoptable by other state initiatives beyond p21.

