X-Road® is an open-source data exchange layer that lets organisations share data securely with one another over the public internet, acting as the connective tissue between government and private-sector systems. It is a reference example of a DPI building block: federated by design, decentralised, and running as national infrastructure in Estonia, Finland, Iceland and more than twenty other countries.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
Core function is secure inter-organisational data exchange, placing it in the Data Exchange domain. It is sector-agnostic by design and used across health, tax, justice, social protection and business registries, operating at national scale in over twenty countries.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
Specifications are fully published: OpenAPI 3 for the Admin API, WSDL for SOAP services, and a documented Service Metadata Protocol. It builds on TLS 1.2+, OCSP and X.509 PKI alongside its own X-Road protocol, exchanging XML and JSON against published message schemas.
Is it a modular building block that does one thing well, rather than a monolithic platform?
The system is composed of independent components — Central Server, Security Server and Configuration Proxy — that can be deployed and updated separately. X-Road is unambiguously the infrastructure layer, with services built by member organisations as the application layer, and countries configure it through Central Server policies rather than forking.
Can other public and private actors build on top of it?
Any organisation can deploy a Security Server and join, with a developer portal supporting service discovery. Hundreds of organisations across several countries independently build services on it, and governance sits with the Nordic Institute for Interoperability Solutions under an MIT licence with multiple contributing countries.
Can it run in distributed or federated deployments suited to national infrastructure?
Federation is explicit: a trust federation protocol allows national deployments to interoperate across borders. Data exchange is peer-to-peer with no central repository, so data stays with its owner, and all components support redundancy with Security and Central Servers running in high-availability pairs.
Does it meet the security and privacy bar for population-scale infrastructure?
Security rests on mutual TLS authentication, message signing, OCSP validation and comprehensive timestamped audit logging, documented in a published security architecture. Only metadata is logged, so data minimisation is built into the design, and regular security assessments are carried out by NIIS and member states.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA