This Opinion explores the concept of technologies and ecosystems aiming at empowering individuals to control the sharing of their personal data (‘personal information management systems’ or ‘PIMS’ for short). Our vision is to create a new reality where individuals manage and control their online identity. Our aim to transform the current provider centric system into a hiucmsaynstecmentwr here individuals are protected against unlawful processing of their data and against intrusive tracking and profiling techniques that aim at circumventing key data protec tion principles.
The full text of this Opinion can be found in other languages at the EDPS website
This Opinion explores the concept of technologies and ecosystems aiming at empowering individuals to control the sharing of their personal data (‘personal information management systems’ or ‘PIMS’ for short).
Our vision is to create a new reality where individuals manage and control their online identity. Our aim to transform the current provider centric system into a human centric system where individuals are protected against unlawful processing of their data and against intrusive tracking and profiling techniques that aim at circumventing key data protection principles.
This new reality will be facilitated by the modernised EU regulatory framework and the possibilities offered by vigorous joined-up enforcement by all relevant supervisory and regulatory authorities.
The recently adopted General Data Protection Regulation (GDPR) strengthens and modernises the regulatory framework so that it remains effective in the era of big data by strengthening individuals’ trust and confidence online and in the Digital Single Market. The new rules, including those on increased transparency and powerful rights of access and data portability, serve to allow users more control over their data, and may also help contribute to more efficient markets for personal data, to the benefit of consumers and businesses.
Most recently we have issued an Opinion on effective enforcement of fundamental rights in the age of big data. This highlights current market conditions and business practices that create obstacles for effective exercise of individuals’ rights to the protection of their personal data and other fundamental rights, and calls for stepping up concerted and consistent enforcement of competition, consumer protection and data protection laws. We hope that this increased enforcement will serve to create market conditions in which privacy-friendly services can thrive. The approach in this Opinion aims at strengthening fundamental rights in our digital world at the same time as opening new opportunities for businesses to develop innovative personal data based services built on mutual trust. PIMS promise to offer not only a new technical architecture and organisation for data management, but also trust frameworks and, as a result, alternative business models for collecting and processing personal data in the era of big data, in a manner more respectful of European data protection law.
In this Opinion, we briefly describe what PIMS are, what problems they are intended to solve, and how. We then analyse how they can contribute to a better protection of personal data and what challenges they face. Finally, we identify ways forward to build upon the opportunities they offer. For new data protection business models to thrive, additional incentives for the service providers offering them may be necessary. It should be explored, in particular, which policy initiatives could motivate data controllers to accept this way of data provision. Furthermore, an initiative by public services to accept PIMS as a data source instead of direct data collection could add critical mass to the acceptance of PIMS.
The emerging landscape of PIMS, aiming at putting individuals and consumers back in control of their personal data, deserves consideration, support and further research with a view to contributing to a sustainable and ethical use of big data and to the effective implementation of the principles of the recently adopted GDPR.
Day by day, the importance of personal data in society is increasing. For this reason, is urgent to make sure individuals are in position to know and control their personal data, but also to gain personal knowdlegde from them and to claim their share of their benefits. MyData pursues that goal, a network of 90 organisations and 600 individuals. MyData is working to empower individuals with their personal data, helping them develop knowledge, make informed decisions and interact more consciously and efficiently with each other as well as with organisations.
Today, the balance of power is massively tilted towards organisations, who alone have the power to collect, trade and make decisions based on personal data, whereas individuals can only hope, if they work hard, to gain some control over what happens with their data. The shifts and principles that we lay out in this Declaration aim at restoring balance and moving towards a human-centric vision of personal data. We believe they are the conditions for a just, sustainable and prosperous digital society whose foundations are:
Trust and confidence, that rest on balanced and fair relationships between people, as well as between people and organisations;
Self-determination, that is achieved, not only by legal protection, but also by proactive actions to share the power of data with individuals;
Maximising the collective benefits of personal data, by fairly sharing them between organisations, individuals and society.
1. MYDATA SHIFTS: WHAT NEEDS TO CHANGE
Our overriding goal is to empower individuals to use their personal data to their own ends, and to securely share them under their own terms. We will apply and practice this human-centric approach to our own services, and we will build tools and share knowledge to help others do the same.
1.1. FROM FORMAL TO ACTIONABLE RIGHTS
In many countries, individuals have enjoyed legal data protection for decades, yet their rights have remained mostly formal: little known, hard to enforce, and often obscured by corporate practices. We want true transparency and truly informed consent to become the new normal for when people and organisations interact. We intend access and redress, portability, and the right to be forgotten, to become “one-click rights”: rights that are as simple and efficient to use as today’s and tomorrow’s best online services.
1.2. FROM DATA PROTECTION TO DATA EMPOWERMENT
Data protection regulation and corporate ethics codes are designed to protect people from abuse and misuse of their personal data by organisations. While these will remain necessary, we intend to change common practices towards a situation where individuals are both protected and empowered to use the data that organisations hold about them. Examples of such uses include simplifying administrative paperwork, processing data from multiple sources to improve one’s self-knowledge, personalised AI assistants, decision-making, and data sharing under the individual’s own terms.
1.3. FROM CLOSED TO OPEN ECOSYSTEMS
Today’s data economy creates network effects favoring a few platforms able to collect and process the largest masses of personal data. These platforms are locking up markets, not just for their competitors, but also for most businesses who risk losing direct access to their customers. By letting individuals control what happens to their data, we intend to create a truly free flow of data – freely decided by individuals, free from global choke points – and to create balance, fairness, diversity and competition in the digital economy.
2. MYDATA ROLES: WHO DOES WHAT
Please note: “Roles” are not “Actors” an individual or organisation may fulfill one or more roles at once.
An individual that manages the use of their own personal data, for their own purposes, and maintains relationships with other individuals, services or organisations.
A data source collects and processes personal data which the other roles (including Persons) may wish to access and use.
DATA USING SERVICE
A data using service can be authorised to fetch and use personal data from one or more data sources.
PERSONAL DATA OPERATOR
A Personal Data Operator enables individuals to securely access, manage and use their personal data, as well as to control the flow of personal data with, and between, data sources and data using services. Individuals can be their own operator. In other cases, operators are not using the information itself, but enabling connectivity and secure sharing of data between the other roles in the ecosystem.
3. MYDATA PRINCIPLES: WHAT WE WANT TO ACHIEVE
In order to produce the shifts that are needed for a human-centric approach to personal data, we commit to working towards and advocating the following principles:
3.1 HUMAN-CENTRIC CONTROL OF PERSONAL DATA
Individuals should be empowered actors in the management of their personal lives both online and offline. They should be provided with the practical means to understand and effectively control who has access to data about them and how it is used and shared.
We want privacy, data security and data minimisation to become standard practice in the design of applications. We want organisations to enable individuals to understand privacy policies and how to activate them. We want individuals to be empowered to give, deny or revoke their consent to share data based on a clear understanding of why, how and for how long their data will be used. Ultimately, we want the terms and conditions for using personal data to become negotiable in a fair way between individuals and organisations.
3.2 INDIVIDUAL AS THE POINT OF INTEGRATION
The value of personal data grows exponentially with their diversity; however, so does the threat to privacy. This contradiction can be solved if individuals become the “hubs” where, or through which cross-referencing of personal data happens.
By making it possible for individuals to have a 360-degree view of their data and act as their “point of integration”, we want to enable a new generation of tools and services that provide deep personalisation and create new data-based knowledge, without compromising privacy nor adding to the amount of personal data in circulation.
3.3 INDIVIDUAL EMPOWERMENT
In a data-driven society, as in any society, individuals should not just be seen as customers or users of pre-defined services and applications. They should be considered free and autonomous agents, capable of setting and pursuing their own goals. They should have agency and initiative.
We want individuals to be able to securely manage their personal data in their own preferred way. We intend to help individuals have the tools, skills and assistance to transform their personal data into useful information, knowledge and autonomous decision-making. We believe that these are the preconditions for fair and beneficial data-based relationships.
3.4 PORTABILITY: ACCESS AND RE-USE
The portability of personal data, that allows individuals to obtain and reuse their personal data for their own purposes and across different services, is the key to make the shift from data in closed silos to data which become reusable resources. Data portability should not be merely a legal right, but combined with practical means.
We want to empower individuals to effectively port their personal data, both by downloading it to their personal devices, and by transmitting it to other services. We intend to help Data Sources make these data available securely and easily, in a structured, commonly-used and machine-readable format. This applies to all personal data regardless of the legal basis (contract, consent, legitimate interest, etc.) of data collection, with possible exceptions for enriched data.
3.5 TRANSPARENCY AND ACCOUNTABILITY
Organisations that use a person’s data should say what they do with them and why, and should do what they say. They should take responsibility for intended, as well as unintended, consequences of holding and using personal data, including, but not limited to, security incidents, and allow individuals to call them out on this responsibility.
We want to make sure that privacy terms and policies reflect reality, in ways that allow people to make informed choices beforehand and can be verified during and after operations. We want to allow individuals to understand how and why decisions based on their data are made. We want to create easy to use and safe channels for individuals to see and control what happens to their data, to alert them of possible issues, and to challenge algorithm-based decisions.
The purpose of interoperability is to decrease friction in the data flow from data sources to data using services, while eliminating the possibilities of data lock-in. It should be achieved by continuously driving towards common business practices and technical standards.
In order to maximise the positive effects of open ecosystems, we will continuously work towards interoperability of data, open APIs, protocols, applications and infrastructure, so that all personal data are portable and reusable, without losing user control. We will build upon commonly accepted standards, ontologies, libraries and schemas, or help develop new ones if necessary.
4. ACTIONS: WHAT SHOULD HAPPEN NOW
Sign the Declaration, as an individual and/or as an organisation. This Declaration is written in the future tense: if your organisation isn’t quite there, but is committed to moving into this direction, it should still sign it!
Comment on the Declaration. This Declaration will evolve over time, based on your ideas and practical experience. There will be an initial review after 6 months.
Use the Declaration to further your own projects and intentions. Base your trust framework, or your terms of services, on it. Use it to lobby and convince clients, partners, stakeholders etc.
This Declaration of Principles draws upon many sources of inspiration, the most significant ones being:
The MyData Principles (Open Knowledge Finland)
The MesInfos Self Data Charter (Fing)
The Project VRM Principles (Project VRM)
The ODI data sharing principles (Open Data Institute)
The Personal Data Ecosystem Roles & Definitions (PDEC)
La percepción que los usuarios tenemos sobre tratamiento de nuestros datos personales está en plena evolución y debemos de ser capaces de encontrar respuestas y soluciones que generen confianza en un entorno, el digital, que necesita de estos datos para prestar nuevos servicios que den respuestas personalizadas y adaptadas a cada uno de nosotros. En este articulo lo analizamos en detalle y te proponemos algunos documentos que te ayudaran a entender como esta cambiando.
Si analizamos las encuestas y trabajos de investigación que se ocupan de medir las percepciones de confianza observamos un interesante cambio de tendencia. Hasta hace poco la falta de confianza era mayor hacia los organismos públicos que hacia las empresas u organizaciones privadas algo que ha empezado a cambiar a raíz de irse conociendo sucesivos usos fraudulentos o abusivos sobre datos personales y privados de todos los ciudadanos por empresas relacionadas con internet y las nuevas tecnologías.
Si bien la confianza de los usuarios en la Internet sigue siendo elevada, ya que el 74% de los usuarios dijo que confiaba en Internet en 2019, la preocupación por nuestra privacidad está aún más extendida y sigue creciendo año tras año.
Los usuarios siguen señalando a los delincuentes cibernéticos como una importante fuente de desconfianza y de preocupaciones sobre la privacidad en línea, pero no como su única fuente de preocupación. En lugar de ser considerados como una mejora de la seguridad y la privacidad en línea, muchos encuestados también consideran que los gobiernos, los medios sociales y las empresas de Internet contribuyen a la desconfianza en la Internet o a las preocupaciones sobre la privacidad en línea.
Los ciudadanos cada vez confíanos menos en las organizaciones que gestionan nuestros datos y esta falta de confianza contrasta con un elevado nivel de incomprensión de cómo se recogen y cómo se utilizan estos datos personales. Esto explicaría las contradicciones que encontramos entre lo que pensamos y lo que hacemos cuando utilizamos los nuevos soportes digitales al no cuestionar el uso que hacen de nuestros datos estas plataformas y empresas que cuestionamos y de las cuales decimos mayoritariamente que no nos fiamos.
Los estudios también ponen de relieve las percepciones muy diferentes de los usuarios de Internet en función de los niveles de ingresos y educación, en particular cuando se enfrentan a problemas de confianza en el mundo digital. Quienes ocupan posiciones de mayor nivel social -los más ricos, bien educados o los hombres- tienen sistemáticamente más probabilidades adoptar medidas que puedan mejorar eficazmente su confianza y privacidad en línea.
Y esto está provocando ya algunos cambios en los comportamientos y en el uso que hacemos de las diferentes herramientas y plataformas on-line tal y como recoge esta gráfica del estudio realizado por IPSOS para la Internet Society (ISOC) CIGI-Ipsos Global Survey on Internet Security and Trust
También muestra las diferencias generacionales los mayores tenemos poca confianza y seguridad en nosotros mismos al contrario que los más jóvenes que creen tener el monopolio de la comprensión de la tecnología y le otorgan un mayor nivel de confianza.
La regulación ayuda a generar confianza
La regulación ayuda tanto a las empresas de datos y a los ciudadanos
Las nuevas regulaciones y políticas adoptadas en materia de privacidad proporcionan "guarda railes" que incentivan la innovación y que, sin duda, ayudan a crear confianza en las sociedades. En general, los consumidores aceptan mejor a las empresas que usan sus datos cuando estos conocen las normas de privacidad (por ejemplo, el Reglamento General de Protección de Datos de la UE - o GDPR) se sentían mucho más cómodos que los encuestados que no las conocían.
Los consumidores valoran el papel del gobierno en la regulación del uso de los datos, y ven la GDPR muy favorablemente. Los encuestados quieren que el gobierno desempeñe un papel de supervisión y que se asegure de que las empresas cumplan la ley y sus políticas declaradas. Tal vez por esta razón, la GDPR se percibe muy positivamente en todo el mundo (55% favorable frente a 5% desfavorable). Además, los consumidores consideraron que la GDPR les ha dado más control sobre sus datos y ha aumentado su confianza en las empresas que utilizan sus datos.
Nuevos modelos de explotación de datos personales PIM
Coinciden los diferentes estudios y encuestas en que, a pesar de que Internet sigue siendo mayoritariamente confiable para los usuarios, cada vez aumenta la desconfianza y por tanto no podemos ni debemos mirar para otro lado y debemos de actuar y promover iniciativas como las que plantea el proyecto www.PIMCity.org