Personal Data Control: A New Paradigm

A Thesis

  • This thesis begins with a question rather than a conclusion. For more than three decades, digital technologies have transformed the way we communicate, collaborate and share information. Email, cloud computing, smartphones and artificial intelligence have connected billions of people, accelerated economies and reshaped almost every aspect of modern life. They represent one of the greatest periods of technological innovation in human
    history.
  • This thesis does not question the significance of those achievements. It asks a different question. As digital communication has evolved, our relationship with our personal information has evolved alongside it. The personal paperwork and sensitive
    documents that quietly underpin our lives have become increasingly valuable, increasingly interconnected, and increasingly exposed. Yet many of the assumptions governing how those documents are managed have remained largely unchanged.
  •  Much has been written about protecting personal data but far less has been written about controlling it.
    The purpose of this thesis is not to criticise the technologies that brought us here. Every generation creates solutions for the challenges of its own time. Rather, it explores whether changing circumstances now invite us to think differently
    about the relationship between people, organisations, and the information that represents our lives.
  • Some readers will agree with every conclusion while others will not. That is entirely reasonable and our ambition is not to persuade you to reach a specific conclusion. Rather, if having read these pages, you find yourself asking different questions about personal data than when you began, then this thesis will have achieved its purpose.

PART I

How Did We Get Here?

barney-goodman-RGtxL6XI9kY-unsplash

Communication and Control

andrey-k-dsny5H5Ur2Y-unsplash

The Assumptions We No Longer Notice

natalia-blauth-wkajGpTkK7k-unsplash

The Technologies That Changed the World

PART II

What Has Changed?

silviu-zidaru-OnBaz6e5dfg-unsplash

The Architecture of Trust

designiments-iF8E2b60ajc-unsplash

Trust Has Been Outsourced

josue-michel-xCU7nCMNfI8-unsplash

Our Personal Data

PART III

A Different Architecture

christopher-stites-5wVz6IgfvzY-unsplash

Anchored Information

lena-polishko-Dh24FR2BJjg-unsplash

Control

A little toddler is riding on his father's shoulders on the moor

Custody

PART IV

A Different Architecture

ruben-mavarez-Ix3RhJ-rxmE-unsplash

Better for Society

colin-meg-ri9t0ga9mwA-unsplash

Better for Organisations

adam-kring-Bv0FAF9kJZU-unsplash

Better for Individuals

PART V

Rethinking Personal Data Control

Every generation inherits the technologies that solved the problems of its time. Every generation also inherits the responsibility to ask whether those technologies continue to reflect the world that has emerged around them.

This thesis has not argued against the technologies that transformed digital communication. Their contribution is extraordinary.

It has asked whether the challenge before us is changing.

Communication connects people. Stewardship protects the information through which those relationships increasingly operate. Communication moves information. Stewardship asks how our relationship with that information should be governed throughout its lifetime.

The objective is control.

Not control as secrecy or restriction, but meaningful control: clarity over where personal information resides, who may access it, for what purpose, for how long and under whose authority.

A philosophy of stewardship leads naturally to different principles.

Personal information should remain with its natural custodian wherever appropriate. Legitimate access should be governed by clear permission.

Possession should extend no further, and no longer, than genuine need requires.

The consequence is a different architecture.

Rather than assuming that legitimate interaction requires another copy, information can remain anchored while appropriate access to view is granted.

Where possession is genuinely necessary, organisations retain the information and the responsibilities that accompany it. Where access is sufficient, unnecessary possession can be avoided.

This does not diminish organisational responsibility. It clarifies it.

Individuals retain greater control over the information that represents their lives. Organisations remain responsible for the information they genuinely need to hold and for the way they interact with information entrusted to their access.

Responsibility sits where it most naturally belongs.

Progress has rarely depended upon discarding the achievements of previous generations. It begins by recognising when changing circumstances invite a different way of thinking. Artificial intelligence, cyber crime, identity fraud and the increasing value of personal information make that invitation increasingly difficult to ignore.

The future of personal information may therefore depend less upon moving documents more efficiently and more upon questioning whether they need to move at all.

The defining question is no longer simply:

How do we protect personal data?

It is also:

How do we enable people to retain meaningful control over their paperwork and important documents, while allowing organisations appropriate access whenever legitimate interaction requires it?

If future generations come to regard stewardship, custody, permission and restraint as natural foundations of digital trust, the digital age will have achieved something more significant than faster communication.

It will have created a more human relationship between people, organisations and the information that quietly underpins our lives.