The Innovation in the Digital Economy (IDEA) Framework
A stronger digital economy starts with citizens back in control. Real control over personal data builds a safer digital space, corrects the imbalance that lets a small number of data aggregators set the terms for everyone else, and drives new waves of innovation, economic growth, and digital sovereignty.
Seven years of research, consultation, and discussion in fifteen minutes.
THE IDEA FRAMEWORK: Human-centred Digital Governance
Governance That Serves People
Most digital governance regimes try to make companies more compliant, or platforms more accountable, or enforcement more effective. The IDEA framework asks a different question: what would it take for people to have enforceable control over personal data. Answering that question serves two goals at once. It gives real substance to fundamental rights, and it fixes a structural market failure that no amount of enforcement can reach on its own.
The current regime leaves the underlying imbalance untouched. Regulators act after harm has occurred. Terms of service are set unilaterally. Consent is nominal rather than meaningful. This is not only a regulation failure. It is a market failure and a governance failure at once, and it calls for a structural response rather than incremental compliance.
The IDEA framework introduces four mechanisms that reinforce each other. People gain verified, portable control over verified personal data through legally recognised trusted third parties. Expert representatives, negotiate on citizens behalf, much as professionals already do in other sectors of the economy. They also owe duties to act in the citizens best interests. And citizens can negotiate collectively, correcting the bargaining asymmetry that individual consent cannot fix.
None of this requires new institutions built from nothing. In Europe, for example, it builds on the GDPR, the Digital Governance Act, and Data Act. It is also aligned with the Digital Omnibus proposal.
The IDEA framework, in the words of our chairs
In personal data markets, data acts as a form of payment. Citizens cannot negotiate or benefit from its value.
The IDEA framework proposes four connected mechanisms that give people control over their verified personal data, collective negotiation led by expert representatives who owe them duties to act in their best interest. This will transform compliance and accountability into market outcomes.
The digital economy runs on two levels.
The GIDE community describes an above-ground system of transparent commerce sitting on top of a below-ground system of barter. People receive services that are free or underpriced. They pay in the continuous harvesting of their personal data. Because there is no price, there is nothing to compare, and nothing to negotiate.
Actors below the line of visibility include large social media platforms, AI powered services, digital service providers, data brokers and political actors.
Personal data markets sit almost entirely below the line. That is the part of the market the IDEA framework is designed to correct.
The GIDE community calls this an influencer-funded digital barter. Alternatives to advertising and data monetisation are rare, so businesses that avoid them normally have to charge full price and end up serving a small segment of users. The absence of a visible price stops the market from allocating resources efficiently, and rewards innovation aimed at capturing engagement only.
A working market needs three things. Personal data markets have none of them.
There is an economic failure at the core of personal data markets. Personal data works as an implicit currency of digital exchange. People hand it over without price signals, without bargaining power and without effective oversight.
A market requires control
01People do not control their personal data
Once data is collected it is copied, combined and analysed beyond the awareness or reach of the person it came from. The same applies to groups, whose shared behaviour is predicted, segmented and targeted.
A market requires accountability
02Data aggregators answer to almost no one
Terms of service are opaque and non-negotiable. Low entry barriers and strong network effects push the sector towards concentration, so people have few alternative providers to move to.
A market requires protection from asymmetry
03One side knows everything, the other knows almost nothing
Aggregators hold a detailed picture of individual behaviour. Individuals know little about how their data is processed. A small number of firms control the underlying infrastructure and set the terms for everyone else.
Four mechanisms. Each one is the precondition for the next.
The IDEA framework is a closed system in which every part depends on the others. Select any mechanism to see what it supplies and what it cannot work without.
↻ And back to 01. Negotiation only works on data that can be verified.
Effective control over key personal data
"I control my key personal data."
Legally recognised repositories, governed by the person the data is about, hold a defined subset of verified personal data. Registries release it only on request. Every issuance is auditable, revocable and transmitted machine to machine.
The dependency chain runs as follows: control empowers people but risks reinforcing asymmetries without representation; representation requires specified fiduciary duties; fiduciary duties need collective negotiation to become binding outcomes; and collective negotiation requires verifiable key personal data repositories to function.
Who controls what, who owes what, and who agrees the terms.
Select a mechanism to see which relationships it changes.
Scroll the diagram sideways to see all of it
Registries may be run by public authorities, licensed private entities or consumer cooperatives, all under common regulatory standards. Expert representatives may be non-profit trusts, cooperatives or licensed intermediaries, and must remain independent of data aggregators.
Key personal data is a small, defined subset. That is what makes it controllable.
The IDEA framework does not ask citizens to control all data points companies have about them. It targets a specific set of personal data points that can be verified by trusted third parties.
It is routinely required for legal, contractual or administrative relationships.
This is the data you have to give to open an account, sign a contract or prove who you are.
It can be verified by a trusted third party.
Verification is what turns a claim into a credential, and a credential into something that can be issued, withheld and withdrawn.
Examples of key personal data
The precise list should be settled through regulatory consultation rather than fixed in advance. In the EU, the final list would be informed by the GDPR, the European Digital Identity framework, the NIS2 Directive and the know your customer and anti money laundering regimes.
Scattered, unverified and bundled with inferences.
Fragmented across every platform that has ever asked for it.
Accuracy and authenticity are never independently checked.
Bundled together with inferred profiles about you.
Circulated through processing chains you cannot see.
Held in a registry the person governs.
Verified once by a trusted registry rather than re-collected everywhere.
Issued only on request, and only for the approved purpose.
Revocable by the person at any point, not consented to once and forgotten.
Transmitted machine to machine, with an auditable record of every issuance.
The legal effect is that KPD processing practices become a continuous, revocable authorisation. It also offers a route out of consent fatigue, since one central act of authorisation can be transmitted automatically instead of being requested again by every site.
Nobody reads the terms. The IDEA framework proposes someone whose job it is.
The accountability gap is not caused by people being careless. It is caused by an impossible workload. Individuals lack the time, the expertise and the leverage, and regulators cannot monitor everything. The expert representative is the new institutional role designed to close it.
You are on your own.
You face terms drafted by specialists and offered on a take it or leave it basis.
You have no practical way to assess what the processing actually involves.
You have no leverage, because you are one person among millions.
You cannot monitor what happens after you click accept.
Enforcement, if it comes at all, comes long after the harm.
You appoint a professional.
You give a written, plain language mandate to an accredited representative.
They understand the technical and legal environment, because that is their profession.
They negotiate on behalf of a group, so the leverage is real.
They monitor processing continuously and can revisit agreements.
They are bound by fiduciary duties, and answerable for breaching them.
Accreditation, oversight and enforceability.
Legitimacy rests on three things: an accreditation process that tests competence and independence, reporting obligations and audits, and sanctions for breach. Representatives must remain independent of data aggregators.
You can leave, and take your mandate with you.
Representatives are paid for the service, which creates a professional market. People would have many competing representatives to choose from and few obstacles to switching between them.
The IDEA framework produces accountability in two directions at once. Vertically, the representative answers to the person. Horizontally, the representative holds the aggregator to the agreed terms. Both reduce reliance on enforcement after the fact.
Not another disclosure rule. A duty owed to you.
Compliance asks whether a company followed the rules. A legal duty asks whether it acted in your interest. This changes the relationship rather than adding to the paperwork.
Loyalty
Act solely in the interests of the person whose data it is, and avoid conflicts of interest.
Care
Apply professional competence and genuine awareness of risk, rather than minimum effort.
Transparency
Communicate clearly about data practices, including the role played by algorithms.
Expert representatives are always fully bound. For data aggregators, there are two paths.
Good faith negotiation produces a presumption of compliance.
Where terms are agreed through expert representatives, those documented terms create a rebuttable presumption that the person's best interests were respected. The presumption stands until a court, arbitrator or oversight body finds the terms were not followed.
Refusal means being bound directly, and proving it yourself.
An aggregator that will not negotiate becomes directly bound by the fiduciary duty and must independently demonstrate compliance. This creates a strong incentive to negotiate rather than face high threshold, litigation prone statutory obligations.
This conditional structure is not new to EU law. Under the GDPR, controllers using certification mechanisms and approved codes of conduct already benefit from reduced liability and a lighter evidentiary burden. Under the Digital Markets Act, gatekeepers with approved compliance measures or binding commitments can avoid stricter intervention.
A right you cannot exercise alone becomes real when it is pooled.
The IDEA framework draws experience from labour markets and financial services. Data rights become effective when they are exercised collectively. Grouping people who share similar preferences gives them bargaining strength that no individual has.
One person, acting alone
Accept the terms, or do without the service.
mandate
A defined group, represented
Negotiate the terms, with standard conditions applied across the group.
What gets negotiated
How a negotiation runs
Representation
Experts are accredited to represent a defined group of data subjects, under regulatory oversight.
Negotiation
Representatives and aggregators agree processing terms, with arbitration available if talks stall.
Compliance
The agreed terms operate as binding standards, carrying a presumption of compliance for firms that adhere.
Data subjects retain the final authority to consent. Smart contracts could carry the agreed standards at scale, encoding purpose limitation, processing restrictions, audit triggers and value sharing, and updating in response to regulatory change.
A case that would not have needed reconstructing.
€200m
The fine imposed by the European Commission on Meta over its consent or pay model. The Commission concluded that the model failed to meet the standard for valid consent and did not offer a genuinely equivalent alternative to people who declined to release their data.
Under the IDEA framework, clear and verifiable negotiated terms would have served the people affected, the Commission and the company alike. There would have been no need to investigate interface design or reconstruct user choice after the event. Enforcement could have asked a single question: did the company follow the terms it had already agreed?
Related concerns about consent under conditions of unequal bargaining power have also arisen before the German competition authority and the Court of Justice of the European Union.
The point is not more regulation. It is a fully functioning market.
When people can verify, control and negotiate the use of their data, economic actors compete on service quality rather than extraction capacity.
Trust and innovation are mutually reinforcing: stable expectations lower the cost of mistrust, better trusted systems receive more accurate data, and smaller firms gain market access through expert representatives.
This is not a transfer of burden from companies to individuals.
The IDEA framework realigns incentives across the whole system. Each actor is offered something it currently lacks.
Data subjects
- Unified, verified control over key personal data
- Professional representation, continuously
- Terms that can be understood and compared
- Real bargaining power through the group
- Rights that are exercised, not just held
Data aggregators
- A single reference point for lawful processing across Member States
- Narrower interpretive uncertainty and limited liability exposure
- Lower compliance and administrative load
- Fewer challenges to the validity of consent after the fact
- More accurate data, because trusted systems receive better information
- Standardised terms that reduce transaction costs
Regulators
- A clearer supervisory baseline to check conduct against
- Documented terms, timestamps and agreed conditions
- Less need to reconstruct intent or interface design
- A smaller administrative load and narrower disputes
- More targeted intervention
The digital economy
- Trust as a driver of innovation and growth
- Competition on service quality rather than extraction
- Smaller firms competing on more equal terms
- Market access for new entrants through representatives
- Greater democratic legitimacy for digital systems
The EU would not be starting from zero.
The institutional plumbing largely exists. Enactment would need targeted amendments to several instruments rather than wholesale legislative reform.
GDPR
Regulation (EU) 2016/679
Does not oppose collective negotiation of processing terms, and needs no new lawful ground to permit it. Already lets Member States set conditions for national identifier numbers. Already rewards certification and approved codes of conduct with reduced liability.
A best interests duty on controllers processing at scale, and a requirement to source key personal data only from authenticated, data subject controlled registries.
Data Governance Act
Regulation (EU) 2022/868
Recognises data intermediation services and data cooperatives. Cooperatives can already negotiate processing terms for their members and help them make informed choices. Intermediaries must act in members' best interests when supporting their rights.
An amendment allowing certain intermediaries to act as expert representatives, with a clean separation from their intermediation functions. Neutrality obligations currently prevent an intermediary from actively representing data subjects. Gatekeepers would be barred from the role.
European Digital Identity
Regulation (EU) 2024/1183, amending eIDAS
Establishes an EU wide framework for issuing, authenticating and recognising high assurance electronic identities, with cross border interoperability and supervision of trusted identity services.
Registry obligations would mirror those of Qualified Trust Service Providers: verification, auditability, secure storage, supervisory audits and liability for mis-issued credentials.
NIS2 Directive
Directive (EU) 2022/2555
Sets cybersecurity duties including identity and access management controls, logging and traceability requirements.
It supplies the trusted security layer that key personal data registries would operate within.
AML and KYC framework
Regulation (EU) 2024/1624 and Directive (EU) 2024/1640
Already requires entities to verify sensitive identifiers through a trusted third party, covering name, date and place of birth, nationality, address and identity documents.
Together with the GDPR and the digital identity framework, it already covers most of what would fall within key personal data.
Digital Markets Act
Regulation (EU) 2022/1925
Shows that EU law already accepts conditional adjustment of regulatory duties. Gatekeepers with approved compliance measures or binding commitments can avoid stricter intervention.
It supplies the precedent for the presumption of compliance, and the definition of gatekeepers who would be excluded from acting as expert representatives.
Data Act and Digital Services Act
Regulation (EU) 2023/2854 and Regulation (EU) 2022/2065
Extend the fairness principle across recent EU digital legislation, alongside the GDPR and the Digital Markets Act.
Fiduciary duties are presented as building on that established fairness principle rather than importing an unfamiliar concept.
ePrivacy Directive
Directive 2002/58/EC, applied alongside the GDPR
Governs access to terminal equipment, which in practice produces the repeated consent prompts that people now ignore.
A single act of authorisation, transmitted automatically as a stable and auditable preference signal, satisfying both regimes at once and reducing friction between them.
Digital Omnibus Proposal
Tabled by the European Commission, 19 November 2025
A proposal to simplify the existing digital legislative framework, intended to ease business compliance without weakening core EU policy objectives. It already signals a direction towards preference based control.
A proposal moving through the legislative process. Political and institutional pushback from EU institutions and civil society makes substantive redrafting likely.
IMCO draft opinion
Internal Market and Consumer Protection Committee, 8 June 2026
A draft committee opinion that introduces data expert representatives, collective negotiation on an aggregated mandate, machine readable negotiated terms and four new articles setting recognition conditions, a good faith duty to negotiate, fiduciary duties and mandate requirements.
A draft opinion of one parliamentary committee. It is not adopted law and its content may change.
Key personal data registries
No equivalent instrument at present
A defined category of key personal data, set by Commission delegated act after consultation, and a duty on organisations above the small enterprise threshold to source it only from authenticated, data subject controlled registries, keeping records that verify the sourcing.
Standards and supervision
Extension of existing administrative bodies
Technical work on machine readable standards for key personal data, an accreditation and oversight body for expert representatives and trusted repositories, and an independent commission to supervise the negotiation framework and report on how the market is working.
A reform process is already open.
Timing matters. The GIDE community considers the IDEA framework and Digital Omnibus to be the next building blocks of human centred digital governance.
GDPR adopted
The individual centred foundation of EU data protection. It permits collective negotiation without requiring a new lawful ground.
Data Governance Act, Digital Markets Act, Digital Services Act and NIS2
Data intermediaries and cooperatives are recognised. Conditional regulatory duties are established for gatekeepers. Cybersecurity and identity management obligations are set.
Data Act
The fairness principle is extended further across EU digital legislation.
European Digital Identity and the AML package
High assurance electronic identity is established EU wide. Verification of identifiers through trusted third parties is required across the financial system.
The Commission tables the Digital Omnibus Proposal
A simplification package covering several existing instruments. It opens the legislative vehicle through which elements of the IDEA framework could travel.
IMCO publishes a draft opinion
The committee text introduces data expert representatives, collective negotiation on an aggregated mandate, and machine readable negotiated terms. It is a draft opinion, not adopted law.
Read what the draft opinion actually proposes+
Defines a data expert representative as a data intermediation services provider recognised to act in a fiduciary capacity, advising and, where mandated, negotiating on behalf of individuals in their dealings with data controllers.
Defines collective negotiation as negotiation on an aggregated mandate from a defined group, producing standard terms applied uniformly across that group.
Provides for the outcome to be recorded as machine readable negotiated terms.
Conditions recognition on independence, expertise, published conflict of interest rules, indemnity insurance and acceptance of the fiduciary duties. It excludes gatekeepers and very large online platforms, and provides for yearly review, a public register and Commission delegated acts on minimum standards.
Imposes a duty to negotiate in good faith once a mandate is notified, without obliging agreement. Mediation follows after four months and binding arbitration two months later. Micro and small enterprises are exempt. Negotiated terms carry a rebuttable presumption that best interests were respected.
Codifies the duties of loyalty, care and transparency.
Requires a written, plain language mandate covering scope, duration, free revocation, cost based remuneration and complaints. Negotiated terms suffice for lawful processing, and the right to negotiate through a representative cannot be waived.
The EU Digital Identity Wallet enters into force
This strengthens the practical viability of controlling key personal data at source.
What the Digital Omnibus would still need
Complete the representation regime
Confirm the governance of expert representatives and data subject groupings under formal recognition and audit conditions. Add portability of clients between providers. Provide that negotiated terms and encoded preferences prevail over controller side defaults, and that one authorisation satisfies both the GDPR lawful basis and ePrivacy consent for terminal equipment access. Apply the good faith duty to small mid-caps only where they process the personal data of more than 50,000 individuals in the Union.
Extend the fiduciary duty to controllers
Impose a best interests duty on controllers processing personal data at scale. Where a controller refuses to negotiate, it becomes directly bound by the duty and must independently demonstrate compliance.
Introduce key personal data
Define the category, with the specific classes set by Commission delegated act following a consultation coordinated by the European Data Innovation Board with the Commission, ENISA and the European Data Protection Board.
Source it from registries people control
Require companies and public entities, other than micro and small enterprises, to source key personal data only from authenticated, data subject controlled registries, and to keep records verifying that sourcing.
Governance, oversight and evaluation
Mandate the European Data Innovation Board to coordinate guidance on registry governance with the Commission, ENISA and the European Data Protection Board. Establish a multistakeholder working party to set standards for machine readable key personal data and for transmitting terms and smart contracts. Confer audit attributes on the Board to verify sourcing. Extend oversight to cover representatives for vulnerable groups, trusted repositories and their security standards, and whistleblower support. Require the Commission to report periodically on how the regime operates.
Read the paper. Follow where the argument is going.
The full paper
An Innovation for the Digital Economy Act for Europe
Global Initiative for Digital Empowerment
Read the full paper