The Innovation in the Digital Economy (IDEA) Framework

A stronger digital economy starts with citizens back in control. Real control over personal data builds a safer digital space, corrects the imbalance that lets a small number of data aggregators set the terms for everyone else, and drives new waves of innovation, economic growth, and digital sovereignty.

Learn More

Seven years of research, consultation, and discussion in fifteen minutes.

THE IDEA FRAMEWORK: Human-centred Digital Governance

Governance That Serves People

Most digital governance regimes try to make companies more compliant, or platforms more accountable, or enforcement more effective. The IDEA framework asks a different question: what would it take for people to have enforceable control over personal data. Answering that question serves two goals at once. It gives real substance to fundamental rights, and it fixes a structural market failure that no amount of enforcement can reach on its own.

The current regime leaves the underlying imbalance untouched. Regulators act after harm has occurred. Terms of service are set unilaterally. Consent is nominal rather than meaningful. This is not only a regulation failure. It is a market failure and a governance failure at once, and it calls for a structural response rather than incremental compliance.

The IDEA framework introduces four mechanisms that reinforce each other. People gain verified, portable control over verified personal data through legally recognised trusted third parties. Expert representatives, negotiate on citizens behalf, much as professionals already do in other sectors of the economy. They also owe duties to act in the citizens best interests. And citizens can negotiate collectively, correcting the bargaining asymmetry that individual consent cannot fix.

None of this requires new institutions built from nothing. In Europe, for example, it builds on the GDPR, the Digital Governance Act, and Data Act. It is also aligned with the Digital Omnibus proposal.

The IDEA framework, in the words of our chairs

The IDEA Framework · A proposed architecture for personal data markets
The IDEA Framework, a proposal

In personal data markets, data acts as a form of payment. Citizens cannot negotiate or benefit from its value.

The IDEA framework proposes four connected mechanisms that give people control over their verified personal data, collective negotiation led by expert representatives who owe them duties to act in their best interest. This will transform compliance and accountability into market outcomes.

Dennis Snower  ·  Paul Twomey
Diagram of digital markets, showing an above ground system of priced commerce and advertising sitting on top of a below ground system of barter in personal data.
01  /  The hidden exchange

The digital economy runs on two levels.

The GIDE community describes an above-ground system of transparent commerce sitting on top of a below-ground system of barter. People receive services that are free or underpriced. They pay in the continuous harvesting of their personal data. Because there is no price, there is nothing to compare, and nothing to negotiate.

Above the line and below the line
priced and visible E-commerce Subscriptions Payment for services Collection Profiling Prediction Targeting and monetisation unpriced and largely unseen

Actors below the line of visibility include large social media platforms, AI powered services, digital service providers, data brokers and political actors.

Personal data markets sit almost entirely below the line. That is the part of the market the IDEA framework is designed to correct.

The GIDE community calls this an influencer-funded digital barter. Alternatives to advertising and data monetisation are rare, so businesses that avoid them normally have to charge full price and end up serving a small segment of users. The absence of a visible price stops the market from allocating resources efficiently, and rewards innovation aimed at capturing engagement only.

02  /  The problem

A working market needs three things. Personal data markets have none of them.

There is an economic failure at the core of personal data markets. Personal data works as an implicit currency of digital exchange. People hand it over without price signals, without bargaining power and without effective oversight.

Three structural failures

A market requires control

01

People do not control their personal data

Once data is collected it is copied, combined and analysed beyond the awareness or reach of the person it came from. The same applies to groups, whose shared behaviour is predicted, segmented and targeted.

This exposes people to manipulation. Platforms exploit psychological biases, algorithmic curation amplifies divisive content, and choices are narrowed.

A market requires accountability

02

Data aggregators answer to almost no one

Terms of service are opaque and non-negotiable. Low entry barriers and strong network effects push the sector towards concentration, so people have few alternative providers to move to.

<0.5% Share of reported data breaches under the GDPR that have resulted in a penalty, on figures from published GDPR enforcement surveys.

A market requires protection from asymmetry

03

One side knows everything, the other knows almost nothing

Aggregators hold a detailed picture of individual behaviour. Individuals know little about how their data is processed. A small number of firms control the underlying infrastructure and set the terms for everyone else.

People cannot value their data, verify how it is used, or protect themselves from breaches. The concentration makes the system economically fragile and politically consequential.
03  /  The proposal

Four mechanisms. Each one is the precondition for the next.

The IDEA framework is a closed system in which every part depends on the others. Select any mechanism to see what it supplies and what it cannot work without.

The IDEA framework
Each mechanism is the precondition for the next 01 Control over key personal data 02 Representation by accredited experts 03 Fiduciary duty loyalty, care, transparency 04 Negotiation collective and binding

↻ And back to 01. Negotiation only works on data that can be verified.

Mechanism 01

Effective control over key personal data

"I control my key personal data."

Legally recognised repositories, governed by the person the data is about, hold a defined subset of verified personal data. Registries release it only on request. Every issuance is auditable, revocable and transmitted machine to machine.

Supplies
Depends on

The dependency chain runs as follows: control empowers people but risks reinforcing asymmetries without representation; representation requires specified fiduciary duties; fiduciary duties need collective negotiation to become binding outcomes; and collective negotiation requires verifiable key personal data repositories to function.

04  /  How it works

Who controls what, who owes what, and who agrees the terms.

Select a mechanism to see which relationships it changes.

Actors and relationships
GOVERNMENT BODIES AND INSTITUTIONS Accredits representatives · supervises registries · verifies agreed terms DATA SUBJECT The person the data is about EXPERT REPRESENTATIVE New institutional role DATA AGGREGATOR Collects, combines and processes data KPD REGISTRY Verified, revocable Auditable issuance

Scroll the diagram sideways to see all of it

Registries may be run by public authorities, licensed private entities or consumer cooperatives, all under common regulatory standards. Expert representatives may be non-profit trusts, cooperatives or licensed intermediaries, and must remain independent of data aggregators.

05  /  Mechanism 01 in depth

Key personal data is a small, defined subset. That is what makes it controllable.

The IDEA framework does not ask citizens to control all data points companies have about them. It targets a specific set of personal data points that can be verified by trusted third parties.

Key personal data, or KPD
Test one

It is routinely required for legal, contractual or administrative relationships.

This is the data you have to give to open an account, sign a contract or prove who you are.

Test two

It can be verified by a trusted third party.

Verification is what turns a claim into a credential, and a credential into something that can be issued, withheld and withdrawn.

Examples of key personal data

Full name National identification numbers Passport number Tax identification Financial account numbers Home and email address Telephone number Geolocation Facial images Fingerprints Biometric data Vehicle identifiers Persistent network identifiers

The precise list should be settled through regulatory consultation rather than fixed in advance. In the EU, the final list would be informed by the GDPR, the European Digital Identity framework, the NIS2 Directive and the know your customer and anti money laundering regimes.

Where KPD sits today

Scattered, unverified and bundled with inferences.

1

Fragmented across every platform that has ever asked for it.

2

Accuracy and authenticity are never independently checked.

3

Bundled together with inferred profiles about you.

4

Circulated through processing chains you cannot see.

Where KPD would sit under IDEA

Held in a registry the person governs.

1

Verified once by a trusted registry rather than re-collected everywhere.

2

Issued only on request, and only for the approved purpose.

3

Revocable by the person at any point, not consented to once and forgotten.

4

Transmitted machine to machine, with an auditable record of every issuance.

The legal effect is that KPD processing practices become a continuous, revocable authorisation. It also offers a route out of consent fatigue, since one central act of authorisation can be transmitted automatically instead of being requested again by every site.

06  /  Mechanism 02 in depth

Nobody reads the terms. The IDEA framework proposes someone whose job it is.

The accountability gap is not caused by people being careless. It is caused by an impossible workload. Individuals lack the time, the expertise and the leverage, and regulators cannot monitor everything. The expert representative is the new institutional role designed to close it.

The expert representative
Today

You are on your own.

1

You face terms drafted by specialists and offered on a take it or leave it basis.

2

You have no practical way to assess what the processing actually involves.

3

You have no leverage, because you are one person among millions.

4

You cannot monitor what happens after you click accept.

5

Enforcement, if it comes at all, comes long after the harm.

Under IDEA

You appoint a professional.

1

You give a written, plain language mandate to an accredited representative.

2

They understand the technical and legal environment, because that is their profession.

3

They negotiate on behalf of a group, so the leverage is real.

4

They monitor processing continuously and can revisit agreements.

5

They are bound by fiduciary duties, and answerable for breaching them.

What keeps them honest

Accreditation, oversight and enforceability.

Legitimacy rests on three things: an accreditation process that tests competence and independence, reporting obligations and audits, and sanctions for breach. Representatives must remain independent of data aggregators.

What keeps them competitive

You can leave, and take your mandate with you.

Representatives are paid for the service, which creates a professional market. People would have many competing representatives to choose from and few obstacles to switching between them.

The IDEA framework produces accountability in two directions at once. Vertically, the representative answers to the person. Horizontally, the representative holds the aggregator to the agreed terms. Both reduce reliance on enforcement after the fact.

07  /  Mechanism 03 in depth

Not another disclosure rule. A duty owed to you.

Compliance asks whether a company followed the rules. A legal duty asks whether it acted in your interest. This changes the relationship rather than adding to the paperwork.

Fiduciary duties
01

Loyalty

Act solely in the interests of the person whose data it is, and avoid conflicts of interest.

02

Care

Apply professional competence and genuine awareness of risk, rather than minimum effort.

03

Transparency

Communicate clearly about data practices, including the role played by algorithms.

Expert representatives are always fully bound. For data aggregators, there are two paths.

Path A · The aggregator negotiates

Good faith negotiation produces a presumption of compliance.

Where terms are agreed through expert representatives, those documented terms create a rebuttable presumption that the person's best interests were respected. The presumption stands until a court, arbitrator or oversight body finds the terms were not followed.

Path B · The aggregator refuses

Refusal means being bound directly, and proving it yourself.

An aggregator that will not negotiate becomes directly bound by the fiduciary duty and must independently demonstrate compliance. This creates a strong incentive to negotiate rather than face high threshold, litigation prone statutory obligations.

This conditional structure is not new to EU law. Under the GDPR, controllers using certification mechanisms and approved codes of conduct already benefit from reduced liability and a lighter evidentiary burden. Under the Digital Markets Act, gatekeepers with approved compliance measures or binding commitments can avoid stricter intervention.

08  /  Mechanism 04 in depth

A right you cannot exercise alone becomes real when it is pooled.

The IDEA framework draws experience from labour markets and financial services. Data rights become effective when they are exercised collectively. Grouping people who share similar preferences gives them bargaining strength that no individual has.

Collective negotiation

One person, acting alone

Accept the terms, or do without the service.

Aggregated
mandate

A defined group, represented

Negotiate the terms, with standard conditions applied across the group.

What gets negotiated

Data collection Permitted purposes Use Sharing Retention Transparency Redress Accruing benefits

How a negotiation runs

Stage one

Representation

Experts are accredited to represent a defined group of data subjects, under regulatory oversight.

Stage two

Negotiation

Representatives and aggregators agree processing terms, with arbitration available if talks stall.

Stage three

Compliance

The agreed terms operate as binding standards, carrying a presumption of compliance for firms that adhere.

Data subjects retain the final authority to consent. Smart contracts could carry the agreed standards at scale, encoding purpose limitation, processing restrictions, audit triggers and value sharing, and updating in response to regulatory change.

Real benefits for both citizens and companies

A case that would not have needed reconstructing.

€200m

The fine imposed by the European Commission on Meta over its consent or pay model. The Commission concluded that the model failed to meet the standard for valid consent and did not offer a genuinely equivalent alternative to people who declined to release their data.

Under the IDEA framework, clear and verifiable negotiated terms would have served the people affected, the Commission and the company alike. There would have been no need to investigate interface design or reconstruct user choice after the event. Enforcement could have asked a single question: did the company follow the terms it had already agreed?

Related concerns about consent under conditions of unequal bargaining power have also arisen before the German competition authority and the Court of Justice of the European Union.

09  /  What changes

The point is not more regulation. It is a fully functioning market.

When people can verify, control and negotiate the use of their data, economic actors compete on service quality rather than extraction capacity.

The proposed shift in market equilibrium

Trust and innovation are mutually reinforcing: stable expectations lower the cost of mistrust, better trusted systems receive more accurate data, and smaller firms gain market access through expert representatives.

10  /  The case for each actor

This is not a transfer of burden from companies to individuals.

The IDEA framework realigns incentives across the whole system. Each actor is offered something it currently lacks.

Claimed benefits by actor

Data subjects

  • Unified, verified control over key personal data
  • Professional representation, continuously
  • Terms that can be understood and compared
  • Real bargaining power through the group
  • Rights that are exercised, not just held

Data aggregators

  • A single reference point for lawful processing across Member States
  • Narrower interpretive uncertainty and limited liability exposure
  • Lower compliance and administrative load
  • Fewer challenges to the validity of consent after the fact
  • More accurate data, because trusted systems receive better information
  • Standardised terms that reduce transaction costs

Regulators

  • A clearer supervisory baseline to check conduct against
  • Documented terms, timestamps and agreed conditions
  • Less need to reconstruct intent or interface design
  • A smaller administrative load and narrower disputes
  • More targeted intervention

The digital economy

  • Trust as a driver of innovation and growth
  • Competition on service quality rather than extraction
  • Smaller firms competing on more equal terms
  • Market access for new entrants through representatives
  • Greater democratic legitimacy for digital systems
11  /  Regulatory adequacy in the European Union

The EU would not be starting from zero.

The institutional plumbing largely exists. Enactment would need targeted amendments to several instruments rather than wholesale legislative reform.

The existing EU instruments the IDEA framework builds on
Exists today

GDPR

Regulation (EU) 2016/679

What it already does

Does not oppose collective negotiation of processing terms, and needs no new lawful ground to permit it. Already lets Member States set conditions for national identifier numbers. Already rewards certification and approved codes of conduct with reduced liability.

What the IDEA framework would add

A best interests duty on controllers processing at scale, and a requirement to source key personal data only from authenticated, data subject controlled registries.

Exists today

Data Governance Act

Regulation (EU) 2022/868

What it already does

Recognises data intermediation services and data cooperatives. Cooperatives can already negotiate processing terms for their members and help them make informed choices. Intermediaries must act in members' best interests when supporting their rights.

What the IDEA framework would add

An amendment allowing certain intermediaries to act as expert representatives, with a clean separation from their intermediation functions. Neutrality obligations currently prevent an intermediary from actively representing data subjects. Gatekeepers would be barred from the role.

Exists today

European Digital Identity

Regulation (EU) 2024/1183, amending eIDAS

What it already does

Establishes an EU wide framework for issuing, authenticating and recognising high assurance electronic identities, with cross border interoperability and supervision of trusted identity services.

How the IDEA framework leverages it

Registry obligations would mirror those of Qualified Trust Service Providers: verification, auditability, secure storage, supervisory audits and liability for mis-issued credentials.

Exists today

NIS2 Directive

Directive (EU) 2022/2555

What it already does

Sets cybersecurity duties including identity and access management controls, logging and traceability requirements.

How the IDEA framework leverages it

It supplies the trusted security layer that key personal data registries would operate within.

Exists today

AML and KYC framework

Regulation (EU) 2024/1624 and Directive (EU) 2024/1640

What it already does

Already requires entities to verify sensitive identifiers through a trusted third party, covering name, date and place of birth, nationality, address and identity documents.

How the IDEA framework leverages it

Together with the GDPR and the digital identity framework, it already covers most of what would fall within key personal data.

Exists today

Digital Markets Act

Regulation (EU) 2022/1925

What it already does

Shows that EU law already accepts conditional adjustment of regulatory duties. Gatekeepers with approved compliance measures or binding commitments can avoid stricter intervention.

How the IDEA framework leverages it

It supplies the precedent for the presumption of compliance, and the definition of gatekeepers who would be excluded from acting as expert representatives.

Exists today

Data Act and Digital Services Act

Regulation (EU) 2023/2854 and Regulation (EU) 2022/2065

What they already do

Extend the fairness principle across recent EU digital legislation, alongside the GDPR and the Digital Markets Act.

How the IDEA framework leverages it

Fiduciary duties are presented as building on that established fairness principle rather than importing an unfamiliar concept.

Exists today

ePrivacy Directive

Directive 2002/58/EC, applied alongside the GDPR

What it already does

Governs access to terminal equipment, which in practice produces the repeated consent prompts that people now ignore.

What the IDEA framework would add

A single act of authorisation, transmitted automatically as a stable and auditable preference signal, satisfying both regimes at once and reducing friction between them.

Under negotiation now

Digital Omnibus Proposal

Tabled by the European Commission, 19 November 2025

What it is

A proposal to simplify the existing digital legislative framework, intended to ease business compliance without weakening core EU policy objectives. It already signals a direction towards preference based control.

Status

A proposal moving through the legislative process. Political and institutional pushback from EU institutions and civil society makes substantive redrafting likely.

Under negotiation now

IMCO draft opinion

Internal Market and Consumer Protection Committee, 8 June 2026

What it proposes

A draft committee opinion that introduces data expert representatives, collective negotiation on an aggregated mandate, machine readable negotiated terms and four new articles setting recognition conditions, a good faith duty to negotiate, fiduciary duties and mandate requirements.

Status

A draft opinion of one parliamentary committee. It is not adopted law and its content may change.

Proposed under the IDEA framework

Key personal data registries

No equivalent instrument at present

What would be created

A defined category of key personal data, set by Commission delegated act after consultation, and a duty on organisations above the small enterprise threshold to source it only from authenticated, data subject controlled registries, keeping records that verify the sourcing.

Proposed under the IDEA framework

Standards and supervision

Extension of existing administrative bodies

What would be created

Technical work on machine readable standards for key personal data, an accreditation and oversight body for expert representatives and trusted repositories, and an independent commission to supervise the negotiation framework and report on how the market is working.

12  /  The policy window

A reform process is already open.

Timing matters. The GIDE community considers the IDEA framework and Digital Omnibus to be the next building blocks of human centred digital governance.

How the legislative landscape was built, and where it stands
27 Apr 2016
27 Apr 2016

GDPR adopted

The individual centred foundation of EU data protection. It permits collective negotiation without requiring a new lawful ground.

2022
2022

Data Governance Act, Digital Markets Act, Digital Services Act and NIS2

Data intermediaries and cooperatives are recognised. Conditional regulatory duties are established for gatekeepers. Cybersecurity and identity management obligations are set.

14 Nov 2023
14 Nov 2023

Data Act

The fairness principle is extended further across EU digital legislation.

2024
2024

European Digital Identity and the AML package

High assurance electronic identity is established EU wide. Verification of identifiers through trusted third parties is required across the financial system.

19 Nov 2025
19 Nov 2025

The Commission tables the Digital Omnibus Proposal

A simplification package covering several existing instruments. It opens the legislative vehicle through which elements of the IDEA framework could travel.

8 Jun 2026
8 Jun 2026

IMCO publishes a draft opinion

The committee text introduces data expert representatives, collective negotiation on an aggregated mandate, and machine readable negotiated terms. It is a draft opinion, not adopted law.

Read what the draft opinion actually proposes+
Amendment 32

Defines a data expert representative as a data intermediation services provider recognised to act in a fiduciary capacity, advising and, where mandated, negotiating on behalf of individuals in their dealings with data controllers.

Amendment 33

Defines collective negotiation as negotiation on an aggregated mandate from a defined group, producing standard terms applied uniformly across that group.

Amendment 34

Provides for the outcome to be recorded as machine readable negotiated terms.

Article 32ea

Conditions recognition on independence, expertise, published conflict of interest rules, indemnity insurance and acceptance of the fiduciary duties. It excludes gatekeepers and very large online platforms, and provides for yearly review, a public register and Commission delegated acts on minimum standards.

Article 32eb

Imposes a duty to negotiate in good faith once a mandate is notified, without obliging agreement. Mediation follows after four months and binding arbitration two months later. Micro and small enterprises are exempt. Negotiated terms carry a rebuttable presumption that best interests were respected.

Article 32ec

Codifies the duties of loyalty, care and transparency.

Article 32ed

Requires a written, plain language mandate covering scope, duration, free revocation, cost based remuneration and complaints. Negotiated terms suffice for lawful processing, and the right to negotiate through a representative cannot be waived.

End 2026
End 2026

The EU Digital Identity Wallet enters into force

This strengthens the practical viability of controlling key personal data at source.

What the Digital Omnibus would still need

Addition 01

Complete the representation regime

Confirm the governance of expert representatives and data subject groupings under formal recognition and audit conditions. Add portability of clients between providers. Provide that negotiated terms and encoded preferences prevail over controller side defaults, and that one authorisation satisfies both the GDPR lawful basis and ePrivacy consent for terminal equipment access. Apply the good faith duty to small mid-caps only where they process the personal data of more than 50,000 individuals in the Union.

Addition 02

Extend the fiduciary duty to controllers

Impose a best interests duty on controllers processing personal data at scale. Where a controller refuses to negotiate, it becomes directly bound by the duty and must independently demonstrate compliance.

Addition 03

Introduce key personal data

Define the category, with the specific classes set by Commission delegated act following a consultation coordinated by the European Data Innovation Board with the Commission, ENISA and the European Data Protection Board.

Addition 04

Source it from registries people control

Require companies and public entities, other than micro and small enterprises, to source key personal data only from authenticated, data subject controlled registries, and to keep records verifying that sourcing.

Addition 05

Governance, oversight and evaluation

Mandate the European Data Innovation Board to coordinate guidance on registry governance with the Commission, ENISA and the European Data Protection Board. Establish a multistakeholder working party to set standards for machine readable key personal data and for transmitting terms and smart contracts. Confer audit attributes on the Board to verify sourcing. Extend oversight to cover representatives for vulnerable groups, trusted repositories and their security standards, and whistleblower support. Require the Commission to report periodically on how the regime operates.

13  /  Go further

Read the paper. Follow where the argument is going.