Decoupling data custody from analysis

Put your data in a Databank. Not in everyone else's systems.

Today, every company you deal with ends up holding a copy of your data. The databanking model proposes a regulated custodian — a Databank — that holds it instead, and answers questions on your behalf without ever handing over the underlying record. You stay the owner. Everyone else gets an answer, not your file.

The problem

Money can only be spent once. Data can be copied forever.

When you hand over a password, a payment, or a date of birth, you don't transfer it the way you transfer money — you surrender control of something infinitely reproducible. Once copied, it can be sold, merged, retained for decades, or lost to a breach, and there is no way to take it back.

Diagram comparing the conventional model, where raw personal data flows directly from a user to a company, with the Databanking model, where a Databank sandbox sits between the user and the company and only a bit-scarce result crosses the boundary.
Left: data handed over directly is gone for good. Right: a Databank answers the question instead of forwarding the file.
How it works

Four principles, one structural separation

The whole proposal rests on keeping data custody and data analysis in different, legally separated hands — enforced by regulation, not by a company's good intentions.

1

Custodial separation

A Databank can hold your data but never analyse it for its own benefit — that's someone else's business, kept structurally apart. It profits from subscriptions and access fees, never from what it stores.

2

Bit-scarce answers

Anyone wanting to know something about you submits a question, not a data request. They get back one to four bits — "yes", "over 18", "sufficient funds" — never the underlying record.

3

A data dividend

When someone pays to query your data, you get a statutory share of that fee. Monetisation and privacy stop being opposites.

4

Real portability

A standardised account format means moving your entire data holding from one Databank to another is as mechanical as switching banks today. No lock-in — Databanks compete on service and on the terms they offer you, not on how hard you are to leave.

In practice

A retailer wants to know if you're over 18. Here's what actually happens.

No date of birth ever leaves the Databank — only the answer to the one question that was actually asked.

  1. 1
    DepositYour date of birth sits encrypted with your Databank — nobody else holds the key.
  2. 2
    QueryThe retailer submits an algorithm — "is this person over 18?" — not a request for your file.
  3. 3
    ExecutionYour data and the retailer's algorithm meet only inside the sandbox, briefly, and never anywhere else.
  4. 4
    ResultOne bit crosses the boundary: eligible: true. No birthdate, no margin, no extra context.
  5. 5
    AuditYou see exactly who asked, what they asked, and what they got back — and you're paid a share of the fee.

Walk through the full example, with pseudocode and the bit-budget math →

Use cases

Where this changes the default

A representative sample, not an exhaustive list — more use cases will likely emerge once the underlying infrastructure exists.

Online shopping & shipping

Sellers get an opaque delivery token, never your actual address — only the carrier resolves it, through a secure channel with your Databank.

Authentication

Prove who you are, or that you're old enough, without handing over an ID document or a real email address.

AI & research

Models are brought to the data and run inside the sandbox, rather than the data being exported to wherever the model lives.

Credit-worthiness

Lenders get a qualifying decision, not your entire financial history — closer to how a soft credit check already works, but enforced rather than voluntary.

Online advertising

Advertisers buy audience matches, not your browsing history. A redesigned, opt-in browser routes your navigation data to your own Databank instead of to third-party trackers, and sites query it directly from there, for a fee shared with you.

Taxis & ride hailing

Pickup and destination appear on the driver's dashboard only for the duration of the ride. Afterwards the operator keeps just the date, the fare, and a link token — enough for an auditor to ask "did this ride take place?" or for a return-trip discount, both yes/no answers. Your movement history lives in your Databank, not theirs.

Read the full case study →

Health data

Cross-sectional health research keeps working — researchers and providers query within strict, audited limits, opted into separately — but no individual has to hand the same raw record to every hospital, insurer, and study that wants a piece of it.

Read the full case study →

Age assurance

UK Online Safety Act age checks currently mean showing an ID or a face scan to every platform separately. Verify once with your Databank instead, and each platform gets only the threshold answer it actually needs — "over 18: yes" — never the document.

Read the full case study →

The right to be deleted

Asking a data broker to erase your data today means handing them that very data so they can find your record. Under Databanking, a broker gets only a deliberately lossy fingerprint — useless for reconstruction — plus a token to ask the sandbox "does this record match this user?". One bit comes back; a match triggers deletion.

Read the full case study →

Not entirely new

Pieces of this already exist — just not put together, and not by law

Apple's Hide My Email and iCloud Private Relay, tokenised age checks from providers like Yoti, and the soft credit check your bank runs before pre-approving you all narrow what crosses an organisational boundary. None of them generalise the idea across every kind of personal data, make it a legal entitlement, or share the resulting revenue with you. The EU's Data Governance Act comes closest on the regulatory side — close enough that it's worth a dedicated comparison.

See exactly where EU law already matches this proposal, and where the gaps are →