Today, every company you deal with ends up holding a copy of your data. The databanking model proposes a regulated custodian — a Databank — that holds it instead, and answers questions on your behalf without ever handing over the underlying record. You stay the owner. Everyone else gets an answer, not your file.
When you hand over a password, a payment, or a date of birth, you don't transfer it the way you transfer money — you surrender control of something infinitely reproducible. Once copied, it can be sold, merged, retained for decades, or lost to a breach, and there is no way to take it back.
The whole proposal rests on keeping data custody and data analysis in different, legally separated hands — enforced by regulation, not by a company's good intentions.
A Databank can hold your data but never analyse it for its own benefit — that's someone else's business, kept structurally apart. It profits from subscriptions and access fees, never from what it stores.
Anyone wanting to know something about you submits a question, not a data request. They get back one to four bits — "yes", "over 18", "sufficient funds" — never the underlying record.
When someone pays to query your data, you get a statutory share of that fee. Monetisation and privacy stop being opposites.
A standardised account format means moving your entire data holding from one Databank to another is as mechanical as switching banks today. No lock-in — Databanks compete on service and on the terms they offer you, not on how hard you are to leave.
No date of birth ever leaves the Databank — only the answer to the one question that was actually asked.
Walk through the full example, with pseudocode and the bit-budget math →
A representative sample, not an exhaustive list — more use cases will likely emerge once the underlying infrastructure exists.
Sellers get an opaque delivery token, never your actual address — only the carrier resolves it, through a secure channel with your Databank.
Prove who you are, or that you're old enough, without handing over an ID document or a real email address.
Models are brought to the data and run inside the sandbox, rather than the data being exported to wherever the model lives.
Lenders get a qualifying decision, not your entire financial history — closer to how a soft credit check already works, but enforced rather than voluntary.
Advertisers buy audience matches, not your browsing history. A redesigned, opt-in browser routes your navigation data to your own Databank instead of to third-party trackers, and sites query it directly from there, for a fee shared with you.
Pickup and destination appear on the driver's dashboard only for the duration of the ride. Afterwards the operator keeps just the date, the fare, and a link token — enough for an auditor to ask "did this ride take place?" or for a return-trip discount, both yes/no answers. Your movement history lives in your Databank, not theirs.
Cross-sectional health research keeps working — researchers and providers query within strict, audited limits, opted into separately — but no individual has to hand the same raw record to every hospital, insurer, and study that wants a piece of it.
UK Online Safety Act age checks currently mean showing an ID or a face scan to every platform separately. Verify once with your Databank instead, and each platform gets only the threshold answer it actually needs — "over 18: yes" — never the document.
Asking a data broker to erase your data today means handing them that very data so they can find your record. Under Databanking, a broker gets only a deliberately lossy fingerprint — useless for reconstruction — plus a token to ask the sandbox "does this record match this user?". One bit comes back; a match triggers deletion.
Apple's Hide My Email and iCloud Private Relay, tokenised age checks from providers like Yoti, and the soft credit check your bank runs before pre-approving you all narrow what crosses an organisational boundary. None of them generalise the idea across every kind of personal data, make it a legal entitlement, or share the resulting revenue with you. The EU's Data Governance Act comes closest on the regulatory side — close enough that it's worth a dedicated comparison.
See exactly where EU law already matches this proposal, and where the gaps are →