Regulation (EU) 2022/868 — the Data Governance Act — is the closest real-world precedent for Databanking. Its Chapter III governs "data intermediation services": neutral custodians of exactly the kind this proposal envisions. Here's where the two already align, and where new legislation would still be needed.
| Whitepaper requirement | Closest DGA provision | Alignment |
|---|---|---|
| 1. Prohibition of data analysis | Art. 12(a)–(c) — neutrality, no use of data for own purposes | Strong |
| 2. Revenue model restrictions | Art. 12(c), (h) — no monetisation outside intermediation fees | Partial |
| 3. User income from data access | None | Gap |
| 4. Granular access controls | Implied by Art. 12(c), (f); no technical mandate | Weak |
| 5. Transparency & accountability | Art. 11 (notification), Art. 12(j) (record-keeping) | Partial |
| 6. Data portability | Art. 12(f); GDPR Art. 20 | Strong (narrower) |
| 7. Security requirements | Art. 12(g)–(h) | Strong |
| Mechanism: sandboxed bit-scarce architecture | None | Gap |
| Mechanism: structural / legal separation | Art. 12(a), (d) | Strong |
Databanking would bar custodians from analysing user data for their own benefit, technically as well as legally: data and algorithm meet only inside an ephemeral, Databank-internal sandbox, with no separate third party involved — the container is destroyed once a bit-scarce result leaves it.
DGA Art. 12(a)/(c) already imposes the same neutrality obligation as a legal duty — the single closest match in the whole Act. The gap is that the DGA doesn't require the technical impossibility of analysis, only a contractual promise not to.
Databanking would limit custodian revenue to subscriptions and access fees, full stop.
DGA Art. 12(c)/(h) bans self-dealing but doesn't positively enumerate permitted revenue sources the way Databanking does — partial alignment.
Databanking proposes a statutory share of access-fee revenue paid back to the individual — a custodial "data dividend".
The DGA has no equivalent. Intermediaries may charge data users fees, but nothing requires passing any of it back to the person the data describes. This is the clearest gap in the comparison, and would need new legislation rather than a reinterpretation of the Act.
Databanking specifies per-requestor, per-purpose, per-query permissions, with the ability to ban specific requestors outright.
DGA Art. 12(c)/(f) requires consent mechanisms in principle but sets no granularity standard — the technical specificity Databanking proposes goes well beyond what's mandated today.
Databanking calls for recurring, user-facing transparency reports and independent audits.
DGA Art. 11 requires registration with a competent authority and activity logging (Art. 12(j)), but doesn't mandate the kind of regular, independent compliance audit the whitepaper envisions.
Databanking treats portability as an unconditional, account-level right — like switching banks.
DGA Art. 12(f) requires "adequate interoperability"; GDPR Art. 20 grants a narrower portability right that excludes inferred data and most non-consent processing grounds. Direction matches; scope is narrower.
Databanking requires robust encryption, secure storage, and strong authentication.
DGA Art. 12(g)/(h), read alongside GDPR Art. 32, already covers this ground reasonably well — one of the better-specified areas of the existing law.
This is Databanking's central technical contribution, and it has no counterpart anywhere in the DGA. The Act is technology-neutral by design — it regulates the legal posture of intermediaries, not how (or how little) data is disclosed per query.
DGA Art. 12(a)/(d) already requires intermediation services to be a legally distinct entity from any other business a provider runs, with independent pricing. This is the Act's most direct anticipation of Databanking's thesis — and the provision the whitepaper itself cites as the closest existing precedent. The catch: the DGA does not impose a universal obligation on large personal-data holders to become data intermediation services; rather, it regulates actors that choose to provide such services. Databanking, by contrast, envisions mandatory reclassification for anyone holding personal data at scale.