Regulatory comparison

Databanking vs. the EU Data Governance Act

Regulation (EU) 2022/868 — the Data Governance Act — is the closest real-world precedent for Databanking. Its Chapter III governs "data intermediation services": neutral custodians of exactly the kind this proposal envisions. Here's where the two already align, and where new legislation would still be needed.

Whitepaper requirementClosest DGA provisionAlignment
1. Prohibition of data analysisArt. 12(a)–(c) — neutrality, no use of data for own purposesStrong
2. Revenue model restrictionsArt. 12(c), (h) — no monetisation outside intermediation feesPartial
3. User income from data accessNoneGap
4. Granular access controlsImplied by Art. 12(c), (f); no technical mandateWeak
5. Transparency & accountabilityArt. 11 (notification), Art. 12(j) (record-keeping)Partial
6. Data portabilityArt. 12(f); GDPR Art. 20Strong (narrower)
7. Security requirementsArt. 12(g)–(h)Strong
Mechanism: sandboxed bit-scarce architectureNoneGap
Mechanism: structural / legal separationArt. 12(a), (d)Strong

1. Prohibition of data analysis

Databanking would bar custodians from analysing user data for their own benefit, technically as well as legally: data and algorithm meet only inside an ephemeral, Databank-internal sandbox, with no separate third party involved — the container is destroyed once a bit-scarce result leaves it.

DGA Art. 12(a)/(c) already imposes the same neutrality obligation as a legal duty — the single closest match in the whole Act. The gap is that the DGA doesn't require the technical impossibility of analysis, only a contractual promise not to.

2. Revenue model restrictions

Databanking would limit custodian revenue to subscriptions and access fees, full stop.

DGA Art. 12(c)/(h) bans self-dealing but doesn't positively enumerate permitted revenue sources the way Databanking does — partial alignment.

3. User income from data access

Databanking proposes a statutory share of access-fee revenue paid back to the individual — a custodial "data dividend".

The DGA has no equivalent. Intermediaries may charge data users fees, but nothing requires passing any of it back to the person the data describes. This is the clearest gap in the comparison, and would need new legislation rather than a reinterpretation of the Act.

4. Granular access controls

Databanking specifies per-requestor, per-purpose, per-query permissions, with the ability to ban specific requestors outright.

DGA Art. 12(c)/(f) requires consent mechanisms in principle but sets no granularity standard — the technical specificity Databanking proposes goes well beyond what's mandated today.

5. Transparency & accountability

Databanking calls for recurring, user-facing transparency reports and independent audits.

DGA Art. 11 requires registration with a competent authority and activity logging (Art. 12(j)), but doesn't mandate the kind of regular, independent compliance audit the whitepaper envisions.

6. Data portability

Databanking treats portability as an unconditional, account-level right — like switching banks.

DGA Art. 12(f) requires "adequate interoperability"; GDPR Art. 20 grants a narrower portability right that excludes inferred data and most non-consent processing grounds. Direction matches; scope is narrower.

7. Security requirements

Databanking requires robust encryption, secure storage, and strong authentication.

DGA Art. 12(g)/(h), read alongside GDPR Art. 32, already covers this ground reasonably well — one of the better-specified areas of the existing law.

Mechanism: sandboxed, bit-scarce architecture

This is Databanking's central technical contribution, and it has no counterpart anywhere in the DGA. The Act is technology-neutral by design — it regulates the legal posture of intermediaries, not how (or how little) data is disclosed per query.

Mechanism: structural / legal separation

DGA Art. 12(a)/(d) already requires intermediation services to be a legally distinct entity from any other business a provider runs, with independent pricing. This is the Act's most direct anticipation of Databanking's thesis — and the provision the whitepaper itself cites as the closest existing precedent. The catch: the DGA does not impose a universal obligation on large personal-data holders to become data intermediation services; rather, it regulates actors that choose to provide such services. Databanking, by contrast, envisions mandatory reclassification for anyone holding personal data at scale.

Overall: a registered DGA data intermediation service is already most of the way to being a Databank in the legal sense. The two largest open gaps — no statutory data dividend, and no mandated sandboxed architecture — would need new legislation layered on top of the DGA, not a reinterpretation of the existing text.

← Back to the concept overview