The whitepaper stays deliberately concise. The questions below arise every time the proposal is discussed, so they get a proper answer here instead of crowding the paper itself.
Yes, in the same sense that a bank is an attractive target because it holds money. The comparison that matters isn't "Databank vs. nothing," it's "one regulated Databank, audited and insured against breach" vs. "the same data already scattered, today, across thousands of companies with wildly uneven security practices." Databanking doesn't remove concentration risk — it replaces uncontrolled replication risk with regulated custodial risk, the same trade-off banking made with money centuries ago, with most of the relevant playbook (operational security, fraud detection, disaster recovery, regulatory audit) already worked out and ready to port across.
Most people won't, and shouldn't have to. Databanks would offer a small set of permission templates — something like Maximum Privacy, Research Friendly, Healthcare Friendly, Advertising Enabled, Revenue Maximising — and most users would simply pick one and move on, the same way most people pick a bank account tier rather than negotiating its terms line by line. Anyone who wants granular, per-Requestor control still has it underneath the template, exactly as banking apps, LinkedIn, and most cloud platforms already expose both a simple default and an advanced settings panel for people who want it.
This is exactly the kind of query Databanking is built for, and it's a good concrete illustration of the model. Today, "know your customer" (KYC) checks mean every company you sign up with collects and stores its own copy of your face and your ID document — a live biometric and a government document, duplicated across every bank, dating app, and gig platform that asks for one. Under Databanking, the company instead queries your Databank account: it gets back a verified-identity link or token — "this is a real person, the document matches the face, here is a verification reference" — not the video or the document image itself. The company never holds your mugshot or your licence scan; it holds a pointer to a verification that your Databank performed once and can re-attest whenever a new Requestor needs it. One verification, reused everywhere, instead of the same sensitive biometric file copied to every company that happens to ask for it.
Yes, and it's arguably the strongest near-term application of the model. Platforms now have a live legal duty to check users' ages, and regulators are actively enforcing it — but every platform currently runs its own check from scratch, meaning the same ID document, face scan, or card gets handed to a different company each time. Under Databanking, the age fact is established once with a regulated custodian, and every later platform receives a yes/no predicate instead of the underlying evidence. Databanking doesn't replace the underlying verification methods regulators require — it replaces the need to repeat them on every platform. See the age-assurance case study for the regulatory detail.
Probably not much per transaction — likely fractions of a cent or a penny per query, not a meaningful one-off payout. The model doesn't depend on any single payment being large; it depends on frequency, scale, and automation. The closest precedent is digital advertising itself, where individually tiny per-impression values aggregate into one of the largest revenue pools in the economy — the difference under Databanking is that a share of that flow reaches the person the data describes, rather than all of it staying with the platform. Sizing this properly — against existing ad-tech, data-brokerage, healthcare data, and research-access markets — is future work, not something the whitepaper claims to have already calculated.
No — it changes the access path, not whether lawful access exists. Today a warrant or equivalent legal instrument is usually served directly on whichever company happens to hold the data. Under Databanking it would be served on the Databank instead, through a single regulated access mechanism rather than an ad hoc one per company. Because every Databank already logs every access to an audit ledger, lawful requests become more accountable and traceable than today's fragmented landscape, not less.
Not directly, no. Some categories of data — credit, medical, and criminal history among them — are owned but not directly editable: the Owner cannot unilaterally delete or mask part of the record. What ownership does guarantee is visibility and accountability: Owners can see this data in full, together with an audit trail of how each entry was generated, and can flag errors or request corrections through their Databank. That's already a meaningful improvement over today's credit or medical histories, which are largely opaque to the individual and come with no audit trail at all.
You could, in the same sense you could keep your savings in cash under a mattress instead of in a bank account. Custody alone was never really the service a bank — or a Databank — provides. What you'd be giving up is authentication, guaranteed availability, portability between providers, dispute resolution, regulatory compliance, statutory compensation handling when someone pays to query your data, and key recovery if you lose access. A Databank is closer to a financial institution than to a storage device, and self-hosting remains a valid option for anyone who only wants the storage part.
Several mechanisms handle this without needing a single, universal answer. Data can sit in a joint account, shared by the relevant parties under rules they agree on. It can be ceded to one of the parties, who becomes the sole Owner of record. It can be transferred to the Databank account of an entity rather than an individual — a company, a charity, a trust — when the data properly belongs to that entity rather than to any one person. And ownership itself can be transferred between accounts as a discrete event: the data plus its access restrictions packaged together as a single object, with a hash of that package recorded on a blockchain as a tamper-evident record of who owned what, and when, without putting the data itself on-chain.
Public-by-design content fits the same model with one extra setting. A video, like any other data, sits in its creator's Databank account, but with public access permissions instead of restricted ones. A third party — a subsidiary or contractor of the Databank, playing the role a video platform plays today — accesses and streams it on request, paying a micropayment per view that's shared with the creator. The difference from today's model is who gets paid and how: instead of Alphabet monetising the view through inserted advertising, the Databank ecosystem monetises it directly through the access fee, with a share flowing back to the person who made the content.