Data back into human hands
The Estonian e-state should return data to the citizen: the person should be the owner of the data, not the content of the state server.
Data back into human hands
The next development of the Estonian e-government should not be a new registry, a new interface, or a new convenience service. The next development should be the opposite: bringing data back under human control.
Sensitive data does not have to reside in the convenient central systems of the state by default. It can reside in an encrypted data repository controlled by the person themselves — be it a data safe linked to an ID card, a digital wallet with a security chip, or another personal data carrier. The idea is simple: the state should not keep everything about a person just in case.
If an official wants to see data, they must request access. If a court wants to open a document, there must be a visible trace. If the police or other authority uses the legal right to view data without consent, it must be verifiable later by a human and an independent auditor.
The current model treats the citizen as the data source. A more correct model would treat the citizen as the data owner.
E-government should not mean that a person's life is scattered across state servers. E-government should mean that a person controls who uses their data, for what purpose, and for how long.
Yes, in some situations the state must have emergency access. But emergency access must not be a convenient back door. It must be visible, justified, time-limited, and later verifiable. Any “I looked because I got it” type request should be punishable, not tolerated by default.
Estonia has created a situation where data collection has become an ideology in itself. Everything is collected, everything is interfaced, everything is automated, and then it is called innovation. In reality, it is often just digital greed.
The entire data kingdom should be based on one simple rule:
Data doesn't have to be collected just because it's technically possible.
If the state wants a person's data, it must be able to answer three questions:
What are they needed for?
Why can't they be kept under the person's own control?
What happens if they leak?
If there are no honest answers to these questions, then there is no need for a new database. Then it is necessary not to collect the data.
Because data protection is not when the state promises to keep all your secrets locked away.
True data protection is when the state doesn't need these secrets at all.
