Data centers or the individual themselves? The next digital revolution could give data back to the citizen.
Estonia has built one of the most digital states in the world. 3,000 databases, where 130,000 officials monitor 1 million citizens, and it never seems to stop. Our data flows between the registers, the
Estonia has built one of the most digital states in the world. 3,000 databases, where 130,000 officials monitor 1 million citizens, and it never seems to stop.
Our data circulates between registries, government agencies, banks, businesses, and various information systems. This has made life more convenient, but it has also raised a question to which we have not yet paid sufficient attention:
Who owns a person's data, and who should actually have control over it?
In today's digital world, it's common to think of data as something collected by large data centers. Over the years, a person generates a considerable digital footprint: name, addresses, education, professional experience, entrepreneurial activity, assets, transactions, documents, contracts, communications, and dozens of other data fragments.
This data is scattered across different systems.
But another model could exist.
Each person could have their own personal data center
The idea is simple:
Each person could own and control their own digital data space.
This does not necessarily mean a physical server at the person's home.
This could be a secure digital environment — a personal database or a digital vault — which the person accesses themselves and whose usage rights they control.
It would contain the documents and data specific to the individual:
identity documents;
education data;
professional information;
contracts;
documents related to entrepreneurship;
real estate data;
insurance data;
bank documents;
health data;
official correspondence;
permits and certificates;
other digital evidence needed by the person.
The important thing is not just where the data is located, but who decides who can use it.
The state should not own a person's data.
The state naturally needs data to accomplish its missions.
But the need to process data and the question of data ownership or control are not one and the same thing.
If the state needs specific information to make a decision, it could request access to that information.
The person grants this access.
For certain public missions arising from the law, the person's consent would naturally not be required, but even in this case, the person could see what data has been used, by whom, and for what purpose.
This would create a whole new level of transparency.
Currently, the data is fragmented.
The current problem is not just data security.
The problem is also fragmentation.
A person can have dozens of accounts and systems containing information about them. Here's a document, there's another. In one system, there's an old address, in another, a new one. In a third, there's the employer's data.
The person themselves may not even know what information exists anywhere about them.
Even less can it easily control who has access to it.
A personal data space would reverse this logic.
The data would be visible to the individual in one place, and different administrations and companies would be granted, if necessary, access only to the strictly necessary part.
"Just show me what you need."
This could become one of the most important principles of the new data society.
If a person wishes to prove that they are of legal age, the other party does not need to know their date of birth, identification number, address, or other data.
All you need to know is:
"Yes, this person is of legal age."
If a company wants to verify a person's level of education, it is not necessary to send them their entire academic record.
If an administration needs proof of income, the person does not have to send all of their bank transactions.
If a bank needs a specific document, it is given access to that document — not to the person's entire digital life.
This is the principle of the minimum necessary.
Data could circulate, but not people.
Currently, people often have to transport their documents themselves from one place to another.
She downloads a file.
She sends it by email.
She prints it.
She signs it.
She scans it again.
It proves that the document is authentic.
A better system would be one where data flows securely directly from one system to another, with the person's permission.
For example :
"You authorize company X to verify your document attesting to your level of education."
You press a button.
Access is granted.
Once the objective is achieved, access ends.
The person does not have to be the courier of their own documents.
This would also change the way the state functions.
A very interesting link emerges here with the reduction of bureaucracy.
If each person's data were located in their controlled digital space, and if public administrations could, when needed, securely obtain the necessary information, the work of the civil servant could also change.
The official would no longer have to ask the person:
"Please send us a document that the state already actually possesses."
He might ask:
"Do you authorize us to use this document from your data space?"
That's a major difference.
In the first case, the person works in the service of the state's data system.
In the second case, the state's data system works in the service of the individual.
The data center does not need to disappear
This idea does not mean that large data centers would become useless.
Quite the opposite.
The data could continue to reside in highly secure professional data centers.
The question concerns architecture and control.
A data center can be a technical repository, but it is the individual who should remain the controller of their own data.
This is an important distinction.
Just as money can be in a bank while belonging to the person, digital data could also be in a cloud or secure data center, without the person losing control of its use.
Citizens could have access to a "digital safe"
Let's imagine that every European citizen has their own digital safe.
A single, secure place where important documents and evidence are gathered throughout one's life.
A child is born — their digital identity is created.
He goes to school — education data is added.
He obtains a certificate or diploma — this goes into his safe.
He enters working life — professional documents are added.
He creates a company — the data related to his entrepreneurial activity is linked to his digital identity.
He buys a property — the necessary documents are in his digital safe.
He concludes a contract — the contract remains in his controlled archive.
Over the decades, a person builds a digital biography.
Not a digital biography scattered in state files, but a digital vault that the person controls themselves.
This could be the next step for the European digital state
Estonia's first digital revolution made the state electronic.
The next one could make the digital state human-centered.
We should no longer simply ask:
"How can we make government information systems more efficient?"
We should ask:
"How can we give individuals control over their digital lives?"
It's a much broader question.
Because data is not simply a technical resource.
They describe a person.
His life.
His assets.
His work.
His relationships.
His education.
His decisions.
His story.
That is why this principle should be at the heart of a person's digital identity:
My data. My digital vault. My decision about who uses it.
The new data era
We have become accustomed to thinking that what is big is better.
Large data centers.
Large databases.
Large platforms.
Large information systems.
But the next evolution of digital society could take a different direction.
Not all data gathered in one large center, but data controlled by the person, capable of circulating securely, if necessary, between different systems.
The state doesn't need to know everything.
The company doesn't need to know everything.
The bank doesn't need to know everything.
The civil servant does not need to know everything.
Each person should only be able to know what they truly need to accomplish their mission.
And the person should be able to see who is using their data.
This could be Europe's next major digital policy objective.
Not simply to digitize the state.
But to ensure that the digital state remains at the service of the individual, who remains in control of their own data.
Because true digital freedom is not limited to the ability to use online services.
True digital freedom is the ability to control one's own digital life.