Inclusion of the Personal Data Intermediary
As it was mentionned in the WG on 15/01, opening this issue to discuss the inclusion of the Personal Data Intermediary.
Issue Summary:
This issue proposes the inclusion of the Personal Data Intermediary (PDI) in the Gaia-X conceptual model, highlighting its role in enhancing data sovereignty, user control, and compliance with data protection regulations.
Details:
1. Role and Importance of PDI
- The PDI centralizes the user's control over their data, allowing them to manage consent for data usage by various participants in a data space.
- Designed with human-centric principles, the PDI empowers individuals to grant, manage, and revoke consent for data use, ensuring data sovereignty in the digital age.
2. Use Case Example: Skills Data Space
- An individual logs into a skills portfolio at a university, connected to a data space for job matching services.
- The individual uses a PDI to grant consent for a job matching service to access their skills data.
- The PDI communicates consent to relevant parties (university, job matching service) and oversees data exchange.
- Individuals can manage and revoke consents anytime via the PDI.
3. Impact of PDI in Data Spaces:
- Governance Level: Provides trust and neutrality, independent of data processing or service provision.
- Business Level: Facilitates data space participation and matching of data resources.
- UX Level: Enhances user-friendliness in data management.
- Technical Level: Enables consent-driven data sharing, ensuring compliance with data protection regulations.
4. Key Components of PDI:
- Consent Management: User-friendly platform for managing consent, adhering to international standards like ISO/IEC TS 27560:2023 on Consent Record information structure.
- Catalogue: Navigating data providers and service providers, integrating Gaia-X Trust Framework schemas.
5. Integration in Gaia-X Conceptual Model:
- PDI as a consent management solution, aligning with the conceptual model's focus on data usage consent, discovery, and cataloging.
- Potential roles in data product integration, management, and data transmission logging.
A couple links:
- The slides of the presentation that showed this content during the WG meeting:
- Prometheus-X wip catalog component (in association with the PDI)
- Prometheus-X wip consent management component (basis for the PDI)