Submind YouTube summaries
Thumbnail for PDP-Connect / PDPP working sessions - 2026/08/27

PDP-Connect / PDPP working sessions - 2026/08/27

Watch on YouTube

Video summary

The working session led by Art of the Vanna Foundation focused on establishing a robust governance framework for the Personal Data Portability (PDP) standard, with the goal of gathering expert feedback before a public comment period begins in September. The proposed structure separates management from technical execution by creating an elected board to oversee long-term strategy and status grants, while a technical committee handles the review and merging of specifications. This governance model distinguishes between "supporter" tiers for those with ideological interest and "partner" tiers requiring actual technical implementation, ensuring that membership reflects active contribution rather than just support. Additionally, conformance is treated as a distinct concept from membership to avoid mandating it, allowing entities to demonstrate adherence to the standard without necessarily registering or receiving operational permissions. A critical discussion centered on balancing the need for control with the risks of creating barriers to entry, particularly regarding how official data sources like OpenAI might reject unauthorized connectors. To prevent treating data portability as an attack and to avoid demoralizing smaller businesses, the group proposes a tiered architecture featuring "Verified Sources" for high-risk entities, "Accessors" for lightweight integrators often used by SMEs, and "Operators" who maintain core system compliance. This approach aims to provide a legitimate pathway for data access while ensuring safety and accuracy through a streamlined verification process that includes ongoing compliance checks, potentially utilizing annual attestations similar to EU standards rather than relying solely on initial sign-ups. The session also addressed the broader regulatory landscape and adoption strategies, noting the European Union's stable environment under GDPR as a starting point while observing the United States moving toward a "data utarchy." Participants debated how to encourage global adoption by addressing specific pain points such as medical data ingestion for AI models, emphasizing that raising standards is difficult once established but essential to prevent large entities from settling for low-tier compliance. The ultimate goal is to create social pressure where high-standard adoption by major players compels others to follow suit, ensuring the standard remains open enough for regulatory acceptance while maintaining its integrity against the risk of fragmentation or low-quality implementations. Looking ahead, the group plans to present a draft governance document at GDC for public comment before locking in specifications by October, with a timeline to determine the legal personality of the governance body within a year via LFDT labs. The strategy involves seeking independent reviews from governments, particularly in developing nations, and gathering feedback through GitHub or direct meetings to refine the framework. By combining bottom-up interest building with top-down regulatory encouragement, the initiative seeks to create a scalable model that supports global adoption without compromising on security or the open nature of the standard, ensuring that the PDP ecosystem can evolve sustainably as legal structures within the Linux Foundation are formalized.
Read the full video transcript
Hello. Um, it's Art here who is the managing director of the Vanna Foundation and I think I'm in charge of uh this session. Um, apologies for my delay. I was uh trying to log in here. I'm currently in the Kingdom of Bhutan. So um really excited for folks to be joining this session. I'm going to um share my screen so that we can start talking through some of the uh working parts of this. Uh but before I do um I will wait a couple of minutes because it does take some sometimes it takes a bit of time for people to join. Um and in that couple of minutes awesome. I see Drummond on here. Justin, hello. and then somebody dialing in. >> Hey Dr. How you doing? >> Good. I finally made it to one of these. Uh it's >> excellent. >> It's been um crazy uh you know this is the last week before GDC and I got back from New Zealand last weekend. [clears throat] So I was like ah crazy week. >> Well I'm glad you I'm glad you're able to join. Um, I was just telling the folks that um I'm calling in from the Kingdom of Bhutan right now. Um, I wish I could show you these wonderful mountains that I have here to my left. >> Seriously? >> Yeah. If my internet drops in or out or I'm a little bit slow, that's that's probably it. >> Where are you in Bhutan? >> Uh, I'm in um Tempu, which is the capital. Yeah, it's I've only been there once, but we the uh uh we went to Tempo on for for for two days uh at the end of it. It was after the Bhutan Innovation Forum. Have you been to Bhutan before? >> No, this is my first time and um I have uh I've managed to get some time to explore a little bit, but I definitely have to come back because I have to leave tomorrow. So, I will um uh I'll come back. It's a big country. Is it are you you know visiting or are you is it business? >> Um so we um I was invited to be here by uh Yeezy Labs um uh so um Binance's lab Binance's um uh investment arm. Uh they uh invested in VA earlier on um and so they're concluding a cohort of um folks that have they've been incubating here for the last five weeks. Um, and so there's a bunch of folks like me who have just flown in um to see the work that they've done um to help some of their their uh their startup founders and to see what we can do next for them. But honestly, it was um it was such a surprise coming here um getting the invite first of all, but then coming here and just not knowing what to expect and then seeing such a very different country which is really really cool. Um and then I yesterday had the chance to go run up the mountains a little bit, went on a morning run and it's absolutely stunning. Hey Karen, how you doing? >> I am doing fine. How are you doing? >> I'm very well, thank you. I was just catching Drummond and Justin folks up on the fact that I'm calling in from Bhutan of all places. Um on my way to GDC, but um I had to stop over here. >> Are you uh seeing any folks from the National Digital Identity uh uh program, NDI? >> Not not um not here on this trip. No, I'm really stuck into this um convergence forum. Um, but I do have to, that's why I've got to come back. There's a lot of really interesting um, tech work happening here. But I think there's a lot of just interesting society work happening here. I was um, speaking to one of my mates who um, does a a program around mindfulness in schools. Um, and it it's like a different education kind of pedagogy or system where they they teach compassion first and lessons later. Uh, and I think it's a there's some really interesting stuff that I definitely need to come back here for. Next next trip, I've got to I got to make my way over to to Geneva, which I'm sure you and Karen are also heading over. Justin will also be there. Justin Slaughter um he's a he's a good friend of mine. We've been working for many years together, but he'll also be on the panel with us next week. Um, and I'm uh I'm excited to actually put this standard out there for public comment. Um, so I I don't want to take up too much of your time, but I want to be able to walk through this session. Um, this session is focused on governance, which is why I'm running it. Um, and uh, the point of this session is just to start to get some feedback around how we're thinking about governance, start to poke holes in it. um with a view to being able to set a um uh next week to have this governance piece of the standard out there ready for public comment. So I kind of want to get um top eyes on it right now to see what you guys would say about it. Um and then I'll go through a presentation just because I think it'll be easy for us to walk through about how we're thinking about governance and some of the different pieces. Amazing. Cool. Thank you, Dr. I will make sure that I blast through some of the bits and then >> I don't want to rush you or all. I just it's just that's just a situation I had tonight and I haven't made any of these meetings so I wanted to at least come to as much of this one as I could. >> Appreciate it. Um and and obviously like this is going to be recorded and we're going to send it out to the community as well and there's going to be opportunities for you all to to comment on it. And I guess I'll say the last bit first, but what we're doing in these presessions is trying to get as much expert advice and opinion in on the standards, the the the the draft standards so that when it goes out to public comment, we have something that's a little bit more firm. And the plan is that at GDC we actually launch the draft period um the comment period uh and have that close in around October. So, we'll run a 4-week public commentary period where we're going to circulate it to a wider audience where we're expecting to get some more feedback. So, your initial feedback is obviously incredibly important to us, but this isn't the only opportunity that you'll have to provide feedback either informally or formally on this standard, and I was going to cover that in the end, but I just wanted to set that out at the start. Um, so this is going to be a little bit dactic at the start, but I do um if you do have any questions or anything you want to um pop into um the the chat, feel free to. Um can everyone see my screen first of all? Perfect. So this section this session is going to really cover governance, membership and conformance. Um and I'll talk about why we've split it up into those three areas um uh as part of the introduction. And again, this is uh with a view to creating the the pre-conultation draft. Um and then the formal public review will open on the 3rd of September when we launch as a GDC and it'll close on the 1st of October. So um I think everyone here is either governance or governance adjacent which is amazing. So I don't really have to explain why governance of a standard is important, but just for the folks who may not be um as versed on why governance is important. Um you can set a standard, you can set a protocol, but getting people to adopt it, maintain it, and use it is something that you need to think about when you're setting up the protocol. And so within the context of PDP, we have this um durable specific record that allows people to move their personal data. Um and that's been scoped out by um Tim and Anna on the technical side. But on the governance piece um we need to think about a way to actually get adoption of this more broadly if it's going to be a ubiquitous standard. How this interacts with other existing standards and standards defining bodies and how we continue the growth and development of this as the world of AI and the world of portable data continues. So that's essentially what the scope of this discussion is. it's how do we continue uh how do we get this standard adopted and then how do we continue um with uh with the growth of this standard. So as I mentioned at the start we've separated things out into governance, membership and conformance. And the reason why we've kept that in that way is because governance for me defines how this standard continues um and is able to be maintained in the long term, how it functionally operates. membership solves a problem of how do we actually get people to adopt this standard at a global scale which we we we kind of need for anything relating to kind of personal data and this kind of societal change that we want to drive from PDP and from VA and so um I'll set out what I think is going to help with adoption there and I'd love feedback on that in particular from you Drummond and you Karen who've seen this and seen adoption of standards as well and um uh I'd love to get some of your experience um to bear on that. And then conformance is the piece that I wanted to separate out and it it it kind of boils down to this. We're setting an open source standard out just because um you are um the the program having membership under this program or being Oh, Lisa, hello. I was just um uh just going through the deck. Um I'll catch you up. Um there's just to catch you up. I'm in Bhutan. Apologies if my internet drops out because I'm in Bhutan. Um but um the point of this is basically to set through set set out like how we're thinking about adoption and governance of PDP. And um I'll just go back to this slide because I think it's important just for framing splitting it up into three kind of um buckets for me. Governance which looks at the longevity of PDP and how it's able to respond to things as well as how it relates to other protocols. Membership is how we look at adoption and how we try to get global adoption of a standard. And then conformance is the piece that I wanted to separate out there because in setting out an open source standard, you kind of don't want to mandate membership as conformance. Conformance operates um separately from that and conformance status is not permission to operate. We set the standard out so that people can aspire to achieve it. Um whether or not they want to register their um achievement is something that should be separate from that process. And that's just like philosophically how Anna and I are aligned on this. We would rather folks go and try to achieve this standard versus try to gain some sort of membership or incentive program to try to get into a PDP stamp. Um I'll go through um each of these in turn um and then we can kind of work through that. As I said at the start, if you want to interrupt, feel free to just type a message in and hop off mic. Or if you just want to interrupt, that's totally fine. Um and there's obviously the opportunity to comment on it um in uh in a more formal way on um on GitHub or in um go to pdbv.dev as well. Um so the structure I wanted to stick with uh this is the governance piece. I really wanted to stick with something that was really um light at least at the start and something that could grow. Um, so the long-term structure that we're envvisaging is some sort of board or steering committee with an elected chair that does, I guess, most of the grunt work associated with maintaining things like the register and maintaining some of the administration associated with PDP and implementation. Um, I chose five, maybe it should be three um for the kind of committee structure. That's all configurable. Um, the register piece of it is really important. Um I know folks here who've run registries or run run run registers. It is not an easy job. You are constantly trying to maintain something where people are applying and moving through it. That's why we needed somebody on the committee level who's responsible for actually operationalizing this. And then I wanted to separate out the technical committee um for the reason that um there are going to be things that the technical committee can do in relation to PDP as a standard that should be separated from the pieces relating to membership um and conformance which should be um done by the body that kind of governs this entire standard. So just in brief what each does is the board sets the conformance criteria the currency rules grants and withdraws status here is appeals appoints the technical committee and represents the program to the Linux foundation an LFDT. The chair is the operator of the board. Um sits on the board but also makes sure that all of the the the pieces of the project continue to function. And the technical committee um reviews the submissions in public recommends. They're the ones who are um looking at pull requests in GitHub. They're the ones that are looking um at compliance relating to the data connectors. Um and but they're they're because they're the ones also setting those compliance standards. uh they're they're making a recommendation to the board versus actually making those decisions. That's again something that I'm kind of questioning whether that's the right approach. Um open to thoughts and ideas on that before uh oh yeah I'll go to how each is constituted and then we'll pause here and I'd love some comments on just the governance piece of this. So um board elected by partners um and we'll talk about what a partner is. One organization, one vote. A partner is basically a member um who uh has implemented part one part of PDP. Um the chair is elected by the partners as well. They will just have a special voting system for the chair. Um and then the technical committee is actually appointed by the board. And and why I think that's also important is there needs to be some longevity in the techn committee. It would be the folks that uh like Tim and Anna who um are deeply technically involved in the idea of data portability and who see themselves as having more than just a two-year tenure and seeing this through as a project that evolves. So the technical committee is actually really the heart of the project because they're the ones who are really thinking about data portability in the arc of how it relates to AI whereas the board and chair is really just the management piece that allows this to kind of be adopted. Um just to kind of articulate that a little bit further, uh the technical committee approves and merges the specification. The board will uh publishes the versions on the site. Um the technical committee approves and merges um the the review standard. The board will set the criteria. The technical committee reviews and recommends the conformance submissions. The board will grant or refuse it um on whatever grounds. um the technical committee decides on codes, views and extensions. The board has no role in that. And then the membership terms, appeals and committee membership that's really at the board level. So you can almost think of this as like kind of a CTO COO kind of a function um in in a traditional organization. Um so that we have that kind of separation of powers and the ability to set technical standards that are um I think more longer term than anything that the board wishes to kind of um advocate for in the short term. Um, membership is the next kind of topic that I wanted to talk through, but let's go back to governance and see if you guys have any comments on what you what you've seen work from a structuring perspective to ensure the the longevity and continuation of an organization. And and as I said, I tried to keep this as simple as possible. >> Open to comments. >> One question, are you envisioning any financial um support? because if if you look at the any kind of financial support for the organization itself then who is authorized to sign and pay for things? >> Um I think as an LFDT lab um any membership or financial um dues need to be um at the LFDT level. Drummond, you can correct me if I'm wrong on that. Um I my assumption is that um all of that needs to happen at the LFDT level. Um I'm not envisioning anything I'm envisioning this to be completely voluntary at this stage and maybe it will evolve into something different and something more after that but um at at least for the first iteration or first round >> um yeah I'm I'm envisaging voluntariness um Drummond. Okay. Because >> No, go ahead, Karen. Finish. >> I mean, I I was just thinking, I mean, if there's any kind of contracts, who's authorized to sign them? >> Um, >> you know, all all those >> things that go behind making something work. Uh, well, if you're going to set up an [clears throat] organization as part of the governance structure, you need to think about so, you know, the board can approve and and the uh whoever the chair is authorized to sign, >> you know, things like that. That's a great point, Dr. What works in terms of legal personality for some of the other labs or projects at LFTT? >> Well, that's that's the reason that was the question I was going to ask. Um, so, um, you know, [laughter] having done this stuff at LF for, you know, like 15 years now. Um, there's three classes of projects at LF. There's open source projects, there's open standard projects, JDF, joint development foundation, and then there's this third a couple examples of these governance projects um of which I'm not involved with any just aware that they have played with a couple of those. Um and so that was going to be my my question. Uh an LFDT labs project is an open-source project for the code. Um, so I'm I'm as I'm wondering so what is the uh the going to be a home for the standard? Is that going to be a community spec or a working group uh or a project? And then this kind of governance is might fit that governance body. But what are you envisioning um is the actual legal home for uh the board, the organization? >> Those are excellent questions. Um the where we're at with LFDT is it's uh draft it's it it exists as a lab with a view to creating a community spec. But what that doesn't cover is how that community spec is rolled out and governed and then implemented. >> Right. >> Um I haven't been in that discussion yet with Daniela and the folks there and I'm very open to taking advice. Um you you mentioned that there are a couple of other projects that are kind of in this third category. Do um do you know who they are? I'll write them down and see if I can reach out to them. I I know the one early on there was that that that third category of governance related projects were um really driven by blockchains. >> Um so the >> the person who would know the answer to that question well Daniela um but also uh uh Mike uh oh god what's Mike's last name? It just went out of my head. Uh it's going to come right back to me. Um he is the uh general counsel and he's the one who who who sets all that stuff up. I'll find I'll >> remind myself of his name right now. Um >> Oh yeah. Anyway, >> it'll anyway that's that's who would know if they have it. >> Um >> yeah, >> I just want to stress that >> neither the open source uh or the JDF project types are good for governance. They're great for open source code or open standards. At Trust RT, we're a JDF project and we do uh obviously protocols uh technical protocols and we do models for governance. We don't do governance. It's a very church and state thing. You want to do governance, we say great, go set up a governance or however, wherever you want to do it. >> I mean, I'll I'll definitely chat to Daniela about this and get her advice on how best to to structure this. Um you'll see there's like an interim governance piece which is much more simplified. It's basically the maintainers of the the PDP connect PDP connect um >> project in the interim and this governance structure I should have said this at the start this governance structure is only triggered after let me just see where interim let me just quickly interim arrangements um uh so maintainers uh will basically execute all of these functions in this kind of interim period so the sooner of a 100 partners or one year from pro program life. So we do have about a year to set up exactly what the legal personality of this body is, how that relates to LFT and Linux and then um kind of how this relates to the open standard piece versus like the governance and membership and organization piece. So we've given ourselves a bit of a runway to do that. The the main goal actually and this is actually a nice segue into the membership piece. It's that we need to move fast. We need to get people to start saying we care about how people are using their personal data and we're we're ready to implement systems that will um uh protect or preserve or allow control of personal data at the individual level. And I think that if we wait too long to set up detailed governance on this right now, um I'm I mean I'm already seeing it that um uh I think uh Anthropic just pushed a change um that allowed um semantic memory to be put into um their the into Claude and um it's not governed by the user. The user has no self- sovereignty associated with that. So we're seeing this this idea of kind of hoarding personal information in deeper data silos that I think we need to start breaking down now. Um so the the purpose of light governance I guess at the start is to try to move through these membership levels and start to have and we at the VA foundation are happy to take on the idea of like we will administer these kind of signups getting people to say make a commitment to doing this up until um we get formal governance ready. Lisa, >> um do you have any of those um potential the the ones you're afraid you're not moving enough fast for? Do you have any of them signed up to become members? Because I I I know you pointed out elsewhere in the documentation that the hardest part is getting adoption and um are and my other question other question related to adoption is are you looking for any regulatory support? Yes. Okay. Very good questions. Um on the members interested in uh adopting um we through the through the VAR and open data labs network have relationships with some of the researchers at um some of the entities that we would want to have these standards adopted by um as well as folks on the uh kind of government affairs side of things. So this kind of interacts with that. Um we haven't floated this with them yet for for for full transparency because we want the standard to be in a place where the community is happy with it before we start to think about membership. And I that's kind of how we want it to be driven like we we want to consult with all of the folks that have created existing standards and we also want to make sure that people individuals because ultimately we're a system that is individuals based that individuals actually think that this is a fair standard through which they should be controlling their data. So we haven't started to seek formal um uh support yet. Um and this is the reason why we have this supporter tier because actually it's more of an supporter is a misnomer here. It's an indication of interest saying that you are ideologically for this thing versus the partner tier which is actually the technical implementation piece. Um so on that piece short answer no not yet. Um but hopefully that will be remedied through an a light form of um the kind of showing support um and existing networks on the government piece. Um very interesting. So um the panel that we're hosting uh uh at GDC uh with Karen um it will actually have um so VA as a protocol is currently being assessed by the EU sandbox for AI um to see whether or not we comply with high-risisk AI use cases in the form of how our data can be contributed to those high risk AI use cases. Um, I think the US is a bit of an interesting place for that right now. Um, Justin, you could, is Justin still on? Maybe he dropped. No. Yeah, Justin, you you might be able to speak to how some of the US regulatory and policy landscape is shaking out on AI and data. Um, we've pursued the EU because we think that's more stable and there's a lot more work going in there. Um, but we're very open to having this be adopted at that level. I think the EU is where to start with because that's kind of the crux of like GDPR exists but there's no protocol that actually operationalizes that. Um so to get that kind of adoption uh in the EU could be really strong for us. >> Yeah. So what I would describe the US situation right now as is approaching a form of data utarchy. They're trying to maximize the amount of data that is only in the US. They're trying to minimize the amount of data that is using data centers abroad that is using foreign models. This ironically is an opening because it underscores the importance more than ever of having sovereignty both for individuals and for countries. The US has approximately I think 15% of the world's GDP and 4% of the world's population. Most data does never touch the US, does not engage US entities other than through data centers. More than ever, there is a need for a standard that is global in nature, that is portable, and also that is demonstrable in terms of its providence and its veracity. This is what this protocol can provide, I think. Lisa, I think you're probably hinting to the idea of like how do we get fast adoption and then there's like you can get fast adoption through relationships and through kind of like the work that like building consoria around that to support this. I would love actually any thoughts that you have on how we should we should do that at the start on the on the private sector side. But then obviously another fast track to adoption is getting a regulatory body to say you got to do this. >> Exactly right. I would love >> the the the nature of adoption is one of sticks and carrots. People choose to do it either because it gets them or alternatively something that avoids a regulator punishing them. In this case, I think you have both which is that the Europeans are terrified of US dominance of AI of data systems generally leading to a form of digital feudalism of Europe. They want to encourage and you see this in Brussels with the statements about the AI act that data systems operate in Europe that are free of US domination. This means the Europeans should be very friendly toward a open standard like this. But also a lot of Europeans I think are nervous about having their data taken over by state actors whether in Washington or Beijing. >> Yeah. Uh Lisa, do you want to respond to that quickly? Yeah, my concern was actually a little bit more um that the regulators may not see this as sufficiently open if they're >> memberships and board and it's closed and there's no open mailing list and the governments themselves don't have a way to participate. Um that that the structure you I I would if if that's something you're hoping for. Um, I don't know what the answer is, but I would check that you're building something that would be acceptable by >> regulators if that's what you're hoping for. Um, >> that's that's that's a fantastic point. And you know what? I realize that we should probably ask that question when we're on the panel next week. I wish you were there, Lisa. [laughter] Um uh but Karen and I can can ask that question of Professor Rodelo because I think that that's kind of like the you know it's it's a it's a fundamental question like how do you get like how do you get government buy in on something that's moving too quickly where the governments like globally or like even supernationally and and in the US haven't come up with what their approach is right >> so it's like I can constitute like a a group of like ministers talking about this but none of them would agree on the right approach to and they're very leerary about blessing something and I think provenence of that thing is is is a is a good word for it. Um my other uh tack was thinking about how you generate demand for something and um the thing I'm most used to and and I I know Drummond has seen this too in identity space is you bring something that the companies you're talking to who would implement it uh need that it serves a need that they have. >> Um and bringing something that is a need that users have generally fails. That's so true. Um I wish um Gavin Starks was um this is not a good time for him, but he was >> um person who set up uh the open banking standard in the UK. Um and I'm getting some inspiration from him and he's he's provided some input and advice on the scope and spec of PDP as well. But I think that goes to the point of like there are there are multiple trajectories to get fast adoption and open banking was a really interesting one which was um they started with big and then went small and then there's like the the other approach of you start with small and then go big and I think like just getting that critical mass point. I don't know if there's a wrong or right pathway to this. Um you're you're all obviously much more experienced than I am on a lot of this. So if you have any like really strong views I'm I'm all all for like strong views. held um lightly. >> What I would say is they're not exclusive. It is often useful to go at both roots to both try to create bottom up interest and also find some kind of body whether that is governmental non-governmental corporation that can encourage it usage from the top down. >> Yeah. >> Yeah. And sorry >> that's looking at the gaps and pain points. If if you aren't addressing a painoint, >> then it's going to be very hard for you to get any traction for something to happen. >> Yeah. Uh Drummond, you've been waiting patiently. Sorry. >> Yeah. And I I I do have to go to So, no, it's this governance question. It's I was I was going to ask just to clarify scope. Um >> are you looking at global scope meaning do you want this to be uh you know something adopted ubiquitously internet scale or are you looking for it to be in a you know specific industry or country? >> Good question. Um I personally ubiquitously because I think that the way that we're managing personal data is is suboptimal for everyone involved in that transaction. Yeah, I I don't disagree with you on that. I'm just going to point out whatever scale you're after, you have to, in my opinion, design your governance for that. And you know, a single fivep person board to manage a I mean, just look at DNS, right? You want a internet utility there. I mean, it was 20 years in the in the in the making. it it's you know huge international uh uh effort to establish how do you govern a utility like DNS so if it's a uh if it's a utility if you want it to be at that level I think you need to and it doesn't mean you have to reproduce an I can but of course this is the the >> the a problem we're similar to you know we're tackling a a related set of things with uh >> uh governance the first person cooperative and it's it's It's a big challenge. I'm not saying don't shy away from it. We're not shying away from it. But you need to think about how do you get the stakeholders around the world in all countries and cultures and personal data is as large as people everywhere. Just ask Lisa. [laughter] So with that thought as in we got to think about that. I'm happy to try and you know talk more to the extent that um you know us and the other 1500 people in Geneva will have time to do it but um let's let's tackle it one way or the other. >> Thank you Dr. Yeah. Yeah. Perfect. Um just on that point as as Drummond's exiting I think the I think one thing that that's surfacing here is this trade-off between scale and immediate speed. And I think it's surfacing in a lot of areas relating to standard setting in AI where we need to move really quickly. I'm sure you're feeling this in relation to identity. It's like we need to move really quickly on this with everything that's happening. But how do we set up bodies and systems that are able to scale to the level of a DNS or an IAN? That took several years to set up. We don't have several years right now. Um, and so maybe this requires a lot of like the folks in this room thinking about like what is interim arrangement so that we can just get something out the door right now that we just need to get done so that we can start to start to make traction on this. >> Yep. Yep. Good thoughts. Okay. Sorry, I do have to go now, but um I'll see you in Geneva. >> Thank you. >> You bet. >> See you in Geneva. See you in Geneva. Um any further thoughts before I kind of dive into a couple of membership and conformance? The last two sections here. Um these are all fantastic by the way. Thank you. Cool. Um so membership as I was mentioning um and yeah I think that based on this discussion this is going to be very much in flux but um I do like the I I I think the idea of having let me start with like what does the supporter tier solve for an organization? I think right now AI has a PR problem. I was just looking at the Pew Research um piece right now. Um let me actually pull up that exact stat because it's really fascinating. I was um Justin, you've probably you're probably super aware of this research. Um um content, let me see. So the stat is um 7 in 10 Americans expect AI to make their personal data less secure and only 3% say more secure. And at the same time, anybody who I know who's developing AI is struggling with getting context to make their AI performant. And so I think about this is like, you know, Lisa to your point of like what problem do we solve for these people? I think something like PDP or a standard um like this can say we we support personal data. We support this. Now I think about this in the context also of um the work that you've done at DTI and I'm like is it is it too easy just to say you're a supporter if you're not willing to kind of execute on a commitment and and that's where I kind of and that's the question that I wanted to this forum of saying like >> I hope you're a better salesperson than we are because this this really requires to to sell people on a vision >> and this is a vision that with DTI we've been unable to sell very many people on like so it's been very hard to add members to DTI and we are still tiny about where we were three years ago because we've been unable to sign people up to the vision to grow and even when we sign them up to be members it is very hard to get them to move from there to write code. Yeah. Yeah. >> When when you know there's five VPs inside a large company who each have a veto power because this crosses lines the you know the the the protocol people the ops people the domain specialists and the legal and the you know port the one portability team and any one of them could say no and it's dead. So >> yes >> I I want to echo that. It's very easy to lower standards. it's very hard to raise them. When people join an organization, it is often very easy them to take something that's, you know, a lighter level of regulation or self-imposed requirement. It's very hard to add to it. At the same time, if you have too harsh or strict a standard and nobody joins it, it's a dead standard. >> Yeah. The solution I find is you want to have initially people joining to show interest and then people joining at the highest possible level to create that most powerful of social forces, shame and envy. >> If a few entities will join the highest standard, others will be compelled to do that. We saw that today with Meta calling on YouTube and Tik Tok to follow their voluntary standards on children that they agreed to at the barrel of a regulatory enforcement action. >> So I think in some ways again you want to have small entities joining for any reason but large entities joining as high up the stack as possible. >> The number one danger is if a large entity joins a supporter to get their name they'll never move higher and other people will think that's the new standard. So this this is part of the one of the pieces of the governance design um that interacts with the the election of the board which again is in flux. I wanted to keep it at one organization one vote. So that if meta was to be in an organization with a bunch of um you know like smaller companies that are trying to do data portability meta will only ever have one vote in relation to this and that might not be acceptable. Kind of leads to your point. like it's hard to get these folks to sign up, let alone sign up to a body that's governance stacked against them based on, you know, size. So, I actually think that this is this is where I want um as much feedback and as much thinking as possible. Lisa, if you could um if you like what's the what are some of like the biggest lessons that you've learned in terms of you've obviously articulated one, which is like if anybody in that chain says no, then it's a no. What have you found to be successful in relation to adoption? Um, it's just so hard. Um, the some of this work is already going on in the IETF. >> Yeah. and and I'm trying to see how parallel it is to when instant messaging was hot and instant messaging came to the ITF. >> Um like why did people show up? Who was afraid of missing the boat? One of the advantages of bringing something to the IETF is that uh companies like well Cisco at the time but it would be different names you you'd conjure today >> couldn't say that they were unaware of the work. they couldn't just ignore it >> because they were at the ITF anyways going to router layer working groups >> and the what Jabber did was first of all they built an open source thing that worked and had a few people few people involved then they brought it to IETF and gave up control >> in order to broaden the audience because again Cisco couldn't say um they were unaware of it they couldn't say it didn't work for them if they didn't put comments on it >> when they were there at the you know at each venue. >> Um and then after five years of it being an ITF thing, they took all of their extensions and built the XSF, the XMPPP standards foundation. So they took all the extensions back private. >> Yeah. >> But they needed to build the audience and they went to the ITF for that. So they kind of relinquished control to get that broad base and then brought it back in in order to make themselves sustainable. I I do think there's a bit of a journey like that for something like this. Um that's actually really helpful as an example. Um Karen, do you have any thoughts on adoption from it e's perspective? >> Well, I mean [clears throat] you have to go through our process. I don't know if you've talked to Pervo, but he he's very close to several of our >> uh working groups. Um, >> perva and I are having a conversation I think in two days at some point. Crazy travel. [laughter] >> You know, if you if you get adopted by E, you've gone through our process and it's something that goes out to our over half um a million members in 190 countries. Um, >> yeah. >> So, it gets announced to those people and you know from the working group once you start that you can build this out in many different ways. We actually also have an open source community >> um that that works on a lot of things related to open source that come out of the standards development process itself. So there there I mean a couple communities that that could assist. Um but you know it was thinking back to your struggles to to start this. They're still struggling to come up with an AI governance model. >> Um you know a lot of puts and takes for um you know the UN wants to be in charge of it and so does everybody else. >> Um yeah and so you've got some sovereignty issues to address. I think you've got the same thing in terms of uh personal identifiers. There's sovereignty issues that need to be addressed and how you're going to going manage that um in a in a very disparit world. >> Yeah. It's similar to the problem relating to governments like no there's there's no north star that's kind of emerged and there's no consistent um approach to take. So to try to represent all of them to try to create that broad church is is a challenge. >> You you can't do that. But but what you can do is sift through it all and find the the critical pain point for everybody. >> Yeah. and then and then build build your your model and and in essence your story around that painoint and how it solves this in in a variety of uh interoperable ways >> because again right now what I'm looking at in terms of AI governance itself is the interoperability between all the different models out there has to be common threads common threads tend to be personal data >> data sources Then it goes to is is the data trustworthy? >> How do you know? >> I mean all of those, you know, it's going to be a very nuanced and layered approach to get down to your protocol actually can address all of those things. >> It doesn't break any individual model, but it allows models to interoperate. This is actually a really cool segue into this section of the conformance piece because I think that some of the incentives pieces I mean this is the carrot and the stick piece. I think conformance relates more to to the stick and I'll kind of kind of talk about that. So there are basically three uh actors in the PDP system. There's the source which is where the data comes from. There's the accessor, the person who's trying to get the data. And then there's the verified operator. So the operator basically enforces the relationship between the source and the accessor based on the PDP standard which um which will which is to give confidence to a user that they're in control of their data. As in this slide here to be a partner you would have had to have implemented at least one of these three pieces. So this is where it could be kind of interesting. So put the the like um think about um OpenAI right now. Um would they be a source, an accessor, or an operator? Um an accessor simply needs to say we receive data in a in a way through PDP. That's the lightest level. So if you wanted to be a member, a partner um and you could say and and this could solve a problem. So I know that OpenAI and Anthropica are right now struggling with the ingestion of personal medical information. Right. So if they were saying I want to be a valid a valid accessor through the PDP system, they would um they they they uh it could solve a pain point for them in that they want to access the data. At the same time um this is where the stick comes in. Somebody um the way that PDP is designed is we have these open source data connectors that can be contributed by the community. So essentially a community member can create a way for people to get their own uh chbt data or the official organization and that's the official source piece can say no no no no we don't want this we we want to control this like we want ourselves to be the ones who are um developing uh the data connected the source um so we actually have two different types of sources we have one source which is verified by the technical committee as safe and accurate and then we have an official source which is like ChachiBT or OpenAI saying no no this is the official source of information from OpenAI. Um there's the stick element of that of if somebody develops an OpenAI connector that isn't OpenAI that's a risk to OpenAI. The only way they're going to be able to solve that is through um becoming an official source which requires them to become partner status and implement something that is PDP compliant. question to the group. How successful the sticks work in this space? Um especially it's basically like if if you're a you know chief security officer you're like wait somebody's able to access their personal data through them but you know GDPR download export right that could be the the way that the data is accessed. Um what is there incentive there to say like I don't want somebody to build to build that on my product so I want to build it myself. So traditionally um companies treat this as a attack and >> deploy everything from captures to rate limiting to removing user accounts to discourage this kind of action. Like there's all kinds last 20 years are littered with startups who on behalf of the user try to gain access to um data that the companies hosting the data have not put into public APIs or they do and then a third party gets it and then like no we don't actually like that we're yanking it and so they they treat this like um like like they have antibodies responding to it rather than an invitation to come to the table. Yeah. >> And and user data portability is rare enough that um if they have to terminate some users accounts because they weren't supposed to th to point a third party client at their guey and they did >> these companies would would do it. What about where they can't where it's a a GDPR export style flow and it's I guess they just make it difficult. They they go all the way to the 30-day limit on GDPR and just make it >> almost impossible for that data to be fresh. >> Yeah. And they and and um make sure that the user that it's happening on the users on their side that they can have control over the um fire hose of data and who can receive it. This is where I want to get my white hat hack white hat hat hat on. White hack hat on. Um it's like is our open source community faster and better to be able to respond to some of these antibodies that they put in? >> It it may be the case like it this may be an inflection point. >> I feel like it is like from a just seeing where the conversation is at and how frustrated people are and how important this is like the pure research just shows that people are just like I one of the reasons why they don't want to use AI is is because of this data problem. Are we in a historically different moment? Potentially. >> Potentially. >> I'm happy. I would stake my bets on it and try to drive that. I know there's a lot of people in the VA community that that are frustrated with the way that their data is handled. I think there's a lot of people generally in the community that are frustrated about how their data is handled. So >> well and I think there's a lot of people that don't even know how their data is handled. >> Yes. Yeah. We definitely have to do the education piece. That's not part of the work here. But you know as Drummond said like we if we do constitute a body like VA does that education piece within our community through our discord and through community events. But I'm wondering if like this as a body needs to have a broader statement of education around this. But I've I've also got to think about this separation of tasks because you almost don't want this to turn into a lobbying advocacy group. It needs to maintain that >> that could be the kiss of death for for anything going forward. Um >> yeah, >> I mean it's something to note but not something to really build out at this point in time >> that it's important that that uh uh you know individuals understand and um how their [clears throat] data is used and they and that they have a role and a responsibility in that data use. >> So I might share some insight here from the experience at Bar. I know we have seven minutes left but I want I want to cover this. It's um the problem is that when we tell people when we give people the makeup of how their data is used, the landscape, the architecture, they come back and say, "Okay, so what can we do?" And that's really the genesis of PDP and why we want to do this because we want to say, "Well, there's there's an alternative because it's been really tough actually to do these education pieces on the VA side where at the end of the workshop people like, "All right, so what do I do? I just stuck using Facebook again. And so from an individual's perspective, not having a collective voice or a resource on this has been a real challenge. I think um it's been quite quite demoralizing on that side. Um, I think where we're seeing a lot of traction is smaller, um, even just like series B style, like pre-public companies that are trying to compete with some of the larger players, um, and want access to data so that they can, um, that they can compete on a level playing field. So, we're getting some business support there and and maybe that's the secret here. We kind of attack that mid-market. Anyway, just some thoughts, you know, almost form a users group so that um You know, it can be individuals worried about their data versus the small and medium-sized businesses who really don't have a lot of resources, but they need to know because their business is going to be dependent upon it. >> Yeah. And they're their their pain point that we're solving is that they're scared of being eclipsed because of these larger players >> or or scared that their data is being used and they don't know anything about it. >> Truth. Yeah. Um so this piece uh is quite uh detailed in terms of uh verified source, verified access or verified operator. This is the one piece that I also wanted to so the the process for getting verification is also set out in the write up. Um I won't go through that but but right now it's supposed to be light. It's basically submission, review, grant and merge and publish. Um so this is I covered verified sources. Um and sources are actually really important to us because the source is essentially the the potential the has the largest potential surface area for um controversy I would say both technical as well as from a relationship management perspective uh carrot and stick. Um the accessor piece is the lightest and I think that's the one where a lot of small to medium enterprises are going to want to play because they want to access the data. So they'll say that they want to be compliant. They'll indicate support and then they will integrate with VA. We're already seeing this with most of the client base on the open data lab side of VA, the the web 2 company. Um they're really interested in ingesting user data and we tell them that they need to ingest user data on this system and they're like that's perfect because we don't really want to deal with these platform APIs or we can't access the data through platform APIs. So I think this is actually going to be the lightest form. And then operators is obviously going to be the heaviest one. These are the core of the system. This is core to the system. VA um uh is the only operator of PDP right now, but it shouldn't be. There should be a lot other potential operators of this system that can credibly verify that the users's grant will be complied with as it relates to the data moving from accessor to source. Um the board's job is to keep the register the board's main role is to make sure that that register is accurate. And as it relates to um uh I was going to say >> in in in your structure, would you also want to have some sort of compliance role where you >> I mean people might sign up for all of this stuff, but how do you prove it? >> That's that's true. Um and that's kind of the the different levels here. Uh sorry, let me uh supporter should it require an additional compliance check. Um, one of the things that we do pull in, um, and I, uh, and Lisa and I are talking about this of like I think that from a one thing that DTI does really well is being able to showcase like who is this, is this entity the person that they say they are and is the entity that's requesting the data. I think when when there are um, external uh, certifications like that or registers like that, PDP should adopt that as reference and true. So Karen, to your point, if um someone drops off the DTI register, we should be in contact with the the DTI folks and also remove that from the the PDP register. >> Well, I mean, I'm looking at a lot of the things that come out of the EU and and they're they're building in annual compliance reviews and and edistations. you're following the rules that that you know you just because you said you follow the rules to get into the club doesn't mean you're going to continue with following the rules. Um and so they want a stationation or some proof. >> The I haven't looked at the EU attestations but that's definitely something we should look at here. Um and any of the I don't think the US has any attestations at this point the way that governing they really don't. Most of it's coming out of the EU. I mean, they've got one for their their cyber security requirements. Um, they built in some things for the their risk levels for in their AI act. Um, >> yeah. >> And so, you know, governments like asurances that they've done the right thing and you're going to continue to do the right thing. >> I like that. Um, I'm mindful that I only have a minute left and LFDT will literally cut me off in a minute, so >> I'm going to jump. No, no worries at all. Um uh we talked about interim arrangements. Um I think timelinewise we want to I'll take all of this feedback. Uh would we welcome any um any written feedback as well um either in the GitHub or just mention me directly if you if you want to discuss this more deeply. Um yes feel free to let's set up a meeting. We'd love to talk about it. Um we will present this at GDC and then present a draft for public comment. So there's going to be another turn of feedback that we're going to be putting in here. And I think that that's also the opportunity to broaden the church on this and to take and I think Europe is the perfect place for this right now. So that's the plan at GDC for us to try to connect with folks that can provide comment on this um and can be part of the broad church that we're trying to build to try to move this. Um and then >> well recommendation find one government to kind of review it and get their comments independently. >> Amazing. We an EU member state >> um Well, I mean we we have >> has a committee of governments, you know, look talk to somebody from Switzerland or Brazil or somebody like that, >> you know, set up a bilateral meeting with them one-on-one, walk through this and get get their feedback. >> Yeah, I I I will second that. If you can get it from the developing world in particular, and you're in art, Bhutan right now, Art, but I know you can't necessarily ring up the minister, that would be especially powerful because that is the community of nations that have the most to gain and most to protect from this. That's such a good idea. I already have two candidates in mind. Yes. Yes. Thank you. I love this. I get so many ideas from this. Um, these are just some open questions. Um you 01 tell me what's wrong with it. Of course um uh these are the four questions but I think more questions have actually surfaced on this call that I'll send out in the um recap. Um and if there's anything missing or what's missing on this I would love um any feedback. So I'll send out the recap post this call. Um thank you guys so much for attending. I really really do appreciate it. Um I love all of this information. I'm going to have to take a minute to digest all of it and then work out what I have to do next. But there's some work to do before the 3rd of September and then probably a lot more work to do before we lock it in in October. But um I really appreciate your time. Thank you so much. >> Thank you. >> Bye. Bye. >> Bye.