Video summary
The working session led by Art of the Vanna Foundation focused on establishing a robust governance framework for the Personal Data Portability (PDP) standard, with the goal of gathering expert feedback before a public comment period begins in September. The proposed structure separates management from technical execution by creating an elected board to oversee long-term strategy and status grants, while a technical committee handles the review and merging of specifications. This governance model distinguishes between "supporter" tiers for those with ideological interest and "partner" tiers requiring actual technical implementation, ensuring that membership reflects active contribution rather than just support. Additionally, conformance is treated as a distinct concept from membership to avoid mandating it, allowing entities to demonstrate adherence to the standard without necessarily registering or receiving operational permissions.
A critical discussion centered on balancing the need for control with the risks of creating barriers to entry, particularly regarding how official data sources like OpenAI might reject unauthorized connectors. To prevent treating data portability as an attack and to avoid demoralizing smaller businesses, the group proposes a tiered architecture featuring "Verified Sources" for high-risk entities, "Accessors" for lightweight integrators often used by SMEs, and "Operators" who maintain core system compliance. This approach aims to provide a legitimate pathway for data access while ensuring safety and accuracy through a streamlined verification process that includes ongoing compliance checks, potentially utilizing annual attestations similar to EU standards rather than relying solely on initial sign-ups.
The session also addressed the broader regulatory landscape and adoption strategies, noting the European Union's stable environment under GDPR as a starting point while observing the United States moving toward a "data utarchy." Participants debated how to encourage global adoption by addressing specific pain points such as medical data ingestion for AI models, emphasizing that raising standards is difficult once established but essential to prevent large entities from settling for low-tier compliance. The ultimate goal is to create social pressure where high-standard adoption by major players compels others to follow suit, ensuring the standard remains open enough for regulatory acceptance while maintaining its integrity against the risk of fragmentation or low-quality implementations.
Looking ahead, the group plans to present a draft governance document at GDC for public comment before locking in specifications by October, with a timeline to determine the legal personality of the governance body within a year via LFDT labs. The strategy involves seeking independent reviews from governments, particularly in developing nations, and gathering feedback through GitHub or direct meetings to refine the framework. By combining bottom-up interest building with top-down regulatory encouragement, the initiative seeks to create a scalable model that supports global adoption without compromising on security or the open nature of the standard, ensuring that the PDP ecosystem can evolve sustainably as legal structures within the Linux Foundation are formalized.
Read the full video transcript
Hello.
Um,
it's Art here who is the managing
director of the Vanna Foundation and I
think I'm in charge of uh this session.
Um, apologies for my delay. I was uh
trying to log in here. I'm currently in
the Kingdom of Bhutan. So um really
excited for folks to be joining this
session. I'm going to um share my screen
so that we can start talking through
some of the uh working parts of this. Uh
but before I do um I will wait a couple
of minutes because it does take some
sometimes it takes a bit of time for
people to join. Um and in that couple of
minutes
awesome. I see Drummond on here. Justin,
hello. and then somebody dialing in.
>> Hey Dr. How you doing?
>> Good. I finally made it to one of these.
Uh it's
>> excellent.
>> It's been um
crazy uh you know this is the last week
before GDC and I got back from New
Zealand last weekend. [clears throat] So
I was like ah crazy week.
>> Well I'm glad you I'm glad you're able
to join. Um, I was just telling the
folks that um I'm calling in from the
Kingdom of Bhutan right now. Um, I wish
I could show you these wonderful
mountains that I have here to my left.
>> Seriously?
>> Yeah. If my internet drops in or out or
I'm a little bit slow, that's that's
probably it.
>> Where are you in Bhutan?
>> Uh, I'm in um Tempu, which is the
capital. Yeah, it's I've only been there
once, but we the uh uh
we went to Tempo on for for for two days
uh at the end of it. It was after the
Bhutan Innovation Forum. Have you been
to Bhutan before?
>> No, this is my first time and um I have
uh I've managed to get some time to
explore a little bit, but I definitely
have to come back because I have to
leave tomorrow. So, I will um uh I'll
come back. It's a big country. Is it are
you you know visiting or are you is it
business?
>> Um so we um I was invited to be here by
uh Yeezy Labs um uh so um Binance's lab
Binance's um uh investment arm. Uh they
uh invested in VA earlier on um and so
they're concluding a cohort of um folks
that have they've been incubating here
for the last five weeks. Um, and so
there's a bunch of folks like me who
have just flown in um to see the work
that they've done um to help some of
their their uh their startup founders
and to see what we can do next for them.
But honestly, it was um it was such a
surprise coming here um getting the
invite first of all, but then coming
here and just not knowing what to expect
and then seeing such a very different
country which is really really cool. Um
and then I yesterday had the chance to
go run up the mountains a little bit,
went on a morning run and it's
absolutely stunning. Hey Karen, how you
doing?
>> I am doing fine. How are you doing?
>> I'm very well, thank you. I was just
catching Drummond and Justin folks up on
the fact that I'm calling in from Bhutan
of all places. Um on my way to GDC, but
um I had to stop over here.
>> Are you uh seeing any folks from the
National Digital Identity uh uh program,
NDI?
>> Not not um not here on this trip. No,
I'm really stuck into this um
convergence forum. Um, but I do have to,
that's why I've got to come back.
There's a lot of really interesting um,
tech work happening here. But I think
there's a lot of just interesting
society work happening here. I was um,
speaking to one of my mates who um, does
a a program around mindfulness in
schools. Um, and it it's like a
different education
kind of pedagogy or system where they
they teach compassion first and lessons
later. Uh, and I think it's a there's
some really interesting stuff that I
definitely need to come back here for.
Next next trip, I've got to I got to
make my way over to to Geneva, which I'm
sure you and Karen are also heading
over. Justin will also be there. Justin
Slaughter um he's a he's a good friend
of mine. We've been working for many
years together, but he'll also be on the
panel with us next week. Um, and I'm uh
I'm excited to actually put this
standard out there for public comment.
Um, so I I don't want to take up too
much of your time, but I want to be able
to walk through this session. Um, this
session is focused on governance, which
is why I'm running it. Um, and uh, the
point of this session is just to start
to get some feedback around how we're
thinking about governance, start to poke
holes in it. um with a view to being
able to set a um uh next week to have
this governance piece of the standard
out there ready for public comment. So I
kind of want to get um top eyes on it
right now to see what you guys would say
about it. Um and then I'll go through a
presentation just because I think it'll
be easy for us to walk through about how
we're thinking about governance and some
of the different pieces.
Amazing. Cool. Thank you, Dr. I will
make sure that I blast through some of
the bits and then
>> I don't want to rush you or all. I just
it's just that's just a situation I had
tonight and I haven't made any of these
meetings so I wanted to at least come to
as much of this one as I could.
>> Appreciate it. Um and and obviously like
this is going to be recorded and we're
going to send it out to the community as
well and there's going to be
opportunities for you all to to comment
on it. And I guess I'll say the last bit
first, but what we're doing in these
presessions is trying to get as much
expert advice and opinion in on the
standards, the the the the draft
standards so that when it goes out to
public comment, we have something that's
a little bit more firm. And the plan is
that at GDC we actually launch the draft
period um the comment period uh and have
that close in around October. So, we'll
run a 4-week public commentary period
where we're going to circulate it to a
wider audience where we're expecting to
get some more feedback. So, your initial
feedback is obviously incredibly
important to us, but this isn't the only
opportunity that you'll have to provide
feedback either informally or formally
on this standard, and I was going to
cover that in the end, but I just wanted
to set that out at the start. Um, so
this is going to be a little bit dactic
at the start, but I do um if you do have
any questions or anything you want to um
pop into um the the chat, feel free to.
Um can everyone see my screen first of
all?
Perfect. So this section this session is
going to really cover governance,
membership and conformance. Um and I'll
talk about why we've split it up into
those three areas um uh as part of the
introduction. And again, this is uh with
a view to creating the the
pre-conultation draft. Um and then the
formal public review will open on the
3rd of September when we launch as a GDC
and it'll close on the 1st of October.
So um I think everyone here is either
governance or governance adjacent which
is amazing. So I don't really have to
explain why governance of a standard is
important, but just for the folks who
may not be um as versed on why
governance is important. Um you can set
a standard, you can set a protocol, but
getting people to adopt it, maintain it,
and use it is something that you need to
think about when you're setting up the
protocol. And so within the context of
PDP, we have this um durable specific
record that allows people to move their
personal data.
Um and that's been scoped out by um Tim
and Anna on the technical side. But on
the governance piece um we need to think
about a way to actually get adoption of
this more broadly if it's going to be a
ubiquitous standard. How this interacts
with other existing standards and
standards defining bodies and how we
continue the growth and development of
this as the world of AI and the world of
portable data continues. So that's
essentially what the scope of this
discussion is. it's how do we continue
uh how do we get this standard adopted
and then how do we continue um with uh
with the growth of this standard.
So as I mentioned at the start we've
separated things out into governance,
membership and conformance. And the
reason why we've kept that in that way
is because governance for me defines how
this standard continues um and is able
to be maintained in the long term, how
it functionally operates. membership
solves a problem of how do we actually
get people to adopt this standard at a
global scale which we we we kind of need
for anything relating to kind of
personal data and this kind of societal
change that we want to drive from PDP
and from VA and so um I'll set out what
I think is going to help with adoption
there and I'd love feedback on that in
particular from you Drummond and you
Karen who've seen this and seen adoption
of standards as well and um uh I'd love
to get some of your experience um to
bear on that. And then conformance is
the piece that I wanted to separate out
and it it it kind of boils down to this.
We're setting an open source standard
out just because um you are um the the
program having membership under this
program or being Oh, Lisa, hello.
I was just um uh just going through the
deck. Um I'll catch you up. Um there's
just to catch you up. I'm in Bhutan.
Apologies if my internet drops out
because I'm in Bhutan. Um but um the
point of this is basically to set
through set set out like how we're
thinking about adoption and governance
of PDP. And um I'll just go back to this
slide because I think it's important
just for framing splitting it up into
three kind of um buckets for me.
Governance which looks at the longevity
of PDP and how it's able to respond to
things as well as how it relates to
other protocols. Membership is how we
look at adoption and how we try to get
global adoption of a standard. And then
conformance is the piece that I wanted
to separate out there because in setting
out an open source standard, you kind of
don't want to mandate membership as
conformance. Conformance operates um
separately from that and conformance
status is not permission to operate. We
set the standard out so that people can
aspire to achieve it. Um whether or not
they want to register their um
achievement is something that should be
separate from that process. And that's
just like philosophically how Anna and I
are aligned on this. We would rather
folks go and try to achieve this
standard versus try to gain some sort of
membership or incentive program to try
to get into a PDP stamp. Um
I'll go through um each of these in turn
um and then we can kind of work through
that. As I said at the start, if you
want to interrupt, feel free to just
type a message in and hop off mic. Or if
you just want to interrupt, that's
totally fine. Um and there's obviously
the opportunity to comment on it um in
uh in a more formal way on um on GitHub
or in um go to pdbv.dev as well. Um so
the structure I wanted to stick with uh
this is the governance piece. I really
wanted to stick with something that was
really um light at least at the start
and something that could grow. Um, so
the long-term structure that we're
envvisaging is some sort of board or
steering committee with an elected chair
that does, I guess, most of the grunt
work associated with maintaining things
like the register and maintaining some
of the administration associated with
PDP and implementation. Um, I chose
five, maybe it should be three um for
the kind of committee structure. That's
all configurable. Um, the register piece
of it is really important. Um I know
folks here who've run registries or run
run run registers. It is not an easy
job. You are constantly trying to
maintain something where people are
applying and moving through it. That's
why we needed somebody on the committee
level who's responsible for actually
operationalizing this. And then I wanted
to separate out the technical committee
um for the reason that um there are
going to be things that the technical
committee can do in relation to PDP as a
standard that should be separated from
the pieces relating to membership um and
conformance which should be um done by
the body that kind of governs this
entire standard.
So just in brief what each does is the
board sets the conformance criteria the
currency rules grants and withdraws
status here is appeals appoints the
technical committee and represents the
program to the Linux foundation an LFDT.
The chair is the operator of the board.
Um sits on the board but also makes sure
that all of the the the pieces of the
project continue to function. And the
technical committee um reviews the
submissions in public recommends.
They're the ones who are um looking at
pull requests in GitHub. They're the
ones that are looking um at compliance
relating to the data connectors. Um and
but they're they're because they're the
ones also setting those compliance
standards. uh they're they're making a
recommendation to the board versus
actually making those decisions.
That's again something that I'm kind of
questioning whether that's the right
approach. Um open to thoughts and ideas
on that before uh oh yeah I'll go to how
each is constituted and then we'll pause
here and I'd love some comments on just
the governance piece of this. So um
board elected by partners um and we'll
talk about what a partner is. One
organization, one vote. A partner is
basically a member um who uh has
implemented part one part of PDP.
Um the chair is elected by the partners
as well. They will just have a special
voting system for the chair. Um and then
the technical committee is actually
appointed by the board. And and why I
think that's also important is there
needs to be some longevity in the techn
committee. It would be the folks that uh
like Tim and Anna who um are deeply
technically involved in the idea of data
portability and who see themselves as
having more than just a two-year tenure
and seeing this through as a project
that evolves. So the technical committee
is actually really the heart of the
project because they're the ones who are
really thinking about data portability
in the arc of how it relates to AI
whereas the board and chair is really
just the management piece that allows
this to kind of be adopted.
Um just to kind of articulate that a
little bit further, uh the technical
committee approves and merges the
specification. The board will uh
publishes the versions on the site. Um
the technical committee approves and
merges um the the review standard. The
board will set the criteria. The
technical committee reviews and
recommends the conformance submissions.
The board will grant or refuse it um on
whatever grounds. um the technical
committee decides on codes, views and
extensions. The board has no role in
that. And then the membership terms,
appeals and committee membership that's
really at the board level. So you can
almost think of this as like kind of a
CTO COO kind of a function um in in a
traditional organization. Um so that we
have that kind of separation of powers
and the ability to set technical
standards that are um I think more
longer term than anything that the board
wishes to kind of um advocate for in the
short term.
Um, membership is the next kind of topic
that I wanted to talk through, but let's
go back to governance and see if you
guys have any comments on what you what
you've seen work from a structuring
perspective to ensure the the longevity
and continuation of an organization. And
and as I said, I tried to keep this as
simple as possible.
>> Open to comments.
>> One question,
are you envisioning any financial um
support?
because if if you look at the any kind
of financial support for the
organization itself then who is
authorized to sign and pay for things?
>> Um I think as an LFDT lab um any
membership or financial um dues need to
be um at the LFDT level. Drummond, you
can correct me if I'm wrong on that. Um
I my assumption is that um all of that
needs to happen at the LFDT level. Um
I'm not envisioning anything I'm
envisioning this to be completely
voluntary at this stage and maybe it
will evolve into something different and
something more after that but um at at
least for the first iteration or first
round
>> um yeah I'm I'm envisaging voluntariness
um Drummond. Okay. Because
>> No, go ahead, Karen. Finish.
>> I mean, I I was just thinking, I mean,
if there's any kind of contracts, who's
authorized to sign them?
>> Um,
>> you know, all all those
>> things that go behind making something
work. Uh, well, if you're going to set
up an [clears throat] organization as
part of the governance structure, you
need to think about so, you know, the
board can approve and and the uh whoever
the chair is authorized to sign,
>> you know, things like that.
That's a great point, Dr. What works in
terms of legal personality for some of
the other labs or projects at LFTT?
>> Well, that's that's the reason that was
the question I was going to ask. Um, so,
um, you know, [laughter]
having done this stuff at LF for, you
know, like 15 years now. Um,
there's three classes of projects at LF.
There's open source projects, there's
open standard projects, JDF, joint
development foundation, and then there's
this third a couple examples of these
governance projects um of which I'm not
involved with any just aware that they
have played with a couple of those. Um
and so that was going to be my my
question. Uh an LFDT labs project is an
open-source project for the code. Um, so
I'm I'm as I'm wondering so
what is the uh the going to be a home
for the standard? Is that going to be a
community spec or a working group uh or
a project? And then this kind of
governance is might fit that governance
body. But what are you envisioning um is
the actual legal home for uh the board,
the organization?
>> Those are excellent questions. Um the
where we're at with LFDT is it's uh
draft it's it it exists as a lab with a
view to creating a community spec. But
what that doesn't cover is how that
community spec is rolled out and
governed and then implemented.
>> Right.
>> Um I haven't been in that discussion yet
with Daniela and the folks there and I'm
very open to taking advice. Um you you
mentioned that there are a couple of
other projects that are kind of in this
third category. Do um do you know who
they are? I'll write them down and see
if I can reach out to them.
I I know the one early on there was that
that that third category of governance
related projects were um really driven
by blockchains.
>> Um so the
>> the person who would know the answer to
that question well Daniela um but also
uh uh Mike uh oh god what's Mike's last
name? It just went out of my head. Uh
it's going to come right back to me. Um
he is the uh general counsel and he's
the one who who who sets all that stuff
up. I'll find I'll
>> remind myself of his name right now. Um
>> Oh yeah. Anyway,
>> it'll anyway that's that's who would
know if they have it.
>> Um
>> yeah,
>> I just want to stress that
>> neither the open source uh or the JDF
project types are good for governance.
They're great for open source code or
open standards. At Trust RT, we're a JDF
project and we do uh obviously protocols
uh technical protocols and we do models
for governance. We don't do governance.
It's a very church and state thing. You
want to do governance, we say great, go
set up a governance or however, wherever
you want to do it.
>> I mean, I'll I'll definitely chat to
Daniela about this and get her advice on
how best to to structure this. Um you'll
see there's like an interim governance
piece which is much more simplified.
It's basically the maintainers of the
the PDP connect PDP connect um
>> project in the interim and this
governance structure I should have said
this at the start this governance
structure is only triggered after let me
just see where interim let me just
quickly
interim arrangements
um
uh so maintainers uh will basically
execute all of these functions in this
kind of interim period so the sooner of
a 100 partners or one year from pro
program life. So we do have about a year
to set up exactly what the legal
personality of this body is, how that
relates to LFT and Linux and then um
kind of how this relates to the open
standard piece versus like the
governance and membership and
organization piece. So we've given
ourselves a bit of a runway to do that.
The the main goal actually and this is
actually a nice segue into the
membership piece. It's that we need to
move fast. We need to get people to
start saying we care about how people
are using their personal data and we're
we're ready to implement systems that
will um
uh
protect or preserve or allow control of
personal data at the individual level.
And I think that if we wait too long to
set up detailed governance on this right
now, um I'm I mean I'm already seeing it
that
um uh I think uh Anthropic just pushed a
change um that allowed um semantic
memory to be put into um their the into
Claude
and um it's not governed by the user.
The user has no self- sovereignty
associated with that. So we're seeing
this this idea of kind of hoarding
personal information in deeper data
silos that I think we need to start
breaking down now. Um so the the purpose
of light governance I guess at the start
is to try to move through these
membership levels and start to have and
we at the VA foundation are happy to
take on the idea of like we will
administer these kind of signups getting
people to say make a commitment to doing
this
up until um we get formal governance
ready. Lisa,
>> um do you have any of those um potential
the the ones you're afraid you're not
moving enough fast for? Do you have any
of them signed up to become members?
Because I I I know you pointed out
elsewhere in the documentation that the
hardest part is getting adoption and um
are and my other question other question
related to adoption is are you looking
for any regulatory support?
Yes. Okay. Very good questions. Um on
the members interested in uh adopting
um
we through the through the VAR and open
data labs network have relationships
with some of the researchers at um some
of the entities that we would want to
have these standards adopted by um as
well as folks on the uh kind of
government affairs side of things. So
this kind of interacts with that. Um we
haven't floated this with them yet for
for for full transparency because we
want the standard to be in a place where
the community is happy with it before we
start to think about membership. And I
that's kind of how we want it to be
driven like we we want to consult with
all of the folks that have created
existing standards and we also want to
make sure that people individuals
because ultimately we're a system that
is individuals based that individuals
actually think that this is a fair
standard through which they should be
controlling their data. So we haven't
started to seek formal um uh support
yet. Um and this is the reason why we
have this supporter tier because
actually it's more of an supporter is a
misnomer here. It's an indication of
interest saying that you are
ideologically for this thing versus the
partner tier which is actually the
technical implementation piece. Um so on
that piece short answer no not yet. Um
but hopefully that will be remedied
through an a light form of um the kind
of showing support um and existing
networks on the government piece. Um
very interesting. So um the panel that
we're hosting uh uh at GDC uh with Karen
um it will actually have um so VA as a
protocol is currently being assessed by
the EU sandbox for AI um to see whether
or not we comply with high-risisk AI use
cases in the form of how our data can be
contributed to those high risk AI use
cases. Um,
I think the US is a bit of an
interesting place for that right now.
Um, Justin, you could, is Justin still
on? Maybe he dropped. No. Yeah, Justin,
you you might be able to speak to how
some of the US regulatory and policy
landscape is shaking out on AI and data.
Um, we've pursued the EU because we
think that's more stable and there's a
lot more work going in there. Um, but
we're very open to having this be
adopted at that level. I think the EU is
where to start with because that's kind
of the crux of like GDPR exists but
there's no protocol that actually
operationalizes that. Um so to get that
kind of adoption uh in the EU could be
really strong for us.
>> Yeah. So what I would describe the US
situation right now as is approaching a
form of data utarchy. They're trying to
maximize the amount of data that is only
in the US. They're trying to minimize
the amount of data that is using data
centers abroad that is using foreign
models. This ironically is an opening
because it underscores the importance
more than ever of having sovereignty
both for individuals and for countries.
The US has approximately
I think 15% of the world's GDP and 4% of
the world's population. Most data does
never
touch the US, does not engage US
entities other than through data
centers. More than ever, there is a need
for a standard that is global in nature,
that is portable, and also that is
demonstrable in terms of its providence
and its veracity. This is what this
protocol can provide, I think.
Lisa, I think you're probably hinting to
the idea of like how do we get fast
adoption and then there's like you can
get fast adoption through relationships
and through kind of like the work that
like building consoria around that to
support this. I would love actually
any thoughts that you have on how we
should we should do that at the start on
the on the private sector side. But then
obviously another fast track to adoption
is getting a regulatory body to say you
got to do this.
>> Exactly right. I would love
>> the the the nature of adoption is one of
sticks and carrots. People choose to do
it either because it gets them or
alternatively something that avoids a
regulator punishing them. In this case,
I think you have both which is that the
Europeans are terrified of
US dominance of AI of data systems
generally leading to a form of digital
feudalism of Europe. They want to
encourage and you see this in Brussels
with the statements about the AI act
that data systems operate in Europe that
are free of US domination. This means
the Europeans should be very friendly
toward a open standard like this. But
also a lot of Europeans I think are
nervous about having their data taken
over by state actors whether in
Washington or Beijing.
>> Yeah. Uh Lisa, do you want to respond to
that quickly? Yeah, my concern was
actually a little bit more um that the
regulators may not see this as
sufficiently open if they're
>> memberships and board and it's closed
and there's no open mailing list and the
governments themselves don't have a way
to participate. Um that that the
structure you I I would if if that's
something you're hoping for. Um, I don't
know what the answer is, but I would
check that you're building something
that would be acceptable by
>> regulators if that's what you're hoping
for. Um,
>> that's that's that's a fantastic point.
And you know what? I realize that we
should probably ask that question when
we're on the panel next week. I wish you
were there, Lisa. [laughter]
Um uh but Karen and I can can ask that
question of Professor Rodelo because I
think that that's kind of like the you
know it's it's a it's a fundamental
question like how do you get like how do
you get government buy in on something
that's moving too quickly where the
governments like globally or like even
supernationally and and in the US
haven't come up with what their approach
is right
>> so it's like I can constitute like a a
group of like ministers talking about
this but none of them would agree on the
right approach to
and they're very leerary about blessing
something and I think provenence of that
thing is is is a is a good word for it.
Um my other uh tack was thinking about
how you generate demand for something
and um the thing I'm most used to and
and I I know Drummond has seen this too
in identity space is you bring something
that the companies you're talking to who
would implement it uh need that it
serves a need that they have.
>> Um and bringing something that is a need
that users have generally fails.
That's so true. Um I wish um Gavin
Starks was um this is not a good time
for him, but he was
>> um person who set up uh the open banking
standard in the UK. Um and I'm getting
some inspiration from him and he's he's
provided some input and advice on the
scope and spec of PDP as well. But I
think that goes to the point of like
there are there are multiple
trajectories to get fast adoption and
open banking was a really interesting
one which was um they started with big
and then went small and then there's
like the the other approach of you start
with small and then go big and I think
like just getting that critical mass
point.
I don't know if there's a wrong or right
pathway to this. Um you're you're all
obviously much more experienced than I
am on a lot of this. So if you have any
like really strong views I'm I'm all all
for like strong views. held um lightly.
>> What I would say is they're not
exclusive. It is often useful to go at
both roots to both try to create bottom
up interest and also find some kind of
body whether that is governmental
non-governmental corporation that can
encourage it usage from the top down.
>> Yeah.
>> Yeah. And
sorry
>> that's looking at the gaps and pain
points. If if you aren't addressing a
painoint,
>> then it's going to be very hard for you
to get any traction for something to
happen.
>> Yeah. Uh Drummond, you've been waiting
patiently. Sorry.
>> Yeah. And I I I do have to go to So, no,
it's this governance question. It's I
was I was going to ask just to clarify
scope. Um
>> are you looking at global scope meaning
do you want this to be uh you know
something adopted ubiquitously internet
scale or are you looking for it to be in
a you know specific industry or country?
>> Good question. Um
I personally ubiquitously because I
think that the way that we're managing
personal data is is suboptimal for
everyone involved in that transaction.
Yeah, I I don't disagree with you on
that. I'm just going to point out
whatever scale you're after, you have
to, in my opinion, design your
governance for that. And you know, a
single fivep person board to manage a I
mean, just look at DNS, right? You want
a internet utility there. I mean, it was
20 years in the in the in the making. it
it's you know huge international uh uh
effort to establish how do you govern a
utility like DNS so if it's a uh if it's
a utility if you want it to be at that
level I think you need to and it doesn't
mean you have to reproduce an I can but
of course this is the the
>> the a problem we're similar to you know
we're tackling a a related set of things
with uh
>> uh governance the first person
cooperative and it's it's It's a big
challenge. I'm not saying don't shy away
from it. We're not shying away from it.
But you need to think about how do you
get the stakeholders around the world in
all countries and cultures and personal
data is as large as people everywhere.
Just ask Lisa.
[laughter]
So with that thought as in we got to
think about that. I'm happy to try and
you know talk more to the extent that um
you know us and the other 1500 people in
Geneva will have time to do it but um
let's let's tackle it one way or the
other.
>> Thank you Dr. Yeah. Yeah. Perfect. Um
just on that point as as Drummond's
exiting I think the I think one thing
that that's surfacing here is this
trade-off between scale and immediate
speed. And I think it's surfacing in a
lot of areas relating to standard
setting in AI where
we need to move really quickly. I'm sure
you're feeling this in relation to
identity. It's like we need to move
really quickly on this with everything
that's happening. But how do we set up
bodies and systems that are able to
scale to the level of a DNS or an IAN?
That took several years to set up. We
don't have several years right now. Um,
and so maybe this requires a lot of like
the folks in this room thinking about
like what is interim arrangement so that
we can just get something out the door
right now that we just need to get done
so that we can start to start to make
traction on this.
>> Yep. Yep. Good thoughts. Okay. Sorry, I
do have to go now, but um I'll see you
in Geneva.
>> Thank you.
>> You bet.
>> See you in Geneva. See you in Geneva. Um
any further thoughts before I kind of
dive into a couple of membership and
conformance? The last two sections here.
Um these are all fantastic by the way.
Thank you.
Cool. Um so membership as I was
mentioning um and yeah I think that
based on this discussion this is going
to be very much in flux but um
I do like the I I I think the idea of
having
let me start with like what does the
supporter tier solve for an
organization? I think right now AI has a
PR problem. I was just looking at the
Pew Research um piece right now. Um let
me actually pull up that exact stat
because it's really fascinating. I was
um Justin, you've probably you're
probably super aware of this research.
Um um
content, let me see. So the stat is
um
7 in 10 Americans expect AI to make
their personal data less secure and only
3% say more secure.
And at the same time, anybody who I know
who's developing AI is struggling with
getting context to make their AI
performant.
And so I think about this is like, you
know, Lisa to your point of like what
problem do we solve for these people? I
think something like PDP or a standard
um like this can say
we we support personal data. We support
this. Now
I think about this in the context also
of um the work that you've done at DTI
and I'm like is it is it too easy just
to say you're a supporter if you're not
willing to kind of execute on a
commitment and and that's where I kind
of and that's the question that I wanted
to this forum of saying like
>> I hope you're a better salesperson than
we are because this this really requires
to to sell people on a vision
>> and this is a vision that with DTI we've
been unable to sell very many people on
like so it's been very hard to add
members to DTI and we are still tiny
about where we were three years ago
because we've been unable to sign people
up to the vision to grow and even when
we sign them up to be members it is very
hard to get them to move from there to
write code. Yeah. Yeah.
>> When when you know there's five VPs
inside a large company who each have a
veto power because this crosses lines
the you know the the the protocol people
the ops people the domain specialists
and the
legal and the you know port the one
portability team and any one of them
could say no and it's dead. So
>> yes
>> I I want to echo that. It's very easy to
lower standards. it's very hard to raise
them. When people join an organization,
it is often very easy them to take
something that's, you know, a lighter
level of regulation or self-imposed
requirement. It's very hard to add to
it. At the same time, if you have too
harsh or strict a standard and nobody
joins it, it's a dead standard.
>> Yeah. The solution I find is you want to
have
initially people joining to show
interest and then people joining at the
highest possible level to create that
most powerful of social forces, shame
and envy.
>> If a few entities will join the highest
standard, others will be compelled to do
that. We saw that today with Meta
calling on YouTube and Tik Tok to follow
their voluntary standards on children
that they agreed to at the barrel of a
regulatory enforcement action.
>> So I think in some ways again you want
to have small entities joining for any
reason but large entities joining as
high up the stack as possible.
>> The number one danger is if a large
entity joins a supporter to get their
name they'll never move higher and other
people will think that's the new
standard.
So this this is part of the one of the
pieces of the governance design um that
interacts with the the election of the
board which again is in flux.
I wanted to keep it at one organization
one vote. So that if meta was to be in
an organization with a bunch of um you
know like smaller companies that are
trying to do data portability meta will
only ever have one vote in relation to
this and that might not be acceptable.
Kind of leads to your point. like it's
hard to get these folks to sign up, let
alone sign up to a body that's
governance stacked against them based
on, you know, size. So, I actually think
that this is this is where I want um as
much feedback and as much thinking as
possible. Lisa, if you could um if you
like what's the what are some of like
the biggest lessons that you've learned
in terms of you've obviously articulated
one, which is like if anybody in that
chain says no, then it's a no. What have
you found to be successful in relation
to adoption?
Um,
it's just so hard.
Um,
the
some of this work is already going on in
the IETF.
>> Yeah. and and I'm trying to see how
parallel it is to when instant messaging
was hot and instant messaging came to
the ITF.
>> Um like why did people show up? Who was
afraid of missing the boat? One of the
advantages of bringing something to the
IETF is that uh companies like well
Cisco at the time but it would be
different names you you'd conjure today
>> couldn't say that they were unaware of
the work. they couldn't just ignore it
>> because they were at the ITF anyways
going to router layer working groups
>> and
the what Jabber did was first of all
they built an open source thing that
worked and had a few people few people
involved then they brought it to IETF
and gave up control
>> in order to broaden the audience because
again Cisco couldn't say um they were
unaware of it they couldn't say it
didn't work for them if they didn't put
comments on it
>> when they were there at the you know at
each venue.
>> Um and then after five years of it being
an ITF thing, they took all of their
extensions and built the XSF, the XMPPP
standards foundation. So they took all
the extensions back private.
>> Yeah.
>> But they needed to build the audience
and they went to the ITF for that. So
they kind of relinquished control to get
that broad base and then brought it back
in in order to make themselves
sustainable. I I do think there's a bit
of a journey like that for something
like this. Um that's actually really
helpful as an example. Um Karen, do you
have any thoughts on adoption from it
e's perspective?
>> Well, I mean [clears throat] you have to
go through our process. I don't know if
you've talked to Pervo, but he he's very
close to several of our
>> uh working groups.
Um,
>> perva and I are having a conversation I
think in two days at some point. Crazy
travel. [laughter]
>> You know, if you if you get adopted by
E, you've gone through our process and
it's something that goes out to our over
half um a million members in 190
countries. Um,
>> yeah.
>> So, it gets announced to those people
and you know from the working group once
you start that you can build this out in
many different ways. We actually also
have an open source community
>> um that that works on a lot of things
related to open source that come out of
the standards development process
itself.
So there there I mean a couple
communities that that could assist. Um
but you know it was thinking back to
your struggles to to start this. They're
still struggling to come up with an AI
governance model.
>> Um you know a lot of puts and takes for
um you know the UN wants to be in charge
of it and so does everybody else.
>> Um yeah and so you've got some
sovereignty issues to address. I think
you've got the same thing in terms of uh
personal identifiers. There's
sovereignty issues that need to be
addressed
and how you're going to going manage
that um in a in a very disparit world.
>> Yeah. It's similar to the problem
relating to governments like no there's
there's no north star that's kind of
emerged and there's no consistent um
approach to take. So to try to represent
all of them to try to create that broad
church is is a challenge.
>> You you can't do that. But but what you
can do is sift through it all and find
the the critical pain point for
everybody.
>> Yeah. and then and then build build your
your model and and in essence your story
around that painoint and how it solves
this in in a variety of uh interoperable
ways
>> because again right now what I'm looking
at in terms of AI governance itself is
the interoperability between all the
different models out there has to be
common threads common threads tend to be
personal data
>> data sources
Then it goes to is is the data
trustworthy?
>> How do you know?
>> I mean all of those, you know, it's
going to be a very nuanced and layered
approach to get down to your protocol
actually can address all of those
things.
>> It doesn't break any individual model,
but it allows models to interoperate.
This is actually a really cool segue
into this section of the conformance
piece because I think that some of the
incentives pieces I mean this is the
carrot and the stick piece. I think
conformance relates more to to the stick
and I'll kind of kind of talk about
that. So there are basically three uh
actors in the PDP system. There's the
source which is where the data comes
from. There's the accessor, the person
who's trying to get the data. And then
there's the verified operator. So the
operator basically enforces the
relationship between the source and the
accessor based on the PDP standard which
um which will which is to give
confidence to a user that they're in
control of their data. As in this slide
here to be a partner you would have had
to have implemented at least one of
these three pieces. So this is where it
could be kind of interesting. So put the
the like um think about um OpenAI right
now. Um would they be a source, an
accessor, or an operator? Um an accessor
simply needs to say we receive data in a
in a way through PDP.
That's the lightest level. So if you
wanted to be a member, a partner um and
you could say and and this could solve a
problem. So I know that OpenAI and
Anthropica are right now struggling with
the ingestion of personal medical
information. Right. So if they were
saying I want to be a valid a valid
accessor through the PDP system, they
would um they they they uh it could
solve a pain point for them in that they
want to access the data. At the same
time um
this is where the stick comes in.
Somebody um the way that PDP is designed
is we have these open source data
connectors that can be contributed by
the community. So essentially a
community member can create a way for
people to get their own uh chbt data or
the official organization and that's the
official source piece can say no no no
no we don't want this we we want to
control this like we want ourselves to
be the ones who are um developing uh the
data connected the source um so we
actually have two different types of
sources we have one source which is
verified by the technical committee as
safe and accurate and then we have an
official source which is like ChachiBT
or OpenAI saying no no this is the
official source of information from
OpenAI.
Um there's the stick element of that of
if somebody develops an OpenAI connector
that isn't OpenAI that's a risk to
OpenAI.
The only way they're going to be able to
solve that is through um
becoming an official source which
requires them to become partner status
and implement something that is PDP
compliant. question to the group. How
successful the sticks work in this
space?
Um especially it's basically like if if
you're a you know chief security officer
you're like wait somebody's able to
access their personal data through them
but you know GDPR download export right
that could be the the way that the data
is accessed. Um
what is there incentive there to say
like I don't want somebody to build to
build that on my product so I want to
build it myself. So traditionally
um companies treat this as a attack and
>> deploy everything from captures to rate
limiting to removing user accounts to
discourage this kind of action. Like
there's all kinds last 20 years are
littered with startups who on behalf of
the user try to gain access to
um data that the companies hosting the
data have not put into public APIs or
they do and then a third party gets it
and then like no we don't actually like
that we're yanking it and so they they
treat this like um like like they have
antibodies responding to it rather than
an invitation to come to the table.
Yeah.
>> And and user data portability is rare
enough that um if they have to terminate
some users accounts because they weren't
supposed to th to point a third party
client at their guey and they did
>> these companies would would do it.
What about where they can't where it's a
a GDPR export style flow and it's I
guess they just make it difficult. They
they go all the way to the 30-day limit
on GDPR and just make it
>> almost impossible for that data to be
fresh.
>> Yeah. And they and and um make sure that
the user that it's happening on the
users on their side that they can have
control over the um fire hose of data
and who can receive it.
This is where I want to get my white hat
hack white hat hat hat on. White hack
hat on. Um it's like is our open source
community faster and better to be able
to respond to some of these antibodies
that they put in?
>> It it may be the case like it this may
be an inflection point.
>> I feel like it is like from a just
seeing where the conversation is at and
how frustrated people are and how
important this is like the pure research
just shows that people are just like
I one of the reasons why they don't want
to use AI is is because of this data
problem.
Are we in a historically different
moment? Potentially.
>> Potentially.
>> I'm happy. I would stake my bets on it
and try to drive that. I know there's a
lot of people in the VA community that
that are frustrated with the way that
their data is handled. I think there's a
lot of people generally in the community
that are frustrated about how their data
is handled. So
>> well and I think there's a lot of people
that don't even know how their data is
handled.
>> Yes. Yeah. We definitely have to do the
education piece. That's not part of the
work here. But you know as Drummond said
like we if we do constitute a body like
VA does that education piece within our
community through our discord and
through community events. But I'm
wondering if like this as a body needs
to have a broader statement of education
around this. But I've I've also got to
think about this separation of tasks
because you almost don't want this to
turn into a lobbying advocacy group. It
needs to maintain that
>> that could be the kiss of death for for
anything going forward. Um
>> yeah,
>> I mean it's something to note but not
something to really build out at this
point in time
>> that it's important that that uh uh you
know individuals understand and um how
their [clears throat] data is used and
they and that they have a role and a
responsibility in that data use.
>> So I might share some insight here from
the experience at Bar. I know we have
seven minutes left but I want I want to
cover this. It's um the problem is that
when we tell people when we give people
the makeup of how their data is used,
the landscape, the architecture, they
come back and say, "Okay, so what can we
do?" And that's really the genesis of
PDP and why we want to do this because
we want to say, "Well, there's there's
an alternative because it's been really
tough actually to do these education
pieces on the VA side where at the end
of the workshop people like, "All right,
so what do I do? I just stuck using
Facebook again.
And so from an individual's perspective,
not having a collective voice or a
resource on this has been a real
challenge. I think um it's been quite
quite demoralizing on that side. Um, I
think where we're seeing a lot of
traction is smaller, um, even just like
series B style, like pre-public
companies that are trying to compete
with some of the larger players, um, and
want access to data so that they can,
um, that they can compete on a level
playing field. So, we're getting some
business support there and and maybe
that's the secret here. We kind of
attack that mid-market. Anyway, just
some thoughts,
you know, almost form a users group so
that um You know, it can be individuals
worried about their data versus the
small and medium-sized businesses who
really don't have a lot of resources,
but they need to know because their
business is going to be dependent upon
it.
>> Yeah. And they're their their pain point
that we're solving is that they're
scared of being eclipsed because of
these larger players
>> or or scared that their data is being
used and they don't know anything about
it.
>> Truth. Yeah. Um so this piece uh is
quite uh detailed in terms of uh
verified source, verified access or
verified operator. This is the one piece
that I also wanted to so the the process
for getting verification is also set out
in the write up. Um I won't go through
that but but right now it's supposed to
be light. It's basically submission,
review, grant and merge and publish. Um
so this is I covered verified sources.
Um and sources are actually really
important to us because the source is
essentially the the potential the has
the largest potential surface area for
um controversy I would say both
technical as well as from a relationship
management perspective uh carrot and
stick. Um the accessor piece is the
lightest and I think that's the one
where a lot of small to medium
enterprises are going to want to play
because they want to access the data. So
they'll say that they want to be
compliant. They'll indicate support and
then they will integrate with VA. We're
already seeing this with most of the
client base on the open data lab side of
VA, the the web 2 company. Um they're
really interested in ingesting user data
and we tell them that they need to
ingest user data on this system and
they're like that's perfect because we
don't really want to deal with these
platform APIs or we can't access the
data through platform APIs. So I think
this is actually going to be the
lightest form. And then operators is
obviously going to be the heaviest one.
These are the core of the system. This
is core to the system. VA um uh is the
only operator of PDP right now, but it
shouldn't be. There should be a lot
other potential operators of this system
that can credibly verify that the
users's grant will be complied with as
it relates to the data moving from
accessor to source.
Um the board's job is to keep the
register the board's main role is to
make sure that that register is
accurate.
And as it relates to um uh I was going
to say
>> in in in your structure, would you also
want to have some sort of compliance
role where you
>> I mean people might sign up for all of
this stuff, but how do you prove it?
>> That's that's true. Um and that's kind
of the the different levels here. Uh
sorry, let me uh supporter should it
require an additional compliance check.
Um, one of the things that we do pull
in, um, and I, uh, and Lisa and I are
talking about this of like I think that
from a one thing that DTI does really
well is being able to showcase like who
is this, is this entity the person that
they say they are and is the entity
that's requesting the data. I think when
when there are um, external uh,
certifications like that or registers
like that, PDP should adopt that as
reference and true. So Karen, to your
point, if um someone drops off the DTI
register, we should be in contact with
the the DTI folks and also remove that
from the the PDP register.
>> Well, I mean, I'm looking at a lot of
the things that come out of the EU and
and they're they're building in annual
compliance reviews and and edistations.
you're following the rules that that you
know you just because you said you
follow the rules to get into the club
doesn't mean you're going to continue
with following the rules. Um and so they
want a stationation or some proof.
>> The I haven't looked at the EU
attestations but that's definitely
something we should look at here. Um and
any of the I don't think the US has any
attestations at this point the way that
governing they really don't. Most of
it's coming out of the EU. I mean,
they've got one for their their cyber
security requirements. Um, they built in
some things for the their risk levels
for in their AI act. Um,
>> yeah.
>> And so, you know, governments like
asurances that they've done the right
thing and you're going to continue to do
the right thing.
>> I like that. Um, I'm mindful that I only
have a minute left and LFDT will
literally cut me off in a minute, so
>> I'm going to jump. No, no worries at
all. Um uh we talked about interim
arrangements. Um I think timelinewise we
want to I'll take all of this feedback.
Uh would we welcome any um any written
feedback as well um either in the GitHub
or just mention me directly if you if
you want to discuss this more deeply. Um
yes feel free to let's set up a meeting.
We'd love to talk about it. Um we will
present this at GDC and then present a
draft for public comment. So there's
going to be another turn of feedback
that we're going to be putting in here.
And I think that that's also the
opportunity to broaden the church on
this and to take and I think Europe is
the perfect place for this right now. So
that's the plan at GDC for us to try to
connect with folks that can provide
comment on this um and can be part of
the broad church that we're trying to
build to try to move this. Um and then
>> well recommendation find one government
to kind of review it and get their
comments independently.
>> Amazing. We an EU member state
>> um
Well, I mean we we have
>> has a committee of governments, you
know, look talk to somebody from
Switzerland or Brazil or somebody like
that,
>> you know, set up a bilateral meeting
with them one-on-one, walk through this
and get get their feedback.
>> Yeah, I I I will second that. If you can
get it from the developing world in
particular, and you're in art, Bhutan
right now, Art, but I know you can't
necessarily ring up the minister, that
would be especially powerful because
that is the community of nations that
have the most to gain and most to
protect from this.
That's such a good idea. I already have
two candidates in mind. Yes. Yes. Thank
you. I love this. I get so many ideas
from this. Um, these are just some open
questions. Um you 01 tell me what's
wrong with it. Of course um uh these are
the four questions but I think more
questions have actually surfaced on this
call that I'll send out in the um recap.
Um and if there's anything missing or
what's missing on this I would love um
any feedback. So I'll send out the recap
post this call. Um thank you guys so
much for attending. I really really do
appreciate it. Um I love all of this
information. I'm going to have to take a
minute to digest all of it and then work
out what I have to do next. But there's
some work to do before the 3rd of
September and then probably a lot more
work to do before we lock it in in
October. But um I really appreciate your
time. Thank you so much.
>> Thank you.
>> Bye. Bye.
>> Bye.