Skip to main content

PRI3

Control stays with the holder

Nothing can be proven about data without its rightful controller — the data subject, or a holder acting under the subject’s mandate — because proof generation requires their cryptographic material: consent is enforced by construction, delegation is itself a provable and revocable artifact, and where processing occurs is declared in the contract and enforced at the access layer.

Rationale

Control that depends on a supplier honouring a setting is control in name only. Requiring the holder’s own cryptographic participation means consent is enforced by the system itself, not by trust in whoever runs the software — so data subjects, and the businesses acting for them, keep genuine authority over their information. This principle decides who may authorise the exchanges that Principle 1 shapes; together they ensure nothing crosses a boundary without both a real need and a real mandate.

Implications

  • No administrator, operator or platform back door can generate a proof on the holder’s behalf, so no provable claim about protected data can be produced without the controller’s authorisation — which reassures customers and regulators that the data’s owner cannot be silently stood in for.
  • Delegation is a first-class, revocable artifact, so mandates — including assisted arrangements for people who cannot act for themselves — can be granted, evidenced and withdrawn without re-engineering the system.
  • Where processing takes place is a declared, contract-level choice enforced at the access layer and backed by an audit trail — an operational commitment you can point to, not a cryptographic guarantee dressed up as one.
‹ All twelve principles

Build on the principles
from day one.

Join the waitlist