This is Icebreaker One’s response to DSIT’s Empowering people through data intermediaries. It can be published openly.
Please note that throughout this consultation, Icebreaker One uses the terms Open, Shared and Closed data as defined here.
If you have any questions about our submission or require clarifications please do not hesitate to contact us via policy@ib1.org. We have omitted questions which we did not answer.
Thank you for considering our submission.
Consultation response:
Amending UK GDPR
Question 1: To what extent do you agree or disagree with this statement: Providing legislative clarity alone in UK GDPR would be sufficient to address barriers faced by intermediaries?
No response
Question 2: If UK GDPR were amended to clarify the role of intermediaries, do you think any further details should be included alongside explicit delegation of data subject rights, for example, guidance, code of practice, specific data formats, frequency, or how portability should operate in practice?
While we agree that clarification of delegation would be beneficial to data subjects, any amendment to UK GDPR must be made carefully, in consultation with EU and other international data protection counterparts alongside operators of UK governance schemes that incorporate GDPR such as Open Banking and the Smart Energy Code. In particular, the change must not put EU adequacy determinations at risk, as the economic and social impacts of a weakened or lost adequacy status are likely to be disproportionate to the benefit.
If UK GDPR is amended, the purpose of, and limits to operation of, data intermediaries need to be made clear in the drafting in order to build trust. The drafting should include requirements for them to be: Neutral – the purpose for the data processing cannot be set by the intermediary; Fiduciary – acting strictly in the data subject’s interest, not in their own or a third party’s; Permissioned – possessing reliable evidence for permission to act as delegate for a scoped purpose.
To aid adoption and oversight, these requirements could be provided as model contract or privacy policy terms for intermediaries to execute as part of their usage agreements with the data subjects on whose behalf they act.
Regulation
Question 3: What obligations on data controllers, if any, would be effective in supporting requests made via authorised data intermediaries?
No response
Question 4: How burdensome would an authorisation or registration requirement on intermediaries be for your organisation?
No response
Question 5: What would be the advantages and/or disadvantages of the UK implementing a regime similar to that of the EU’s regime?
No response
Question 6: To what extent could it help to build trust between intermediaries, controllers and individuals?
No response
Question 7: How important do you view regulatory alignment with the EU for your operations, given potential changes arising from the Digital Omnibus proposal?
No response
Question 8: To what extent would a voluntary registration process for intermediaries likely be sufficient, to ensure services comply with rules?
No response
Question 9: For data controllers: would an EU-style model make you more likely to accept delegated requests from intermediaries on an official register?
No response
Question 10: If a certification scheme were adopted for data intermediaries in the UK, who would be best suited to carry out the certification process? For example: self-certification, regulator certification, government certification or third-party certification.
No response
Question 11: To what extent do you agree or disagree with the following statement: an authorisation scheme (whether notification-based, registration, or licensing-based) would meaningfully reduce the uncertainty or friction you/your organisation currently face?
No response
Question 12: For data controllers: How important is formal recognition of intermediaries (e.g., being listed, registered, or licensed) in giving you confidence as a data controller to accept delegated rights requests?
No response
Question 13: Which of the following approaches would best strike the right balance between assurance and proportionality for your sector?
No response
Question 14: To what extent would requiring the use of Portability APIs affect the level of friction your organisation experiences when responding to or submitting delegated data access requests?
No response
Question 15: How would requiring mandatory APIs affect your organisation’s compliance costs, especially relative to existing data portability obligations?
No response
Question 16: Which of the following would need further standardisation to make mandatory APIs more workable?
No response
Non-Legislative Options
Question 17: For data controllers: To what extent would a non-statutory authorisation scheme, potentially run by industry, increase your willingness in using or accepting requests from data intermediaries?
No response
Question 18: What standards or criteria would be most important for an industry-run authorisation scheme to be effective?
No response
Question 19: What oversight or accountability arrangements would be necessary to ensure an industry-run scheme remains trusted?
An industry-run scheme must have strong, visible governance to maintain trust and ensure the scheme operates in an accountable and legitimate way. This includes establishing principles and processes, defining roles and responsibilities, and a significant investment in public communication. Delivery oversight with operational monitoring and clear routes to redress are also required.
Governance must be based on principles of transparency, accountability, engagement and responsiveness, with enough flexibility to adapt to specific socio-technical contexts and goals. Adopting an iterative, collaborative approach with stakeholder engagement and regular review ensures that an industry-led scheme remains effective, credible and trusted.
Question 20: What measures, if any, would be needed to ensure such a scheme does not disadvantage new or smaller entrants?
Schemes should provide a clear, tested pathway to operation, with transparent requirements, onboarding and compliance expectations. Providing a tested pathway to operation gives greater certainty and reduces the cost and complexity of entering the market. The pathway may include variable entry requirements dependent on considerations such as data sensitivity, tiers of purposes, and number of data subjects using the intermediary.
IB1’s Project Perseus, the UK’s first cross-sector Smart Data scheme, provides a practical example. Its 6-month pilot phase tested the technical, legal and user experience aspects of a trust framework, highlighting the need to reduce friction and enhance the way Perseus works for SMEs, energy data providers, carbon accounting providers and financial service providers. A sandbox environment enables all participants to develop their implementations safely using synthetic data, and to continuously improve SME user experience. The scheme also provides onboarding support and guidance, open source example implementations, case studies from participants and supporting discussion channels.
Question 21: For data controllers: Could a statutory code of practice increase your confidence in using or accepting requests from intermediaries?
No response
Question 22: Would an industry-led code provide meaningful reassurance about the credibility of intermediaries?
Yes, a well-governed industry-led code should provide meaningful reassurance about the credibility of intermediaries, provided that it meets the requirements for transparency, accountability, engagement and responsiveness mentioned in Q19. Particular attention must be paid to messaging and communication intended to inform and reassure data subjects so they are not unduly burdened in their decision to use an intermediary as a delegate, and are clear about routes to redress if there are issues with the intermediary or the data transfer and onward use.
Question 23: Do you believe voluntary, industry led approaches can meaningfully reduce data controller friction that was reported in our call for evidence last year?
No response
Question 24: Would updated ICO guidance meaningfully change how your organisation handles delegated rights requests?
No response
Question 25: What specific elements of guidance would be most useful to you?
No response
Question 26: Would guidance alone be enough, or would you expect additional regulatory or legislative measures to address barriers facing the intermediaries market?
No response
Data Portability Through Smart Data Schemes
Question 27: To what extent could a Smart Data scheme provide sufficient trust for intermediaries operating in your sector?
Smart Data schemes are a proven, scalable approach to secure, private data sharing and should be built as a priority. Building interoperable schemes that are based on harmonised legal, procedural and technical definitions will provide the basis for trusted data sharing and for intermediaries to operate effectively.
Our experience with Perseus demonstrates that trust is strengthened when Schemes have a clear purpose, with well-defined roles and responsibilities, transparent governance, assured data flows, proportionate technical requirements and onboarding support. Its pilot and sandbox also showed the value of testing these elements with participants and iterating the framework in response to stakeholder feedback.
By defining priority user needs and use cases, schemes can be designed and adapted to real-world requirements, identify and mitigate uncertainties early and reduce friction for participants. This approach provides clarity and assurance needed for intermediaries while allowing schemes to evolve as the market develops.
Question 28: What measures would be needed to ensure Smart Data schemes adequately support intermediaries, or vice versa?
A Smart Data scheme involving intermediaries simply needs to include them in the governance framework: defining their roles and responsibilities, accountability and liability the same as for other scheme participants. This provides certainty for all participants, reduces friction and supports trusted data sharing.
Smart data schemes should provide communication guidelines or requirements that assist intermediaries in their approach to building user journeys, disclosures and permissions.
Smart data schemes should be designed for continuous improvement and adaptation so that they remain relevant and effective as technology, markets and user needs evolve. Care must be taken to ensure that ongoing changes do not become onerous for participants, or introduce risk or confusion for end users.
Question 29: How do you see a Smart Data scheme in digital markets interacting with data intermediaries?
No response
Question 30: What would each of their respective roles be in supporting effective data portability?
No response
Final Questions
Question 31: Are you aware of good international examples where action has been taken to improve the operation of data intermediaries?
No response
Question 32: Do you think one option or a combination of the options discussed in this consultation would work best to improve the operation of data intermediaries in the UK?
No response
Question 33: What other options should be considered in your opinion?
No response
Question 34: What additional infrastructure, if any, do you think is essential to enable data intermediaries to operate effectively especially in high-priority sectors (for example, finance, energy, health or transport)?
Trust frameworks operate at sector level to collaboratively establish and maintain a light layer of identity management, governance, common definitions, principles and open standards for data sharing. They provide the foundations of a trusted data-sharing ecosystem that sector- or use case-specific schemes can build on.
Trust frameworks and Smart Data schemes should be complementary. Trust frameworks provide the common foundation for identity, governance and interoperability across a sector or sectors while individual schemes can build upon these foundations to target specific market-wide applications. This approach enables targeted and efficient data sharing and identity verification without requiring every scheme to recreate underlying trust infrastructure.
Question 35: What interoperability challenges currently limit the effectiveness of data intermediaries?
No response
Question 36: What types of infrastructure would help address these challenges? (For example, technical standards, governance arrangements, or supporting services).
Infrastructure that enables and supports trust frameworks for data sharing should be prioritised. This includes clear governance, open standards and identity and assurance mechanisms that support participants to interact with confidence.
Good governance also addresses challenges of adoption by providing participants with clarity and confidence needed for technical infrastructure. Governance should be designed into the framework from the outset rather than through a technical-first approach. Infrastructure should be designed as an enabling layer for the trust framework, with technical standards and supporting services developed to implement and reinforce agreed governance principles.
As more schemes are rolled out, work is needed to characterise and harmonise the ID & verification, accreditation, legal, licensing and procedural aspects of data sharing in order to ensure schemes are interoperable and remove friction for participants and end-users. It is likely that these considerations, not technical interoperability, will cause the majority of bottlenecks to realising the full value of data portability enabled by data intermediaries.