Personal data

Data has been structured in effectively the same way since 1760. It was a great structure for a card index, but once connected to the internet it has caused real problems. We are exploring why and what can be done about it.

$10.22 Million
Average cost of a US data breach in 2025, the highest of any region.
$332 Billion
Estimated size of the global data broker market in 2025.
€1.2 Billion
GDPR fines issued by European regulators in 2025 alone.

Our approach

The prevailing assumption, that organisations should gather and store personal data, has been shown through the constant breaching of vast data stores to be catastrophically wrong. Our research examines the alternative: that individuals hold and control their own personal data on their own devices, and organisations request permissioned access to answers rather than copies of the underlying material (proof of being over eighteen rather than a full date of birth, for example). This removes the honeypot of centralised PII on which the industrial-scale fraud economy is built.
The risks of centralising data
The risks of centralising data
As federated, centralised identity systems have proliferated, identity and personal data have become one and the same placing consumers and organisations at risk.
The end of the seed phrase
The end of the seed phrase
A persons identity is incredibly precious, but because of the way in which technology and identity have evolved, todays systems don’t treat it with the care it deserves.

Discover our wider research

View research