WHY
On the Internet, and in the digital realm, we humans are now second-class citizens. Despite being by far the largest population, with the most advanced capabilities and tools, and the most complex needs – we are subordinate to organisations. We are ‘Data Subjects’. That is an anomaly in that organisations are constructs that consist of aggregations of humans coming together for a particular purpose – understanding the nature of those organisations and to whom they have fiduciary duty is crucial to navigating this paradox.
If we want scale, optimisation for all parties over time, and interoperability, we must enable individuals to be more than second class citizens. Legislators must ensure that the means to enable this is enacted, or at worst not excluded from regulations.
In technical terms this means we must move beyond the ‘client-server’ assumption inherent in much of today’s digital communications model (World Wide Web, browsers, mobile application ecosystems, ‘smart TV’ et al). The ‘client-server’ approach has both technical and then power implications. Regulations that embed this technical and power approach enshrine that imbalance as the only way in which societies can operate. The Internet itself does not assume this model in that all Internet nodes are of equal status at the protocols level.
WHAT
The IEEE 7012 standard published January 2026 (aka ‘MyTerms’) builds at The Internet level and thus does not assume a technical or power imbalance. The standard operates top down (do not do online what would be unacceptable in the physical world). And bottom up in that it assumes all digital capabilities and protocols of The Internet are available to all parties. Just as with retail banking and mobile telephony and any other category that runs as a network, any party can interact with any other party on the network with minimal technical friction.
Specifically, MyTerms mandates and assumes that both parties to a proposed dataexchange have an agent acting on their behalf that propose, negotiate, sign and record theagreements that govern the exchange. It does not mandate the form that the personal agent or entity agent must take. But it is reasonable to assume that individuals may use personal data services, fiduciary data intermediaries, apps, browser plug-ins, digital wallets or agentic AI. And that ultimately such signal management and recording will be built into browsers and operating systems (mobile and otherwise).
Personal Agents that enact standardised, machine-readable privacy signals, as envisaged in EU Digital Omnibus Article 88b have now been built and will be brought to market via MyData Global and others in Q4 2026. On the organisation side the agents will surface within web and app servers; or be outsourced to consent management providers or customer data platforms. The relationship artefacts from agreement signing can be madeavailable for use in CRM, customer service, marketing and advertising systems. Digital wallets, individual or organisation-side can be used to ensure the parties are who they say they are where that is required or useful.
It must be made clear that the standard is about the means through which data sharing agreements are proposed, iterated upon, signed and recorded. It does NOT replace any local privacy, data protection or other regulation. It sits on top to enable the agreement process between individuals and organisations who wish to exchange information under standardised machine-readable contracts. This approach to adding contract-based data sharing agreements over and above regulations as a best practice is already very common in B2B scenarios. MyTerms enables that to also work well in consumer data sharing scenarios. It should also be made clear that the standard is as much about enabling data that people do want to flow, as it is about stopping un-wanted flows. IEEE 7012/ MyTerms has a positive business case, not least because it enables Intent signals as well as privacy signals. Intent data, when shared in ways that protect the individual, is premium fuel for new, privacy-minded approaches to digital advertising, marketing, and AI-powered agents.
The innovations in the standard are:
• The individual is the first-party, organisations are the second
• It runs on contract law, underpinned by other relevant regulations
• Both parties are assumed to have ‘an agent’ (various options apply)
• Both parties must retain their own copies of the signed agreements
• Designed to enable all digital relationships between first and second parties; and specifically prevent 3rd party surveillance and similar models within these contract-governed relationships
The key innovation that relates most to ‘privacy signals’ is the default MyTerms agreement named ‘Service Only’. This concept is deeply rooted in GDPR and similar regulations and says unambiguously ‘I wish to engage with your digital service but at the base service level; and remind you of your data minimisation and purpose limitation obligations. So, to be specific, I do not wish any third-party add-ons such as cookies or other tracking devices installed on or around my devices’.
HOW
An illustration of one mobile app-based implementation is shown below. It is underpinned by an open source ‘handshake’ protocol; think of that like ‘Docusign’ for standardised privacy policies that are clear, equitable and recorded by both parties to the agreement.
This may sound troubling to many organisations, and policymakers. However, that default ‘Service Only’ signal is accompanied by more granular options through which the individual can manage, with a few clicks, a greater depth of ‘first party’ relationship. And better still the MyTerms agreement ‘Personal Data Contribution – INTENT’ is a clear and unambiguous ‘I’m in market’ signal that again can easily be configured and made available to chosen organisations. There are further contribution agreements optimised for ‘Data for Good’ projects, and to enable desirable AI model training and deployment. This model is very enabling of data exchange relationships that are worthy of trust. And specifically excludes those that are opaque, one-sided and portrayed in ‘take it or leave it’ terms.
The privacy signal approach works in the two main relationship states that individuals encounter online. Those are:
• Pre-relationship/ ‘just looking’ in which cookies and similar tracking devices are the primary problem being regulated
• In a digital relationship with an organisation (usually seen as ‘has an account’) in which both cookies/ similar and ‘consent’ (with associated rights, data types shared and purposes enabled) are being regulated.

We offer up the above and the ability to leverage the IEEE 7012 / MyTerms standard in the requirement around Privacy Signals/ Article 88b; or indeed in the wider requirements for simplification of privacy and data protection legislation.We do so on the basis that it is an already published global standard that points to a much higher bar for individual data protection and empowerment than the current norm and does so without compromising at all on the economic necessities or benefits derived from personal data exchange.
It offers the option for forward-looking policymakers to support personal empowerment online as well as protection. And in doing so help future-proof against agentic AI and the pro’s ad cons that this will undoubtedly unleash.
ART.88B and MyTerms
Article 88b in the EU Digital Omnibus began as a very clear statement of intent, that people should have a single, standardised means of expressing their online privacy preferences. It had a ‘carve out’ for the media sector included. The text has since been the subject of much debate and lobbying and is under threat of not moving forward at all. We must be clear, that not moving forward with advanced privacy signalling leaves the individual ‘consumer’, who is actually the originator/ source of the data in question, as able to do nothing other than click every banner and check every consent box in front of them.
IEEE 7012/ MyTerms offers the ability to move beyond that to a world where the personal data that should flow does, and the data that should not (as defined by individual preferences) does not. MyData and others will push forward and enable that model; we ask that regulators ensure this win-win model is supported in legislation.

