Yes, thank you. Before I kick that off, I have one question for you. Just by a show and raise of hands, who has ever regretted subscribing to a paper or to an email or something else? Okay. Just from my own life, we once took care of a young lady, and she came home after an afternoon of shopping, and she looked a bit sad because she subscribed to a newspaper. So what happened to her, she was in the shopping street, and some people approached her with a nice sales talk. And in the end, somehow she put down her signature, and now she had this subscription.
So she came home to us and asked us to help how to solve it. And in this case, luckily for her, there's the legal obligation of these service providers to allow you to cancel for free within 14 business days. So that helped her. But actually, this feeling of regret of a decision that you made at the time, at the time that you were thinking consciously that you were making this decision, is an underlying theme of the research that I did. Really briefly about me, I'm having two hats. And this afternoon, I'll be wearing my research hat.
I also have a consultant hat, sometimes difficult to explain to people, but we do IAM advisory. Sonic B is a boutique shop in the Netherlands and Germany. And I'm also currently doing PhD research at Delft University into exactly this risk. Because what the EIDIS regulation says is that we're going to give this wallet under the sole control of the user, and thereby giving this user full autonomy, independence, freedom, and control over their data and where they share it. At the same time, the legislation also said this should protect them also against things like manipulation.
And making a decision and regretting it afterwards can be one effect of being manipulated into a certain action. So this was the starting point for my research. And last year, I already shared a bit about it. And I said, okay, so if we are going to give this user sole control, and we send them out there, like a youth in the shopping street, and people are preying on them to sell subscriptions, or preying on them to get their data, we need to give them proper protection. And this was one picture that I used last year to show proper protection with responsibility.
You also need to be able to carry this responsibility. So bringing that back to this context of the user that now has this wallet, with the issuing parties, and the relying parties, of which we don't know exactly what data they will have, I was a bit pleasantly surprised by the presentation just now by Mirko that said, yeah, but the wallet is going to check every request. And if this relying party is asking too much, they will block it. And I've had that conversation in my interviews as well. And I said, yeah, but how many attributes are we talking about? And is that use case specific?
We're now working at a customer that says, yeah, I can use date of birth for registration, but not for the periodic checks. So now I need to register per use case what data I'm going to get from this wallet. And is that the list of the bid data, or is there more data? And what then happens to the story of this wallet can be used for more purposes as well. So my loyalty card can be in there. Do I need to get that also in the register? So there are still questions to figure out. But similar to the example that I gave of this youngster, there is a legal protection that is helping us.
So the first part of this research is already published last year. And my question was, what is exactly this risk of oversharing with the wallet? How can we unpack that risk? Because there are a couple of actors involved, a user, a wallet, a relying party, which contributes what to the risk? And my hypothesis was, we need to protect you, the user, the citizen. So what do the users need to properly handle this sole control of over their data? And what measures can we take? And full disclosure upfront, my results show that we can't really fix the user in the wallet.
If we restrict it too much, we will hamper the ecosystem development. And if we leave it wide open, the user will probably overuse it. So that's a difficult point as well. So I ended up at the relying party. So instead of asking, how can we give the user the capabilities to handle this control? The question now is, how can we influence all these relying parties to state a responsible data request? So my research was based on 17 interviews with relying parties, government, two NGOs, one on privacy, one on the rights of minors, and a wallet provider. And I asked them those questions.
And he said, yeah, well, the risk itself is not that complex. It's sharing more data than required. So we need to list all the requirements, all the use cases, all the purposes. And if we ask more, then that is the risk. This regret came up in a lot of interviews. Already kind of hinting towards the fact that even though I think I'm an autonomous being, and I make informed decisions, I can be quite easily manipulated and influenced by nudging techniques, by dark patterns, or just by the 5% discount, and please download your entire wallet to my platform. It's also highly contextual.
So it's difficult to kind of do a blanket approach to this risk, because when I'm with the doctor, I really want to share a lot of data, because this guy is going to give a diagnosis. But when I'm at the shop, I might want to share less. If I'm an alcoholic, I may want to have a lock on my wallet that I can't buy alcohol. Would that be possible to not share data and prevent myself? So in these contexts, when you go into the details, it becomes messy really fast. It's realistic. It's a real risk, but nothing new. We already overshare a lot. And it originates in over-asking.
So what they said, if the relying party wouldn't ask too much, then we wouldn't have this risk. One of the challenges with relying parties is that they have a data-driven business model, or at least some of them have, and that is the incentive to get more data of all their users. So looking at the aspects that contribute to the risk, I found that from all these interviews, and the user, the fact that the user has full control creates this risk of oversharing. That the user wants to buy an apartment and is willing to share any data for that purpose is goal orientation.
Also, if you can speed up the process, they don't have time to think, they will just hit the button. The fact that I'm very aware that I'm not need to share my passport here at the supermarket, but that that context awareness can get lost online is also a contributing factor. Does the average Jane or John Doe understand what portal they're looking at and what is proportional? The indifference from some users, they really don't care. They don't understand perhaps. One interesting was the projected trust. So I'm getting this wallet from the government. So it's trusted, right?
I can just use it because it's trusted. The fact that the issuer is trusted doesn't mean that the request and the data transaction that I'm doing is trusted as well. But you need to explain that to users. And the mere request fatigue. So what we have with the cookie consent walls, we'll just click it through because after 20 of these approval buttons, you'll click it through. Now the wallet contributes here by being really easy. So I was glad to hear that we're now already having a lot of discussions on blocking requests or not.
The fact that it's qualified data also makes it more interesting for a lot of relying parties because I cannot lie about my date of birth anymore. I cannot lie about my city where I live anymore. And one of the privacy groups made an early statement on that saying, this is what the big tech wasn't looking for. We can eradicate anonymity because every Facebook account now needs to be validated with an EUDIW. So how does that work? And the design orientation. So is it privacy by design or not privacy by design?
But the most factors were at the relying party where they said that if a relying party has a data driven business model, they will have a natural incentive to gather data. If they are the only one that delivered a service, they have a monopoly position and they can force you to share data. They can bundle data requests. So I don't want to share all the data.
Well, is that possible to share half of the data requests or part of the data? What does that, does then the relying party give me that service or not? Or will they say, well, Hank, too bad you can't give me your family composition out of your wallet. We'll get the data out of the wallet that you have. And now here's this online form and you can still submit it. So it will not be qualified, but the relying party, if they want to have this data, they will find a way.
Also, some relying parties have strong assurance requirements, think banks. So what happens if the auditor comes in and says, well, you have this level of assurance based on data that you get, but you could have gotten qualified data. Why don't you ask more data from your users? Because then your risk level goes down and we have more assurance. And the other question is, does the auditor know what a verifiable credential is and will he rely on it? Or are the audit and control framework still looking for the copy of the passport? And if it's not in the file, you will get a finding.
The last two were the fixed customer journeys. So we spoke to one party and they said, yeah, but now I'm getting all the data at the start of the process. And then I carry it through with the wallet. I can minimize that. I can get the data at the point where I need it, but then this customer needs to come back every time I need another attribute. How does that work? And of course the malicious actors can influence and manipulate.
Now, from that, I have four areas that came up, what the user needed from my hypothesis that we can fix the user. And it's just plain knowledge, knowing stuff, then being aware of your situation and your context. And from that, having also the understanding and that is more geared towards understanding the impact of data sharing, the impact of privacy towards also the indifference aspect. And then you also need to be able to critically evaluate such a data sharing request. You need to be aware that it's actually a data sharing request with a certain impact.
And that also means that especially around haste and goal orientation, it's really difficult to stop and think because you're not sharing data. You're buying a cinema ticket. So everything that gets in the way, you'll just click it through. Let's get it over with. So it poses a lot of responsibility and requirements to the user. And we also saw that digital literacy is spread through the population, not in an evenly manner. So when I asked the interviewers, do you think the users are capable?
The general response was, no, we cannot trust them from our expert opinion with this responsibility because they just don't have all these things that they need. There's not the proper protection in place. And mind you, this is data from mid last year. So everything that these guys here have been developing in Sprint Funcus and in the EDI programs has happened after that. But we said, no, the user have limited capabilities. There is not one user. We're talking the entire population. So we have a highly educated, lower educated, elderly, young people, handicapped people, basically everybody.
So it's going to be extremely difficult to get this one tool out to the general audience and have them responsibly use it. I did continue in those interviews to say, okay, so what kind of measures do we take? But quite quickly became apparent that this user cannot be fixed. They need to think before they share. And there are a hundred ways to distract the user or get them to not think and get into a flow of just sharing. There are many things you can do on the wallet.
Differentiation in the UX, change of screen color when sharing critical attributes, but then you need to identify which are critical attributes and which are not. Introduce friction, but too much friction will make your wallet unattractive and they will find a wallet that is easy to use. A privacy first setup. So that was an interesting one where one said, I can design the wallet and you need to configure it so that it is more privacy sensitive. I can also design the wallet and require you to make the effort to make it less privacy sensitive, so more open.
So in that design, you can also make choices that steer the user and set the default setting. Looking at time, I would have loved to go through all of them, but I can't. And it's also because this came out of the research as a lot of measures that you can take on all of the actors and aspects of this combination. But my results was, yeah, we can't really fix this user. We don't want to restrict the wallet too much. Also not because this is under the user's control. Who are we as a government to restrict this user? So we get into the whole paternalistic discussion.
So to what level can the government intervene in my free will? I mean, I have a passport. I can share the copies wherever I want. There's no cop standing next to me saying, no, you can't share it here. So how does that translate to the digital realm? Or is it actually wrong in this realm already? And the question that I ended up with is, so then how are we going to solve this? Because what would be a reason for this relying party not to over-ask? And that means that I need to look at it from a different perspective from the relying party.
And I chose a digital platform also because my promoter is on digital platforms. So aligning interests there and an ecosystem perspective. So what can we do in the business model of digital platforms or what changes in the ecosystem around digital platforms with the introduction of the wallet? And then I'm not looking at the ecosystem of the wallet itself, but the ecosystem in which this wallet will be used. And then what incentives play a role there? Because ecosystems have a funny characteristic, and that is emergence.
So ecosystems consist of independent actors that work together, but you don't know where they will be next year because they talk to each other, influence each other, and there's no clear path. Similar to what we used to have in a company, you have a value chain going from A to B. And then when companies started working together, we saw value networks creating also with independent actors. So we don't know exactly how that will evolve. And that is part of the study of my promoter as well, looking at what incentives can we put in place to steer this development of the ecosystem?
So can these be business model driven incentives, like what you just said about where does the money come from? Where is the profit? Or reputation? So you see with platforms, the network effect is sought after because that means growth. More users means more suppliers means more users means more suppliers. So then you get a very large platform. But things like reputation and legitimacy can restrict that somewhat. So there are studies already that show, yeah, but you can't grow that because if you have all kinds of fraudsters on your platform, people will start to step away again.
So that will influence your decisions on how to shape a platform. The other is the transparency. So what I really liked in the presentation about the dashboard, if we create transparency, I'm thinking so everybody can register for every data element. We're not going to check it.
Okay, that makes it fast, but also dirty. But if it's transparent, then I know that some privacy people and some human rights people and some other interests will just go through it. And then you get pressure out of public opinion. Not sure in the current geopolitical state if that will give you anything, but that's a different. And the last one is just regulation.
But again, regulation without enforcement is just the toothless tiger. So they will bite, they will chew a little bit. In Dutch we say, and then they let go. So that's not making any impact. And I think one of the challenges there is if we give this wallet a report suspicious behavior button, it's really interesting to see how this will work because where does that message go through? What happens if you get 1 million messages in a day? How do you investigate? Where do you put a proof? And who is then going to intervene in this ecosystem?
Because in the EIDAS, it's clear that the government has a role. But around the digital platform, it's less clear who is the ultimate owner, who sets the rules of that ecosystem. It's more that emergence again, that working together. So that's what I'm going to spend the next four years at Delft University on with my academic glasses on. So that will be a lot of conceptualizing, problematizing, and all that type of stuff. By the way, I can tell you there's a huge load of knowledge in that domain that we're not aware of, but that we should use more.
And then this could be like the ecosystem of a digital platform with the platform owner, let's say, Apple, the complementor, so all the people that create apps and things that you get on this platform, and then the consumers that make use of it. And then I think the question is that we have our own ecosystem around the wallet. And where will this wallet end up? And what will it do in these business models? I think it will be another study to see how these two influence each other.
So my first question will be, if we can kind of understand how this works, and we drop the wallet in there, what happens there? Because if nothing happens there, we also can predict the behavior that we already see nowadays in these business models. So with that, I see Torsten standing up. That's my cue. And I'm also right before lunch, so I'm really glad that you could stay until this time. If you want to ask some questions or get some more information, reach out to me. I want to thank you for your attention.