We are pleased to introduce PDP-Connect, a new personal data consent and authorization specification lab at LF Decentralized Trust (LFDT). The lab was initiated by the Vana Foundation, the organization behind the Vana protocol. The protocol, which was launched in 2024, is now among the most widely adopted personal data networks, with a community of more than 1.5 million people managing and sharing their data on their own terms.
Through PDP-Connect, the Vana Foundation, which sits under LFDT member Vana, Inc., is working with the LFDT community to develop the Personal Data Portability Protocol (PDPP): an open specification for how a person authorizes an application's ongoing access to their personal data, and how that authorization is enforced.
There is more at stake here than data portability. Every AI system is only as good as the context it works from. For the tools people use every day, that context is personal data: your history, your preferences, your conversations, your records. That context is who you are, as the digital world sees you.
So the question of who controls it matters. Whoever holds your context shapes how AI understands you, what it can do for you, and what it gets wrong about you. Today that control sits with whichever platform happens to hold the data. PDPP moves it to the person: a standard for authorizing access to personal data is a standard for who governs the context AI runs on.
Today there is no standard way for a person to authorize an application's access to their data. Users hand credentials to agents they do not control, applications scrape what they can, and each platform that offers data access does it differently, with its own scopes and consent flows. GDPR Article 20 and the EU Digital Markets Act establish the right to portability, but as the Data Transfer Initiative noted this year, standardized direct transfer of personal data remains "a work in progress, with few exceptions."
Serious work already covers the neighboring layers:
PDPP adds to this corpus of work by defining the permissioning and consent layer. It creates a standard way for a person to grant an application access to specific personal data, on their terms, with proof that the server enforces the grant, and to bring their data with them wherever they go. It profiles OAuth 2.0 and RFC 9396 for personal data, adds user-defined access authorization for which records and under what scope, and composes with each of these layers rather than replacing any of them.
Vana began as research by Anna Kazlauskas and Art Abal, then students at the MIT Media Lab, asking how an economy for user-owned data could actually function. The question was never abstract: if your context is who you are in the digital world, then owning it has to mean something. The protocol that grew out of that research now serves more than 1.5 million people managing and sharing their data on their own terms, and builders creating applications on the basis of user consent.
PDPP extends what that network learned into a standard anyone can implement, with an open home at LFDT where anyone can help shape it. Adoption is the measure the market cares about most, and adoption is what a neutral, shared specification makes possible.
Throughout August, a working group went through the draft specification section by section across four open sessions, from architecture and foundations to governance. The sessions drew participants from the IEEE Standards Association, data portability practitioners from major consumer platforms, and builders and researchers from across the LFDT community. The draft they shaped is open now: read it and file issues at https://github.com/PDP-Connect/pdpp.
The PDPP draft will be presented at the Global Digital Collaboration Conference (GDC) in Geneva (September 1-3, Palexpo) and, thereafter, become available for public comment.
GDC is where the world's digital infrastructure gets decided: the one table where governments, UN agencies, and the internet's standards bodies sit together. Hosted by the Swiss Confederation, its co-conveners span governments and standards bodies, among them the European Commission, the International Telecommunication Union, the World Health Organization, ISO, IEC, W3C and ETSI. They sit alongside the consortia through which the world's largest technology companies do their standards work: the FIDO Alliance, whose members include Apple, Google and Microsoft, the OpenWallet Foundation, the Cloud Signature Consortium, GLEIF, Trust over IP, and LF Decentralized Trust.
Within that program, the lab's moment is the PDP-Connect community launch session:
On Thursday September 10 at 9:00 am Pacific, the lab will host an online session, "Introducing PDP-Connect," for anyone who can't join us in Geneva: builders who want to implement the standard, businesses that handle personal data, and individuals who care about who controls theirs. Presented by the project maintainers, it covers:
Register here: https://www.meetup.com/lfdt-sf/events/316182770/
The PDP-Connect lab is currently maintained by Anna Kazlauskas, Tim Nunamaker, and Art Abal of the Vana Foundation.