In our latest guest blog, Iain Henderson, Volunteer with The MyTerms Alliance, explores the challenges facing today’s digital privacy landscape and the need to rethink how personal data is shared and managed. Iain introduces IEEE 7012 (nicknamed MyTerms), a global standard designed to support clearer agreements between individuals and organisations, and considers how new approaches to digital trust could shape the future of data exchange.
Do you really enjoy reading and clicking through to the detail on cookie banners? Or you can’t wait to read the next 30-page privacy policy and consent notice that pops up in front of you?
I suspect that’s not the case; unless of course you are a highly paid privacy and data protection expert or corporate lawyer paid to do so….
That being the case, this suggests that vast amounts of data exchange and related transactions are taking place based on terms that have not been read, far less understood and agreed with.
How can we have built an entire global digital ecosystem across all aspects of life on a premise that people have read, understand and agree with when in fact they have done none of those?
Maybe that crept up on us over 25-30 years, but that we have such a situation is now undeniable.
And then we have the almost complete lack of meaningful teeth for the ‘data rights’ we all have as individuals. Data portability for example, or even the basic ability to amend or delete which is not possible when data has been subsumed into AI models.
And virtually no enforcement for massive scale known breaches of data regulations such as Real Time Bidding in AdTech which has been called the biggest data breach in history. Or fines being issued that are just a small cost of doing business for the big tech players involved.
In other words, personal data is in a real mess in today’s online environment. And doing more of the same will just make that worse…
Thankfully, help is at hand….
Earlier this year, a new global privacy standard was published; known as IEEE 7012, nicknamed ‘MyTerms’. Some 8 years in the making, the standard offers a potential route through the current mess.
Simplistically, rather than each of us having a different privacy policy in place for every organisation we deal with, people can choose from a series of standardised agreements written from the individual perspective. That means built in transparency. The agreements have been vetted by consumer groups; but are also very reasonable from the organisational perspective. Each agreement is a clear articulation of:
- Here’s what IS allowed under this agreement (permissions)
- Here’s what is NOT allowed under this agreement (prohibitions)
Each key term in the agreements (the permitted and prohibited processes) is fully defined in the great resource that is the Data Privacy Vocabulary (think Wikipedia for privacy and data protection related words).
The contents of the agreements will evolve over time, not least to ensure that any new negative behaviours that emerge from technology innovation can easily be added to the prohibitions list.
One of those agreements ‘Service Only’ is the default setting. This concept is deeply rooted in GDPR and similar means that organisations can only gather the data they need to deliver their core service and can only use that data gathered in the context of providing the service in question. Specifically, that means no third-party tracking or surveillance activity – MyTerms excludes those options by design.
Further agreements exist for more evolved data sharing relationships, for AI/ data for good contributions, and sharing intent data (the most commercial of the agreements).
Other facets of the standard are:
- The agreements are formed as contracts; so data exchange is based on contract law – sitting a level above the local data regulations.
- Each party (individual and organisation) is represented by an agent; which could be a browser, browser plug-in or a mobile app on the individual side. And web/ app server plug-ins/ code on the organisation side.
- There is a handshake/ negotiation protocol; think of that as like Docusign or similar for privacy policies
- Both parties must receive copies of the signed agreements
The visual below shows the emerging MyTerms app for individuals, in testing now and available more widely in Q4 2026.

One of the ways in which MyTerms will surface will be as a trust mark, available from MyData Global and others over time, as a symbol that an organisation will accept MyTerms agreements when proposed by individuals in onboarding journeys.
Another mode will be as a ‘privacy signal’. This concept, now deep in consultation in the EU as part of the Digital Omnibus (update to GDPR) sees a privacy signal as a single place from which an individuals can manage and share their privacy preferences. This can mean, for example, that cookie banners do not need to be shown, and consent journeys simplified.
This model is clearly different to the current approach but should be easily adoptable for the vast number and proportion of organisations/ web sites and apps that are not engaging in third party tracking and similar. Regulated sectors, including public sector, are obvious candidates, as are SME’s; and Retail Media Networks as they are already convinced of the need to curate and build on genuine ‘first party data relationships.
Distribution of and access to MyTerms will include mass-market channels such as plug-ins for all the main web platforms such as WordPress. Over time we would hope to see the IEEE 7012 standard built into browsers and mobile operating systems themselves.
So what will this all mean down the track?
The team behind the standard are certainly optimistic that the world can move beyond the current mess to a more equitable and ultimately trustworthy model. We see more agreement types emerging; for example, there are already requests to develop one specifically for the needs of children online; another request for an employment related agreement. We have formed The MyTerms Alliance, an industry association much like The Wi-Fi Alliance – formed around another IEEE global standard (IEEE 802.11/ Wi-Fi).
If this sounds of interest, then please reach out either as a potential deployer of the MyTerms trust mark; or a customer-tech provider who might wish to enable your platform to accept MyTerms. Now is certainly a good time to get involved, and all feedback is welcome.
