LGPD and GDPR taught companies to ask for permission. But asking for permission to collect data is not the same as treating the person as a legitimate participant in the value that data creates. Most organizations understood compliance as protection against fines, not as a sign that the relationship between companies and individuals is being rewritten. This understanding will be costly.
What is data dignity and why it goes beyond privacy
Privacy is a defensive right. It protects the individual from having sensitive information exposed or used against them. Data dignity is an offensive concept: it assumes that the data generated by a person has real economic value and that they should have significant control over how this value circulates and, in some cases, receive part of it.
The “data as labor” movement — data as work — is the most direct formulation of this idea. Economists such as Glen Weyl and Imanol Arrieta-Ibarra argue that user behavior on digital platforms is a form of unpaid labor. Every search, every click, every interaction trains models and powers systems worth billions. The user receives the service; the company retains the residual value. Data dignity questions whether this arrangement is fair or sustainable.
Portability, data stores and data trusts
Data portability was the first concrete step in this direction. The right to export your data from Spotify, Google or any regulated platform seems simple, but it opens up a difficult question: portable to where, and in what format? Without true interoperability, portability is an empty promise that serves more legal compliance than genuine control.
Personal data stores — repositories controlled by the user, outside the companies' infrastructure — represent an alternative architecture. Projects such as Solid, led by Tim Berners-Lee, and self-sovereign identity initiatives propose that the individual be the hub of their own data, granting access to applications at will. Traction is still limited, but the direction is clear.
Data trusts are a collective model: independent organizations that manage data on behalf of groups of people, negotiating terms with companies and ensuring that the collective use of data reflects the interests of members. It is a model that already exists in healthcare — medical data consortia with shared governance — and that is beginning to be explored in urban mobility and precision agriculture.
What changes for companies built on user data
For companies whose business model depends on behavioral data at scale, data dignity is not a philosophical question. It is a threat to the operating model. When users have real tools to revoke consent, migrate data, or limit the use of their information for model training, the asymmetry that underpins these businesses begins to diminish.
The pressure comes from three directions at once. Regulatory: The European AI Act, GDPR extensions and similar discussions in Brazil expand the scope of individual control, especially in automated decision contexts. Market: More sophisticated consumers, especially in younger age groups, are willing to pay for platforms that do not monetize their behaviors. And competitive: business models based on explicit consent and sharing value with users are beginning to emerge as a differentiator, not a disadvantage.
Apple has already explored this as a positioning strategy with App Tracking Transparency. The result was a significant reconfiguration of the mobile advertising market. Data dignity generalizes this vector.
How a leader should look at this
The strategic question is not whether data dignity will become a regulatory or market expectation. It's when and how quickly. The organization that treats this as a compliance problem will always be chasing it; what you treat as a design opportunity can set the standard.
This requires three simultaneous movements. First, honest audit of the data inventory: what data the company collects, for what, for how long, and what economic value it represents. Most organizations don't know how to answer these questions accurately. Second, redesign consent flows — not as forms to click “accept,” but as interfaces that actually communicate what is being collected and allow for granular choices. Third, exploration of value sharing models: this could be credits, discounts, co-ownership of insights generated with user data, or simply transparency about how the data is used and what return it generates.
None of these moves are trivial. All require changes in data architecture, product design and organizational culture. But the cost of not doing so — erosion of trust, loss of regulatory control, vulnerability to players that adopt data dignity as a value proposition — is considerably greater.
Privacy was about protecting the user from harm. Data dignity is about recognizing that the user is a co-creator of digital value. Companies that understand this distinction early will have a considerable advantage in the regulations and market preferences to come.
Also read
- LGPD in 2026: what has changed, what has not yet been complied with and what is coming
- LGPD two years later: what has really changed in Brazilian companies
- Real consent or regulatory theater: how to differentiate
- Self-sovereign digital identity: architecture and implications
- Synthetic Data and Privacy: Train and Test Without Exposing Personal Data
- LGPD in applications: what changes in privacy when you need to scale
