Xavier Drilhon tribune on protecting citizens' data ownership
August 31, 2026

Protecting citizens' data ownership: a democratic choice first, a competitive advantage second

Protecting citizens' data is not, first and foremost, an economic trade-off. It is a societal choice — and one that happens to be economically sound, because it will become a decisive competitive advantage in the global digital contest.

In broad terms, the American model concentrates data in the hands of platforms, and the Chinese model concentrates it in the hands of the state. The European model is the only one that starts from the principle that data belongs to the individual. This is not a technical choice. It is a choice against the prevailing orthodoxy — and a rather liberal one, in that it protects property. Cambridge Analytica did not merely expose platform excesses. It showed, in concrete terms, what it means not to own your own data. The consumer is a citizen first.

Well-designed regulation creates value

That choice has a cost, obviously. It can disrupt processes, force unbudgeted investment, stretch timelines. Every company operating in a data-intensive sector knows this. Stopping there, though, is asking the wrong question.

Peter Drucker said well before the internet that "there is nothing so useless as doing efficiently that which should not be done at all."

That is the point. Well-designed regulation does not push you to improve what already exists. It forces you to rethink it. Open banking is the proof: banks were not asked to do the same thing better. They were required to open their data, and therefore to partner with innovation. Services emerged that nobody could have imagined five years earlier.

Two kinds of regulation still need to be distinguished: rules that set outcome requirements create a frame in which innovation can happen; rules that prescribe the means freeze the system while pretending to steer it.

On data, Europe's bet will pay off

GDPR was dismissed as a competitive handicap. It became the global reference, and citizens adopted it. The major US platforms aligned their worldwide practices on the European standard — not out of conviction, but because it became economically impossible to operate otherwise. Proof that a well-set constraint, grounded in a philosophy that protects freedom, can become the norm without stalling growth.

The Data Governance Act, the Data Act, the AI Act, eIDAS, FIDA: all of these regulations impose a trust framework that is already delivering, or will.

Protecting the citizen is a constraint on the market, yes. Tomorrow, it is what the market will demand.

And Europe, having put that principle first, will then hold a competitive advantage nobody can take away.

March 31, 2026

The European Digital Identity Wallet is a major step forward — but it won’t be enough on its own.

A wallet, even a digital one, only contains data that is preloaded and largely static. Yet real‑life decisions — renting a flat, applying for a loan, enrolling a child at school — rely on dynamic, ever‑changing data: income, expenses, tax status, insurance coverage, or energy consumption.

The wallet was never designed to handle this complexity — and that’s normal. The real challenge is how it can be complemented, and who will organize trusted data circulation beyond the wallet.

These issues are explored in a recent opinion piece by Xavier Drilhon, President of MiTrust, published this week in the Journal du Net.

👉 Learn more

October 14, 2025

MiTrust has been recognised by Arcep as a Data Intermediation Service Provider, alongside Hub One DataTrust, under the Data Governance Act.

This recognition confirms MiTrust’s role as a trusted third party for secure and compliant personal data sharing across Europe.

👉‍ Learn more

April 14, 2025

MiTrust: first company in France to be awarded the "EU-recognised Data Intermediation Service Provider" label

In addition to simple registration, this label is awarded by Arcep after consultation with the CNIL and rigorous monitoring of compliance with the requirements of the Data Governance Act, particularly in terms of ✅ security, ✅ neutrality, ✅ transparency and ✅ respect for privacy.

👉 Learn more

June 18, 2024

White paper on consent-based personal data sharing

In today's digital landscape, verifying personal data is essential for various online transactions. Traditional credit bureau checks come with limitations and privacy concerns. This article highlights an alternative or additional approach: consent-based personal data sharing. This method empowers individuals to control their data 💪, enhancing privacy 🔒while improving verification efficiency and accuracy ✔️.

👉 Learn more

June 4, 2024

MiTrust's role institutionalized at European level

Following the enactment of the French SREN law, MiTrust is now registered as a Data Intermediation Service Provider with French authority Arcep and in the associated European register.

👉‍ Learn more

January 16, 2024

"Personal Data Sharing: MiTrust Plays the Trustworthy Third Party" by mind fintech

"MiTrust, which attracted the corporate fund of CNP Assurances, entering the capital in 2021, offers a solution for personal data sharing through open banking or connecting to a telecom operator or government service. Its promise: to position itself as a trustworthy third party and thereby facilitate the collection of data, particularly in the credit approval process....."

👉‍ Learn more (FR)

July 21, 2021

MiTrust in Challenges: "Simplifying the sharing of personal data"

Xavier DRILHON, President, and Martin COLOMB, Cofounder & CMO, share their vision and ambition for MiTrust in Challenges.

‍👉 Learn more

March 4, 2020

MiTrust is now a registered AISP

This registration as AISP with the Banque de France / Autorité de contrôle prudentiel et de résolution allows European end users to securely filter and share their banking information; a testimony to MiTrust’s commitment towards privacy and security.

MiTrust is registered under the identification code 17368 (CIB), and therefore meets the requirements of this designation in terms of security, compliance, governance and insurance.