Insight Brief · Applied Architecture Series · July 2026
The Fiduciary
How a data cooperative — not a platform — turns shared data into infrastructure institutions can trust, without anyone surrendering ownership of what they contributed.
Nehitek Foundation
July 2026
Applied Architecture Series
~1,750 words
Anyone who wants to use data they did not generate runs into the same wall. Take it without real consent, and you inherit the distrust that follows. Leave it untouched out of caution, and the insight stays locked away. The way through is not another privacy law. It is a fiduciary.
01 · The Pattern
Locked Data, Forfeited Insight
Look closely at almost any system that runs on data it did not itself generate — credit underwriting, public benefits delivery, health research, agricultural supply chains, disaster response, language and cultural preservation — and the same standoff appears. The data exists. The will to use it exists. What is missing is a structure both sides can trust: one that lets the people who generated the data keep a real say in how it travels, and lets the institution that needs it rely on something sturdier than a one-time consent checkbox.
Today that data almost always ends up in one of two places, and neither serves the people who created it. Either it is harvested under sweeping terms-of-service consent, leaving its source to discover after the fact — through a privacy policy or a breach notice — how little say they actually kept. Or it is sealed inside the household, business, or community that holds it: safe, but inert, and the insight that sharing would unlock never materializes — the credit that is never extended, the outbreak caught too late, the disaster nobody prepared for. Extraction and isolation look like opposites. They are really two ways of leaving the same value stranded.
“Data’s hard problem was never collection. It is that the moment data is shared, its source tends to lose every say in what happens to it next.”
No consent form, however long, fixes this — because the problem is not the wording of the agreement but the absence of anyone standing on the source’s side of it. What the situation calls for is not a better rule but a missing role: an institution positioned between the people who generate data and the institutions that want it, and bound — legally and structurally — to act for the former. Nehitek calls that institution a fiduciary.
02 · The Case for the Fiduciary
A Credit Union for Data
The word carries a specific legal weight, and we mean it literally. A fiduciary is an organization bound to act in someone else’s interest — the duty a credit union owes its depositors, or a pension trustee owes a beneficiary. A data cooperative simply moves that duty from capital to data. It gathers what members choose to share, negotiates on their behalf with the institutions that want to use it, audits how the data is actually handled, and channels the resulting insight — not merely a payment — back to the members who generated it.
This is the same fault line we have traced through the rest of our work — in The Open Finance Blueprint and across our Solutions framework — only here it runs through data rather than capital. A platform concentrates control and quietly makes captives of the people who depend on it; architecture stays open, interoperable, and inspectable, and earns trust precisely because it can be joined, audited, and walked away from. A company that collects data directly is the platform: it dictates the terms, books the data as a proprietary asset, and leaves its sources no standing claim on what happens afterward. A cooperative is the architecture — a neutral, member-governed broker that any institution can negotiate with, and any member can quit, portable insight in hand.
None of this puts friction on the analytics. Finding the pattern, training the model, informing the policy — the cooperative leaves that work untouched, because that work was never the problem. What it takes away is the institution’s standing as the only voice in the room when the question of use comes up. A second voice is now always present: the members’, carried by an organization that answers to them by law.
Set the extractive arrangement and the fiduciary one beside the other, and the difference shows up in exactly the places a data source cares about.
Table 1 · Extractive platform vs. data cooperative, across what a data source can still control.
| Property |
Extractive platform |
Data cooperative |
| Consent |
A one-time terms-of-service checkbox, signed once and forgotten. |
Granular and revocable, at the level of a single data request. |
| Ownership |
Shared data becomes the collector’s proprietary asset. |
Members keep an enforceable claim on how their data is used. |
| Value flow |
Insight and revenue accrue to the collector. |
Insight, access, or revenue flows back to the members who generated it. |
| Exit & portability |
Leaving means losing access; the insight stays locked in. |
Members can leave and take their portable insight with them. |
| Accountability |
Privacy policy and breach disclosure, applied after the fact. |
A standing fiduciary duty, audited on members’ behalf. |
03 · The Layer
Three Parts, Built to Last
None of this stays standing on good intentions. The fiduciary rests on three concrete properties, each chosen because it should still hold in five years — whatever regulations, institutions, or data-sharing technologies arrive by then.
Fiduciary governance is the restraint at the center of the model. Every bit of leverage the cooperative holds — its scale, its expertise, its seat at the table — is spent on the members’ behalf, never used to overrule them. This is the cooperative’s founding charge, not a compliance feature added once it is up and running, and it is what lets a member say plainly what the cooperative may and may not do with their data.
Consent and portability keep the arrangement reversible. A member can green-light one use, refuse the next, and exit altogether with their insight in tow — much as a depositor can move between credit unions without losing their balance. Consent that cannot be withdrawn, and insight that cannot travel, are not really either; they are a one-way transfer wearing the costume of a partnership.
Plug-and-play interoperability keeps the model from narrowing into dependence. Built on open data-exchange standards, a cooperative can connect to many counterparties at once, the way sound public infrastructure refuses to let any one operator become a chokepoint. No lone institution, government system, or technology vendor should ever be the only rail the cooperative can run on.
04 · The Mechanism
Consent. Represent. Audit. Return.
The three properties above describe what the fiduciary is. A four-step cycle describes what it does — the same loop wherever data has to move from the people who generate it to an institution that wants to use it. It is the part that turns principle into routine.
Consent and Represent describe what most data arrangements already claim to do: collect a permission, strike a deal. It is the next two steps they skip. A platform gathers consent at sign-up and sets terms with whoever it sells to, but nothing obliges it to check what happens afterward, and nothing sends value back. The cooperative’s real difference begins exactly where the ordinary arrangement ends.
Audit is the step that does the fiduciary’s defining work. A negotiated term means nothing if no one confirms it was honored, so the cooperative verifies — on the record — that each use matched what members agreed to, and can act when it did not. Consent that is never checked against actual use is not governance; it is paperwork. This is the enforcement no member could perform alone, carried out on their behalf.
Return is where the loop closes and the model’s logic becomes visible. Value does not stop at the institution that requested the data; it travels back to the members who made it possible — as insight, access, or revenue — the way a sound cooperative reinvests in its own people rather than pocketing a one-time gain. That returning flow is what keeps members contributing, and what lets the system grow without ever asking them to concede more control.
“Return is not an afterthought to the cycle. It is the proof that the first three steps meant anything at all.”
05 · Universality
One Governance Model. Infinite Domains.
The data cooperative outgrows any single sector for the same reason the rest of Nehitek’s work does: the fiduciary stays fixed while the data domain changes around it — the constant and the variable.
Take credit and capital-markets decisioning, where MSME underwriting via digital asset registries — the subject of Nehitek’s Open Finance Utility work — is just one case: it draws on cooperatively governed data exactly as it draws on a harnessed AI layer. The same holds for public health research, where individuals must be able to control which studies their health data feeds; for small-enterprise data shared across fragmented trades like construction; for catch-and-yield data exchanged between fishers, farmers, and regulators; for gig workers banding together to bargain with the platforms that route their work; and for communities asserting sovereignty over indigenous and linguistic data long taken without consent or credit. Each comes with its own data, its own institutions, its own rules. None of them changes what the fiduciary, consent, and interoperability layer beneath has to do.
Charter a cooperative for one domain, and the second comes far cheaper than the first. The consent machinery exists. The auditing relationships are live. The interoperability discipline is already habit. A new domain is bolted onto the fiduciary that already runs — it does not call for a fiduciary built from scratch.
06 · The Nehitek Role
Investigate. Design. Build.
Nehitek does not set out to be a data broker, run cooperatives, or sell compliance advice. Its role is narrower and more structural: to architect the fiduciary relationship — and the open rails that let it scale — and to see both through to working reality inside the institutions and communities that need them.
Investigate: Tracing where a sector’s data relationships have gone quietly extractive — where consent has hardened into a one-time checkbox instead of a living right, where shared data flows only toward the collector and never back, where one party has become the sole arbiter of how everyone else’s data gets used. It is structural diagnosis, not a data-strategy questionnaire.
Design: Drawing up the fiduciary, consent, and interoperability architecture for a specific domain — fitted to its regulatory regime, the institutions in play, and the community the cooperative exists to serve. Accountability and auditability have to be built into the structure, not bolted on once the cooperative is already running.
Build: Working alongside the institutions, regional DPI initiatives, and standards bodies whose buy-in makes the result real. Nehitek’s standing here is grounded in its governance pedigree: Co-Founder Mei Lin Fung — a pioneer of CRM at Oracle, now focused on Digital Public Infrastructure, MSME financing, and AI governance — co-founded the People-Centered Internet with Vint Cerf, chairs the IEEE SSIT Sustainability Technical Committee, and sits on the GovStack Global Advisory Council — all bearing directly on the data-governance and digital-public-infrastructure questions this layer exists to answer.
This layer’s distinct contribution to the UN Sustainable Development Goals follows from its function, not from any single deployment. Open, interoperable data-exchange rails advance SDG 9 (Industry, Innovation and Infrastructure). Fiduciary, auditable data governance advances SDG 16 (Peace, Justice and Strong Institutions) as an institution-building exercise, not just a compliance one. The multi-stakeholder work required to charter and connect cooperatives advances SDG 17 (Partnerships for the Goals) and SDG 11 (Sustainable Cities and Communities). And closing the data divide between groups that are data-rich and groups that are data-invisible advances SDG 10 (Reduced Inequalities), SDG 8 (Decent Work and Economic Growth) for workers bargaining collectively over their own data, and SDG 5 (Gender Equality) for the communities most often left out of the datasets that shape digital systems.
07 · Conclusion
The Opportunity
The distrust that surrounds data sharing — in credit, health, agriculture, labor, and cultural data alike — will not be drafted away in a better consent form. It is an architectural absence. The same split between what data is worth when shared and what it risks when extracted shows up everywhere a system reaches for data it did not itself produce.
The fiduciary supplies that architecture. Because a cooperative negotiates, audits, and returns value — and never sells outright or rules by fiat — it can hold data institutions genuinely need, with members’ control written into the structure rather than promised on the side. Consent and portability keep the relationship reversible; open interoperability keeps any one institution from becoming the only rail it can run on.
And the opening is not confined to one sector. It is anywhere an institution needs data it can only use if it first earns the trust to. The data domain changes — credit, health, agriculture, labor, culture, climate. The fiduciary does not.