Insight Brief · Applied Architecture Series · July 2026

The Fiduciary

How a data cooperative — not a platform — turns shared data into infrastructure institutions can trust, without anyone surrendering ownership of what they contributed.

Anyone who wants to use data they did not generate runs into the same wall. Take it without real consent, and you inherit the distrust that follows. Leave it untouched out of caution, and the insight stays locked away. The way through is not another privacy law. It is a fiduciary.

Locked Data, Forfeited Insight

Look closely at almost any system that runs on data it did not itself generate — credit underwriting, public benefits delivery, health research, agricultural supply chains, disaster response, language and cultural preservation — and the same standoff appears. The data exists. The will to use it exists. What is missing is a structure both sides can trust: one that lets the people who generated the data keep a real say in how it travels, and lets the institution that needs it rely on something sturdier than a one-time consent checkbox.

Today that data almost always ends up in one of two places, and neither serves the people who created it. Either it is harvested under sweeping terms-of-service consent, leaving its source to discover after the fact — through a privacy policy or a breach notice — how little say they actually kept. Or it is sealed inside the household, business, or community that holds it: safe, but inert, and the insight that sharing would unlock never materializes — the credit that is never extended, the outbreak caught too late, the disaster nobody prepared for. Extraction and isolation look like opposites. They are really two ways of leaving the same value stranded.

“Data’s hard problem was never collection. It is that the moment data is shared, its source tends to lose every say in what happens to it next.”

No consent form, however long, fixes this — because the problem is not the wording of the agreement but the absence of anyone standing on the source’s side of it. What the situation calls for is not a better rule but a missing role: an institution positioned between the people who generate data and the institutions that want it, and bound — legally and structurally — to act for the former. Nehitek calls that institution a fiduciary.


A Credit Union for Data

The word carries a specific legal weight, and we mean it literally. A fiduciary is an organization bound to act in someone else’s interest — the duty a credit union owes its depositors, or a pension trustee owes a beneficiary. A data cooperative simply moves that duty from capital to data. It gathers what members choose to share, negotiates on their behalf with the institutions that want to use it, audits how the data is actually handled, and channels the resulting insight — not merely a payment — back to the members who generated it.

This is the same fault line we have traced through the rest of our work — in The Open Finance Blueprint and across our Solutions framework — only here it runs through data rather than capital. A platform concentrates control and quietly makes captives of the people who depend on it; architecture stays open, interoperable, and inspectable, and earns trust precisely because it can be joined, audited, and walked away from. A company that collects data directly is the platform: it dictates the terms, books the data as a proprietary asset, and leaves its sources no standing claim on what happens afterward. A cooperative is the architecture — a neutral, member-governed broker that any institution can negotiate with, and any member can quit, portable insight in hand.

None of this puts friction on the analytics. Finding the pattern, training the model, informing the policy — the cooperative leaves that work untouched, because that work was never the problem. What it takes away is the institution’s standing as the only voice in the room when the question of use comes up. A second voice is now always present: the members’, carried by an organization that answers to them by law.

Set the extractive arrangement and the fiduciary one beside the other, and the difference shows up in exactly the places a data source cares about.

Table 1 · Extractive platform vs. data cooperative, across what a data source can still control.
Property Extractive platform Data cooperative
Consent A one-time terms-of-service checkbox, signed once and forgotten. Granular and revocable, at the level of a single data request.
Ownership Shared data becomes the collector’s proprietary asset. Members keep an enforceable claim on how their data is used.
Value flow Insight and revenue accrue to the collector. Insight, access, or revenue flows back to the members who generated it.
Exit & portability Leaving means losing access; the insight stays locked in. Members can leave and take their portable insight with them.
Accountability Privacy policy and breach disclosure, applied after the fact. A standing fiduciary duty, audited on members’ behalf.
Figure 1 · The Data Cooperative — Three Enduring Properties
The Fiduciary · Governance Architecture Nehitek Foundation · July 2026
01
Fiduciary Governance
Restraint by design. The cooperative negotiates, audits, and represents — it does not sell data outright or decide unilaterally on members’ behalf. Members retain an enforceable claim on how their data is used.
Member-Owned · Enforceable Duty · Negotiated Use
02
Consent & Portability
Granular, revocable consent at the level of a single data request — not a one-time terms-of-service checkbox — and insight that travels with the member rather than staying locked inside one institution.
Granular Consent · Revocable · Portable Insight
03
Plug-and-Play Interoperability
Built on open, interoperable data-exchange rails so a cooperative can connect to many institutions without bespoke integration for each one. No single institution or vendor becomes the cooperative’s only counterparty.
Open Rails · No Single Counterparty · DPI-Compatible
Member Accountability — Cross-Cutting
Education, democratic member control, and concern for community — the cooperative principles that keep the fiduciary from drifting into the extractive pattern it exists to replace.
Democratic Control · Oversight · Redress

Three Parts, Built to Last

None of this stays standing on good intentions. The fiduciary rests on three concrete properties, each chosen because it should still hold in five years — whatever regulations, institutions, or data-sharing technologies arrive by then.

Fiduciary governance is the restraint at the center of the model. Every bit of leverage the cooperative holds — its scale, its expertise, its seat at the table — is spent on the members’ behalf, never used to overrule them. This is the cooperative’s founding charge, not a compliance feature added once it is up and running, and it is what lets a member say plainly what the cooperative may and may not do with their data.

Consent and portability keep the arrangement reversible. A member can green-light one use, refuse the next, and exit altogether with their insight in tow — much as a depositor can move between credit unions without losing their balance. Consent that cannot be withdrawn, and insight that cannot travel, are not really either; they are a one-way transfer wearing the costume of a partnership.

Plug-and-play interoperability keeps the model from narrowing into dependence. Built on open data-exchange standards, a cooperative can connect to many counterparties at once, the way sound public infrastructure refuses to let any one operator become a chokepoint. No lone institution, government system, or technology vendor should ever be the only rail the cooperative can run on.


Consent. Represent. Audit. Return.

The three properties above describe what the fiduciary is. A four-step cycle describes what it does — the same loop wherever data has to move from the people who generate it to an institution that wants to use it. It is the part that turns principle into routine.

Figure 2 · The Operating Cycle — Consent → Represent → Audit → Return
01 · Consent
Opt in, granularly
A member grants — and can later withdraw — permission for a specific use, at the level of a single request, rather than signing one blanket agreement and forgetting it.
02 · Represent
Negotiate, don’t surrender
The cooperative negotiates terms with the institution that wants the data, standing in for members who could never bargain alone. The underlying records stay inside the fiduciary boundary; only the agreed-on insight leaves.
03 · Audit
Verify the use
The cooperative confirms, on the record, that the data was used only as agreed — the enforcement step that turns a promise into a governed arrangement, and acts when a term is broken.
04 · Return
Value flows back
Insight, access, or revenue returns to the members who made the data possible — not just the institution that asked — closing the loop and funding the next request.

Consent and Represent describe what most data arrangements already claim to do: collect a permission, strike a deal. It is the next two steps they skip. A platform gathers consent at sign-up and sets terms with whoever it sells to, but nothing obliges it to check what happens afterward, and nothing sends value back. The cooperative’s real difference begins exactly where the ordinary arrangement ends.

Audit is the step that does the fiduciary’s defining work. A negotiated term means nothing if no one confirms it was honored, so the cooperative verifies — on the record — that each use matched what members agreed to, and can act when it did not. Consent that is never checked against actual use is not governance; it is paperwork. This is the enforcement no member could perform alone, carried out on their behalf.

Return is where the loop closes and the model’s logic becomes visible. Value does not stop at the institution that requested the data; it travels back to the members who made it possible — as insight, access, or revenue — the way a sound cooperative reinvests in its own people rather than pocketing a one-time gain. That returning flow is what keeps members contributing, and what lets the system grow without ever asking them to concede more control.

“Return is not an afterthought to the cycle. It is the proof that the first three steps meant anything at all.”


One Governance Model. Infinite Domains.

The data cooperative outgrows any single sector for the same reason the rest of Nehitek’s work does: the fiduciary stays fixed while the data domain changes around it — the constant and the variable.

Take credit and capital-markets decisioning, where MSME underwriting via digital asset registries — the subject of Nehitek’s Open Finance Utility work — is just one case: it draws on cooperatively governed data exactly as it draws on a harnessed AI layer. The same holds for public health research, where individuals must be able to control which studies their health data feeds; for small-enterprise data shared across fragmented trades like construction; for catch-and-yield data exchanged between fishers, farmers, and regulators; for gig workers banding together to bargain with the platforms that route their work; and for communities asserting sovereignty over indigenous and linguistic data long taken without consent or credit. Each comes with its own data, its own institutions, its own rules. None of them changes what the fiduciary, consent, and interoperability layer beneath has to do.

Charter a cooperative for one domain, and the second comes far cheaper than the first. The consent machinery exists. The auditing relationships are live. The interoperability discipline is already habit. A new domain is bolted onto the fiduciary that already runs — it does not call for a fiduciary built from scratch.

Figure 3 · Where the Fiduciary Applies — Selected Data Domains
SME Data Sharing

Sector-Wide Analytics

Fragmented sectors like construction combine operational data across member firms to reach analytics none could afford alone, while keeping ownership.

Health Research

Member-Controlled Health Data

Individuals choose what health data to contribute and which research it supports, with the cooperative auditing every use.

Agriculture & Fisheries

Catch & Yield Data Sharing

Producers share operational data with regulators for market access and sustainability compliance, without surrendering it outright.

Gig & Platform Work

Worker-Owned Trip & Task Data

Workers combine data generated on third-party platforms to negotiate terms and inform public policy on their own behalf.

Indigenous & Linguistic Data

Cultural Data Sovereignty

Communities govern what data trains models built on their language and knowledge, with attribution and value flowing back.

National ID & Benefits

Cross-Verified Eligibility

Interoperable data exchange lets benefits systems verify eligibility without each agency holding a duplicate copy of every record.

Climate & Disaster Data

Community-Governed Risk Data

Communities combine environmental and risk data to inform climate action and disaster response on terms they help set.

Capital Markets & Credit

Rights-Respecting Underwriting Data

Provenance-tracked, consented data feeding MSME underwriting — the role data cooperatives play inside Nehitek’s Open Finance Utility work, among other credit systems.


Investigate. Design. Build.

Nehitek does not set out to be a data broker, run cooperatives, or sell compliance advice. Its role is narrower and more structural: to architect the fiduciary relationship — and the open rails that let it scale — and to see both through to working reality inside the institutions and communities that need them.

Investigate: Tracing where a sector’s data relationships have gone quietly extractive — where consent has hardened into a one-time checkbox instead of a living right, where shared data flows only toward the collector and never back, where one party has become the sole arbiter of how everyone else’s data gets used. It is structural diagnosis, not a data-strategy questionnaire.

Design: Drawing up the fiduciary, consent, and interoperability architecture for a specific domain — fitted to its regulatory regime, the institutions in play, and the community the cooperative exists to serve. Accountability and auditability have to be built into the structure, not bolted on once the cooperative is already running.

Build: Working alongside the institutions, regional DPI initiatives, and standards bodies whose buy-in makes the result real. Nehitek’s standing here is grounded in its governance pedigree: Co-Founder Mei Lin Fung — a pioneer of CRM at Oracle, now focused on Digital Public Infrastructure, MSME financing, and AI governance — co-founded the People-Centered Internet with Vint Cerf, chairs the IEEE SSIT Sustainability Technical Committee, and sits on the GovStack Global Advisory Council — all bearing directly on the data-governance and digital-public-infrastructure questions this layer exists to answer.

This layer’s distinct contribution to the UN Sustainable Development Goals follows from its function, not from any single deployment. Open, interoperable data-exchange rails advance SDG 9 (Industry, Innovation and Infrastructure). Fiduciary, auditable data governance advances SDG 16 (Peace, Justice and Strong Institutions) as an institution-building exercise, not just a compliance one. The multi-stakeholder work required to charter and connect cooperatives advances SDG 17 (Partnerships for the Goals) and SDG 11 (Sustainable Cities and Communities). And closing the data divide between groups that are data-rich and groups that are data-invisible advances SDG 10 (Reduced Inequalities), SDG 8 (Decent Work and Economic Growth) for workers bargaining collectively over their own data, and SDG 5 (Gender Equality) for the communities most often left out of the datasets that shape digital systems.


The Opportunity

The distrust that surrounds data sharing — in credit, health, agriculture, labor, and cultural data alike — will not be drafted away in a better consent form. It is an architectural absence. The same split between what data is worth when shared and what it risks when extracted shows up everywhere a system reaches for data it did not itself produce.

The fiduciary supplies that architecture. Because a cooperative negotiates, audits, and returns value — and never sells outright or rules by fiat — it can hold data institutions genuinely need, with members’ control written into the structure rather than promised on the side. Consent and portability keep the relationship reversible; open interoperability keeps any one institution from becoming the only rail it can run on.

And the opening is not confined to one sector. It is anywhere an institution needs data it can only use if it first earns the trust to. The data domain changes — credit, health, agriculture, labor, culture, climate. The fiduciary does not.

About Nehitek Foundation

Nehitek Foundation is an applied think tank that investigates global challenges, designs structural frameworks, and actively builds the enabling solutions required to fix them. We operate at the intersection of deep economic intelligence and applied architectural design — mapping the macro-economic reality of complex problems, then building the solutions required to solve them.

Engage With This Work

This brief is part of the Nehitek Applied Architecture Series. To discuss a specific data governance challenge, scope a fiduciary model for an existing data-sharing arrangement, or explore partnership as a funder, policymaker, or enterprise, get in touch or write to engage@nehitek.com.