The core specification does not state how PDPP relates to sources governed by sector-specific consent regimes (e.g. open banking, health data under FHIR/SMART).
Position proposed for a short informative passage (Section 1 or Scope):
- A source that participates gives up nothing: its regime obligations and its accredited access channels are untouched.
- PDPP governs access those channels do not cover: the user's own copy of their data, and recipients outside the regime's accreditation. Today that access happens through raw exports with no controls, for example a user bringing banking data to an AI agent.
- Grants already support expiry (
expires_at); a sector compatibility profile could let a regulated source require it. Compatibility profiles are a possible roadmap item.
The core specification does not state how PDPP relates to sources governed by sector-specific consent regimes (e.g. open banking, health data under FHIR/SMART).
Position proposed for a short informative passage (Section 1 or Scope):
expires_at); a sector compatibility profile could let a regulated source require it. Compatibility profiles are a possible roadmap item.