Data Intermediaries Will Make Consent Operations a Competitive Capability
The Government’s consultation on data intermediaries has been extended until 7 September 2026. That administrative change may appear marginal, but it gives UK businesses an extra week to engage with a policy question that reaches well beyond privacy teams.
Data intermediaries are third parties that help individuals access, manage or share their personal data. In the Government’s framing, they could include data wallets and personal information management services acting with a person’s explicit permission. The intended prize is a more practical version of data portability: information moving at an individual’s direction, rather than remaining locked inside the businesses that collected it.
For consumer-facing firms, this is not merely an emerging compliance category. It is an early test of whether their customer-data operations are designed for genuine customer agency.
“The commercial value of consent depends on whether it can be understood, verified and acted upon in practice.”
The real issue is operational, not conceptual
Most organisations already accept the principle that customers should have meaningful control over their information. The difficulty begins when that control is exercised through another service.
A data intermediary introduces new practical questions. How does a business verify that the intermediary has authority to act? Which data is within scope? In what format can it be supplied? Who owns the customer experience when a request fails, arrives incomplete or exposes a mismatch in records?
These are not exotic edge cases. They are the ordinary operational details that determine whether a right feels usable or merely exists on paper.
The UK’s established portability right is deliberately bounded. It generally applies to personal data an individual has provided, where processing is automated and based on consent or contractual necessity. Organisations must provide data in a structured, commonly used and machine-readable form, but they are not expected to rebuild systems around every other company’s technical architecture.
That distinction matters. The policy debate is not proposing that every customer database becomes universally open. It is asking how a trusted third party can help an individual make existing rights more usable, while reducing the uncertainty that currently discourages both data holders and potential intermediary services.
For businesses, the immediate task is to identify where their present processes depend on ambiguity, manual intervention or a customer giving up.
Consumer insight teams should take notice
Market researchers have a particular interest in how this develops. The future value of data intermediaries will not rest simply on moving files between systems. It will rest on whether people understand the exchange, trust the party facilitating it and see a worthwhile outcome.
That makes consent design a research problem as much as a legal one.
A customer deciding whether to share transaction, energy, health or retail data through an intermediary is making a judgement about relevance, risk and control. Dense permissions, uncertain benefits and unclear withdrawal routes will depress participation. Equally, a simplified journey that conceals meaningful choices may achieve a short-term opt-in while damaging trust and inviting scrutiny.

Research teams can help businesses move beyond the crude metric of consent rate. They should examine comprehension, confidence, perceived reversibility and the practical reasons people abandon a data-sharing journey. Segmenting by digital confidence, financial vulnerability or prior experience of poor service will be more useful than treating the public as a single audience for “data empowerment”.
This work should also reach product development. A service built on customer-directed data will need a credible proposition before it needs a polished interface. “Share your data” is not a proposition. Helping a household compare recurring costs, consolidate records, identify an entitlement or contribute safely to research may be.
The strongest use cases will make the exchange legible: what is shared, with whom, for what purpose, for how long and with what benefit.
Intermediaries expose weak data foundations
Many firms have invested heavily in collection, analytics and personalisation. Fewer have built equally mature capabilities for traceable release of information at a customer’s direction.
The result can be an awkward gap. Data may be available to internal teams through dashboards, vendors and customer-relationship platforms, yet difficult to assemble accurately, securely and consistently when an individual requests it.
Data intermediaries would make that gap more visible. They would require businesses to join up identity verification, permissions, records management, APIs, security controls and customer support. Crucially, those functions must work together rather than pass responsibility between teams.
This is why the issue belongs in commercial planning. Poorly handled portability requests carry a compliance risk, but they also reveal an experience problem. A customer who cannot understand where their information is held or why an authorised request is delayed is unlikely to distinguish between a technical limitation and a company choosing to be obstructive.
Conversely, businesses that can process authorised sharing cleanly may earn an advantage in markets where switching, comparison and personalised support depend on reliable data flows.
Prepare for plural routes to data sharing
The consultation sits alongside the UK’s wider Smart Data agenda, which aims to create sector-specific arrangements for secure data sharing. Open Banking remains the best-known reference point, but the policy direction is broader: services should increasingly be able to work with data held elsewhere, under clear permissions and safeguards.
Businesses should resist the temptation to wait for one definitive technical standard or a single universal intermediary model. The market is more likely to develop through a mixture of sector schemes, specialist services and evolving regulatory expectations.
A sensible preparation plan is modest but specific. Map the data that could be portable; document the legal basis and quality of those records; identify how third-party authority would be validated; test the customer-facing explanation; and establish an escalation route for contested or suspicious requests. None of this requires predicting the final policy outcome.
It does require treating data sharing as a service operation rather than a compliance exception.
The consultation extension is therefore useful time, not a reason for delay. Companies that respond should focus on the frictions that matter in real journeys: authentication, scope, data quality, liability, accessibility and redress. Companies that do not respond should still use the moment to inspect their own readiness.
If consumer-directed data sharing expands, the organisations best placed to benefit will be those that have made trust executable.



Comments