iSHARE.vc is the open framework for issuing, managing, and verifying Verifiable Credentials across data spaces — public, private, sensitive, and commercial. Built on W3C standards, backed by a global network of certified issuers.
iSHARE.vc is het open framework voor het uitgeven, beheren en verifiëren van Verifiable Credentials over dataspaces heen — publiek, privaat, gevoelig en commercieel. Gebouwd op W3C-standaarden, met een globaal netwerk van gecertificeerde issuers.
A party becomes a certified Participant Credential Issuer or Data Rights Controller via the iSHARE Foundation, anchored in eIDAS or PKIoverheid.
Een partij wordt gecertificeerd als Participant Credential Issuer of Data Rights Controller via de iSHARE Foundation, verankerd in eIDAS of PKIoverheid.
The certified issuer creates a cryptographically signed credential — Participant, Data Rights, or any compatible third-party credential (e.g. ISO 27001).
De gecertificeerde issuer maakt een cryptografisch gesignede credential — Participant, Data Rights, of een compatibele externe credential (bijv. ISO 27001).
The organisation stores credentials in its own Credential Store (wallet). Data Rights Credentials are issued by a certified Data Rights Controller on behalf of the Data Rightsholder.
De organisatie slaat credentials op in een eigen Credential Store (wallet). Data Rights Credentials worden uitgegeven door een gecertificeerde Data Rights Controller namens de Data Rightsholder.
The holder presents credentials via DCP or OpenID4VP. The verifier validates cryptographically against the Trusted List — no contact with the issuer required.
De holder presenteert credentials via DCP of OpenID4VP. De verifier valideert cryptografisch tegen de Trusted List — geen contact met de issuer nodig.
The iSHARE framework defines a core set at schemas.ishare.eu. The same W3C VC infrastructure also carries any third-party credential — ISO certifications, sector labels, regulatory proofs — presented alongside iSHARE credentials in one Verifiable Presentation.
Het iSHARE-framework definieert een kernset op schemas.ishare.eu. Dezelfde W3C VC-infrastructuur draagt ook externe credentials — ISO-certificeringen, sectorlabels, compliance-bewijzen — gepresenteerd naast iSHARE-credentials in één Verifiable Presentation.
The top-level iSHARE credential. Proves your organisation is a legitimate data space participant: framework-compliant, registered in one or more data spaces, with signed agreements and valid certificates — in one signed document.
De overkoepelende iSHARE-credential. Bewijst dat uw organisatie een legitieme dataspace-deelnemer is: framework-compliant, geregistreerd in een of meer dataspaces, met ondertekende overeenkomsten en geldige certificaten — in één gesigneerd document.
Certifies iSHARE framework membership per framework: roles, signed agreements, X.509 certificates, and identity provider assertions. Packaged inside the Participant Credential.
Bewijst iSHARE-frameworklidmaatschap per framework: rollen, overeenkomsten, X.509-certificaten en IDP-assertions. Onderdeel van het Participant Credential.
Confirms membership in one or more data spaces — your role, the applicable rulebook, and your signed dataspace agreements. Packaged inside the Participant Credential.
Bevestigt lidmaatschap in een of meer dataspaces — uw rol, het toepasselijke rulebook en ondertekende overeenkomsten. Onderdeel van het Participant Credential.
Grants access to specific data at a Service Provider. Specifies who, what attributes, for how long — and carries an iSHARE Licence defining permitted use.
Verleent toegang tot specifieke data bij een Service Provider. Legt vast wie, welke attributen, hoe lang — en draagt een iSHARE Licentie met het toegestane gebruik.
Privacy-preserving mechanism for publishing active / revoked / suspended status of issued credentials via compressed bitstrings.
Privacy-preserving mechanisme voor het publiceren van de status (actief / ingetrokken / gesuspendeerd) via gecomprimeerde bitstrings.
Any credential from a trusted third party presented alongside iSHARE credentials. The Service Provider decides which it accepts.
Elke credential van een vertrouwde derde partij naast iSHARE-credentials. De Service Provider bepaalt welke hij accepteert.
Confirms a natural person may act on behalf of an organisation. Will integrate with eIDAS 2.0 and European Digital Identity Wallets. Schema in preparation.
Bevestigt dat een natuurlijk persoon namens een organisatie mag handelen. Integreert met eIDAS 2.0 en European Digital Identity Wallets. Schema in voorbereiding.
Step through the full credential lifecycle — from the Data Rightsholder instructing a Data Rights Controller, to the connector enforcing the iSHARE Licence when data is actually shared.
Doorloop de volledige credential-lifecycle — van de Data Rightsholder die de Data Rights Controller instrueert, tot de connector die de iSHARE Licentie handhaaft op het moment van datadeling.
Open data is publicly available — but that does not make it unconditional. An iSHARE Licence on a public source lets rights holders enforce legal conditions without closing the data: geographic restrictions, purpose limitations, logging obligations. The data stays open. The conditions become enforceable.
Open data is vrij beschikbaar — maar dat betekent niet dat het zonder voorwaarden is. Een iSHARE Licentie op een publieke bron stelt rechthebbenden in staat juridische voorwaarden af te dwingen zonder de data te sluiten: geografische beperkingen, doelbinding, logverplichting. De data blijft open. De voorwaarden worden afdwingbaar.
Only consumers whose Participant Credential confirms a Dutch or EU legal entity get through. Non-NL consumers are refused — even if the endpoint is publicly reachable.
Alleen consumers wier Participant Credential een Nederlandse of EU-rechtspersoon bevestigt komen erdoor. Niet-NL consumers worden geweigerd — ook al is het endpoint publiek bereikbaar.
The iSHARE Licence specifies the permitted purpose — research only, non-commercial, no AI training. The consumer must accept these terms before access is granted.
De iSHARE Licentie legt het toegestane doel vast — alleen onderzoek, niet-commercieel, geen AI-training. De consumer moet deze voorwaarden accepteren voor toegang.
Every access event is logged against the consumer's verified identity. The rights holder knows who accessed what, when — full audit trail without closing the source.
Elke toegangsgebeurtenis wordt gelogd op basis van de geverifieerde identiteit. De rechthebbende weet wie wat heeft ingezien, wanneer — volledig auditspoor zonder de bron te sluiten.
Some fields are open, others require a specific sector credential. A smart meter dataset may expose aggregated readings freely but require a sector credential for raw per-address data.
Sommige velden zijn open, andere vereisen een specifieke sectorale credential. Een slimmemeter-dataset kan geaggregeerde metingen vrij aanbieden maar een sectorale credential vereisen voor ruwe per-adresdata.
The same DRC mechanism on a public source. The front door is the licence check.
Hetzelfde DRC-mechanisme op een publieke bron. De voordeur is de licentietoets.
iSHARE does not close open data. It places a licence-enforcing front door in front of it. Any consumer with the right Participant Credential and licence acceptance gets through. Everyone else — including consumers from outside the permitted jurisdiction — is refused. The rights holder finally has legal certainty about who uses their data, for what purpose, and under which conditions — even when the data is public.
iSHARE sluit open data niet. Het plaatst een licentie-afdwingende voordeur ervoor. Elke consumer met het juiste Participant Credential en licentieacceptatie komt erdoor. Iedereen anders — inclusief consumers van buiten de toegestane jurisdictie — wordt geweigerd. De rechthebbende heeft eindelijk juridische zekerheid over wie zijn data gebruikt, met welk doel, en onder welke voorwaarden — ook als de data open is.
Public, private, sensitive or commercial — the same credential mechanism gives rights holders control and consumers verifiable access, regardless of the domain.
Publiek, privaat, gevoelig of commercieel — hetzelfde credential-mechanisme geeft rechthebbenden controle en consumers verifieerbare toegang, ongeacht het domein.
A municipality publishes air quality measurements as open data. The DRC enforces: NL legal entities only, research purpose, no commercial resale — while keeping the endpoint publicly reachable.
Een gemeente publiceert luchtkwaliteitsmetingen als open data. Het DRC dwingt af: alleen NL-rechtspersonen, onderzoeksdoel, geen commerciële doorverkoop — terwijl het endpoint publiek bereikbaar blijft.
A logistics provider shares shipment data with a carrier — only for specific routes, only for active contracts, only readable by the carrier's system credential. Revocable the moment the contract ends.
Een logistiek dienstverlener deelt zendingdata met een vervoerder — alleen voor specifieke routes, alleen bij actieve contracten, alleen leesbaar door de systeemcredential van de vervoerder. Intrekbaar op het moment het contract eindigt.
A citizen delegates read access to their smart meter data to an energy advisor — strictly scoped to their address, for 30 days, non-transferable. The citizen can revoke at any moment.
Een burger delegeert leestoegang tot zijn slimmemeterdata aan een energieadviseur — strikt beperkt tot zijn adres, voor 30 dagen, niet overdraagbaar. De burger kan op elk moment intrekken.
An ERP vendor grants an AI model access to live operational data — under a commercial iSHARE Licence specifying permitted inference tasks, data retention zero, no model training. Full legal provability of the terms.
Een ERP-leverancier verleent een AI-model toegang tot live operationele data — onder een commerciële iSHARE Licentie met toegestane inferentietaken, nul dataretentie, geen modeltraining. Volledige juridische bewijsbaarheid van de voorwaarden.
Governments and international bodies worldwide face a critical bottleneck: AI systems require vast, high-quality datasets — yet rights holders lack a trusted, machine-enforceable way to specify and verify how their data may be used for AI training.
Overheden en internationale organisaties wereldwijd stuiten op een kritieke blokkade: AI-systemen vereisen enorme, hoogwaardige datasets — maar rechthebbenden missen een betrouwbare, machine-afdwingbare manier om te specificeren en te verifiëren hoe hun data voor AI-training mag worden gebruikt.
Today's AI training pipelines ingest data with little verifiable control over provenance or usage conditions. Rights holders — from public bodies to private companies — cannot enforce their terms once data leaves their systems. The EU AI Act, the European Data Act, and G7 AI principles all call for a solution. iSHARE VC is that solution.
Huidige AI-trainingspipelines verwerken data met weinig verifieerbare controle over herkomst of gebruiksvoorwaarden. Rechthebbenden — van overheden tot private bedrijven — kunnen hun voorwaarden niet afdwingen zodra data hun systemen verlaat. De EU AI Act, de European Data Act en G7 AI-principes vragen allemaal om een oplossing. iSHARE VC is die oplossing.
The European Data Act (2024) establishes rights for data holders to control how data — especially IoT and machine-generated data — may be accessed and used. The EU AI Act requires transparency about training data provenance. iSHARE Data Rights Credentials implement exactly these principles: the allowed use, the allowed recipient, and the legal licence are embedded in the credential itself.
De European Data Act (2024) kent rechten toe aan datahouders om te controleren hoe data — met name IoT- en machinegegenereerde data — mag worden benaderd en gebruikt. De EU AI Act vereist transparantie over de herkomst van trainingsdata. iSHARE Data Rights Credentials implementeren precies deze principes: het toegestane gebruik, de toegestane ontvanger en de juridische licentie zijn ingebakken in het credential zelf.
The G7 Hiroshima AI Process, Japan's DFFT (Data Free Flow with Trust), the US NIST AI RMF, and Singapore's Model AI Governance Framework all call for trustworthy, auditable data-sharing with clear provenance. iSHARE VC provides a standards-based, interoperable layer that any jurisdiction can plug into — built on W3C VC 2.0 and open standards, not a proprietary platform.
Het G7 Hiroshima AI Process, Japan's DFFT (Data Free Flow with Trust), het US NIST AI RMF en Singapore's Model AI Governance Framework vragen allemaal om betrouwbare, controleerbare datadeling met duidelijke herkomst. iSHARE VC biedt een op standaarden gebaseerde, interoperabele laag die elke jurisdictie kan aansluiten — gebouwd op W3C VC 2.0 en open standaarden, niet op een proprietair platform.
A Data Rights Credential embeds: who may access the data, what attributes are allowed, at which connector, under which licence (including AI training restrictions), and for how long. The connector enforces these conditions at the moment of data transfer. The rights holder gets cryptographic, timestamped proof that the consumer accepted the terms.
Een Data Rights Credential bevat: wie de data mag benaderen, welke attributen zijn toegestaan, bij welke connector, onder welke licentie (inclusief AI-trainingsbeperkingen), en hoe lang. De connector dwingt deze voorwaarden af op het moment van datatransfer. De rechthebbende krijgt cryptografisch, tijdgestempeld bewijs dat de consumer de voorwaarden heeft geaccepteerd.
iSHARE Foundation is working with European and international bodies on frameworks for trustworthy AI data governance. The Data Rights Credential is designed to serve as a reusable building block — interoperable across jurisdictions, open to any standards-compliant implementation, and governed by a non-commercial, neutral scheme owner. If your government or organisation is working on AI data policy, contact us.
iSHARE Foundation werkt samen met Europese en internationale instanties aan kaders voor betrouwbare AI-datagovernance. Het Data Rights Credential is ontworpen als herbruikbaar bouwblok — interoperabel over jurisdicties, open voor elke standaardsconforme implementatie, en beheerd door een niet-commerciële, neutrale scheme owner. Als uw overheid of organisatie werkt aan AI-databeleid, neem dan contact op.
The iSHARE Foundation certifies two independent networks — one for Participant Credentials (who you are) and one for Data Rights Credentials (what you may access). A verifier checks both when validating a Verifiable Presentation.
De iSHARE Foundation certificeert twee onafhankelijke netwerken — één voor Participant Credentials (wie je bent) en één voor Data Rights Credentials (wat je mag inzien). Een verifier controleert beide bij het valideren van een Verifiable Presentation.
Two layers: the Certificate Authority chain that anchors trust, and the public key of each certified party. Both are published and machine-readable — no central call-back required to verify a credential.
Twee lagen: de Certificate Authority-keten die het vertrouwen verankert, en de public key van elke gecertificeerde partij. Beide zijn gepubliceerd en machine-leesbaar — geen centrale call-back nodig om een credential te verifiëren.
A credential signed by a key that is not on the Trusted Issuers Registry is rejected by every verifier in the ecosystem — automatically. Being on the list is what makes your credentials commercially viable.
Een credential ondertekend met een sleutel die niet in de Trusted Issuers Registry staat, wordt automatisch afgewezen door elke verifier in het ecosysteem. Op de lijst staan is wat uw credentials commercieel inzetbaar maakt.
A certified party issues any combination of Participant Credentials and Data Rights Credentials under one membership. Your public key appears once in the Registry, regardless of credential types issued.
Een gecertificeerde partij geeft elke combinatie van Participant Credentials en Data Rights Credentials uit onder één lidmaatschap. Uw public key staat eenmalig in het Register, ongeacht welke credential-typen u uitgeeft.
Certified parties that validate legal entity identity and issue Participant Credentials confirming iSHARE adherence.
Gecertificeerde partijen die de rechtspersoon valideren en Participant Credentials uitgeven die iSHARE-aansluiting bevestigen.
Certified issuers of Data Rights Credentials on behalf of Data Rightsholders — specifying who may access what, under which iSHARE Licence.
Gecertificeerde issuers van Data Rights Credentials namens Data Rightsholders — met vastlegging van wie wat mag inzien, onder welke iSHARE Licentie.
A verifier must confirm the credential was issued by a Trusted List party, the signature is valid, and the credential has not been revoked via the Bitstring Status List.
Een verifier moet bevestigen dat de credential is uitgegeven door een Trusted List-partij, de handtekening geldig is, en dat de credential niet ingetrokken is via de Bitstring Status List.
All iSHARE credentials must conform to JSON schemas published by the Scheme Owner — guaranteeing interoperability across all implementations.
Alle iSHARE-credentials moeten conformeren aan de door de Scheme Owner gepubliceerde JSON-schema's — dit garandeert interoperabiliteit over alle implementaties heen.
| Schema | Schema | v | Scenario | Description | Beschrijving | Link | Link |
|---|---|---|---|---|---|---|---|
| iSHARE Participant Credential | iSHARE Participant Credential | v3 | M2M H2M | Compound credential — combines Compliance + Dataspace participation in one document | Samengesteld credential — combineert Compliance + Dataspace-deelname in één document | schema.json ↗ | schema.json ↗ |
| iSHARE Compliance Credential | iSHARE Compliance Credential | v3 | M2M H2M | Framework roles, agreements, X.509 certificates and IDP assertions per framework | Frameworkrollen, overeenkomsten, X.509-certificaten en IDP-assertions per framework | schema.json ↗ | schema.json ↗ |
| Dataspace Participant Credential | Dataspace Participant Credential | v3 | M2M H2M | Dataspace membership, roles, rulebook and agreements per dataspace | Dataspace-lidmaatschap, rollen, rulebook en overeenkomsten per dataspace | schema.json ↗ | schema.json ↗ |
| Data Rights Credential | Data Rights Credential | v3 | M2M H2M | Delegation proof with iSHARE Licence specifying permitted use, attributes and validity | Delegatiebewijs met iSHARE Licentie, attributen en geldigheidsduur | schema.json ↗ | schema.json ↗ |
| Bitstring Status List | Bitstring Status List | v3 | M2M H2M | Privacy-preserving revocation and status for all issued credentials | Privacy-preserving revocatie en status voor alle uitgegeven credentials | schema.json ↗ | schema.json ↗ |
| Identity Credential | Identity Credential | — | H2M | Natural person acting on behalf of an organisation — schema in preparation (eIDAS 2.0 / EUDIW) | Natuurlijk persoon namens organisatie — schema in voorbereiding (eIDAS 2.0 / EUDIW) | Coming soon | Binnenkort |
Three open standards — together covering machine-to-machine and human-to-machine credential exchange completely.
Drie open standaarden — samen dekken ze machine-to-machine én mens-naar-machine uitwisseling volledig af.
Fully automated credential exchange between systems. No human intervention required.
Volledig geautomatiseerde credential-uitwisseling tussen systemen. Geen menselijke tussenkomst vereist.
Credential issuance where a user requests credentials from an issuer via a holder application. OAuth 2.0-based.
Credential-uitgifte waarbij een gebruiker via een holder-applicatie credentials aanvraagt bij een issuer. OAuth 2.0-gebaseerd.
Credential presentation by a user to a verifier. Supports selective attribute disclosure via Verifiable Presentations.
Credential-presentatie door een gebruiker aan een verifier. Ondersteunt selectieve attribuutdisclosure via Verifiable Presentations.
Every Data Rights Credential carries a legally binding iSHARE Licence. The moment a Data Consumer presents a Verifiable Presentation, they have cryptographically accepted that licence — and bear full legal responsibility for compliance. No separate contract needed. No ambiguity possible.
Elk Data Rights Credential draagt een juridisch bindende iSHARE Licentie. Op het moment dat een Data Consumer een Verifiable Presentation presenteert, heeft hij die licentie cryptografisch geaccepteerd — en draagt hij volledige juridische verantwoordelijkheid voor naleving. Geen apart contract nodig. Geen onduidelijkheid mogelijk.
iSHARE Licences at licenses.ishare.eu are standardised, machine-readable legal modules. A Data Rightsholder combines them like Lego bricks into a Data Rights Credential. Each combination is legally binding the moment the consumer presents a Verifiable Presentation — no negotiation, no separate paperwork.
iSHARE Licenties op licenses.ishare.eu zijn gestandaardiseerde, machine-leesbare juridische modules. Een Data Rightsholder combineert ze als Lego-blokjes in een Data Rights Credential. Elke combinatie is juridisch bindend zodra de consumer een Verifiable Presentation presenteert — geen onderhandeling, geen apart papierwerk.
Cryptographic proof the receiver accepted your licence. Enforceable without a bilateral contract.
Cryptografisch bewijs dat de ontvanger jouw licentie accepteerde. Afdwingbaar zonder bilateraal contract.
Verified identity + verified licence acceptance in one VP. No manual checks before sharing.
Geverifieerde identiteit + geverifieerde licentie-acceptatie in één VP. Geen handmatige checks voor datadeling.
Clear, machine-readable terms on every transaction. Explicit acceptance — not implied. No ambiguity about what is permitted.
Heldere, machine-leesbare voorwaarden bij elke transactie. Expliciete acceptatie — niet impliciet. Geen onduidelijkheid over wat is toegestaan.
Full audit trail. Every access tied to a verified legal entity, stated purpose, and accepted licence — timestamped and machine-readable.
Volledig auditspoor. Elke toegang gekoppeld aan geverifieerde rechtspersoon, opgegeven doel en geaccepteerde licentie — tijdgestempeld en machine-leesbaar.
Your Data. Your Choice.
Jouw Data. Jouw Keuze.
Become a certified issuer, implement iSHARE VC as a Service Provider, or verify credentials as part of your data space.
Word certified issuer, implementeer iSHARE VC als Service Provider, of verifieer credentials als deel van jouw dataspace.