A cryptographically signed permission slip — proving who may access which data, for how long, and under exactly which conditions.
Een cryptografisch ondertekende toestemmingsverklaring — bewijs van wie welke data mag inzien, hoe lang, en onder welke exacte voorwaarden.
Think of it as a signed permission slip — but with a legal stamp built in. The data owner says: "This person may read these files, for 30 days, only for this purpose." That statement is cryptographically signed so no one can fake or alter it.
Unlike a username and password, the Data Rights Credential travels with the request itself. Any system can verify it instantly — no phone call to the issuer needed. And because it carries an iSHARE Licence, the legal conditions of use are machine-readable, not buried in a PDF.
Zie het als een ondertekend toestemmingsbriefje — maar dan met een juridische stempel erop. De data-eigenaar zegt: "Deze persoon mag deze bestanden lezen, gedurende 30 dagen, alleen voor dit doel." Die verklaring is cryptografisch ondertekend, zodat niemand hem kan vervalsen of wijzigen.
In tegenstelling tot een gebruikersnaam en wachtwoord reist de Data Rights Credential mee met de aanvraag zelf. Elk systeem kan hem direct verifiëren — geen telefonisch contact met de issuer nodig. En omdat hij een iSHARE Licentie bevat, zijn de juridische gebruiksvoorwaarden machine-leesbaar, niet verstopt in een PDF.
The party whose data it is — a citizen, a company, a public body. Decides who gets access and under which conditions. Instructs the Data Rights Controller to issue the credential.
De partij wiens data het is — een burger, een bedrijf, een publieke instantie. Beslist wie toegang krijgt en onder welke voorwaarden. Instrueert de Data Rights Controller om de credential uit te geven.
A certified intermediary on the iSHARE Trusted List. Signs and issues the credential on behalf of the Rightsholder. Responsible for revocation if access must be withdrawn.
Een gecertificeerde tussenpersoon op de iSHARE Trusted List. Ondertekent en geeft de credential uit namens de Rightsholder. Verantwoordelijk voor intrekking als toegang moet worden beëindigd.
The data platform that receives and enforces the credential. Verifies the signature, checks the Trusted List, confirms the credential is not revoked, and enforces the licence conditions before releasing data.
Het dataplatform dat de credential ontvangt en handhaaft. Controleert de handtekening, raadpleegt de Trusted List, controleert revocatie en handhaaft de licentievoorwaarden voor datavrijgave.
The organisation or person who presents the credential to gain access. Stores it in a credential store (wallet) and presents it automatically when connecting to the data platform.
De organisatie of persoon die de credential presenteert om toegang te krijgen. Bewaart hem in een credential store (wallet) en presenteert hem automatisch bij verbinding met het dataplatform.
The iSHARE Foundation is a non-commercial foundation that acts as Scheme Owner: it defines the rules, certifies Data Rights Controllers, and maintains the Trusted List. It does not issue credentials itself and has no commercial role in individual transactions. Think of it as a standards body — it approves which organisations may issue credentials, but is never involved when a credential is actually issued.
De iSHARE Foundation is een niet-commerciële stichting die optreedt als Scheme Owner: ze stelt de regels, certificeert Data Rights Controllers en beheert de Trusted List. Ze geeft zelf geen credentials uit en heeft geen commerciële rol bij individuele transacties. Vergelijk het met een norminstituut: het keurt goed welke organisaties credentials mogen uitgeven, maar is bij de daadwerkelijke uitgifte nooit zelf betrokken.
Each field has a clear job. Together they answer: who, what, how, how long, and under which rules.
Elk veld heeft een duidelijke functie. Samen beantwoorden ze: wie, wat, hoe, hoe lang en onder welke regels.
A realistic, step-by-step walk-through from instruction to verified access.
Een realistische, stapsgewijze doorloop van instructie tot geverifieerde toegang.
| VC type | VC type | DataRightsCredential | |
| Schema URL | Schema URL | https://schemas.ishare.eu/v3/datarights/schema.json | |
| Context URL | Context URL | https://schemas.ishare.eu/v3/datarights/context.jsonld | |
| Issued by | Uitgegeven door | Data Rights Controller (certified by iSHARE Foundation) | Data Rights Controller (gecertificeerd door iSHARE Foundation) |
| Exchange (M2M) | Uitwisseling (M2M) | DCP v1.0 | |
| Exchange (H2M) | Uitwisseling (H2M) | OpenID4VP | |
| Revocation | Revocatie | Bitstring Status List (W3C) | Bitstring Status List (W3C) |
| Licence registry | Licentieregister | licenses.ishare.eu |