iSHARE Verifiable Credential

Data Rights Credential

Data Rights Credential

A cryptographically signed permission slip — proving who may access which data, for how long, and under exactly which conditions.

Een cryptografisch ondertekende toestemmingsverklaring — bewijs van wie welke data mag inzien, hoe lang, en onder welke exacte voorwaarden.

What is it?
Wat is het?

A signed permission slip with a legal stamp built in

Een ondertekend toestemmingsbewijs met juridische kracht

Plain-language analogy
Begrijpelijke uitleg

Think of it as a signed permission slip — but with a legal stamp built in. The data owner says: "This person may read these files, for 30 days, only for this purpose." That statement is cryptographically signed so no one can fake or alter it.

Unlike a username and password, the Data Rights Credential travels with the request itself. Any system can verify it instantly — no phone call to the issuer needed. And because it carries an iSHARE Licence, the legal conditions of use are machine-readable, not buried in a PDF.

Zie het als een ondertekend toestemmingsbriefje — maar dan met een juridische stempel erop. De data-eigenaar zegt: "Deze persoon mag deze bestanden lezen, gedurende 30 dagen, alleen voor dit doel." Die verklaring is cryptografisch ondertekend, zodat niemand hem kan vervalsen of wijzigen.

In tegenstelling tot een gebruikersnaam en wachtwoord reist de Data Rights Credential mee met de aanvraag zelf. Elk systeem kan hem direct verifiëren — geen telefonisch contact met de issuer nodig. En omdat hij een iSHARE Licentie bevat, zijn de juridische gebruiksvoorwaarden machine-leesbaar, niet verstopt in een PDF.

Who is involved?
Wie is erbij betrokken?

Four roles, one credential

Vier rollen, één credential

Data Rightsholder

Data Rightsholder

The party whose data it is — a citizen, a company, a public body. Decides who gets access and under which conditions. Instructs the Data Rights Controller to issue the credential.

De partij wiens data het is — een burger, een bedrijf, een publieke instantie. Beslist wie toegang krijgt en onder welke voorwaarden. Instrueert de Data Rights Controller om de credential uit te geven.

Data Rights Controller

Data Rights Controller

A certified intermediary on the iSHARE Trusted List. Signs and issues the credential on behalf of the Rightsholder. Responsible for revocation if access must be withdrawn.

Een gecertificeerde tussenpersoon op de iSHARE Trusted List. Ondertekent en geeft de credential uit namens de Rightsholder. Verantwoordelijk voor intrekking als toegang moet worden beëindigd.

Service Provider / Connector

Service Provider / Connector

The data platform that receives and enforces the credential. Verifies the signature, checks the Trusted List, confirms the credential is not revoked, and enforces the licence conditions before releasing data.

Het dataplatform dat de credential ontvangt en handhaaft. Controleert de handtekening, raadpleegt de Trusted List, controleert revocatie en handhaaft de licentievoorwaarden voor datavrijgave.

Data Consumer

Data Consumer

The organisation or person who presents the credential to gain access. Stores it in a credential store (wallet) and presents it automatically when connecting to the data platform.

De organisatie of persoon die de credential presenteert om toegang te krijgen. Bewaart hem in een credential store (wallet) en presenteert hem automatisch bij verbinding met het dataplatform.

iSHARE Foundation — Scheme Owner, not an issuer iSHARE Foundation — Scheme Owner, geen issuer

The iSHARE Foundation is a non-commercial foundation that acts as Scheme Owner: it defines the rules, certifies Data Rights Controllers, and maintains the Trusted List. It does not issue credentials itself and has no commercial role in individual transactions. Think of it as a standards body — it approves which organisations may issue credentials, but is never involved when a credential is actually issued.

De iSHARE Foundation is een niet-commerciële stichting die optreedt als Scheme Owner: ze stelt de regels, certificeert Data Rights Controllers en beheert de Trusted List. Ze geeft zelf geen credentials uit en heeft geen commerciële rol bij individuele transacties. Vergelijk het met een norminstituut: het keurt goed welke organisaties credentials mogen uitgeven, maar is bij de daadwerkelijke uitgifte nooit zelf betrokken.

What's inside?
Wat staat er in?

Key fields in the credential

Belangrijkste velden in de credential

Each field has a clear job. Together they answer: who, what, how, how long, and under which rules.

Elk veld heeft een duidelijke functie. Samen beantwoorden ze: wie, wat, hoe, hoe lang en onder welke regels.

Concrete example
Concreet voorbeeld

A citizen shares smart-meter data with an energy advisor

Een burger deelt slimmemeterdata met een energieadviseur

A realistic, step-by-step walk-through from instruction to verified access.

Een realistische, stapsgewijze doorloop van instructie tot geverifieerde toegang.

1
The citizen instructs their energy supplier (the Data Rights Controller) via an online portal: "Please give energy advisor Organisation X access to my meter data until 30 September 2026."
De burger instrueert de energieleverancier (de Data Rights Controller) via een online portal: "Geef energieadviseur Organisatie X toegang tot mijn meterdata tot 30 september 2026."
2
The energy supplier creates and cryptographically signs a Data Rights Credential: Advisor Organisation X may read meter address Y until 30 Sept 2026, under iSHARE Licence L-001 (professional energy advisory only).
De energieleverancier maakt en ondertekent cryptografisch een Data Rights Credential: Adviseur Organisatie X mag lezen van meteradres Y tot 30 sept 2026, onder iSHARE Licentie L-001 (alleen professioneel energieadvies).
3
The credential is delivered to the energy advisor's credential store. The advisor's connector system receives it automatically.
De credential wordt afgeleverd in de credential store van de energieadviseur. Het connectorsysteem van de adviseur ontvangt hem automatisch.
4
The advisor's system presents the Data Rights Credential to the energy data platform when requesting access to the meter data.
Het systeem van de adviseur presenteert de Data Rights Credential aan het energiedataplatform bij het opvragen van de meterdata.
5
The platform runs four checks: Is the issuer on the Trusted List? Is the signature valid? Is the credential not revoked? Are the licence conditions met?
Het platform voert vier controles uit: staat de issuer op de Trusted List? Is de handtekening geldig? Is de credential niet ingetrokken? Zijn de licentievoorwaarden voldaan?
6
All checks pass. Access is granted — and every access event is logged with the advisor's verified identity, creating a legally provable audit trail.
Alle controles slagen. Toegang wordt verleend — en elke toegangsgebeurtenis wordt gelogd met de geverifieerde identiteit van de adviseur, wat een juridisch aantoonbare audittrail oplevert.
Technical details
Technische details

For developers

Voor ontwikkelaars

Show technical specification Technische specificatie tonen
VC typeVC typeDataRightsCredential
Schema URLSchema URLhttps://schemas.ishare.eu/v3/datarights/schema.json
Context URLContext URLhttps://schemas.ishare.eu/v3/datarights/context.jsonld
Issued byUitgegeven doorData Rights Controller (certified by iSHARE Foundation)Data Rights Controller (gecertificeerd door iSHARE Foundation)
Exchange (M2M)Uitwisseling (M2M)DCP v1.0
Exchange (H2M)Uitwisseling (H2M)OpenID4VP
RevocationRevocatieBitstring Status List (W3C)Bitstring Status List (W3C)
Licence registryLicentieregisterlicenses.ishare.eu
Other credentials
Andere credentials