Zero Collection
Avoid collecting personal data that is not necessary for a clearly declared function. Collection should be justified, limited and never treated as the automatic starting point.
Zero Data Protocol is an architectural framework for reducing unnecessary personal-data collection, retention and exploitation by design.
Initiated by Lajos Nagy, ZDP offers a direction for building useful digital functions with less dependency on personal identity and persistent behavioural traces.
Digital systems gradually became dependent on collection, storage, tracking and profiling. ZDP begins with another question: what data is genuinely necessary for the function to work?
Zero Data Protocol (ZDP) is an independent and emerging architectural framework initiated by Lajos Nagy for designing digital systems that reduce unnecessary dependency on personal data. It is structured around three principles: Zero Collection, Zero Retention and Zero Exploitation. ZDP promotes privacy by architecture by avoiding non-essential collection, limiting retention to defined functional or legal needs, and preventing profiling or behavioural exploitation beyond the declared purpose. It complements cybersecurity, encryption, privacy-enhancing technologies and regulatory frameworks such as GDPR; it does not replace them and is not currently a ratified technical standard or certification.
ZDP moves the privacy question upstream — from protecting everything after collection to reducing what enters the system in the first place.
Avoid collecting personal data that is not necessary for a clearly declared function. Collection should be justified, limited and never treated as the automatic starting point.
Do not retain personal data beyond defined functional, security or legal needs. Where processing is necessary, prefer limited, purpose-bound and appropriately protected retention.
Prevent personal traces from being repurposed for undeclared profiling, behavioural targeting or identity-based exploitation beyond the function the user intended to access.
ZDP does not replace protection. It adds an earlier architectural decision: determine whether personal data needs to exist inside the system at all.
ZDP may work alongside legal, security and privacy-enhancing approaches, but it should not be confused with them.
GDPR regulates how personal data is lawfully processed and protected. ZDP asks whether that data dependency can be reduced architecturally. ZDP does not replace legal compliance.
Zero Data Retention focuses on what happens after data is processed. ZDP also examines collection and exploitation before deciding whether retention is necessary.
Zero-knowledge proofs are cryptographic techniques for proving statements without revealing underlying information. They may support a ZDP-aligned design, but they are not the framework itself.
Zero Trust continuously verifies access and assumes no implicit trust. ZDP focuses on reducing unnecessary personal-data dependency. The two directions can be complementary.
Data minimisation reduces the amount of data processed. ZDP extends that logic into an architectural question: can the function be redesigned so that the dependency does not arise?
Zero-party data is information voluntarily provided by a user. ZDP still asks whether collecting and retaining that personal information is necessary for the declared function.
These examples illustrate potential design directions. They are not claims of certified implementation or proven universal suitability.
Explore short-lived capabilities, selective disclosure or privacy-preserving proofs where persistent identity is not functionally required.
Prefer contextual or session-based choices over permanent behavioural profiles and cross-service user tracking.
Separate functional transaction requirements from unnecessary profiling, while respecting financial, fraud-prevention and legal retention obligations.
Limit unnecessary identity-linked prompts, logs, training reuse and behavioural inference through explicit purpose and retention boundaries.
Evaluate whether contact graphs, message metadata or persistent identity records are necessary for the specific communication function.
Replace individual surveillance with aggregate, contextual or privacy-preserving measurement wherever the business question allows it.
Zero Data Protocol is currently being developed as an independent architectural framework.
Its three founding principles provide a clear direction for reducing unnecessary personal-data dependency, but ZDP is not yet a ratified technical standard, certification system or universally adopted implementation protocol.
Its long-term ambition is to contribute to a broadly applicable architectural standard for data non-dependency.
A credible architectural framework must describe not only its direction, but also what it cannot promise.
Systems may still require technical, transactional, security or legally mandated data. ZDP focuses on necessity, purpose, proportionality and limited retention.
Less personal data can reduce exposure, but software vulnerabilities, fraud, availability failures and other security risks still require dedicated controls.
Encryption, access control, monitoring, secure development and incident response remain necessary wherever systems process data.
ZDP is not legal advice, an official regulatory framework or a current certification scheme. Applicable laws and sector-specific obligations remain fully relevant.
Zero Data Protocol was initiated and developed by Lajos Nagy, AI Privacy Architect and founder of NAGY Consulting.
ZDP began as an independent exploration of a fundamental architectural question: can digital systems deliver useful functions without making personal-data collection, retention and exploitation their default operating model?
The framework is under active development. Its evolution will be documented through versioned publications, practical examples, clearly stated limitations and opportunities for external review.
These resources explain the framework’s relationship with cybersecurity, regulation and privacy-before-collection.
Why reducing unnecessary personal data can reduce what a vulnerability or breach is able to expose.
Read the article → RegulationThe difference between regulating personal data and reducing the architectural need to collect it.
Read the article → Core principleUnderstanding privacy before collection without claiming that all operational data can disappear.
Read the article →ZDP does not promise the elimination of every form of data, risk or legal responsibility. It provides an architectural direction for avoiding unnecessary collection, limiting retention and preventing exploitation beyond a system’s declared purpose.