Independent emerging framework

What if digital systems needed less personal data?

Zero Data Protocol is an architectural framework for reducing unnecessary personal-data collection, retention and exploitation by design.

Initiated by Lajos Nagy, ZDP offers a direction for building useful digital functions with less dependency on personal identity and persistent behavioural traces.

Current status Independent emerging framework
Core structure Three architectural principles
Standardisation Not currently ratified
The internet was meant to connect — not to observe.

Digital systems gradually became dependent on collection, storage, tracking and profiling. ZDP begins with another question: what data is genuinely necessary for the function to work?

Canonical definition

What is Zero Data Protocol?

Zero Data Protocol (ZDP) is an independent and emerging architectural framework initiated by Lajos Nagy for designing digital systems that reduce unnecessary dependency on personal data. It is structured around three principles: Zero Collection, Zero Retention and Zero Exploitation. ZDP promotes privacy by architecture by avoiding non-essential collection, limiting retention to defined functional or legal needs, and preventing profiling or behavioural exploitation beyond the declared purpose. It complements cybersecurity, encryption, privacy-enhancing technologies and regulatory frameworks such as GDPR; it does not replace them and is not currently a ratified technical standard or certification.

No unnecessary data collected means less sensitive data to protect. ZDP does not claim that every digital system can operate without any data. It requires each personal-data dependency to be examined, justified and limited.
The foundation

Three core principles

ZDP moves the privacy question upstream — from protecting everything after collection to reducing what enters the system in the first place.

01

Zero Collection

Avoid collecting personal data that is not necessary for a clearly declared function. Collection should be justified, limited and never treated as the automatic starting point.

02

Zero Retention

Do not retain personal data beyond defined functional, security or legal needs. Where processing is necessary, prefer limited, purpose-bound and appropriately protected retention.

03

Zero Exploitation

Prevent personal traces from being repurposed for undeclared profiling, behavioural targeting or identity-based exploitation beyond the function the user intended to access.

Privacy by architecture

From data-heavy by default to data-necessary by design

ZDP does not replace protection. It adds an earlier architectural decision: determine whether personal data needs to exist inside the system at all.

Traditional data-dependent model
  • Broad collection before necessity is assessed
  • Persistent identity and behavioural profiles
  • Long or undefined retention periods
  • Protection applied after data enters the system
  • Additional exposure and compliance complexity
ZDP architectural direction
  • Minimal personal data by default
  • Anonymous or pseudonymous interaction where feasible
  • Limited and purpose-defined retention
  • Clear functional and legal data boundaries
  • No unnecessary collection or exploitation
Related, but different

What ZDP is — and what it is not

ZDP may work alongside legal, security and privacy-enhancing approaches, but it should not be confused with them.

ZDP vs GDPR

GDPR regulates how personal data is lawfully processed and protected. ZDP asks whether that data dependency can be reduced architecturally. ZDP does not replace legal compliance.

ZDP vs Zero Data Retention

Zero Data Retention focuses on what happens after data is processed. ZDP also examines collection and exploitation before deciding whether retention is necessary.

ZDP vs Zero-Knowledge Proofs

Zero-knowledge proofs are cryptographic techniques for proving statements without revealing underlying information. They may support a ZDP-aligned design, but they are not the framework itself.

ZDP vs Zero Trust

Zero Trust continuously verifies access and assumes no implicit trust. ZDP focuses on reducing unnecessary personal-data dependency. The two directions can be complementary.

ZDP vs Data Minimisation

Data minimisation reduces the amount of data processed. ZDP extends that logic into an architectural question: can the function be redesigned so that the dependency does not arise?

ZDP vs Zero-Party Data

Zero-party data is information voluntarily provided by a user. ZDP still asks whether collecting and retaining that personal information is necessary for the declared function.

Practical direction

Where the framework can be explored

These examples illustrate potential design directions. They are not claims of certified implementation or proven universal suitability.

Authentication

Explore short-lived capabilities, selective disclosure or privacy-preserving proofs where persistent identity is not functionally required.

Content and recommendations

Prefer contextual or session-based choices over permanent behavioural profiles and cross-service user tracking.

Payments and transactions

Separate functional transaction requirements from unnecessary profiling, while respecting financial, fraud-prevention and legal retention obligations.

Artificial intelligence

Limit unnecessary identity-linked prompts, logs, training reuse and behavioural inference through explicit purpose and retention boundaries.

Communication systems

Evaluate whether contact graphs, message metadata or persistent identity records are necessary for the specific communication function.

Analytics

Replace individual surveillance with aggregate, contextual or privacy-preserving measurement wherever the business question allows it.

Transparent positioning

Current development status

Zero Data Protocol is currently being developed as an independent architectural framework.

Its three founding principles provide a clear direction for reducing unnecessary personal-data dependency, but ZDP is not yet a ratified technical standard, certification system or universally adopted implementation protocol.

Its long-term ambition is to contribute to a broadly applicable architectural standard for data non-dependency.

Foundational white paper Canonical definitions, scope, principles and limitations.
Versioned public specification Requirements, exclusions and architectural guidance.
Implementation examples Realistic patterns showing necessary and unnecessary data.
Assessment criteria Transparent rules for evaluating ZDP alignment.
External examination Progressive technical review and independent criticism.
In ZDP, the word “Protocol” refers to an organised set of architectural principles, future requirements and assessment rules. It does not currently designate a network protocol, an RFC, an API specification or an official certification.
Scope and honesty

Limits that must remain visible

A credible architectural framework must describe not only its direction, but also what it cannot promise.

ZDP does not mean no operational data

Systems may still require technical, transactional, security or legally mandated data. ZDP focuses on necessity, purpose, proportionality and limited retention.

ZDP does not eliminate every risk

Less personal data can reduce exposure, but software vulnerabilities, fraud, availability failures and other security risks still require dedicated controls.

ZDP does not replace cybersecurity

Encryption, access control, monitoring, secure development and incident response remain necessary wherever systems process data.

ZDP does not certify compliance

ZDP is not legal advice, an official regulatory framework or a current certification scheme. Applicable laws and sector-specific obligations remain fully relevant.

Origin and development

Initiated by Lajos Nagy

Zero Data Protocol was initiated and developed by Lajos Nagy, AI Privacy Architect and founder of NAGY Consulting.

ZDP began as an independent exploration of a fundamental architectural question: can digital systems deliver useful functions without making personal-data collection, retention and exploitation their default operating model?

The framework is under active development. Its evolution will be documented through versioned publications, practical examples, clearly stated limitations and opportunities for external review.

Frequently asked questions

Clear answers about ZDP

What does ZDP mean?
ZDP means Zero Data Protocol. It is an independent and emerging architectural framework for reducing unnecessary personal-data collection, retention and exploitation by design.
Is ZDP an official standard?
No. ZDP has not been ratified by ISO, NIST, IETF or another recognised standards body. Its ambition is to develop clear principles, requirements, implementation guidance and assessment criteria that can be examined independently.
Why is it called a protocol?
In ZDP, “Protocol” refers to an organised set of architectural principles and future evaluation rules. It does not currently mean a network protocol, an RFC, an API or an official certification standard.
Does ZDP mean that a system processes no data at all?
No. Digital functions may require operational, security, transactional or legally mandated data. ZDP asks systems to avoid unnecessary personal data and to limit necessary processing to a defined purpose and retention period.
Is ZDP the same as Zero Data Retention?
No. Zero Data Retention focuses primarily on avoiding storage after processing. ZDP also examines whether collection and exploitation are necessary before retention is considered.
Does ZDP replace GDPR or privacy law?
No. ZDP is an architectural direction, not a legal compliance framework. Organisations remain responsible for all laws, regulations and sector-specific obligations that apply to them.
Does ZDP replace encryption or cybersecurity?
No. Encryption and security controls protect necessary data and systems. ZDP complements them by asking whether some personal data can be avoided, shortened in retention or separated from identity.
Who initiated Zero Data Protocol?
Zero Data Protocol was initiated and developed by Lajos Nagy as an independent architectural framework. Its future development is intended to become increasingly documented, versioned and open to technical examination.
The defining question

Do we still need to collect it at all?

ZDP does not promise the elimination of every form of data, risk or legal responsibility. It provides an architectural direction for avoiding unnecessary collection, limiting retention and preventing exploitation beyond a system’s declared purpose.