Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.

UMA Legal

Our "elevator pitch":


The overall goal of this subgroup is to accelerate adoption and reduce inhibitors in a business context.

This subgroup has produced its first draft reportA Proposed Licensing Model for User-Managed Access (or, "How the UMA protocol enables a license-based model for controlling access rights to personal digital assets")


. This paper is intended for professionals in the areas of law, privacy, risk, compliance, security policy, and business policy, particularly those responsible for building and running UMA-enabled services. 

What is the purpose of this model? The UMA technical protocol enables individuals to apply protection policies to their digital assets by using services to issue "permission tokens". The UMA


business model maps those permission tokens and related artifacts to licenses as legal devices. This licensing mechanism is valuable to individuals, organizations, legal professionals, and privacy professionals because it allows Alice to license Bob to use her digital resources on her terms


You can find out more about UMA here:

Part of the UMA WG's work is overtly technical, and part of the work explores other layers of the BLT (business-legal-technical) sandwich. The documents linked from this page, dedicated to the Legal subgroup's work, reflect efforts in these other areas, many produced by our ad hoc "legal subgroup".

The overall goal of this subgroup: Accelerate adoption and reduce inhibitors in a business context.


  • Produce a set of toolkits and associated educational materials by the end of 2017 whose purpose is to accelerate the ability of those in the following roles to adopt, deploy, and use UMA-enabled services in a manner consistent with protecting privacy rights:
    • Individuals ("natural persons")
    • Organizations ("legal persons" such as businesses and governments)
    • Legal representatives of the above
  • Focus on GDPR-related toolkits first and foremost. A toolkit could be anything that helps use or leverage an existing piece of legislation or framework, such as an SDK, a checklist, consent receipt templates or profiles, or a set of CommonAccord text, and could be related to the GDPR itself, the EU-U.S. Privacy Shield, BCRs, and so on.
  • Develop a roadmap by the end of 2016 that identifies specific deliverables and timelines within 2017.
  • By the end of 2016, develop two initial deliverables to To inform the roadmap work, develop:
    • Comparative analysis of UMA and GDPR concepts such as data subject, processor, and controller
    • Roundup of contractual and regulatory use cases
  • Leverage specialist legal expertise wherever possible to complete and review the deliverables.



The subgroup found funding to work with legal expert Tim Reiniger starting in 2017, with a schedule to produce three staged deliverables. The first, Use Cases for Analyzing and Determining a Legal Framework, was delivered in draft on 28 Feb 2017, with the group providing commentary and revisions as input to later stages, resulting in a revised final version delivered 26 Mar 2017. The second, The Legal Value Perspective for UMA Use Cases, was delivered on 31 May 2017, again after extensive group review and commentary. The third, UMA Definitions Annotated, was delivered 25 Aug 2017. Next up: Working on the broader legal framework, getting broader review, and choosing toolkits to develop in Q4 2017 and beyondA broader "legal framework" (now called business model), incorporating a revised version of the definitions, was published in early 2018.

Subgroup meetings

The subgroup's meeting times and notes are here. We meet on most Fridays at 8am PT.

If you are just visiting and are interested to join the UMA Work Group and take part in this subgroup's efforts, we invite you to join! Visit our home page and see the Join link there. Note: Since the legal subgroup meetings do not count towards WG quorum, it's advised to join as a "non-voting participant" unless you also intend to join the WG meetings on Thursdays at 9am PT.


" initiative to create global codes of legal transacting by codifying and automating legal documents, including contracts, permits, organizational documents, and consents. We anticipate that there will be codes for each jurisdiction, in each language. For international dealings and coordination, there will be at least one "global" code."

Here is one version of the draft model text. The definitions are more mature than the clauses, but all of this text predates the analysis being performed and may be radically changed.

Additional artifacts

An UMA in Contractual and Regulatory Contexts primer/manual is in early draft form. This slide deck, presented at Digital Contracts, Identities, and Blockchain at MIT in May 2016, shares some key use cases. A few additional artifacts are available on the WG's GitHub wiki. All of this work predates the analysis being performed. We may produce a completely new primer/manual at the end of this processAsk the chair to get access to the "UMA Legal Definitions" slide deck.