Code of Conduct

This file is a Code of Conduct first written in 2020 for the LumoSQL project, with the heading: This file exists because the LumoSQL Project needed it, less than one year after starting in 2019. We take it seriously, and hope that most English-reading adults can understand what is said. We hope this is not needed very often. Collective kindness is needed more than ever in this global pandemic. Here is Version 1.6 – Updated 9th February, 2026. ...

16 September 2026 · 5 min · Dan Shearer

Health Observer Systems: A Comparative Review

I looked for every health data system that shares features with my Medical Snapshot proposal, something I’ve been working on since 2007. Such programmes medically measure people over time, store what they find, and don’t usually tell the individuals what their own data says. This article summarises what I have learned by looking at 25 existing systems, covering 90 years from the Tuskegee Syphilis Study ↗ (1932) to Our Future Health ↗ (2022). I have tried to indicate my biases and assumptions but the purpose of these notes is to inform my own thoughts about the Snapshot concept. I also came across built-in biases in search engines. ...

17 April 2026 · 9 min · Dan Shearer

Health Observer Systems: Scoring Table

This page contains the working behind the Health Observer Systems comparative review of the Medical Snapshot system: feature definitions, search and source notes, and the full scoring table. The R source reproduces the plots. This is very boring but I’m showing how I got to my conclusion. If someone is into statistics and would enjoy improving this design then yes please I’d love to hear from you. My research question This analysis is an exploration of how existing systems compare to my hypothetical Snapshot system. The matrix measures how close each system comes to the Snapshot’s architecture, asking the narrow question: which of the Snapshot’s features has each existing system implemented? ...

17 April 2026 · 6 min · Dan Shearer

Medical Snapshot

This is about an Observer-only Medical system, which can be immensely useful to society and governments, helping understand health and reducing suffering. There are many such systems but all of them have a common principle: individuals have their health monitored and are not told the results. So what’s in it for the individual who gives up the right to their own health data? I started thinking about this while working in health systems (the Internet Archive found a version from 2010 ↗). Over the years since then I have been variously employed in privacy, data sharing/donation, safety in health data movements, causality and risk assessment and my original background of cybersecurity - all of which are combined in observer health systems. When I realised my idea was not new at all, I compared it with 25 existing systems over the last 90 years, using a scoring system and graphical analysis. ...

14 April 2026 · 18 min · Dan Shearer

Data Mobility in the Trumpian Post-Brexit Era

These matters of complicated jurisdiction and sovereignty law require the advice of an experienced international lawyer. These lawyers need the advice of experienced international technologists, and that is the bit I do. Each has to know quite a bit about what the other is doing, so I study the relevant statutes and speak to the people who are drafting the next versions of the regulations. The 2023 EU-US Data Privacy Framework (DPF) ↗ was intended to put limits on US surveillance of EU citizens (with UK citizens covered in a later bolt-on) but in 2026 it is on life support. Designed to allow US companies such as Amazon, Microsoft, Iron Mountain and the like to hold vast amounts data despite US government spying, it has had mandatory parts of it collapse. The US Privacy and Civil Liberties Oversight Board (PCLOB) is one, and the equally essential US Act of Congress FISA Section 702 ↗ expired in June 2026. These failures do not stop the surveillance, just the oversight of the spying the US promised. EU/UK businesses often choose to store their data within US control, and so these laws and frameworks are designed to make it legal for them to do so. See the companion article on the root cause, but the upshot is there is no protection for EU/UK data. These legalities are a kind of expensive compliance dance that does not achieve its goal, except to continue the revenue stream for these US companies. ...

11 February 2026 · 15 min · Dan Shearer

One Health and Epidemiology

While working with the Rule-based Epidemic Modelling group at the University of Southampton ↗ I began to consider the wider context, outside our core area of studying malaria. On the one hand, the techniques of epidemiology save lives at scale, but on the other, emerging diseases and newer health-related epidemics are accelerating. It seemed as if the field of epidemiology was really struggling, and indeed that turns out to be true. Most of the world has now adopted a new, holistic and systemic approach to healthcare, called One Health. One Health treats ecology, animals and humans as a system of systems across dozens of science fields, using the language of epidemiology. ...

10 February 2026 · 2 min · Dan Shearer

Patents and the MIT License

Patents and the MIT License Some of my software projects use MIT so I have studied this issue. Although in many respects the world has moved on from copyright wars to much higher-stakes legal shenanigans, the detail of licensing still matters. In my case: My LumoSQL project is based on probably the most-used software, SQLite, whose license states it is in the “Public Domain”. The meaning of this isn’t entirely clear in some cases, and a 21st century software project starting decades after SQLite shouldn’t copy this. I chose MIT as a commonly accepted alternative, but which license is that exactly, and what does the text imply about patents? This is known, but I had to dig. The MIT license is massively used, but who will defend it if needed? We know the answer for the GPL, and also Apache-type licenses. I am now satisfied that quite a lot of enormous organisations really do care about MIT. There are lots of reasons why MIT isn’t ideal, but in my view those are trumped by it being widely accepted as fit for purpose, and relied upon by organisations who care that it remains effective and unambiguous. My notes are mostly kept in my many contributions ↗ to the Wikipedia page on the MIT License ↗ since that is where the decades-old knowledge of the MIT license origins is already maintained. The legal minds in many of the largest companies in the world seem to accept that at least in the US the MIT license implies a patent grant. As probably the most-used open source license, the MIT license has many wealthy corporate defenders if anyone wanted to test that idea.

10 February 2026 · 2 min · Dan Shearer

Opportunity in GDPR Article 28

The detail of the GDPR and its implied computer science contain a solution for sharing secrets according to law. This continues to be true in 2026, as the Digital Omnibus Regulation ↗ takes shape. Executive Summary The GDPR sets up a conflict in trust between companies in particular circumstances, which can only be resolved by using the automation of a cryptographic audit trail with particular properties as described below. Problem Statement Under the EU’s GDPR ↗ law virtually every company is a Controller, and virtually all Controllers use at least one Processor. When a Processor is engaged, the GDPR requires that a contract is signed with the very specific contents spelled out in clause 3 of Article 28. The GDPR requires that Controllers and Processors cooperate together in order to deliver data protection, and this cooperation needs to be very carefully managed to maintain the security and other guarantees that the GDPR also requires. That’s what this mandatory contract is intended to achieve. ...

9 February 2026 · 14 min · Dan Shearer

How to Replace Windows NT with Linux

When Linux was a Struggling Challenger 💡 Key Point This is a 2026 restoration of my (Dan Shearer’s) 1998-2001 guide, preserved at archive.org ↗. Links have been updated to point to the archives where possible. In 1999 I joined my first startup, Linuxcare in San Francisco. The Linuxcare story is a quintessential United States dot-com bubble narrative, featuring a famous venture capital fund, massive growth, a failed IPO, and a fancy new ex-IBM CEO resigning under a cloud. Founded in 1998, Linuxcare aimed to be the “0800 number for Linux”. So close! ...

8 February 2026 · 45 min · Dan Shearer

Root cause of the EU-US privacy battles

These matters of complicated jurisdiction and sovereignty law require the advice of an experienced international data lawyer. These lawyers need the advice of experienced international technologists, and that is the bit I do. Each has to know quite a bit about what the other is doing, so I study the relevant statutes and speak to the people drafting the next versions of the regulations. The EU Court of Justice has twice ↗ decided ↗ that US spying means EU data cannot be managed by US companies, because it violates the privacy of EU citizens. This was very awkward because US companies captured a large part of the EU data market and used their money and influence to spin this issue and in 2026 the court will decide the appeal on a third decision ↗. The facts have materially changed and many observers feel there is potential the court will strike down the 2023 EU-US Data Privacy Framework (DPF) ↗ currently in force. Throughout this period the various laws and regulatory schemes keep getting changed to provide a way for the practically unlimited US spying to be presented as limited by US government promises. Even if these companies promise to hold data within the EU, and even if they are otherwise highly compliant, the US government still insists on access to all data at all times. That is why these cases keep getting brought and in 2026 the mood in Europe is very different. Perhaps this time there will be a definitive “no” from the court given that many EU governments and companies are turning away from US cloud as a matter of sovereign policy. The UK situation depends in many ways on whatever it is that the EU court decides. ...

8 February 2026 · 8 min · Dan Shearer