Not Before Time

Not Before Time is a public broadcast facility built on existing technology. Not Before Time gives three strong guarantees that information: will not be readable before a certain future time was not sealed before a certain past date and time was not electronically signed before a certain time These support human rights, democracy and business. The second guarantee is a lower bound on sealing, not a creation date. A released NBT private key cannot be inside a package sealed before its release, although it can be added to old material later. The claim cannot be checked until the package opens; a priority claim needs the ciphertext published or independently anchored at the relevant time. ...

10 April 2026 · 20 min · Dan Shearer

Data Mobility in the Trumpian Post-Brexit Era

These matters of complicated jurisdiction and sovereignty law require the advice of an experienced international lawyer. These lawyers need the advice of experienced international technologists, and that is the bit I do. Each has to know quite a bit about what the other is doing, so I study the relevant statutes and speak to the people who are drafting the next versions of the regulations. The 2023 EU-US Data Privacy Framework (DPF) ↗ was intended to put limits on US surveillance of EU citizens (with UK citizens covered in a later bolt-on) but in 2026 it is on life support. Designed to allow US companies such as Amazon, Microsoft, Iron Mountain and the like to hold vast amounts data despite US government spying, it has had mandatory parts of it collapse. The US Privacy and Civil Liberties Oversight Board (PCLOB) is one, and the equally essential US Act of Congress FISA Section 702 ↗ expired in June 2026. These failures do not stop the surveillance, just the oversight of the spying the US promised. EU/UK businesses often choose to store their data within US control, and so these laws and frameworks are designed to make it legal for them to do so. See the companion article on the root cause, but the upshot is there is no protection for EU/UK data. These legalities are a kind of expensive compliance dance that does not achieve its goal, except to continue the revenue stream for these US companies. ...

11 February 2026 · 15 min · Dan Shearer

Opportunity in GDPR Article 28

The detail of the GDPR and its implied computer science contain a solution for sharing secrets according to law. This continues to be true in 2026, as the Digital Omnibus Regulation ↗ takes shape. Executive Summary The GDPR sets up a conflict in trust between companies in particular circumstances, which can only be resolved by using the automation of a cryptographic audit trail with particular properties as described below. Problem Statement Under the EU’s GDPR ↗ law virtually every company is a Controller, and virtually all Controllers use at least one Processor. When a Processor is engaged, the GDPR requires that a contract is signed with the very specific contents spelled out in clause 3 of Article 28. The GDPR requires that Controllers and Processors cooperate together in order to deliver data protection, and this cooperation needs to be very carefully managed to maintain the security and other guarantees that the GDPR also requires. That’s what this mandatory contract is intended to achieve. ...

9 February 2026 · 14 min · Dan Shearer

Root cause of the EU-US privacy battles

These matters of complicated jurisdiction and sovereignty law require the advice of an experienced international data lawyer. These lawyers need the advice of experienced international technologists, and that is the bit I do. Each has to know quite a bit about what the other is doing, so I study the relevant statutes and speak to the people drafting the next versions of the regulations. The EU Court of Justice has twice ↗ decided ↗ that US spying means EU data cannot be managed by US companies, because it violates the privacy of EU citizens. This was very awkward because US companies captured a large part of the EU data market and used their money and influence to spin this issue and in 2026 the court will decide the appeal on a third decision ↗. The facts have materially changed and many observers feel there is potential the court will strike down the 2023 EU-US Data Privacy Framework (DPF) ↗ currently in force. Throughout this period the various laws and regulatory schemes keep getting changed to provide a way for the practically unlimited US spying to be presented as limited by US government promises. Even if these companies promise to hold data within the EU, and even if they are otherwise highly compliant, the US government still insists on access to all data at all times. That is why these cases keep getting brought and in 2026 the mood in Europe is very different. Perhaps this time there will be a definitive “no” from the court given that many EU governments and companies are turning away from US cloud as a matter of sovereign policy. The UK situation depends in many ways on whatever it is that the EU court decides. ...

8 February 2026 · 8 min · Dan Shearer

Fossil

The Fossil ↗ source code management system is the most fully-featured alternative to Git, and has decades of development and testing starting in 2007. After helping Fossil make some changes I now use Fossil for several projects. I also use Git extensively on various software forges (but not GitHub unless I must). Mercurial ↗ is actively maintained as described in this FOSDEM 2026 talk ↗ but is rarely chosen for new projects today. So if we stick to supported production tools that get new users it’s either Fossil or Git. Git use is vastly greater than Fossil’s, but on features, portability, longevity and developer response time Fossil tends to lead Git. ...

8 February 2026 · 13 min · Dan Shearer

LumoSQL

LumoSQL ↗ protects data on mobile phones and other computers using a new data storage technology which is highly compatible with most existing devices. The first part of this gives better robustness in the case of a powerloss or other crash, and at-rest encryption. Most apps have no encryption at all so this is a great improvement. With the second part of LumoSQL being developed now, the device owner decides who can read or change their data down to the level of individual rows if they choose. This decision continues to be enforced even after it has been copied off the phone to (for example) a bank or dating or insurance company for processing with their in-house database software. Today, device owners are rarely in control of the privacy of their own data, despite the many privacy laws. If a phone is separated from its owner, LumoSQL data rows cannot be read without the consent of either the phone owner or someone to whom the phone owner has granted access even if the phone has been unlocked. These controls are fine-grained, meaning different levels of permission can be granted. ...

7 February 2026 · 9 min · Dan Shearer

Security Standards and Certifications

I have been lead implementer of the main security and privacy standards several times each. These can seem intimidating, but properly used they improve security overall, and can help a business run more smoothly. From a pragmatic, business point of view: These standards are about writing down the actual rules of your business relevant to security and privacy, and then writing down how you improve these rules, and recording how well they work. All businesses can benefit from challenging their working habits and practices, and since privacy and security touch most parts of a business, this is an opportunity to review how the business works before something goes wrong. From the point of view of both Computer Science and Information Management Science: ...

1 February 2026 · 5 min · Dan Shearer