ADAFP Digital LaboratorySolid FPA
Programme in design phase

Political data should belong to the people it describes

Solid for Political Activities (Solid FPA) is a programme of the ADAFP Digital Laboratory. It will use Solid, an open web standard, so that members, activists and political organisations hold their own data and decide who may use it.

Why political data needs a different model

Most political organisations keep their members, volunteers and supporters in one central database. That is convenient, but it concentrates risk.

One list, one target

A single membership database can be leaked, hacked, sold or seized. When it is exposed, everyone on it is exposed at once.

The law treats it as sensitive

Political opinion is special personal information under South Africa's POPIA and a special category of data under the EU's GDPR. Holding it brings strict duties.

Members rarely control their records

People who join an organisation usually cannot see, correct, move or withdraw the data held about them in any practical way.

What Solid is

Solid is an open standard for managing digital identities and storing data so it can be reused across web applications. It was developed at Sir Tim Berners-Lee's lab at MIT, is incubated by the W3C Solid Community Group, and is being standardised by the W3C Linked Web Storage Working Group. The Open Data Institute is its steward.

Instead of every application keeping its own copy of your data, Solid stores it in a personal online data store, called a Pod. Applications ask for permission to read or write specific data, and the owner can grant or withdraw that permission.

Learn more: solidproject.orgW3C Linked Web Storage WGOpen Data Institute

Pod
A secure online store that belongs to a person or an organisation. It can be hosted by a provider they choose or on their own server.
WebID
A web identity used to sign in and to state who is allowed to access what.
Access control
Rules set by the owner that decide which people and applications can see or change each piece of data.
Interoperability
Different applications can work with the same data, so an organisation is not locked into one supplier.

How ADAFP will use it

The principle is simple: ADAFP tools will ask for access to data instead of collecting it.

Pods

  • Individual members and activists
  • Member parties and organisations

Permissions set by the owner

  • Granted for a purpose
  • Limited to specific data
  • Can be withdrawn at any time

Applications

  • Membership and volunteer management
  • Secure document sharing
  • ADAFP Digital Laboratory tools

Solid FPA is designed so that ADAFP never needs a central list of the individual members of its member organisations. Each organisation keeps control of its own records.

What organisations will be able to do

Keep a membership register members can see

Each member's record sits in a Pod they can view and correct, while the party holds the permissions it needs to run the organisation.

Contact people only with consent

Communication preferences are stored with the person, so consent is clear, recorded and easy to withdraw.

Share documents between organisations

Member organisations can work on joint statements, policy drafts and training materials, sharing only with the people and groups they choose.

Manage volunteers and party agents

Volunteers can carry their own profile, training record and credentials from one activity to the next instead of registering again each time.

Change tools without losing data

Because the data stays in the Pod, an organisation can switch applications or providers without rebuilding its records.

Leave cleanly

When a member leaves, access can be withdrawn and the record returned, rather than left behind in someone else's database.

Infrastructure and security

The working system will run on dedicated infrastructure, separate from ADAFP's public websites. The approach:

  • Dedicated servers for Solid FPA, isolated from other ADAFP services.
  • Open-source Solid server software, so the code can be reviewed independently.
  • Development and testing with test data only. No real personal data will be stored before an independent security review.
  • Encrypted connections, strong sign-in and only the minimum data needed for each purpose.
  • Compliance with POPIA and, where it applies, the GDPR, with a clear record of who is responsible for each dataset.
  • Training for users through the ADAFP Digital Security Unit, because a secure server does not protect a compromised phone or a reused password.

What Solid FPA will not do

No technology makes political work risk-free. Solid FPA will reduce the damage a single breach can do and give people control of their data. It will not make anyone invisible to surveillance, and it cannot protect data on devices that are already compromised. The Solid standards are also still developing, and the programme will follow them as they mature.

Roadmap

  1. Design

    Define the architecture, data models and legal framework with member organisations and technical partners.

  2. Proof of concept

    Build a first working version and test it with test data only.

  3. Pilot

    Run a pilot with a small group of member organisations, after an independent security review.

  4. Evaluation and rollout

    Publish what worked and what did not, then open the system to more organisations across the alliance.

Part of the ADAFP Digital Laboratory

The ADAFP Digital Laboratory brings together the alliance's technology work for democracy.

ai.adafp.org

AI Unit

AI tools for research, drafting and translation, used by member organisations under the ADAFP AI Ethics Charter.

Visit the AI Unit
You are here

Solid FPA

Data sovereignty for political organisations and their members.

In preparation

Digital Security Unit

Online security training for members, activists and staff.

Get involved

We are looking for member organisations interested in taking part in the pilot, and for universities, technical partners and funders who share the goal of democratic data sovereignty.

Email the programme

solid@adafp.org