Fiduciary Commons
The Fiduciary Commons proposes three foundational model statutes and companion legislation that give constitutional duties legal force. VIDA mandates citizen-controlled digital identity architecture. PDTA imposes enforceable fiduciary duties on government actors who handle personal data. GAAFA extends those duties to AI systems making decisions about citizens. Companion statutes apply the framework's architectural principles to specific problems, from automated license plate readers to commercial surveillance. Together they constitute a complete constitutional architecture for the digital state.
A fiduciary is someone entrusted to act on your behalf, legally required to put your interests ahead of their own. Your lawyer is a fiduciary. So is your doctor. So is a financial advisor who manages your retirement savings. The law treats these relationships differently from ordinary transactions because there is a fundamental power imbalance: you are vulnerable, you cannot fully monitor what they are doing, and you have no practical choice but to trust them.
Fiduciary duties are specific and enforceable. The duty of loyalty means the fiduciary cannot use your information against you or for purposes you did not authorize. The duty of care means they must handle your affairs competently. The duty of confidentiality means they cannot share what they know about you without your consent. These are not aspirations. They are legal obligations you can enforce in court. The Fiduciary Commons argues that government's relationship to citizens with respect to personal data is already a fiduciary one, and that the law should treat it as such.
Think about what happens when you interact with government over the course of a few years. You get a driver's license. You apply for a permit. You file your taxes. You enroll a child in a public school. You use a Medicaid benefit. Each of these transactions requires you to share personal information, and you have no meaningful choice about it.
Every one of those transactions feeds a database. In a modern integrated government information system, those databases talk to each other. The result is a comprehensive profile of your identity, your finances, your family structure, your health history, your property, and your movements, assembled without any court order, governed by administrative policy rather than law, and accessible to officials and contractors you will never meet. The founders knew this architecture. They called it a general warrant. They fought a revolution in part to prohibit it. The founding-era state constitutions of Massachusetts (1780), Pennsylvania (1776), and Virginia (1776) contained explicit privacy protections predating the Fourth Amendment. The Amendment itself was ratified specifically to make general warrants unconstitutional. And yet here they are, rebuilt in digital form.
The problem is not that individual officials are malicious. The problem is structural: the architecture itself creates surveillance power that no court has authorized and no law has constrained. The Fiduciary Commons argues that the remedy must be architectural as well, built into how government digital systems are designed, not promised in how officials choose to use them.
Every state that has addressed automated license plate readers has tried to limit how long police retain the data. None has asked why police need to retain it at all.
The framework's companion statute mandates query-without-collection: a scan checks a plate against active warrants, confirms or denies, and retains nothing about plates that do not match. The surveillance capability is never created.
These short presentations introduce the argument in plain language. No law degree required.
How modern government databases quietly recreate the founding-era surveillance architecture the Fourth Amendment was ratified to prohibit, and what to do about it.
Why digital identity is the load-bearing element of everything, and how citizen-controlled identity architecture changes the entire data relationship between you and government.
The fiduciary framework is not merely a theory. It is embodied in three specific draft statutes, each designed to be introduced in a state legislature. Together they constitute a complete legal architecture.
Requires that government digital identity systems be built on decentralized, citizen-controlled architecture. Prohibits centralized identity repositories. Mandates that you retain control of your own credentials.
In plain terms: when you prove who you are to a government system, the system should confirm the fact it needs, not collect and store everything about you.
Read VIDA → PDTAEstablishes citizens as the primary trustees of their own personal data. Imposes binding fiduciary duties of loyalty, care, and confidentiality on all government actors who handle that data.
In plain terms: government handles your data the way a lawyer handles client confidences. It cannot use it for unauthorized purposes, and you can sue if it does.
Read PDTA → GAAFAExtends fiduciary obligations to AI systems making decisions about citizens. Requires assessments before deployment. Establishes your right to know when an algorithm affected a decision about you, and why.
In plain terms: if a government algorithm decides you qualify for a benefit, flags you for audit, or affects your record, you have the right to know it happened and to challenge it.
Read GAAFA →The ground shifts: Chatrie's impact on data governance beyond the Fourth Amendment. The Supreme Court's 2026 decision in Chatrie v. United States categorically rejected durational thresholds for Fourth Amendment protection and described unchecked government surveillance as a "virtual panopticon." This article examines what Chatrie means for state-level data governance frameworks.
Read at IAPP →The case for constitutionally grounded AI and data architecture. Why AI governance and data governance are the same problem, and why both require constitutional grounding rather than administrative policy.
Read at StateTech →Michael G. Leahy is an attorney and former Secretary of Information Technology for the State of Maryland, where he served as the state's Chief Information Officer and a member of the Governor's Cabinet from 2017 to 2023. He oversaw a team of more than 300 staff, a technology budget exceeding $160 million, and the state's IT infrastructure, data privacy policy, and cybersecurity posture across all executive branch agencies. He served as President of NASCIO, the National Association of State Chief Information Officers, in 2021 and 2022.
The Fiduciary Commons framework is a direct product of that experience: the product of watching, from the inside, how government technology procurement systematically purchases surveillance architecture without recognizing it as such, and concluding that the remedy has to be constitutional and architectural, not merely administrative.
The Fiduciary Commons is a constitutional and legislative framework proposing that government already owes citizens fiduciary duties regarding personal data, grounded in Fourth Amendment doctrine and the public trust tradition. It includes three model statutes (VIDA, PDTA, and GAAFA) designed for introduction in state legislatures, establishing enforceable duties of loyalty, care, and confidentiality for government handling of personal data, digital identity, and algorithmic decision-making.
A fiduciary is someone entrusted to act on your behalf, legally required to put your interests ahead of their own. Your lawyer, your doctor, and your financial advisor are all fiduciaries. Government's relationship with citizens regarding personal data meets every structural condition for fiduciary obligation: citizens entrust information involuntarily, government exercises discretionary authority over that information, and citizens cannot exit the relationship or bargain for protections. The Fiduciary Commons argues that the Constitution already requires government to act as a fiduciary with respect to personal data, and that the law should enforce that requirement.
Most privacy law relies on notice-and-consent frameworks, which fail when citizens have no meaningful choice about whether to interact with government. The Fiduciary Commons replaces consent with fiduciary duty: government actors owe enforceable obligations regardless of whether citizens "agree" to data collection. The key structural difference is the private right of action, which allows citizens to enforce these duties directly in court rather than depending on agency enforcement discretion.
Utah has enacted identity-layer legislation (SB 260 and SB 275) that converges substantially with VIDA's architecture through its State-Endorsed Digital Identity (SEDI) initiative. Utah is in conversation with multiple states considering joining the SEDI Consortium. The Fiduciary Commons framework adds layers SEDI does not reach: enforceable fiduciary duties with a private right of action (PDTA) and algorithmic accountability (GAAFA).
Michael G. Leahy is the author and principal drafter. He is an attorney and former Secretary of Information Technology for the State of Maryland, where he served as CIO and a member of the Governor's Cabinet. He served as President of NASCIO, the National Association of State Chief Information Officers, in 2021 and 2022. The framework is a direct product of that experience: watching from the inside how government technology procurement systematically purchases surveillance architecture without recognizing it as such.