Your Data Isn't the Asset. The Inference Is.

Consent governs what gets collected. Value is captured at what gets inferred — and three CJEU rulings plus a €200M DMA fine show Europe's institutions already know.

Your Data Isn't the Asset. The Inference Is.
The keyhole never got bigger. What's on the other side learned to see through it.

6.3 billion people, 79% of the world's population, now live under a national data protection law. Almost none of those laws govern the thing that now carries the value: not the data a person hands over, but what a system infers from it afterwards.

That gap is the privacy story of this decade. I write this from a European vantage point because the problem is clearest here: the GDPR turned privacy into a serious regulatory regime. It did so around a model in which the risk lived at collection: tell people what you take, get their consent, and the rest follows. The economics of data have moved on. The consent screen has not.

The record is no longer the unit

The commercial web was built on identifiers. The cookie made tracking possible, the tracker made targeting possible, and for two decades the privacy debate was a debate about disclosure: what is collected, for how long, with whose permission.

An AI stack does not need your record. It needs enough of everyone's fragments to predict what your record would have said. Location traces, purchase patterns, device signals and browsing rhythms that looked harmless individually become, in combination, a profile nobody disclosed — health, finances, orientation, politics, risk. Remove the name and the email address, and the prediction still works. The privacy problem has not been solved; it has been displaced downstream of the point where the law looks.

The economic unit is no longer the record. It is the prediction.

This is why consent is an incomplete control rather than a wrong one. Consent can authorise a collection. It cannot govern the open-ended set of conclusions a model will later draw from that collection, combined with a thousand others. Once inference is the asset, whoever owns the pipeline owns the asymmetry — and asymmetry, not data volume, is what gets monetised.

Diagram contrasting the old privacy model, risk from data you consciously share, with the new model, risk from what AI infers about you.
Consent sits on the left. Value sits on the right.

Europe's courts saw it first

The interesting thing is that the Court of Justice of the EU has already accepted this logic. In three rulings, the court moved the regulated object from the record to the inference, while most compliance programmes stayed where they were.

Stylised human figure assembled from network nodes, with data streams flowing in from a classical institutional building on one side and decision arrows on the other.
A name, a pharmacy order, a score: none of it is sensitive data until something deduces from it.

In OT (August 2022), a Lithuanian official was required to publish the name of his partner. A name is not sensitive data. The court held that because a partner's name is "liable indirectly to reveal" sexual orientation, publishing it is processing special-category data. In Lindenapotheke (October 2024), an online pharmacy's order data became health data — regardless of whether the pharmacy intended to infer anything, and regardless of whether the inference would even be correct. And in SCHUFA (December 2023), the court held that a credit reference agency's probability score is itself an automated decision under Article 22, because banks draw so heavily on it that the score is the refusal.

Read together, the line is unmistakable. The court treats what can be deduced as the thing the law protects; the compliance industry still treats what was collected as the thing it documents. The gap between those two positions is where a great deal of European data processing currently sits — technically consented, legally exposed.

Privacy is competition policy now

The second shift is institutional, and it matters more for anyone who runs a company than the case law does.

In Meta v Bundeskartellamt (July 2023), the CJEU confirmed that a competition authority may assess GDPR compliance as part of an abuse-of-dominance case, and that a dominant platform's market position bears on whether a user's consent was freely given at all. Two years later the theory became a fine. On 23 April 2025 the European Commission fined Meta €200 million under the Digital Markets Act — not for collecting data, but for combining it across services without a genuine alternative. The "consent or pay" model was the first gatekeeper conduct the DMA punished.

Look at what was sanctioned. The DMA did not fine the collection. It fined the combination — the step where fragments become inference. That is a competition regulator treating the inference stack as a source of market power, which is exactly what it is: whoever holds the richest behavioural graph, the strongest model and the most permissive retention regime can shape prices, access and entry for everyone else. Privacy is not adjacent to market structure. It is one of the mechanisms through which market structure is built.

A firm that turns fragments into inference is no longer selling a service. It is selling information asymmetry.

What this means if you buy software

For an operator, the practical consequence is that the privacy notice has become the least important document in the stack, and the contract the most important one. Three things worth insisting on before signing.

  • Separate collection rights from use rights. A vendor can be allowed to process a narrow set of inputs without being allowed to repurpose them for profiling, model training or enrichment. That distinction belongs in the agreement, not in a policy page the vendor can rewrite.
  • Treat "we anonymise" as the start of a conversation. Anonymisation addresses the record. Ask what the system can still infer once names are gone, and whether it uses aggregation, access controls or other privacy-enhancing techniques to limit linkage across datasets.
  • Treat model access as a commercial right, not a default. If a vendor can combine your data with other customers' data, you are not buying a service; you are contributing to an inference asset you will later pay to access. Decide in advance whether that is the deal.

None of this is a compliance exercise. It is bargaining power. The party that controls what can be inferred from a dataset controls the value in it — and the contract is the only place where a buyer still gets to say who that party is.

The privacy question used to be what people were willing to share. That question is settled, and it was the wrong one. The question now is who controls the inference engine, because that is where the value is captured — and, as Europe's courts and regulators are starting to say out loud, where the power is too.

If you want this kind of analysis every week, ELECTE's Newsletter covers AI, privacy, regulation, and market power from a European perspective. I focus on the structural consequences that vendor messaging tends to leave out — especially where contracts, procurement, and regulation ultimately determine who controls the system.


One housekeeping note: The ELECTE Quarterly is now live — a new print-quality journal built around one question about artificial intelligence and human judgment in each issue. The first issue is out now.

And separately: a completely rebuilt electe.net is going live very soon. More on that next.


Sources


Fabio Lauria

CEO & Founder, ELECTE

Every week, we explore AI without the hype — using data, analysis and an independent perspective.

If you found this analysis useful, please share it with someone who might be interested. And if you’d like to find out how ELECTE uses AI to automate data analysis and reporting, you can find out more at electe.net.