Least-Privilege Access: The Governance the Circular Economy Forgot
By Marco A. Bravo-Fabián — Candidate for Doctor, Universidade de Santiago de Compostela (ICEDE). ORCID 0009-0001-4372-2076.
We keep discussing the circular economy as a technology problem — better sorting, better recycling, better passports. It isn’t, mostly. The recurring bottleneck is a governance problem hiding in plain sight: who is allowed to read and write which data about an object, at which point in its life. Get that wrong and no amount of technology helps.
The circular economy runs on data nobody can safely share
A repairer needs to know how a product is built. A reseller needs to prove it’s authentic. A recycler needs its material composition. Each of these actors needs real, specific data about the object — and each is, from the manufacturer’s point of view, an outsider, sometimes a competitor. So the data stays locked up, and circularity stalls not because the recycling technology is missing but because the information to use it never arrives at the right hands.
The instinct to lock everything down is understandable and self-defeating. The instinct to open everything up is naive and dangerous. Both are the wrong frame.
Least privilege is the missing frame
Security engineering solved a version of this problem decades ago, and the principle it arrived at is exactly what the circular economy needs: least privilege — give each party the minimum access required to do its job, and no more. Applied to a product’s passport, that means a layered model. The public sees what establishes trust. The owner sees a private layer bound to their unit. Verified circular-economy actors — repairers, remanufacturers, resellers, recyclers — each get a role-scoped view of exactly the fields their work requires, plus the right to write the events they perform.
This is not a privacy compromise grafted onto an open system. It is what makes the system possible at all. Least privilege is precisely the mechanism that lets a manufacturer expose enough for the ecosystem to function without exposing everything to everyone.
Why this is governance, not features
I’ve argued in peer-reviewed work that the digital product passport is best understood as a data-governance infrastructure (Bravo-Fabián, López-Pérez & Vence, 2026, Journal of Cleaner Production, doi.org/10.1016/j.jclepro.2026.148875). The word that matters there is governance. Standards define the format of the data; governance defines who may touch it and under what conditions. The EU Data Act is essentially a governance instrument — it legislates access and portability rights. A passport that ignores least privilege can be perfectly standards-compliant and still fail, because it answers the format question and dodges the access question.
The circular economy is an access-control problem
If there is one reframe I would offer to anyone building for circularity, it is this: stop treating the hard part as sorting and shredding, and start treating it as access control. The technical layers — resolvers, credentials, open event standards — are increasingly available and increasingly boring. What remains genuinely hard, and genuinely valuable, is deciding who gets to see and do what, and enforcing it by design. That is the governance the circular economy forgot, and it is where the next decade of real progress will come from.
Designing access for a circular product?
Least-privilege data governance is where circular models succeed or stall. Let’s talk.
