Published April 23, 20266 min read

A European Career Profile: What Control Over Professional Data Really Means

EU hosting alone does not create data sovereignty. Purpose limitation, explicit approvals, portability, and honest incentives matter too.

Do not confuse “European” with “under your control”

A service can run in Europe and still collect as much data as possible, measure user behaviour, or push profiles into a commercial visibility model. Conversely, even a restrained service remains external infrastructure that receives professional data.

A useful assessment therefore starts with purpose and boundaries.

Five questions to ask of a career profile

1. What is the data used for?

Professional facts should generate the profile, PDF, and export. They should not quietly become material for audience segmentation, advertising, or sale to third parties.

2. Who decides what becomes public?

An initial agent sync is not permission to publish. A new person.work Career Record stays private until its owner deliberately releases it.

3. What may the agent do?

OAuth does not simply authenticate “an AI”. It authorises a client to perform narrowly scoped actions on the owner's own account. The agent may read and propose changes. It cannot edit someone else's profile, approve its own proposals, or publish a private record.

4. Can I take the data elsewhere?

An open, machine-readable export is more than an archive file. Roles, projects, dates, optional evidence, and profession-specific extensions must remain structured so another tool can understand them.

5. What incentives does the operator have?

person.work is currently a non-commercial goodwill project. There are no plans, upgrades, advertising, or paid reach. Profile data is not sold. Operational limits are not hidden product tiers.

Data minimisation for public profiles

A public CV is visible by definition. That does not mean every piece of source material belongs in it. Private contact details, confidential project information, and internal documents must not become public simply because an agent found them in the source.

It is useful to separate the private record available to authorised tools from the deliberately published view. Confirmations should expose only the information needed to understand them.

The honest position of person.work

person.work is not a “European LinkedIn clone”. It replaces neither networking nor client acquisition. It tackles a narrower infrastructure job: maintain an existing CV with the owner's own agent as a confirmed, portable Career Record and render several outputs from it.

That limit reduces both data appetite and product pressure. It is also testable: a future feed, ranking, data sale, or paywall would break today's project philosophy rather than represent a neutral feature.

Frequently asked questions

Is EU hosting enough for a privacy-conscious career profile?

No. Data minimisation, clear purposes, controlled publishing, deletion and export options, and whether profile data is sold or used for advertising matter as well.

Does person.work sell profile data?

No. person.work is a non-commercial goodwill project without advertising, paid visibility, or the sale of profile data.

Is a new Career Record public immediately?

No. A record created or synchronised through MCP stays private until its owner deliberately publishes it.

Maintain your existing CV with the agent you already use.

person.work stores your confirmed Career Record facts and renders web, PDF, and JSON from them. Non-commercial, with no feed and no sale of profile data.

Connect agent