That's right! We also need to use Mike's new compact ZKP technique to preserve privacy. Owning our own data--such as health data a la VCI/CCI--is *not* enough. If the underlying data cannot be kept secret by using ZKP's for all transactions, then what's the point? Decentralization without maximum user privacy and user control just frees the surveillance capitalists from having to run a central database.
Privacy policy is good to have--just like laws against robbery are good to have. But cryptography is the equivilent of a pistol in my hand, leveled at the robber. Cryptography is real power.