News

How Gen Z Thinks About Identity Data

Moca Network
August 4, 2026

Takeaway: Gen Z is not careless about privacy. They are more willing to share data when the value exchange is clear — because they increasingly expect property rights over their identity data.

For years, the shorthand has been simple: Gen Z is the “privacy generation.” They grew up with data breaches in the headlines, cookie banners on every site, and constant debate about surveillance. So it is easy to assume they must be the most protective, locked-down generation online.

The data tells a more interesting story. And understanding it matters for anyone building products, writing policy, or trying to earn the trust of the largest consumer cohort of the next decade.

The Paradox: Gen Z Shares the Most and Guards the Most

Start with the numbers that seem to contradict each other:

  • Around 88% of Gen Z say they are willing to share some personal data with social platforms, compared with roughly 67% of older adults.
  • They rate their willingness to trade data for a better experience about 15% higher than non-Gen Z.
  • Yet they are more protective of their identity than the generation directly above them: 38% of Gen Z worry about protecting their identity online, versus 29% of Millennials.

At first glance, this looks like hypocrisy. The generation most willing to hand over data is also the one most concerned about its identity?

Careless and careful at the same time?

The resolution is that these are not opposites for Gen Z. They are two settings on the same dial.

Privacy Is a Dynamic Spectrum

The mental model that makes Gen Z behavior easier to understand is this: privacy is a dynamic spectrum.

Gen Z shares when the benefit is clear. They revoke access, abandon platforms, or change behavior when a platform oversteps.

Privacy, for this generation, is not a fixed wall between “public” and “private.” It is a dial they adjust constantly, depending on what they get in return and how much they trust the other side.

That reframing explains a lot:

  • They do not fear data collection in the abstract. They fear losing control of it.
  • They will trade data for personalization, but expect the ability to take it back.
  • Trust is conditional, not granted once and forgotten.

In other words, the willingness to share is not the absence of standards. It is a transaction with terms attached. Break the terms, and the same user who onboarded in seconds may delete the app just as fast.

What This Signals to Product Teams and Regulators

Gen Z wants data control that is convenient, adaptable, and ongoing. That is a signal worth reading carefully.

Most of today's privacy machinery was designed for a different mindset. Cookie banners, 40-page consent forms, and all-or-nothing “accept terms” buttons assume privacy is a one-time gate users pass through.

Gen Z behaves as if privacy is an ongoing negotiation. They want to grant, adjust, and withdraw permission over time, with clarity about what they are giving and what they get.

Static consent models are increasingly out of step with how the largest emerging consumer group wants to manage digital life.

From Privacy to Ownership

Gen Z is not only asking for more privacy. They are asking for ownership.

They want the right to carry their identity across platforms, prove what needs proving, share what they choose to share, and keep it intact when they leave.

Less “hide my data.” More “this is mine, and I decide who uses it and when.”

That is not a privacy demand in the traditional sense. It is closer to a property-rights demand: treat identity and data as something the user owns, not something platforms borrow by default.

What This Means for the Next Identity Layer

If ownership is the real ask, the infrastructure underneath has to change. The next identity layer needs to let platforms:

  • Verify a user without hoarding raw data.
  • Personalize an experience without taking custody of the underlying information.
  • Let people prove things about themselves without handing over the original file.

This is the thinking behind AIR³, Moca Network's privacy-preserving identity infrastructure. Users own their credentials, and platforms verify against them without absorbing the liability of storing sensitive personal data.

Prove “over 18” without revealing a birth date. Confirm eligibility without exposing the document behind it.

The generation that gives away data most freely may be the first to demand that they own it. The open question is who is building for that shift — and who is still printing consent forms.

Sources: figures drawn from research by Oliver Wyman Forum, Cisco, the Center for Generational Kinetics, and Gallup.

Related reading

More from AIR: AIR Identity and communities and fandom, or browse the full AIR blog.

Partner with AIR

AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.

Partner with us to grow your business.

AIR is built by Moca Network, the identity network of Animoca Brands.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
UAE and APAC identity verification rules by market. AIR blog key visual
News
UAE and APAC Digital Identity Verification Requirements: A Market-by-Market Guide for 2026
UAE and APAC identity verification rules for fintech and crypto firms: CBUAE, VARA, ADGM, MAS, HKMA, RBI, Korea and MASAK, compared market by market for 2026.
European Union flags outside an EU institution building in Brussels
News
How Zero-Knowledge Proofs Work for KYC, and What GDPR Still Requires
How zero-knowledge proofs work for KYC: issuers, predicate proofs, revocation and nullifiers, plus what GDPR and AML record-keeping rules still require.
Smartphone showing an approved identity credential beside a passport and bank cards
News
What Is Reusable KYC? How Reusable Identity Credentials Work
Reusable KYC lets a business accept proof of a check a customer already passed elsewhere. How it works, who offers it, and what FATF reliance rules require.