The alternative I've been leaning toward increasingly is to have user-controls-data as the model. Rather than pop up to a particular vendor, supply auth tokens, and have them pull up
their information on
you, you show up,
they provide their tokens, and you provide your information (in their formats).
Combine this with a strong regime prohibiting inter-enterprise transfers of personal data. So that if Firm A want to talk to Firm B about User X, Firm A submits User X the request, Firm B confirms, and User X either complies or doesn't.
This would ... change certain dynamics of use of personal data.
Avoiding data loss: mumble, mumble something PKI key escrow trusted parties distributed encrypted data. Some form of personal data server as data origin, with re-shares distributed around social infrastructure. It may be a pipe dream, but at the very least it's a different model for considering pervasive data. If the user's Personal Data Stick or Home Server Box is destroyed in fire (or stolen or the cat eats it, or ...), then they and a trusted set of key escrow holders if necessary can reconstruct the data from shards spread amongs some n other systems, no one of which could individually reconstruct the whole.
"Services" in this model would be applications distributed out to operate on the user's own data directly.
Among other implications, the concept of coming up with a common base universal data format seems like a possible outcome. That could still be modified for individual service use, but the transforms would still have to map back to the core.