Rough idea:
GDPR.2 as a collab between europe and w3c.
Two new concept:
* if I try to connect to a service, I provide gkr@jellycopter.net and jellycopter.net advertise a oauth2 authentication service, the service isn't allowed to ask for password or 2FA. They must jellycopter.net for my autorisation, like the connect with gmail or facebook buttons.
* the oauth2 authorisation also do asking consent for email. Answer comes with info to mark email as consensual.