“Many people say data is the new oil—the oil of the twenty-first century. . . .
If data is the new oil, then data protection is the new pollution control.”

We live in a data-centric world. From our Cyber Monday purchases to the political pages we follow on social media, nearly everything we do online may be logged by firms that have a monetary interest in our data. This generally is not a bad thing. The standard ad-based business model provides access to internet services for many people who otherwise would not (or could not) participate in subscription-based models. And most of the data collected—as well as the manner in which they are used—are often unobjectionable to even the more private Internet users; this is especially true when firms only use data for their own purposes.

Yet concerns obviously arise when these data are accessed by other firms absent users’ consent: like when Facebook’s policies led to the disclosure of nearly 87 million users’ personal data to political consultancy Cambridge Analytica ahead of the 2016 U.S. presidential election.[2] Or when Facebook data are unlawfully accessed by third parties, as the most recent Facebook breach demonstrates.[3] In these cases, users trusted Facebook with their data, and users were let down.[4] Given the uncertainty of whether Facebook (and other similar companies) will actually be held accountable for data disclosures like these, a thoughtful review of the patchwork of American laws governing data privacy is certainly in order.[5]

But even if Congress were to comprehensively reform this country’s data privacy laws, such reform alone may be inadequate to safeguard Americans’ rights to data privacy. Like atmospheric pollution, personal data have a distinct capacity to evade the confines of national borders.[6] Domestic laws are therefore often inadequate. An international legal regime that establishes a set of fundamental principles, on which both consumers and data firms (or at least some of them) can agree, may come closer to solving the problem.

The General Data Protection Regulation

The European approach is instructive. Through the General Data Protection Regulation (GDPR), which took effect this past May, the European Union cemented personal data protection as a “fundamental right” for all within the Union.[7] The GDPR broadly defines “personal data” as “any information relating to an identified or identifiable natural person . . . .”[8] It places strict requirements on the collection, processing, and security of personal data entrusted to vendors.[9] And it has a remarkably international reach—even well beyond the European Union.[10]

At bottom, the GDPR recognizes that “personal data belongs to the person.”[11] Its underlying principles for data processing are implemented by empowering consumers with greater control over their data and by imposing robust consent requirements on firms regarding the use of personal data.[12] The GDPR gives consumers the right to access data held by any firm at any time[13] and to demand that any firm rectifies inaccurate or incomplete data to fit the specified purposes for which the data were collected.[14] Consumers also are granted a “right to be forgotten,” through which they can request that all their personal data held by a firm be wholly erased “without undue delay,” under certain circumstances.[15]

Further, the GDPR imposes requirements on firms relying only on the consent provided by consumers to access their data.[16] Any firm’s request for consent must be in “clear and plain language” and “presented in a manner that is clearly distinguishable” from other matters.[17] Consumers also have the right to withdraw consent at any time, and “it shall be as easy to withdraw as to give consent.”[18] Finally, the firm must be able to demonstrate that the consumer in fact consented to the data collection and processing.[19]

In short, the effect of the GDPR is to standardize the rules of the game for handling personal data. Although perhaps not perfect,[20] the GDPR serves as an instructive model for comprehensive reform of international data privacy laws.

Moving Forward: Prioritizing Consent

As breaches like the ones affecting Facebook in the last year highlight, the data privacy protections available under American law is complicated, incomplete, and unclear at best.[21] The forms of legal recourse currently available in the United States[22] are limited in that they often may fail to provide sufficient incentives to deter the unlawful disclosure of personal data.[23] In short, these remedies are often retrospective in nature. But a policy fix that is prospective in nature, like one that places more robust requirements on firms collecting data through users’ “consent,”[24] may be appropriate.

But as alluded to above, a purely domestic approach may be inadequate. Data easily flows across borders (and may even be stored on servers located abroad—which itself makes enforcement of domestic privacy regulations complicated).[25] Instead, an international regime would be ideal.

While there are no uncomplicated solutions to the problem presented here, a more direct approach may be preferable. The United States could, for instance, enter into a treaty with the European Union, adopting the GDPR’s consent requirements (and the corresponding responsibilities that are imposed on firms). In so doing, firms attempting to collect Americans’ personal data per their consent would have to ensure that the user’s consent is informed and presented separately from any consent request for collecting other information.[26]

This would mean that instead of tucking notices of data collection away in rarely read privacy policies or terms of service agreements, firms would have to ensure that their consumers in fact know which of their data are being collected by the firm. This emphasis on a more informed consent standard would certainly represent a step in the right direction for protecting consumers’ privacy online.

And to the extent that some of the GDPR’s more innovation-stifling requirements may be met with opposition from American business leaders (for example, the 72-hour breach notification requirement[27] and the requirement to obtain prior-authorization before processing data in new ways[28]), these provisions could be omitted from this first-step solution.

Not only is prioritizing consent a user-friendly policy, it is also one that many American businesses (particularly those interacting with European consumers, but also some others) are already implementing to comply with the GDPR.[29] A consent treaty between the United States and the European Union may also have the added benefit of simplifying existing cross-Atlantic data agreements,[30] although the precise implications obviously would depend on the agreement ultimately enacted.


While it is impossible to adequately discuss a topic as complex as data privacy in a single blog post, the preceding attempts at least to flag the issues most relevant to protecting Americans’ privacy rights online. And while there are countless solutions available, policy makers should prioritize reforming consent standards. Although this would likely not be the only long-term reform needed, it would be a good first step—and would have the primary (and much needed) effect of providing more clear and effective data privacy protections to millions of Americans.

