08

Freedom from Concentrated Power

Consumer and Digital Rights

People should be protected from fraud, unsafe products, abusive data practices, manipulative interfaces, discriminatory automated systems, and unreasonable digital surveillance.

  • Last reviewed
  • 9 minute read

Why It Matters

People now make essential decisions through systems they cannot inspect: applying for work or credit, managing health information, paying bills, learning, communicating, and proving identity. A nominal choice is not meaningful when the interface hides consequences, data collection is unavoidable, or a consequential denial offers no understandable reason.

Digital rights should protect agency without promising perfect control. They include safe products, honest interfaces, restrained data use, security, appeal, repair, and limits on both public and private surveillance appropriate to the source of power.

Historical Root

The Bill of Rights limits specified government actions, including unreasonable searches and seizures and restrictions on expression. Those constitutional constraints do not automatically govern every private data practice. Modern consumer and digital policy therefore combines constitutional doctrine, statutes, regulation, contract, competition, and proposed new duties. National Archives and Records Administration U.S. Constitution

What Exists Today

United States protections are sectoral: different rules may apply to communications, health, finance, credit, children, education, biometrics, government records, product safety, and state consumer privacy. Competition law can address some forms of lock-in or exclusion but is not a complete privacy code. Federal Trade Commission

The FTC has documented interface practices that can obscure material terms, make cancellation difficult, or steer people toward unintended disclosures. NIST’s AI Risk Management Framework offers a voluntary process for governing, mapping, measuring, and managing AI risk; it does not itself create a remedy. Federal Trade Commission National Institute of Standards and Technology

Research note: This draft is not yet a current federal-and-state privacy-law chart and does not claim that every listed practice is unlawful in every context.

Where the Gaps Are

Fragmented rules can leave similar data protected differently, make responsibility hard to locate, and require users to manage risks through unreadable notices. Consequential automated decisions may be opaque even when the underlying process is lawful. Small organizations can also face obligations they cannot operationalize without shared standards and tools.

What Success Could Look Like

Success means less unnecessary collection, fewer unsafe defaults, intelligible choices, secure products, fair cancellation, reasons and appeals for consequential decisions, and remedies proportionate to harm. Measures must include burden on users and smaller organizations, not just the number of privacy policies published.

Policy Options

Options include a general privacy floor, sector-specific protections, data minimization, security duties, algorithmic documentation, independent testing, appeal rights, right to repair, portability, interoperability, procurement standards, and limits on government surveillance.

Choices and Tradeoffs

Privacy can conflict with fraud prevention, accessibility, research, and safety; portability can increase breach risk; transparency can enable gaming; and detailed compliance can entrench incumbents. Risk-based rules should be clear enough for enforcement and flexible enough for changing technology.

Serious Objections

Skeptics warn that regulation will favor large firms and that transparency can compromise trade secrets or security. Those are design constraints. Standardized compliance, regulator access, outcome testing, user-facing reasons, and protected confidential review can produce accountability without demanding public source code.

Questions Still Open

Research must compare consent models, sensitive-data rules, children’s privacy, biometrics, automated-decision appeals, cybersecurity duties, repair, and surveillance oversight. It should separate evidence about actual behavior from claims based only on what a policy notice permits.

Measuring progress

Questions for judging success

These are outcome categories and measurable questions, not invented targets.

  • Data collection limited to clear and legitimate purposes
  • Choices and cancellations that are as usable as enrollment
  • Safety and security maintained across the product life cycle
  • Notice, explanation, and appeal for consequential automated decisions
  • Nondiscrimination tested through relevant outcomes and processes
  • Practical repair, redress, and enforcement options

Policy toolbox

Possible mechanisms

A proposed guarantee is a goal, not a synonym for one bill or program. Different levels of government and institutions can carry different parts.

Federal legislation

A general privacy floor

Define collection, use, retention, access, correction, deletion, security, and enforcement duties while preserving stronger sectoral protections.

Regulation and enforcement

Fair interfaces and cancellation

Prohibit material deception and manipulative design, require understandable terms, and make stopping a service reasonably comparable to starting it.

Default rules

Minimize data by design

Make limited collection, short retention, secure defaults, and purpose boundaries ordinary product requirements rather than expert-only settings.

Disclosure and transparency

Accountable automated decisions

Require documentation, testing, notice, human review, and appeal in consequential uses while protecting security and legitimate trade secrets.

Competition policy

Switching, portability, and repair

Reduce unjustified lock-in through interoperability, data portability, cancellation, and repair rights designed with privacy and safety safeguards.

Implementation questions

  1. Which data uses require opt-in consent and which should be prohibited regardless of consent?
  2. What automated decisions are consequential enough to require notice and appeal?
  3. How should small-organization duties scale with risk rather than revenue alone?
  4. Which government surveillance rules require warrants, minimization, reporting, or independent review?

Choices and tradeoffs

What responsible design must confront

Privacy and useful services

Strict limits can reduce surveillance and breach exposure, while some data uses support fraud prevention, accessibility, research, or personalization.

Transparency and gaming

Explanations can improve accountability, but disclosure that is too detailed may expose security controls, enable manipulation, or overwhelm users.

Portability and security

Moving data can reduce lock-in, yet weak authentication or broad export rights can increase identity theft and unauthorized disclosure.

Uniformity and experimentation

A national floor can simplify compliance, while state experimentation can reveal stronger protections and emerging harms.

Serious objections

Strong concerns deserve direct answers

Broad digital rules would entrench large firms that can afford compliance

Complex, paperwork-heavy duties can do that. Rules should focus on risk and outcomes, provide standard tools for smaller organizations, and deny exemptions where a small actor creates high-impact harm.

Algorithmic transparency will expose trade secrets and invite gaming

Accountability need not mean publishing source code. Auditable documentation, regulator access, impact testing, adverse-action reasons, and user appeal can provide scrutiny while protecting legitimate confidential information.

Research agenda

Questions still open

  • Which consent designs produce informed choice rather than box-checking fatigue?
  • How should biometric, children's, location, and inferred data receive heightened treatment?
  • Which audit methods reliably detect discriminatory automated outcomes?
  • How can product security duties remain current without freezing technical standards in statute?

Evidence

Sources

Source type, role, and limitations are shown so readers can judge what each item can—and cannot—support.

Government analysis Verified metadata

Bringing Dark Patterns to Light

Federal Trade Commission

Published
September 2022
Accessed
August 11, 2026
Role
Supporting, Critical, Contextual

A staff report describing interface practices that can obscure, subvert, or impair consumer choice, including hidden terms, difficult cancellation, and designs that steer disclosure of personal information.

Limits: The report presents enforcement and policy analysis rather than a comprehensive prevalence study, and interface practices continue to evolve.

Government analysis Verified metadata

Artificial Intelligence Risk Management Framework (AI RMF 1.0)

Elham Tabassi. National Institute of Standards and Technology

Published
January 26, 2023
Accessed
August 11, 2026
Role
Methodological, Supporting, Contextual

A voluntary, rights-preserving framework for governing, mapping, measuring, and managing risks from artificial-intelligence systems.

Limits: The framework is voluntary and non-sector-specific, is being revised, and does not by itself create legal duties or remedies.

Primary historical document Verified metadata

Constitution of the United States: Analysis and Interpretation

Congress.gov, Library of Congress

Published
Constitutional text with congressional annotations
Accessed
August 11, 2026
Role
Historical, Contextual

The constitutional text, amendments, and links to the congressionally prepared Constitution Annotated.

Limits: The constitutional text must be read with case law and doctrine; this entry is not a substitute for legal advice or a current issue-specific survey.

Primary historical document Verified metadata

The Bill of Rights

National Archives and Records Administration

Published
December 15, 1791
Accessed
August 11, 2026
Role
Historical, Contextual

The National Archives presentation and transcript of the first ten amendments to the United States Constitution.

Limits: The document's text does not by itself explain modern incorporation, remedies, or the boundary between governmental and private conduct.

Government analysis Verified metadata

Guide to Antitrust Laws

Federal Trade Commission

Published
Current agency guidance
Accessed
August 11, 2026
Role
Supporting, Contextual

An official guide to federal competition law, merger review, agreements among competitors, monopolization, and the roles of the federal antitrust agencies.

Limits: Agency guidance is general and does not resolve fact-specific liability or the empirical effects of every form of concentration.

Revision history

  1. Initial working draft separated government constitutional limits from proposed consumer and platform protections.