

Demand comprehensive federal privacy laws for Americans
The Issue
To the United States Congress and the President of the United States:
TL;DR
The United States is one of the world's leading technology powers, yet Americans still do not have one comprehensive federal privacy law giving everyone meaningful and enforceable control over personal information.
That is becoming increasingly difficult to justify.
Europe has the General Data Protection Regulation, commonly known as the GDPR.
Canada has the Personal Information Protection and Electronic Documents Act, or PIPEDA.
South Africa has the Protection of Personal Information Act, or POPIA.
China has the Personal Information Protection Law, or PIPL.
These laws are not identical. They exist under very different legal systems, provide different rights, contain different exceptions, and should not all be treated as equally protective of civil liberties.
But they demonstrate something important:
Countries around the world have recognized that modern digital economies need comprehensive national rules governing how companies collect, process, retain, disclose, and protect personal information.
The United States still has a patchwork.
That should embarrass us.
It is especially ironic when American politicians repeatedly warn us that we must protect Americans' data from China.
That concern can be legitimate.
But China itself has enacted a nationwide private-sector personal information law that includes requirements involving data minimization, defined purposes, retention, transparency, consent, and individual rights, while the United States still lacks a comprehensive federal equivalent applying broadly to Americans.
To be absolutely clear, this does not mean China should be treated as a model for protection from government surveillance or as equivalent to American constitutional civil liberties.
That is not the point.
The point is much simpler:
If American politicians believe enormous collections of personal information become a national-security threat when China might obtain them, then perhaps we should stop allowing enormous amounts of unnecessary personal information to be collected, retained, aggregated, and traded in the first place.
Data minimization is not only privacy.
Data minimization is cybersecurity.
Data minimization can also be national security.
Congress should establish a strong national right to privacy drawing lessons from GDPR, PIPEDA, POPIA, PIPL, American state privacy laws, cybersecurity principles, and other frameworks around the world.
Americans should have the right to know what organizations know about us, access that information, correct it, delete it when there is no legitimate reason to retain it, move it between services where practical, and opt out of unnecessary sale, sharing, tracking, and profiling.
Organizations should be required to minimize collection, clearly explain why information is collected, limit how long it is retained, appropriately protect it, and face meaningful consequences when they knowingly violate our rights.
Sensitive information such as precise location, health data, biometrics, financial information, private communications, authentication information, and information about children should receive stronger protection.
Data brokers should not be allowed to quietly build detailed dossiers on Americans while forcing each person to hunt through hundreds of obscure opt-out systems.
Government agencies should not be able to purchase sensitive commercial data simply to bypass legal protections that would otherwise apply.
Artificial intelligence should not become an excuse to collect everything forever.
Employees should not lose all privacy rights when they clock in.
Bystanders should not lose their privacy because somebody standing next to them purchased smart glasses or another recording device.
Strong encryption and private communications should remain protected.
Federal legislation should establish a strong national floor without erasing stronger protections states have already enacted.
And this is not theoretical to me.
I work professionally in cybersecurity, and when I have meaningful choices about where to locate some of my own infrastructure or which cloud regions and providers to use, I often prefer European options partly because I want to operate in an environment governed by comprehensive privacy rules such as the GDPR.
I am an American working in American cybersecurity.
I should not have to look across the Atlantic for the kind of comprehensive privacy environment I wish existed at home.
This petition is not anti-technology.
It is about making America better at technology.
Real technological leadership is not simply inventing something first.
Real technological leadership also means understanding the risks created by that technology and building the legal, security, and engineering frameworks necessary to use it responsibly.
If excessive data collection is dangerous when TikTok does it, then the same behavior should be regulated when Meta, Google, Apple, Microsoft, an advertising network, a data broker, an AI company, an employer, a vehicle manufacturer, a smart-device manufacturer, or anyone else does it.
If the behavior is dangerous, regulate the behavior.
If the data is sensitive, protect the data.
If Americans deserve privacy from one company, we deserve privacy from all of them.
Privacy is not secrecy.
Privacy is control.
THE MOMENT THAT MADE THIS IMPOSSIBLE FOR ME TO IGNORE
The moment that really crystallized this issue for me was watching the United States debate banning TikTok over privacy and data collection.
Again and again, I heard politicians warn that it was dangerous for a company to collect enormous amounts of information about Americans.
And I kept thinking:
If collecting this much information about people is dangerous, why are we only talking about one app?
Why should the rules change depending on whether the logo belongs to a Chinese company, an American company, an advertising network, a smart television manufacturer, a data broker, a vehicle manufacturer, or a social-media platform?
If the behavior is dangerous, regulate the behavior.
If the data is sensitive, protect the data.
If Americans deserve privacy from one company, we deserve privacy from all of them.
National-security concerns involving foreign governments may justify additional narrowly tailored restrictions.
That is a separate issue.
But banning one application does not create a right to privacy.
It does not stop another company from collecting the same categories of information.
It does not stop data brokers from creating detailed profiles.
It does not establish deletion rights.
It does not establish data-minimization requirements.
It does not establish reasonable retention limits.
It does not give Americans a universal right to know who has their information.
It does not protect Americans from whatever application becomes popular next.
Stop playing whack-a-mole with individual companies.
Regulate the data.
Regulate the behavior.
Give the individual rights.
AMERICA IS FALLING BEHIND IN PRIVACY GOVERNANCE
This is not merely a comparison between the United States and Europe.
The privacy debate has become global because the technology creating the problem is global.
Europe has the GDPR.
Canada has PIPEDA.
South Africa has POPIA.
China has PIPL.
Other countries and jurisdictions have adopted their own comprehensive privacy and data-protection frameworks.
These laws are not interchangeable.
They do not all provide identical rights.
They do not all operate under democratic constitutional systems.
They should not all be copied.
But they show that countries with drastically different politics, economies, cultures, and legal traditions have reached a similar conclusion:
Personal information cannot simply exist in a legal free-for-all.
Modern economies built around enormous amounts of data need rules.
They need transparency.
They need limits.
They need security.
They need accountability.
They need enforceable rights.
The United States is home to some of the most powerful technology companies, cloud platforms, artificial-intelligence companies, advertising systems, social networks, data brokers, software companies, and digital infrastructure on Earth.
Yet our legal framework for personal information remains fragmented.
That is not technological leadership.
America is extraordinarily good at inventing technology.
We have been much worse at updating laws quickly enough to address the risks created by that technology.
Innovation without risk management is not leadership.
It is technical debt at the scale of a country.
CHINA SHOULD NOT BE ABLE TO EMBARRASS US ON PRIVATE-SECTOR DATA MINIMIZATION
There is an extraordinary irony in the American privacy debate.
American politicians repeatedly tell Americans that we should fear China obtaining our personal information.
Again, national-security concerns involving China can absolutely be legitimate.
But consider the contradiction.
China enacted the Personal Information Protection Law, commonly known as PIPL.
Among other requirements, that framework imposes rules concerning defined and reasonable purposes, collection limited to what is necessary, restrictions on excessive collection, retention, transparency, consent, certain automated decisions, and individual rights.
Meanwhile, the United States still does not provide every American with an equivalent comprehensive federal privacy baseline applying broadly across the private sector.
Think about how absurd that sounds.
American politicians tell us that China getting too much data about Americans is dangerous.
Yet our own country still allows a sprawling commercial ecosystem to collect, aggregate, retain, infer from, buy, and sell enormous quantities of information about Americans without one comprehensive federal law establishing uniform rights.
China should not be able to look at the United States and effectively say:
Even we decided companies need nationwide rules limiting personal information collection. Why haven't you?
That should bother Congress.
That should embarrass Congress.
To be absolutely clear, this is not praise for Chinese government surveillance.
PIPL does not mean China's political system provides the same privacy protections Americans should expect from a democratic constitutional government.
That is not the argument.
The argument is that even a country American politicians repeatedly identify as a serious surveillance and data-security concern recognized that private companies need nationwide legal rules governing personal information.
The United States still has not done the equivalent comprehensively at the federal level.
If China obtaining Americans' information is a national-security concern, then Congress should recognize an obvious defensive measure:
Collect less unnecessary information in the first place.
Retain less unnecessary information.
Allow fewer unnecessary transfers.
Restrict unnecessary aggregation.
Give Americans meaningful control over what companies know about us.
You cannot steal a database that was never created.
You cannot purchase information that was never collected.
You cannot leak information that was deleted years ago.
Data minimization is privacy.
Data minimization is cybersecurity.
And in some circumstances, data minimization is national security.
I SHOULD NOT HAVE TO LOOK TO EUROPE FOR STRONGER PRIVACY EXPECTATIONS
This affects decisions I make personally.
I work professionally in cybersecurity.
I operate infrastructure.
I use cloud services.
I understand that simply placing a server inside Europe does not magically guarantee that every activity involving it becomes protected by the GDPR.
Privacy law is more complicated than geography alone.
But when I have a meaningful choice about where to locate some infrastructure, which cloud region to use, or which providers I want to trust, I often prefer European options partly because I value operating in an environment where comprehensive privacy regulation exists.
Think about what that says.
I am an American working professionally in cybersecurity, yet I sometimes look outside my own country for the stronger privacy environment I wish existed here.
I should not have to do that.
American infrastructure should be able to compete on privacy.
American cloud providers should operate under clear privacy expectations.
American technology companies should be able to tell customers that strong privacy protections are a feature of doing business in the United States.
Choosing American infrastructure should not inherently mean accepting weaker national privacy expectations.
If anything, America should be establishing the standard the rest of the world wants to follow.
IMAGINE IF THE PHYSICAL WORLD WORKED LIKE THE DIGITAL WORLD
Imagine walking down the street and discovering that companies you have never heard of are following you.
They record which stores you enter.
They record how long you stay.
They record what products you stop to examine.
They record who you are standing beside.
They notice when you visit a doctor.
They know which religious institution you attend.
They can see which political events you visit.
They track where you work.
They know where you sleep.
They record where you travel.
They record what you buy.
Then those companies combine their records with information purchased from other companies, build detailed profiles about you, infer things you never explicitly told them, and sell or share access to those profiles with organizations you have never knowingly interacted with.
Most Americans would find that horrifying if someone physically followed them around with a clipboard.
Yet versions of this happen every day in the digital world.
Websites, applications, advertising networks, data brokers, connected vehicles, televisions, social networks, wearables, location services, smart devices, and countless other systems can generate extraordinary amounts of information about our lives.
People often have little practical understanding of who ultimately receives that information, how long it remains stored, what conclusions are drawn from it, how it is combined with other information, or what somebody may decide to use it for years later.
Technology has dramatically shifted the balance of power between individuals and organizations capable of collecting information about them.
Our laws need to restore some of that balance.
PRIVACY SHOULD BE A RIGHT, NOT A PREMIUM FEATURE
I am not anti-technology.
I am not anti-cloud.
I am not anti-AI.
I am not anti-advertising.
I am not demanding that organizations stop processing information genuinely necessary to provide products and services people deliberately request.
My career depends on technology.
I regularly work with cloud infrastructure, security products, logs, telemetry, access controls, automation, and systems that legitimately need information to function.
That experience is exactly why I believe America desperately needs comprehensive privacy legislation.
Cybersecurity teaches one of the simplest lessons imaginable:
Data you never collect cannot be stolen from you.
Data you delete cannot be breached five years later.
Access that is never granted cannot be abused.
In cybersecurity, we preach least privilege.
People and systems should receive only the access reasonably necessary to perform their function.
We should apply the same principle to personal information.
Call it least privilege for data.
A company should collect what it reasonably needs to provide the product or service I requested, use it for clearly identified purposes, protect it while it has it, and delete it when it no longer has a legitimate reason to retain it.
It should not be considered normal for every application, website, television, vehicle, wearable, social network, advertising company, data broker, employer, or AI company to collect as much information as technically possible simply because storage is inexpensive and somebody might discover a way to monetize it later.
America does not need to copy GDPR.
America does not need to copy PIPEDA.
America does not need to copy POPIA.
America certainly does not need to copy PIPL wholesale.
We should learn from all of them.
Take what works.
Reject what does not.
Combine those lessons with American constitutional principles, cybersecurity engineering, state privacy laws, consumer protection, and technological expertise.
Then build something better.
AMERICA'S PATCHWORK IS NOT ENOUGH
The United States does have privacy protections.
Medical information has certain protections.
Financial information has certain protections.
Children's information has certain protections.
Some communications have legal protections.
Some states have enacted broader consumer privacy laws.
The Federal Trade Commission can pursue certain deceptive or unfair practices.
But these protections are fragmented across industries, categories of information, states, regulators, contractual terms, privacy policies, and specific circumstances.
What America still lacks is one comprehensive federal baseline providing meaningful privacy rights to everyone.
Some Americans receive stronger protections because of where they live.
Others receive fewer.
That is not a reasonable way to handle something as fundamental as control over personal information.
Your basic rights over your digital life should not depend on which side of a state line you happen to live on.
An American living in Ohio should not inherently deserve less privacy than someone living in California.
A person should not need a law degree to determine whether they have the right to ask a company what information it holds about them.
Businesses also have a legitimate interest in understandable national rules rather than navigating an increasingly complicated collection of inconsistent requirements.
A comprehensive federal law can establish consistent definitions, rights, interfaces, security expectations, and compliance requirements.
But that national law should establish a strong minimum.
It should not become an excuse to erase stronger protections states have already enacted.
Federal law should raise the floor.
It should not lower the ceiling.
AMERICANS SHOULD KNOW WHAT COMPANIES KNOW ABOUT US
A person should have the right to ask an organization:
What information do you have about me?
And receive a meaningful answer.
Not a 75-page privacy policy.
Not vague categories such as "information from our partners."
Not an intentionally difficult portal designed to make people give up.
Tell me what information you possess.
Tell me where it came from.
Tell me what you inferred from it.
Tell me why you use it.
Tell me who receives it.
Tell me how long you intend to keep it.
Tell me which data brokers or third parties supplied information about me.
Tell me whether my information is materially being used to train, fine-tune, evaluate, or otherwise improve an AI system.
Tell me whether my information is being used for profiling or consequential automated decision-making.
If a company can build a detailed profile about me, I should have the right to see that profile.
THE RIGHT TO DELETE SHOULD ACTUALLY MEAN DELETE
There should be a strong federal right to deletion.
If I close an account and a company no longer has a legitimate legal, security, fraud-prevention, contractual, financial, or operational reason to maintain my personal information, I should be able to tell them:
Delete it.
There obviously need to be reasonable exceptions.
Records required for legal obligations, litigation, fraud prevention, cybersecurity investigations, financial recordkeeping, public records, legitimate journalism, and clearly defined public-interest purposes may need to be retained.
Backups may require technically reasonable deletion schedules rather than instantaneous removal.
But "we might figure out how to monetize this someday" should not qualify as a legitimate reason to retain someone's personal life indefinitely.
Where appropriate, deletion requests should also propagate to processors and applicable third parties that received the information from the organization.
CONSENT SHOULD ACTUALLY MEAN CONSENT
We need to stop pretending that clicking "I Agree" to a massive contract written by attorneys constitutes meaningful consent to everything a company might ever invent.
Consent should be specific.
Consent should be informed.
Consent should be freely given.
Consent should be understandable.
Consent should be revocable.
And withdrawing optional consent should be approximately as easy as giving it.
If an application needs my location to show nearby restaurants, that does not automatically mean it should receive unlimited permission to retain my location history for ten years, combine it with my browsing history, sell it to data brokers, infer sensitive characteristics about me, and feed it into future machine-learning systems.
Those are different purposes.
They should be treated as different decisions.
We also need rules against deceptive privacy interfaces and dark patterns.
Rejecting optional tracking should not require fourteen clicks when accepting it requires one.
Turning off targeted advertising should not mysteriously turn itself back on.
Closing an account should not require hunting through support pages for half an hour.
Privacy controls should be understandable to normal human beings.
SENSITIVE INFORMATION DESERVES STRONGER PROTECTION
Some information can cause extraordinary harm if abused.
Precise geolocation can reveal where you sleep, where you work, which doctor you visit, which religious institution you attend, which political events you participate in, who you spend time with, and where your children go.
Health information can expose some of the most intimate details of a person's life.
Biometrics can be extraordinarily difficult or impossible to replace once compromised.
Private communications can expose relationships, finances, medical concerns, legal matters, political activity, and personal struggles.
Federal law should establish stronger protections for categories including precise geolocation, health and medical information, biometric identifiers, facial-recognition data, voiceprints, genetic information, financial information, government identification numbers, private communications, authentication credentials, information about minors, and information capable of revealing highly sensitive characteristics or activities.
Your location history is not merely "marketing data."
It can become a map of your life.
Sensitive information should generally require stronger justification, stricter safeguards, shorter retention periods, and affirmative permission for unnecessary secondary uses.
REIN IN DATA BROKERS
Data brokers demonstrate why America's current consent model is fundamentally broken.
Most Americans have never knowingly opened an account with many of the companies buying and selling information about them.
You cannot meaningfully consent to a relationship you do not even know exists.
Federal legislation should create meaningful data-broker transparency.
Americans should be able to determine which registered data brokers possess information about them, what categories of information those companies process, where that information comes from, what it is used for, and how it is shared.
There should also be a practical national mechanism allowing people to tell covered data brokers:
Do not sell or share my personal information.
Delete information you do not have a legitimate legal reason to retain.
Americans should not have to identify hundreds of obscure companies individually, navigate hundreds of different opt-out forms, hand over additional personal information simply to prove our identities, and repeat the process over and over again.
The burden should be on the companies profiting from our information.
It should not be on the people being profiled.
DO NOT LET GOVERNMENT PURCHASES BECOME A SURVEILLANCE LOOPHOLE
A meaningful right to privacy must address government acquisition of commercially available sensitive information too.
If law enforcement or another government agency would ordinarily need a warrant, subpoena, court order, or other legal process to compel sensitive information directly, the government should not automatically be able to sidestep those protections merely because equivalent information can be purchased from a commercial data broker.
The Constitution should not become optional because somebody added a shopping cart.
Federal law should establish clear rules for government acquisition of especially sensitive commercially available information, including precise location information, communications information, health information, biometrics, and similar categories.
Reasonable emergency and legitimate national-security exceptions can exist with appropriate safeguards and oversight.
But privacy protections should not vanish simply because surveillance has been outsourced.
THIS IS BIGGER THAN TIKTOK
If TikTok's data collection is dangerous, regulate the dangerous data collection.
If Meta does it, the same privacy rules should apply.
If Google does it, the same privacy rules should apply.
If Apple does it, the same privacy rules should apply.
If Microsoft does it, the same privacy rules should apply.
If an advertising company does it, the same privacy rules should apply.
If a data broker does it, the same privacy rules should apply.
If an AI company does it, the same privacy rules should apply.
If a foreign company serving Americans does it, the same baseline privacy rules should apply.
National-security concerns involving foreign governments may require additional restrictions.
But that is not a substitute for privacy law.
Banning one application does not establish deletion rights.
It does not establish access rights.
It does not establish data minimization.
It does not restrict data brokers.
It does not establish retention limits.
It does not stop another company from gathering the same information.
And it does not protect Americans from the next popular application.
Stop playing whack-a-mole with companies.
Regulate the behavior.
Regulate the data.
Give the individual rights.
AI MAKES PRIVACY LEGISLATION MORE URGENT, NOT LESS
Artificial intelligence dramatically increases what can be learned from enormous collections of information.
Information that once seemed individually insignificant can now be aggregated, correlated, classified, summarized, searched, inferred from, and analyzed at enormous scale.
A dozen seemingly harmless data points may become extremely revealing when combined with thousands of others.
Companies should not automatically receive perpetual permission to use someone's personal information for AI merely because that person once interacted with a service.
Organizations should be transparent when personal information is materially used for AI training, profiling, or consequential automated decision-making.
Sensitive information deserves stronger safeguards.
People should have meaningful rights when automated systems make or substantially influence consequential decisions about them.
Organizations developing AI should practice privacy by design and data minimization rather than ingesting everything they can find and worrying about the consequences afterward.
AI should not become an excuse to collect everything forever.
The arrival of more powerful technology is not an argument for fewer privacy rights.
It is an argument for establishing those rights now.
PROTECT PEOPLE WHO NEVER BOUGHT THE PRODUCT
Privacy legislation also needs to protect non-users and bystanders.
Smart glasses, wearable cameras, connected vehicles, always-listening assistants, facial-recognition systems, doorbell cameras, and other AI-enabled devices complicate traditional ideas of consent.
The person wearing or purchasing a device may have accepted its terms of service.
Everyone standing around that person did not.
A company should not gain unlimited rights to identify, profile, retain, analyze, or monetize a bystander's face, voice, movements, associations, location, or conversations merely because somebody else purchased a gadget.
This does not mean outlawing cameras.
It does not mean prohibiting ordinary photography.
There is a meaningful difference between a human being taking a photograph and a multinational corporation automatically extracting, identifying, correlating, retaining, and monetizing information about every person who happens to enter a camera's field of view.
Those are not the same thing.
Devices designed for persistent recording or automated analysis should include appropriate privacy protections, clear indicators where practical, reasonable retention limitations, and safeguards against building commercial profiles of people who never became customers.
EMPLOYEES ARE PEOPLE TOO
Federal privacy legislation should not pretend privacy suddenly disappears when somebody clocks into work.
Employers obviously have legitimate reasons to process employee information.
Payroll is necessary.
Benefits administration is necessary.
Cybersecurity monitoring is necessary.
Fraud prevention is necessary.
Physical security is necessary.
Compliance and investigations can be necessary.
Ordinary business operations require information.
But necessity should have boundaries.
Employees should receive meaningful transparency into substantial workplace surveillance and how their information is being used.
Intrusive biometric monitoring, persistent location tracking, automated employee scoring, AI profiling, and unnecessary secondary uses of employee information should require legitimate and proportionate justification.
Employers should not be able to bury unnecessarily broad permissions inside documents that effectively require someone to surrender unlimited rights to their name, likeness, voice, recordings, or other personal information for any imaginable purpose forever.
Consent becomes questionable when refusing it could affect someone's livelihood.
Privacy law needs to recognize that power imbalance.
PROTECT ENCRYPTION AND PRIVATE COMMUNICATIONS
Protecting children and combating crime are legitimate government responsibilities.
But protecting people does not require treating every person as a suspect.
Mass surveillance should not become the default answer to difficult social problems.
End-to-end encryption protects journalists, abuse victims, activists, businesses, cybersecurity professionals, government employees, families, children, financial information, medical information, and ordinary conversations.
Federal privacy legislation should protect the ability to use strong encryption and reject blanket requirements to create encryption backdoors or indiscriminately scan everyone's private communications.
Law enforcement should investigate suspects.
Platforms should be held accountable when they knowingly facilitate abuse.
Companies should build safer systems.
Governments should properly fund investigators and victim services.
Privacy-preserving technologies should be encouraged.
But "scan everybody" should not be the starting point.
A right to privacy means the government should have a reason to intrude.
It should not mean every citizen has to constantly prove they have nothing to hide.
PRIVACY IS CYBERSECURITY
Some people discuss privacy and cybersecurity as if they are unrelated.
They are deeply connected.
Every unnecessary database is another target.
Every unnecessary copy of personal information expands the attack surface.
Every additional vendor receiving information creates another supply-chain dependency.
Every employee with unnecessary access creates another possible insider risk.
Every piece of personal information retained indefinitely increases the consequences of the eventual breach.
Data minimization is not merely a privacy concept.
It is risk reduction.
Organizations holding substantial amounts of personal information should be required to implement reasonable administrative, technical, and physical safeguards proportionate to the sensitivity and volume of that information.
They should understand what data they possess.
They should know where sensitive information is stored.
They should restrict access.
They should manage vendors.
They should log appropriate access.
They should encrypt sensitive information where appropriate.
They should establish retention schedules.
They should regularly determine whether information is still necessary.
When something goes wrong, affected people deserve timely and useful information rather than vague corporate language months later.
MAKE PRIVACY VIOLATIONS EXPENSIVE ENOUGH TO MATTER
A privacy law without meaningful enforcement is a suggestion.
Companies should not be able to calculate violations of our privacy as merely another operating expense.
Enforcement should be proportional to the seriousness of the conduct and the size of the organization.
A fine that could destroy a small business may mean virtually nothing to a multinational corporation earning billions of dollars.
For the largest organizations, serious or deliberate violations should therefore permit penalties tied to revenue so enforcement remains meaningful regardless of company size.
The Federal Trade Commission should receive strong enforcement authority, adequate staffing, technical resources, and the ability to impose meaningful penalties.
State regulators and state attorneys general should retain appropriate enforcement powers.
For serious violations, individuals should also have an appropriately designed ability to seek redress rather than being entirely dependent on whether a government agency happens to take their case.
Rights ordinary people cannot enforce are not meaningful rights.
FEDERAL LAW SHOULD BE A FLOOR, NOT A CEILING
Businesses have a legitimate interest in predictable national standards.
Fifty incompatible privacy regimes can become difficult to navigate, particularly for smaller organizations.
A comprehensive federal law can create consistent definitions, minimum rights, interfaces, security expectations, and compliance requirements.
But Congress should not respond to states finally giving residents meaningful protections by passing a weaker national law that wipes those protections away.
Federal law should establish a strong national minimum.
States should retain reasonable authority to provide stronger protections.
Uniformity should simplify compliance.
It should not become another word for weakening privacy.
SMALL BUSINESSES SHOULD HAVE PROPORTIONAL OBLIGATIONS
Privacy regulation should be proportionate.
A neighborhood bakery maintaining a customer mailing list should not face the same compliance burden as a global advertising company profiling hundreds of millions of people.
Requirements can scale based on factors such as organization size, revenue, number of people affected, volume and sensitivity of information, risk created by the processing, and whether monetizing personal information is a core part of the business model.
Small organizations should receive standardized tools, templates, technical guidance, reasonable implementation periods, and appropriate safe harbors for good-faith security practices.
But fundamental privacy rights should not disappear based on company size.
A small company should not receive special permission to secretly sell someone's medical information simply because it is small.
Privacy rights belong to the individual.
Compliance obligations can be proportional.
WHAT CONGRESS SHOULD PASS
We call on Congress to enact comprehensive federal privacy legislation establishing, at minimum, the following protections:
DEMAND 01: A FEDERAL RIGHT TO PRIVACY
Every American should have meaningful and enforceable legal rights concerning the reasonable protection, collection, retention, use, and disclosure of their personal information.
DEMAND 02: A RIGHT TO KNOW
People should be able to determine what personal information an organization possesses, where it came from, why it is being processed, how long it will be retained, and who receives it.
DEMAND 03: A RIGHT OF ACCESS
People should be able to obtain a usable copy of personal information associated with them.
DEMAND 04: A RIGHT TO CORRECTION
People should be able to correct materially inaccurate information about themselves.
DEMAND 05: A RIGHT TO DELETION
People should be able to require deletion when information is no longer reasonably necessary, subject to clearly defined legal, security, fraud-prevention, and public-interest exceptions.
DEMAND 06: A RIGHT TO DATA PORTABILITY
Where technically reasonable, people should be able to export information they provided in a structured and commonly usable format so leaving a service does not mean abandoning years of personal information.
DEMAND 07: A RIGHT TO OBJECT AND OPT OUT
People should be able to reject the sale or unnecessary sharing of personal information, extensive cross-service behavioral advertising, and certain forms of profiling.
DEMAND 08: STRONGER PROTECTION FOR SENSITIVE DATA
Sensitive information should receive heightened safeguards and generally require affirmative authorization for unnecessary secondary uses.
DEMAND 09: DATA MINIMIZATION
Organizations should collect and retain only information reasonably necessary for clearly identified purposes.
DEMAND 10: PURPOSE LIMITATION
Information collected for one purpose should not automatically become available for unrelated future purposes.
DEMAND 11: STORAGE LIMITATION
Organizations should establish reasonable retention periods instead of storing personal information indefinitely.
DEMAND 12: PRIVACY BY DESIGN AND BY DEFAULT
Privacy should be treated as an engineering requirement from the beginning. Reasonable privacy-protective settings should be the default, particularly for children and sensitive information.
DEMAND 13: PROTECTION FROM DARK PATTERNS
Companies should not manipulate people into surrendering privacy through deceptive interfaces, confusing consent screens, or opt-out processes designed to discourage people from exercising their rights.
DEMAND 14: DATA-BROKER TRANSPARENCY AND UNIVERSAL CONTROLS
Americans should not have to identify and opt out of hundreds of unknown data brokers individually. There should be a national data-broker registry and a practical universal mechanism for opting out of covered data sales and requesting deletion.
DEMAND 15: PROTECTION FOR NON-USERS AND BYSTANDERS
Companies should face meaningful limitations on identifying, profiling, retaining, or monetizing information about people who never established a relationship with their service.
DEMAND 16: AI TRANSPARENCY AND PRIVACY RIGHTS
People should receive meaningful information and protections when personal information is materially used for AI training, profiling, or consequential automated decision-making.
DEMAND 17: WORKPLACE PRIVACY PROTECTIONS
Employees should receive reasonable protections against disproportionate surveillance, biometric monitoring, persistent tracking, AI profiling, and coercive secondary uses of personal information.
DEMAND 18: PROTECTION FOR STRONG ENCRYPTION
Federal privacy law should protect secure private communications rather than creating blanket encryption-backdoor requirements or indiscriminate scanning mandates.
DEMAND 19: RESTRICTIONS ON GOVERNMENT PURCHASES OF SENSITIVE DATA
Government agencies should not automatically be able to purchase their way around privacy protections or legal processes that would otherwise apply if they sought the same sensitive information directly.
DEMAND 20: STRONG CYBERSECURITY REQUIREMENTS
Organizations holding personal information should implement reasonable administrative, technical, and physical safeguards proportionate to the sensitivity and risk of the information involved.
DEMAND 21: MEANINGFUL BREACH ACCOUNTABILITY
People deserve timely and understandable notification when their information is compromised, meaningful information about what happened, and appropriate remedies when organizations fail to reasonably protect sensitive information.
DEMAND 22: STRONG ENFORCEMENT
The Federal Trade Commission, state regulators, and state attorneys general need meaningful enforcement authority and adequate technical resources. Individuals should also have appropriate mechanisms to seek redress for serious violations.
DEMAND 23: PENALTIES THAT SCALE WITH THE OFFENDER
Penalties must be large enough that violating Americans' privacy cannot simply become another line item in a corporate budget. Serious violations by enormous companies should carry consequences proportionate to their size and revenue.
DEMAND 24: PROTECTION FOR STRONGER STATE LAWS
Federal legislation should establish a strong national minimum without unnecessarily eliminating stronger privacy protections enacted by individual states.
DEMAND 25: INTERNATIONAL INTEROPERABILITY
Congress should design federal privacy requirements with enough compatibility and clarity that American businesses can operate efficiently alongside major international privacy frameworks while maintaining strong American constitutional protections.
DEMAND 26: REGULAR REVIEW
Congress should require periodic review of federal privacy protections so the law can evolve alongside artificial intelligence, biometrics, augmented reality, connected vehicles, wearable computers, emerging surveillance technologies, and whatever comes next.
WE DO NOT HAVE TO CHOOSE BETWEEN TECHNOLOGY AND PRIVACY
The argument that privacy protections will destroy innovation presents a false choice.
Engineering already works within constraints.
We design systems around electrical limits.
We design around bandwidth limits.
We design around safety requirements.
We design around authentication requirements.
We design around building codes.
We design around accessibility standards.
We design around financial controls.
We design around cybersecurity requirements.
Privacy can be a design requirement too.
Companies operating internationally already build systems capable of responding to privacy rights in jurisdictions where those rights exist.
Americans should not receive weaker rights simply because of which side of the Atlantic Ocean they live on.
Strong privacy protections can also encourage competition and trust.
Data portability makes it easier to leave dominant platforms.
Transparency helps consumers make meaningful decisions.
Data minimization reduces breach exposure.
Clear national standards give businesses predictable expectations.
International compatibility can make it easier for American companies to operate globally.
Privacy and innovation do not have to be enemies.
In fact, responsible privacy engineering should become another area in which American technology leads.
"I HAVE NOTHING TO HIDE" MISSES THE POINT
Privacy is not about hiding wrongdoing.
You close the bathroom door.
You put your mail in an envelope.
You use passwords.
You lock your phone.
You expect your doctor to protect your medical information.
You probably do not publish your bank statements on your front lawn.
You probably do not want strangers reading every conversation you have with your spouse, children, friends, coworkers, attorney, doctor, or therapist.
None of that makes you suspicious.
Privacy is the ability to decide which parts of your life you share, with whom, for what purpose, and for how long.
Privacy is not secrecy.
Privacy is control.
THE BALANCE OF POWER HAS SHIFTED TOO FAR
An ordinary person cannot realistically negotiate privacy terms with Meta.
Or Google.
Or an insurance company.
Or a data broker they have never heard of.
Or the operating system on their phone.
Or every advertising exchange operating behind a website.
Or every analytics provider embedded in an application.
Or every vendor supplying technology to the products and services they use.
The idea that people can simply "choose another service" ignores how deeply integrated data collection has become into modern life.
There may be dozens, hundreds, or even thousands of organizations involved in the data generated by an ordinary person's digital activity.
Meaningful privacy cannot depend on every American becoming an attorney, cybersecurity engineer, privacy researcher, and network analyst.
The law exists in part to establish rules when massive power imbalances make meaningful individual negotiation unrealistic.
That is exactly what we need here.
PRIVACY SHOULD NOT BE SOMETHING ONLY TECHNICAL PEOPLE CAN DEFEND
People often respond to privacy concerns by suggesting that individuals should simply configure their devices better.
Use a different browser.
Install an ad blocker.
Change dozens of privacy settings.
Run network-level filtering.
Use a VPN.
Read every privacy policy.
Avoid certain applications.
Understand every permission request.
Audit every connected device.
Opt out of hundreds of data brokers.
Technical people may be able to reduce portions of their exposure.
That is not a privacy framework.
A society cannot base fundamental rights on whether every citizen has enough technical knowledge and free time to continuously defend themselves against an entire data economy.
Security professionals should be able to use advanced privacy controls because we want to.
Ordinary people should not need to become security professionals just to have privacy.
WAITING WILL ONLY MAKE THIS HARDER
Computers are becoming more powerful.
Storage is becoming cheaper.
Artificial intelligence can analyze previously unimaginable quantities of information.
Cameras are becoming smaller.
Microphones are becoming ubiquitous.
Cars are computers.
Televisions are computers.
Watches are computers.
Glasses are becoming computers.
Homes are filled with network-connected sensors.
Advertising networks follow people between services.
Data brokers combine information from countless sources.
Biometric systems increasingly identify people without asking them to identify themselves.
The amount of information available about an ordinary person is growing faster than our legal protections.
Every year we delay means more infrastructure and more business models become dependent on unrestricted collection.
Waiting another decade will not make this easier.
The best time to establish comprehensive American privacy rights was years ago.
The second-best time is now.
OUR DEMAND
We call upon the United States Congress to pass, and the President of the United States to sign, comprehensive federal privacy legislation establishing meaningful and enforceable privacy rights for every American.
Study the GDPR.
Study PIPEDA.
Study POPIA.
Study PIPL.
Study American state privacy laws.
Study what works.
Study what failed.
Learn from cybersecurity engineering.
Learn from privacy researchers.
Learn from civil-liberties advocates.
Learn from consumer advocates.
Listen to businesses that actually have to implement these systems.
Listen to parents.
Listen to workers.
Listen to journalists.
Listen to victims of identity theft and data breaches.
Listen to ordinary Americans who are tired of discovering that another company they have never heard of possesses intimate details about their lives.
Then build something better.
America should not merely catch up.
America should lead.
Do not make this Republican versus Democrat.
Do not make it TikTok versus Meta.
Do not make it America versus Europe.
Do not make it consumers versus technology.
And do not spend another decade warning us about foreign governments obtaining Americans' information while refusing to address the enormous domestic ecosystem that collects and trades that information in the first place.
This is bigger than any one platform, political party, administration, country, or technology company.
Americans deserve to know who has our data.
We deserve to know what they are doing with it.
We deserve to know where they obtained it.
We deserve to correct it.
We deserve to delete it when there is no legitimate reason to keep it.
We deserve to say no to its sale.
We deserve stronger protection for our most sensitive information.
We deserve reasonable protections from profiling.
We deserve meaningful privacy in the workplace.
We deserve protection when we are merely bystanders to someone else's device.
We deserve strong encryption and private communications.
We deserve protection from indiscriminate surveillance.
We deserve privacy even when the technology collecting information is new.
And we deserve meaningful consequences when organizations knowingly violate those rights.
Our personal information should not belong to whichever company managed to collect it first.
If Congress is genuinely concerned about China obtaining Americans' personal information, start by giving Americans meaningful control over how much of that information exists in corporate databases in the first place.
America helped build the digital age.
We should not be one of the countries struggling to understand the risks it created.
Technology has changed.
The balance of power has changed.
The rest of the world has been updating its laws.
Our laws need to catch up.
Then they need to lead.
Please sign this petition and urge Congress to give every American a meaningful and enforceable right to privacy.
Privacy should be a right, not a setting buried three menus deep.
SELECTED SOURCES AND FURTHER READING
SOURCE: U.S. Government Accountability Office, Protecting Personal Privacy
https://www.gao.gov/protecting-personal-privacy
SOURCE: European Data Protection Board, Basic GDPR Principles
https://www.edpb.europa.eu/topics/key-gdpr-concepts/basic-principles_en
SOURCE: European Commission, Data Protection Rights
https://commission.europa.eu/law/law-topic/data-protection/information-individuals_en
SOURCE: Office of the Privacy Commissioner of Canada, PIPEDA and Fair Information Principles
https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/
SOURCE: Information Regulator of South Africa, Protection of Personal Information Act
https://inforegulator.org.za/
SOURCE: Personal Information Protection Law of the People's Republic of China, English-language reference
https://en.spp.gov.cn/2021-12/29/c_948419.htm
SOURCE: Federal Trade Commission, Staff Report on Social Media and Video Streaming Surveillance
https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-staff-report-finds-large-social-media-video-streaming-companies-have-engaged-vast-surveillance
SOURCE: Federal Trade Commission, X-Mode/Outlogic Sensitive Location Data Enforcement
https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data
SOURCE: Federal Trade Commission, Data Broker Transparency Report
https://www.ftc.gov/news-events/news/press-releases/2014/05/ftc-recommends-congress-require-data-broker-industry-be-more-transparent-give-consumers-greater
SOURCE: National Institute of Standards and Technology, Privacy Framework
https://www.nist.gov/privacy-framework

16
The Issue
To the United States Congress and the President of the United States:
TL;DR
The United States is one of the world's leading technology powers, yet Americans still do not have one comprehensive federal privacy law giving everyone meaningful and enforceable control over personal information.
That is becoming increasingly difficult to justify.
Europe has the General Data Protection Regulation, commonly known as the GDPR.
Canada has the Personal Information Protection and Electronic Documents Act, or PIPEDA.
South Africa has the Protection of Personal Information Act, or POPIA.
China has the Personal Information Protection Law, or PIPL.
These laws are not identical. They exist under very different legal systems, provide different rights, contain different exceptions, and should not all be treated as equally protective of civil liberties.
But they demonstrate something important:
Countries around the world have recognized that modern digital economies need comprehensive national rules governing how companies collect, process, retain, disclose, and protect personal information.
The United States still has a patchwork.
That should embarrass us.
It is especially ironic when American politicians repeatedly warn us that we must protect Americans' data from China.
That concern can be legitimate.
But China itself has enacted a nationwide private-sector personal information law that includes requirements involving data minimization, defined purposes, retention, transparency, consent, and individual rights, while the United States still lacks a comprehensive federal equivalent applying broadly to Americans.
To be absolutely clear, this does not mean China should be treated as a model for protection from government surveillance or as equivalent to American constitutional civil liberties.
That is not the point.
The point is much simpler:
If American politicians believe enormous collections of personal information become a national-security threat when China might obtain them, then perhaps we should stop allowing enormous amounts of unnecessary personal information to be collected, retained, aggregated, and traded in the first place.
Data minimization is not only privacy.
Data minimization is cybersecurity.
Data minimization can also be national security.
Congress should establish a strong national right to privacy drawing lessons from GDPR, PIPEDA, POPIA, PIPL, American state privacy laws, cybersecurity principles, and other frameworks around the world.
Americans should have the right to know what organizations know about us, access that information, correct it, delete it when there is no legitimate reason to retain it, move it between services where practical, and opt out of unnecessary sale, sharing, tracking, and profiling.
Organizations should be required to minimize collection, clearly explain why information is collected, limit how long it is retained, appropriately protect it, and face meaningful consequences when they knowingly violate our rights.
Sensitive information such as precise location, health data, biometrics, financial information, private communications, authentication information, and information about children should receive stronger protection.
Data brokers should not be allowed to quietly build detailed dossiers on Americans while forcing each person to hunt through hundreds of obscure opt-out systems.
Government agencies should not be able to purchase sensitive commercial data simply to bypass legal protections that would otherwise apply.
Artificial intelligence should not become an excuse to collect everything forever.
Employees should not lose all privacy rights when they clock in.
Bystanders should not lose their privacy because somebody standing next to them purchased smart glasses or another recording device.
Strong encryption and private communications should remain protected.
Federal legislation should establish a strong national floor without erasing stronger protections states have already enacted.
And this is not theoretical to me.
I work professionally in cybersecurity, and when I have meaningful choices about where to locate some of my own infrastructure or which cloud regions and providers to use, I often prefer European options partly because I want to operate in an environment governed by comprehensive privacy rules such as the GDPR.
I am an American working in American cybersecurity.
I should not have to look across the Atlantic for the kind of comprehensive privacy environment I wish existed at home.
This petition is not anti-technology.
It is about making America better at technology.
Real technological leadership is not simply inventing something first.
Real technological leadership also means understanding the risks created by that technology and building the legal, security, and engineering frameworks necessary to use it responsibly.
If excessive data collection is dangerous when TikTok does it, then the same behavior should be regulated when Meta, Google, Apple, Microsoft, an advertising network, a data broker, an AI company, an employer, a vehicle manufacturer, a smart-device manufacturer, or anyone else does it.
If the behavior is dangerous, regulate the behavior.
If the data is sensitive, protect the data.
If Americans deserve privacy from one company, we deserve privacy from all of them.
Privacy is not secrecy.
Privacy is control.
THE MOMENT THAT MADE THIS IMPOSSIBLE FOR ME TO IGNORE
The moment that really crystallized this issue for me was watching the United States debate banning TikTok over privacy and data collection.
Again and again, I heard politicians warn that it was dangerous for a company to collect enormous amounts of information about Americans.
And I kept thinking:
If collecting this much information about people is dangerous, why are we only talking about one app?
Why should the rules change depending on whether the logo belongs to a Chinese company, an American company, an advertising network, a smart television manufacturer, a data broker, a vehicle manufacturer, or a social-media platform?
If the behavior is dangerous, regulate the behavior.
If the data is sensitive, protect the data.
If Americans deserve privacy from one company, we deserve privacy from all of them.
National-security concerns involving foreign governments may justify additional narrowly tailored restrictions.
That is a separate issue.
But banning one application does not create a right to privacy.
It does not stop another company from collecting the same categories of information.
It does not stop data brokers from creating detailed profiles.
It does not establish deletion rights.
It does not establish data-minimization requirements.
It does not establish reasonable retention limits.
It does not give Americans a universal right to know who has their information.
It does not protect Americans from whatever application becomes popular next.
Stop playing whack-a-mole with individual companies.
Regulate the data.
Regulate the behavior.
Give the individual rights.
AMERICA IS FALLING BEHIND IN PRIVACY GOVERNANCE
This is not merely a comparison between the United States and Europe.
The privacy debate has become global because the technology creating the problem is global.
Europe has the GDPR.
Canada has PIPEDA.
South Africa has POPIA.
China has PIPL.
Other countries and jurisdictions have adopted their own comprehensive privacy and data-protection frameworks.
These laws are not interchangeable.
They do not all provide identical rights.
They do not all operate under democratic constitutional systems.
They should not all be copied.
But they show that countries with drastically different politics, economies, cultures, and legal traditions have reached a similar conclusion:
Personal information cannot simply exist in a legal free-for-all.
Modern economies built around enormous amounts of data need rules.
They need transparency.
They need limits.
They need security.
They need accountability.
They need enforceable rights.
The United States is home to some of the most powerful technology companies, cloud platforms, artificial-intelligence companies, advertising systems, social networks, data brokers, software companies, and digital infrastructure on Earth.
Yet our legal framework for personal information remains fragmented.
That is not technological leadership.
America is extraordinarily good at inventing technology.
We have been much worse at updating laws quickly enough to address the risks created by that technology.
Innovation without risk management is not leadership.
It is technical debt at the scale of a country.
CHINA SHOULD NOT BE ABLE TO EMBARRASS US ON PRIVATE-SECTOR DATA MINIMIZATION
There is an extraordinary irony in the American privacy debate.
American politicians repeatedly tell Americans that we should fear China obtaining our personal information.
Again, national-security concerns involving China can absolutely be legitimate.
But consider the contradiction.
China enacted the Personal Information Protection Law, commonly known as PIPL.
Among other requirements, that framework imposes rules concerning defined and reasonable purposes, collection limited to what is necessary, restrictions on excessive collection, retention, transparency, consent, certain automated decisions, and individual rights.
Meanwhile, the United States still does not provide every American with an equivalent comprehensive federal privacy baseline applying broadly across the private sector.
Think about how absurd that sounds.
American politicians tell us that China getting too much data about Americans is dangerous.
Yet our own country still allows a sprawling commercial ecosystem to collect, aggregate, retain, infer from, buy, and sell enormous quantities of information about Americans without one comprehensive federal law establishing uniform rights.
China should not be able to look at the United States and effectively say:
Even we decided companies need nationwide rules limiting personal information collection. Why haven't you?
That should bother Congress.
That should embarrass Congress.
To be absolutely clear, this is not praise for Chinese government surveillance.
PIPL does not mean China's political system provides the same privacy protections Americans should expect from a democratic constitutional government.
That is not the argument.
The argument is that even a country American politicians repeatedly identify as a serious surveillance and data-security concern recognized that private companies need nationwide legal rules governing personal information.
The United States still has not done the equivalent comprehensively at the federal level.
If China obtaining Americans' information is a national-security concern, then Congress should recognize an obvious defensive measure:
Collect less unnecessary information in the first place.
Retain less unnecessary information.
Allow fewer unnecessary transfers.
Restrict unnecessary aggregation.
Give Americans meaningful control over what companies know about us.
You cannot steal a database that was never created.
You cannot purchase information that was never collected.
You cannot leak information that was deleted years ago.
Data minimization is privacy.
Data minimization is cybersecurity.
And in some circumstances, data minimization is national security.
I SHOULD NOT HAVE TO LOOK TO EUROPE FOR STRONGER PRIVACY EXPECTATIONS
This affects decisions I make personally.
I work professionally in cybersecurity.
I operate infrastructure.
I use cloud services.
I understand that simply placing a server inside Europe does not magically guarantee that every activity involving it becomes protected by the GDPR.
Privacy law is more complicated than geography alone.
But when I have a meaningful choice about where to locate some infrastructure, which cloud region to use, or which providers I want to trust, I often prefer European options partly because I value operating in an environment where comprehensive privacy regulation exists.
Think about what that says.
I am an American working professionally in cybersecurity, yet I sometimes look outside my own country for the stronger privacy environment I wish existed here.
I should not have to do that.
American infrastructure should be able to compete on privacy.
American cloud providers should operate under clear privacy expectations.
American technology companies should be able to tell customers that strong privacy protections are a feature of doing business in the United States.
Choosing American infrastructure should not inherently mean accepting weaker national privacy expectations.
If anything, America should be establishing the standard the rest of the world wants to follow.
IMAGINE IF THE PHYSICAL WORLD WORKED LIKE THE DIGITAL WORLD
Imagine walking down the street and discovering that companies you have never heard of are following you.
They record which stores you enter.
They record how long you stay.
They record what products you stop to examine.
They record who you are standing beside.
They notice when you visit a doctor.
They know which religious institution you attend.
They can see which political events you visit.
They track where you work.
They know where you sleep.
They record where you travel.
They record what you buy.
Then those companies combine their records with information purchased from other companies, build detailed profiles about you, infer things you never explicitly told them, and sell or share access to those profiles with organizations you have never knowingly interacted with.
Most Americans would find that horrifying if someone physically followed them around with a clipboard.
Yet versions of this happen every day in the digital world.
Websites, applications, advertising networks, data brokers, connected vehicles, televisions, social networks, wearables, location services, smart devices, and countless other systems can generate extraordinary amounts of information about our lives.
People often have little practical understanding of who ultimately receives that information, how long it remains stored, what conclusions are drawn from it, how it is combined with other information, or what somebody may decide to use it for years later.
Technology has dramatically shifted the balance of power between individuals and organizations capable of collecting information about them.
Our laws need to restore some of that balance.
PRIVACY SHOULD BE A RIGHT, NOT A PREMIUM FEATURE
I am not anti-technology.
I am not anti-cloud.
I am not anti-AI.
I am not anti-advertising.
I am not demanding that organizations stop processing information genuinely necessary to provide products and services people deliberately request.
My career depends on technology.
I regularly work with cloud infrastructure, security products, logs, telemetry, access controls, automation, and systems that legitimately need information to function.
That experience is exactly why I believe America desperately needs comprehensive privacy legislation.
Cybersecurity teaches one of the simplest lessons imaginable:
Data you never collect cannot be stolen from you.
Data you delete cannot be breached five years later.
Access that is never granted cannot be abused.
In cybersecurity, we preach least privilege.
People and systems should receive only the access reasonably necessary to perform their function.
We should apply the same principle to personal information.
Call it least privilege for data.
A company should collect what it reasonably needs to provide the product or service I requested, use it for clearly identified purposes, protect it while it has it, and delete it when it no longer has a legitimate reason to retain it.
It should not be considered normal for every application, website, television, vehicle, wearable, social network, advertising company, data broker, employer, or AI company to collect as much information as technically possible simply because storage is inexpensive and somebody might discover a way to monetize it later.
America does not need to copy GDPR.
America does not need to copy PIPEDA.
America does not need to copy POPIA.
America certainly does not need to copy PIPL wholesale.
We should learn from all of them.
Take what works.
Reject what does not.
Combine those lessons with American constitutional principles, cybersecurity engineering, state privacy laws, consumer protection, and technological expertise.
Then build something better.
AMERICA'S PATCHWORK IS NOT ENOUGH
The United States does have privacy protections.
Medical information has certain protections.
Financial information has certain protections.
Children's information has certain protections.
Some communications have legal protections.
Some states have enacted broader consumer privacy laws.
The Federal Trade Commission can pursue certain deceptive or unfair practices.
But these protections are fragmented across industries, categories of information, states, regulators, contractual terms, privacy policies, and specific circumstances.
What America still lacks is one comprehensive federal baseline providing meaningful privacy rights to everyone.
Some Americans receive stronger protections because of where they live.
Others receive fewer.
That is not a reasonable way to handle something as fundamental as control over personal information.
Your basic rights over your digital life should not depend on which side of a state line you happen to live on.
An American living in Ohio should not inherently deserve less privacy than someone living in California.
A person should not need a law degree to determine whether they have the right to ask a company what information it holds about them.
Businesses also have a legitimate interest in understandable national rules rather than navigating an increasingly complicated collection of inconsistent requirements.
A comprehensive federal law can establish consistent definitions, rights, interfaces, security expectations, and compliance requirements.
But that national law should establish a strong minimum.
It should not become an excuse to erase stronger protections states have already enacted.
Federal law should raise the floor.
It should not lower the ceiling.
AMERICANS SHOULD KNOW WHAT COMPANIES KNOW ABOUT US
A person should have the right to ask an organization:
What information do you have about me?
And receive a meaningful answer.
Not a 75-page privacy policy.
Not vague categories such as "information from our partners."
Not an intentionally difficult portal designed to make people give up.
Tell me what information you possess.
Tell me where it came from.
Tell me what you inferred from it.
Tell me why you use it.
Tell me who receives it.
Tell me how long you intend to keep it.
Tell me which data brokers or third parties supplied information about me.
Tell me whether my information is materially being used to train, fine-tune, evaluate, or otherwise improve an AI system.
Tell me whether my information is being used for profiling or consequential automated decision-making.
If a company can build a detailed profile about me, I should have the right to see that profile.
THE RIGHT TO DELETE SHOULD ACTUALLY MEAN DELETE
There should be a strong federal right to deletion.
If I close an account and a company no longer has a legitimate legal, security, fraud-prevention, contractual, financial, or operational reason to maintain my personal information, I should be able to tell them:
Delete it.
There obviously need to be reasonable exceptions.
Records required for legal obligations, litigation, fraud prevention, cybersecurity investigations, financial recordkeeping, public records, legitimate journalism, and clearly defined public-interest purposes may need to be retained.
Backups may require technically reasonable deletion schedules rather than instantaneous removal.
But "we might figure out how to monetize this someday" should not qualify as a legitimate reason to retain someone's personal life indefinitely.
Where appropriate, deletion requests should also propagate to processors and applicable third parties that received the information from the organization.
CONSENT SHOULD ACTUALLY MEAN CONSENT
We need to stop pretending that clicking "I Agree" to a massive contract written by attorneys constitutes meaningful consent to everything a company might ever invent.
Consent should be specific.
Consent should be informed.
Consent should be freely given.
Consent should be understandable.
Consent should be revocable.
And withdrawing optional consent should be approximately as easy as giving it.
If an application needs my location to show nearby restaurants, that does not automatically mean it should receive unlimited permission to retain my location history for ten years, combine it with my browsing history, sell it to data brokers, infer sensitive characteristics about me, and feed it into future machine-learning systems.
Those are different purposes.
They should be treated as different decisions.
We also need rules against deceptive privacy interfaces and dark patterns.
Rejecting optional tracking should not require fourteen clicks when accepting it requires one.
Turning off targeted advertising should not mysteriously turn itself back on.
Closing an account should not require hunting through support pages for half an hour.
Privacy controls should be understandable to normal human beings.
SENSITIVE INFORMATION DESERVES STRONGER PROTECTION
Some information can cause extraordinary harm if abused.
Precise geolocation can reveal where you sleep, where you work, which doctor you visit, which religious institution you attend, which political events you participate in, who you spend time with, and where your children go.
Health information can expose some of the most intimate details of a person's life.
Biometrics can be extraordinarily difficult or impossible to replace once compromised.
Private communications can expose relationships, finances, medical concerns, legal matters, political activity, and personal struggles.
Federal law should establish stronger protections for categories including precise geolocation, health and medical information, biometric identifiers, facial-recognition data, voiceprints, genetic information, financial information, government identification numbers, private communications, authentication credentials, information about minors, and information capable of revealing highly sensitive characteristics or activities.
Your location history is not merely "marketing data."
It can become a map of your life.
Sensitive information should generally require stronger justification, stricter safeguards, shorter retention periods, and affirmative permission for unnecessary secondary uses.
REIN IN DATA BROKERS
Data brokers demonstrate why America's current consent model is fundamentally broken.
Most Americans have never knowingly opened an account with many of the companies buying and selling information about them.
You cannot meaningfully consent to a relationship you do not even know exists.
Federal legislation should create meaningful data-broker transparency.
Americans should be able to determine which registered data brokers possess information about them, what categories of information those companies process, where that information comes from, what it is used for, and how it is shared.
There should also be a practical national mechanism allowing people to tell covered data brokers:
Do not sell or share my personal information.
Delete information you do not have a legitimate legal reason to retain.
Americans should not have to identify hundreds of obscure companies individually, navigate hundreds of different opt-out forms, hand over additional personal information simply to prove our identities, and repeat the process over and over again.
The burden should be on the companies profiting from our information.
It should not be on the people being profiled.
DO NOT LET GOVERNMENT PURCHASES BECOME A SURVEILLANCE LOOPHOLE
A meaningful right to privacy must address government acquisition of commercially available sensitive information too.
If law enforcement or another government agency would ordinarily need a warrant, subpoena, court order, or other legal process to compel sensitive information directly, the government should not automatically be able to sidestep those protections merely because equivalent information can be purchased from a commercial data broker.
The Constitution should not become optional because somebody added a shopping cart.
Federal law should establish clear rules for government acquisition of especially sensitive commercially available information, including precise location information, communications information, health information, biometrics, and similar categories.
Reasonable emergency and legitimate national-security exceptions can exist with appropriate safeguards and oversight.
But privacy protections should not vanish simply because surveillance has been outsourced.
THIS IS BIGGER THAN TIKTOK
If TikTok's data collection is dangerous, regulate the dangerous data collection.
If Meta does it, the same privacy rules should apply.
If Google does it, the same privacy rules should apply.
If Apple does it, the same privacy rules should apply.
If Microsoft does it, the same privacy rules should apply.
If an advertising company does it, the same privacy rules should apply.
If a data broker does it, the same privacy rules should apply.
If an AI company does it, the same privacy rules should apply.
If a foreign company serving Americans does it, the same baseline privacy rules should apply.
National-security concerns involving foreign governments may require additional restrictions.
But that is not a substitute for privacy law.
Banning one application does not establish deletion rights.
It does not establish access rights.
It does not establish data minimization.
It does not restrict data brokers.
It does not establish retention limits.
It does not stop another company from gathering the same information.
And it does not protect Americans from the next popular application.
Stop playing whack-a-mole with companies.
Regulate the behavior.
Regulate the data.
Give the individual rights.
AI MAKES PRIVACY LEGISLATION MORE URGENT, NOT LESS
Artificial intelligence dramatically increases what can be learned from enormous collections of information.
Information that once seemed individually insignificant can now be aggregated, correlated, classified, summarized, searched, inferred from, and analyzed at enormous scale.
A dozen seemingly harmless data points may become extremely revealing when combined with thousands of others.
Companies should not automatically receive perpetual permission to use someone's personal information for AI merely because that person once interacted with a service.
Organizations should be transparent when personal information is materially used for AI training, profiling, or consequential automated decision-making.
Sensitive information deserves stronger safeguards.
People should have meaningful rights when automated systems make or substantially influence consequential decisions about them.
Organizations developing AI should practice privacy by design and data minimization rather than ingesting everything they can find and worrying about the consequences afterward.
AI should not become an excuse to collect everything forever.
The arrival of more powerful technology is not an argument for fewer privacy rights.
It is an argument for establishing those rights now.
PROTECT PEOPLE WHO NEVER BOUGHT THE PRODUCT
Privacy legislation also needs to protect non-users and bystanders.
Smart glasses, wearable cameras, connected vehicles, always-listening assistants, facial-recognition systems, doorbell cameras, and other AI-enabled devices complicate traditional ideas of consent.
The person wearing or purchasing a device may have accepted its terms of service.
Everyone standing around that person did not.
A company should not gain unlimited rights to identify, profile, retain, analyze, or monetize a bystander's face, voice, movements, associations, location, or conversations merely because somebody else purchased a gadget.
This does not mean outlawing cameras.
It does not mean prohibiting ordinary photography.
There is a meaningful difference between a human being taking a photograph and a multinational corporation automatically extracting, identifying, correlating, retaining, and monetizing information about every person who happens to enter a camera's field of view.
Those are not the same thing.
Devices designed for persistent recording or automated analysis should include appropriate privacy protections, clear indicators where practical, reasonable retention limitations, and safeguards against building commercial profiles of people who never became customers.
EMPLOYEES ARE PEOPLE TOO
Federal privacy legislation should not pretend privacy suddenly disappears when somebody clocks into work.
Employers obviously have legitimate reasons to process employee information.
Payroll is necessary.
Benefits administration is necessary.
Cybersecurity monitoring is necessary.
Fraud prevention is necessary.
Physical security is necessary.
Compliance and investigations can be necessary.
Ordinary business operations require information.
But necessity should have boundaries.
Employees should receive meaningful transparency into substantial workplace surveillance and how their information is being used.
Intrusive biometric monitoring, persistent location tracking, automated employee scoring, AI profiling, and unnecessary secondary uses of employee information should require legitimate and proportionate justification.
Employers should not be able to bury unnecessarily broad permissions inside documents that effectively require someone to surrender unlimited rights to their name, likeness, voice, recordings, or other personal information for any imaginable purpose forever.
Consent becomes questionable when refusing it could affect someone's livelihood.
Privacy law needs to recognize that power imbalance.
PROTECT ENCRYPTION AND PRIVATE COMMUNICATIONS
Protecting children and combating crime are legitimate government responsibilities.
But protecting people does not require treating every person as a suspect.
Mass surveillance should not become the default answer to difficult social problems.
End-to-end encryption protects journalists, abuse victims, activists, businesses, cybersecurity professionals, government employees, families, children, financial information, medical information, and ordinary conversations.
Federal privacy legislation should protect the ability to use strong encryption and reject blanket requirements to create encryption backdoors or indiscriminately scan everyone's private communications.
Law enforcement should investigate suspects.
Platforms should be held accountable when they knowingly facilitate abuse.
Companies should build safer systems.
Governments should properly fund investigators and victim services.
Privacy-preserving technologies should be encouraged.
But "scan everybody" should not be the starting point.
A right to privacy means the government should have a reason to intrude.
It should not mean every citizen has to constantly prove they have nothing to hide.
PRIVACY IS CYBERSECURITY
Some people discuss privacy and cybersecurity as if they are unrelated.
They are deeply connected.
Every unnecessary database is another target.
Every unnecessary copy of personal information expands the attack surface.
Every additional vendor receiving information creates another supply-chain dependency.
Every employee with unnecessary access creates another possible insider risk.
Every piece of personal information retained indefinitely increases the consequences of the eventual breach.
Data minimization is not merely a privacy concept.
It is risk reduction.
Organizations holding substantial amounts of personal information should be required to implement reasonable administrative, technical, and physical safeguards proportionate to the sensitivity and volume of that information.
They should understand what data they possess.
They should know where sensitive information is stored.
They should restrict access.
They should manage vendors.
They should log appropriate access.
They should encrypt sensitive information where appropriate.
They should establish retention schedules.
They should regularly determine whether information is still necessary.
When something goes wrong, affected people deserve timely and useful information rather than vague corporate language months later.
MAKE PRIVACY VIOLATIONS EXPENSIVE ENOUGH TO MATTER
A privacy law without meaningful enforcement is a suggestion.
Companies should not be able to calculate violations of our privacy as merely another operating expense.
Enforcement should be proportional to the seriousness of the conduct and the size of the organization.
A fine that could destroy a small business may mean virtually nothing to a multinational corporation earning billions of dollars.
For the largest organizations, serious or deliberate violations should therefore permit penalties tied to revenue so enforcement remains meaningful regardless of company size.
The Federal Trade Commission should receive strong enforcement authority, adequate staffing, technical resources, and the ability to impose meaningful penalties.
State regulators and state attorneys general should retain appropriate enforcement powers.
For serious violations, individuals should also have an appropriately designed ability to seek redress rather than being entirely dependent on whether a government agency happens to take their case.
Rights ordinary people cannot enforce are not meaningful rights.
FEDERAL LAW SHOULD BE A FLOOR, NOT A CEILING
Businesses have a legitimate interest in predictable national standards.
Fifty incompatible privacy regimes can become difficult to navigate, particularly for smaller organizations.
A comprehensive federal law can create consistent definitions, minimum rights, interfaces, security expectations, and compliance requirements.
But Congress should not respond to states finally giving residents meaningful protections by passing a weaker national law that wipes those protections away.
Federal law should establish a strong national minimum.
States should retain reasonable authority to provide stronger protections.
Uniformity should simplify compliance.
It should not become another word for weakening privacy.
SMALL BUSINESSES SHOULD HAVE PROPORTIONAL OBLIGATIONS
Privacy regulation should be proportionate.
A neighborhood bakery maintaining a customer mailing list should not face the same compliance burden as a global advertising company profiling hundreds of millions of people.
Requirements can scale based on factors such as organization size, revenue, number of people affected, volume and sensitivity of information, risk created by the processing, and whether monetizing personal information is a core part of the business model.
Small organizations should receive standardized tools, templates, technical guidance, reasonable implementation periods, and appropriate safe harbors for good-faith security practices.
But fundamental privacy rights should not disappear based on company size.
A small company should not receive special permission to secretly sell someone's medical information simply because it is small.
Privacy rights belong to the individual.
Compliance obligations can be proportional.
WHAT CONGRESS SHOULD PASS
We call on Congress to enact comprehensive federal privacy legislation establishing, at minimum, the following protections:
DEMAND 01: A FEDERAL RIGHT TO PRIVACY
Every American should have meaningful and enforceable legal rights concerning the reasonable protection, collection, retention, use, and disclosure of their personal information.
DEMAND 02: A RIGHT TO KNOW
People should be able to determine what personal information an organization possesses, where it came from, why it is being processed, how long it will be retained, and who receives it.
DEMAND 03: A RIGHT OF ACCESS
People should be able to obtain a usable copy of personal information associated with them.
DEMAND 04: A RIGHT TO CORRECTION
People should be able to correct materially inaccurate information about themselves.
DEMAND 05: A RIGHT TO DELETION
People should be able to require deletion when information is no longer reasonably necessary, subject to clearly defined legal, security, fraud-prevention, and public-interest exceptions.
DEMAND 06: A RIGHT TO DATA PORTABILITY
Where technically reasonable, people should be able to export information they provided in a structured and commonly usable format so leaving a service does not mean abandoning years of personal information.
DEMAND 07: A RIGHT TO OBJECT AND OPT OUT
People should be able to reject the sale or unnecessary sharing of personal information, extensive cross-service behavioral advertising, and certain forms of profiling.
DEMAND 08: STRONGER PROTECTION FOR SENSITIVE DATA
Sensitive information should receive heightened safeguards and generally require affirmative authorization for unnecessary secondary uses.
DEMAND 09: DATA MINIMIZATION
Organizations should collect and retain only information reasonably necessary for clearly identified purposes.
DEMAND 10: PURPOSE LIMITATION
Information collected for one purpose should not automatically become available for unrelated future purposes.
DEMAND 11: STORAGE LIMITATION
Organizations should establish reasonable retention periods instead of storing personal information indefinitely.
DEMAND 12: PRIVACY BY DESIGN AND BY DEFAULT
Privacy should be treated as an engineering requirement from the beginning. Reasonable privacy-protective settings should be the default, particularly for children and sensitive information.
DEMAND 13: PROTECTION FROM DARK PATTERNS
Companies should not manipulate people into surrendering privacy through deceptive interfaces, confusing consent screens, or opt-out processes designed to discourage people from exercising their rights.
DEMAND 14: DATA-BROKER TRANSPARENCY AND UNIVERSAL CONTROLS
Americans should not have to identify and opt out of hundreds of unknown data brokers individually. There should be a national data-broker registry and a practical universal mechanism for opting out of covered data sales and requesting deletion.
DEMAND 15: PROTECTION FOR NON-USERS AND BYSTANDERS
Companies should face meaningful limitations on identifying, profiling, retaining, or monetizing information about people who never established a relationship with their service.
DEMAND 16: AI TRANSPARENCY AND PRIVACY RIGHTS
People should receive meaningful information and protections when personal information is materially used for AI training, profiling, or consequential automated decision-making.
DEMAND 17: WORKPLACE PRIVACY PROTECTIONS
Employees should receive reasonable protections against disproportionate surveillance, biometric monitoring, persistent tracking, AI profiling, and coercive secondary uses of personal information.
DEMAND 18: PROTECTION FOR STRONG ENCRYPTION
Federal privacy law should protect secure private communications rather than creating blanket encryption-backdoor requirements or indiscriminate scanning mandates.
DEMAND 19: RESTRICTIONS ON GOVERNMENT PURCHASES OF SENSITIVE DATA
Government agencies should not automatically be able to purchase their way around privacy protections or legal processes that would otherwise apply if they sought the same sensitive information directly.
DEMAND 20: STRONG CYBERSECURITY REQUIREMENTS
Organizations holding personal information should implement reasonable administrative, technical, and physical safeguards proportionate to the sensitivity and risk of the information involved.
DEMAND 21: MEANINGFUL BREACH ACCOUNTABILITY
People deserve timely and understandable notification when their information is compromised, meaningful information about what happened, and appropriate remedies when organizations fail to reasonably protect sensitive information.
DEMAND 22: STRONG ENFORCEMENT
The Federal Trade Commission, state regulators, and state attorneys general need meaningful enforcement authority and adequate technical resources. Individuals should also have appropriate mechanisms to seek redress for serious violations.
DEMAND 23: PENALTIES THAT SCALE WITH THE OFFENDER
Penalties must be large enough that violating Americans' privacy cannot simply become another line item in a corporate budget. Serious violations by enormous companies should carry consequences proportionate to their size and revenue.
DEMAND 24: PROTECTION FOR STRONGER STATE LAWS
Federal legislation should establish a strong national minimum without unnecessarily eliminating stronger privacy protections enacted by individual states.
DEMAND 25: INTERNATIONAL INTEROPERABILITY
Congress should design federal privacy requirements with enough compatibility and clarity that American businesses can operate efficiently alongside major international privacy frameworks while maintaining strong American constitutional protections.
DEMAND 26: REGULAR REVIEW
Congress should require periodic review of federal privacy protections so the law can evolve alongside artificial intelligence, biometrics, augmented reality, connected vehicles, wearable computers, emerging surveillance technologies, and whatever comes next.
WE DO NOT HAVE TO CHOOSE BETWEEN TECHNOLOGY AND PRIVACY
The argument that privacy protections will destroy innovation presents a false choice.
Engineering already works within constraints.
We design systems around electrical limits.
We design around bandwidth limits.
We design around safety requirements.
We design around authentication requirements.
We design around building codes.
We design around accessibility standards.
We design around financial controls.
We design around cybersecurity requirements.
Privacy can be a design requirement too.
Companies operating internationally already build systems capable of responding to privacy rights in jurisdictions where those rights exist.
Americans should not receive weaker rights simply because of which side of the Atlantic Ocean they live on.
Strong privacy protections can also encourage competition and trust.
Data portability makes it easier to leave dominant platforms.
Transparency helps consumers make meaningful decisions.
Data minimization reduces breach exposure.
Clear national standards give businesses predictable expectations.
International compatibility can make it easier for American companies to operate globally.
Privacy and innovation do not have to be enemies.
In fact, responsible privacy engineering should become another area in which American technology leads.
"I HAVE NOTHING TO HIDE" MISSES THE POINT
Privacy is not about hiding wrongdoing.
You close the bathroom door.
You put your mail in an envelope.
You use passwords.
You lock your phone.
You expect your doctor to protect your medical information.
You probably do not publish your bank statements on your front lawn.
You probably do not want strangers reading every conversation you have with your spouse, children, friends, coworkers, attorney, doctor, or therapist.
None of that makes you suspicious.
Privacy is the ability to decide which parts of your life you share, with whom, for what purpose, and for how long.
Privacy is not secrecy.
Privacy is control.
THE BALANCE OF POWER HAS SHIFTED TOO FAR
An ordinary person cannot realistically negotiate privacy terms with Meta.
Or Google.
Or an insurance company.
Or a data broker they have never heard of.
Or the operating system on their phone.
Or every advertising exchange operating behind a website.
Or every analytics provider embedded in an application.
Or every vendor supplying technology to the products and services they use.
The idea that people can simply "choose another service" ignores how deeply integrated data collection has become into modern life.
There may be dozens, hundreds, or even thousands of organizations involved in the data generated by an ordinary person's digital activity.
Meaningful privacy cannot depend on every American becoming an attorney, cybersecurity engineer, privacy researcher, and network analyst.
The law exists in part to establish rules when massive power imbalances make meaningful individual negotiation unrealistic.
That is exactly what we need here.
PRIVACY SHOULD NOT BE SOMETHING ONLY TECHNICAL PEOPLE CAN DEFEND
People often respond to privacy concerns by suggesting that individuals should simply configure their devices better.
Use a different browser.
Install an ad blocker.
Change dozens of privacy settings.
Run network-level filtering.
Use a VPN.
Read every privacy policy.
Avoid certain applications.
Understand every permission request.
Audit every connected device.
Opt out of hundreds of data brokers.
Technical people may be able to reduce portions of their exposure.
That is not a privacy framework.
A society cannot base fundamental rights on whether every citizen has enough technical knowledge and free time to continuously defend themselves against an entire data economy.
Security professionals should be able to use advanced privacy controls because we want to.
Ordinary people should not need to become security professionals just to have privacy.
WAITING WILL ONLY MAKE THIS HARDER
Computers are becoming more powerful.
Storage is becoming cheaper.
Artificial intelligence can analyze previously unimaginable quantities of information.
Cameras are becoming smaller.
Microphones are becoming ubiquitous.
Cars are computers.
Televisions are computers.
Watches are computers.
Glasses are becoming computers.
Homes are filled with network-connected sensors.
Advertising networks follow people between services.
Data brokers combine information from countless sources.
Biometric systems increasingly identify people without asking them to identify themselves.
The amount of information available about an ordinary person is growing faster than our legal protections.
Every year we delay means more infrastructure and more business models become dependent on unrestricted collection.
Waiting another decade will not make this easier.
The best time to establish comprehensive American privacy rights was years ago.
The second-best time is now.
OUR DEMAND
We call upon the United States Congress to pass, and the President of the United States to sign, comprehensive federal privacy legislation establishing meaningful and enforceable privacy rights for every American.
Study the GDPR.
Study PIPEDA.
Study POPIA.
Study PIPL.
Study American state privacy laws.
Study what works.
Study what failed.
Learn from cybersecurity engineering.
Learn from privacy researchers.
Learn from civil-liberties advocates.
Learn from consumer advocates.
Listen to businesses that actually have to implement these systems.
Listen to parents.
Listen to workers.
Listen to journalists.
Listen to victims of identity theft and data breaches.
Listen to ordinary Americans who are tired of discovering that another company they have never heard of possesses intimate details about their lives.
Then build something better.
America should not merely catch up.
America should lead.
Do not make this Republican versus Democrat.
Do not make it TikTok versus Meta.
Do not make it America versus Europe.
Do not make it consumers versus technology.
And do not spend another decade warning us about foreign governments obtaining Americans' information while refusing to address the enormous domestic ecosystem that collects and trades that information in the first place.
This is bigger than any one platform, political party, administration, country, or technology company.
Americans deserve to know who has our data.
We deserve to know what they are doing with it.
We deserve to know where they obtained it.
We deserve to correct it.
We deserve to delete it when there is no legitimate reason to keep it.
We deserve to say no to its sale.
We deserve stronger protection for our most sensitive information.
We deserve reasonable protections from profiling.
We deserve meaningful privacy in the workplace.
We deserve protection when we are merely bystanders to someone else's device.
We deserve strong encryption and private communications.
We deserve protection from indiscriminate surveillance.
We deserve privacy even when the technology collecting information is new.
And we deserve meaningful consequences when organizations knowingly violate those rights.
Our personal information should not belong to whichever company managed to collect it first.
If Congress is genuinely concerned about China obtaining Americans' personal information, start by giving Americans meaningful control over how much of that information exists in corporate databases in the first place.
America helped build the digital age.
We should not be one of the countries struggling to understand the risks it created.
Technology has changed.
The balance of power has changed.
The rest of the world has been updating its laws.
Our laws need to catch up.
Then they need to lead.
Please sign this petition and urge Congress to give every American a meaningful and enforceable right to privacy.
Privacy should be a right, not a setting buried three menus deep.
SELECTED SOURCES AND FURTHER READING
SOURCE: U.S. Government Accountability Office, Protecting Personal Privacy
https://www.gao.gov/protecting-personal-privacy
SOURCE: European Data Protection Board, Basic GDPR Principles
https://www.edpb.europa.eu/topics/key-gdpr-concepts/basic-principles_en
SOURCE: European Commission, Data Protection Rights
https://commission.europa.eu/law/law-topic/data-protection/information-individuals_en
SOURCE: Office of the Privacy Commissioner of Canada, PIPEDA and Fair Information Principles
https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/
SOURCE: Information Regulator of South Africa, Protection of Personal Information Act
https://inforegulator.org.za/
SOURCE: Personal Information Protection Law of the People's Republic of China, English-language reference
https://en.spp.gov.cn/2021-12/29/c_948419.htm
SOURCE: Federal Trade Commission, Staff Report on Social Media and Video Streaming Surveillance
https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-staff-report-finds-large-social-media-video-streaming-companies-have-engaged-vast-surveillance
SOURCE: Federal Trade Commission, X-Mode/Outlogic Sensitive Location Data Enforcement
https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data
SOURCE: Federal Trade Commission, Data Broker Transparency Report
https://www.ftc.gov/news-events/news/press-releases/2014/05/ftc-recommends-congress-require-data-broker-industry-be-more-transparent-give-consumers-greater
SOURCE: National Institute of Standards and Technology, Privacy Framework
https://www.nist.gov/privacy-framework

The Decision Makers
Supporter Voices
Petition Updates
Share this petition
Petition created on August 14, 2026
