Guarantee 08

Freedom from Concentrated Power

Consumer and Digital Rights

People should be protected from fraud, unsafe products, abusive data practices, manipulative interfaces, discriminatory automated systems, and unreasonable digital surveillance.

  • Last reviewed
  • 12 minute read

At a glance

The proposal before the detail

This summary is drawn from the canonical page fields; the full argument and evidence follow.

Proposal status
Working draft Proposed public guarantee
Central public purpose
Digital freedom requires usable consent, data minimization, safe products, accountable automation, practical remedies, and limits on surveillance that respect both consumer and constitutional law.
Current legal and institutional baseline
Constitutional protections constrain certain government conduct, while statutes and regulations govern particular consumer, privacy, safety, credit, and sectoral practices. The comprehensive digital guarantee proposed here does not yet exist as one enforceable federal right.
Primary promise
Freedom from Concentrated Power
Last reviewed
Important tradeoffs
  • Privacy and useful services
  • Transparency and gaming
  • Portability and security
Serious unresolved question
Which consent designs produce informed choice rather than box-checking fatigue?

Why It Matters

People now apply for work and credit, manage health information, pay bills, learn, communicate, and prove identity through systems they cannot fully inspect. A nominal choice is not meaningful when the interface hides consequences, refusal means losing an essential service, or a consequential denial offers no useful reason.

This guarantee starts from a practical rule: the party that designs and profits from a system should carry duties proportionate to the risk it creates. People still have responsibilities to use products safely and protect credentials, but they should not have to defeat deceptive design, audit a machine-learning model, or repair insecure defaults before they can participate in ordinary life.

Digital rights should protect agency without promising perfect control. They include safe products, honest interfaces, restrained data use, security, appeal, repair, and limits on both public and private surveillance appropriate to the source of power.

Historical Root

The Bill of Rights limits specified government actions, including unreasonable searches and seizures and restrictions on expression. Those constitutional constraints do not automatically govern a retailer, data broker, employer, or social platform in the same way. Modern consumer and digital policy therefore combines constitutional doctrine, statutes, regulation, contract, competition, and proposed new duties.

Consumer protection also has a long institutional lineage: law can require truthful claims, safe products, fair credit reporting, and remedies when private transactions cause defined harms. Digital systems change the scale and speed of those problems, but they do not erase the need to identify the responsible institution, the legal authority, and the available remedy.

What Exists Today

The United States does not have one general federal law covering every commercial use of personal data. Federal protections are sectoral: different laws address particular industries or information, including credit reports, specified health and financial records, communications, and children’s data. The FTC also uses Section 5 of the FTC Act and specific statutes within its jurisdiction against certain unfair or deceptive privacy and security practices. Neither that authority nor competition law is a complete privacy code.

States have added both sector-specific and broader consumer privacy laws. Their coverage, definitions, exemptions, enforcement, remedies, and treatment of stronger local rules differ. A federal privacy proposal therefore must answer two questions rather than one: what protections should apply nationwide, and which stronger state protections should remain available?

Some existing rules already reach decisions made with newer technology. In credit, for example, the CFPB has explained that use of a complex algorithm does not remove a creditor’s duty under the Equal Credit Opportunity Act and Regulation B to give specific principal reasons for an adverse action. That is a concrete sectoral protection, not a general right to an explanation from every automated system.

The FTC has documented interface practices that can obscure material terms, make cancellation difficult, or steer people toward unintended disclosures. NIST’s AI Risk Management Framework offers a voluntary process for governing, mapping, measuring, and managing AI risk; it does not itself create a remedy. CISA and partner agencies likewise urge manufacturers to take responsibility for product security and safe defaults, but that secure-by-design guidance is voluntary.

Scope of this edition: This is a national policy framework, not a fifty-state compliance chart or individualized legal advice. A practice described as harmful is not necessarily unlawful in every jurisdiction, and a voluntary framework is not presented as an enforceable right.

Where the Gaps Are

Fragmented rules can leave similar data protected differently depending on who holds it and why. Responsibility is hard to locate when a service relies on data brokers, cloud vendors, advertisers, model providers, and downstream customers. People are then asked to manage systemic risk through notices they cannot negotiate.

Consent cannot carry the whole burden. It is weak when refusal is costly, choices are bundled, collection happens in the background, or data are later used to infer sensitive facts. At the same time, prohibiting every use that lacks individualized consent could block fraud detection, accessibility, security, and socially valuable research. The harder policy task is to define purposes, duties, and prohibited practices that apply even when someone clicked “agree.”

Consequential automated decisions raise a related gap. A system can be statistically accurate overall and still rely on poor data, conceal an administrative error, reproduce an unlawful distinction, or offer no route for correction. Small organizations can also face obligations they cannot operationalize without shared standards, technical assistance, and rules scaled to actual risk.

What Success Could Look Like

Success means less unnecessary collection, fewer unsafe defaults, intelligible choices, secure products, fair cancellation, reasons and appeals for consequential decisions, and remedies proportionate to harm.

A public scorecard should ask measurable questions: Can a person learn which entity made a decision? Can inaccurate data be corrected before damage compounds? Do products receive security support for a stated period? Are cancellation and deletion requests completed without avoidable steps? Do audits test relevant error and discrimination risks? How long are sensitive data retained, and who receives them? Measures must include burden on users and smaller organizations, not just the number of notices published.

Policy Options

A privacy floor with real boundaries

A general federal floor could define covered data and entities; limit collection, use, sharing, and retention; establish access, correction, deletion, and portability rights; require reasonable security; and specify enforcement. It must also state clearly how it interacts with health, finance, education, communications, labor, and state law. Uniformity is not automatically protective if it replaces stronger rules with a weaker ceiling.

Duties for consequential automated decisions

The strongest case for explanation and appeal exists where a system materially affects work, credit, housing, education, health, insurance, public benefits, or liberty. Requirements can include documented purpose, data provenance, predeployment testing, monitoring, notice, accurate reasons, human review, record preservation, and a timely correction process. The duty should fit the decision: a movie recommendation does not require the same process as a denial of housing.

Product security and repair

Security should begin with supported software, safe defaults, vulnerability handling, usable updates, and clear end-of-support dates rather than placing the entire burden on buyers. Procurement can accelerate those practices by requiring them in public contracts. Repair and interoperability can reduce lock-in, but access interfaces, replacement parts, and diagnostic data must be designed to avoid creating new safety or privacy failures.

Government access and surveillance

Rules for commercial privacy cannot substitute for rules governing government. Warrants, statutory authority, minimization, retention, notice, reporting, adversarial review, inspectors general, and courts play different roles. The appropriate safeguard depends on what is collected, from whom, for what purpose, at what scale, and with what consequence.

Choices and Tradeoffs

Privacy can conflict with fraud prevention, accessibility, research, and safety; portability can increase breach risk; transparency can enable gaming; and detailed compliance can entrench incumbents. Age checks can protect children while also creating demands for sensitive identity data. Rules aimed at manipulative distribution or automated ranking can affect lawful expression.

These are not reasons to accept the status quo. They are reasons to define protected outcomes, assign responsibility, test less restrictive methods, and require evidence before imposing the same process on every system. Risk-based rules should be clear enough for enforcement and flexible enough for changing technology.

Serious Objections

One objection is that privacy compliance becomes a fixed cost that large incumbents can absorb and smaller competitors cannot. Another is that forced disclosure can expose trade secrets, security controls, or a system to manipulation. A third is that consumers value convenience and personalization and should be free to exchange data for services.

All three objections matter. Standardized compliance tools, risk-based duties, confidential regulator access, outcome testing, and specific user-facing reasons can provide scrutiny without demanding public source code. Low-risk personalization based on a genuine choice need not be treated like secret use of sensitive data for a consequential decision. But contract freedom is not enough where terms are hidden, exit is unrealistic, or harms reach people who never agreed.

Questions Still Open

Before legislation, this platform would seek comparative evidence on six questions:

  1. Which data practices should be prohibited, which should require affirmative consent, and which can rely on a documented legitimate purpose?
  2. Which enforcement mix produces timely correction: agency supervision, state enforcement, private lawsuits, contractual remedies, or some combination?
  3. Which automated-decision tests reliably reveal material error or discrimination without becoming paperwork detached from outcomes?
  4. Which age-assurance designs reduce risk to children without normalizing identification of every user?
  5. Which repair and interoperability rules have reduced lock-in without weakening safety or cybersecurity?
  6. Which surveillance safeguards provide meaningful review without preventing legitimate, legally authorized investigations?

The evidence review should measure actual conduct and outcomes—not only what a privacy policy, model card, or compliance filing says is permitted.

Evidence

Sources

Source type, role, and limitations are shown so readers can judge what each item can—and cannot—support.

Government analysis Verified metadata

Bringing Dark Patterns to Light

Federal Trade Commission

A staff report describing interface practices that can obscure, subvert, or impair consumer choice, including hidden terms, difficult cancellation, and designs that steer disclosure of personal information.

Limits: The report presents enforcement and policy analysis rather than a comprehensive prevalence study, and interface practices continue to evolve.

Government analysis Verified metadata

Artificial Intelligence Risk Management Framework (AI RMF 1.0)

Elham Tabassi. National Institute of Standards and Technology

A voluntary, rights-preserving framework for governing, mapping, measuring, and managing risks from artificial-intelligence systems.

Limits: The framework is voluntary and non-sector-specific, is being revised, and does not by itself create legal duties or remedies.

Primary historical document Verified metadata

Constitution of the United States: Analysis and Interpretation

Congress.gov, Library of Congress

The constitutional text, amendments, and links to the congressionally prepared Constitution Annotated.

Limits: The constitutional text must be read with case law and doctrine; this entry is not a substitute for legal advice or a current issue-specific survey.

Primary historical document Verified metadata

The Bill of Rights

National Archives and Records Administration

The National Archives presentation and transcript of the first ten amendments to the United States Constitution.

Limits: The document's text does not by itself explain modern incorporation, remedies, or the boundary between governmental and private conduct.

Government analysis Verified metadata

Guide to Antitrust Laws

Federal Trade Commission

An official guide to federal competition law, merger review, agreements among competitors, monopolization, and the roles of the federal antitrust agencies.

Limits: Agency guidance is general and does not resolve fact-specific liability or the empirical effects of every form of concentration.

Government analysis Verified metadata

Preemption and Privacy Law

Chris D. Linebaugh. Congressional Research Service

A congressional legal analysis of the United States' sector-specific federal privacy laws, the growth of state privacy statutes, and the choices Congress faces when deciding whether a federal law should preserve or preempt state protections.

Limits: The report describes law as of August 2025 and is not a live fifty-state survey or legal advice. State enactments, effective dates, litigation, and federal proposals continue to change.

Government analysis Verified metadata

Privacy and Security Enforcement

Federal Trade Commission

The FTC's overview of privacy and data-security enforcement, including its use of Section 5 of the FTC Act against unfair or deceptive practices and its authority under specified sectoral statutes.

Limits: An enforcement overview reflects the FTC's jurisdiction and case selection. It does not create a comprehensive federal privacy right, cover every entity, or establish that every harmful data practice violates existing law.

Government analysis Verified metadata

Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software

Cybersecurity and Infrastructure Security Agency and international partners

Joint government guidance urging technology manufacturers to take responsibility for customer security outcomes, use safe defaults, disclose security information responsibly, and make product security an executive responsibility.

Limits: The document is voluntary guidance, not a statute or universal product-security standard. Its principles require sector-specific engineering, enforcement, liability, and measurement choices before they become enforceable duties.

Government analysis Verified metadata

Consumer Financial Protection Circular 2022-03: Adverse action notification requirements in connection with credit decisions based on complex algorithms

Consumer Financial Protection Bureau

The CFPB's explanation that creditors using complex algorithms remain subject to Equal Credit Opportunity Act and Regulation B requirements to give applicants specific, accurate principal reasons for adverse credit actions.

Limits: The circular states an agency interpretation in a defined credit-law context. It does not create a general right to an explanation for every automated decision and should be checked against later law, guidance, and litigation.

Revision history

  1. Launch revision added the current privacy-law structure, concrete enforcement examples, product-security duties, and civil-liberties tradeoffs.
  2. Initial working draft separated government constitutional limits from proposed consumer and platform protections.