Lawmakers focus on protecting individuals from Big Tech when they should develop laws focusing specifically on collective data rights to prevent harm to society
Context & Ripple Effects
This op-ed lands mid-arc in a long-running fight over what US data regulation should regulate. Back in 2018, tech companies were already [[a:932778|lobbying for a federal privacy law that would override California's and give them wide leeway]] over personal information — a push to set the baseline on firms' terms. Since then, coverage has shown why the individual-consent frame keeps failing: Facebook and Google's human-rights and public-interest commitments are hamstrung by their ad-based profit models, and Wired has argued that limiting Facebook specifically requires taking citizens' data rights more seriously than content moderation or even antitrust.
The article's core claim — that protecting individuals is the wrong unit of analysis — connects directly to later coverage of [[a:1157074|US fixation on TikTok while data brokers sell Americans' information to anyone, including China]], and to Democrats' window-bound push to get tech regulation done before Republicans retake Congress. The recurring theme across all of it: harm accumulates at the population level, but the proposed remedies operate person by person.
First-order effects
- Under an individual-protection frame, platforms like Facebook and Google can honor per-user consent rules while their ad-based business models keep monetizing aggregate behavioral data whose harms — manipulation, discrimination, civic erosion — fall on groups no single user signed away.
- Data brokers operating in the gap between state laws and the absent federal statute continue selling information on US citizens to any buyer, with no legal instrument aimed at the collective exposure itself.
Second-order effects
- Industry lobbying for a preemptive federal privacy law becomes more consequential, not less: a framework built around individual notice-and-consent would lock in the very framing the article says fails, making later collective-data-rights legislation structurally harder to retrofit.
- Company-by-company regulatory attention (Facebook via moderation and antitrust debates, TikTok via national-security scrutiny) substitutes for a general rule, so each platform gets its own political fight while the underlying data-broker economy stays untouched.
Third-order effects
- If the individual-rights pattern holds, US tech governance settles into a firm-centric regime — consent dashboards, per-platform enforcement, episodic congressional hearings — while society-level harms from aggregated data remain legally invisible, pushing regulators toward blunt tools like bans rather than rights-based frameworks.
- A durable collective-data-rights layer would change the industry's cost structure: obligations keyed to populations and datasets rather than users would hit exactly the ad-funded growth models that current coverage shows are incompatible with voluntary restraint.
The trend: US data regulation is consolidating around individual consent and company-specific enforcement even as the documented harms — ad-driven platform incentives, brokered citizen data — accumulate at the collective level where no law currently operates.