Category Archives: Personal Privacy Research

After You Click “Agree,” Who Should Be Responsible for Your Data—How MyData and Corporate Responsibility Can Build a Privacy Governance Framework for the AI Era

Editor’s Note: This article is an extension of “Latest Perspective | Don’t Cram Privacy Risks into a Single “Agree” Button—Companies Should Bear Their Share of Responsibility” The previous article discussed the limitations of the “notice-and-consent” mechanism in the AI era, arguing that privacy protection should not depend primarily on individuals reading terms and assessing risks; instead, greater responsibility should be placed on the companies that control data and algorithms. Building on that discussion, this article introduces the MyData concept and explores how corporate accountability can be combined with individual autonomy over personal data. On the one hand, companies must not treat user consent as a basis for avoiding liability. On the other hand, mechanisms such as personal data stores, data portability, and intelligent agents should give individuals genuine and continuous control over their data. The article’s central argument is that privacy governance in the AI era should not require a choice between “individual responsibility” and “corporate responsibility.” Instead, it should establish a collaborative framework based on “individual control, corporate accountability, and technological assistance.”

Daniel J. Solove is a professor at the George Washington University Law School in the United States whose research focuses primarily on privacy, information technology, and legal governance. In his Wall Street Journal article “How Can We Protect Our Privacy in the Age of AI?”, Solove discusses the new risks to personal privacy arising from the development of artificial intelligence. The internet, smartphones, and digital platforms continuously collect personal data, while AI can combine and analyze those data to infer sensitive information that individuals have never directly disclosed. Consumers may share only records of ordinary purchases, such as soap or beverages, yet algorithms may use those records to infer their health conditions and political leanings.[1]

Solove argues that the current privacy regime places too much responsibility on consumers. Faced with vast numbers of privacy policies, authorization pop-ups, and data-processing rules, ordinary people have neither enough time to read them individually nor the ability to determine how their data will be combined and used. AI further increases the complexity of data-based inferences. Even when consumers know what information they have provided, they cannot accurately predict what companies may derive from it.

At first glance, this view appears to be somewhat at odds with the individual autonomy over personal data emphasized by MyData. Solove is cautious about placing responsibility for data control on consumers, whereas MyData advocates using technological and institutional arrangements to return control over personal data to individuals. The MyData Declaration identifies individual empowerment, control over data, and more balanced relationships between people and organizations as important objectives.[2]

Closer analysis reveals that Solove’s emphasis on corporate responsibility and the MyData philosophy are highly complementary. MyData addresses individuals’ lack of data-management tools and meaningful control, while Solove’s approach to corporate accountability addresses the problem of companies using technological complexity to shift responsibility onto individuals. Combining the two can respond to concerns that consumers are incapable of bearing the burden of privacy protection alone, while also providing a more comprehensive data-governance framework for the next-generation data economy, particularly during the MyData 2.0 stage.

I. The Core Connection: Different Paths Toward the Shared Goal of Ending the Failure of “Informed Consent”

Solove’s position and the MyData philosophy share a common target of criticism: the existing “notice-and-consent” model. Under this model, companies use privacy policies and user agreements to explain their data-processing practices to consumers. Once users click “Agree,” companies obtain permission to collect and use their data.

This system assumes that consumers can understand the terms, assess the risks, and anticipate the consequences of data use. In reality, consumers encounter large numbers of authorization pages every day. Privacy policies are usually lengthy, while data-processing activities involve multiple platforms, systems, and partner organizations. Individuals find it difficult to read every policy carefully or continuously track who retains their data, how those data are used, and how long they are stored.

Solove has described this problem as “privacy self-management and the consent dilemma.” He points out that relying on individual consent to manage privacy has clear limitations and that privacy law should not depend excessively on consumers’ personal choices.[3] The development of AI further magnifies those limitations. When users consent to a company’s collection of an ordinary piece of data, they have little way of knowing whether the company will combine it with other information or whether an algorithm will use it to infer sensitive information concerning health, religion, or political views.

In Solove’s view, companies satisfy formal notification requirements through lengthy privacy statements, while the actual burden of protecting privacy falls on consumers. When problems arise, companies may also justify their conduct by arguing that “the user already consented.” A user’s click of the consent button can show only that the user accepted the conditions presented at that time. It can hardly prove that the user understood every possible future use of the data or every inference that an algorithm might draw.

MyData criticizes the same model from the perspective of data-control structures. The current data ecosystem is centered on companies. Once users grant authorization, their personal data generally enter corporate servers, where companies retain, analyze, and use them over extended periods. Users have little ability to monitor the continuing flow of their data and lack practical means to modify permissions, stop data use, or transfer their data at any time.

MyData seeks to shift data governance from a company-centric model to a human-centric one, enabling individuals to access, manage, and use data concerning themselves and to understand how those data flow.[4] Users should be able to decide who may use their data and for what purposes, and to modify or withdraw those decisions in response to changing circumstances. In this way, personal data can be freed from the isolated silos of different corporate systems.

Solove focuses on companies’ use of “consent” to shift responsibility, while MyData focuses on individuals’ loss of meaningful control after they have “consented.” Together, these perspectives demonstrate that a one-time click of the consent button can no longer support privacy governance in the AI era. User authorization may constitute a condition for a company’s use of data, but it cannot serve as a basis for exempting the company from responsibility. A new governance model must strengthen both individuals’ continuing control and companies’ continuing responsibilities.

II. The Core Difference: A “Defensive Shield” and an “Empowerment Engine”

Solove and MyData place different emphases on possible solutions. Solove gives greater weight to risk prevention and corporate accountability. He argues that assigning responsibility for data control to consumers is deeply problematic because ordinary people have very limited attention, time, and professional expertise and cannot manage the complex risks created by AI-generated inferences.

Even when the law gives consumers more choices and consent buttons, users still struggle to identify discrimination, errors, and excessive analysis embedded in algorithmic design. Solove advocates using data minimization, technological review, algorithmic accountability, and legal liability to build a “defensive shield” for consumers. When companies’ use of data or AI algorithms creates an unreasonable risk of harm, they should bear the corresponding responsibility.

In his article, Solove draws on the historical experience of the food, pharmaceutical, and automobile industries. Food and automobiles once presented serious safety problems. Only after the law established systems for inspection, testing, and liability did companies acquire stronger incentives to improve product safety.[1] Under the same logic, digital technologies and AI should undergo privacy and safety reviews before being placed into use, and companies should be held accountable when their algorithms cause harm.

MyData places greater emphasis on individual empowerment, with the central objective of returning control over data to individuals. Through data portability rights and personal data stores, individuals can aggregate, manage, and use their own data and choose the parties to which those data will be provided according to specific needs. They can also restrict the scope of data use, stop data flows when necessary, or transfer their data to other services.

The MyData white paper describes this as a human-centric model for the use of personal data and emphasizes the construction of an interoperable data ecosystem in which individuals participate in exercising control.[4] Under this model, individuals are transformed from passive sources of data into active participants in data relationships. MyData is therefore more akin to an “empowerment engine,” focused on improving individuals’ ability to manage and use their data.

The two approaches also differ in the emphasis they place on the value of data. Solove focuses primarily on the risks associated with data, with the aim of reducing excessive corporate data collection and preventing algorithms from harming individuals.

MyData also recognizes the value of data as an asset and a factor of production, seeking to enable data to flow under conditions that are secure, transparent, and subject to individual control. Individuals can use their multidimensional data to obtain fairer credit assessments and more personalized services that better reflect their actual circumstances.

III. Building a Unified Framework: Deep Integration of Sovereignty and Accountability

Combining MyData with Solove’s approach to corporate responsibility can produce an integrated model consisting of “underlying autonomy, overarching accountability, and intelligent agents.” Within this framework, individuals possess meaningful control over their data, companies cannot use user consent to avoid responsibility, and technological tools help reduce the difficulty individuals face in managing their data.

The first component is the infrastructure layer, which establishes personal data sovereignty based on personal data stores. Users’ core behavioral data can be stored in personal data stores (PDSs) or corresponding decentralized nodes, reducing the unrestricted accumulation of data by centralized companies. At the same time, users possess direct, operational control over “cutting off data flows” and “porting and transferring data,” thereby implementing the “right to deletion” and the genuine control supported by Solove.

The second component is the regulatory baseline layer, which removes the liability-exempting effect of “consent.” “User consent” is no longer a justification for exempting companies from responsibility. Even when users authorize a company to use their data through MyData, the company must still bear strict legal responsibility if its AI algorithm produces discrimination—for example, by misusing nonfinancial data in credit-technology assessments—or makes out-of-scope inferences about sensitive information. This addresses Solove’s concern that “ordinary people cannot anticipate AI risks.”

The third component is the implementation and agency layer, consisting of AI-powered personal data fiduciaries. Solove argues that giving users control is unworkable because the technology is too complex. The key to resolving this contradiction is to use AI to counter AI. Under the unified framework, users do not need to read the terms personally. A “personal AI agent” embedded in the PDS system serves as a digital-era “lawyer” or “fiduciary.” Based on the user’s broad preferences, it automatically negotiates terms with companies’ AI systems and applies data-minimization filters.

The fourth component is the application layer, involving native data-driven credit technology and value assessment. Historically, the U.S. credit system of the 1970s and 1980s was “technology-driven,” having been built on early information-technology architectures. Today’s global innovations, particularly those in China, are instead natively “data-driven.” Under this unified framework, the development of modern credit technology, or CreditTech, will become healthier. Through MyData, users can aggregate their multidimensional data and use them to demonstrate their creditworthiness to B2B service providers or financial institutions. When institutions process those data, however, they must be subject to requirements such as the “pre-market algorithm review” advocated by Solove. This approach not only prevents unlawful inferences about sensitive information but also fully satisfies the demanding requirements of international financial standards, eliminating overly generalized and unprofessional labels.

Conclusion

Daniel J. Solove identifies an exceptionally important problem: we should not expect exposed and defenseless consumers to protect themselves. By combining his model of “strong accountability” with MyData’s model of “strong autonomy,” we can arrive at an ideal solution. MyData provides the tools and vault—the PDS—for managing data, while Solove’s accountability regime surrounds that vault with an impenetrable, high-voltage legal barrier. Under this unified framework, data can remain securely under individual control while also being used with confidence to support economic innovation in the AI era.

References

[1] Solove, Daniel J. “How Can We Protect Our Privacy in the Age of AI?” Chinese edition of The Wall Street Journal,

https://cn.wsj.com/articles/ai-privacy-laws-data-b272b29f?mod=cn_feature_1_pos_4.

[2] MyData Global. “MyData Declaration.” https://mydata.org/participate/declaration/.

[3] Daniel J. Solove, “Privacy Self-Management and the Consent Dilemma,” 126 Harv. L. Rev. 1880 (2013).

[4] Poikola, Antti, et al. MyData: An Introduction to Human-Centric Use of Personal Data. Third Updated English Edition, MyData Global, 2020.

Note: The author, Shanli Zhang, is a doctoral student at Shandong University Law School and a research assistant to Dr. Xinhai Liu. His research focuses on personal data and personal privacy protection. WeChat: 18811157736. Comments and corrections are welcome.

Latest Perspective | Don’t Cram Privacy Risks into a Single “Agree” Button—Companies Should Bear Their Share of Responsibility

When was the last time you seriously read a privacy policy from beginning to end?

In the age of AI, the data we hand over every day may reveal far more than we realize. A shopping record, a browsing trace, or a one-time location permission may appear ordinary in isolation. However, once analyzed and combined by algorithms, such data may be used to infer a person’s health status, purchasing power, interests and preferences, and even more sensitive personal characteristics.

I. AI Can Understand Your Data—and It Is Magnifying an Old Problem

The Chinese edition of The Wall Street Journal recently published an article by Daniel J. Solove titled “How to Maintain Our Privacy in the AI Age,” which addresses precisely this issue: when AI can analyze enormous quantities of personal data, are our existing approaches to privacy protection still adequate? [1]

The author, Daniel J. Solove, is a professor at the George Washington University Law School who has long studied privacy law, data security, and technology governance. He developed the influential “taxonomy of privacy,” which divides privacy violations into different categories, including information collection, information processing, information dissemination, and invasion. [2]

Solove warns that the broader environment of this century has not been friendly to privacy. The internet has risen, smartphones track geographic locations, large numbers of companies continuously collect personal data, and surveillance networks continue to expand. AI is now capable of analyzing vast digital records and can infer a great deal of information about individuals. [1]

The problem is that many privacy laws and platform rules still rely on an old approach: companies provide notice, and users give consent. In theory, this gives users a choice. In reality, however, ordinary people find it difficult to understand what they are actually consenting to. How will their data be shared? What risks may arise from a privacy notice? Could those risks become more serious in the future as AI’s analytical capabilities grow? Most people have neither the time nor the professional expertise needed to assess each of these questions individually.

Using everyday consumer data as an example, Solove reminds us that seemingly ordinary shopping records, once analyzed by AI, may be used to infer more sensitive information, such as health conditions, religious beliefs, and political leanings. Solove therefore reaches a key conclusion: most laws today attempt to shift responsibility for protecting privacy onto consumers. But digital technologies are too complex for ordinary people to manage. We need a different strategy—one that holds companies accountable. [1]

II. Privacy Protection Cannot End with “I Have Read and Agree”

For more than two decades, online privacy protection has largely relied on the model of “notice and consent.” Companies draft privacy policies, users click “Agree,” and the processing of their data is then formally authorized.

The problem with this approach is that it places an extremely complex technological and legal issue on the shoulders of ordinary consumers. Users cannot fully understand what data a company collects. They also have difficulty knowing which third parties may use that data, let alone predicting what an AI system may infer from it. Although this arrangement appears to offer users a choice, many people simply click “Agree” so that they can continue using the service.

“I have read and agree” has often become little more than a formality. It appears to respect users’ choices, but it can easily become a tool through which companies shift responsibility. Solove’s proposed direction is clear: privacy protection must move away from consumer self-management and toward corporate accountability.

He notes that food and pharmaceutical manufacturers also operated under inadequate regulation in the past. Formaldehyde was once added to spoiled milk to make it taste sweeter, and it was only after many infants died that stronger regulation was introduced. The automobile industry went through a similar period. Before laws imposed mandatory safety requirements, automobiles were extremely dangerous means of transportation. [1] Food and automobile safety later improved not because consumers became better at protecting themselves, but because the law required companies to assume responsibility for safety. Cars became subject to safety testing, farms became subject to inspection, and accountability mechanisms were introduced for defective products. Innovations such as seat belts and airbags also emerged in response to safety requirements. [1]

Solove argues that privacy protection requires a similar approach. Companies that collect and use data should not be able to avoid liability merely by issuing a privacy policy. When a company’s use of data or AI algorithms creates an unreasonable risk of harm, it should be held accountable. [1]

More specifically, there are at least several possible directions.

(1) Data Minimization

Companies should collect and use data only for the purposes for which it was originally collected and should not arbitrarily expand the scope of its use. Strict implementation of the principle of data minimization is an important means of effectively protecting privacy. The European Union’s General Data Protection Regulation (GDPR) also establishes data minimization as a fundamental principle. [3] China’s Personal Information Protection Law likewise provides that the collection of personal information must be limited to the minimum scope necessary to achieve the purpose of processing. [4]

(2) The Right to Deletion

Solove notes that the right to deletion has long been part of European Union data protection law. Although it was once regarded as impractical in the United States, it has now been incorporated into consumer privacy laws in various U.S. states and no longer generates substantial controversy. [1] This demonstrates that some privacy protections once considered excessively strict are becoming more widely accepted institutional arrangements as the digital environment evolves.

(3) Restricting “Dark Patterns”

“Dark patterns” are deceptive or manipulative technological designs that induce users to share data they would not otherwise have provided. [1] Such designs prevent users from making genuine choices and further undermine the meaning of “consent.”

(4) Holding Irresponsible Technology Design and Harmful Algorithms Accountable

Solove proposes imposing liability for negligent or reckless technology design, holding harmful algorithms accountable, and requiring protective mechanisms to be built into technologies to prevent them from being used to violate privacy. [1]

The logic underlying these proposals is simple: those who control the data, algorithms, and technological systems should bear the corresponding responsibility. Ordinary consumers need rights, but companies need boundaries even more.

III. Implications for China: Turning the Principle of Corporate Responsibility into Action

China has already entered an era in which everyday life is highly digitalized. As of December 2025, China had 1.125 billion internet users, with an internet penetration rate of 80.1%. The number of generative AI users had reached 602 million, representing a penetration rate of 42.8%. [5] Users certainly need to improve their awareness of privacy. However, if privacy protection depends primarily on individuals reading agreements line by line and assessing each risk separately, it will be difficult to establish genuinely effective protection. For China, the priority is to clearly define the boundaries of corporate data collection, the boundaries of algorithmic use, and the boundaries of corporate responsibility when something goes wrong.

China’s existing laws already incorporate this approach. Article 6 of the Personal Information Protection Law requires that the collection of personal information be limited to the minimum scope necessary to achieve the purpose of processing and prohibits excessive collection. Article 9 provides that personal information processors must be responsible for their personal information processing activities and must adopt the measures necessary to protect the security of personal information. [4] The Data Security Law also requires data processors to establish sound, full-process data security management systems, adopt appropriate technical and other necessary measures to safeguard data security, and promptly take remedial, response, and reporting measures when risks are identified or security incidents occur. [6]

The next crucial step is to ensure that these principles are genuinely reflected in corporate conduct.

Companies must not collect as much data as possible simply because it has commercial value. They must not arbitrarily expand the purposes for which data is used merely because users have clicked “Agree.” They must not avoid explanation and accountability simply because algorithms are complex. Nor should they confine privacy protection to policy documents without implementing it in product design, data management, and algorithmic governance.

Privacy risks in the age of AI will become more difficult to detect. In the past, people were primarily concerned about information leaks. Today, they must also guard against information being inferred, combined, used to create profiles, and applied in ways that affect individual opportunities and choices. Many forms of harm may not take the form of an obvious, one-time data breach. Instead, they may occur gradually through long-term data analysis and algorithmic decision-making.

This is also the most important warning conveyed by Solove’s article: ordinary people cannot always be expected to shoulder the burden of privacy protection by themselves.

Individuals can become more vigilant, but they cannot live every day as though they were legal and technical experts. Those that truly need to assume greater responsibility are the companies that control the data, algorithms, and access points to digital platforms.

The central point in discussions of privacy protection in the age of AI is clear:

Data cannot be collected without limits, algorithms cannot be used without constraints, and responsibility cannot be shifted onto users through a privacy policy. Only by placing genuine responsibility on the companies that control data and technology can privacy protection in the age of AI move beyond a purely formal “Agree” button.

References

[1] Daniel J. Solove, “How to Maintain Our Privacy in the AI Age,” The Wall Street Journal (June 23, 2026).

[2] Daniel J. Solove, “A Taxonomy of Privacy,” University of Pennsylvania Law Review, Vol. 154, No. 3, p. 477, 2006.

[3] European Union General Data Protection Regulation (GDPR).

[4] Personal Information Protection Law of the People’s Republic of China.

[5] Policy and International Cooperation Institute of the China Internet Network Information Center, The 57th Statistical Report on China’s Internet Development, February 2026.

[6] Data Security Law of the People’s Republic of China.

Note: Shanli Zhang, the author of this article, is a doctoral student at Shandong University Law School and a research assistant to Dr. Xinhai Liu. His research focuses on personal data and privacy protection. WeChat: 18811157736. Comments, exchanges, and corrections are welcome.