Editor’s Note: This article is an extension of “Latest Perspective | Don’t Cram Privacy Risks into a Single “Agree” Button—Companies Should Bear Their Share of Responsibility” The previous article discussed the limitations of the “notice-and-consent” mechanism in the AI era, arguing that privacy protection should not depend primarily on individuals reading terms and assessing risks; instead, greater responsibility should be placed on the companies that control data and algorithms. Building on that discussion, this article introduces the MyData concept and explores how corporate accountability can be combined with individual autonomy over personal data. On the one hand, companies must not treat user consent as a basis for avoiding liability. On the other hand, mechanisms such as personal data stores, data portability, and intelligent agents should give individuals genuine and continuous control over their data. The article’s central argument is that privacy governance in the AI era should not require a choice between “individual responsibility” and “corporate responsibility.” Instead, it should establish a collaborative framework based on “individual control, corporate accountability, and technological assistance.”

Daniel J. Solove is a professor at the George Washington University Law School in the United States whose research focuses primarily on privacy, information technology, and legal governance. In his Wall Street Journal article “How Can We Protect Our Privacy in the Age of AI?”, Solove discusses the new risks to personal privacy arising from the development of artificial intelligence. The internet, smartphones, and digital platforms continuously collect personal data, while AI can combine and analyze those data to infer sensitive information that individuals have never directly disclosed. Consumers may share only records of ordinary purchases, such as soap or beverages, yet algorithms may use those records to infer their health conditions and political leanings.[1]
Solove argues that the current privacy regime places too much responsibility on consumers. Faced with vast numbers of privacy policies, authorization pop-ups, and data-processing rules, ordinary people have neither enough time to read them individually nor the ability to determine how their data will be combined and used. AI further increases the complexity of data-based inferences. Even when consumers know what information they have provided, they cannot accurately predict what companies may derive from it.
At first glance, this view appears to be somewhat at odds with the individual autonomy over personal data emphasized by MyData. Solove is cautious about placing responsibility for data control on consumers, whereas MyData advocates using technological and institutional arrangements to return control over personal data to individuals. The MyData Declaration identifies individual empowerment, control over data, and more balanced relationships between people and organizations as important objectives.[2]
Closer analysis reveals that Solove’s emphasis on corporate responsibility and the MyData philosophy are highly complementary. MyData addresses individuals’ lack of data-management tools and meaningful control, while Solove’s approach to corporate accountability addresses the problem of companies using technological complexity to shift responsibility onto individuals. Combining the two can respond to concerns that consumers are incapable of bearing the burden of privacy protection alone, while also providing a more comprehensive data-governance framework for the next-generation data economy, particularly during the MyData 2.0 stage.
I. The Core Connection: Different Paths Toward the Shared Goal of Ending the Failure of “Informed Consent”
Solove’s position and the MyData philosophy share a common target of criticism: the existing “notice-and-consent” model. Under this model, companies use privacy policies and user agreements to explain their data-processing practices to consumers. Once users click “Agree,” companies obtain permission to collect and use their data.
This system assumes that consumers can understand the terms, assess the risks, and anticipate the consequences of data use. In reality, consumers encounter large numbers of authorization pages every day. Privacy policies are usually lengthy, while data-processing activities involve multiple platforms, systems, and partner organizations. Individuals find it difficult to read every policy carefully or continuously track who retains their data, how those data are used, and how long they are stored.
Solove has described this problem as “privacy self-management and the consent dilemma.” He points out that relying on individual consent to manage privacy has clear limitations and that privacy law should not depend excessively on consumers’ personal choices.[3] The development of AI further magnifies those limitations. When users consent to a company’s collection of an ordinary piece of data, they have little way of knowing whether the company will combine it with other information or whether an algorithm will use it to infer sensitive information concerning health, religion, or political views.
In Solove’s view, companies satisfy formal notification requirements through lengthy privacy statements, while the actual burden of protecting privacy falls on consumers. When problems arise, companies may also justify their conduct by arguing that “the user already consented.” A user’s click of the consent button can show only that the user accepted the conditions presented at that time. It can hardly prove that the user understood every possible future use of the data or every inference that an algorithm might draw.
MyData criticizes the same model from the perspective of data-control structures. The current data ecosystem is centered on companies. Once users grant authorization, their personal data generally enter corporate servers, where companies retain, analyze, and use them over extended periods. Users have little ability to monitor the continuing flow of their data and lack practical means to modify permissions, stop data use, or transfer their data at any time.
MyData seeks to shift data governance from a company-centric model to a human-centric one, enabling individuals to access, manage, and use data concerning themselves and to understand how those data flow.[4] Users should be able to decide who may use their data and for what purposes, and to modify or withdraw those decisions in response to changing circumstances. In this way, personal data can be freed from the isolated silos of different corporate systems.
Solove focuses on companies’ use of “consent” to shift responsibility, while MyData focuses on individuals’ loss of meaningful control after they have “consented.” Together, these perspectives demonstrate that a one-time click of the consent button can no longer support privacy governance in the AI era. User authorization may constitute a condition for a company’s use of data, but it cannot serve as a basis for exempting the company from responsibility. A new governance model must strengthen both individuals’ continuing control and companies’ continuing responsibilities.
II. The Core Difference: A “Defensive Shield” and an “Empowerment Engine”
Solove and MyData place different emphases on possible solutions. Solove gives greater weight to risk prevention and corporate accountability. He argues that assigning responsibility for data control to consumers is deeply problematic because ordinary people have very limited attention, time, and professional expertise and cannot manage the complex risks created by AI-generated inferences.
Even when the law gives consumers more choices and consent buttons, users still struggle to identify discrimination, errors, and excessive analysis embedded in algorithmic design. Solove advocates using data minimization, technological review, algorithmic accountability, and legal liability to build a “defensive shield” for consumers. When companies’ use of data or AI algorithms creates an unreasonable risk of harm, they should bear the corresponding responsibility.
In his article, Solove draws on the historical experience of the food, pharmaceutical, and automobile industries. Food and automobiles once presented serious safety problems. Only after the law established systems for inspection, testing, and liability did companies acquire stronger incentives to improve product safety.[1] Under the same logic, digital technologies and AI should undergo privacy and safety reviews before being placed into use, and companies should be held accountable when their algorithms cause harm.
MyData places greater emphasis on individual empowerment, with the central objective of returning control over data to individuals. Through data portability rights and personal data stores, individuals can aggregate, manage, and use their own data and choose the parties to which those data will be provided according to specific needs. They can also restrict the scope of data use, stop data flows when necessary, or transfer their data to other services.
The MyData white paper describes this as a human-centric model for the use of personal data and emphasizes the construction of an interoperable data ecosystem in which individuals participate in exercising control.[4] Under this model, individuals are transformed from passive sources of data into active participants in data relationships. MyData is therefore more akin to an “empowerment engine,” focused on improving individuals’ ability to manage and use their data.
The two approaches also differ in the emphasis they place on the value of data. Solove focuses primarily on the risks associated with data, with the aim of reducing excessive corporate data collection and preventing algorithms from harming individuals.
MyData also recognizes the value of data as an asset and a factor of production, seeking to enable data to flow under conditions that are secure, transparent, and subject to individual control. Individuals can use their multidimensional data to obtain fairer credit assessments and more personalized services that better reflect their actual circumstances.
III. Building a Unified Framework: Deep Integration of Sovereignty and Accountability
Combining MyData with Solove’s approach to corporate responsibility can produce an integrated model consisting of “underlying autonomy, overarching accountability, and intelligent agents.” Within this framework, individuals possess meaningful control over their data, companies cannot use user consent to avoid responsibility, and technological tools help reduce the difficulty individuals face in managing their data.
The first component is the infrastructure layer, which establishes personal data sovereignty based on personal data stores. Users’ core behavioral data can be stored in personal data stores (PDSs) or corresponding decentralized nodes, reducing the unrestricted accumulation of data by centralized companies. At the same time, users possess direct, operational control over “cutting off data flows” and “porting and transferring data,” thereby implementing the “right to deletion” and the genuine control supported by Solove.
The second component is the regulatory baseline layer, which removes the liability-exempting effect of “consent.” “User consent” is no longer a justification for exempting companies from responsibility. Even when users authorize a company to use their data through MyData, the company must still bear strict legal responsibility if its AI algorithm produces discrimination—for example, by misusing nonfinancial data in credit-technology assessments—or makes out-of-scope inferences about sensitive information. This addresses Solove’s concern that “ordinary people cannot anticipate AI risks.”
The third component is the implementation and agency layer, consisting of AI-powered personal data fiduciaries. Solove argues that giving users control is unworkable because the technology is too complex. The key to resolving this contradiction is to use AI to counter AI. Under the unified framework, users do not need to read the terms personally. A “personal AI agent” embedded in the PDS system serves as a digital-era “lawyer” or “fiduciary.” Based on the user’s broad preferences, it automatically negotiates terms with companies’ AI systems and applies data-minimization filters.
The fourth component is the application layer, involving native data-driven credit technology and value assessment. Historically, the U.S. credit system of the 1970s and 1980s was “technology-driven,” having been built on early information-technology architectures. Today’s global innovations, particularly those in China, are instead natively “data-driven.” Under this unified framework, the development of modern credit technology, or CreditTech, will become healthier. Through MyData, users can aggregate their multidimensional data and use them to demonstrate their creditworthiness to B2B service providers or financial institutions. When institutions process those data, however, they must be subject to requirements such as the “pre-market algorithm review” advocated by Solove. This approach not only prevents unlawful inferences about sensitive information but also fully satisfies the demanding requirements of international financial standards, eliminating overly generalized and unprofessional labels.
Conclusion
Daniel J. Solove identifies an exceptionally important problem: we should not expect exposed and defenseless consumers to protect themselves. By combining his model of “strong accountability” with MyData’s model of “strong autonomy,” we can arrive at an ideal solution. MyData provides the tools and vault—the PDS—for managing data, while Solove’s accountability regime surrounds that vault with an impenetrable, high-voltage legal barrier. Under this unified framework, data can remain securely under individual control while also being used with confidence to support economic innovation in the AI era.
References
[1] Solove, Daniel J. “How Can We Protect Our Privacy in the Age of AI?” Chinese edition of The Wall Street Journal,
https://cn.wsj.com/articles/ai-privacy-laws-data-b272b29f?mod=cn_feature_1_pos_4.
[2] MyData Global. “MyData Declaration.” https://mydata.org/participate/declaration/.
[3] Daniel J. Solove, “Privacy Self-Management and the Consent Dilemma,” 126 Harv. L. Rev. 1880 (2013).
[4] Poikola, Antti, et al. MyData: An Introduction to Human-Centric Use of Personal Data. Third Updated English Edition, MyData Global, 2020.
Note: The author, Shanli Zhang, is a doctoral student at Shandong University Law School and a research assistant to Dr. Xinhai Liu. His research focuses on personal data and personal privacy protection. WeChat: 18811157736. Comments and corrections are welcome.

