Essays
Papers and Effects, Restored
A few weeks ago I wrote about the database of ruin, the machine assembling itself out of cameras, phones, and purchase records into a single ledger that holds something ruinous about everyone alive. I ended that piece the way most privacy writing ends, with a warning and a question: whether we still recognize the general warrant well enough to refuse it a second time. A reader asked, fairly, what refusing it actually looks like. Not the mood. The mechanism. Here is an attempt at one.
Start with the assumption sitting underneath every case study in that essay, an assumption so old nobody bothers to state it anymore. When a camera on a pole photographs your license plate, the photograph belongs to whoever owns the camera. When your phone reports its location to a tower, the log belongs to the carrier. When a company scans your face to unlock a door, the faceprint belongs to the company. Nobody voted for this rule. Nobody argued for it against an alternative and won. It fell out, by default, from who happened to hold the recording device, and every fight since then, over consent forms, retention windows, audit trails, has been a fight to soften the edges of a rule nobody chose in the first place. Soften it enough and you get Sold as Local Control, thirty days instead of forever, a promise instead of a wall. The rule itself never moves.
Flip it. Suppose the law said the opposite: that a fact describing a particular, identifiable person, their face, their plate, their location, their body, belongs to that person the moment it is recorded, regardless of who owns the device that recorded it. Everything downstream changes. This has been proposed before, several times, by serious people, and each version broke on a different rock. Worth knowing which rocks before building the next boat.
Paid for it is not the same as asked first
Jaron Lanier made the first serious run at this, in a book called Who Owns the Future?, and the idea he landed on was called data dignity. Platforms he named siren servers, Facebook, Google, the rest, were extracting a person’s clicks, photos, and habits for free and building enormous companies on top of them, and the fix he proposed was to pay for it. Treat data as labor. Eric Posner and Glen Weyl picked up the same thread in Radical Markets and gave it an economic frame: a labor movement for the data economy, people organizing the way factory workers once did to get paid for what they produce.
Andrew Yang tried to turn the idea into policy with the Data Dividend Project, built around California’s own consumer privacy law, and here the idea met its first real test. The dividend that survived contact with an actual legislature was a tax so small that critics agreed on almost nothing else that year except that it was, in one reporter’s phrase, not radical, just useless. A company with a market value larger than most countries absorbs a rounding error and keeps doing exactly what it was doing.
The deeper problem is not the size of the check, though. It is what cashing it means. Data as labor treats the taking as legitimate and prices the transaction, the way a mine owner and a miner argue over a wage rather than over whether the mountain should be dug up at all. Apply that logic to a license plate reader and the strangeness shows immediately. Nobody parked outside their own house wants a royalty statement for the plate scan. They want the camera not aimed at their driveway without a reason. Compensation answers a question nobody driving to work actually asked. The question was never what my movements are worth. It was who gets to record them in the first place.
A duty the fox writes for the henhouse
Jack Balkin and Jonathan Zittrain took a different approach, borrowed from an older and more settled part of the law. A doctor owes a patient confidentiality, care, and loyalty, not because the patient wrote it into a contract but because the law imposes it on anyone who holds that kind of power over another person. Balkin proposed treating platforms the same way: information fiduciaries, bound by the same duties, obligated by statute to act in a user’s interest rather than merely disclosing when they have not.
It is a serious idea, and it still fails for a simple reason. A fiduciary duty needs someone checking whether it was honored, and in Balkin’s own model that someone is very often the fiduciary itself, filling out its own compliance report. Lina Khan and David Pozen wrote the sharpest reply, arguing that dressing a voluntary code of conduct up as a fiduciary obligation manages the appearance of protection more than the substance of it. I made almost the identical argument about a license plate company’s audit log, a record written by the party being audited, reviewed on a schedule the reviewed party sets, published through a portal one of Flock’s own customer success managers admitted in writing was functionally useless. A duty the fox is trusted to enforce against himself is not a duty. It is a brochure with a citation attached.
The one place this has actually worked
One version of this has actually worked, not in theory but in courtrooms, for a specific reason the other two did not share. Illinois passed the Biometric Information Privacy Act in 2008, requiring written consent before anyone collects a fingerprint, a faceprint, or a voiceprint, forbidding the sale of that data outright, and letting the individual whose biometric was taken sue directly, without waiting for a regulator to notice or care. Facebook paid six hundred fifty million dollars over a photo tagging feature that scanned faces without consent. Clearview AI, which scraped billions of photos to build a searchable face database, is still settling BIPA claims years later, most recently by handing plaintiffs an equity stake in the company. None of that happened because a regulator inspected a server. It happened because an individual held a right and used it.
BIPA also shows the failure mode a property right falls into when it is built carelessly. In 2023 the Illinois Supreme Court ruled, in Cothron versus White Castle, that every single fingerprint scan, not every relationship with a company, counted as a separate violation, which put a fast food chain whose employees clocked in with a thumbprint on the hook for damages a dissenting justice called annihilative: as much as seventeen billion dollars over what was, whatever else it was, not a seventeen billion dollar harm. The legislature fixed it the following year, capping recovery at one violation per person rather than one violation per scan. The lesson is not that private rights of action are too dangerous to grant. It is that they have to be built to punish the taking, not multiplied by how many times a machine happened to click.
What a badge cannot buy from a boardroom
None of this reaches the actual subject of the database of ruin, because BIPA is a consumer protection statute aimed at companies, and the machine on the pole outside your house is very often run by, or for, a government. A property right against Facebook does not touch a police department. The Fourth Amendment, not a state privacy statute, is the document written specifically to restrain that actor.
For decades the reigning rule there was the third party doctrine, set down in Smith versus Maryland and United States versus Miller, holding that information voluntarily shared with a bank or a phone company carries no reasonable expectation of privacy, because you already handed it to someone else. That is the exact route around the Fourth Amendment I named in the database of ruin: the corporate laundromat, the government buying what it may not seize because a private company already holds it.
The doctrine has already begun to crack under the weight of what modern data actually is. In United States versus Jones, in 2012, the Court held that attaching a GPS tracker to a car was a search, and Justice Sotomayor’s concurrence went further than the majority needed to, suggesting that even short term tracking might qualify and that the whole third party doctrine deserved a second look in a world where sharing a phone’s location with a carrier is not voluntary in any sense that matters. Six years later, in Carpenter versus United States, the Court took the next step and made it a holding rather than a suggestion, ruling that historical cell site location records, an exhaustive log of where a person’s phone had been for months, required a warrant despite being held by a third party carrier, because there is, in the Court’s own words, a world of difference between the old business records the doctrine was built for and an encyclopedic chronicle of a person’s movements collected without a single voluntary act on their part.
That is the crack the flip walks through. Carpenter treated a person’s location history as close enough to their papers that the government needs a judge’s permission to read it. A license plate scanned by a camera on a public pole is the same fact by another instrument: a chronicle of where a car has been, indefinitely retained, searchable by a login. A doctrine that already bent for a cell tower has no principled reason to hold firm for a pole.
The flip, stated plainly
Put the pieces together and the proposal is not exotic. It borrows one working part from each failed attempt and drops the rest.
First, ownership by default. A fact that describes a particular person’s identity, face, voice, fingerprint, or location belongs to that person the instant it is recorded, regardless of who owns the camera, the pole, or the server it lands on. Not licensed to them. Not shared with them through a portal. Owned, the way BIPA already treats a fingerprint, extended to cover the plate, the face, and the trail of location points a network of cameras assembles into a map of a life.
Second, a non-alienable core. A person may license a specific, time-boxed, named use of their own data, the way a homeowner might let a security company keep a doorbell recording for thirty days to help catch whoever tried the handle. What they cannot do is sign away the underlying ownership permanently in the small print of a contract nobody reread, the way Flock’s own terms of service quietly dropped its promise never to sell customer data and replaced it with a perpetual license to keep using it anyway. Samuelson’s objection to propertizing privacy is correct as far as it goes: property is ordinarily alienable, and an alienable right to your own face will be traded away for a coupon the first week it exists. The answer is not to abandon ownership. It is to make this one corner of it inalienable, the same way the law already refuses to enforce a contract selling yourself into indefinite servitude no matter how willingly you signed it.
Third, a private right of action with damages calibrated to the taking, not the machine’s click rate. White Castle’s near miss is the cautionary tale, and the fix already exists in statute: one recovery per person per violation of the right, not one recovery per scan. Big enough to make ignoring the right to exclude cost more than respecting it. Small enough that a company is punished for what it did, not multiplied into bankruptcy by how many times a server happened to run.
Fourth, and this is the piece none of the commercial proposals reach, a warrant requirement that follows the ownership across the line into government hands. If the data is a person’s papers, Carpenter’s own logic already supplies the rule: the government needs a warrant naming the person and the cause, the same as it would to search a house, before it may compel a private party to hand over what it was never entitled to seize directly. Not an opt out. Not a retention policy a city council votes on that a vendor’s next terms of service revision can quietly outrun. A rule of constitutional weight, the kind neither an engineer nor a police chief’s good intentions can toggle off in a settings menu.
Self-enforcing beats supervised
Compare this to the alternative most privacy advocates reach for, a permission bureaucracy on the model of Europe’s GDPR: an agency that certifies consent forms, audits compliance, and fines violators out of a fund the state controls. That model requires believing the regulator will always want to do its job, will never be captured by the industry it oversees, and will never be underfunded, understaffed, or quietly on a vendor’s side the way the departments in Sold as Local Control kept discovering their own contractor was. It substitutes one permanent watcher for another and asks you to trust the new one more than the old.
A genuine property right does not need that faith. Its owner enforces it herself, whenever she chooses, in a courtroom that does not answer to the industry it is judging. That is the libertarian answer to the database of ruin: not a bigger agency watching the watchers, but a right small enough for one person to hold and use without anyone’s permission, the same reason a deed to a house needs no regulator standing in the yard. Self-enforcing beats supervised, because supervision can be captured, and a right held individually cannot be bought off in bulk.
What was already written
None of this requires a new amendment or a new philosophy. The words are already sitting in the Fourth Amendment: persons, houses, papers, and effects, written by men who could not have imagined a camera that never blinks or a database that never forgets, but who understood exactly why a government must never be allowed to search everyone in advance on the chance that something turns up. A license plate log is a paper. A faceprint is an effect. The Constitution already calls these things what they are. The only question left is whether the law says so before the next camera goes up on the next pole, or whether we wait, as we always seem to, for an audit to tell us what we already owned.
Sources
- Wikipedia: Who Owns the Future?
- DeGruyter: Data as Labor (Radical Markets)
- Vice: Andrew Yang’s Data Dividend Isn’t Radical, It’s Useless
- Tech Policy: Zittrain and Balkin Propose Information Fiduciaries
- Harvard Law Review: A Skeptical View of Information Fiduciaries
- ACLU of Illinois: Biometric Information Privacy Act (BIPA)
- TechCrunch: Facebook will pay $650 million to settle BIPA class action
- ACLU: Settlement Ensures Clearview AI Complies With Illinois Biometric Privacy Law
- National Law Review: The $17 Billion Slider? Illinois Supreme Court Decides White Castle BIPA Case
- Jackson Lewis: Illinois Supreme Court Issues Long-Awaited BIPA Decision in Cothron v. White Castle
- Justia: Smith v. Maryland, 442 U.S. 735 (1979)
- Wikipedia: United States v. Miller (1976)
- UNC School of Government: The Supreme Court on GPS Tracking, U.S. v. Jones
- Hunton: Supreme Court Holds Warrant Required for Historical Cell Phone Location Information