FREEDOM ON THE NET 2023 The Repressive Power of Artificial Intelligence 4. SAFEGUARD PERSONAL DATA Comprehensive data protection regulations and industry policies on data protection are essential for upholding privacy and other human rights online, but they require careful crafting to ensure that they do not contribute to internet fragmentation— the siloing of the global internet into nation-based segments—and cannot be used by governments to undermine privacy and other fundamental freedoms. Governments Democracies should collaborate to create interoperable privacy regimes that comprehensively safeguard user information, while also allowing data to flow across borders to jurisdictions with similar levels of protection. Individuals should be given control over their information, including the right to access it, delete it, and easily transfer it to the providers of their choosing. Laws should include guardrails that limit the ways in which private companies can use personal data for AI development and in their AI systems, including algorithmic recommendations. Updated data-privacy protections should feature provisions that grant independent regulators and oversight mechanisms the ability, resources, and expertise to ensure compliance by foreign and domestic companies with privacy, nondiscrimination, and consumer-protection laws. The US Congress should urgently pass a comprehensive federal law on data privacy that includes data minimization, the principle that personal information should only be collected and stored to the extent necessary for a specific purpose, and purpose limitation, the principle that personal data gathered for one purpose should not later be used for another. This is especially relevant for discussions around generative AI and other technologies that depend on harvesting information online without people’s consent. In the absence of congressional action, the US Federal Trade Commission (FTC) has been working to address these concerns through new regulations on commercial surveillance and data security. While an Advance Notice of Proposed Rulemaking was announced over a year ago, the process will not be completed for at least another year. In the meantime, Congress should ensure that the FTC has sufficient resources to develop and enforce meaningful regulations related to data protection. In addition to the FTC’s action, this year the Consumer Financial Protection Bureau (CFPB) announced proposed rulemaking under the Fair Credit Reporting Act, with the aim of holding the data broker industry accountable for the misuse of personal information. Among other principles, the CFPB should prioritize data minimization in its new regulations. Companies Companies should minimize the collection of personal information, such as health, biometric, and location data, and limit how third parties can access and use it. Companies should also clearly explain to people who use their services what data are being collected and for what purpose, including what information may be collected from user prompts to generative AI services. Finally, companies should ensure that people who use their services have control over their own information, including the right to access it, delete it, and prevent it from affecting an algorithm’s behavior. 5. PROTECT A FREE AND OPEN INTERNET A successful defense of the free, open, and interoperable internet will depend on international cooperation and a shared vision for global internet freedom. Democracies should live up to their own values at home in order to serve as more credible advocates for internet freedom abroad. Freedom House research shows that governments learn from one another, with leaders in less free countries often pointing to the problematic actions of democratic states to justify their repressive policies. Democratic governments everywhere have an opportunity to set a positive example by effectively tackling the genuine challenges of the digital age in a way that strengthens human rights and the global internet. 34 @freedomonthenet #FreedomOnTheNet

Select target paragraph3