FREEDOM ON
THE NET 2023
The Repressive Power
of Artificial Intelligence
4. SAFEGUARD PERSONAL DATA
Comprehensive data protection regulations and industry policies on data protection are essential for upholding privacy and
other human rights online, but they require careful crafting to ensure that they do not contribute to internet fragmentation—
the siloing of the global internet into nation-based segments—and cannot be used by governments to undermine privacy and
other fundamental freedoms.
Governments
Democracies should collaborate to create interoperable privacy regimes that comprehensively safeguard user information, while
also allowing data to flow across borders to jurisdictions with similar levels of protection. Individuals should be given control
over their information, including the right to access it, delete it, and easily transfer it to the providers of their choosing. Laws
should include guardrails that limit the ways in which private companies can use personal data for AI development and in their
AI systems, including algorithmic recommendations. Updated data-privacy protections should feature provisions that grant
independent regulators and oversight mechanisms the ability, resources, and expertise to ensure compliance by foreign and
domestic companies with privacy, nondiscrimination, and consumer-protection laws.
The US Congress should urgently pass a comprehensive federal law on data privacy that includes data minimization, the principle that
personal information should only be collected and stored to the extent necessary for a specific purpose, and purpose limitation, the
principle that personal data gathered for one purpose should not later be used for another. This is especially relevant for discussions
around generative AI and other technologies that depend on harvesting information online without people’s consent.
In the absence of congressional action, the US Federal Trade Commission (FTC) has been working to address these concerns
through new regulations on commercial surveillance and data security. While an Advance Notice of Proposed Rulemaking was
announced over a year ago, the process will not be completed for at least another year. In the meantime, Congress should
ensure that the FTC has sufficient resources to develop and enforce meaningful regulations related to data protection.
In addition to the FTC’s action, this year the Consumer Financial Protection Bureau (CFPB) announced proposed rulemaking
under the Fair Credit Reporting Act, with the aim of holding the data broker industry accountable for the misuse of personal
information. Among other principles, the CFPB should prioritize data minimization in its new regulations.
Companies
Companies should minimize the collection of personal information, such as health, biometric, and location data, and limit how
third parties can access and use it. Companies should also clearly explain to people who use their services what data are being
collected and for what purpose, including what information may be collected from user prompts to generative AI services.
Finally, companies should ensure that people who use their services have control over their own information, including the right
to access it, delete it, and prevent it from affecting an algorithm’s behavior.
5. PROTECT A FREE AND OPEN INTERNET
A successful defense of the free, open, and interoperable internet will depend on international cooperation and a shared
vision for global internet freedom. Democracies should live up to their own values at home in order to serve as more credible
advocates for internet freedom abroad. Freedom House research shows that governments learn from one another, with
leaders in less free countries often pointing to the problematic actions of democratic states to justify their repressive policies.
Democratic governments everywhere have an opportunity to set a positive example by effectively tackling the genuine
challenges of the digital age in a way that strengthens human rights and the global internet.
34
@freedomonthenet
#FreedomOnTheNet