Skip to content

Part 2: Is Data Privacy Dead? The Answer Must be No

  • by

Photo by lilartsy.

Claire McKay Bowen and Aaron R. Williams


An ex-DOGE member reportedly stole two Social Security databases that “…include records for more than 500 million living and dead Americans, including Social Security numbers, places and dates of birth, citizenship, race and ethnicity, and parents’ names.” At the same time, mounting evidence suggests that ICE is using social media and other available data to target people.

While individuals can and should take steps to protect themselves, these examples show how our current system for safeguarding data and ensuring the data are used only for public good is falling short. Preserving our data privacy requires updating the laws and regulations on how our data are collected and used.

It’s about regulation and governance.

Although we can individually manage some of our information by being mindful of what we share (as discussed in Part 1), many aspects of data collection are outside of our direct control. For that reason, our government must be responsible—both in the laws it sets for public and private data and its own data handling practices—for how our data are collected, stored, shared, and used. Unfortunately, those laws and practices appear to be lagging behind the needs of the public.

Although new technologies and associated risks are rapidly evolving, such as the widespread use of AI, there is no single federal law that comprehensively covers data privacy and confidentiality. While the Privacy Act of 1974 serves as a backbone, there is a patchwork of laws in the United States that each attempt to address an aspect of privacy, confidentiality, and security of personal data. The laws we have are often limited to specific federal agencies (e.g., Title 13 confidentiality protections for data at the U.S. Census Bureau) or specific data types (e.g., Family Educational Rights and Privacy Act privacy and confidentiality protections for education records).

Gaps in the patchwork, including the lack of a federal-level consumer data privacy law, have allowed the multibillion-dollar data broker industry to flourish with little to no regulation. Furthermore, our foundational laws, like the Privacy Act of 1974, were created long before personal computers, the internet, smartphones, and social media. In fact, more than a decade ago the Government Accountability Office noted that advances in technology had “rendered some of the provisions of the Privacy Act and the E-Government Act of 2002 inadequate to fully protect all personally identifiable information collected, used, and maintained by the federal government.” And yet, despite some amendments, the Privacy Act of 1974 has remained substantially the same for more than 50 years. Some states have worked to bolster their state data privacy laws, but those laws don’t cover every state and may be preempted by federal law.

So far, we’ve described what’s outdated or missing in privacy laws, but not what would be “good” laws and regulations. A strong, comprehensive data privacy law should reflect widely accepted principles such as those outlined in the APDU Guiding Principles on Privacy and Ethics. In practice, this means requiring that data be used to benefit the public without harming individuals, with clear accountability for how and why data are collected and used. People should be able to access and correct their data—and in some cases have that data deleted. Laws should mandate transparency, informed consent, and clear limits on data use, including ensuring that statistical data are not repurposed for other uses. They should also require modern privacy protections, clear access tiers, and strong ethical standards for data users. When tradeoffs are unclear, privacy should come first.

It’s not just about now. It’s also thinking about the future.

Although headlines may suggest that the idea of “data privacy” is dead, and our current system seems bleak, all hope is not lost. It is possible to establish new, comprehensive privacy legislation that incorporates strong data governance. Organizations like professional societies, non-profits, and advocacy groups are pushing for better laws and regulations.

This isn’t about whether your privacy or my privacy is dead at the moment. It is about how our information can and should be used for the public good—for us and for our society—now and in the future. Continuing to lose ground now will only make it harder for those who come after us.

What can I do?

Call your representatives, comment on Federal Register notices seeking public input on data privacy laws and regulations, and support advocacy groups working toward comprehensive privacy legislation. Help people understand how strong data privacy laws benefit all of us by ensuring that those who hold our data treat it—and the people represented in the data—fairly.