Part IV

DRA Feasibility

The technical groundwork already exists. Six working precedents, running at scale today.

849 words · 4 min

The associational data rights framework allows for dynamic flexibility in adapting new terms and verification mechanisms to rapid technological changes and data practices. Many of the same new technologies which in our current digital economy threaten digital sovereignty and community also make it more feasible to manage the complexity of associational data rights.

Data principals should have the ability to seamlessly join DRAs by opting into terms across the devices and services they regularly interface with. A principal should be able to join one or more DRAs that represent his values and his digital interests, but without having to manually search and opt into terms for every individual app and device. They should be able to state once, in plain words, their data governance interests, and trust agents and DRAs to faithfully advance those interests wherever applicable.

Technical feasibility. New techniques make several of these tasks and functions easier than they once were. For example:

  • Portable profiles. These could enable people to specify their privacy, control, and economic interests once, in plain language, and transmit them from one DRA to the next without the need to re-enter them for each DRA or digital service. Researchers have specified a user-owned, interoperable preference layer of exactly this kind, titled the Human Context Protocol, through which individuals articulate their preferences once and carry them across AI services.1 And Apple, Google, and Meta already jointly operate open-source infrastructure that moves user data directly between competing services at a user's request.2

  • Background enrollment agents. Software that reads those preferences and acts on them, automatically matching a person with the right DRA, and flagging changes in terms. This removes the manual work that would otherwise create friction. A working precedent that operates at scale today is the Global Privacy Control, a browser signal that transmits a person's opt-out preference automatically to every website they visit.3 California law requires businesses to honor it and the state's attorney general has already enforced it.4 As of mid-2026, twelve states require covered businesses to honor universal opt-out preference signals such as the Global Privacy Control.5

  • Agentic systems for trust-governed identity and discovery. Emerging technical architecture for ensuring that personal AI agents can trust a third-party agent with a human principal's data, such as OpenAgenet, could enable the frictionless exercise of associational data rights at scale.6

  • Cryptographic attestation. A platform can produce mathematical proof that it handled data according to the agreed rules, so a DRA can verify compliance instead of taking the platform's word for it. Apple's Private Cloud Compute already does this at consumer scale. Before an iPhone will send a user's data to Apple's AI servers, each server must cryptographically prove that it is running publicly inspectable software, logged in a tamper-evident registry open to outside researchers.7

  • Privacy-preserving auditing. Federated learning (FL) and secure multi-party computation (SMPC) would allow data to be analyzed without being copied or exposed, enabling DRAs to audit how member data is used without breaching security or privacy. Google has trained its mobile keyboard models leveraging FL across hundreds of millions of phones since 2017.8 Ten competing pharmaceutical companies jointly trained drug-discovery models on more than 2.6 billion confidential data points using FL without any firm seeing another's data.9 And Greater Boston employers have for a decade computed citywide wage-gap statistics using SMPC covering roughly one in six area employees without disclosing a single individual salary record.10 These examples are drawn from a much larger record kept by the United Nations and the UK government, each of which maintain public registries cataloging real-world deployments of privacy-preserving computation.11

  • Verified membership. A DRA's bargaining power depends on the size and authenticity of its membership, which bad actors could otherwise inflate with fake or automated accounts. Personhood credentials allow individuals to prove they are real people without disclosing any personal information enabling DRAs to certify their membership rolls, and platforms to trust them, while preserving member privacy.12

Consider how these pieces fit together in practice. Suppose a DRA organized around family life negotiates terms providing that member conversations with a platform's AI assistant may not be used to train AI companions designed to simulate intimate human relationships. Under today's architecture, the DRA could do little more than take the platform's word for it. Under the architecture described above, compliance is verifiable. The platform runs its training systems in an attested environment that proves which software and which data sources fed which models and the DRA conducts periodic privacy-preserving audits confirming that member conversations are absent from the restricted training corpora, without the platform surrendering proprietary systems and without the DRA ever accessing raw member records.13 A verified breach then triggers the remedies described in Part III.

While these technologies and methods hold promise for making DRA ecosystems technically feasible and seamless for the average data principal, ADRACA is tech neutral. It would create the governance model and incentive structures to allow the necessary sociotechnical institutions to emerge organically. This will ensure that DRAs and related institutions are able to quickly adapt to rapid changes in data collection, use, and technology.

Footnotes

  1. Anand V. Shah, Tobin South, Talfan Evans, Hannah Rose Kirk, Jiaxin Pei, Andrew Trask, E. Glen Weyl & Michiel A. Bakker, Robust AI Personalization Will Require a Human Context Protocol (September 2025), https://ssrn.com/abstract=5403981.

  2. Data Transfer Initiative, https://dtinit.org (last visited Aug. 5, 2026) (nonprofit founded by Apple, Google, and Meta to operate the open-source Data Transfer Project, which connects more than a dozen major services for direct user-initiated data transfers).

  3. Global Privacy Control, https://globalprivacycontrol.org (last visited Aug. 5, 2026).

  4. Press Release, Cal. Dep't of Justice, Attorney General Bonta Announces Settlement with Sephora as Part of Ongoing Enforcement of California Consumer Privacy Act (Aug. 24, 2022), https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-settlement-sephora-part-ongoing-enforcement.

  5. California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. See Colo. Rev. Stat. § 6-1-1306(1)(a)(IV); Colorado Dep't of Law, Universal Opt-Out and the Colorado Privacy Act, https://coag.gov/opt-out/ (last visited Aug. 5, 2026) (maintaining the state's public list of recognized opt-out mechanisms, of which the Global Privacy Control was the first); Universal Opt-Out Mechanisms and Global Privacy Control: State Law Requirements and Compliance Guidance, Tannenbaum Helpern Syracuse & Hirschtritt LLP (Mar. 2026), https://www.thsh.com/publications/universal-opt-out-mechanisms-and-global-privacy-control-state-law-requirements-and-compliance-guidance/; Global Privacy Controls: Preparing for the Next Wave of Enforcement, Foster Garvey (Apr. 2026), https://www.foster.com/newsroom/legal-alerts/global-privacy-controls-preparing-for-the-next-wave-of-enforcement/ (noting a coordinated California–Colorado–Connecticut enforcement sweep against businesses failing to honor GPC signals).

  6. Jinliang Xu, OpenAgenet / OAN White Paper: Open Infrastructure for Trusted Agent Interconnection, arXiv:2606.03161 (June 2026), https://arxiv.org/abs/2606.03161.

  7. Apple Security Engineering & Architecture, Private Cloud Compute: A New Frontier for AI Privacy in the Cloud, Apple Security Research Blog (June 10, 2024), https://security.apple.com/blog/private-cloud-compute/; see also Apple, Private Cloud Compute Security Guide, https://security.apple.com/documentation/private-cloud-compute (last visited Aug. 5, 2026) (documenting the attestation architecture and the virtual research environment through which outside researchers verify Apple's claims).

  8. Brendan McMahan & Daniel Ramage, Federated Learning: Collaborative Machine Learning Without Centralized Training Data, Google Research Blog (Apr. 6, 2017), https://research.google/blog/federated-learning-collaborative-machine-learning-without-centralized-training-data/; Yuanbo Zhang et al., Private Federated Learning in Gboard, arXiv:2306.14793 (2023).

  9. MELLODDY: Cross-Pharma Federated Learning at Unprecedented Scale Unlocks Benefits in QSAR Without Compromising Proprietary Information, J. Chem. Inf. & Modeling (2024), https://pubs.acs.org/doi/10.1021/acs.jcim.3c00799; see also MELLODDY, Year 3 Announcement (July 13, 2022), https://www.melloddy.eu/y3announcement.

  10. Boston Women's Workforce Council, Data Privacy, https://thebwwc.org/mpc (last visited Aug. 5, 2026); UN Comm. of Experts on Big Data & Data Science for Official Statistics, Boston Women's Workforce Council: Measuring Salary Disparity Using Secure Multi-Party Computation, https://unstats.un.org/wiki/spaces/UGTTOPPT/pages/150012020 (last visited Aug. 5, 2026).

  11. UN Comm. of Experts on Big Data & Data Science for Official Statistics, PETs Case Study Repository, https://unstats.un.org/bigdata/task-teams/privacy/case-studies/ (last visited Aug. 5, 2026) (collecting the eighteen production and pilot deployments documented in Chapter 3 of the 2023 UN Guide on Privacy-Enhancing Technologies for Official Statistics); UK Gov't, Repository of Privacy Enhancing Technologies (PETs) Use Cases, https://www.gov.uk/guidance/repository-of-privacy-enhancing-technologies-pets-use-cases (last visited Aug. 5, 2026).

  12. Steven Adler, Zoë Hitzig, Shrey Jain et al., Personhood Credentials: Artificial Intelligence and the Value of Privacy-Preserving Tools to Distinguish Who Is Real Online, arXiv:2408.07892 (2024).

  13. For the general framework combining these techniques into end-to-end verifiable data governance, see Andrew Trask, Emma Bluemke, Ben Garfinkel, Carlos Ghezzou Cuervas-Mons & Allan Dafoe, Beyond Privacy Trade-offs with Structured Transparency, arXiv:2012.08347 (2020).