The following editorial appears on Bloomberg Opinion.
Members of Congress are finally getting serious about protecting privacy online. If only they had some better ideas on how to do so.
The latest entrant is a bill sponsored by Sens. Josh Hawley, R-Mo., and Mark Warner, D-Va. Among other things, it would require big tech platforms such as Facebook and Google to tell users how much money their personal information generates and disclose how much their data is worth in aggregate.
At first glance, this seems promising. Much of the digital economy is built on a trade-off: Consumers get free services — email, maps, social media — in return for divulging their data. Yet there’s significant evidence that they don’t fully understand this exchange. They routinely tell pollsters they care about privacy even while using services that blithely violate it.
In theory, if consumers knew how much their data was worth, they could make better decisions about what information they give up and what goods or services are worth the risk. In reality, though, they’ll have no idea what to do with this added transparency. They’re already overloaded with information about how online services employ their data. Adding another meaningless statistic will hardly help. The implication is that users should be compensated above and beyond the free services they already receive, yet none of the targeted companies will be writing checks any time soon.
One of the great benefits of the data-for-services exchange is that — unlike with cash — a given user’s data is in inexhaustible supply. It can be shared again and again, across different services, in perpetuity. Breaking that model in favor of one preferred by Congress is in no one’s interests.
More to the point, placing a value on data is hard. Only when aggregated and analyzed at scale can it generate revenue. Companies often put the same data sets to multiple uses — serving ads, improving performance, testing new designs or products — and then attempt to derive insights from all of it. That process resists easy quantification.
The bill directs the Securities and Exchange Commission to “develop methodologies for calculating data value” and to “enable businesses to adopt methodologies that reflect the uses, sectors and business models.” That’s a recipe for boundless red tape and a needless imposition on the agency. At best, it would produce an arbitrary figure with no obvious purpose.
A far better approach is to shift the burden of managing data from users to companies in a way that doesn’t destroy the latter’s business models. One promising method is to offer an “information fiduciary” standard. Such fiduciaries would be prohibited from handling data in ways that harmed their users. Congress could establish a set of best practices for companies to follow, and those that agreed could be offered a federal preemption from state and local privacy laws.
In this way, consumers would know if their data was in good hands without needing an engineering degree. Companies would have an incentive to behave. And Congress could otherwise occupy itself. Everybody wins.