The Great Data Grab

 

From data brokers and advertisers to law enforcement and government agencies, countless actors can access our personal data. GW experts argue that stronger privacy protections are urgently needed in a world built on constant connectivity. 

Story // Katherine Shaver

 

 

 

 

Every day, you leave behind a personal digital trail easily accessed by police, governments, companies and anyone else willing to pay for it.

Your smartwatch records every step and heartbeat of your morning workout. A GPS company tracks your driving commute, while roadside cameras could capture your license plate. Over lunch, you might research that weird rash on your leg, browse the latest headlines, or hit “like” on a friend’s beach vacation photos. When you arrive home, your TV will know what you watch and for how long.

By bedtime, your 16-hour day will have fed the digital dossier that details your habits, whereabouts, relationships, health, even your favorite ice cream flavor and preferred hemorrhoid cream.

As the amount of personal data generated continues to soar, George Washington University experts are at the forefront of international discussions about how to better protect consumers’ privacy. They’ve testified before Congress, consulted with top officials in U.S. federal agencies and the European Union and helped state lawmakers think through legislation. GW faculty and their students are also wrestling with these issues in privacy and technology law courses offered by the Center for Law & Technology: The Bernard Center.

Their scrutiny comes as our online data becomes increasingly intimate, with smart phones, health apps and wearable devices logging everything from how well we sleep to when a person can expect their next period. Meanwhile, the proliferation of security cameras and facial recognition software in public areas has expanded governments’ powers of surveillance.

Turbocharging their long-running concerns is the ever-growing sophistication of artificial intelligence to quickly interpret reams of data in ways not previously imagined.

“I think people should be very worried right now,” said Daniel J. Solove, the Bernard Professor of Intellectual Property and Technology Law at GW Law and author of the 2025 book, “On Privacy and Technology.”

“We’re really in an unprecedented situation,” Solove said. “An enormous amount of personal data is being gathered. It’s being used in ways that are increasing and are having a tremendous impact on people’s lives.”

Meanwhile, federal and state laws needed to regulate how data may be collected, stored and used lag far behind advances in technology, Solove and other GW experts say.

GW Law professor Andrew Guthrie Ferguson said the U.S. needs more safeguards.

Ferguson, who teaches criminal law and procedure, recently published a book, “Your Data Will Be Used Against You,” which explores how everyday digital technologies are reshaping privacy, policy and civil liberties. Without safeguards, he said, authorities can use personal data to spy on immigrants, protesters, journalists, scientists or anyone else the government deems to be a threat or criminal.

“If you have a cell phone,” Ferguson said, “you’re basically carrying a tracking device everywhere you go.”

The problem affects all ages and spans the political spectrum.

Children’s data can be used to target them for advertising and train algorithms aimed at keeping them glued to social media platforms.

Prosecutors seeking to enforce a state’s abortion laws could theoretically use a woman’s “abortion clinic near me” Google search as evidence against her.

Gun owners could theoretically find themselves on a government gun registry simply because a license plate reader recorded their car outside a gun shop or gun show.

Without more effective legal guardrails, Ferguson said, “anyone’s data can be used against them.”  

 

 

Image
Daniel J. Solove

 

 

“We're really in an unprecedented situation. An enormous amount of personal data is being gathered.”
Daniel J. Solove

GW Law

 

 

""

 

Questions about personal data—and how much it should be protected—date back to the late 1960s, when governments and companies began to increasingly use computers to process everything from military records to personnel files in searchable systems.

Since then, the digital age has relied on an arrangement of convenience: Consumers, whether fully aware or not, consent to tech companies selling their personal data in exchange for easy, and often free, access to everything from web searches to weather forecasts.

That business model, known as “surveillance capitalism,” leaves consumers vulnerable to tech companies financially incentivized to collect and sell their information, said Susan Ariel Aaronson, a GW research professor of international affairs who directs the Institute for International Science and Technology Policy and the Digital Trade and Data Governance Hub. The Hub maps the governance of data in the U.S. and other countries and how governance can affect AI.

Tech firms often sell customer information to “data brokers,” which compile data from public records, shopping habits and other online activity and sources to build detailed digital profiles of individuals. The brokers, in turn, sell these “digital dossiers” to marketing and advertising firms, insurance companies, political parties and campaigns, law enforcement agencies and anyone else seeking to sell products, assess risk or find people.

Most of the information is sold in bulk but can include people’s names, Social Security numbers, past addresses, employment history and other personal information.

“The problem,” Aaronson said, “is you lose control over your data.”

Solove has highlighted how Target sent baby product ads to certain women after its algorithm predicted they were newly pregnant, based on their buying certain vitamin supplements, unscented soap and other products.

U.S. laws intended to protect consumers’ data privacy have proven largely ineffective, Solove said. They typically require individuals to opt out of sharing their data—an approach known as “notice-and-choice.”

But many people assume, incorrectly, that any data they consent to share will be used only by that app or website, he said. Most who encounter multiple pages of confusing, tiny-type legalese simply agree and move on.

“No one reads the privacy notices before consenting,” Solove said. “It’s like ‘Hey, you can read War and Peace—or you can click ‘accept.’”

Even if we agree to share our data with specific companies and apps, we often don’t get to choose—or even know—how it’s used by law enforcement, Ferguson said.

He points to an Ohio man accused of arson in 2017 after investigators obtained a warrant for his pacemaker data; authorities argued that his heart activity contradicted his claim that he was sleeping when a fire started in his home. (The man died while awaiting an appellate court ruling on whether the pacemaker data could be used at his trial.)

People who think they have nothing to hide as a law-abiding citizen still have reason for concern, Ferguson said. That’s because authorities who abuse their power could use personal data to punish, embarrass or silence protesters, people critical of the government and groups that have faced racial or religious discrimination, he said.

According to a recent Washington Post analysis, at least 50 law enforcement officers have been accused of misusing license-plate readers for unauthorized purposes; more than half of those were accused of using the technology to spy on wives, girlfriends, exes, or others they were romantically interested in or connected to.

“The default in a free society should be to live free from government surveillance until there is a good reason to invade that privacy,” Ferguson said. “There is no right for police to know everything about us.”

He was heartened by the U.S. Supreme Court ruling in June that law enforcement needed a warrant to collect cell phone location data. The court’s majority opinion said people’s “reasonable expectation of privacy” for such information granted them protection under the Constitution’s Fourth Amendment, which prohibits law enforcement from “unreasonable” searches and seizures without a warrant from a judge.

Even so, Ferguson said, warrants provide insufficient protection because police must show relatively little evidence to show probable cause for a warrant. In some states, such as Virginia, warrants can be approved by magistrate judges who have never attended law school.

Police also are allowed to use mass surveillance such as public security cameras, license plate readers and facial recognition software, regardless of whether people are suspected of crimes.

“Now everyone is sort of presumed guilty and being watched, even though 99.9 percent of everything that's being watched is innocent conduct,” Ferguson said.

Rather than investigating a crime and gradually building a case against a particular suspect, he said, police soon could use AI to work backwards by whittling away at a massive data set until a suspect emerges.

For example, he said, police looking for the owner of a certain make of car used in a crime could use AI to find patterns in vast databases culled from license plate readers and vehicle registrations. AI could then, correctly or incorrectly, interpret the kind of person likely to own such a car, and vehicle owners who fit that description could find themselves swept up in a criminal investigation.

“AI is basically going to supercharge police surveillance powers,” Ferguson said. “It allows police to see more, do more and analyze more over a broader scale—and do that much, much more quickly.”

 

 

 

 

“The problem is you lose control over your data.”
Susan Ariel Aaronson

Elliott School of International Affairs

Image
Susan Ariel Aaronson

 

 

""

 

Though countries across the world have struggled with tech-related privacy challenges, most are far ahead of the United States in requiring companies, organizations and governments to protect consumers.

Worldwide, 144 of 197 countries have laws protecting personal information online, Aaronson said. Some regulate only government access or use of data, while others regulate the same for companies, and some do both.

The European Union’s General Data Protection Regulation outlines how companies must handle personal data and minimize the amount they collect. It also clarifies consumers’ privacy rights and allows companies and organizations to use children’s personal data only if a parent or guardian gives explicit consent.

In Australia, companies and organizations may only collect information genuinely needed and must tell people why their information is being collected. In the United Kingdom, companies must ensure personal information is kept no longer than necessary and is handled securely to protect it from hackers.

While the United States does protect some sensitive information, such as medical and some financial records, it has no comprehensive federal law protecting personal data. Instead, it relies on a patchwork of federal and state regulations that cover certain sectors, such as healthcare and banking.

“The United States is way behind,” said Aaronson.

The latest U.S. attempt, called the Secure Data Act, would establish a “national framework” for consumer privacy rights and protecting personal data. As of late July, the bill had yet to be voted out of a House committee. Aaronson said she doubts it will move quickly, noting political gridlock in Congress.

While almost half of the states have “comprehensive” data privacy laws, GW experts say, most are too limited to be effective. For example, Ferguson said, most states that restrict how data may be used carve out blanket exceptions for law enforcement officials who obtain a warrant or subpoena.

Ferguson said Congress needs to set a higher bar for granting such warrants, similar to standards for wiretap warrants. Bugging someone’s home is considered such a government invasion of personal privacy, he said, that federal law allows it only for certain serious crimes and after police have proven they have no other options to gather necessary evidence.

Congress also should limit the amount of time that state and local governments may retain data, he said. For example, New Hampshire requires that license plate images be purged and destroyed within three minutes of their capture, unless the tag has been linked to a wanted vehicle or person. That prevents authorities from using the data to track vehicles’ whereabouts.

Solove said individuals should no longer be tasked with having to sort through long, confusing “opt out” notices. Consumers don’t have the means to protect their data from giant tech companies, he said, any more than they can ensure the safety of their vehicles, food or drugs—all industries that the government regulates.

“We’ve got to hold companies responsible” for not sharing customers’ data, Solove said. “Until you hold them responsible, nothing will happen.”

 

 

Image
Andrew Guthrie Ferguson

 

 

“AI is basically going to supercharge police surveillance powers.”
Andrew Guthrie Ferguson

GW Law

 

""

 

Even as Congress and state lawmakers have been slow to act, GW’s scholars remain hopeful, especially as more people come to appreciate how their private data could be exploited by companies or abused by governments.

Ferguson said he’s been heartened by the “DeFlock” movement. The grassroots effort is pushing back against AI-powered license plate readers that record all passing vehicles, including their make, model and any dents, bumper stickers or other distinguishing features.

As of late July, 95 communities have deactivated such cameras or canceled contracts with surveillance companies following public opposition, according to deflock.org.

Other cities have also responded to public pushback. In 2024, Chicago didn’t renew its contract for ShotSpotter, an audio system that detects and alerts law enforcement to gunshots through hundreds of acoustic sensors installed across the city.

“There’s a growing sense that we don't like this sort of mass surveillance,” Ferguson said.

Solove said he welcomes such efforts but said they do relatively little in a country that still has  tens of millions of public cameras keeping watch–on top of the wearable devices, apps and websites constantly collecting our data.

The solution, he said, lies in people convincing lawmakers to provide more protections while granting them more control over their digital footprints.

“The public is ready,” Solove said. “What we need is real leadership.”