The U.S. Needs a New Paradigm for Data Governance

The U.S. Senate and House hearings last week on Facebook’s use of data and foreign interference in the U.S. election raised important challenges concerning data privacy, security, ethics, transparency, and responsibility. They also illuminated what could become a vast chasm between traditional privacy and security laws and regulations and rapidly evolving internet-related business models and activities. To help close this gap, technologists need to seriously reevaluate their relationship with government. Here are four ways to start: Help to increase tech literacy in Washington; create and enforce stronger policies for governing third parties’ use of data; invest in user-centered models for consent and terms of service; and include data ethics as a central component of any regulatory reform.
The U.S. Senate and House hearings last week on Facebook’s use of data and foreign interference in the U.S. election raised important challenges concerning data privacy, security, ethics, transparency, and responsibility. They also illuminated what could become a vast chasm between traditional privacy and security laws and regulations and rapidly evolving internet-related business models and activities. To help close this gap, technologists need to seriously reevaluate their relationship with government. Here are four ways to start.
Help to increase tech literacy in Washington. Lawmakers expressed surprise and confusion about Facebook’s business model, including how the company generates revenue and uses data for targeted advertising. They also seemed to misunderstand how Facebook functions as a platform for third-party applications and how users’ data is flowing between the user, Facebook, and third parties. This lack of knowledge — despite the millions of dollars that the tech industry spent on lobbying Washington in 2017 — shows that technology literacy among lawmakers still needs to be improved.
It’s especially important since Washington is clearly interested in enhanced regulation of the data economy. Multiple lawmakers suggested more expansive federal privacy legislation. There are state efforts as well, such as the California Consumer Privacy Act. The question is whether regulators will be able to create rules that reflect modern business models and data flows and support innovative services and products. To ensure that they do, internet and technology companies must engage with legislators in a different way, beyond the transactional and fleeting.
To accomplish this, those who care about the future of technology must be more strategic and focused on educating the federal government and changing its culture over the long term. A few examples of how to embed tech expertise into policy making are TechCongress, the U.S. Digital Service, and the Presidential Innovation Fellows. These programs offer an extended opportunity for people with different experiences and backgrounds to work together to improve how government works — increasing their exposure to different ideas, forcing collaboration, and working through tension and conflicting viewpoints. And when those technologists finish their public service tour of duty and return to industry, they will go back with a deeper understanding of public service.
Create and enforce stronger policies for governing third parties’ use of data. Much of the internet economy runs on application programming interfaces (APIs). Companies such as Facebook, Google, Apple, Amazon, and Salesforce have robust developer programs that encourage third-party integration with their platforms via APIs. These partnerships make it possible to offer customers valuable services — for example, add-on applications that allow you to customize your Gmail experience.
However, these partnerships can also lead to data spreading to places that are far beyond users’ awareness or control.


