Conclusion
A new social contract for American families and communities.
Few serious proposals exist that would give American families and communities agency over how AI and digital technologies implicate their values and interests. Until we operationalize associational data rights, many of the known antisocial consequences of the digital economy, and rapidly emerging agentic AI economy, are likely to get replicated or even exacerbated. These patterns are leading to substantial political polarization and tensions on both the right and left, fueling concerns about the expansion of AI and the development of data centers across the country.
We need a new social contract for American families and communities who have grown increasingly frustrated and distrustful of industrial grade surveillance, manipulation, and extraction.
Policymakers have yet to strike the proper balance. Associational data rights provide a viable third way—that complements other efforts around a national data privacy floor—by creating new intermediaries empowered to embed the values of different communal, religious, and civic commitments into the social contract governing data and the digital economy. This communal governance layer will preserve the bedrock of American society by securing the privacy, control, and economic interests of families and communities in the digital age and the information economy for generations to come.
Questions
Common objections
Answers here rest on the framework itself; each links to the part it comes from. This list grows as the argument meets its critics.
01Isn't this just another privacy law?
No. A privacy floor regulates what companies may do with data once they hold it. Associational data rights change who sets the terms in the first place.
Part II argues that top-down regimes have to pick one answer for everybody, and cannot let different communities settle the same question differently. What one community considers a fair trade for a free service, another finds a violation of conscience. The framework is explicit that it complements a national privacy floor rather than replacing it.
02Why can't people just opt out individually?
Because individual choice is not leverage. Part II gives three reasons it fails.
Consent is extracted hundreds of times a day against interfaces built to extract it. One person's data commands almost no bargaining power, because data gets its value from combination. And the costs are delayed and obscured, so acting alone reliably trades a long-term communal interest for an immediate personal convenience.
03If it's my data, why do I need an association?
Because it was never only yours. Part I's central claim is that data is co-produced: a DNA sample reveals your siblings, a photograph captures everyone at the table, and an aggregated record is valuable precisely because it predicts people who never consented to anything.
A right you exercise alone cannot govern a thing you produce together. That is the gap a right held individually but exercisable only in concert is meant to close.
04Would this end free services?
The framework does not require it. Data counterparties may still offer their own default terms — those terms simply cannot waive associational rights, and any terms negotiated with a DRA must be offered to everyone affected, operating as a floor.
Obligations are subject to equitable tests of reasonableness, and small DRAs are given no general veto. Part III is direct that the burden "will not place an unmanageable burden upon data counterparties."
05Isn't this a large new regulatory regime?
The framework argues the opposite — that it removes a distortion rather than adding one.
"DRAs would not amount to a new one-to-many regulatory scheme, but rather a restoration of the digital economy to something more closely resembling a genuine market, in which the people who co-produce the data that powers digital products have a meaningful say in what they give away and what they receive in return."
06What stops a DRA from selling out its members?
Several things, layered. A DRA has to be certified by a regulator and show a members-only ownership and governance structure that guards against conflicts of interest and foreign or non-member control. It acts as a fiduciary. Funding may not compromise its independence from the companies it bargains against, and fees from counterparties can be fixed by law to prevent kickbacks.
Regulators can revoke a charter for breach of fiduciary duty or deceptive practice, informed by audits, membership engagement and complaint records. Members can sue, or simply leave for a competing DRA. And a DRA can be enjoined by other DRAs whose members its bargains would harm — which pushes it toward terms acceptable beyond its own roll.
07Is any of this technically possible today?
Part IV catalogues six techniques already running at production scale, none of them written into the bill.
Universal opt-out signals are honoured by law in twelve states. Apple's Private Cloud Compute already makes servers cryptographically prove what software they run before a phone will send them data. Google has trained keyboard models across hundreds of millions of phones without collecting them; ten competing pharmaceutical companies jointly trained on 2.6 billion confidential data points without any firm seeing another's; Greater Boston employers have computed citywide wage-gap statistics covering roughly one in six area employees without disclosing a single salary. Personhood credentials let a DRA prove its membership is real without exposing who its members are.
08How is this different from a data cooperative or a data union?
Mainly in what makes it possible. Part III argues that associational arrangements for consumer data are unlikely to succeed without enabling legislation, because nothing today obliges a company to bargain with such a body — so nothing motivates anyone to form one.
ADRACA supplies the missing precondition: a permissions requirement that a counterparty must satisfy before collecting or productizing covered data.
09Who would be able to join one?
Deliberately the small side of the asymmetry. Data subjects — individuals, households, and civil society institutions such as schools, churches, nonprofits and civic associations, plus small and mid-sized enterprises for their own proprietary data. Content providers — anyone whose copyrighted work, image, voice or likeness appears on a public service. And mixed data dependents, where data is the product of an intentional relationship between them, such as a creator and their subscribers.
10Can someone belong to more than one?
Yes, and the framework expects it. "People derive meaning and value from membership in multiple different communities. DRAs can and should roughly correspond to groups and interests that already characterize a person's life: their church, their union, their profession, their political interests, their region, and their social group. Memberships can and should overlap."
Where two of a person's DRAs have conflicting terms, they can specify which governs, and DRAs can resolve the conflict through coalitions or the inter-DRA claims described in Part III.