Personal Data & Records Rights

PERSONAL DATA & RECORDS RIGHTS

Personal Records and Data Ownership

Your Records Belong to You

Individuals should have a strong legal right to obtain, control, transfer, and use records created substantially about them or for services they purchased.

This should include, where applicable:

  • medical records;

  • laboratory results;

  • medical imaging;

  • prescriptions and treatment records;

  • dental records;

  • educational transcripts;

  • diplomas and certifications;

  • academic records;

  • employment records concerning the worker;

  • training records;

  • professional licensing records;

  • financial records concerning the customer;

  • insurance records;

  • other comparable personal records.

The institution that creates or maintains the record may retain a lawful copy where necessary, but it should not treat information fundamentally about an individual as something the individual has no meaningful control over.

Right to Complete Copies

Individuals should have the right to obtain a complete usable copy of their records without unreasonable delay.

Records should be available electronically in a commonly usable format whenever reasonably possible.

Organizations should not:

  • deliberately make records difficult to obtain;

  • require unnecessary fax or mail procedures when secure electronic delivery is available;

  • impose excessive copying fees;

  • force individuals to remain with a provider merely because that provider controls their records.

Reasonable identity verification may be required.

Medical Records

Patients should have timely access to their own medical information.

This should include, subject to narrow lawful exceptions:

  • physician notes;

  • diagnoses;

  • laboratory results;

  • imaging;

  • treatment history;

  • medication records;

  • surgical reports;

  • referral records;

  • billing records;

  • insurance records;

  • rehabilitation records.

The patient should be able to transmit those records directly to another provider of their choosing.

A healthcare provider may retain its own legally required copy, but should not be able to deny the patient meaningful access to information concerning the patient's own care.

Educational Records

Students should have durable access to educational records they earned or paid to obtain.

Schools, colleges, universities, certification programs, and training institutions should provide students with usable copies of:

  • transcripts;

  • grades;

  • completion records;

  • certifications;

  • diplomas;

  • course histories;

  • records required for transfer or employment.

A school should not be able to effectively hold someone's education hostage merely because the institution closes, changes systems, or has an unrelated financial dispute.

Right to Transfer Records

People should be able to direct that their personal records be securely transferred to another lawful institution.

Examples include:

  • doctor to doctor;

  • school to school;

  • bank to bank where applicable;

  • insurer to insurer;

  • employer training records to the employee where legally appropriate.

Interoperability should be encouraged so that changing providers does not require rebuilding someone's life history from scratch.

Right to Correct Materially Inaccurate Records

Individuals should have a meaningful process for challenging materially inaccurate information held about them.

The record holder should:

  • investigate credible disputes;

  • correct demonstrably false factual information;

  • record unresolved disputes where appropriate;

  • notify downstream recipients of significant corrections where reasonably possible.

This is particularly important where records affect:

  • healthcare;

  • credit;

  • employment;

  • education;

  • licensing;

  • insurance;

  • government benefits.

Right to Delete Personal Data

Individuals should generally have the right to require businesses and organizations to delete personal data that is no longer reasonably necessary for the purpose for which it was collected.

Deletion should include copies held by contractors and processors where reasonably feasible.

The organization should not simply mark information "inactive" while continuing to retain and monetize it indefinitely.

Exceptions to Deletion

Deletion rights should not require destruction where retention is reasonably necessary because of:

  • a court order;

  • active litigation;

  • criminal investigation;

  • legal record-retention requirements;

  • tax requirements;

  • medical continuity and patient-safety requirements;

  • fraud prevention;

  • protection of another person's rights;

  • legitimate archival obligations;

  • other specifically defined legal requirements.

Retention should last only as long as the lawful reason requires.

No Selling Personal Data Without Meaningful Consent

Sensitive personal information should not be sold or transferred merely because someone clicked through a lengthy terms-of-service agreement.

Heightened consent standards should apply to:

  • health information;

  • precise location;

  • biometric data;

  • genetic information;

  • financial information;

  • private communications;

  • children's information.

Consumers should be able to see who has received significant categories of their sensitive data.

Right to Revoke Consent

Where data use is based primarily on consent, individuals should ordinarily be able to withdraw that consent prospectively.

Withdrawal should be as easy as granting consent.

Companies should not make deletion or privacy controls intentionally difficult to find or use.

Data Minimization

Businesses and government agencies should collect only information reasonably necessary for the legitimate service or governmental function being performed.

"Collect everything because storage is cheap" should not be an acceptable privacy model.

Government Data

Government should be held to at least as strong a privacy standard as private companies.

Government agencies should not retain personal information indefinitely merely because they possess the technical ability to do so.

Records concerning innocent people should have defined retention periods unless there is a legitimate legal reason to preserve them.

Financial, Digital, Driving, and Personal Data Privacy

Banking and Financial Privacy

Financial institutions should not disclose detailed personal banking information to government without appropriate legal process.

Protected information should include:

  • account balances;

  • purchases;

  • transfers;

  • deposits;

  • withdrawals;

  • payment history;

  • merchant information;

  • loan activity;

  • investment activity;

  • cryptocurrency transactions;

  • other identifiable financial records.

For access to detailed historical financial activity, government should generally be required to obtain a warrant based on probable cause, subject to narrowly defined emergency and regulatory exceptions.

Internet and Online Activity Privacy

A person's online activity should be treated as private personal information.

Protected information should include:

  • browsing history;

  • search history;

  • app usage;

  • private messages;

  • email metadata and content where legally protected;

  • online purchases;

  • viewing history;

  • location history;

  • account activity;

  • cloud files;

  • social-media private activity;

  • other identifiable digital behavior.

Government should not obtain detailed historical online activity merely by purchasing it from a private company.

If government would need a warrant to compel the information directly, buying the same information from a data broker should not bypass that requirement.

Communications Privacy

Private communications should receive strong legal protection.

Government access to private:

  • messages;

  • email;

  • stored communications;

  • cloud documents;

  • voice communications

should generally require appropriate judicial process.

Mass collection without individualized suspicion should not become ordinary domestic practice.

Data Broker Restrictions

Companies whose business model involves collecting and selling personal information should face strict limitations.

Sensitive information should not be sold without meaningful consent.

This should include:

  • precise location;

  • financial activity;

  • medical information;

  • biometrics;

  • genetic information;

  • private communications;

  • browsing history;

  • detailed consumer profiles.

Notice to the Individual

When government obtains a person's sensitive private records, the individual should generally be notified.

Notice should identify:

  • what information was obtained;

  • which agency obtained it;

  • the legal authority used;

  • the period covered;

  • how the person may challenge unlawful access.

Delayed Notice

Notice may be temporarily delayed where a judge finds that immediate notification would create a substantial risk of:

  • destruction of evidence;

  • flight;

  • witness intimidation;

  • serious danger;

  • compromise of an active investigation.

Delayed notice should have a defined expiration date.

Government should return to court if additional delay is necessary.

Secret surveillance should not continue indefinitely merely because notification is inconvenient.

Right to Challenge

Individuals should have a meaningful legal mechanism to challenge improper government access to their private records.

Where unlawful access is proven, remedies may include:

  • suppression of unlawfully obtained evidence;

  • deletion of improperly obtained records;

  • correction of government databases;

  • civil remedies;

  • disciplinary action;

  • criminal consequences for intentional serious abuse.

No Reverse Warrants Without Extraordinary Justification

Government should not routinely demand information identifying everyone who:

  • was in a certain geographic area;

  • searched a particular phrase;

  • visited a particular website;

  • attended a particular lawful event.

Such broad reverse-search methods should face exceptionally strict constitutional and judicial scrutiny.

Protected Locations and Activities

Heightened protection should apply to data revealing visits to or participation in:

  • medical facilities;

  • counseling;

  • religious services;

  • political organizations;

  • lawful protests;

  • union activity;

  • legal offices;

  • gun stores;

  • journalists;

  • other activities closely connected to constitutional rights.

Lawful participation in protected activity should not itself justify surveillance.

Transparency Reports

Large companies receiving government requests for customer data should publish aggregate transparency reports where legally permitted.

Reports may include:

  • number of government requests;

  • general categories of requests;

  • number challenged;

  • number complied with;

  • emergency requests.

Individual investigations and protected information should remain confidential where required.

No Retaliation for Exercising Privacy Rights

Businesses should not deny ordinary essential services merely because someone exercises legally protected privacy rights, except where particular data is genuinely necessary to provide the requested service.

Privacy Enforcement and Deadlines

  • A covered organization must acknowledge a verified request to access, correct, transfer, or delete personal data within 10 days and complete it within 30 days. One additional 30-day extension is allowed only with written notice explaining the reason.

  • A denial must identify the legal or operational exception, the categories of data withheld, the retention period, and the internal and external appeal process.

  • Identifiable location information not tied to an active requested service, fraud investigation, safety incident, or legal duty must be deleted within 30 days unless the individual gives separate informed consent for longer retention.

  • Government delayed-notice orders for sensitive records expire after 90 days. Each extension requires new judicial findings, and notice must be provided when the delay ends unless another court order is entered.

  • Organizations must keep an access and disclosure log for sensitive data and provide the individual a usable summary upon verified request, subject to lawful investigative and security exceptions.

  • State attorneys general and designated federal regulators may seek deletion, correction, restitution, civil penalties, and injunctions. Individuals may seek actual damages and injunctive relief for knowing or reckless misuse, unlawful sale, retaliation, or refusal to honor a final correction or deletion order.

Related policies: Privacy Rights; Surveillance, Facial Recognition & Location Tracking; Credit & Financial Reputation Reform; Consumer Rights.

Status: Proposed / Draft — not yet formally adopted.

Originally published: August 15, 2026.

Last updated: September 25, 2026.

Version: Draft 0.1.

Previous
Previous

Surveillance, Facial Recognition & Location Tracking

Next
Next

Connected Vehicles, Privacy & Remote Control