5 min read

The Ethics of Personal Data: Who Should Own Your Digital Life?

Written by
Amelia McMillan
Published on
October 2, 2026

"You own your data" is an often repeated sentence in the technology industry, and almost nobody who says it actually means anything by it.

‍

If you own something, you can use it, exclude others from it, sell it, destroy it, and pass it on. Run your digital life against that list. You can usually view and use your data, you can sometimes export it, and you can occasionally get it deleted, eventually, after filling in a form. You cannot exclude the company holding your data from reading it, you cannot sell it, and you have no reliable way to pass it on.

‍

That isn't ownership. It's a rental, on terms the ‘landlord’ can change.

‍

Four Answers, All of Them Kind Of Right

‍

The reason this ownership question hasn't been settled is that there are several defensible positions:

‍

  1. You own it, because it's about you. The intuitive answer, and the one most privacy regulation is built on. Its weakness is that a large amount of data isn't about one person: a photograph of a dinner party is about six people, a message thread has two authors, etc. 

‍

  1. They own it, because they generated it. Your purchase history didn't exist until a company recorded it. Your engagement patterns are observations a firm made using its own infrastructure. This position gets dismissed as self-serving, but it’s stronger than we like to admit – the record is a thing the company made.

‍

  1. Nobody should own it, because ownership is the wrong frame. Property law was built for scarce, rivalrous things – if I take your car, you don't have a car. Data is infinitely copyable and non-rivalrous, so importing property concepts produces absurdities. The alternative framing is fiduciary duty: the holder has obligations to act in your interest, the way a doctor or a lawyer does, regardless of who "owns" the file.

‍

  1. Everyone owns it collectively, because its value is aggregate. Your individual health record is worth almost nothing to an aggregator. Ten million health records are worth an enormous amount and could produce genuine public good. A purely individualist framework makes that pooling difficult, which is a cost that privacy advocates don't always acknowledge.

‍

I don't think any of these wins outright, and I'd be a little bit suspicious of a company that told you otherwise.

Where the Ethical Failure Lives

‍

Set the ownership question aside for a moment, because there's something more important underneath it. Most of what people object to isn't a violation of ownership – it's a violation of expectation.

‍

It’s rare that anyone reads the Terms and Conditions and Privacy Policy for all the applications they use. Reading all the privacy policies you agree to in a year would take several working weeks, the language is deliberately general, and the choice is usually accept-or-don't-use-the-thing. 

‍

Secondary use is where the real harm sits. You gave a company data for one purpose and it was used for another. Your fitness tracker data informing insurance pricing. Your grocery purchases inferring a pregnancy. Nothing was stolen, and every step may have been technically disclosed, and it's still not what you agreed to in any meaningful sense.

‍

This type of inference dodges the whole privacy/ownership framework. Companies increasingly derive sensitive attributes you never disclosed – health conditions, sexuality, political leanings, financial distress – from seemingly simple behavior. You can't consent to a conclusion you didn't know could be drawn, and you can't request deletion of a fact about yourself that you don't know exists. Your expectations of what is being done with your data have been violated. 

‍

The Architecture Argument

‍

A privacy policy is basically a promise. It’s a promise from the company to you about what they will and won’t do with your data. Promises survive until the company is acquired, until the business model stops working, until a government makes a demand, or until someone gets in without permission. None of those require anyone to act in bad faith, they just require that circumstances change. 

‍

Architecture is different. If a company is technically incapable of reading your data, that constraint holds through acquisition, bankruptcy, subpoena, and breach. It doesn't depend on the current management being decent people. Zero-knowledge encryption, on-device processing, and local-first storage move the guarantee out of the policy document and into the system design.

‍

The important distinction is between "we won't" and "we can't," and only one of those survives a change of circumstance.

Thinkspan is Built Differently

‍

Thinkspan is built on zero-knowledge architecture. Your information is encrypted on your device before anything is transmitted, and we don't hold the keys to your data. To be precise: data does reach our servers (that’s how we’re able to provide real-time backups), but reaches them as gibberish. Nothing is readable.

‍

The honest trade-off: encryption this strong means we cannot recover your data if you lose your password. It’s a real cost, and anyone promising you strong privacy with no trade-offs is either confused or misleading you. 

‍

What This Asks of You

‍

Privacy and personal data regulation will eventually, hopefully, catch up. In the meantime the practical question is: for each service you use, is your data protected by a promise or by architecture?

‍

Whether the records should belong to you, to them, or to nobody is a real argument with real considerations on several sides. But "who should own it" might be the second question. The first is whether anyone should be able to read it at all.

‍

Spread the word
Data Privacy
Technology Education
Amelia McMillan
Head of Content, Thinkspan

Get Insights Delivered Straight to Your Inbox

Subscribe to our newsletter for the latest tips and insights on personal information security.

Explore Our Latest Insights

Stay updated with our informative blog posts.

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life's most important information stays protected and accessible.

Stay Informed

Be the first to know about feature releases and get tips for living your best life by signing up for our newsletter.

By clicking Sign Up, you confirm your agreement with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.