Fundamentals

Do You Own Your Personal Data? Rights, Control, and Ownership

By Daniel Sardá · Published on

7 min read1,474 words

In this article · 6 sections

Personal data is about us, but that does not necessarily make it property we can sell or reclaim like an object. The distinction matters for understanding our rights and the limits on companies and public authorities.

The short answer needs qualification: personal data is about you, and that connection can give you rights over how it is processed, but it does not necessarily make you the owner of every record, copy, or conclusion drawn from it.

This is more than a dispute over words. Saying “my data” expresses a legitimate intuition about autonomy and privacy. Yet ownership commonly includes powers to use an asset, exclude others from it, or transfer it. Information works differently: it can be copied, refer to several people, and arise from a relationship among them. That is why many legal systems protect people through specific rights and duties without declaring every datum to be their marketable property.

There is no identical legal answer in every country. The applicable law, the context, and the reason data is processed determine the actual scope of protection. Even so, a few distinctions can help us navigate the issue without being specialists.

Key idea: Being the data subject means that information relates to you. It does not automatically give you proprietary control over every copy, use, or inference.

Before discussing ownership, separate five different things

In everyday digital life, we use “data” to refer to very different objects. Treating them as the same thing leads to misleading conclusions.

Imagine that you complete a form to open an account. You provide your name and address; an organization stores them on a server; it adds them to a customer database; and it may produce a risk profile. These things are connected, but they are not the same legal object.

A company may own the server and have rights in the organization of its database. That does not give it unlimited freedom to use personal information. Conversely, the fact that a profile concerns you does not necessarily mean you own the server, the database, or the method that produced the inference.

In the European Union, legal protection for databases does not by itself create a right over every item of data they contain, nor does it displace privacy rules. The distinction shows why what property law protects and what data law protects are closely related but different questions.

Data subject, controller, and processor do not mean “owner”

Data-protection rules generally assign roles and responsibilities. The vocabulary varies by jurisdiction, but the European framework offers a useful example:

If a retailer hires a provider to host its customer database, the retailer may act as controller and the provider as processor. None of these labels means that anyone owns the person, or grants a general license to do anything with the information.

The distinction also helps allocate responsibility. The practical question is no longer merely “who owns the data?” It becomes more precise: who decided to collect it, for what purpose, on what legal basis, who must protect it, and against whom can I exercise my rights?

What control can a person have?

Depending on the applicable legal order, a person may be able to find out what information is being processed, correct errors, object to certain uses, request erasure, or receive certain data in a reusable format. The GDPR, for example, recognizes rights of access, rectification, erasure, portability, and objection, each with its own conditions and limits.

These rights do not amount to absolute power over information. Erasure may yield to legal obligations, freedom of expression, research purposes, or the defense of legal claims. Portability does not necessarily include every observed datum or every inference an organization has produced. And deleting a record from one system does not erase historical facts or information lawfully retained by third parties.

Nor does every instance of processing rest on consent. In frameworks such as the EU’s, consent is one possible legal basis alongside a contract, a legal obligation, vital interests, a public task, or a legitimate interest subject to assessment. Agreeing to terms, entering into a contract, and transferring ownership of an asset are therefore different acts. A consent form is not automatically a sale of data.

Key idea: Effective protection does not promise total control. It defines specific powers, enforceable obligations, and justified exceptions.

A name is not the only thing that identifies someone

Removing a name from a table can reduce risk, but it does not always make data anonymous. A combination of age, location, occupation, and habits may identify someone again when matched with other sources.

Pseudonymization replaces direct identifiers with codes or references while preserving the possibility of restoring the link through additional information. Under the European approach, pseudonymized data therefore remains personal data. Anonymization requires identification to no longer be reasonably possible in context; it is not simply a matter of deleting a column.

Inferences call for the same care. A platform may infer a preference, an economic circumstance, or a risk from observed behavior. Even if the conclusion is uncertain and was never supplied by the user, it can affect that person by determining what they see, the price they receive, or the opportunity they are offered. In jurisdictions such as the EU, an inference linked to an identified or identifiable person may fall within the scope of personal data.

That does not mean every inference belongs entirely to the individual. It means that the effort or technology used to create it does not automatically eliminate the interests of the person to whom it is applied.

Would treating data as property solve the problem?

The proposal is appealing: if data were transferable property, each person could decide who uses it and demand payment. That intuition draws attention to autonomy and to the economic value companies derive from information.

But the solution has limits. The World Bank notes that different interests overlap in the creation and use of data. A record of a purchase involves the buyer, the seller, the payment provider, and sometimes other people. A photograph or conversation may reveal information about several individuals. Giving one person exclusive control could impair the legitimate rights of others.

There is also an imbalance of power. Someone who needs a service may agree to a broad transfer without understanding its consequences or having a meaningful alternative. If a sale extinguished future protections, a one-time decision could expose that person indefinitely. A formally voluntary market does not by itself remove information asymmetries or the effects data use has on third parties.

From a liberal perspective, autonomy matters, but so do responsibility, a private sphere, and predictable limits on power. Protecting the person does not require granting a proprietary monopoly over every piece of information related to them. It does require predictable rules and safeguards for those who collect, analyze, and share data, whether they are companies or public authorities.

Key idea: Treating data as a commodity may recognize its value, but it does not by itself solve privacy, unequal power, or the interests of third parties.

A better question than “is it mine?”

When dealing with an app, a business, or an institution, it is useful to ask more specific questions:

This approach avoids two opposite errors: assuming that an organization may do anything because it controls the infrastructure, or believing that a person can remove from reality every fact that concerns them.

Personal data does not fit neatly into the logic of a physical object. It is information about people, relationships, and events; it can be copied in many places and acquire new meanings when combined. The stronger institutional answer is not to repeat that “your data is yours,” but to recognize the personal connection, define legitimate uses, and hold accountable those who exercise power through information.

AI and Personal Data: How to Use These Tools with More ControlA practical guide to deciding what to share with an AI tool, minimizing personal data, and retaining control over how it is used.Property Rights Protection: Rules and Safeguards Against Arbitrary ActionProtecting property means more than recognizing a right: it requires clear rules, impartial procedures, and effective remedies against dispossession and arbitrary deprivation.Contracts and Private Property: How They Are Connected and How They DifferPrivate property defines a sphere of control over goods and resources; contracts let people rearrange uses, transfers, and obligations voluntarily under general rules.