Source-linked AI summary
Rights by Architecture: A Human-Compatible Sociotechnical Layer for Digital Protection Across Regulatory Regimes
Soheil Human
TL;DR
Digital rights are formally recognized but remain difficult to exercise because heterogeneous laws, conflicting incentives, fragmented architectures, and asymmetrical control shape the systems through which rights are enacted. Using conceptual synthesis and problematization, the paper theorizes a human-compatible rights layer and concludes that rights-supporting infrastructure should communicate plural rights-relevant acts without replacing legal authority. The paper also identifies clear boundaries: such a layer cannot itself provide recognition, legality, remedy, or a solution to broader digital harms.
Problem
Digital rights remain difficult to exercise through information systems because legal heterogeneity, conflicting incentives, fragmented architectures, and asymmetrical control preserve controller and client power.
Method
The paper uses critical-conceptual IS inquiry, disciplined conceptual synthesis, problematization, and comparison of legal regimes and rights-communication standards.
Results
The paper develops a human-compatible rights layer for standardized, machine-readable, bidirectional, and jurisdictionally plural communication of rights-related information, acts, decisions, and records.
Takeaways & Limitations
Rights-supporting architecture should support plural legal grammars, vulnerable people, and digital environments while leaving entitlements, legality, oversight, and consequences to law and institutions.
Takeaways & Limitations
The rights layer cannot itself remedy surveillance capitalism, platform concentration, manipulative models, weak enforcement, first-party use, sensitive inference, or pressured disclosure.
Abstract
from arXiv · showhide
Digital rights increasingly exist in law but remain difficult to exercise through the information systems that mediate them. Using disciplined conceptual synthesis and problematization, this critical-conceptual IS paper explains the gap through the interaction of legal heterogeneity, conflicting organizational and commercial incentives, fragmented architectures, and asymmetrical control over rights-relevant acts. It then theorizes a human-compatible rights layer: a governed sociotechnical capability for standardized, machine-readable, bidirectional, and jurisdictionally plural communication of requests, consent, refusal, withdrawal, objection, records, and support. Comparing California-style opt-out signals, the EU's mixed lawful-basis regime, and P3P, DNT, GPC, and ADPC, the paper derives seven normative requirements, develops rights by architecture as a bounded emancipatory policy argument, and treats a proposed GDPR provision on automated and machine-readable privacy management as a policy case for moving from banner-based compliance toward rights-supporting digital infrastructure.
Introduction
The paper argues that formal digital rights remain difficult to exercise because rights-relevant choices are mediated through fragmented, controller-controlled systems across heterogeneous legal regimes. It proposes a human-compatible rights layer that embeds standardized, machine-readable communication into architecture while preserving legal plurality and institutional authority.
- Problem: Digital systems externalized rights expression, memory, withdrawal, delegation, and contestation to fragmented service-specific interfaces.This produces repeated banners, opaque policies, asymmetric buttons, and fragmented records.
- Contribution: The proposed rights layer is a governed sociotechnical capability for standardized, machine-readable, bidirectional, and jurisdictionally plural communication among rights-system participants.It does not decide substantive law; law and institutions determine when communicated acts bind and what follows from obstruction.
- Problem: California-style opt-out signals cannot serve as universal privacy grammar because legal regimes recognize different rights and lawful-basis structures.Infrastructure can make one jurisdiction's technical form appear globally natural, potentially narrowing rights elsewhere.
- Research Questions: The paper asks what explains the gap between formally recognized rights and practical exercisability, and what requirements could narrow it without collapsing legal plurality or reproducing control asymmetries.Privacy and data protection provide the developed comparative case.
- Approach: The inquiry combines critical IS, privacy theory, infrastructure research, internet governance, legal materials, and standards history through a six-step conceptual synthesis.The comparison covers California opt-out, the EU mixed lawful-basis regime, P3P, DNT, GPC, and ADPC.
- Boundary: The mainly EU–California machine-readable case may underrepresent rights, practices, and communities outside those regimes or resistant to codification.The proposition and requirements remain contestable through empirical inquiry, institutional experience, and affected-community evaluation.
Critical-Theoretical Lens: Rights, Power, and Sociotechnical Infrastructure
The paper treats rights exercisability as a relational IS phenomenon shaped by legal, infrastructural, organizational, and material arrangements rather than isolated user choices. A rights layer is therefore modeled as a governed capability connecting plural semantics, exchanges, durable state, workflows, oversight, and remedy.
- Rights Exercisability: The gap persists when heterogeneous entitlements lack interoperable channels and fragmented systems asymmetrically allocate initiation, representation, memory, evidence, and contestation.Inaccessible channels also externalize cognitive and social burdens to users.
- Sociotechnical Infrastructure: A rights layer is an analytical and architectural concept for a governed capability, not a protocol-stack stratum.Rights-related state can persist through linked messages, identifiers, acknowledgements, receipts, records, and workflows despite HTTP statelessness.
- Sociotechnical Infrastructure: An institutionally complete capability must connect legally plural semantics, client-controller exchange, durable state, organizational handling, oversight, and remedy.The analysis identifies what such arrangements must connect without claiming that one globally accepted arrangement already exists.
- Sociotechnical Infrastructure: The unit of analysis is a focal governed sociotechnical capability produced by interoperable vocabularies, protocols, participants, records, and organizational routines.This framing places rights communication within a shared, open, heterogeneous, evolving information infrastructure.
- Rights Exercisability: Privacy by design does not specify interoperable user-side rights channels, so the narrower contribution concerns whether a person or authorized agent can initiate and retain a legally situated act outside a duty-bearer's interface.Initiation, presentation, assistance, preference storage, and limited evidence may shift without transferring authority over legality or consequence.
- Digital Protection: Digital protection extends beyond data protection to agency, manipulation, discrimination, collective autonomy, and democratic resilience in digital environments.Data protection remains central but is incomplete when harms arise through uses, inferences, and environments.
Why Notice-and-Choice Keeps Failing
Notice-and-choice repeatedly fails because users face cognitive, temporal, collective, and environmental burdens while interfaces and legal grammars remain fragmented. The paper therefore distinguishes narrow opt-out signals from a richer rights layer capable of carrying context, bidirectionality, and records.
- Individual Burdens: Privacy policies and consent banners undermine informed choice through complexity, unreadability, defaults, asymmetry, hidden settings, and dark patterns.The model assumes people can evaluate information and form preferences, but the empirical record challenges that assumption.
- Individual Burdens: Repeatedly managing complex legal and technical trade-offs without durable memory, support, or usable records outsources systemic complexity to the least resourced actor.Observed clicks are poor evidence of unconstrained preference under constrained contexts and social pressures.
- Temporal Failure: Consent, refusal, withdrawal, and objection are continuing relations that require portable, intelligible records of what was communicated, to whom, under which description, and when.Service-specific channels make these relations difficult to manage even where withdrawal must be as easy as consent.
- Collective and Vulnerable Contexts: Privacy decisions can affect relatives, coworkers, communities, and children, making solitary individual clicking insufficient for relational and collective contexts.Children require support, and online data privacy can be understood as part of children's media rights.
- Environmental Failure: Screen-only, controller-specific mechanisms can fail in ambient, inaccessible, cross-device, and cross-service environments such as IoT, mixed reality, robots, vehicles, wearables, and agentic AI.Machine-readable communication is proposed as support for these settings.
- Jurisdictional Mismatch: California's GPC provides a legally recognized sale-or-sharing opt-out, whereas the EU's mixed lawful-basis regime requires richer, context-dependent communication.One binary global signal cannot represent the EU grammar without loss.
- Jurisdictional Mismatch: A rights layer must carry vocabulary, context, bidirectionality, and records: a binary signal can be one message within it, not the layer itself.Standards should accommodate GPC-like opt-outs and ADPC-like consent, refusal, withdrawal, and objection without universalizing either regime.
- Power and Standardization: Technology concentration makes standardization a power struggle because dominant firms can let the easiest technical solution define practical rights across jurisdictions.A human-compatible layer must allow plural legal grammars rather than impose one binary signal globally.
Protocol Histories and Lessons for Regulation
P3P, DNT, GPC, and ADPC illustrate successive trade-offs between machine-readability, institutional force, scope, and richness. Their history supports legally grounded automation that preserves human and vulnerable-user involvement.
- P3P: P3P made website practices machine-readable for browser comparison, but fragile self-description, limited deployment, and misused compact policies weakened its practical force.Machine-readability was feasible, but incentives and enforcement were insufficient.
- DNT: DNT enabled browser preference signals and site status responses, yet compliant behavior remained outside the specification and deployment proved insufficient.The W3C process ended in a 2019 Working Group Note rather than a Recommendation.
- GPC: GPC connected a browser signal to a legally recognized California sale-or-share opt-out, but its deliberately narrow scope does not cover consent, withdrawal, objection, or contextual rights.It demonstrates that browsers can communicate rights firms must honor without representing the full rights grammar.
- ADPC: ADPC specifies richer bidirectional communication of data-protection information, requests, preferences, and decisions between user-side software and services.It supports general and specific choices, consent, refusal, withdrawal, objection, and potentially compatible legal profiles through HTTP, JavaScript, and Bluetooth.
- Regulatory Lessons: The protocol sequence moves from unenforced self-description through simple but institutionally weak preference signaling and narrow recognized opt-outs toward richer bidirectional communication.These lessons orient proposed GDPR automation toward legal grounding while keeping supported and vulnerable people involved.
Proposed Article 88b and the EU Opportunity
The proposed Article 88b illustrates how automated, machine-readable communication could support rights-relevant acts while leaving legal recognition and institutional enforcement to separate actors. Its implementation would require coordination among standards, clients, controllers, oversight, and enforcement.
- Article 88b is presented as a worked case for automated, machine-readable choices involving consent, refusal, and objection.
- A standardized channel could carry propositions or requests through a chosen client, support assistance, and return controller acknowledgments, status, and linked records.
- The capability coordinates communication without itself deciding substantive law, universal duties, recognition, adjudication, or remedy.
- Adoption should remain disaggregated and avoid blanket browser-default consent or dependence on dominant browsers.
Normative Requirements for a Human-Compatible Rights Layer
The paper derives seven requirements for a rights layer that can communicate legally meaningful acts across actors, time, and regulatory contexts. These requirements combine plurality, bidirectionality, records, accountable mediation, human support, auditability, and adaptability.
- Legal plurality: NR1 requires legal plurality through extensible vocabularies and accountable semantic governance rather than privileging one jurisdiction’s ontology.
- Bidirectionality: NR2 requires bidirectional exchange so controllers can communicate context while people or agents can send decisions, refusals, withdrawals, and objections.
- Person-held records: NR3 requires durable, privacy-preserving person-held records showing what was requested, decided, and revised over time.
- Accountable client mediation: NR4 shifts interface power toward standardized, accessible, independently audited client mediation without eliminating manipulation risks.
- Human support and auditability: NR5 supports cognitive, contextual, and collective assistance while NR6 connects machine-readable handling to verifiable traces, enforceable duties, and sanctions.
- Adaptability: NR7 makes the layer adaptable to emerging forms of digital protection, including generative AI, personalization, IoT, and vulnerability inference.
Human-Compatible Automation and Delegation
The paper treats automation and delegation as configurable forms of support rather than replacements for agency. Their legitimacy depends on visibility, reviewability, revocability, scoped authority, logging, and privacy-preserving access.
- Automation can reduce the burden of repetitive, steered clicking, but must preserve agency, reviewability, and contestation.
- Users should be able to choose assistance levels ranging from reminders and prompts to refusal rules, recommendations, protective settings, and manual paths.
- Assistance must remain visible, intelligible, accessible, reviewable, configurable, and revocable, with users able to refuse or contest it.
- Delegated support requires scoped, logged, revocable authority and minimized access for parents, caregivers, professionals, and civil-society organizations.
Legal Pluralism Beyond the EU and California
A global rights layer must accommodate legal and sectoral plurality rather than encode the logic of California or the EU as a universal template. The paper therefore favors modular profiles, gateways, and cumulative evolution from existing standards.
- Legal systems differ across opt-outs, prior consent, fairness, transparency, authorization, privacy, safety, AI governance, and competition concerns.
- Plurality calls for a modular core covering actors, acts, status, time, and revocation, with jurisdictional vocabularies and gateways to existing systems.
- Existing resources include ODRL, DPV, ADPC, ISO/IEC consent records, and IEEE machine-readable privacy terms, but none alone integrates the full rights-layer arrangement.
- The proposal connects these resources with P3P, DNT, GPC, clients, controller systems, complaint processes, profiles, gateways, testing, and revision.
Reviewability and Contestability
Reviewability and contestability make rights exercise inspectable, revisable, and challengeable rather than opaque or one-sided. These requirements become more important as digital protection extends across vulnerable users, pervasive environments, and behavior-shaping uses.
- Reviewability: Reviewability lets users inspect request histories, identify automated decisions and applied rules, and revise choices without reconstructing browsing histories.It is presented as a safeguard against hidden paternalism and as support for meaningful control.
- Contestability: Contestability enables users and institutions to challenge invalid requests, dishonest vocabulary, ignored refusals, and uses exceeding communicated purposes.Delegation logs, authority revocation, plain-language explanations, and independent oversight are part of this condition.
- Broader digital protection: Digital protection addresses harms arising from uses, inferences, and environments, including manipulation, discrimination, and behavior-shaping personalization beyond data transfer.Respecting a do-not-sell signal does not by itself prevent harmful first-party personalization.
- Vulnerability and support: Children require age-appropriate explanations, guardian-mediated decision support, protective defaults, and external oversight rather than merely improved clicking interfaces.The proposed layer is intended to support children across games, learning platforms, social media, smart toys, voice assistants, and immersive environments.
- Vulnerability and support: Human-compatible rights support should accommodate diverse vulnerabilities through multilingual interfaces, screen-reader compatibility, simplified explanations, trusted intermediaries, and contextual warnings.The paper frames this as a regulatory issue because unusable rights interfaces make protection socially unequal.
- Pervasive environments: Pervasive environments require rights communication beyond a single website visit because users may not observe or control collection by smart homes, IoT devices, mixed reality, or robots.These systems can sense and act in shared spaces involving bystanders who did not initiate the interaction.
- Generative AI and hyper-personalization: A rights layer should communicate whether and how data may be used for personalization, profiling, inference, or behavior-shaping as generative AI and hyper-personalization raise new risks.The paper places these future rights under digital protection.
Standardization, Power, and the Risk of Capture
Standardization allocates defaults, adjustment costs, and practical capabilities, so dominant actors can shape rights infrastructures around existing business models. Adoption, oversight, user-side safeguards, and timely evolution are therefore necessary because technical specification alone does not ensure effective rights exercise.
- Standardization and power: Standards function as governance arenas that allocate defaults and adjustment costs, while resource asymmetries can let dominant actors shape them around existing business models.Technology firms and advertising networks may participate more continuously than civil society, affected communities, and small firms.
- Risk of capture: A standardized rights act and status can make initiation, obstruction, and contradiction more observable, but cannot make compliance self-enforcing.Capture can still occur through manipulative clients, controller misclassification, narrowed vocabularies, misleading acknowledgments, or weak investigation.
- Implementation and stewardship: Effective adoption requires jurisdiction-specific combinations of binding duties, open standards, reference implementations, conformance tests, certification, procurement, complaint pathways, audits, and sanctions.Civil-society monitoring can expose patterns, while no single lever applies identically across rights or jurisdictions.
- User-side governance: User-side actors can replace controller dominance with client dominance through manipulative defaults, proprietary vocabularies, sensitive state, concentration, switching costs, and interoperability failures.Multiple implementations, open profiles, portable records, independent testing, and regulatory oversight are proposed safeguards.
- Adoption and evolution: DNT's 2019 conclusion as a W3C Working Group Note after insufficient deployment shows that technical specification without ecosystem adoption and institutional force may stall.The paper therefore favors an initial rights-adequate version pursued within explicit timelines and maintained as a living standard.
- Evaluation: Future evaluation should examine legal conformance, human consequences, and ecosystem effects, including interoperability, adoption, and incumbent power.These are prospective criteria for specific implementations rather than reported outcomes.
- Evaluation: Success means improved conditions of rights exercise measured through burden, dark-pattern exposure, withdrawal usability, accountability, accessibility, support, compliance duplication, and auditability.The requirements remain reasoned propositions for deliberation and testing with standards communities and affected groups.
Discussion and Implications for Information Systems
The paper frames rights exercise as an IS phenomenon shaped by law, incentives, fragmented systems, human support, and power. It proposes governed capabilities that communicate rights across regimes while preserving legal authority and requiring safeguards against surveillance and capture.
- Rights exercise is preserved as an unequal distribution of initiation, representation, memory, evidence, coordination, and observability, despite formal legal recognition.
- NR1–NR7 specify a human-compatible layer for standardized, machine-readable, bidirectional, jurisdictionally plural communication of rights-related information, requests, decisions, and records.
- The layer should support opt-out rights without universalizing them and EU consent and objection without reducing them to banners; ADPC is presented as a stronger starting point than GPC for this plurality.
- Machine-readable communication could create shared objects for auditing signal recognition, lawful vocabulary, refusal and withdrawal handling, and fingerprinting or delegation risks.
- The layer cannot supply recognition, legality, remedy, or solutions to surveillance capitalism, platform concentration, weak enforcement, or pressured disclosure.
- Automation should reduce cognitive burden through review, intelligible summaries, alerts, easy withdrawal, and trusted support while preserving agency.
- Legal pluralism retains n-to-m complexity, while local processing, minimized disclosure, secure records, and participatory governance address surveillance, delegation, and legitimacy risks.
Conclusion
The conclusion argues that legal rights have not reorganized the systems through which people exercise them, because power persists across heterogeneous laws, incentives, workflows, support, oversight, and remedy. It presents a bounded rights layer as a law-first infrastructural response that supports plural rights without replacing substantive regulation or enforcement.
- Legal recognition alone has not reorganized rights-exercise systems, leaving procedural, epistemic, and infrastructural power concentrated through heterogeneous and fragmented arrangements.
- NR1–NR7 define a human-compatible layer that communicates rights-related information, requests, decisions, and records across jurisdictions and automated environments.
- Implementation should avoid universal opt-out, consent by default, browser dominance, and industry-defined rights, while building on an open, extensible mechanism linked to oversight and enforcement.
- Rights by architecture is a bounded response: information systems can make rights infrastructural, but architecture is neither independently causal nor sufficient.