Senator Leroy Comrie’s It’s Your Data Act could give New Yorkers something the technology industry has spent decades avoiding: enforceable rights over the information that makes other people rich.
Somewhere in America, a technology company knows what you had for breakfast, how long you stared at your ex’s Instagram profile, whether you are thinking about changing jobs, and how many times you have searched for symptoms that turned out to be gas. It has probably sold some of those insights, used others to train an algorithm, and combined the rest with information from a few million strangers to build something investors call innovation. You, meanwhile, are trying to remember which email address you used to sign up for the app.
Welcome to the information economy, where everybody is working and almost nobody knows they’re on the payroll.
New York State Senator Leroy Comrie has introduced a bill that could begin changing that arrangement. His It’s Your Data Act, S5156, would expand protections for personal information and address its collection and use for commercial or economic value without the required consent. The proposal also recognizes a property interest in certain consumer information. It is not law yet, but if enacted, it could help New Yorkers do something that sounds remarkably ordinary: assert legal rights over information about themselves that other people are using to make money.
This should not be a revolutionary concept in a state where you can own a parking space, license a song, inherit an apartment, and sue somebody for using your photograph in an advertisement without permission. But apparently the moment your personal information becomes useful to a computer, the rules of ownership begin behaving like a New York landlord explaining why your security deposit is nonrefundable.
For the past decade, I have been making an argument that tends to produce two reactions. Economists want to debate it, and technology companies would prefer that I stop making it. The argument is that data is labor. Not because clicking a button is the same as working a twelve-hour shift in a hospital, but because human activity produces economically useful information. Our decisions, conversations, movements, relationships, and experiences create inputs that other people use to produce commercial value. The fact that we do not receive a paycheck for those inputs does not mean they were free to produce or worthless to the companies collecting them.
Consider how strange this arrangement would sound in almost any other industry. Imagine walking into a bakery, providing the flour, sugar, eggs, and recipe, and being told that your contribution has no value because the bakery owns the oven. You might reasonably ask for your ingredients back. The baker might explain that you agreed to the terms and conditions when you entered the store. Those terms, naturally, were printed on a receipt that disappeared when you clicked “Accept All Cookies.”
That is not a perfect description of how data works. Information can be copied, combined, and reused in ways flour cannot. But the economic question remains: if your contribution helps create something valuable, why should the institution controlling the machinery automatically receive the entire benefit?
Artificial intelligence has made the question harder to ignore. We are now watching companies build systems capable of writing, drawing, coding, analyzing, and performing tasks that once required substantial human effort. These systems depend on expensive computing infrastructure and highly skilled engineers. They also depend on enormous quantities of information originating from human beings. We recognize the investors who finance the machines. We recognize the companies that own the servers. We recognize the engineers who build the models. Somehow, the people whose accumulated knowledge and activity make the systems useful are frequently treated as an interesting feature of the landscape.
It is the economic equivalent of thanking the tractor manufacturer for the harvest while forgetting that somebody owned the land and somebody planted the seeds.
This is where Comrie’s legislation becomes interesting. The proposed law does not promise every New Yorker a royalty check whenever an algorithm learns something from their information. Nor does it establish that every commercial use of personal data is unlawful. What it could do is strengthen the legal distinction between having access to somebody’s information and having unlimited permission to exploit it. Under the proposal, certain unauthorized uses could give rise to civil remedies, while businesses would face additional obligations concerning the personal information they collect and hold.
That distinction matters because we have spent years confusing consent with compensation. A company asks whether it may collect your information. You click yes because you want to order dinner, hail a car, or see a photograph of your cousin’s new baby. The company then develops an elaborate commercial infrastructure around that information. We are told the transaction was fair because we consented.
But agreeing to let someone enter your house is not the same as agreeing to let them operate a hotel out of your living room. Permission has a purpose, a scope, and a context. If personal information has economic value, the terms governing its commercial use deserve more scrutiny than a disappearing notification at the bottom of a screen.
The next question is what we could actually do if New York recognized stronger rights over that information.
First, we could begin documenting what companies collect, what they are authorized to do with it, and whether their actual practices comply with the law. Today, most people have no practical way to trace their information across the commercial systems that use it. We know that information is valuable because entire industries are built around acquiring and processing it. Yet the individual contributor is often the least informed participant in the transaction.
Imagine a New Yorker opening an application that identifies companies holding their personal information, examines the relevant permissions, and helps document potentially unauthorized commercial uses. Instead of complaining vaguely that a technology company stole their data, the person could assemble evidence identifying what was collected, when it was collected, what permission existed, and how the information may have been used. A licensed attorney could evaluate whether that evidence establishes an actual legal claim.
This is where a new generation of legal technology could become useful. We could develop systems that make the initial investigation of data-rights claims less expensive, more consistent, and more accessible. Attorneys could evaluate recurring patterns across many individuals, distinguish legally supportable cases from speculation, and pursue appropriate remedies. The point would not be to manufacture lawsuits. It would be to make existing and future legal rights practical for people who cannot afford to spend $20,000 proving that a company improperly used information worth a fraction of that amount.
There is something wonderfully American about the possibility that the same technology companies using artificial intelligence to reduce their labor costs could eventually face artificial intelligence systems helping ordinary people investigate their legal rights. I suspect the industry’s enthusiasm for automation might become slightly more complicated once the robots start reading the privacy policies.
But lawsuits are only the beginning. My larger interest is in the economic value of the information itself.
Consider a nurse who spends twenty years producing clinical observations and treatment records. A teacher whose instructional methods and classroom interactions help improve educational software. A musician whose recordings contribute to a system that can imitate a particular style of performance. A delivery worker whose daily movements help a platform develop more efficient routing systems. These people may be paid for their immediate work, but the information generated through that work can have an economic life extending far beyond the original transaction.
Does that mean each person automatically owns every downstream product? Of course not. The hospital contributes infrastructure. The software company contributes engineering. The investors contribute capital. Other people contribute additional information. Production is collaborative. That is precisely why we need better methods of understanding who contributed what.
In my research, I describe information as a factor of production alongside labor and capital. Economists have spent generations building methods to estimate the contributions of workers, equipment, investment, and other productive resources. We can extend that analysis to informational inputs. The familiar production function can be expanded to (Y = F(K,L,I)), where information joins capital and labor as an explicitly measured contributor to economic output.
Nobody needs to memorize that equation to understand the underlying problem. If a company knows precisely how much it spent on graphics processing units but has no method for valuing the human information that makes those processors commercially useful, its accounting is telling an incomplete story.
I have been developing approaches to estimating those contributions, including methods that connect informational inputs to commercial outputs. Such calculations do not magically create a legal right to payment. A court would still need an applicable law, evidence of a violation, causation, and a legally recognized measure of damages. But valuation can inform licensing, negotiations, expert analysis, collective bargaining, and future legislation. We already estimate the economic value of patents, brands, customer relationships, and other intangible assets. It is difficult to argue that informational contributions are inherently beyond economic analysis when companies routinely spend enormous sums acquiring them.
The possibilities become especially interesting when we move from individual rights to collective action.
One person’s information may have limited economic value in isolation. The information generated by ten thousand nurses, teachers, drivers, or creative professionals may have substantial value when assembled into a dataset used to develop a commercial system. This is why I began advancing the concept of data unions. Workers and contributors should be able to organize around the informational value they collectively produce, just as workers have historically organized around wages, benefits, and working conditions.
A union might negotiate terms governing how worker-generated information is licensed for AI training. A professional association might establish a collective data-use agreement. Artists might negotiate compensation for particular commercial uses of their recorded performances. Individuals might participate in data cooperatives that license information for research or commercial development under transparent terms.
None of this requires pretending that every dataset belongs exclusively to one person. Information is often relational. A conversation belongs to the experience of more than one participant. A medical record may reflect the contributions of a patient, a clinician, and an institution. The challenge is to establish rights and obligations that recognize these relationships rather than allowing the most powerful participant to claim everything by default.
And there is another industry that should be paying attention: insurance.
If companies face clearer legal obligations concerning personal information, they will need better ways to measure their exposure to liability. Insurers will need to understand the probability and severity of claims involving unauthorized collection, disclosure, retention, and commercial use. Organizations developing AI systems will need to document where their informational inputs originated and whether those inputs were obtained and used lawfully.
The same evidence that helps a person establish a data-rights claim can help an insurer assess the underlying risk. Better documentation could improve underwriting, encourage responsible information management, and make compliance more measurable. Instead of waiting for a billion-dollar dispute to discover that nobody knows where a model’s training information came from, companies could begin addressing those questions before the dispute occurs.
This is one reason I believe the conversation belongs in New York. We are home to major financial institutions, insurance markets, healthcare systems, universities, creative industries, organized labor, and technology companies. The state has both the economic complexity and institutional capacity to experiment with new ways of recognizing informational rights. A stronger legal framework could support new businesses in data valuation, auditing, licensing, legal services, and insurance.
There are legitimate concerns. We do not want a system in which ordinary research becomes impossible because every observation requires a licensing agreement. We do not want to undermine journalism, legitimate public-interest uses, or beneficial innovation. We should not assume that every piece of information is private property simply because someone can connect it to a person. And we should certainly avoid creating a legal environment where a speculative calculation is enough to threaten a company with litigation.
Those concerns are reasons to design the rules carefully, not reasons to ignore the economic relationship entirely. We have managed to create complicated legal frameworks for intellectual property, financial securities, employment, real estate, and insurance. I am confident that the legal profession can survive the intellectual challenge of determining when personal information creates enforceable rights and when its use should remain unrestricted.
What interests me most is the possibility of changing when we recognize economic value.
Historically, we have allowed institutions to capture ownership and distribute profits, then argued afterward about whether enough of that wealth should be redistributed. My philosophy of Inclusionism asks us to consider a different approach. What if we recognized contributions closer to the moment value was created? What if attribution, ownership, and participation were built into the transaction instead of becoming subjects of political conflict years later?
I call this reparations in real time. It is not simply a demand for compensation after an injury. It is a framework for designing economic relationships so that contributors retain meaningful agency and participation in the value they help create.
Comrie’s bill would not accomplish all of that. Its immediate focus is personal data rights, not a comprehensive system of informational royalties or collective ownership. Additional legislation, contractual innovation, technical standards, and economic research would be needed to establish broader compensation rights. But recognizing that personal information can remain the property of the individual, even when held by a company, could help establish the foundation for those conversations.
The distinction between privacy and economic participation is particularly important. Privacy asks whether someone should be allowed to collect or use your information. Economic participation asks what happens when that information becomes a productive asset. The questions overlap, but they are not identical. A company might comply with every consent requirement and still build a highly profitable product from information contributed by millions of people who receive no share of the resulting wealth.
That may be lawful. Whether it is economically equitable is a different question, and one that future policymakers, workers, consumers, and businesses will increasingly confront.
We have reached a peculiar moment in history. Artificial intelligence can estimate the value of a company in milliseconds, optimize the price of an airline ticket, predict consumer demand, and help financial institutions evaluate billions of dollars in assets. Yet when someone asks what their own informational contributions are worth, the answer is usually that the calculation is too complicated.
Funny how complexity becomes an insurmountable obstacle precisely when ordinary people might be the ones getting paid.
New York has an opportunity to begin changing that conversation. If Senator Comrie’s It’s Your Data Act becomes law, it could give individuals additional tools to protect their information, provide attorneys with new grounds for certain legal claims, and encourage companies to take their informational obligations more seriously. Combined with economic valuation, collective bargaining, and responsible legal technology, those rights could become part of a much larger transformation in how we recognize human contributions to the digital economy.
The goal is not to sue every technology company into oblivion. I would prefer that they continue innovating, creating jobs, and building useful things. I would simply like the people whose information helps make those things possible to have a meaningful place in the economic relationship.
For years, the technology industry has told us that data is the new oil. That metaphor was always incomplete. Oil does not have a family, go to work, fall in love, develop skills, or spend its life producing new information through relationships with other people. Human beings do.
And unlike oil, we can hire lawyers.
Perhaps New York should give those lawyers something worth arguing about.





