Search papers, labs, and topics across Lattice.
This paper critiques the current challenges in exercising digital rights due to legal heterogeneity and fragmented information systems, highlighting the disconnect between existing laws and their practical implementation. It theorizes a human-compatible rights layer that facilitates standardized, machine-readable communication of rights-related actions across diverse regulatory environments. The authors derive seven normative requirements for this framework, advocating for a shift from traditional compliance mechanisms to a more integrated digital infrastructure that supports user rights effectively.
A human-compatible rights layer could revolutionize how digital rights are exercised, bridging the gap between legal frameworks and practical application.
Digital rights increasingly exist in law but remain difficult to exercise through the information systems that mediate them. Using disciplined conceptual synthesis and problematization, this critical-conceptual IS paper explains the gap through the interaction of legal heterogeneity, conflicting organizational and commercial incentives, fragmented architectures, and asymmetrical control over rights-relevant acts. It then theorizes a human-compatible rights layer: a governed sociotechnical capability for standardized, machine-readable, bidirectional, and jurisdictionally plural communication of requests, consent, refusal, withdrawal, objection, records, and support. Comparing California-style opt-out signals, the EU's mixed lawful-basis regime, and P3P, DNT, GPC, and ADPC, the paper derives seven normative requirements, develops rights by architecture as a bounded emancipatory policy argument, and treats a proposed GDPR provision on automated and machine-readable privacy management as a policy case for moving from banner-based compliance toward rights-supporting digital infrastructure.