Neural-Data Governance
Neural-data governance is the set of legal, institutional, and technical arrangements that determine how brain data are collected, stored, used, shared, and destroyed, and who bears which obligations. Key questions include whether neural data are 'sensitive' by default, whether they are best protected as privacy (a personal interest) or as property (an ownable asset), and how to handle inferences and derived models rather than only raw recordings.
A governance regime must span the whole lifecycle: consent and purpose limitation at collection; data minimization and on-device processing where feasible; access control and de-identification for storage; restrictions on secondary use and onward transfer; and rights to deletion. It must also address the difference between the medical context (regulated, with fiduciary duties) and the consumer context (largely governed by commercial terms of service).
De-identification is weaker for neural data than commonly assumed — individual neural signatures can be re-identifying, and inferences can reveal attributes the subject never disclosed, so anonymization alone is not a sufficient safeguard.