Neurorights, Law, Policy & Governance Frontier

Ownership and control of neural data

The question of who holds rights over neural signals — the individual, the device maker, the clinic, or a platform — and whether those rights are best framed as property ('ownership') or as control (consent, access, correction, deletion). Most legal systems avoid propertizing personal data and instead grant control-type rights, and that is the dominant approach for neural data too.

Concrete law has begun with consumer neurotech. In 2024 Colorado amended its privacy act to classify 'neural data' as sensitive data — the first US state to do so — and California amended the CCPA to add neural data to sensitive personal information. These statutes reach consumer devices; medical neural data is generally governed instead by health-privacy and medical-device regimes.

Ownership framing is intuitive but problematic: property rights can be waived or sold, potentially enabling the very exploitation they aim to prevent. Control- and dignity-based framings (inalienable protections) are often preferred precisely because they cannot be signed away in a single terms-of-service click.