What Gets Enforced? How Power Decides Which Safeguards Still Matter

This post explores selective enforcement, data protection, and how institutions decide which safeguards still matter in practice.

PSA: Rules rarely vanish first. More often than not, it seems that institutions (including and/or excluding the government) decide which protections still apply.

Have you ever noticed that people often talk about rights as if they can only disappear when a law gets repealed?

For example, when things that appear “on paper” seem definite and definitive, but they quietly shift in the background, so the enforcement around those same things (on paper) abruptly and/or simultaneously changes. With or without notice.

And no, I am not talking about AI slop.

It’s when a safeguard may still exist, but only for some people. It also happens when a right remains (technically) intact or when people are told the system is too complicated to challenge and that they should “just leave it to the experts” and keep their opinions to themselves.

That is what today’s post is about, but in a data protection sense, and part of a larger sociotechnical conflict happening around us in real time, around enforcement.

What gets enforced and who enforces

Not every rule bears the same weight in practice. Some rules (or regulations) seem to be enforced quickly and aggressively. Others are treated like suggestions and sometimes even get praised in public while being hollowed out in implementation. However, that is one reason I do not think “having rules” is enough, and I am starting to realize (or at least noticing a pattern) that I’m not the only one.

There is debate over whether those same “rules” can actually constrain power, whether institutions are willing to apply them consistently, and/or whether ordinary people can still (truly) rely on them. That is also part of who gets included while safeguards are still taking shape.

If not, then the problem is not only for the legal folks in the room. It is structural.

Privacy law on paper is not the same as privacy in practice.

While going through this week’s literature, that tension showed up across an ethics cohort that I’m in (I’ll explore that in another post). More specifically, in a Stanford HAI brief, Jennifer King and Tiffany Saade argue that current privacy frameworks are “fundamentally incompatible” with how foundation models are built and that existing rules still do not “meaningfully change developer behavior.” You can read that here: Data Privacy and Foundation Models: Can We Have Both?

Then, in a User Privacy and Large Language Models paper, the authors make a related point from the U.S. side. They argue that without federal privacy regulation, governance of personal data used to train LLMs will remain “limited and fragmented.”

In my opinion, those points do not cancel each other out. They sharpen each other.

One point is about fit. The other is about coverage. See the difference?

The HAI brief warns that if models are built through mass scraping, memorization, chat retraining, and opaque interfaces, then privacy principles like data minimization and purpose limitation are strained from the start. Then, the privacy policies paper adds that the U.S. is especially weak here. For example, at the statewide level, the California Consumer Privacy Act (CCPA, as amended by the California Privacy Rights Act, CPRA) excludes most publicly available information, leaving fewer meaningful limits once data is placed in these systems.

That is not a small distinction. It means that a framework can exist and still fail to hold the line.

Coverage is not the same as control.

This is also where I believe many of us can get tripped up. However, what I’ve gathered from this and other research, and personal and professional experience, is that a company rule or perhaps even a law that covers some category of data is not the same as ordinary people having real control over how their data is collected, reused, shared with a third party, inferred from, or retained.

That privacy policies paper also makes that painfully clear. It found that all six frontier developers that they studied appear to train on users’ chat data by default. Some of the frontier developers retained data indefinitely. It also found that developers’ privacy policies often leave out essential information about those practices.

Animated clip of a man in colonial-style clothing holding a book and quill, with text that reads, “Rules for thee but not for me.” One example of selective enforcement.
GIF via GIPHY.

So before we get to questions of fairness, manipulation, or market power, we are already staring at a “simpler” problem: What good is data protection if a system is built to absorb as much data as possible in the first place, and the rules used as guardrails are ineffective and/or cannot be (practically or not) implemented in the first place?

This is not purely a technical problem, but an enforcement problem. It is also part of what gets tracked once safeguards start failing in practice.

This is what selective enforcement looks like.

To stick with current events, there’s a Tech Policy Press article on ICE that makes this painfully concrete. In the article, an expert on privacy and technology, Jake Laperruque, describes how ICE can use mass phone location tracking, facial recognition, and license plate surveillance to monitor protesters and observers, often by leaning on data brokers, vendor systems, and other forms of surveillance infrastructure. You can read that here: How ICE Will Spy On Protesters, And How You Can Protect Your Privacy.

In short, it shows us how rules around data can be sidestepped without being formally erased. Also, the article points out that cellphone location tracking generally requires a warrant, yet agencies can still work around that protection by buying location data through brokers. Furthermore, it describes how facial recognition and license plate surveillance expand monitoring power in ways that are hard to contest once the infrastructure is already in place.

That is a useful example for this post because it shows the mechanics. It also shows that power does not always need to openly repeal a safeguard. Sometimes they just route around it. That is also one way harm becomes routine inside a system.

Safeguards can exist and still fail.

If we collectively assume that danger begins only once a protection is fully gone, then that becomes our new normal.

Think about recent happenings regarding the stripping away of our fundamental rights (Roe v. Wade). Before Roe v. Wade was repealed, it was considered one of the substantive due process precedents.

And guess what? There’s a whole list of precedents! To stay on topic, I’d like to believe that the precedent most relevant to this post is our fundamental right to privacy. Now, if we lived in the EU, that would be true (here’s their Charter of Fundamental Rights). However, in the U.S., there’s a patchwork of distinctions between our right to privacy and data privacy/protection and it ranges from constitutional to statutory to sectoral. You can see how they get segmented here: https://www.law.cornell.edu/wex/right_to_privacy#:~:text=Further%20Reading,the%20following%20pages%3A

Animated clip of a man in historical costume flipping through a book, with text that says, “Me looking for loopholes.”
GIF via GIPHY.

Or they can be weakened.

Anyway, in practice, a safeguard can stay on the books while being weakened through loopholes, underenforcement, fragmented oversight, vague policies, weak transparency, plain intimidation, and the list goes on. So, although it may not be intentional, this is what happens. That isn’t new either. And it should never be construed as normal. For example, the Supreme Court has at times suggested that the “liberty” protected by the Due Process Clause includes the right to informational privacy. Whalen v. Roe (1977) is a good example, as the Court identified an individual interest in avoiding disclosure of personal matters, though it did not strike down the state law.

These are just some of the reasons why the question is not just about whether a protection/rule/law exists, but whether the structure around it still has enough force to matter.

And it doesn’t seem like policy design can solve it singlehandedly.

More importantly, though, the HAI brief pushes this point toward policy design. It argues for removing personal data from the training pipeline, increasing transparency, building privacy and security by design, and constraining privacy-infringing outputs. In other words, it is not enough to say privacy matters after the fact. The system has to be built in ways that give that principle some teeth. If it is not, people are left to depend on developers, agencies, or institutions to voluntarily do the right thing.

That is a weak position for us, the public, to be in. By then, who absorbs the risk is rarely the actor with the most power.

The public keeps getting the weaker version of protection.

Another thing that resonated in the privacy policies paper is the mentioning of how enterprise users are typically opted out of model training, while ordinary users are expected to opt out on their own. That is not simply a design choice. It reflects whose privacy is treated as more worthy of protection by default.

If meaningful privacy defaults are good enough for enterprise customers, then the issue is not whether stronger protections are possible. It is whether institutions and companies are willing to extend them more broadly.

That is one reason I do not think selective enforcement is something governments do alone. Companies do it too, through product design and policy language, but I’ll leave that for another post.

What gets enforced is also a question of power distribution.

At this point, I think the deeper issue becomes harder to ignore. Once a structure begins applying safeguards unevenly, the rule itself ceases to be the only thing that matters.

Animated clip of a man in historical costume refusing questions, with text that says, “No! You don’t get to ask me questions.”
GIF via GIPHY.

What do we do with that?

Ultimately, I am writing this post to help consolidate thoughts and document the reality that we have found ourselves in. If I had to choose one or two things, I believe we have to get more honest about the difference between having protection and being able to rely on it, and that privacy, surveillance, and enforcement are not isolated topics. The same goes for what gets trusted once doubt becomes part of the information environment. The tools may differ, but the structure is often similar. If I had to choose one more thing, it would be to start asking better questions sooner (more loudly and openly) to help defend rights from where we already are.

The takeaway

We can see that rules rarely disappear first. We can also see that rules can remain visible as enforcement/safeguards (looking at you, checks and balances) shift. So perhaps a better question is not only on what protection(s) exist, but whether institutions still treat them as constraints, or now treat them as obstacles to be routed around.

Overall, what gets enforced can tell us more than any mission statement, policy page, or public promise ever could. It tells us whose safety, privacy, and rights still matter.

And that is one of the clearest ways power reveals itself.

Content on this website and blog is for informational purposes only. Any opinions, reviews, or experiences expressed here are those of the author and do not necessarily reflect the views of others. Any tools or technologies mentioned are shared for informational purposes only and do not constitute an endorsement, affiliation, or recommendation. This post/page does not establish a client relationship with Jarred Andrews. Please review the Disclaimer, Copyright, Privacy Policy, and Terms pages for more information.
Comments
2

Leave a Reply