Engaging the strongest arguments
The Fiduciary Commons Framework makes strong claims. Claims of that scope invite serious objections. They should. A framework that cannot survive the strongest version of the arguments against it does not deserve adoption.
This page presents the six most substantive objections the framework faces, stated at their strongest, and explains how the framework addresses each. The method is deliberate: engage opposing arguments at their best, acknowledge what they get right, and then show why the framework's answer is better. The objections are presented in the strongest form their proponents would recognize.
NIST Special Publication 800-63-4 already recognizes selective disclosure, privacy-enhancing technologies, and Zero Trust architecture. The technical infrastructure the framework demands is available without new legislation. What is needed is adoption and funding, not another layer of statutory obligation.
What is correct in this objectionThe technical standards do exist, and the framework does not dispute their adequacy as technical specifications. VIDA's architectural requirements are deliberately designed to mandate the strongest architecture NIST recognizes.
Why the framework's answer is betterNIST can specify how to build a privacy-preserving identity system. It cannot require anyone to build one. It cannot impose enforceable fiduciary duties on the officials who use the system. It cannot give citizens standing to sue when those duties are violated. It cannot prohibit the architecture of surveillance itself. The framework adds the constitutional grounding, the enforceable legal duties, and the private right of action that transform NIST's technical standards from voluntary guidance into constitutional requirements.
The distinction is not theoretical. The Privacy Act of 1974 contains purpose limitation requirements that are structurally similar to what the PDTA mandates. Those requirements have been rendered largely inoperative by the "routine use" exception, which agencies define at their own discretion. Fifty years of administrative interpretation of a statutory standard demonstrates exactly what happens when technical obligations exist without enforceable legal architecture.
The framework's relationship to NIST is successive, not competitive: it mandates the strongest architecture NIST recognizes and adds the legal and constitutional superstructure NIST cannot provide.
Property is the most robust protection the legal system offers. Owners can exclude others, seek damages for trespass, and alienate their property on their own terms. Justice Gorsuch's concurrence in Carpenter v. United States argued for a property-based approach to digital privacy. If data belongs to citizens, property law already supplies the needed protections.
What is correct in this objectionJustice Gorsuch is right that individuals have a constitutionally cognizable interest in their data records. His analysis reaches the correct destination: individuals should have enforceable rights against government with respect to their personal information. The framework agrees on the destination and diverges on the path.
Why the framework's answer is betterThe property model fails at three structural points, each of which the fiduciary framework resolves.
First, facts are discovered, not created. The underlying facts that data records memorialize, where a person went, what services she received, what taxes she paid, were not authored by anyone. Copyright law has recognized since Feist that facts cannot be owned. Applying property rights to facts requires either accepting that legal fiction or arguing that data records are sufficiently original compilations to warrant protection, a theory that makes constitutional rights contingent on private database architecture.
Second, property can be alienated. If data is property, property law's default rules permit transfer through contract. Users routinely "consent" to data collection under conditions of structural coercion. A property regime that permits alienation under those conditions provides less protection than a fiduciary regime whose obligations are inalienable.
Third, and most fundamentally, the property model cannot reach government's own databases. When government collects data through mandatory administrative processes, no voluntary transfer occurs. Property law's trespass framework presupposes a voluntary exchange or an unauthorized taking. Government data collection is authorized by law, which means the property framework must locate the wrong somewhere in the subsequent use, precisely the move the fiduciary framework makes with enforceable duties rather than ownership claims.
The fiduciary framework accommodates what is correct in Justice Gorsuch's analysis while avoiding what is problematic. The individual does have a custodial interest in their data, but that interest is better understood as trusteeship than ownership, because trusteeship generates enforceable duties without requiring the fiction that facts can be owned.
Feist Publications, Inc. v. Rural Telephone Service Co. held that facts cannot be copyrighted because copyright protects only original expression. Extending that principle to argue that facts cannot be owned in any legally cognizable sense goes beyond what the Court held. The Copyright Clause and the Fourth Amendment protect different interests, and doctrines developed under one do not automatically transfer to the other.
What is correct in this objectionThe correction is technically accurate. Feist is a copyright decision, and its holding is limited to the Copyright Clause. Extending it beyond that context requires independent justification.
Why the framework's answer is betterThe framework's commons premise does not depend on Feist as binding precedent in the Fourth Amendment context. It draws on Feist for the most economical statement of a principle that pervades the legal system: facts are not the product of authorship and cannot be made exclusive to any party. The framework then develops that principle independently through trust law, commons theory, and constitutional structure.
The framework's argument proceeds as follows. Feist recognizes that facts cannot be copyrighted because they are not authored. The framework observes that the same characteristic, the absence of authorship, means facts cannot be owned in any legally cognizable sense: not as copyright, not as trade secret (facts that become public are not secret), and not as real or personal property (facts have no physical corpus and are not the product of labor in the Lockean sense). The commons treatment of personal data therefore rests on the nature of facts themselves, not on any single case.
The distinction matters operationally. If facts could be owned as property, the wealthy could purchase exclusive access to information, creating informational monopolies over public records. If facts could be owned by the person they describe, individuals could suppress truthful information about themselves that others have legitimate interests in knowing. Both outcomes are incompatible with constitutional governance. The commons framework avoids both by treating facts as resources that can be governed but not owned.
Law enforcement depends on rapid access to information across databases. An officer investigating a kidnapping needs to cross-reference phone records, toll records, license plate data, and financial transactions without waiting for individual warrants on each. Fraud prevention requires checking a benefit application against existing records to catch duplicate claims, stolen identities, and coordinated fraud rings.
What is correct in this objectionThe operational concerns are real. Cross-agency data access serves legitimate purposes, and any framework that ignores those purposes will fail in adoption. The framework takes this objection seriously because law enforcement effectiveness is a genuine public good.
Why the framework's answer is betterThe framework does not prohibit law enforcement access to data. It requires that access satisfy constitutional standards that already apply but are not architecturally enforced. Probable cause and judicial authorization are existing Fourth Amendment requirements; the framework builds systems that implement them rather than systems that bypass them.
The practical question is whether constitutional compliance is operationally viable. The evidence says it is. The VLPFA, the framework's companion statute governing automated license plate readers, demonstrates the principle concretely: a scan checks a plate against active warrants, confirms or denies, and retains nothing about plates that do not match. Law enforcement receives every alert it would have received under the current system. What it loses is the ability to build a retroactive movement database of every vehicle that was not suspected of anything.
The fraud prevention objection meets the same answer. Eligibility verification and fraud detection can operate through query-without-collection: a system confirms that an applicant meets eligibility criteria without copying the underlying data into a separate database. The verification happens; the surveillance capability does not.
Technology companies and government agencies operate across state lines. A patchwork of inconsistent state privacy and data governance frameworks creates compliance burdens that favor large organizations and may ultimately be preempted by federal legislation, rendering state-level efforts futile.
What is correct in this objectionRegulatory patchwork is a genuine cost, and interstate inconsistency creates real compliance burdens. The objection is strongest when it observes that federal legislation could expressly preempt state privacy law, as the Gramm-Leach-Bliley Act preempts state law in financial privacy.
Why the framework's answer is betterThe framework's preemption resistance rests on three independent foundations.
First, constitutional grounding. The framework derives its authority from the Fourth Amendment and the government-citizen fiduciary relationship, not from general police power or commerce-clause authority. Federal preemption of state laws that implement federal constitutional protections faces a much higher constitutional bar than preemption of state commercial regulations.
Second, the federal impasse is structural, not contingent. Congress has not enacted comprehensive privacy legislation despite decades of advocacy. The competing interests of the technology industry, law enforcement, and national security agencies have produced a durable equilibrium that prevents federal action. Waiting for Congress to act is not a strategy; it is a decision not to act.
Third, state leadership has historical precedent and structural advantages. State legislatures face narrower versions of the political dynamics that produce federal paralysis. California's CCPA demonstrated that a single state's enactment can shift the national conversation and create de facto national standards through market pressure. Utah's SEDI legislation is playing the same role for identity architecture.
The framework's three foundational statutes are model legislation designed for state adaptation, with bracketed provisions for legislative specification. Interstate consistency is promoted through uniform model language, not through federal imposition.
State IT budgets are constrained. Legacy systems are deeply embedded in agency operations. Replacing integrated databases with purpose-sequestered architecture requires fundamental redesign of enterprise systems that took decades to build. The costs of compliance would consume resources needed for direct services to citizens.
What is correct in this objectionLegacy system transitions are genuinely difficult. Procurement cycles are long. Enterprise architecture changes are complex, expensive, and politically difficult. These are not objections the framework can dismiss.
Why the framework's answer is betterThe cost objection rests on a premise the framework challenges: that constitutional compliance requires new spending beyond what states already plan to spend. States rebuild identity infrastructure, database systems, and cybersecurity architecture on regular procurement cycles, typically five to eight years. The framework does not require rebuilding outside those cycles; it requires that when systems are rebuilt, they be rebuilt to constitutional specifications. The marginal cost of building the right architecture is substantially lower than the cost of building the wrong architecture and then paying to fix it.
The framework's implementation provisions reflect this procurement-cycle logic. New or re-platformed services must comply within 24 months. Existing services have 48 months. Legacy systems that cannot be modified within those timelines receive documented exceptions with specific remediation plans and sunset dates.
The security argument independently supports the cost case. Purpose-sequestered databases limit breach scope: a compromise of a tax administration system cannot reach health records or family court records. The 2024 NASCIO-Deloitte Cybersecurity Study found that only 22 percent of state CISOs describe themselves as highly confident in their ability to protect government data. The architectural mandate the framework requires is also the architecture cybersecurity professionals recommend.
These six objections are the strongest the framework has encountered. They are not the only ones possible. Constitutional frameworks that matter get tested by people who know more about their constituent fields than the author does. Critiques that survive scrutiny will improve the framework. That is not a concession; it is the method.
If you see an objection that is not addressed here, or if you believe one of these responses fails, please say so: scholarship@fiduciarycommons.com