Neurotech
Neural data and who gets to hold it
Recordings from the brain are unusually intimate, largely unregulated as a category, and several jurisdictions have started legislating specifically.

Most privacy frameworks were written around identifiers, transactions and communications. Neural recordings do not fit those categories comfortably, and the gap has become a legislative topic.
Why neural data is treated as different
Several properties distinguish it.
It is not volunteered. A search query is composed deliberately. Neural activity is continuous and largely involuntary.
It may contain information the subject has not disclosed and does not intend to. Even where decoding of specific thoughts is not currently possible, recordings may carry markers relevant to neurological or psychiatric conditions.
It is difficult to anonymise. Individual neural signatures appear to be identifying, in the way that fingerprints and gait are.
It is not revocable. A leaked password can be changed.
Its future readability is unknown. Data collected now may be interpretable by techniques developed later. This is a general problem with biological data and it is acute here.
Where the current gap is
Medical devices used in clinical settings are covered by health data protections in most jurisdictions.
Consumer devices are largely not. A headband sold as a wellness product, collecting EEG continuously and uploading it, may fall outside health data rules entirely — and be governed only by a terms of service document the user did not read.
That document frequently grants broad rights: to use the data for product improvement, to share it with partners, and to retain it indefinitely.
The asymmetry is stark. The same signal recorded in a clinic is protected; recorded by a consumer wearable it is a commercial asset.
What has been enacted
Several jurisdictions have moved.
Chile amended its constitution to protect mental integrity and neural data, and its courts have applied it in a case involving a consumer device.
Several US states have amended consumer privacy statutes to include neural data within sensitive personal information, which brings consent, disclosure and deletion requirements.
UNESCO and other international bodies have produced recommendations on the ethics of neurotechnology.
The direction is consistent: treat neural data as sensitive by default rather than by context.
The concept of neurorights
The framework most commonly proposed, generally comprising a handful of claims.
Mental privacy — protection from unconsented access to neural data.
Personal identity — protection from technology that alters sense of self without consent.
Free will and agency — protection of decision-making from external manipulation.
Fair access to cognitive augmentation, should it become available.
Protection from algorithmic bias in systems interpreting neural data.
Critics argue these largely restate existing rights and that specific regulation of data practices would achieve more than a new category of right.
Both positions have force, and the practical outcome so far has been data protection amendments rather than constitutional change in most places.
What could reasonably be asked of a device
Concrete requirements, several of which good products already meet.
On-device processing by default, with raw signals never leaving the hardware unless the user explicitly opts in.
Explicit, granular consent for each use — product improvement, research, third-party sharing — rather than a single acceptance.
Retention limits, with automatic deletion.
Portability and deletion rights that actually work, including for derived models.
No secondary use for advertising, insurance or employment purposes.
Transparency about what is inferred, not just what is collected. Inference is where the sensitivity lies.
A continuity plan for what happens to the data, and to an implanted device, if the company ceases trading.
The employment and insurance questions
The near-term applications most likely to cause harm.
Workplace monitoring using EEG-based fatigue or attention detection is already marketed, particularly for safety-critical roles such as long-distance driving and heavy machinery.
There is a legitimate safety argument for it and an obvious potential for misuse in performance monitoring.
Several jurisdictions restrict biometric monitoring in employment; whether existing provisions cover neural signals varies.
Insurance is the other case. Data suggesting elevated risk of a neurological condition would be commercially valuable and its use would be, in most people's view, unacceptable.
Genetic information has specific statutory protection in several countries for exactly this reason. Neural data currently does not, in most.
The practical advice
For anyone using a consumer neurotech device: read what the company says it does with the data, check whether processing is local, and assume that anything uploaded may persist indefinitely and be reanalysed later.
That is not paranoia. It is the standard assumption for any biological data, and neural data is the most intimate example of it.





