I believe people should have the right to whatever they want to do with their own data and no one elses. When I am about to engage with your service and you tell me you're going to mine my data to sell me things or even improve my healthcare, it should be
my decision not the governments. Much of the internet today crosses this boundary: when I came to your website, I never authorized you to allow Facebook to track me with that stupid like button. I also disagree with your right to post pictures of me on Facebook or to share my email address and phone number with that new-fangled contacts app you just downloaded without my permission. However, I do believe you have the right to hand your own data to Google in exchange for services like Gmail and Google Maps.
Furthermore, I believe in a consumers right to sue if they are harmed by a companies misuse of data (Equifax).
Note these policies are very consumer oriented (i.e. it's illegal to put Google Analytics on your site without notifying your users.)
What I'm very worried about is when a policy ends inadvertently fostering centralization. For example, the government might require you to store private user information with one of a set of vetted companies to prevent another Equifax situation.
A better policy might be to allow consumers to sue firms for damages resulting from negligence and prevent firms from forcing consumers into binding arbitration.
> But what is it that you’d like to do with people’s private data that you’re worried will be prevented?
In my experience, medical innovation has stagnated because of unreasonable data protection on the part of firms in reaction to government policy. For example, I've had execs get cold feet on a project that would clearly save lives and improve the bottom-line because there's a perceived security loss.
While there are good arguments for these protections, my only point is that regulation never comes for free: efficiency is inevitably lost somewhere, and you need to be comfortable with the trade-off.