GP-IGCSE 9G
Should global digital law place
limits on how much personal data
tech companies can collect, store,
and monetise
Introduction
In an increasingly digital world, personal data has become one of the most valuable
resources. Tech companies like Meta, Google, TikTok, and Amazon collect and
monetise vast amounts of user information, which raises growing concerns about
privacy, surveillance, and consumer protection. In 2023 alone, global data
generation exceeded 120 zettabytes, with estimates predicting a rise to 181
zettabytes by 2025. As data collection becomes more intrusive and commercially
valuable, the debate intensifies: should global digital law limit how much data tech
companies collect, store, and monetise? This report argues that yes,international
limits are urgently necessary to protect privacy and prevent exploitation and stop
monetization from companies.
What is personal data and what's the issue
Personal data refers to any digital information that can identify a person—such as
location, biometrics, browsing behaviour, contacts, messages, and purchasing
habits. Tech companies rely on this data for targeted advertising, algorithmic
prediction, personalised services, and revenue generation. In 2022, over 81% of
global online revenue from social media platforms came from targeted advertising,
which depends heavily on large-scale data harvesting. This economic dependency
makes companies do this data practice.
The issue is global because personal data moves across borders instantly. For
example, a user in India may have their information collected through an app, stored
on cloud servers in Singapore, analysed by machine-learning systems in the United
States, and then sold to advertisers based in Europe. This creates an international
data chain where multiple countries are involved in the collection, storage, and
monetisation of a single individual’s personal information. Since every country has
different digital laws, national regulations alone cannot effectively govern these
cross-border data flows.
Additionally, the world has seen a huge rise in data breaches, which shows the risks
of excessive data storage. Global breaches increased from 1,506 incidents in 2019
to over 2,365 in 2023, compromising billions of records. These leaks often expose
names, photos, phone numbers, medical histories, and even financial details. Many
breaches occur because companies store massive amounts of data for extended
periods, increasing the likelihood of cyberattacks and criminal misuse. This global
2
pattern demonstrates the urgent need for coordinated international limits on data
collection and retention.
This continuous cycle is barely regulated globally, despite its enormous influence on
individual rights, technological development, and economic systems.
Analysis of Perspectives
1. Government / Legal Perspective
Governments emphasise national security, economic growth, and consumer
protection. Countries such as India (Digital Personal Data Protection Act 2023) and
3
the EU (General Data Protection Regulation, GDPR) argue for stricter limits on data
collection to safeguard citizens. The GDPR, for example, enforces the principle of
data minimisation—companies may only collect data strictly necessary for their
services. Many governments fear that excessive corporate data power can
undermine sovereignty. In addition, large data monopolies allow tech giants to
influence elections, public opinion, and political discourse, which governments
perceive as a threat to democratic processes. However, some governments—such
as the US—prioritise innovation and allow companies broad freedom, arguing that
strict global rules may slow technological progress.
2. Humanitarian / Victim Perspective
From a humanitarian viewpoint, unlimited data collection violates fundamental
privacy rights and exposes individuals to exploitation. Breaches of medical records
can cause psychological distress, while leaks of location data can enable stalking,
identity theft, financial fraud, or discrimination. In 2021, over 533 million Facebook
users had their personal data leaked, including phone numbers—demonstrating
how corporate negligence can affect global populations. Human rights groups
argue that communities face the highest risk because algorithms trained on
massive datasets can produce biased outcomes in hiring, policing, or access to
credit. The humanitarian perspective strongly supports limiting data collection to
reduce harm, prevent discrimination, and protect vulnerable groups, especially
children.
3. Corporate / Economic Perspective
Tech companies argue that data collection is essential for providing free digital
services, supporting innovation, and improving user experience. Targeted
advertising funds platforms like Instagram, YouTube, and TikTok, allowing them to
remain free for billions of users. In 2023, advertising accounted for 97.4% of Meta’s
total revenue, demonstrating the dependence on user data. Additionally,
companies claim that strict limits may weaken competitiveness against nations
with more relaxed data laws, such as China. From an economic perspective, the
4
ability to monetise data supports growth, employment, and AI development.
Companies therefore prefer self-regulation over international law.
This shows the average cost of a data breach by country in 2022
Legal Challenges and Limitations
Current global digital law is fragmented. Different nations apply different rules: the
EU uses strong data protection (GDPR), India recently passed its DPDP Act, while
the United States lacks a single federal privacy law. This inconsistency creates
loopholes that tech companies exploit by moving data storage or processing to
nations with weaker regulations.
5
1. Jurisdictional Limits:
No single country can control what happens to data once it crosses borders. A
company headquartered in the US but storing data in Ireland and selling analytics in
Asia becomes a legal puzzle. Courts struggle to determine applicable jurisdiction,
leading to long delays in investigations.
2. Enforcement Difficulty:
Even when laws exist, enforcing them against trillion-dollar corporations is
expensive and politically challenging. GDPR fines (e.g., Ireland’s €1.2 billion fine on
Meta in 2023) show progress, but enforcement is slow. Many smaller countries lack
the capacity to impose compliance on global tech corporations.
3. Ambiguity in Consent Models:
Most companies rely on vague consent forms, often hundreds of pages long. Users
technically “agree,” even though they do not understand what data is being
collected. This legal loophole allows nearly unlimited data harvesting while
companies claim it is voluntary.
4. AI and Predictive Algorithms Escalate the Problem:
Modern AI systems require enormous datasets. Without clear global rules,
companies collect and store unnecessary data “just in case” it becomes useful for
machine learning. This leads to excessive retention periods and increased breach
risks.
Overall, legal fragmentation, weak enforcement, and technological complexity allow
companies to collect and monetise far more data than necessary.
6
Conclusion and Proposed Solutions
The analysis shows that unlimited corporate data collection poses serious threats
to privacy, human rights, and global digital safety. While tech companies argue that
data is essential for innovation, the humanitarian and legal perspectives highlight
the significant risks associated with excessive data harvesting. Therefore, global
digital law should place firm limits on how much personal data companies can
collect, store, and monetise.
Proposed Solutions
1. Establish a Global Data Protection Framework (GDPF):
An international treaty under the United Nations or G20 that sets universal
rules for data minimisation, storage limits, cross-border transfers, and user
rights. This would reduce legal fragmentation and enforce consistent global
standards.
2. Mandatory Data Minimisation Audits:
Tech companies should undergo independent annual audits to justify why
each type of data is collected and how long it is stored. Unnecessary data
must be deleted regularly.
3. Ban Monetisation of Sensitive Data:
Data such as biometrics, health records, and children’s information should
not be monetised under any circumstances.
4. Greater Transparency and User Control:
Users should have access to simple dashboards showing what data is
7
collected and the ability to delete it at any time.
These solutions offer a practical pathway to protecting global privacy while still
encouraging innovation.
References (APA Style)
European Commission. (2023). EU General Data Protection Regulation (GDPR)
enforcement tracker.
Meta Platforms Inc. (2023). Annual report.
Statista. (2023). Global data generation statistics 2015–2025.
Pew Research Center. (2023). Public attitudes on data privacy and surveillance.
IBM Security. (2023). Cost of a Data Breach Report.
8
ENGLISH
“In an agreeable voice” – This shows that Mrs Jellyby tries to appear pleasant and polite, even though she is not truly paying
attention to her guests or family.
“Too much occupied with her African duties” – This phrase reveals that she is completely absorbed in her distant charitable
projects, ignoring the needs of her own home.
“The room… very untidy and very dirty” – The messy and unclean house suggests that she neglects household responsibilities
and does not manage her family’s basic comfort.
“A jaded and unhealthy-looking girl” – Her daughter’s tired appearance shows the harmful effect of Mrs Jellyby’s neglect on
her children.
“Ink… from her tumbled hair to her pretty feet” – This description of her daughter covered in ink highlights the disorder in the
house and the lack of guidance for the children.
“You find me, my dears, as usual, very busy” – Mrs Jellyby proudly claims constant busyness, showing that she believes her
outside work is more important than caring for her family.