· rreck · data · 15 min read
Considerations in data sovereignty
Data sovereignty means continuing, revocable control over data about yourself. A measurement of 5,791 current agreements, 861,316 policy snapshots across 22 years, and 19 before-and-after GDPR pairs shows the mobile-app EULA is engineered to make that control impossible: postgraduate prose, terms that can be rewritten silently, no version to cite, and no way to say no.
This is a position piece, and it stands on other people’s shoulders. The corpora measured here were built and shared by others — the Princeton-Leuven team’s million-snapshot policy archive, the CLAUDETTE project at the European University Institute, Carnegie Mellon’s Usable Privacy Policy Project, the ToS;DR community, and the Internet Archive — and the argument draws on four decades of contract and privacy scholarship, cited throughout. The measurements are ours; the raw material and the intellectual groundwork are theirs. What we add is a position: read together, their data says something stronger than any of them has claimed.
Data sovereignty is usually discussed as a matter of states — where the servers sit, whose courts have jurisdiction. But the research literature settled on a more personal definition: sovereignty over data means meaningful, continuing, revocable control over information about yourself — the ability to know the terms that govern it, to contest them, and to leave (Hummel et al., Big Data & Society, 2021). By that definition, the most consequential data-sovereignty instrument in your life is not a treaty or a regulation. It is the agreement under the “I Agree” button on your phone — and it is engineered so that the sovereignty flows one way.
This piece measures that engineering. We ran readability and structural analysis over 5,791 current consumer agreements, 861,316 historical policy snapshots spanning 1997–2019, and 19 matched before-and-after pairs for major apps — and put the results against forty years of contract scholarship. The finding is not that these documents are merely long and dull. It is that they systematically extinguish every dimension of sovereignty the literature names: control, voice, exit, redress, jurisdiction — and above all, audit. Three percent of mobile-app agreements carry a version number. There is no meaningful way to decline. No version, no exit.
Unreadable, everywhere, always
Measured with the standard readability instruments (Flesch-Kincaid, SMOG, Gunning Fog, Coleman-Liau, ARI), every corpus of consumer terms we examined lands in the same band:
- 5,312 current agreements tracked by ToS;DR: median grade 14.2, SMOG 15.6.
- The 50 terms-of-service in the CLAUDETTE research corpus (2016–18): grade 16.2, SMOG 17.1 — 98% above 12th grade.
- 79 privacy policies from the CMU OPP-115 corpus (2013–16): grade 15.2.
- The current terms of 30 top mobile apps: grade 15.9, SMOG 16.8, median 5,477 words.
The average American adult reads at roughly an 8th-grade level. Legal scholars Benoliel and Becher, measuring the 500 most popular US sign-in agreements, put the requirement at more than 14.5 years of education and named the result a structural contradiction: a legal duty to read attached to documents empirically written not to be readable. Our measurements reproduce theirs on a corpus ten times larger.
The historical record is more damning than any snapshot. The Princeton-Leuven corpus preserves over a million privacy-policy captures going back to 1997, with readability precomputed for each. Across 861,316 curated snapshots and twenty-two years, the share of policies rated “easy,” “fairly easy,” or “very easy” — in either the pre- or post-GDPR era — rounds to 0.0%. Not rare. Zero. Ninety-nine percent of everything anyone was ever asked to agree to was rated difficult or worse. Unreadability is not a lapse of craft; it is the invariant.
The regulation that made it longer
The strongest natural experiment in this space is the GDPR, whose Article 12 has required “concise, transparent, intelligible” terms in “clear and plain language” since May 2018 — the one time a major jurisdiction legislated readability. The million-snapshot record shows what happened. Median policy length crept from 266 words (1997) to 1,054 (2017), roughly 4% a year. Then, in the eighteen months after enforcement, it jumped 33% — 1,136 to 1,514 words — while median grade level reached 13.0, the hardest in the corpus’s history. On the strict cut, policies after GDPR are 52% longer and slightly harder to read than before it. Independent studies agree: Degeling et al. measured +42% length in 2018 alone; Wagner’s 25-year study finds policies quadrupled since 2000, reaching the readability of a law-review article. Compliance became more words, and more words became less sovereignty: the mandate to be clear was answered with prose no one can audit.
Our matched pairs make it concrete. Of 19 major apps whose terms we captured both pre-GDPR (2016–17, via the Internet Archive) and today, 16 got longer — the median by about 2,800 words. Roblox went from 7,146 words to 37,289 (+422%). Reddit went from 3,355 to 14,234 and from grade 14 to grade 19 — postgraduate. Airbnb’s stack now runs 40,899 words: nearly three hours of continuous reading for one service. Even Signal, the privacy community’s darling, grew sixfold. To know the terms of an ordinary phone’s apps is no longer a chore; it is a part-time job.
The science of not reading
None of this would matter if people read the agreements anyway. They do not, and the empirical literature has measured exactly how much they do not. Tracking 48,154 shoppers across software retailers, Bakos, Marotta-Wurgler and Trossen found that one or two in a thousand ever open the license at all, and those who do skim it. In Obar and Oeldorf-Hirsch’s controlled experiment, 74% skipped the policy entirely and 98% missed clauses requiring them to share data with the NSA and surrender a first-born child. McDonald and Cranor computed the reason two decades ago: merely reading the policies one encounters would cost each American roughly 200+ hours a year — a national opportunity cost they priced at $781 billion. Not reading is not laziness. It is the economically correct response to documents priced, in time, beyond any rational budget.
Contract law long ago named the underlying object: the contract of adhesion, “private legislation” imposed take-it-or-leave-it, in Friedrich Kessler’s phrase — from 1943. What the digital form adds is scale and a new twist the older literature could not have imagined: the document itself has become unstable.
No version: the sovereignty of a moving target
In our earlier clause analysis of 92 mobile-app EULAs, 75% reserved the right to rewrite themselves at any time, and 73% bound the user to whatever they become through “continued use.” Against that, 3% carried a version number and 37% a date. The CLAUDETTE research corpus finds the same pattern at near-totality: unilateral-change clauses in 49 of 50 agreements examined. And the change right is exercised: Marotta-Wurgler and Taylor tracked 264 software EULAs across seven years and found 39% materially changed terms — growing longer and more seller-friendly — with no consumer-facing version history. David Horton’s name for the result is exact: shadow terms. The text that governs you at any moment is unknowable in advance.
Put the two facts together and the sovereignty analysis completes itself. You are bound, continuously and automatically, to a document that can change without notice — and that document carries no version stamp by which you could detect the change, cite the text you accepted, or prove it later in a dispute. Control requires an object; here the object is unfixed. Courts have occasionally said as much — the Ninth Circuit in Douglas v. Talk America held that posting revised terms without notice binds no one, and Harris v. Blockbuster found an unlimited amendment right renders the contract “illusory” — but a court can only compare versions someone preserved. The 3% figure is the measurement of the shadow.
It takes outside institutions to reconstruct what the vendors will not stamp. The EFF’s TOSBack tracker, ToS;DR’s crowdsourced annotations, and now Open Terms Archive — which diff-tracks agreements the way a wiki tracks edits, and which the European Commission adopted to power its official Digital Services Act terms database — all exist for one reason: the counterparty to billions of contracts declines to version them. Regulators themselves cannot audit these documents without third-party version control. That is not an oversight. An unversioned document is unauditable, and an unauditable surrender is unbounded.
No exit: what the clauses take
Sovereignty, in the literature, decomposes into a handful of dimensions: control over the rules, a voice in changing them, the ability to exit, access to redress, one’s own jurisdiction, and the power to audit. Map the standard clause inventory of mobile-app agreements onto those dimensions and the coverage is complete — every dimension has a clause extinguishing it, each at majority prevalence: liability disclaimers (86%) foreclose redress; indemnification (59%) inverts it, making the user underwrite the vendor’s risk; discretionary termination (57%) makes exit a right the vendor holds over the user rather than the reverse; venue selection (61%) contracts the user out of their own courts; unilateral modification (75%) and continued-use assent (73%) remove control and voice; the missing version number removes audit. This is what Margaret Jane Radin’s Boilerplate calls normative degradation — rights deleted wholesale without anything that deserves the name of consent — and what Shoshana Zuboff calls the “uncontract”: a contract-shaped instrument that abolishes the mutuality contracts were invented to embody. In Couldry and Mejias’s harder frame, these are the treaties of data colonialism: drafted by one side, in one side’s language, under one side’s law, revisable by the stronger party, signed because refusal means exile from ordinary life.
That last clause is the quiet one. There is no negotiation, no partial acceptance, no version of Instagram or Uber or a banking app with different terms. The choice is assent or absence — and absence from app-mediated life is decreasingly a real option. An agreement you cannot refuse, cannot track, and cannot leave is not an exercise of sovereignty. It is the instrument of its transfer.
The tools exist. They are unassembled.
The standard objection is that machine-readable, versioned, negotiable terms are utopian. The record says otherwise: every component has already been built, tested, and standardized. The W3C’s ODRL is a full Recommendation for machine-readable permissions and duties. Its Data Privacy Vocabulary holds 2,394 concepts, including terms for amendment and jurisdiction clauses. Akoma Ntoso — an OASIS standard with built-in versioning of legal texts — already runs the document pipelines of the European Parliament and the United Nations: version-controlled law is production technology today, just not for consumers. What is missing is assembly and incentive. The one consumer deployment ever attempted, P3P, shipped in browsers in 2002 without enforcement — sites published junk policies at scale (11,176 of 33,139 sites in one audit; Facebook’s machine-readable policy literally read “Facebook does not have a P3P policy”) and the W3C declared it obsolete. Machine-readable terms without enforcement get gamed into noise by exactly the parties they would constrain.
And there is a second asymmetry, this one epistemic. We measured the specification stack a motivated citizen must absorb to even discuss machine-readable terms — ODRL, DPV, LegalRuleML, Akoma Ntoso, and their RDF/OWL prerequisites: roughly 370,000 words, sixty to a hundred hours, two to three work-weeks of postgraduate reading. A vendor needs one lawyer-afternoon to add an arbitration clause. The cost of imposing terms and the cost of understanding them differ twenty-fold, and every hour of that difference is paid by the party the terms bind.
What sovereignty would minimally require
Not utopia. Three ordinary mechanisms, each already standard practice elsewhere:
- A version number and a date on every agreement, with a public changelog — the courtesy extended to every software release, RFC, and act of parliament, withheld only from the documents that bind consumers. Auditability is the prerequisite for every other right: you cannot contest, comply with, or litigate a text you cannot identify.
- Notice-and-consent for material changes, with a real exit — the EU’s Directive 93/13 already presumes no-notice unilateral amendment unfair; Douglas and Harris show US courts agree when asked. Continued use is behavior, not consent.
- Convergence on a small set of standard, plain-language licenses, as open-source software did — so that agreement means selecting a known, named, versioned quantity rather than parsing 40,899 bespoke words per app.
None of this is technically hard. Version stamps cost nothing; the European Parliament’s own documents prove versioned legal text scales; the GNU licenses prove convergence is possible. What the measurements in this piece show is why it has not happened: every increment of length, difficulty, and instability transfers a little more sovereignty from the person tapping the button to the party that wrote what the button says. The agreements are not failing at their job. Their job is the transfer. Until the documents acquire versions and the people acquire an exit, “I Agree” will remain what the data shows it to be — the most efficient instrument of sovereignty surrender ever deployed, executed a billion times a day, in a tenth of a second, sight unseen.
Notes and references
Measurements in this piece. Readability computed with textstat (Flesch-Kincaid, SMOG, Gunning Fog, Coleman-Liau, ARI) over 5,791 English-language agreements drawn from the ToS;DR document corpus, the CLAUDETTE 50- and 142-document ToS corpora (EUI), the CMU OPP-115/APP-350 corpora, current and Internet-Archive captures of 30 top mobile apps, and the Apple/Google store-default agreements. Longitudinal figures from the Princeton-Leuven Longitudinal Corpus of Privacy Policies, 861,316 curated snapshots, 1997–2019, strict pre/post cut at 2018-05-25. Specification word counts measured from the primary W3C/OASIS/academic spec documents. Clause-prevalence figures (n=92 mobile-app EULAs) from the companion analysis, Written to Be Agreed To, Not Read.
- Hummel, P., Braun, M., Tretter, M., & Dabrock, P. (2021). “Data Sovereignty: A Review.” Big Data & Society, 8(1).
- Bakos, Y., Marotta-Wurgler, F., & Trossen, D. R. (2014). “Does Anyone Read the Fine Print? Consumer Attention to Standard-Form Contracts.” Journal of Legal Studies, 43(1).
- Obar, J. A., & Oeldorf-Hirsch, A. (2020). “The Biggest Lie on the Internet.” Information, Communication & Society, 23(1).
- McDonald, A. M., & Cranor, L. F. (2008). “The Cost of Reading Privacy Policies.” I/S: A Journal of Law and Policy for the Information Society, 4(3).
- Benoliel, U., & Becher, S. I. (2019). “The Duty to Read the Unreadable.” Boston College Law Review, 60(8).
- Marotta-Wurgler, F., & Taylor, R. (2013). “Set in Stone? Change and Innovation in Consumer Standard-Form Contracts.” NYU Law Review, 88.
- Horton, D. (2010). “The Shadow Terms: Contract Procedure and Unilateral Amendments.” UCLA Law Review, 57.
- Lippi, M., et al. (2019). “CLAUDETTE: An Automated Detector of Potentially Unfair Clauses in Online Terms of Service.” Artificial Intelligence and Law, 27(2).
- Amos, R., Acar, G., Lucherini, E., Kshirsagar, M., Narayanan, A., & Mayer, J. (2021). “Privacy Policies over Time: Curation and Analysis of a Million-Document Dataset.” The Web Conference (WWW).
- Linden, T., Khandelwal, R., Harkous, H., & Fawaz, K. (2020). “The Privacy Policy Landscape After the GDPR.” PoPETs, 2020(1).
- Degeling, M., et al. (2019). “We Value Your Privacy … Now Take Some Cookies.” NDSS.
- Wagner, I. (2023). “Privacy Policies across the Ages.” ACM Transactions on Privacy and Security, 26(3).
- Kessler, F. (1943). “Contracts of Adhesion — Some Thoughts About Freedom of Contract.” Columbia Law Review, 43.
- Radin, M. J. (2013). Boilerplate: The Fine Print, Vanishing Rights, and the Rule of Law. Princeton University Press.
- Zuboff, S. (2019). The Age of Surveillance Capitalism. PublicAffairs.
- Couldry, N., & Mejias, U. A. (2019). The Costs of Connection. Stanford University Press.
- Fairfield, J. A. T. (2017). Owned: Property, Privacy, and the New Digital Serfdom. Cambridge University Press.
- Solove, D. J. (2013). “Privacy Self-Management and the Consent Dilemma.” Harvard Law Review, 126.
- Douglas v. U.S. District Court ex rel. Talk America, 495 F.3d 1062 (9th Cir. 2007); Harris v. Blockbuster, Inc., 622 F. Supp. 2d 396 (N.D. Tex. 2009).
- GDPR, Article 12(1); Council Directive 93/13/EEC, Annex 1(j).
- W3C ODRL 2.2; W3C Data Privacy Vocabulary 2.3; OASIS LegalRuleML 1.0; OASIS Akoma Ntoso 1.0; W3C P3P 1.0 (declared obsolete 2018); Cranor et al., P3P compact-policy audit (CMU CyLab, 2010).
- Open Terms Archive and the European Commission DSA Terms and Conditions Database.



