Skip to main contentSkip to footer
Ex-TerCo Goal #2

The Highest Common Factor in Law

When any country passes an evidence-based law that protects people from new digital harms like AI, social media, or dark patterns, that protection should be considered for adoption everywhere. Some lawmakers respond faster than others. Nobody should be left unprotected because of geography.

The Evidence

The "Brussels effect": strong laws already spread, by accident

Columbia law professor Anu Bradford documented how EU rules become de-facto global standards: companies serving the EU's ~450M consumers often apply one compliant standard worldwide because fragmenting is costlier, and other legislatures then copy the rules. The mechanism exists; it's just unsystematic.

Bradford, The Brussels Effect (Columbia)

Microsoft proved "highest common factor" is feasible, voluntarily

In 2018 Microsoft extended GDPR data-subject rights (know, correct, delete, port) to ALL consumer customers worldwide, not just Europeans. Adopting the strongest protection everywhere is operationally realistic. It just should not depend on corporate goodwill.

Microsoft On the Issues (2018)

GDPR-style laws reached 172 countries, but 36 still have nothing

Graham Greenleaf's global census counts 172 countries with data-privacy laws (2025), most GDPR-influenced, the largest legal-harmonization experiment in history. Yet 36 UN member states still have neither a law nor a bill, mostly in Africa and the Pacific.

Greenleaf, Global Data Privacy Laws 2025 (SSRN)

A third of humanity is legally unprotected online

UNCTAD found only ~71% of countries have data-privacy legislation (Europe 96% vs Africa 50%, and just 43% of least-developed countries). Identical users of identical platforms get radically different rights based purely on geography.

UNCTAD Global Cyberlaw Tracker

Brazil's LGPD: deliberate transplantation of a strong foreign law

Brazilian legislators explicitly modeled the LGPD (2018) on GDPR, near-identical data-subject rights and extraterritorial reach, adapted locally. Proof that legal 'transplants' of the best available protection work.

IAPP: GDPR matchup, Brazil

California statutorily imported the UK's Children's Code

California's Age-Appropriate Design Code was explicitly modeled on the UK Children's Code. The statute even points businesses to UK ICO guidance. Similar youth protections followed in Ireland, the Netherlands, and Argentina. Diffusion works, but takes years while children stay exposed.

Future of Privacy Forum comparative analysis

For AI, the speed gap is stark: one comprehensive law, worldwide

The EU AI Act, the world's first comprehensive AI legal framework, entered into force August 2024. Most jurisdictions have nothing comparable, leaving their citizens waiting on whatever the fastest lawmakers produce.

European Commission (2024)

Evidence-based child-safety law is accelerating

The US Surgeon General's 2023 advisory found teens using social media 3+ hours daily face double the risk of depression and anxiety symptoms; Australia then passed the world's first under-16 social-media ban (2024). Science-grounded protections exist. The question is how fast they reach everyone.

US Surgeon General's Advisory (2023)

Even "fast" countries leave citizens waiting decades

The US children's-privacy rule (COPPA, 1998) went unamended from 2013 until January 2025, and the comprehensive federal ADPPA privacy bill died in 2022 without a floor vote. Formal machinery for adopting the best protections, Convention 108+, OECD guidelines, model laws, already exists but is underused.

FTC (2025); Council of Europe Convention 108+

"Systematizing what today happens by accident would close a protection gap that the market and ad-hoc legislating have left open for decades."

Analyze a T&C now