IP Law as a Structural Model
Intellectual property law spent the better part of two centuries solving a hard problem: how do you prove you created something intangible? Trademark and copyright both developed formal mechanisms for answering that question. Those mechanisms, registration, fixation, priority, and chain of title, are remarkably instructive when you apply them to personal data ownership.
This is not a metaphor exercise. The structural logic of IP law maps directly onto the technical and legal challenges of asserting that a specific individual originated a specific dataset. Understanding where the analogy holds and where it breaks reveals exactly what a purpose-built data ownership framework needs to do differently.
At Own Your Data Inc, the nonprofit behind MyDataKey™, this analysis sits at the core of how the PDAOS™ (Personal Data Asset Origination System) was designed. The goal was never to clone IP law. The goal was to extract its most defensible concepts and rebuild them for the data layer.
Copyright and the Fixation Doctrine
Copyright does not protect ideas. It protects expression. Specifically, expression that has been fixed in a tangible medium. Under the Copyright Act (17 U.S.C. § 102), a work is protected the moment it is created and fixed. Registration with the U.S. Copyright Office is not required for protection to exist, but it is required to bring an infringement lawsuit in federal court.
That distinction matters enormously. Fixation creates the legal fact. Registration creates the evidentiary record. Without the registration, the legal fact is real but functionally difficult to enforce.
Personal data has an analogous problem. The moment you fill out a form, generate a biometric reading, or send a message, data about you is fixed in a tangible medium. A server, a database, a log file. The legal fact of your origination exists. But there is no parallel registration mechanism that captures a timestamped, tamper-evident record of that origination event in a way you control.
That asymmetry is precisely the gap that data ownership infrastructure needs to close. Copyright law already proved that fixation plus registration equals enforceable claim. The architecture just needs to be rebuilt for the data context.

Trademark Law and the First-to-File Problem
Trademark law in the United States operates on a first-to-use standard. Rights attach to the party who first uses a mark in commerce, not the party who first files a registration application. The Lanham Act (15 U.S.C. § 1051 et seq.) encodes this principle. A senior user can defeat a junior registrant in litigation if they can prove prior use in the relevant geographic market.
Most of the world operates differently. The EU, China, and the majority of national trademark systems use first-to-file. Rights attach to whoever registers first, regardless of prior use. Neither system is obviously correct. They reflect different policy choices about what trademark law is meant to protect.
Data ownership faces an almost identical structural debate. When a data broker ingests your information and creates a monetizable profile, they are effectively operating on a first-to-file model. They captured the data, organized it, and now assert a commercial claim over it. You originated the data, you are the first-to-use analog, but absent any registration-equivalent mechanism, your prior origination claim is legally invisible.
This is not a rhetorical framing. It is a structural description of how commercial data markets currently function. The entity that files, that captures and systematizes, wins by default because there is no competing infrastructure for the originator to assert priority.
Where Data Falls in the IP Taxonomy
Raw data is not copyrightable in the United States. The Supreme Court addressed the underlying principle in Feist Publications, Inc. v. Rural Telephone Service Co. (1991), holding that facts are not protectable and that compilations require a minimum threshold of originality. A list of names and phone numbers fails that test.
Personal data, your health metrics, location history, behavioral patterns, sits in a similarly awkward position. The facts themselves are not copyrightable. The compilation of those facts into a database might be, but the copyright would belong to whoever structured the database, not necessarily the individual whose information populates it.
Trade secret law offers some protection for databases under the Defend Trade Secrets Act (18 U.S.C. § 1836), but that protection runs to companies, not individuals. Patent law is irrelevant to this context. Trademark law protects brands, not datasets.
The honest conclusion is that existing IP frameworks were not designed for personal data origination. They were designed to protect creative expression, commercial identifiers, and inventions. Personal data is none of those things. It is a new category of asset that requires a new legal and technical infrastructure. One that borrows the structural logic of IP law while building mechanisms IP law never developed.

Data Origination as Registration
Copyright registration works because it creates a public, timestamped record linking a specific work to a specific author at a specific moment in time. That record does not create the copyright. It proves it. The distinction is subtle but legally critical.
A data origination certificate functions on the same logic. It does not create your ownership of your personal data in a philosophical sense. You already own it in the same way you already hold a copyright the moment you fix a work. The certificate creates a tamper-evident, timestamped record that proves you held that data first.
When a data broker later claims a commercial interest in your information, a verified origination certificate is the equivalent of a copyright registration in an infringement dispute. It shifts the evidentiary burden. It provides a date-certain record of your prior claim. Without that record, your claim is real but unprovable in any adversarial proceeding.
This is why the MyDataKey™ certificate architecture is designed around cryptographic proofing rather than self-attestation. A certificate you generate and hold yourself is the equivalent of writing your name in your own diary. A certificate anchored to a cryptographic hash, issued by a neutral third party with a verified timestamp, is the equivalent of a notarized registration. The legal and practical weight of those two things is not comparable.
What Current Law Still Gets Wrong
The GDPR and CCPA both recognize individual rights over personal data. Access, deletion, portability, correction. But neither framework treats data as property in the ownership sense. They create procedural rights, not title claims.
Under Article 17 of the GDPR, you can demand erasure. Under CCPA (California Civil Code § 1798.100 et seq.), you can demand disclosure of what has been collected. Neither right gives you a positive claim to the asset itself. The kind of claim that would let you assert priority against a commercial entity that monetized your data without consent.
IP law's contribution to this conversation is the concept of chain of title. In copyright, you can track the ownership history of a work. Who created it, who licensed it, who transferred rights. That chain is what makes licensing markets function. Personal data markets have no equivalent chain-of-title infrastructure. Data flows from originator to broker to purchaser with no traceable record connecting the asset back to the person who created it.
Building that chain requires a registration-equivalent system. It requires that origination events be recorded, timestamped, and linked to verifiable identity at the moment of data creation. Not retroactively, not by the entity collecting the data, but by the individual whose data it is.
The PDAOS Approach: Building on IP Precedent
The Personal Data Asset Origination System, detailed in the PDAOS™ white paper, draws explicitly on IP law's structural precedents. The three core mechanisms, origination recording, certificate issuance, and chain-of-custody tracking, map directly to copyright's fixation doctrine, registration system, and chain-of-title framework.
The first-to-use logic from trademark law informs the priority structure. When a MyDataKey™ certificate records that a specific individual held specific data at a specific cryptographically-verified timestamp, that record functions as a priority claim. It asserts that the individual was the first-to-originate in the same way a senior trademark user asserts prior use in commerce.
This is not a legal fiction. It is a technical record designed to be legible in legal proceedings. The architecture anticipates the evidentiary standards that courts apply to disputed ownership claims. Not because data ownership litigation is currently common, but because the infrastructure needs to be built before the dispute arises, not after.
Own Your Data Inc operates as a nonprofit specifically because the integrity of this system depends on the issuing entity having no commercial interest in the data itself. A for-profit intermediary holding origination records faces structural conflicts of interest that would compromise the neutrality of the record. The nonprofit structure is not incidental to the mission. It is part of the trust architecture.
What Engineers and Advocates Can Do Now
For engineers working on privacy infrastructure, the IP framework analysis has direct technical implications. The most important is that ownership claims require external verification, not self-attestation. Any system where the individual user generates and holds their own proof, without a neutral third-party timestamp and hash anchor, replicates the problem of an unregistered copyright. The claim is real. The proof is weak.
For policy advocates, the IP analogy is strategically useful. Legislators and regulators already understand the structure of copyright and trademark law. Framing data origination rights in those terms, fixation, registration, priority, chain of title, translates a novel concept into established legal vocabulary. That translation reduces the cognitive overhead of advocating for new data property frameworks.
The Federal Trade Commission has consistently engaged with data broker practices under Section 5 of the FTC Act, addressing unfair and deceptive practices in commercial data markets. The Department of Commerce and the National Institute of Standards and Technology have both published frameworks addressing data governance. The legal groundwork for stronger individual data rights exists. The missing piece is the technical and institutional infrastructure to assert those rights with the same rigor that IP law brings to creative works and commercial identifiers.
If you are ready to establish a verifiable origination record for your personal data, MyDataKey™ issues cryptographically-anchored certificates that create exactly that record. The process takes minutes. The evidentiary value compounds over time as data markets evolve and legal frameworks catch up to the infrastructure that already exists. Start at mydatakey.org/signup.
The frameworks we need already exist in outline. Trademark and copyright law spent decades refining the logic of how you prove you owned something first. Personal data origination needs that same logic applied with modern cryptographic tools and a neutral institutional anchor. That work is already underway.
Editorial Review
This article was reviewed by Ryan Gaughan on August 12, 2026 for accuracy, currency, and clarity. Content is updated when laws or guidance change.