Index of Headings
1.Introduction: Surveillance Capitalism and the Data Protection Challenge
2.What Is Surveillance Capitalism? Zuboff's Theory Explained
3.How Legal Scholars View Surveillance Capitalism and the GDPR
- 3.1. The Comparative Approach
- 3.2. The Sceptical Approach
- 3.3. Law as a Constitutive Force in the Data Economy
- 3.4. Can Law Alone Address Surveillance Capitalism?
4.What the GDPR Gets Right: Rights, Fines and Case Law
5.Why Consent Fails Against Surveillance Capitalism
6.AI and Surveillance Capitalism: Emerging Privacy and Manipulation Risks
7.The EU Digital Omnibus: Is Europe Weakening the GDPR and the AI Act?
8.Regulating Surveillance Capitalism: A Structural Legal Approach
9.Conclusion: Regulate the Business Model, Not Just the Paperwork
10.Sources and Further Reading
Surveillance Capitalism and Data Protection Law: Why It Matters
Few phrases have travelled from academic books into everyday arguments as quickly as “surveillance capitalism”. Shoshana Zuboff gave it to us in 2019, and since then lawyers, regulators and ordinary users have been trying to work out whether it describes a real legal problem or just a mood. After reading a fair amount of what legal scholars have written about it, I think it describes both. The mood is justified, but the legal problem is more tangled than the slogan suggests.
In this article I look at the main strands of the legal commentary, test them against the General Data Protection Regulation (GDPR) and the rapid arrival of AI, and then say plainly where I land. My answer is this: the GDPR was a serious attempt to discipline the data economy, and it has done really good, but it was built around the idea of a person consenting to a company's use of their data. Surveillance capitalism and modern AI have both outgrown that idea. We need to regulate the business model, not just the paperwork around it.
What Is Surveillance Capitalism? Zuboff's Theory Explained
Zuboff's claim is that a new economic logic emerged, pioneered by Google and later adopted by Facebook and many others. Companies discovered that the traces people leave online are worth more than what is needed to run the service. That extra data, which she calls behavioural surplus, is fed into prediction products and sold to anyone who wants to know what you will do next. The profit comes from predicting behaviour, and the best way to predict behaviour is to shape it.

Her account is dramatic, and she frames it as a kind of dispossession, comparable to the enclosure of common land. That is where the legal literature picks up. Zuboff herself points to the GDPR as a hopeful sign, and she argues that surveillance capitalism is anti-democratic and needs new institutions, rights and legal frameworks. Lawyers have taken that invitation seriously, but they have not simply agreed with her.
How Legal Scholars View Surveillance Capitalism and the GDPR
I see four broad responses in the commentary.
The first is the comparative camp. A good example is a Harvard thesis that built a scoring rubric from Zuboff's concerns, namely the imbalance of knowledge and power between firms and users and the lack of real detection and sanctions, and then asked whether the GDPR or California's CCPA handles them better. It concluded that the GDPR does, because it covers more ground and gives people more control. A Hungarian cross-Atlantic study reaches a similar place, suggesting that the United States should adopt a federal privacy law modelled on the GDPR while the GDPR itself is adjusted in some respects. The message is that the European approach is the better starting point, and that is a view I largely share.
The second is the sceptical camp, which says that the GDPR protects individual privacy well but does not touch the larger problem. Work by Andrew and Baker on the tensions inside the GDPR argues that it has meaningfully protected personal privacy but falls short on the wider risks of collecting and trading behavioural data. A Brazilian article on the LGPD, which was modelled on the GDPR, comes to a parallel conclusion: it defends users' digital rights but is not an effective brake on surveillance capitalism itself.
The third camp is the most interesting to me, and it questions the premise that law has simply been absent. A recent paper in the technology ethics literature draws on Julie Cohen and Katharina Pistor to argue that informational capitalism was built through legal innovation as much as technical innovation. Property rules, contract terms, intellectual property and the structure of the corporation all helped create the data economy. On this reading, the worry is that if companies comply with the GDPR, they can claim to practise an acceptable, transparent version of surveillance capitalism, which would end up legitimising it. I think this is a serious warning and I return to it below.
The fourth camp asks whether law alone can do the job. One article in a law and philosophy journal compares Aquinas and Dworkin on the foundations of law and concludes that surveillance capitalism needs more than legal rules, since it also attacks truth, autonomy and the ability to form independent judgement. There is also the political critique from the other side, which argues that regulating the sector risks regulating capitalism itself, and that the real legal questions concern things like platform liability. I do not find that critique persuasive on the central point, because the problem I am concerned with is not that firms make money but that they do so by extracting data from people who cannot meaningfully refuse. It is still a reminder that reasonable people disagree about how far regulation should go.

What the GDPR Gets Right: Rights, Fines and Case Law
It is fashionable to complain about the GDPR, so I want to be fair to it. It created a common vocabulary for a continent: personal data, controllers and processors, lawful bases, purpose limitation, data minimisation, and a set of rights to access, correct and delete. It gave regulators the power to fine up to four percent of global turnover, which finally made privacy a boardroom topic. It applies to anyone targeting people in the EU, so its influence reaches well beyond Europe, and many countries, from Brazil to India, have borrowed from it.
The case law has also moved in a helpful direction. In the Meta v Bundeskartellamt judgment of 2023, the Court of Justice accepted that a company's dominant position matters when asking whether consent is truly free, and that combining data from different services for advertising needs a proper legal justification. That decision is important because it links data protection to competition, which is exactly the connection the critics say has been missing. Regulators have since looked hard at “pay or consent” models, where users must either accept tracking or pay a fee, and that debate is really about whether consent can ever be free when the alternative is a charge or exclusion.
GDPR Limitations: Why Consent Fails Against Surveillance Capitalism
The weakness, in my view, is structural. As Advocate Sagir Ahmad says - The GDPR starts from the individual. It asks whether this person agreed, whether this purpose was stated, whether this data was needed. That works for a single transaction, but surveillance capitalism does not operate transaction by transaction. It works through scale, inference and aggregation. Once a company has data on millions of people, it can learn things about you that you never disclosed, simply because people like you behave in certain ways. Your consent, or your refusal, hardly matters to that process.
Enforcement is the other problem. Large firms often have their European headquarters in a single member state, and the one-stop-shop mechanism routes complaints through that national regulator. Cases have taken years, and large fines have often been followed by long appeals and slow compliance. A right that is hard to enforce is, for most people, a right in name only.
AI and Surveillance Capitalism: New Privacy and Manipulation Risks
AI has made the old problem larger and added new ones. Machine learning is, at its core, an engine for turning behavioural data into predictions, which is exactly what Zuboff described. Generative AI adds a second demand: enormous amounts of text, images and personal information scraped from the open web to train models. That raises questions the GDPR was not designed for. Can a model that has absorbed personal data be said to “contain” it? How can someone exercise a right to erasure against a trained system? What is the lawful basis for scraping the public internet?
There is also a deeper issue. Surveillance capitalism was mostly about predicting what you might click or buy. AI systems can now converse with you, imitate people you know, personalise persuasion and operate at a scale no human advertiser could match. If the earlier economy sold certainty about behaviour, the next one can tailor the nudge to each person in real time. That moves the concern from privacy toward autonomy and manipulation, and the GDPR's toolkit is thin there.
The EU's answer is the AI Act, which takes a risk-based approach. It bans some practices outright, including certain manipulative systems and some uses of biometric surveillance, imposes obligations on high-risk systems and sets transparency rules for generative AI. I think it is a useful complement, because it regulates the system and its effects rather than only the data flowing into it. That is a step toward the structural approach I think we need.

EU Digital Omnibus: Is Europe Weakening the GDPR and the AI Act?
What worries me is the direction of travel. In November 2025 the Commission proposed the Digital Omnibus, a package meant to simplify EU digital rules and reduce the burden on business. The AI part was agreed in May 2026 and, as reported by law firms, entered into force in late July 2026 as Regulation 2026/1744. It pushes back the timetable for high-risk AI obligations and eases some administrative requirements, although some transparency duties were kept or reinstated after Parliament pushed back, and new bans on abusive imagery were added.
The data part, which touches the GDPR itself, is moving more slowly and is more controversial. The proposals include making it easier to use personal data for AI training, widening what counts as anonymous data outside the GDPR, and folding cookie and tracking rules into the GDPR. Commentators disagree about the result. Some business-oriented firms argue that the changes do not go far enough, while privacy advocates fear that redefining personal data could shrink the law's reach just when inference and profiling are most powerful. I take the second worry seriously. If the definition of personal data narrows, the very data that feeds profiling may slip out of protection.
How to Regulate Surveillance Capitalism: My Legal Opinion
First, surveillance capitalism is a useful label even if Zuboff's framing is sometimes sweeping. It identifies a business model in which the product is behavioural prediction and the raw material is human experience. Law should be willing to ask whether that model is acceptable at all, rather than only asking how to make it tidier.
Second, the GDPR is necessary but not sufficient. It is the best general data protection law we have, and I would not want to lose it, but its consent-and-rights design leaves the core engine of the business model largely intact. I agree with the scholars who say that individual control cannot carry the weight we have placed on it.
Third, the answer lies in combining tools. Data protection should be paired with competition law, as the Meta decision hints, with consumer protection against manipulative design, and with the AI Act's focus on systems and their effects. I would add stronger structural rules, such as limits on combining data across services, restrictions on behavioural advertising built on sensitive inferences, and meaningful default settings that protect people without requiring them to act. Rules like this tackle the business model directly instead of asking individuals to defend themselves.
Fourth, I agree with the sceptics that law alone will not be enough. Public attitudes, better product design, independent research access to platforms and a healthy press all matter. But law sets the ground rules, and when the rules are weak, the other forces have little to work with.
Conclusion: Regulate the Business Model, Not Just the Paperwork
For lawyers, compliance officers and students who want to turn this debate into working knowledge, structured training is a sensible next step. LAWyersclubindia's course Data Protection and Privacy by Tuhina Joshi is a self-paced, English-language recorded programme of about five hours. As data protection obligations spread across jurisdictions, from the GDPR in Europe to the growing body of privacy law in India, a grounding like this helps professionals read the legislation critically instead of treating compliance as a box-ticking exercise.
The legal literature on surveillance capitalism is largely consistent about one thing: the problem is real and the GDPR is a good start but not an answer. Where I land is slightly firmer than many commentators. I think the central risk is not that the law is absent but that it is aimed at the wrong target, focusing on individual choice when the real power lies in scale and inference. AI sharpens this, because it makes manipulation cheaper and more personal.
Europe has built more of the necessary machinery than anyone else, which is why the current push to simplify matters so much. If simplification means clearer, more enforceable rules, it can help. If it means quietly shrinking the definition of personal data while the technology grows more capable, we will have lowered our guard at the worst possible moment. The test I would apply to every reform is simple: does it reduce the power of firms to extract and exploit human behaviour, or does it only make the extraction easier to document?
Join LAWyersClubIndia's network for daily News Updates, Judgment Summaries, Articles, Forum Threads, Online Law Courses, and MUCH MORE!!"
Tags :Others
