The Right to Exit in Digital Civilization

My illustration entitled: “The Lifeboat from the Centralized Ark” – a gigantic corporate digital vessel begins transforming into a surveillance machine. Me, and other citizens escape aboard smaller decentralized lifeboats powered by encryption, open protocols and peer-to-peer networks. Represents: Alternative infrastructure makes the right to exit practically possible.


A person may appear free to join a digital system while possessing almost no practical freedom to leave it.

The terms of service may say that participation is voluntary. The interface may contain a button for closing an account. The company may insist that dissatisfied users can simply choose another provider.

But what happens when leaving means losing years of correspondence, photographs, contacts, documents, purchases, professional history and social relationships? What happens when a person’s identity, reputation or livelihood has become dependent upon the system? What happens when competing services cannot communicate with it, imported data cannot be used elsewhere or essential functions disappear the moment the account is closed?

Under these conditions, exit may exist formally while remaining impossible in practice.

Cypherpunkism treats this difference as a question of power. A relationship cannot be considered genuinely voluntary merely because entry was voluntary. Meaningful consent must include the continuing ability to refuse, withdraw and leave without surrendering everything accumulated during participation.

The central principle of this essay is:

Participation is not genuinely voluntary when exit requires the abandonment of identity, property, relationships, reputation, records or access to essential services.

Digital Sovereignty therefore requires a right to exit.


From Exit and Voice to Digital Power

In his 1970 work Exit, Voice, and Loyalty, Albert O. Hirschman examined how people respond when organizations deteriorate. They may exercise voice by attempting to change the organization, or they may exercise exit by withdrawing from it.

The two possibilities restrain institutional power in different ways. Voice allows participants to criticize decisions and seek reform. Exit allows them to reject the relationship entirely. When an institution ignores voice but remains vulnerable to exit, it risks losing the people upon whom it depends.

Digital systems complicate this relationship because the institution may accumulate control over the very things a person would need to take away.

A social platform may possess the user’s network of relationships. A cloud provider may hold his documents. A marketplace may control his reputation. A digital store may determine whether purchases remain accessible. An identity provider may become the credential through which he enters unrelated services. A communications platform may retain the only practical connection to a community.

The institution does not merely offer a service. It may become the custodian of the user’s accumulated digital existence.

Under those conditions, exit becomes expensive even when the service itself is free.


The Difference Between Closing an Account and Leaving a System

Closing an account is an administrative action. Leaving a system is the recovery of independence from it.

A person has not meaningfully left if the provider continues to retain unnecessary personal information indefinitely. He has not meaningfully left if his purchases disappear, his identity becomes unusable or his contacts cannot be reached anywhere else. He has not meaningfully left if exported data arrives in an obscure format that no competing service can understand.

The ability to click “delete account” therefore proves very little by itself.

Meaningful exit requires examination of what the person can recover, what he must abandon, what the institution continues to retain and whether another system can receive what is transferred.

This distinction can be expressed simply:

Account deletion ends access. Technological exit ends unnecessary dependence.


Why Exit Is a Question of Sovereignty

Digital Sovereignty is the condition in which an individual retains meaningful authority over his identity, information, communications, credentials, digital possessions and participation in technological systems.

That authority is incomplete if it exists only while the individual accepts the rules of one institution.

A provider that can unilaterally change its terms, increase surveillance, remove functions or restrict access may possess far greater negotiating power than its users. If leaving is realistic, users can reject unacceptable changes. If leaving requires the destruction of their digital lives, the provider knows that resistance will be costly.

Exit therefore affects the balance of power even when it is never exercised. Its credible availability places a limit upon the institution. The possibility of departure strengthens the user’s voice because the operator cannot assume that dissatisfaction will always be followed by submission.

A right that cannot be exercised without disproportionate loss is not an effective right. Digital Sovereignty must therefore be measured not merely by what users are allowed to do inside a system, but by what remains theirs when they leave it.


The Seven Dependencies That Can Prevent Exit

Digital captivity rarely depends upon one explicit prohibition. It is more often produced by several forms of dependency accumulating over time.

1. Identity Dependency

A digital identity may begin as a username for one service and gradually become a credential for many others. When unrelated applications rely upon the same account for authentication, losing or leaving that account can affect access far beyond the original platform.

An identity that cannot be transferred or independently proven remains under the authority of its issuer. The user may be the person described by the identity, but the institution controls whether that identity continues to function.

2. Data Dependency

A service may accumulate photographs, correspondence, documents, location histories, preferences and records over many years. If these cannot be exported completely and intelligibly, the information becomes a barrier to departure.

A collection of downloadable files is better than no export, but portability requires more than raw possession. The structure, relationships, dates and contextual information necessary to understand those files may also need to be preserved.

3. Relationship Dependency

The value of many platforms comes from the presence of other people. A user may dislike the operator’s practices but remain because friends, relatives, customers or colleagues cannot be reached through competing systems.

This is a powerful form of lock-in. The individual is not merely choosing software. He is choosing whether to remain connected to a community.

When closed networks cannot communicate with one another, the operator gains power from every relationship formed inside its boundaries.

4. Reputation Dependency

Ratings, reviews, transaction histories and records of contribution can become economically or socially valuable. Yet reputation is often trapped inside the database of the institution that calculated it.

A seller who has spent years building trust in one marketplace may have to begin again as an unknown participant elsewhere. A contributor may lose evidence of previous work. A professional may lose endorsements that cannot be independently verified.

When reputation cannot travel, accumulated trust becomes a form of institutional collateral.

5. Property Dependency

Digital purchases are often described using the language of ownership even when the user receives only revocable access through a particular account or device.

Books, music, software, virtual objects and other digital goods may become inaccessible if the account is closed, the provider fails or the licensing system changes. The user may have paid for the object while remaining dependent upon continuing authorization from the seller.

If departure destroys the possession, the person did not possess it independently of the platform.

6. Technical Dependency

Proprietary formats, undocumented interfaces and incompatible protocols can prevent information from functioning outside its original environment.

The user may technically receive his data but remain unable to import it elsewhere. A document that cannot be opened, a contact list that cannot be reconstructed or a message archive stripped of its context provides only the appearance of portability.

Technical compatibility therefore has political significance. Standards and interoperable protocols reduce the ability of one operator to convert information into dependency.

7. Essential-Service Dependency

The most serious problem arises when a digital system becomes necessary for employment, education, finance, healthcare, communication or civic participation.

A person cannot simply “choose not to use” an infrastructure when refusal would exclude him from ordinary society. As digital systems become gateways to essential services, their operators acquire powers that resemble those of public institutions.

The more necessary a system becomes, the less convincing it is to describe continued participation as consent merely because an account can theoretically be closed.


The Conditions of Meaningful Exit

A genuine right to exit requires more than a cancellation procedure. It must be supported by technological and institutional conditions that make departure practical.

1. Clear Notice

Users should receive understandable notice before significant changes to privacy practices, access conditions, pricing, functionality or ownership take effect.

A person cannot make a meaningful decision to stay or leave if consequential changes are hidden inside extensive legal documents or applied immediately without time to respond. Notice should arrive early enough for the user to obtain information, secure credentials and arrange alternatives.

2. Complete Data Portability

Individuals should be able to obtain personal information they supplied or generated in a structured, commonly used and machine-readable form.

The European Union’s General Data Protection Regulation, adopted in 2016 and scheduled to apply from May 2018, recognizes a right to data portability. Article 20 provides that qualifying personal data should be receivable in a structured, commonly used and machine-readable format, with transmission to another controller where technically feasible.

This is an important development, but the principle should be understood broadly. Portability must preserve enough structure for information to remain useful. Exporting thousands of disconnected files does not reproduce an organized archive, social graph or history of interaction.

3. Interoperability

Portability allows information to be carried away. Interoperability allows different systems to work together.

Email remains an important example. A person can change providers without demanding that every correspondent move to the same service. Open protocols permit communication across organizational boundaries.

A closed platform produces a different relationship. If communication is possible only among accounts controlled by the same operator, every connection becomes another reason not to leave.

Interoperability reduces this social penalty. It permits individuals to choose tools without requiring entire communities to migrate simultaneously.

4. Independent Control of Credentials

Users should not be required to abandon every identity and authorization merely because they change service providers.

Where practical, credentials should be separable from the platform that uses them. Cryptographic keys controlled by the individual can provide continuity of authorization beyond one institutional database.

This does not eliminate the legitimate role of trusted issuers. It limits the ability of one provider to become the permanent gatekeeper of the person’s entire digital identity.

5. Continuity of Digital Possessions

Leaving a service should not automatically destroy items the user reasonably understood himself to have purchased or created.

Digital systems should distinguish clearly between ownership, licensing and temporary access. Where continuing use depends upon a provider, that dependency should be disclosed before purchase. Where independent possession is technically possible, users should be able to retain usable copies or transfer their rights to compatible systems.

6. Deletion and Residual Privacy

The ability to take information away must be accompanied by rules governing what remains behind.

A departing user should be able to request deletion of personal information that the provider no longer has a legitimate reason to retain. Necessary exceptions may exist for legal obligations, security, fraud prevention, dispute resolution or the rights of others, but those exceptions should not become excuses for indefinite preservation.

Exit is incomplete when the relationship ends but the surveillance record remains forever.

7. Recoverability

A system should anticipate provider failure, acquisition, technical abandonment and loss of support.

Users should have reasonable methods for recovering essential information and functions if the institution disappears. Open formats, independent backups, documented protocols and distributed copies can reduce the risk that one organization’s failure will erase an entire community’s records.

Recoverability is the right to exit exercised under emergency conditions.

8. Viable Alternatives

The right to leave becomes meaningful only when another path exists.

Open standards, competing implementations and the freedom to build alternatives create the environment in which exit can operate. A monopoly may offer a flawless export function while leaving users nowhere useful to go.

This is why the right to exit cannot be separated from open architecture, decentralization and freedom to build.


Portability Is Not Interoperability

Portability and interoperability are related, but they solve different problems.

Portability asks whether the user can take information from one system to another. Interoperability asks whether separate systems can exchange information and maintain relationships without requiring everyone to submit to the same operator.

A service may provide a complete archive while remaining incompatible with every competitor. The user can preserve the past but cannot continue participating in the same community. Conversely, interoperable services may communicate while failing to provide users with complete copies of their own histories.

Digital Sovereignty requires both wherever reasonably possible.

Portability protects what the individual has accumulated. Interoperability prevents future communication from being captured by a single institutional boundary.


Exit and Voice Must Reinforce Each Other

Exit should not become an excuse for institutions to ignore criticism.

Telling users to leave whenever they question a policy is inadequate when the service controls essential infrastructure or has accumulated significant power over public communication. People should possess avenues to express objections, correct errors and challenge consequential decisions.

At the same time, voice without exit can become ceremonial. An institution may invite feedback while retaining the ability to disregard every objection because it knows departure is too costly.

The credible possibility of exit strengthens voice. The availability of voice may also prevent unnecessary exit by allowing problems to be corrected before relationships collapse.

A sovereign digital relationship should therefore provide both:

The ability to challenge the system and the ability to leave it.


Decentralization as Preserved Exit

Decentralization can preserve exit by preventing one institution from possessing exclusive control over participation.

In an open decentralized system, a user may change applications, operate an independent node, select another service provider or continue using the protocol after one operator disappears. The relationship is attached to the network rather than permanently confined to one administrator.

The capacity to fork an open-source project represents an especially powerful form of exit. Participants who fundamentally disagree with a project’s direction may preserve the existing code and develop an alternative. The possibility of a fork does not guarantee that the alternative will attract users or resources, but it prevents control of the original repository from becoming control over every possible continuation.

Decentralization does not automatically produce freedom. A supposedly distributed network may still depend upon a few developers, mining organizations, hosting providers, exchanges or gateways. Its users may possess theoretical alternatives that are too difficult to exercise.

The relevant question is therefore practical: can participants continue to communicate, verify, build and possess without seeking renewed permission from the authority they wish to leave?


My illustration “The Lifeboat from the Centralized Ark” work-in-progress. The art represents: alternative infrastructure makes the right to exit practically possible.


The Limits of Exit

The right to exit cannot be absolute in every circumstance.

A person cannot erase another party’s legitimate evidence of a transaction merely by closing an account. Contractual duties do not automatically disappear when a service is abandoned. Institutions may need to retain limited records to comply with law, resolve disputes, prevent fraud or protect the rights of other people.

Exit also does not entitle a person to take information belonging exclusively to others. A social graph contains relationships involving more than one person. A conversation has several participants. A collaborative document may contain contributions governed by shared rights.

These complications do not invalidate the principle. They require boundaries.

Restrictions on exit should be specific, necessary and proportionate to a legitimate obligation. They should not be expanded into permanent institutional ownership of the departing person’s identity or history.

As argued in “The Rights and Responsibilities of the Cypherpunkist,” sovereignty grants the individual authority over himself, not unrestricted authority over other people. The right to leave must therefore respect the privacy, property and legitimate claims of everyone involved.


The Exit Test

A digital system should be examined through the following practical questions:

  • Can the individual close the account without unreasonable obstruction?
  • Can personal information be exported completely and in a usable format?
  • Can another system receive and interpret that information?
  • Can relationships continue across different providers?
  • Can identity and reputation be demonstrated independently?
  • Can legitimately acquired digital possessions survive departure?
  • Can unnecessary retained information be deleted?
  • Can the user recover essential records if the provider fails?
  • Are competing implementations or alternative providers permitted?
  • Does leaving remain realistic when the service has become socially or economically important?

A system need not satisfy every question perfectly. Different technologies face different security, legal and technical requirements.

But the pattern of answers reveals the underlying relationship. If departure requires the destruction of everything the user has built, the system possesses power through captivity. If identity, information, relationships and possessions remain portable, the individual occupies a more sovereign position.


A Declaration of Technological Exit

My participation in a digital system does not grant that system permanent ownership over my digital existence.

I should be able to retrieve the information I have legitimately contributed.

I should be able to understand what will be lost, retained or transferred when I leave.

I should not be compelled to abandon my identity, records, relationships and possessions merely because I reject one provider.

I should be able to withdraw consent for unnecessary future processing.

I should have access to interoperable alternatives where such compatibility is technically and legally possible.

I should be able to challenge decisions before exclusion becomes irreversible.

I should retain reasonable access to essential records if an institution fails, changes ownership or terminates its service.

I also recognize that my exit must respect the privacy, property and legitimate rights of others.

Leaving a system should end unnecessary dependence—not erase responsibility.


Freedom Must Include the Freedom to Leave

The architecture of technological power is revealed by asking who controls the database, the keys, the permissions, the protocols and the rules. The right to exit adds another question:

What remains under the individual’s control when the relationship ends?

If the answer is nothing, then the individual participated without sovereignty. His identity belonged to the account, his relationships belonged to the network, his reputation belonged to the database and his possessions existed only at the operator’s discretion.

A digitally sovereign system should not require that level of surrender.

It should permit information to be recovered, identity to continue, relationships to cross institutional boundaries and unnecessary records to be removed. It should allow alternative implementations to exist and preserve essential functions against the failure of one provider.

The right to exit does not demand a world without commitments, institutions or shared rules. It demands that cooperation does not become technological captivity.

Consent requires more than the freedom to enter.

Choice requires more than the existence of a cancellation button.

Ownership requires more than temporary access through someone else’s database.

Portability preserves what the individual has created.

Interoperability preserves relationships across boundaries.

Recoverability protects against institutional failure.

Decentralization preserves the possibility of alternatives.

A person is not digitally sovereign if leaving one institution requires abandoning his digital life.

Freedom in digital civilization must include the freedom to leave.


References and Foundational Influences

  1. Hirschman, Albert O. Exit, Voice, and Loyalty: Responses to Decline in Firms, Organizations, and States. Harvard University Press, 1970.
  2. Stallman, Richard. The GNU Manifesto. 1985.
  3. Hughes, Eric. A Cypherpunk’s Manifesto. March 9, 1993.
  4. Carpenter, Brian, ed. “Architectural Principles of the Internet.” RFC 1958, June 1996.
  5. Lessig, Lawrence. Code and Other Laws of Cyberspace. Basic Books, 1999.
  6. Kempf, James and Rob Austein. “The Rise of the Middle and the Future of End-to-End.” RFC 3724, March 2004.
  7. European Parliament and Council of the European Union. Regulation (EU) 2016/679, General Data Protection Regulation. Article 20, Right to Data Portability. April 27, 2016.
  8. World Wide Web Consortium. “Data on the Web Best Practices.” W3C Recommendation, January 31, 2017.
  9. Sim, Herbert R. “Cypherpunkism: A Philosophy of Digital Sovereignty.” October 10, 2010.
  10. Sim, Herbert R. “Digital Sovereignty: A Formal Definition.” December 10, 2013.
  11. Sim, Herbert R. “The Architecture of Power: A Cypherpunkist Theory of Technology.” June 22, 2015.
  12. Sim, Herbert R. “Decentralization Is a Check on Power.” October 26, 2015.
  13. Sim, Herbert R. “The Rights and Responsibilities of the Cypherpunkist.” August 8, 2016.