Tangentially, France has had the CNIL [1] since ~1978, following a scandal about creating a national citizen's database, and exists to prevent exactly that. (I believe the objection stemmed from memories of the Petainist fascist regime during WW2) The CNIL is why France (and now Europe) has "Right to Forget" laws. It is the direct ancestor of stuff like GDPR. Unfortunately, I feel like the CNIL is fairly neutered now…
I wonder if not having such state database is not causing today more issues than it defends from. In the 80s I would get it, the state was the only one able to build such a database and people were afraid of what it would do secretly with it. Nowadays, "everybody" has a database with millions of people (ex: facebook, linkedin, x, tax offices, etc.) and discriminatory actions are done based on whims/stupidity rather t…
It can be hard to believe from more business focused countries, but the agency setting precedents has had dissuasion effects, and most companies do end up caring about their data retention and management policies. I've been in enough meetings where UX proposal gets entirely reworked because of a simple link to the CNIL's guidelines.