R349 SeriesPath to the Abyss Part 7 / 17

Sixth Step: Take Away Their Privacy

When the system knows enough about a person, it no longer has to command them — it can begin to predict them

Privacy is often presented as something needed only by a person who has something to hide. That is one of the most dangerous lies of the digital age. Privacy is not a space for secrets. Privacy is the space in which a person has not yet become a fully measured object. A space in which they can think, read, speak, search, travel, buy, love, doubt, make mistakes and change their mind without every step becoming an entry in a database.

You do not have to take away a person’s voice if you can know precisely enough what they fear. You do not have to ban a product if you can know when they are most susceptible to buying it. You do not have to follow them physically if their phone, car, watch, web browser and payment card do it for you. And you do not have to ask who they are. It is enough to put the fragments together.

The surveillance of the future does not look like a man in a coat

Old surveillance was expensive. It required a police officer, an agent, a wiretapping system, a physical file, a warrant, a person following another person. New surveillance is automated. The person carries the sensor in their own pocket. Charges it every night. Makes sure it has a microphone, camera, GPS, Bluetooth, Wi-Fi and a permanent network connection. Enters contacts, photographs, calendar, messages, health data, payment cards and search history into it themselves.

The system can therefore be incomparably larger than anything previous generations of power could have imagined. This does not mean somebody personally monitors every phone. It means something more efficient. A phone can produce enough data that the person no longer needs to be personally followed.

A concealed spy camera from the Stasi Museum collection in Berlin.
A concealed camera from the Stasi Museum in Berlin. Historical covert surveillance often required specialized hidden equipment. Modern digital tracking can also rely on ordinary connected devices and data flows; the photograph documents an earlier technique and does not equate contemporary services with the Stasi. Image: Roi Boshi / Wikimedia Commons Public domain — released by copyright holder

Location is not just a dot on a map

Precise geolocation can reveal far more than an address. It can show where a person sleeps. Where they work. Where they go on Sundays. Which clinic they visit. With whom they spend the night. How often they go to a bar. Whether they visit a therapist. Whether they stop outside an addiction treatment centre. Whether they attend a political rally. Whether they go to a church, mosque or synagogue. This is not a hypothetical danger. In 2024 the U.S. Federal Trade Commission prohibited X-Mode and its successor Outlogic from selling sensitive location data after the regulator found that the company had sold precise location data from which visits to medical and reproductive-health clinics, places of worship and shelters for victims of abuse could be inferred.[1]

That means the infrastructure capable of turning a phone into a tracking device already existed as a commercial market. There was no need to build a ministry of tracking. There was a market. And the market contained data. This is an important lesson for the entire path: surveillance does not have to be governmental to be dangerous. Sometimes the advertising industry builds it first. The state can arrive later.

Even a privacy protector can sell your history

In 2024 the FTC also finalised action against Avast. This is a particularly instructive case because Avast did not sell users a service called “hand us your privacy”. It sold antivirus and privacy protection. The FTC found that the company collected detailed browsing data from users and, through a subsidiary, sold it to more than one hundred third parties. The data could reveal religious beliefs, health concerns, political preferences, location, financial status and other sensitive information.[2]

The company had to pay $16.5 million and was prohibited from selling or licensing browsing data for advertising purposes. The irony is almost complete. A tool that was supposed to protect a person from tracking became a source of data about them. This is not a reason to conclude that every digital service lies. It is, however, a good enough reason to understand something fundamental: a promise of privacy is not the same thing as the technical impossibility of surveillance. If a system can collect the data, the question remains who may be able to use it tomorrow.

A car is no longer just a car

A modern car is a computer on wheels. In 2024 the FTC publicly warned that connected cars can collect biometric data, geolocation, telematics, video and other personal information. This means that an object once primarily a mechanical machine for moving from point A to point B is becoming another data platform. It knows where you were. When you were there. How you drove. Which phone was connected.[3]

In some systems it even knows who is sitting in the vehicle. And once there is enough data, the boundary between a safety feature and a behavioural profile quickly blurs. Driving data may be useful to an insurer. Valuable to a manufacturer. Interesting to an advertiser. Useful to police. Dangerous to a hacker. Priceless to a future authoritarian government. There is no need to claim that the car was created for that purpose. It is enough to ask: what can be done with the data once it has been collected?

Your face is a password you cannot change

You can change a password. Cancel a card. Change a phone number. You cannot change your face. Nor your fingerprints. Biometrics are therefore useful and dangerous at the same time. They can greatly improve identification security. But once biometric data escape control, a person cannot issue themselves a new face as they can a new bank card. That is why the European Data Protection Board prepared specific guidelines for the use of facial recognition in law enforcement and stressed the sensitivity of biometric data.[4]

That matters. If a technology is sensitive enough to require specific European guidelines, then the issue of mass biometric tracking is not paranoia. It is a legitimate political and civilisational boundary. When does identification become tracking? When does tracking become profiling? When does profiling become prediction? And when does prediction become a reason for the system to start treating a person differently before they have even done anything?

The most valuable data point is the pattern

A single piece of data is often not especially interesting. One purchase. One location. One video. One click. One doctor’s visit. One evening walk. The problem begins when thousands of small data points are assembled into a pattern. Then the system no longer knows only what you did. It begins to infer what you will do. Advertising systems have spent decades trying to estimate what you will buy. Platforms estimate which content will keep you on the screen. Insurers can estimate risk.

Banks assess creditworthiness. Security systems assess suspicious behaviour. Artificial intelligence can accelerate all these processes. This is the turning point. A system that merely observes a person is a surveillance system. A system that can predict them well enough is already something more. It can begin shaping the environment in which some decisions become more likely than others.

No one has to force you

The most effective surveillance is often the kind in which a person changes their own behaviour. If they know they are being watched, they begin to watch what they say. If they know their purchases are recorded, they begin to think about what they will buy. If they know their movements are visible, they begin to think about where they will go. If they know a post can affect a job, account, insurance or social position, they begin filtering themselves. Then the watcher needs fewer punishments. The person becomes their own watcher. That is far more efficient than a threat. And far cheaper.

“I have nothing to hide” is the wrong question

The real question is not: What am I hiding? The real question is: Who is allowed to know what about me, for what purpose, for how long, and with what ability for me to say no? A person has curtains on their windows not because they are a criminal, but because a home is not a public square. They close the bathroom door not because they are hiding a crime, but because they have dignity. A conversation with a friend is not automatically intended for an employer. Health information is not intended for a retailer.

Religious belief is not intended for an advertiser. A child’s location is not a commodity. Privacy is the boundary between the person and the system. When that boundary disappears, the person does not necessarily become unfree immediately. But they become fully exposed to the possibility of future unfreedom.

First we collect the data. The purpose comes later.

This is one of the greatest problems of the digital world. Data can be collected today for convenience and used tomorrow for a completely different reason. A health app may today be intended to count steps. Tomorrow its data may interest an insurer. A location service helps find a restaurant today. Tomorrow its history may reveal a visit to a clinic. A connected car helps with navigation today. Tomorrow its data may affect a risk score. Biometrics unlock a phone today.

Tomorrow the same technology can identify a person in a crowd. This does not mean every such scenario will happen. It means that collecting data is an irreversible decision far more often than it seems at the moment someone clicks “I agree”.

What if the goal is the complete profile?

What if the final system of the future does not need one enormous central database labelled “CITIZEN DOSSIER”? What if it is enough for data to reside in different systems but be linkable when needed? Identity in one place. Money in another. Health in a third. Movement in a fourth. Communication in a fifth. Purchases in a sixth. Biometrics in a seventh. A social relationship graph in an eighth. And artificial intelligence searches for patterns across them.

Such a system does not need a human being to read your file. A machine can read it. And a machine can decide what matters. This is the point at which privacy is no longer merely a personal right. It becomes a question about the balance of power between the individual and the infrastructure.

Freedom needs a zone that is not measured

A fully transparent person before a fully opaque system is not a free person. If the system knows almost everything about the individual while the individual knows almost nothing about the algorithms evaluating them, the relationship is not equal. The person becomes readable. The system remains unreadable. And once a person is readable enough, they are ready for the next step on the path. It is no longer enough simply to know who they are. Their identity can become a key. A key to the bank. To healthcare.

To travel. To a contract. To a government service. To work. To digital space. And when identity changes from an answer to the question “who are you?” into an answer to the question “what are you allowed to do?”, we have already reached the next station. First you observe the person. Then you know them. Then you can classify them. Only then do you begin deciding which doors will open for them.

Sources and further reading

  1. FTC / X-Mode–Outlogic: sale of sensitive location data. Federal Trade Commission, FTC Finalizes Order with X-Mode and Successor Outlogic Prohibiting it from Sharing or Selling Sensitive Location Data, 11 April 2024 Source
  2. FTC / Avast: sale of browsing history. Federal Trade Commission, FTC Finalizes Order with Avast Banning it from Selling or Licensing Web Browsing Data for Advertising and Requiring it to Pay $16.5 Million, 26 June 2024 Source
  3. FTC / connected cars. Federal Trade Commission, Cars & Consumer Data: On Unlawful Collection & Use, 14 May 2024 Source
  4. EDPB / facial recognition. European Data Protection Board, Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement, final version 17 May 2023 Source