Design note — outside the design

What the design must do. One person reads 2,000–5,000 words of argued prose end to end, then follows the argument outward. Sustained reading is the product; every other affordance is a guest.

Three central decisions

  1. The apparatus is sequenced, not surrounding. No sidebar. What you need to decide to read — type, a one-line warranty gloss, status, evidence count, freshness — sits above the prose. What you need to traverse — footnotes, the 66-entry provenance inventory, outgoing links, backlinks, tags, neighbourhood — sits after it. Each happens once, at opposite ends of the read. Between them there is a four-pixel line and nothing else.
  2. That line is the wayfinder. A segmented rule: one segment per H2, flex-grown by that section's word count, filled to your scroll position. In four pixels it answers where you are, how much is left, and whether the next section is long. Hover, focus, tap, or press o to expand it into a labelled bar with search and theme. A resident contents rail would cost a permanent column for an action taken three times a read.
  3. The right margin is the only lane the apparatus may use mid-read. Claim-level footnotes become sidenotes beside the sentence they support, so adjacency carries the distinction the vault makes between a footnote and the note-level sources list. Wikilink previews use the same lane, never the prose. Tables and diagrams may borrow it; prose never leaves its measure. Below 1216px the lane collapses into tap-to-expand disclosures.

Deliberately rejected

Three-column documentation chrome. A resident search box (search is /, Ctrl/Cmd-K, or a labelled control). Coloured badges as the type signal: type is a spelled-out word plus a warranty sentence, colour is strictly redundant, and the page survives greyscale. Zebra striping. Red redlinks — a wanted page is a queue item, so it is muted and dashed rather than loud.

Tradeoffs and open uncertainty

Book setting — indented first lines, no space between paragraphs — buys momentum and costs scannability; the rail and outline scan instead. The lane pushes the column left of centre, which is only earned when footnotes are common; on the 430 notes carrying none, the page reads lopsided. I am not confident the 4px rail is discoverable on touch without a persistent affordance. And I have not solved 66 sources at the foot of a page: collapsed, it is still a bibliography dump; provenance probably wants its own page.

1 / 10  Opening
Vault index 554 notes 21 open questions

Synthesis

Case for privacy and security

A warranted conclusion this vault argues for from its own cited evidence. Read the sources before relying on the claim elsewhere.

Status
Stable Checked at its stated scope
Freshness
Review due 13 Jan 2027 In 5 months · not overdue
Evidence
66 sources 24 archived here, 42 external
Connections
49 out · 36 in Most-linked note in the vault
Length
3,400 words About 15 minutes · 10 sections
Updated
19 Jul 2026 Also known as “why privacy matters”

Privacy is not a claim that a person has something shameful to hide. It is the ability to decide who can learn intimate facts about one’s life, relationships, movements, finances, health, politics, and vulnerabilities.

Security is the practical ability to keep those facts, accounts, devices, and services confidential, available, and accurate. Privacy without security leaks. Security without privacy can become a tightly controlled surveillance system.

The two are connected but not interchangeable. Privacy threat modeling should always ask both: who could obtain or alter this information, and who should not have been collecting it in the first place?

The core claim of this synthesis is that privacy limits the conversion of information into Data as coercive power. Across commercial breaches, spyware campaigns, government databases, health systems, dating platforms, and forensic extraction, the recurring pattern is the same: concentrated sensitive data becomes leverage when weak controls, covert access, or exploitative sharing expose it.

02Why privacy is a right rather than a preference

Privacy protects autonomy, dignity, intimacy, association, bodily integrity, confidentiality, and the conditions for a self-authored life. People need confidential space to form relationships, deliberate, experiment, change their minds, seek care, and manage the boundaries between family, work, politics, and intimacy.

Framing privacy as a preference does specific analytical work: it makes the interest tradeable against convenience, price, and security, and it puts the burden of protection on the individual who declines to trade. European law does not frame it that way. Articles 7 and 8 of the Charter of Fundamental Rights treat private life and the protection of personal data as distinct fundamental rights, and Article 8 of the European Convention on Human Rights admits interference only where it is in accordance with law and necessary in a democratic society.1 The structure of that test matters more than the label: it asks whether an intrusion is necessary and proportionate, which is a question a terms-of-service dialog cannot answer on the subject’s behalf.

The GDPR carries the same logic into ordinary commercial processing by singling out categories of data whose exposure is disproportionately consequential.2

Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.

Regulation (EU) 2016/679, Article 9(1)

The prohibition-first construction is the point. Ordinary personal data is lawful to process where a legal basis exists; special-category data is unlawful to process unless a derogation applies. That inversion encodes an empirical judgement about asymmetry of consequence, and the case studies below are largely an argument that the judgement was correct and that its list is too short.

A right framing also survives the observation that people disclose readily. Revealed preference is a poor instrument here, because the disclosure is usually made to obtain a service, under an interface designed by the party that benefits, with no visibility into onward transfer, and with consequences that arrive years later and cannot be traced back to the disclosure that caused them. The privacy paradox literature is better read as a finding about the measurement instrument than about the underlying interest.

03Why privacy is a safety issue

The safety argument does not depend on an unusual threat model. It depends on the ordinary observation that a person’s location, associations, and health status are the operative inputs to stalking, to intimate partner violence, to targeted violence against journalists and dissidents, and to the more mundane category of coercion that never reaches a court. Someone who has left an abusive household has a threat actor who knows their date of birth, their mother’s name, their bank, and the schools their children attend. Every generic control that assumes an anonymous adversary fails against that one.

Location is the sharpest instrument because it is continuous, involuntary, and predictive. A month of coarse location traces resolves a home, a workplace, a place of worship, a clinic, and the identity of the person whose home is visited overnight. The commercial supply of that data is what turns an individual threat actor into a customer: the market in bulk advertising location has been used to identify a named individual from a purchased dataset, and the technique does not require a warrant, a breach, or a relationship with the target. The vault treats this under Location data brokerage (wanted page — not yet written).

WarningAggregate and de-identified are not the same claim

A dataset described as aggregate may be a table of counts, or it may be per-device records with the identifier hashed. Only the first resists re-identification. When a source says “anonymised”, this vault records the specific transformation applied, because the word alone has no fixed technical meaning and has been used for both.

Health data extends the same logic into a domain where disclosure is not merely embarrassing but changes what a person can do. A diagnosis reaching an employer, a family, or an insurer alters employment, custody, immigration, and insurance outcomes. Where the diagnosis is stigmatised — HIV status, psychiatric care, a termination, gender-affirming treatment — the disclosure can be the harm rather than a step towards it, and there is no remediation path comparable to reissuing a card number.

This is the mechanism the vault names Data as coercive power. Information becomes leverage when someone can act on it against the subject’s interest and the subject cannot prevent, detect, or undo the action. Each of the three conditions is a place a control can bite, and separating them is what keeps the argument from collapsing into a general objection to data.

04Privacy supports equal participation

The same disclosure costs different people different amounts. A home address is administrative for most and disqualifying for a person with a protected identity, a stalker, or an asylum claim. A record of attendance at a demonstration is a memory for most and an employment problem for a public employee. Because the cost is unevenly distributed, a rule that treats disclosure as uniformly minor is not neutral; it reallocates a burden onto the people least able to carry it.

The consequence for participation is that surveillance operates as a participation tax rather than a prohibition. Nobody is forbidden from joining the union, filing the complaint, seeking the diagnosis, or reading the argument; the cost of doing so simply rises for whoever is most exposed. That is a harder harm to measure than a breach, and the evidence is correspondingly weaker.

The chilling-effect literature should be reported at the strength it actually carries. Most of it measures self-reported willingness, in survey conditions, shortly after a salience prompt; the studies that observe behaviour rather than intention are fewer, smaller, and less consistent. The best-supported claim is that awareness of monitoring changes what people say they would do, and that a smaller effect on observed search and reading behaviour has been detected around specific high-salience events. Treating that as a demonstrated general suppression of political activity overstates it. This vault holds the open question under Chilling effects of surveillance (wanted page — not yet written).

05Privacy is market infrastructure

Confidentiality is a precondition for ordinary commerce, not a constraint on it. Negotiation, price discovery, medical consultation, legal advice, journalism, and employment all assume that a party can disclose selectively. Remove the assumption and the transaction either does not happen or happens on worse terms, which is why professional secrecy rules exist in domains that otherwise share no regulatory structure.

The failure is an externality rather than a preference. The party that collects and concentrates the data captures the benefit; the party whose life is described by it absorbs the loss. Where a holder’s expected cost is pL — the probability of a breach times the loss the holder itself bears — and the subject’s loss sits outside that product, minimisation is rational for the subject and irrational for the holder. Regulatory fines, mandatory notification, and litigation exposure are all attempts to move the subject’s loss inside the holder’s L.

TipThe decision rule this section supports

Data a system never collects cannot be breached, subpoenaed, sold in an insolvency, or used as leverage. Where a design choice is genuinely balanced on other grounds, prefer the one that holds less — not because collection is wrong, but because retention is the only variable in the chain below that a holder controls unilaterally and permanently.

Insolvency is the underrated case, because it converts a privacy policy into an asset schedule. A promise made by a going concern is enforceable against a going concern; in a bankruptcy the customer database is property, and the acquirer is bound only by whatever the original notice actually said and whatever the supervising authority is willing to impose. This is the mechanism that made the 23andMe filing a privacy event rather than a business event, and it generalises to every venture holding data it could not have collected under its own successor’s policy.

06A map from data to harm

The argument so far has treated “data leads to harm” as a single step. It is not. Separating the chain matters because each link admits a different control, and because an intervention aimed at the wrong link produces cost without effect.

Collection Concentration Exposure Leverage Harm Minimisation Retentionlimits Encryption,access control Purposelimitation Remedy,notification Controls to the left prevent. Controls to the right only compensate, and compensation is unavailable for disclosure of a fact that cannot be re-secured.

Figure 1. The conversion chain, and where each class of control can interrupt it.

Read left to right, the chain also explains why breach notification is a weak remedy and why it is nonetheless worth having. Notification acts at the last link. It cannot restore confidentiality, and for a fact that cannot be reissued — a genome, a therapy transcript, a sexual orientation — there is nothing downstream to restore. Its actual function is to price the earlier links, by making concentration visible to regulators, insurers, and counterparties.

Table 1. Five data classes, the mechanism that converts each into harm, and whether the harm can be undone. Compiled from the case studies below; “reversible” means the subject can restore the prior state, not that compensation is available.
Data class Conversion mechanism Harm Reversible? Worked example
Payment and identity numbers Resale into fraud markets; credential reuse Financial loss, impersonation Partly — instruments reissue, identifiers do not Equifax
Intimate life and sexual orientation Direct extortion; outing; social sanction Coercion, violence, loss of standing No Ashley Madison, Grindr
Clinical and psychiatric records Extortion of the patient rather than the holder Coercion, withdrawal from care No Vastaamo
Location and association traces Targeting; inference of relationships and attendance Stalking, violence, professional loss No Pegasus against El Faro
Vetting and genetic records State-level targeting; inference onto relatives Persecution, permanent exposure of kin No — and the subject may not be the discloser OPM, 23andMe

Two features of the table carry the argument. First, only the top row is meaningfully reversible, and it is the row that receives most of the regulatory and commercial attention, because it is the row with a priced loss. Second, the bottom row breaks the consent model outright: a genetic record describes relatives who never transacted, and a background-investigation file describes the references the subject named.

07Case studies

These ten are selected because each demonstrates a different conversion mechanism, not because they are the largest by record count. Record counts are a poor severity measure: the Vastaamo compromise is roughly three orders of magnitude smaller than Equifax and produced a category of harm that Equifax did not.

Ashley Madison

In 2015 an actor calling itself the Impact Team published account data for roughly thirty-two million users of an infidelity-oriented dating service, including email addresses, partial payment records, and account contents. The exposure produced documented extortion campaigns, and suicides were reported in the aftermath. The mechanism is the purest form of the pattern: the data had no fraud value and enormous coercive value, so the market that formed around it was an extortion market rather than a carding market.

Equifax

In 2017 a credit bureau failed to patch a known Apache Struts vulnerability (CVE-2017-5638) and lost records covering roughly 147 million people, including social security numbers. The instructive feature is the absence of a relationship: the affected people were not customers and had no ability to decline collection, decline retention, or select a different bureau. Where the subject cannot exit, market discipline is not available as a control and the loss sits entirely outside the holder’s L.

Vastaamo

In 2020 a Finnish private psychotherapy provider was compromised and the records of tens of thousands of patients — including session notes — were taken. The attacker extorted the company and then, when that failed, extorted individual patients directly. The provider entered insolvency; the perpetrator was convicted in 2024. This is the case that most clearly separates the subject’s exposure from the holder’s: the holder’s worst outcome was liquidation, which is bounded, while the patients’ exposure was permanent and individually addressed.

SpyFone

In 2021 the United States Federal Trade Commission banned a stalkerware vendor and its chief executive from the surveillance business and ordered deletion of the data collected. The product was sold as parental and employee monitoring and functioned as covert partner surveillance, harvesting location, messages, and photographs from devices the purchaser did not use. It belongs here because the harm required no breach at all: the intended, advertised operation of the product was the mechanism.

Grindr

Two separate episodes. In 2018 the platform was found to have transmitted user HIV status to analytics vendors; in 2021 the Norwegian data protection authority fined it for sharing user location and profile data with advertising partners without a valid legal basis. Separately, a United States publication identified a named priest in 2021 using commercially purchased app location data. The three together show that the ad-tech supply chain reproduces the outcome of a breach without one occurring.

Pegasus against El Faro

Between 2020 and 2021, forensic analysis attributed Pegasus infections to the phones of more than twenty journalists and staff at the Salvadoran outlet El Faro.3 The targets were not the endpoint: a journalist’s device is a directory of sources. Endpoint compromise defeats transport encryption entirely, which is why this vault treats device integrity and message confidentiality as separate properties rather than two descriptions of one guarantee.

Afghan relocation data leak

A United Kingdom government spreadsheet containing details of roughly nineteen thousand people who had applied for relocation on the basis of work with British forces was disclosed in error in 2022, and the fact of the disclosure was itself kept from the public under a court order until 2025. Two mechanisms compound here: the underlying exposure placed applicants and their families at risk from a hostile government, and the secrecy meant the people at risk could not act on information about their own exposure.

OPM

The 2015 compromise of the United States Office of Personnel Management took background-investigation records for around 21.5 million people, together with 5.6 million sets of fingerprints. Standard-form vetting files contain the subject’s finances, foreign contacts, mental-health history, and named references, so a single record describes several people who never applied for anything. Fingerprints cannot be reissued, which makes this the clearest instance of a loss with no downstream remedy.

VTech

In 2015 a children’s electronics maker lost profile data for roughly 6.4 million children, along with photographs and parent–child chat logs. The data was collected by a toy, from subjects with no capacity to consent, and retained beyond any plausible operational need. It is included because it disposes of the argument that exposure follows from the subject’s own choices.

23andMe

In 2023 credential stuffing against a consumer genetics service reached a small number of accounts directly and, through a relative-matching feature, exposed profile data for several million more. In 2025 the company filed for bankruptcy protection, putting the genetic database into an insolvency process. See 23andMe data breach. The case closes the loop with the market section: the reversibility column and the asset schedule are the same problem seen from two sides.

08Why lawful extraction is still an ethical question

Everything above concerns unlawful access. The harder case is access that is lawful, authorised, and proportionate at the moment it is granted, and disproportionate by the time it is executed. Mobile forensic extraction is the clearest instance, because the warrant is written against an offence and the extraction is performed against a device.

A full-filesystem extraction by a tool such as Cellebrite does not return the evidence sought. It returns the device: message history, photographs, location history, deleted fragments recovered from unallocated space, health records, and the correspondence of every person who ever wrote to the owner.4 Third parties who are not suspects, not notified, and not able to object are the majority of the data subjects in any such extraction.

DangerDo not treat a filter as a technical detail

Where an extraction is scoped by keyword or date filters, the filter is the proportionality control, and its parameters determine what the defence never sees. Whether those parameters are disclosed at trial is an evidentiary question with a different answer in each jurisdiction, and this vault does not currently know the Swedish answer.

That gap is tracked, not assumed away, under Are Swedish mobile-extraction filters disclosed at trial?, which is why this synthesis states the extraction problem without stating a conclusion about Swedish practice. A separate and unresolved question is whether the retained extraction images are themselves subject to a deletion schedule once proceedings conclude, which this vault holds as Retention of forensic extraction images (wanted page — not yet written).

09Objections

“Nothing to hide”

The objection assumes the subject chooses the audience and the interpretation. Neither holds. The audience is whoever obtains the data, including a future employer, a future government, and a hostile relative; the interpretation is made by a party with an interest and without context. The claim also fails on its own terms for anyone whose lawful activity is stigmatised, which is a large fraction of the population at some point in a life.

“Privacy protects wrongdoers”

It does, in the same way that legal representation and evidentiary rules do. The question is not whether a protection is ever useful to a guilty party but whether the marginal enforcement gain from removing it exceeds the aggregate cost to everyone else. That is an empirical question, and it is answerable in specific cases; the objection is usually deployed to avoid asking it.

“People consent by using the service”

Consent is doing two jobs here that it cannot do at once: authorising a specific processing operation, and transferring the entire downstream risk. The second is not something a consent mechanism can effect, which is why the regulatory structure sets obligations that survive consent. The practical test is whether the subject could have understood the onward transfer at the moment of disclosure; in an ad-tech supply chain with hundreds of counterparties, the answer is not close.

“Aggregate data is anonymous”

Sometimes. Aggregation to genuine counts over sufficiently large cells does resist re-identification. Pseudonymised per-device records do not, and the distinction is frequently lost between the technical documentation and the public statement. The operative question is what transformation was actually applied, which is why this vault records the transformation rather than the label.

10Regulatory setting

The European framework is the strongest of the ones surveyed and is still built around holders rather than subjects: it constrains processing, requires a basis, and imposes notification, but it does not make concentration itself costly. Enforcement is slow relative to the speed at which data moves, and the remedies available to an individual after exposure are compensatory in a domain where compensation is structurally inadequate.

The delisting jurisprudence illustrates the limit. A search engine can be required to remove a result, and this is a real remedy for reputational exposure, but the underlying publication persists and the obligation is territorially bounded. See GC and Others C-136/17 for the special-category treatment, and note that an operator’s X-Robots-Tag: noindex header achieves a technically similar outcome voluntarily and instantly, which is a comment on the ratio of legal to technical leverage rather than an argument against the jurisprudence.

Sweden adds two complications this synthesis does not resolve: the constitutional publishing licence that removes some databases from data-protection law entirely, and the breadth of the public-access principle applied to material that was administrative when filed and is searchable now. Both are treated in Utgivningsbevis and data protection (wanted page — not yet written).

NoteScope of this synthesis

The claim argued here is about the conversion of concentrated data into leverage. It is not a claim that any particular regulatory instrument is effective, and it is not a claim about the correct balance in any specific investigative context. Those are argued separately and can be decided against this note without disturbing it.

Open verification steps carried by this note

  • Confirm the Norwegian DPA figure against the decision text rather than press coverage.
  • Replace the secondary source for the OPM fingerprint count with the agency statement.
  • Check whether the 23andMe insolvency produced a binding condition on the genetic database, and record the outcome in the case-study section rather than here.
  • Establish the Swedish position on extraction-filter disclosure, then convert the linked question note to whatever type the answer turns out to be.
  • Re-read the chilling-effect paragraph against the observational studies specifically, since it currently rests on a reading of the survey literature.

Footnotes

Claim-level citations. These support the sentence they are attached to, which is a narrower assertion than the provenance inventory below.

  1. Charter of Fundamental Rights of the European Union, Arts. 7 and 8; ECHR Art. 8(2). The necessity and proportionality test, not consent, is the operative structure in both.
  2. Regulation (EU) 2016/679, Art. 9(1), with the derogations in Art. 9(2). Sexual orientation is inside the Article 9 list while financial distress and immigration status are not, which is a drafting choice rather than a finding about relative harm.
  3. Citizen Lab and Access Now, forensic analysis published January 2022. Attribution is to the spyware and operator infrastructure, not to a named purchasing state.
  4. The distinction between logical, file-system, and full-filesystem extraction is doctrinally load-bearing and frequently collapsed in reporting. Only the last recovers unallocated space.

Provenance — 66 sources

Connections

Argued from here · 36 backlinks

30 more backlinks

Truncated for the mockup.

Neighbourhood

Shares 4 or more links with 11 notes, most densely with Data as coercive power and Privacy threat modeling. Open the local graph.

Tags

File
Case for privacy and security.md
Updated
19 Jul 2026
Review
13 Jan 2027
Aliases
why privacy matters, case for privacy
Keys: / search · o outline · t theme · Esc close

Other surfaces, same rules

Everything below reuses the note page’s type scale and the same principle: the type word is always spelled out, colour is redundant, and non-stable status states what is actually missing rather than showing a badge.

Tag page — privacy, 240 notes

The largest tag in the vault covers 43% of it, so a flat list of 240 is useless. The page leads with type composition, then lists only what a reader can act on: the frontier, then the most-linked notes, then everything else behind a disclosure.

TypeNotesNon-stableOverdue review
Source96011
Entity611419
Concept4297
Synthesis2846
Question992
Event400

Open frontier in this tag · 9

Most linked in this tag

All 240 notes with this tag, alphabetical

Truncated for the mockup.

Co-occurring tags

A source note, entire — 90 words

Source

The ASA statement on statistical significance and P-values

Filed as ASA statement on p-values — the handle is ours, the title is the work’s.

Stable 2 sources No review scheduled Updated 4 Feb 2026

The ASA issued this statement in 2016 to address widespread misuse of statistical significance and p-values. The local PDF is the association’s official release. The statement defines a p-value in relation to a specified statistical model. It says a p-value does not measure the probability that the studied hypothesis is true, the probability that chance alone produced the data, the size or importance of an effect, or the strength of evidence by itself. The statement supports the comparison in Probabilistic interpretations of beyond reasonable doubt.

A stable note can be this short. Status describes reliability at the declared scope, not length.

A question note — the frontier

Question

Are Swedish mobile-extraction filters disclosed at trial?

An admitted gap. Open by design: this stays a question until evidence settles it, or until the finding is that it cannot be settled from reachable evidence.

Working Review overdue by 12 days 7 sources 3 in · 5 out

What is known

Extraction is routinely scoped by keyword and date filters, and the filter determines what the defence never sees. Two published appellate summaries describe the extraction as “targeted” without recording the parameters.

What would settle it

A defence request for filter parameters in a decided case, and either the court’s ruling on it or the prosecutor’s response. Failing that, a practitioner account from either side.

A working note — its gap, stated

Concept

Age assurance

Working Review overdue by 41 days 19 sources 14 in · 22 out

Known material gap The note compares assurance methods on accuracy and data exposure but has no evidence on circumvention rates, so it cannot support any claim about whether a given method works in deployment.

Age assurance is the family of techniques for establishing that a user falls on one side of an age threshold: self-declaration, document checks, facial age estimation, and inference from account history. The methods differ in accuracy, in the data they require, and in what they leave behind — and those three properties trade against each other rather than improving together.

Working is not “unfinished”. It names a specific gap, which is what a reader deciding whether to cite the note needs.