Synthesis
Case for privacy and security
A warranted conclusion this vault argues for from its own cited evidence. Read the sources before relying on the claim elsewhere.
- Status
- Stable Checked at its stated scope
- Freshness
- Review due 13 Jan 2027 In 5 months · not overdue
- Evidence
- 66 sources 24 archived here, 42 external
- Connections
- 49 out · 36 in Most-linked note in the vault
- Length
- 3,400 words About 15 minutes · 10 sections
- Updated
- 19 Jul 2026 Also known as “why privacy matters”
Privacy is not a claim that a person has something shameful to hide. It is the ability to decide who can learn intimate facts about one’s life, relationships, movements, finances, health, politics, and vulnerabilities.
Security is the practical ability to keep those facts, accounts, devices, and services confidential, available, and accurate. Privacy without security leaks. Security without privacy can become a tightly controlled surveillance system.
The two are connected but not interchangeable. Privacy threat modeling should always ask both: who could obtain or alter this information, and who should not have been collecting it in the first place?
The core claim of this synthesis is that privacy limits the conversion of information into Data as coercive power. Across commercial breaches, spyware campaigns, government databases, health systems, dating platforms, and forensic extraction, the recurring pattern is the same: concentrated sensitive data becomes leverage when weak controls, covert access, or exploitative sharing expose it.
02Why privacy is a right rather than a preference
Privacy protects autonomy, dignity, intimacy, association, bodily integrity, confidentiality, and the conditions for a self-authored life. People need confidential space to form relationships, deliberate, experiment, change their minds, seek care, and manage the boundaries between family, work, politics, and intimacy.
Framing privacy as a preference does specific analytical work: it makes the interest tradeable against convenience, price, and security, and it puts the burden of protection on the individual who declines to trade. European law does not frame it that way. Articles 7 and 8 of the Charter of Fundamental Rights treat private life and the protection of personal data as distinct fundamental rights, and Article 8 of the European Convention on Human Rights admits interference only where it is in accordance with law and necessary in a democratic society.1 The structure of that test matters more than the label: it asks whether an intrusion is necessary and proportionate, which is a question a terms-of-service dialog cannot answer on the subject’s behalf.
The GDPR carries the same logic into ordinary commercial processing by singling out categories of data whose exposure is disproportionately consequential.2
Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.
Regulation (EU) 2016/679, Article 9(1)
The prohibition-first construction is the point. Ordinary personal data is lawful to process where a legal basis exists; special-category data is unlawful to process unless a derogation applies. That inversion encodes an empirical judgement about asymmetry of consequence, and the case studies below are largely an argument that the judgement was correct and that its list is too short.
A right framing also survives the observation that people disclose readily. Revealed preference is a poor instrument here, because the disclosure is usually made to obtain a service, under an interface designed by the party that benefits, with no visibility into onward transfer, and with consequences that arrive years later and cannot be traced back to the disclosure that caused them. The privacy paradox literature is better read as a finding about the measurement instrument than about the underlying interest.
03Why privacy is a safety issue
The safety argument does not depend on an unusual threat model. It depends on the ordinary observation that a person’s location, associations, and health status are the operative inputs to stalking, to intimate partner violence, to targeted violence against journalists and dissidents, and to the more mundane category of coercion that never reaches a court. Someone who has left an abusive household has a threat actor who knows their date of birth, their mother’s name, their bank, and the schools their children attend. Every generic control that assumes an anonymous adversary fails against that one.
Location is the sharpest instrument because it is continuous, involuntary, and predictive. A month of coarse location traces resolves a home, a workplace, a place of worship, a clinic, and the identity of the person whose home is visited overnight. The commercial supply of that data is what turns an individual threat actor into a customer: the market in bulk advertising location has been used to identify a named individual from a purchased dataset, and the technique does not require a warrant, a breach, or a relationship with the target. The vault treats this under Location data brokerage (wanted page — not yet written).
WarningAggregate and de-identified are not the same claim
A dataset described as aggregate may be a table of counts, or it may be per-device records with the identifier hashed. Only the first resists re-identification. When a source says “anonymised”, this vault records the specific transformation applied, because the word alone has no fixed technical meaning and has been used for both.
Health data extends the same logic into a domain where disclosure is not merely embarrassing but changes what a person can do. A diagnosis reaching an employer, a family, or an insurer alters employment, custody, immigration, and insurance outcomes. Where the diagnosis is stigmatised — HIV status, psychiatric care, a termination, gender-affirming treatment — the disclosure can be the harm rather than a step towards it, and there is no remediation path comparable to reissuing a card number.
This is the mechanism the vault names Data as coercive power. Information becomes leverage when someone can act on it against the subject’s interest and the subject cannot prevent, detect, or undo the action. Each of the three conditions is a place a control can bite, and separating them is what keeps the argument from collapsing into a general objection to data.
04Privacy supports equal participation
The same disclosure costs different people different amounts. A home address is administrative for most and disqualifying for a person with a protected identity, a stalker, or an asylum claim. A record of attendance at a demonstration is a memory for most and an employment problem for a public employee. Because the cost is unevenly distributed, a rule that treats disclosure as uniformly minor is not neutral; it reallocates a burden onto the people least able to carry it.
The consequence for participation is that surveillance operates as a participation tax rather than a prohibition. Nobody is forbidden from joining the union, filing the complaint, seeking the diagnosis, or reading the argument; the cost of doing so simply rises for whoever is most exposed. That is a harder harm to measure than a breach, and the evidence is correspondingly weaker.
The chilling-effect literature should be reported at the strength it actually carries. Most of it measures self-reported willingness, in survey conditions, shortly after a salience prompt; the studies that observe behaviour rather than intention are fewer, smaller, and less consistent. The best-supported claim is that awareness of monitoring changes what people say they would do, and that a smaller effect on observed search and reading behaviour has been detected around specific high-salience events. Treating that as a demonstrated general suppression of political activity overstates it. This vault holds the open question under Chilling effects of surveillance (wanted page — not yet written).
05Privacy is market infrastructure
Confidentiality is a precondition for ordinary commerce, not a constraint on it. Negotiation, price discovery, medical consultation, legal advice, journalism, and employment all assume that a party can disclose selectively. Remove the assumption and the transaction either does not happen or happens on worse terms, which is why professional secrecy rules exist in domains that otherwise share no regulatory structure.
The failure is an externality rather than a preference. The party that collects and concentrates the data captures the benefit; the party whose life is described by it absorbs the loss. Where a holder’s expected cost is — the probability of a breach times the loss the holder itself bears — and the subject’s loss sits outside that product, minimisation is rational for the subject and irrational for the holder. Regulatory fines, mandatory notification, and litigation exposure are all attempts to move the subject’s loss inside the holder’s .
TipThe decision rule this section supports
Data a system never collects cannot be breached, subpoenaed, sold in an insolvency, or used as leverage. Where a design choice is genuinely balanced on other grounds, prefer the one that holds less — not because collection is wrong, but because retention is the only variable in the chain below that a holder controls unilaterally and permanently.
Insolvency is the underrated case, because it converts a privacy policy into an asset schedule. A promise made by a going concern is enforceable against a going concern; in a bankruptcy the customer database is property, and the acquirer is bound only by whatever the original notice actually said and whatever the supervising authority is willing to impose. This is the mechanism that made the 23andMe filing a privacy event rather than a business event, and it generalises to every venture holding data it could not have collected under its own successor’s policy.
06A map from data to harm
The argument so far has treated “data leads to harm” as a single step. It is not. Separating the chain matters because each link admits a different control, and because an intervention aimed at the wrong link produces cost without effect.
Figure 1. The conversion chain, and where each class of control can interrupt it.
Read left to right, the chain also explains why breach notification is a weak remedy and why it is nonetheless worth having. Notification acts at the last link. It cannot restore confidentiality, and for a fact that cannot be reissued — a genome, a therapy transcript, a sexual orientation — there is nothing downstream to restore. Its actual function is to price the earlier links, by making concentration visible to regulators, insurers, and counterparties.
| Data class | Conversion mechanism | Harm | Reversible? | Worked example |
|---|---|---|---|---|
| Payment and identity numbers | Resale into fraud markets; credential reuse | Financial loss, impersonation | Partly — instruments reissue, identifiers do not | Equifax |
| Intimate life and sexual orientation | Direct extortion; outing; social sanction | Coercion, violence, loss of standing | No | Ashley Madison, Grindr |
| Clinical and psychiatric records | Extortion of the patient rather than the holder | Coercion, withdrawal from care | No | Vastaamo |
| Location and association traces | Targeting; inference of relationships and attendance | Stalking, violence, professional loss | No | Pegasus against El Faro |
| Vetting and genetic records | State-level targeting; inference onto relatives | Persecution, permanent exposure of kin | No — and the subject may not be the discloser | OPM, 23andMe |
Two features of the table carry the argument. First, only the top row is meaningfully reversible, and it is the row that receives most of the regulatory and commercial attention, because it is the row with a priced loss. Second, the bottom row breaks the consent model outright: a genetic record describes relatives who never transacted, and a background-investigation file describes the references the subject named.
07Case studies
These ten are selected because each demonstrates a different conversion mechanism, not because they are the largest by record count. Record counts are a poor severity measure: the Vastaamo compromise is roughly three orders of magnitude smaller than Equifax and produced a category of harm that Equifax did not.
Ashley Madison
In 2015 an actor calling itself the Impact Team published account data for roughly thirty-two million users of an infidelity-oriented dating service, including email addresses, partial payment records, and account contents. The exposure produced documented extortion campaigns, and suicides were reported in the aftermath. The mechanism is the purest form of the pattern: the data had no fraud value and enormous coercive value, so the market that formed around it was an extortion market rather than a carding market.
Equifax
In 2017 a credit bureau failed to patch a known Apache Struts vulnerability
(CVE-2017-5638) and lost records covering roughly 147 million people,
including social security numbers. The instructive feature is the absence of a
relationship: the affected people were not customers and had no ability to decline
collection, decline retention, or select a different bureau. Where the subject cannot
exit, market discipline is not available as a control and the loss sits entirely
outside the holder’s .
Vastaamo
In 2020 a Finnish private psychotherapy provider was compromised and the records of tens of thousands of patients — including session notes — were taken. The attacker extorted the company and then, when that failed, extorted individual patients directly. The provider entered insolvency; the perpetrator was convicted in 2024. This is the case that most clearly separates the subject’s exposure from the holder’s: the holder’s worst outcome was liquidation, which is bounded, while the patients’ exposure was permanent and individually addressed.
SpyFone
In 2021 the United States Federal Trade Commission banned a stalkerware vendor and its chief executive from the surveillance business and ordered deletion of the data collected. The product was sold as parental and employee monitoring and functioned as covert partner surveillance, harvesting location, messages, and photographs from devices the purchaser did not use. It belongs here because the harm required no breach at all: the intended, advertised operation of the product was the mechanism.
Grindr
Two separate episodes. In 2018 the platform was found to have transmitted user HIV status to analytics vendors; in 2021 the Norwegian data protection authority fined it for sharing user location and profile data with advertising partners without a valid legal basis. Separately, a United States publication identified a named priest in 2021 using commercially purchased app location data. The three together show that the ad-tech supply chain reproduces the outcome of a breach without one occurring.
Pegasus against El Faro
Between 2020 and 2021, forensic analysis attributed Pegasus infections to the phones of more than twenty journalists and staff at the Salvadoran outlet El Faro.3 The targets were not the endpoint: a journalist’s device is a directory of sources. Endpoint compromise defeats transport encryption entirely, which is why this vault treats device integrity and message confidentiality as separate properties rather than two descriptions of one guarantee.
Afghan relocation data leak
A United Kingdom government spreadsheet containing details of roughly nineteen thousand people who had applied for relocation on the basis of work with British forces was disclosed in error in 2022, and the fact of the disclosure was itself kept from the public under a court order until 2025. Two mechanisms compound here: the underlying exposure placed applicants and their families at risk from a hostile government, and the secrecy meant the people at risk could not act on information about their own exposure.
OPM
The 2015 compromise of the United States Office of Personnel Management took background-investigation records for around 21.5 million people, together with 5.6 million sets of fingerprints. Standard-form vetting files contain the subject’s finances, foreign contacts, mental-health history, and named references, so a single record describes several people who never applied for anything. Fingerprints cannot be reissued, which makes this the clearest instance of a loss with no downstream remedy.
VTech
In 2015 a children’s electronics maker lost profile data for roughly 6.4 million children, along with photographs and parent–child chat logs. The data was collected by a toy, from subjects with no capacity to consent, and retained beyond any plausible operational need. It is included because it disposes of the argument that exposure follows from the subject’s own choices.
23andMe
In 2023 credential stuffing against a consumer genetics service reached a small number of accounts directly and, through a relative-matching feature, exposed profile data for several million more. In 2025 the company filed for bankruptcy protection, putting the genetic database into an insolvency process. See 23andMe data breach. The case closes the loop with the market section: the reversibility column and the asset schedule are the same problem seen from two sides.
08Why lawful extraction is still an ethical question
Everything above concerns unlawful access. The harder case is access that is lawful, authorised, and proportionate at the moment it is granted, and disproportionate by the time it is executed. Mobile forensic extraction is the clearest instance, because the warrant is written against an offence and the extraction is performed against a device.
A full-filesystem extraction by a tool such as Cellebrite does not return the evidence sought. It returns the device: message history, photographs, location history, deleted fragments recovered from unallocated space, health records, and the correspondence of every person who ever wrote to the owner.4 Third parties who are not suspects, not notified, and not able to object are the majority of the data subjects in any such extraction.
DangerDo not treat a filter as a technical detail
Where an extraction is scoped by keyword or date filters, the filter is the proportionality control, and its parameters determine what the defence never sees. Whether those parameters are disclosed at trial is an evidentiary question with a different answer in each jurisdiction, and this vault does not currently know the Swedish answer.
That gap is tracked, not assumed away, under Are Swedish mobile-extraction filters disclosed at trial?, which is why this synthesis states the extraction problem without stating a conclusion about Swedish practice. A separate and unresolved question is whether the retained extraction images are themselves subject to a deletion schedule once proceedings conclude, which this vault holds as Retention of forensic extraction images (wanted page — not yet written).
09Objections
“Nothing to hide”
The objection assumes the subject chooses the audience and the interpretation. Neither holds. The audience is whoever obtains the data, including a future employer, a future government, and a hostile relative; the interpretation is made by a party with an interest and without context. The claim also fails on its own terms for anyone whose lawful activity is stigmatised, which is a large fraction of the population at some point in a life.
“Privacy protects wrongdoers”
It does, in the same way that legal representation and evidentiary rules do. The question is not whether a protection is ever useful to a guilty party but whether the marginal enforcement gain from removing it exceeds the aggregate cost to everyone else. That is an empirical question, and it is answerable in specific cases; the objection is usually deployed to avoid asking it.
“People consent by using the service”
Consent is doing two jobs here that it cannot do at once: authorising a specific processing operation, and transferring the entire downstream risk. The second is not something a consent mechanism can effect, which is why the regulatory structure sets obligations that survive consent. The practical test is whether the subject could have understood the onward transfer at the moment of disclosure; in an ad-tech supply chain with hundreds of counterparties, the answer is not close.
“Aggregate data is anonymous”
Sometimes. Aggregation to genuine counts over sufficiently large cells does resist re-identification. Pseudonymised per-device records do not, and the distinction is frequently lost between the technical documentation and the public statement. The operative question is what transformation was actually applied, which is why this vault records the transformation rather than the label.
10Regulatory setting
The European framework is the strongest of the ones surveyed and is still built around holders rather than subjects: it constrains processing, requires a basis, and imposes notification, but it does not make concentration itself costly. Enforcement is slow relative to the speed at which data moves, and the remedies available to an individual after exposure are compensatory in a domain where compensation is structurally inadequate.
The delisting jurisprudence illustrates the limit. A search engine can be required to
remove a result, and this is a real remedy for reputational exposure, but the underlying
publication persists and the obligation is territorially bounded. See
GC and Others C-136/17
for the special-category treatment, and note that an operator’s
X-Robots-Tag: noindex header achieves a technically similar outcome
voluntarily and instantly, which is a comment on the ratio of legal to technical
leverage rather than an argument against the jurisprudence.
Sweden adds two complications this synthesis does not resolve: the constitutional publishing licence that removes some databases from data-protection law entirely, and the breadth of the public-access principle applied to material that was administrative when filed and is searchable now. Both are treated in Utgivningsbevis and data protection (wanted page — not yet written).
NoteScope of this synthesis
The claim argued here is about the conversion of concentrated data into leverage. It is not a claim that any particular regulatory instrument is effective, and it is not a claim about the correct balance in any specific investigative context. Those are argued separately and can be decided against this note without disturbing it.
Open verification steps carried by this note
- Confirm the Norwegian DPA figure against the decision text rather than press coverage.
- Replace the secondary source for the OPM fingerprint count with the agency statement.
- Check whether the 23andMe insolvency produced a binding condition on the genetic database, and record the outcome in the case-study section rather than here.
- Establish the Swedish position on extraction-filter disclosure, then convert the linked question note to whatever type the answer turns out to be.
- Re-read the chilling-effect paragraph against the observational studies specifically, since it currently rests on a reading of the survey literature.
Footnotes
Claim-level citations. These support the sentence they are attached to, which is a narrower assertion than the provenance inventory below.
- Charter of Fundamental Rights of the European Union, Arts. 7 and 8; ECHR Art. 8(2). The necessity and proportionality test, not consent, is the operative structure in both. ↩
- Regulation (EU) 2016/679, Art. 9(1), with the derogations in Art. 9(2). Sexual orientation is inside the Article 9 list while financial distress and immigration status are not, which is a drafting choice rather than a finding about relative harm. ↩
- Citizen Lab and Access Now, forensic analysis published January 2022. Attribution is to the spyware and operator infrastructure, not to a named purchasing state. ↩
- The distinction between logical, file-system, and full-filesystem extraction is doctrinally load-bearing and frequently collapsed in reporting. Only the last recovers unallocated space. ↩
Provenance — 66 sources
What materially informed this note as a whole. 24 artifacts are archived on disk and will still open if the web copy disappears; 42 are external references that were read but not captured.
Archived here · 24
- PDFsources/2016-03-asa-statement-on-p-values.pdf
- PDFsources/2015-07-opm-incident-report-to-congress.pdf
- PDFsources/2021-01-datatilsynet-grindr-advance-notification.pdf
- HTMLsources/2022-01-13-citizen-lab-el-faro-pegasus.html
- PDFsources/2021-09-ftc-spyfone-complaint-and-order.pdf
- HTMLsources/2024-04-vastaamo-district-court-judgment-summary.html
18 more archived artifacts
- PDFsources/2017-09-equifax-8k-filing.pdf
- PDFsources/2019-07-ftc-equifax-stipulated-order.pdf
- HTMLsources/2025-03-23andme-chapter-11-filing-coverage.html
- TXTsources/2025-07-uk-afghan-data-incident-statement.txt
- PDFsources/2016-04-gdpr-consolidated-text.pdf
- HTMLsources/2015-11-vtech-breach-disclosure.html
Truncated for the mockup; the generator emits all 24.
External references · 42
- URLeur-lex.europa.eu/eli/reg/2016/679/oj
- URLcitizenlab.ca/2022/01/project-torogoz-el-faro-pegasus
- URLdatatilsynet.no/en/news/2021/grindr-fine
- DOI10.1080/00031305.2016.1154108
38 more external references
Truncated for the mockup.
Connections
Argues from · 49 outgoing
- ConceptData as coercive power
- ConceptPrivacy threat modeling
- EntityCellebrite
- Event23andMe data breach
- SourceGC and Others C-136/17
- QuestionAre Swedish mobile-extraction filters disclosed at trial?
43 more outgoing links
Truncated for the mockup.
Wanted from here · 4
Argued from here · 36 backlinks
- SynthesisAndroid app distribution trust models
- SynthesisRättssäkerhet in Swedish criminal cases
- ConceptAge assurance
- ConceptFalse accusations as an epistemic risk
- EntityApple Private Cloud Compute
- EventKevinfallet
30 more backlinks
Truncated for the mockup.
Neighbourhood
Shares 4 or more links with 11 notes, most densely with Data as coercive power and Privacy threat modeling. Open the local graph.
Tags
- File
- Case for privacy and security.md
- Updated
- 19 Jul 2026
- Review
- 13 Jan 2027
- Aliases
- why privacy matters, case for privacy