Case for privacy and security
alsowhy privacy matters · case for privacy
Privacy is not a claim that a person has something shameful to hide. It is the ability to decide who can learn intimate facts about one's life, relationships, movements, finances, health, politics, and vulnerabilities.
Security is the practical ability to keep those facts, accounts, devices, and services confidential, available, and accurate. Privacy without security leaks. Security without privacy can become a tightly controlled surveillance system.
The two are connected but not interchangeable. Privacy threat modeling should always ask both: who could obtain or alter this information, and who should not have been collecting it in the first place?
The core claim of this synthesis is that privacy limits the conversion of information into Data as coercive power. Across commercial breaches, spyware campaigns, government databases, health systems, dating platforms, and forensic extraction, the recurring pattern is the same: concentrated sensitive data becomes leverage when weak controls, covert access, or exploitative sharing expose it.
Why privacy is a right rather than a preference
Privacy protects autonomy, dignity, intimacy, association, bodily integrity, confidentiality, and the conditions for a self-authored life. People need confidential space to form relationships, deliberate, experiment, change their minds, seek care, and manage the boundaries between family, work, politics, and intimacy.
The preference framing asks what a person is hiding and then evaluates the answer. That makes protection depend on the sympathies of whoever is judging, which means it fails precisely where it is needed: for the person whose lawful life is unpopular, whose immigration status is irregular, whose religion or sexuality is criminalised in a country they may one day transit. A right does not require its holder to justify the exercise, and that is the whole of its practical value. It also does not depend on the holder being sympathetic, which is why the strongest cases for it involve people the reader may not like.
European human rights law reaches the same structure by a different route. In S. and Marper v. United Kingdom the Grand Chamber struck down the indefinite retention of fingerprints, cell samples, and DNA profiles taken from people who had been arrested and then acquitted or never charged. The Court did not weigh how embarrassing the samples were. It objected to the shape of the scheme.
… the blanket and indiscriminate nature of the powers of retention…
S. and Marper v. United Kingdom, Grand Chamber, 4 December 2008, § 1251
The operative distinction is not rhetorical. A preference can be traded away for convenience, and any interface that offers the trade will eventually get a yes from almost everyone; a right sets a floor beneath which the bargain is not on offer at all. This is why Consent theatre is not merely an aesthetic complaint about cookie banners. Where consent is the only mechanism, the protection tracks the design of the dialogue rather than the sensitivity of the data.
Why privacy is a safety issue
The safety argument does not require any general claim that exposure harms everyone equally. It requires only the narrower observation that for an identifiable subset of people, disclosure of a single field converts directly into physical risk. A current address is the canonical case. So is a workplace, a child's school, a daily route, a real name attached to a pseudonym, or the fact that two people are in contact at all.
Sweden makes this concrete in a way most jurisdictions do not. The population register is built on the premise that a person's registered address is ordinarily available, and the protective regimes — sekretessmarkering and the stricter skyddad folkbokföring — are exceptions granted on showing a concrete threat.2 The protection changes who may lawfully obtain the address going forward. It does not reach copies already sold to data brokers, published in a directory, or screenshotted by someone who wishes the person harm.
Danger Address exposure is not reversible
Treat a current address as a one-way field. Protective registration constrains future lawful disclosure; it cannot retract copies already held, and it imposes a permanent administrative cost on the protected person, who must then transact with every counterparty through a proxy address. Design and advice should aim at preventing the first disclosure, not at remediating it.
The same mechanism runs through consumer stalkerware. The commercial pitch is parental oversight; the deployed reality documented in enforcement actions is partner surveillance, and the software's value to the buyer is precisely that the person being tracked does not know. State spyware differs in scale and legality rather than in mechanism: once Pegasus spyware is resident on a phone, the distinction between message content, location, contacts, and the microphone collapses, and so does every assumption the target made when choosing which app to talk in.
Privacy supports equal participation
The cost of exposure is not distributed evenly, and averaging hides that. For most people, a leaked shopping history is an annoyance. For a person seeking an abortion in a hostile jurisdiction, a person whose family does not know they are gay, a witness, a survivor of domestic violence, or an asylum seeker whose home government reads the same database, the identical record is a lever. An argument that privacy costs little because most people are unaffected has selected the wrong denominator: the value of the protection is concentrated in the tail, and the tail is where the harms are.
Participation is the second-order effect. People who expect to be observed answer differently, join differently, and search differently. Self-reported chilling is weak evidence on its own — it is easy to elicit and hard to validate against behaviour — and the honest version of this claim needs the behavioural studies rather than the survey ones, which is what Chilling effects in survey research is wanted for. What is not in doubt is the asymmetry of remedy. A wrong charge on a card is reversed; an inference drawn about someone's health or politics enters systems with no Correction channel at all, and it is acted on by parties the subject cannot identify.
Privacy is market infrastructure
Confidentiality is not an add-on to commerce; it is a precondition for most of it. Salary negotiation, corporate acquisition, legal advice, medical consultation, and journalism all depend on a party's ability to keep information from a counterparty until it chooses to disclose. A market with perfect visibility into every participant's reservation price is not a more efficient market. It is a market with one price-setter.
The reason firms nevertheless under-invest is an ordinary externality. The expected cost a controller reasons about is roughly , the probability of a breach times the loss it bears — regulatory fine, remediation, churn. But the loss the incident actually produces is distributed across the data subjects, who were not party to the decision:
where is the harm to subject i and n is the number of records. Because the second term is invisible on the controller's balance sheet, retention looks free and deletion looks like forgone option value. Data minimisation is the intervention that survives this analysis, because it is the only one that reduces n rather than betting on a lower p. Every control that instead assumes competent operation is a bet that the operator stays competent for the entire retention period, which for a genome or a national identity number is the subject's lifetime.
A map from data to harm
The case studies below differ in sector, jurisdiction, and decade, and they run through the same five stages. Stating the stages separately makes it possible to ask which one a proposed control actually touches, and most proposed controls touch the third.
Case studies
These ten are not a survey. They were selected because each one closes a different link in the chain above with documented evidence rather than inference, and because between them they cover commercial, clinical, state, and consumer collection.
| Case | Year | Data class | Access route | Demonstrated harm |
|---|---|---|---|---|
| Ashley Madison | 2015 | Sexual conduct, billing | Breach and publication | Extortion, resignations, suicides reported |
| Equifax | 2017 | Credit file, national ID | Unpatched web application | Permanent identity exposure; no reissue path |
| Vastaamo | 2020 | Psychotherapy records | Breach and extortion | Direct patient extortion at scale |
| SpyFone | 2021 | Location, messages, photos | Purchased covert install | Partner surveillance; FTC ban |
| Grindr | 2020–21 | Sexuality, precise location | Ad-tech resale | Outing of a named individual |
| Pegasus / El Faro | 2020–21 | Whole device | State spyware, zero-click | Source exposure; press interference |
| Afghan relocation | 2021 | Identity of applicants | Operator error | Named people exposed to reprisal |
| OPM | 2015 | Clearance investigations | State intrusion | Lifelong exposure of associates |
| VTech | 2015 | Children's identities, chats | SQL injection | Children's data in criminal hands |
| 23andMe | 2023 | Genetic and ethnic ancestry | Credential stuffing plus DNA Relatives | Targeted ethnic lists published |
Scroll the table sideways, or focus it and use the arrow keys.
Ashley Madison
The 2015 breach of Avid Life Media published account records for a service whose entire product was discretion. What made it instructive was the second-order market: within weeks the dump was repackaged into searchable sites and extortion letters keyed to individual email addresses. The data class — an account on an infidelity service — was not sensitive under any statutory list. The harm did not require the account to be genuine, only for someone in the subject's life to believe it was.
Equifax
The 2017 compromise of roughly 147 million credit files matters here less for its scale than for its irreversibility. The identifiers exposed were the ones the American system uses as authenticators, and there is no ordinary reissue route for a social security number. The remedy offered was credit monitoring, which detects the harm rather than preventing it, and which places the ongoing cost on the person whose data was taken.
Vastaamo
The Finnish psychotherapy provider Vastaamo held session notes for tens of thousands of patients in a database that had been exposed for years. In late 2020 the attacker demanded ransom from the company and then, when that failed, emailed individual patients demanding payment to keep their therapy notes unpublished. This is the cleanest documented instance of the whole chain: collection that was clinically justified, concentration that was administratively convenient, access through ordinary negligence, and leverage applied directly to the data subject rather than to the controller. The Finnish courts subsequently convicted the perpetrator and the company's chief executive was prosecuted for the data protection failure; the company itself went bankrupt, which is worth stating plainly because it establishes that market discipline arrived far too late to function as a control.
SpyFone
The 2021 United States Federal Trade Commission action against Support King, trading as SpyFone, banned the firm from the surveillance business outright and required it to notify the owners of devices on which its software had been installed. The order is useful evidence because it records the deployment pattern rather than the marketing claim.
Grindr
Two distinct events, a year apart, make the same point about inference. The Norwegian data protection authority fined Grindr for sharing user data with advertising partners without valid consent, on the reasoning that being a user of that app is itself special category data about sexual orientation. Separately, a United States religious publication identified a named priest by purchasing commercially available app location data and correlating it with his home and workplace. No breach occurred in the second case. The data was for sale.
Pegasus against El Faro
Forensic analysis published in 2022 found NSO Group's Pegasus on the phones of more than twenty journalists and staff at the Salvadoran outlet El Faro, with infections clustering around the publication of investigations into the government. The technical detail that matters for this note is the zero-click delivery: the target's operational security choices — which messenger, which links to avoid — were irrelevant to the outcome, so advice framed as user behaviour would not have helped any of them.
Afghan relocation data leak
In September 2021 the United Kingdom Ministry of Defence sent an email to Afghan interpreters eligible for relocation with more than two hundred addresses in the visible field, several with profile photographs and names attached. The mechanism was a mail client default. The subjects were people whose identification by the Taliban was the precise risk the relocation scheme existed to answer.
OPM
The 2015 intrusion into the United States Office of Personnel Management took the SF-86 background investigation files of roughly 21.5 million people. Those forms deliberately record what an adversary would want: foreign contacts, financial problems, substance use, mental health treatment, and the names and addresses of relatives and references who never applied for anything. A clearance file is a dossier the subject was compelled to assemble about themselves and everyone near them.
VTech
The 2015 compromise of the children's tablet maker VTech exposed profiles for several million children, including names, birthdates, genders, and in some cases chat logs and photographs exchanged with parents. It is the clearest case of collection whose subjects could not consent, could not audit, and will still be alive in seventy years.
23andMe
The 2023 credential-stuffing campaign against 23andMe data breach reached about fourteen thousand accounts directly and, through the opt-in DNA Relatives feature, profile data for several million more. The published output was not a generic dump: it was lists filtered to people of Ashkenazi Jewish and Chinese descent. Genetic data also implicates relatives who never used the service and cannot revoke anything, which is the property that distinguishes it from every other record class in this table.
Why lawful extraction is still an ethical question
Every case above involves an access route someone would call improper. The harder case is the lawful one. When a phone is seized under a valid warrant and processed by Cellebrite or an equivalent tool, the extraction is not a breach and no control has failed. It nonetheless produces the same artefact the breaches produced: a single concentrated corpus of one person's messages, photographs, location history, health app records, and the contents of everyone they have ever spoken to.
Three properties of that corpus do the work. It is over-inclusive by construction, because the tool acquires the partition and the filtering happens afterwards. It is asymmetric, because the defence usually receives a report rather than the image. And it is persistent, because retention of the extraction commonly outlives the proceeding. Whether the filtering criteria are disclosed to the defence at all is an open question in Swedish practice, tracked at Are Swedish mobile-extraction filters disclosed at trial?; until it is answered, an Extraction proportionality review has nothing to review against.
Warning Lawfulness is a separate question from proportionality
A lawful warrant answers whether the state may look. It does not answer how much it may take, how long it may keep it, or whether third parties in the address book acquired any standing at all. Do not let this note's citations of breach cases be read as an argument that lawful extraction is equivalent to a criminal intrusion; the claim is narrower, that the resulting concentration has the same properties whatever authorised it.
Objections
“I have nothing to hide.” The claim is usually true and usually irrelevant. It is a statement about the speaker's present circumstances in their present jurisdiction, offered as a statement about a system that will outlive both. It also mistakes the unit of analysis: the person exposed by an address record is often not the person who disclosed it, as the OPM references and the 23andMe relatives show.
“Privacy trades off against security.” Sometimes it does, and those cases should be argued on their specifics. But the framing conceals that most privacy failures here are security failures — unpatched software, absent access control, credential reuse — and that the largest single reduction in breach impact available to any controller is holding less. The trade-off is real at the margin of investigative access; it is largely fictional at the margin of retention.
“Users consented.” Consent to a service is not consent to every downstream inference and resale, and the Grindr cases show the gap. Where the disclosure is a condition of receiving housing, healthcare, or employment, the word is being used for something that is not a choice.
Open checks before this note's status is reconsidered:
- Confirm the Vastaamo extortion figures against the district court judgment rather than press reporting
- Check whether the Norwegian Grindr fine survived appeal and at what amount
- Find a Swedish-language primary source for the skyddad folkbokföring threshold; the current footnote leans on a secondary summary
- Re-read the OPM inspector general report before the 21.5 million figure is cited anywhere else in the vault
Regulatory setting
The GDPR already treats most of the categories above as special: Article 9 covers health, sexual orientation, and genetic and biometric data, and Article 10 handles criminal-offence data on a separate and stricter footing. The Swedish supervisory authority IMY publishes guidance that private actors routinely misread as permitting what it merely declines to prohibit. On the search side, GC and Others C-136/17 establishes that a search engine handling special category data through indexing is not thereby exempt, though it must weigh the public interest in access.
The archived judgment sits at
sources/2019-09-24-gc-and-others-c-136-17.pdf; the Vastaamo
district court decision, in Finnish, at
sources/2023-04-vastaamo-district-court.pdf. Both are cited
from this note's provenance inventory rather than inline, because they
inform the whole argument rather than a single sentence.
Notes
- S. and Marper v. United Kingdom, applications 30562/04 and 30566/04, Grand Chamber judgment of 4 December 2008. Archived at sources/2008-12-04-s-and-marper-v-uk.pdf. ↩
- Threshold and effect of sekretessmarkering and skyddad folkbokföring, summarised from Skatteverket's public guidance; see the open check above, this currently rests on a secondary summary rather than the statute. ↩