Brief note — outside the design

What the design has to do. The reader is not a visitor. They have lived in these 554 notes for months, they hold most of the graph in their head, and they half-remember titles. Their movement is lateral and constant: conclusion to premise, premise to the archived PDF, sideways to a shared tag, back to what cites this. So the design has exactly two jobs, and they pull against each other: a fixed, undisturbed reading column for 5,000 words of dense prose, and near-zero-cost movement out of it and back.

Three central decisions. (1) Search is the navigation. One finder, on / or Ctrl-K, ranking title, alias, tag, heading and full body text, with subsequence matching so scandleg finds "Scandinavian legal realism" and folded diacritics so rattssak finds "Rättssäkerhet". Its result list carries a live preview pane, so confirming you had the right note costs nothing and often ends the trip there. (2) Peek before you leave. Every wikilink and footnote reference reveals the target's type, status and opening sentences on hover or keyboard focus. Most traversals are checks, not departures; this converts them from page loads into glances. (3) A persistent trail in the top bar, so coming back is a click on a name you recognise rather than repeated Back.

Deliberately rejected. An alphabetical index of 554 notes — it is a list nobody can scan and it encodes nothing the reader wants; the finder's empty state offers the trail, the open frontier, and type/tag facets instead. Also rejected: a persistent graph visualisation (pretty, unreadable at 2,303 edges, and it competes with the prose), colour as the primary type signal (every type is a word first), and a two-pane split view (it halves the measure, which the brief ranks above everything).

Uncertain. Whether the right rail earns its width below 1400px, or should always sit under the article. Whether peek popovers irritate a mouse user reading a link-dense paragraph — there is a 180ms delay and no motion, but it needs testing with a real reader. Whether collapsing 66 sources behind a disclosure is honest apparatus or an evasion of the "judge before you trust" job. And the ranking weights are guesses: they have not met the real corpus.

Skip to the note

Case for privacy and security

alsowhy privacy matters · case for privacy

synthesis stable updated 66 sources 36 cited by 49 links out

Privacy is not a claim that a person has something shameful to hide. It is the ability to decide who can learn intimate facts about one's life, relationships, movements, finances, health, politics, and vulnerabilities.

Security is the practical ability to keep those facts, accounts, devices, and services confidential, available, and accurate. Privacy without security leaks. Security without privacy can become a tightly controlled surveillance system.

The two are connected but not interchangeable. Privacy threat modeling should always ask both: who could obtain or alter this information, and who should not have been collecting it in the first place?

The core claim of this synthesis is that privacy limits the conversion of information into Data as coercive power. Across commercial breaches, spyware campaigns, government databases, health systems, dating platforms, and forensic extraction, the recurring pattern is the same: concentrated sensitive data becomes leverage when weak controls, covert access, or exploitative sharing expose it.

Why privacy is a right rather than a preference

Privacy protects autonomy, dignity, intimacy, association, bodily integrity, confidentiality, and the conditions for a self-authored life. People need confidential space to form relationships, deliberate, experiment, change their minds, seek care, and manage the boundaries between family, work, politics, and intimacy.

The preference framing asks what a person is hiding and then evaluates the answer. That makes protection depend on the sympathies of whoever is judging, which means it fails precisely where it is needed: for the person whose lawful life is unpopular, whose immigration status is irregular, whose religion or sexuality is criminalised in a country they may one day transit. A right does not require its holder to justify the exercise, and that is the whole of its practical value. It also does not depend on the holder being sympathetic, which is why the strongest cases for it involve people the reader may not like.

European human rights law reaches the same structure by a different route. In S. and Marper v. United Kingdom the Grand Chamber struck down the indefinite retention of fingerprints, cell samples, and DNA profiles taken from people who had been arrested and then acquitted or never charged. The Court did not weigh how embarrassing the samples were. It objected to the shape of the scheme.

… the blanket and indiscriminate nature of the powers of retention…

S. and Marper v. United Kingdom, Grand Chamber, 4 December 2008, § 1251

The operative distinction is not rhetorical. A preference can be traded away for convenience, and any interface that offers the trade will eventually get a yes from almost everyone; a right sets a floor beneath which the bargain is not on offer at all. This is why Consent theatre is not merely an aesthetic complaint about cookie banners. Where consent is the only mechanism, the protection tracks the design of the dialogue rather than the sensitivity of the data.

Why privacy is a safety issue

The safety argument does not require any general claim that exposure harms everyone equally. It requires only the narrower observation that for an identifiable subset of people, disclosure of a single field converts directly into physical risk. A current address is the canonical case. So is a workplace, a child's school, a daily route, a real name attached to a pseudonym, or the fact that two people are in contact at all.

Sweden makes this concrete in a way most jurisdictions do not. The population register is built on the premise that a person's registered address is ordinarily available, and the protective regimes — sekretessmarkering and the stricter skyddad folkbokföring — are exceptions granted on showing a concrete threat.2 The protection changes who may lawfully obtain the address going forward. It does not reach copies already sold to data brokers, published in a directory, or screenshotted by someone who wishes the person harm.

Danger Address exposure is not reversible

Treat a current address as a one-way field. Protective registration constrains future lawful disclosure; it cannot retract copies already held, and it imposes a permanent administrative cost on the protected person, who must then transact with every counterparty through a proxy address. Design and advice should aim at preventing the first disclosure, not at remediating it.

The same mechanism runs through consumer stalkerware. The commercial pitch is parental oversight; the deployed reality documented in enforcement actions is partner surveillance, and the software's value to the buyer is precisely that the person being tracked does not know. State spyware differs in scale and legality rather than in mechanism: once Pegasus spyware is resident on a phone, the distinction between message content, location, contacts, and the microphone collapses, and so does every assumption the target made when choosing which app to talk in.

Privacy supports equal participation

The cost of exposure is not distributed evenly, and averaging hides that. For most people, a leaked shopping history is an annoyance. For a person seeking an abortion in a hostile jurisdiction, a person whose family does not know they are gay, a witness, a survivor of domestic violence, or an asylum seeker whose home government reads the same database, the identical record is a lever. An argument that privacy costs little because most people are unaffected has selected the wrong denominator: the value of the protection is concentrated in the tail, and the tail is where the harms are.

Participation is the second-order effect. People who expect to be observed answer differently, join differently, and search differently. Self-reported chilling is weak evidence on its own — it is easy to elicit and hard to validate against behaviour — and the honest version of this claim needs the behavioural studies rather than the survey ones, which is what Chilling effects in survey research is wanted for. What is not in doubt is the asymmetry of remedy. A wrong charge on a card is reversed; an inference drawn about someone's health or politics enters systems with no Correction channel at all, and it is acted on by parties the subject cannot identify.

Privacy is market infrastructure

Confidentiality is not an add-on to commerce; it is a precondition for most of it. Salary negotiation, corporate acquisition, legal advice, medical consultation, and journalism all depend on a party's ability to keep information from a counterparty until it chooses to disclose. A market with perfect visibility into every participant's reservation price is not a more efficient market. It is a market with one price-setter.

The reason firms nevertheless under-invest is an ordinary externality. The expected cost a controller reasons about is roughly E=pL, the probability of a breach times the loss it bears — regulatory fine, remediation, churn. But the loss the incident actually produces is distributed across the data subjects, who were not party to the decision:

Lsocial= Lfirm+ i=1n hi

where hi is the harm to subject i and n is the number of records. Because the second term is invisible on the controller's balance sheet, retention looks free and deletion looks like forgone option value. Data minimisation is the intervention that survives this analysis, because it is the only one that reduces n rather than betting on a lower p. Every control that instead assumes competent operation is a bet that the operator stays competent for the entire retention period, which for a genome or a national identity number is the subject's lifetime.

A map from data to harm

The case studies below differ in sector, jurisdiction, and decade, and they run through the same five stages. Stating the stages separately makes it possible to ask which one a proposed control actually touches, and most proposed controls touch the third.

Figure 1 — data to harm
Collection Concentration Access Linkage Leverage Harm forms, sensors, purchase, inference breach lawful demand insider purchase from broker re-identification cross-dataset joins extortion targeting exclusion violence Minimisation acts here — on stages one and two. Access controls, encryption, and audit act on stage three only.
Stage three is where nearly all security engineering lives, and it is the only stage an attacker gets to choose. Controls that reduce what exists at stages one and two are the ones that survive an operator's later incompetence. Related: Data as coercive power, Privacy threat modeling, Re-identification risk.

Case studies

These ten are not a survey. They were selected because each one closes a different link in the chain above with documented evidence rather than inference, and because between them they cover commercial, clinical, state, and consumer collection.

Ten incidents by data class, access route, and the harm actually demonstrated rather than the harm feared.
CaseYear Data classAccess route Demonstrated harm
Ashley Madison2015Sexual conduct, billingBreach and publicationExtortion, resignations, suicides reported
Equifax2017Credit file, national IDUnpatched web applicationPermanent identity exposure; no reissue path
Vastaamo2020Psychotherapy recordsBreach and extortionDirect patient extortion at scale
SpyFone2021Location, messages, photosPurchased covert installPartner surveillance; FTC ban
Grindr2020–21Sexuality, precise locationAd-tech resaleOuting of a named individual
Pegasus / El Faro2020–21Whole deviceState spyware, zero-clickSource exposure; press interference
Afghan relocation2021Identity of applicantsOperator errorNamed people exposed to reprisal
OPM2015Clearance investigationsState intrusionLifelong exposure of associates
VTech2015Children's identities, chatsSQL injectionChildren's data in criminal hands
23andMe2023Genetic and ethnic ancestryCredential stuffing plus DNA RelativesTargeted ethnic lists published

Scroll the table sideways, or focus it and use the arrow keys.

Ashley Madison

The 2015 breach of Avid Life Media published account records for a service whose entire product was discretion. What made it instructive was the second-order market: within weeks the dump was repackaged into searchable sites and extortion letters keyed to individual email addresses. The data class — an account on an infidelity service — was not sensitive under any statutory list. The harm did not require the account to be genuine, only for someone in the subject's life to believe it was.

Equifax

The 2017 compromise of roughly 147 million credit files matters here less for its scale than for its irreversibility. The identifiers exposed were the ones the American system uses as authenticators, and there is no ordinary reissue route for a social security number. The remedy offered was credit monitoring, which detects the harm rather than preventing it, and which places the ongoing cost on the person whose data was taken.

Vastaamo

The Finnish psychotherapy provider Vastaamo held session notes for tens of thousands of patients in a database that had been exposed for years. In late 2020 the attacker demanded ransom from the company and then, when that failed, emailed individual patients demanding payment to keep their therapy notes unpublished. This is the cleanest documented instance of the whole chain: collection that was clinically justified, concentration that was administratively convenient, access through ordinary negligence, and leverage applied directly to the data subject rather than to the controller. The Finnish courts subsequently convicted the perpetrator and the company's chief executive was prosecuted for the data protection failure; the company itself went bankrupt, which is worth stating plainly because it establishes that market discipline arrived far too late to function as a control.

SpyFone

The 2021 United States Federal Trade Commission action against Support King, trading as SpyFone, banned the firm from the surveillance business outright and required it to notify the owners of devices on which its software had been installed. The order is useful evidence because it records the deployment pattern rather than the marketing claim.

Grindr

Two distinct events, a year apart, make the same point about inference. The Norwegian data protection authority fined Grindr for sharing user data with advertising partners without valid consent, on the reasoning that being a user of that app is itself special category data about sexual orientation. Separately, a United States religious publication identified a named priest by purchasing commercially available app location data and correlating it with his home and workplace. No breach occurred in the second case. The data was for sale.

Pegasus against El Faro

Forensic analysis published in 2022 found NSO Group's Pegasus on the phones of more than twenty journalists and staff at the Salvadoran outlet El Faro, with infections clustering around the publication of investigations into the government. The technical detail that matters for this note is the zero-click delivery: the target's operational security choices — which messenger, which links to avoid — were irrelevant to the outcome, so advice framed as user behaviour would not have helped any of them.

Afghan relocation data leak

In September 2021 the United Kingdom Ministry of Defence sent an email to Afghan interpreters eligible for relocation with more than two hundred addresses in the visible field, several with profile photographs and names attached. The mechanism was a mail client default. The subjects were people whose identification by the Taliban was the precise risk the relocation scheme existed to answer.

OPM

The 2015 intrusion into the United States Office of Personnel Management took the SF-86 background investigation files of roughly 21.5 million people. Those forms deliberately record what an adversary would want: foreign contacts, financial problems, substance use, mental health treatment, and the names and addresses of relatives and references who never applied for anything. A clearance file is a dossier the subject was compelled to assemble about themselves and everyone near them.

VTech

The 2015 compromise of the children's tablet maker VTech exposed profiles for several million children, including names, birthdates, genders, and in some cases chat logs and photographs exchanged with parents. It is the clearest case of collection whose subjects could not consent, could not audit, and will still be alive in seventy years.

23andMe

The 2023 credential-stuffing campaign against 23andMe data breach reached about fourteen thousand accounts directly and, through the opt-in DNA Relatives feature, profile data for several million more. The published output was not a generic dump: it was lists filtered to people of Ashkenazi Jewish and Chinese descent. Genetic data also implicates relatives who never used the service and cannot revoke anything, which is the property that distinguishes it from every other record class in this table.

Why lawful extraction is still an ethical question

Every case above involves an access route someone would call improper. The harder case is the lawful one. When a phone is seized under a valid warrant and processed by Cellebrite or an equivalent tool, the extraction is not a breach and no control has failed. It nonetheless produces the same artefact the breaches produced: a single concentrated corpus of one person's messages, photographs, location history, health app records, and the contents of everyone they have ever spoken to.

Three properties of that corpus do the work. It is over-inclusive by construction, because the tool acquires the partition and the filtering happens afterwards. It is asymmetric, because the defence usually receives a report rather than the image. And it is persistent, because retention of the extraction commonly outlives the proceeding. Whether the filtering criteria are disclosed to the defence at all is an open question in Swedish practice, tracked at Are Swedish mobile-extraction filters disclosed at trial?; until it is answered, an Extraction proportionality review has nothing to review against.

Warning Lawfulness is a separate question from proportionality

A lawful warrant answers whether the state may look. It does not answer how much it may take, how long it may keep it, or whether third parties in the address book acquired any standing at all. Do not let this note's citations of breach cases be read as an argument that lawful extraction is equivalent to a criminal intrusion; the claim is narrower, that the resulting concentration has the same properties whatever authorised it.

Objections

“I have nothing to hide.” The claim is usually true and usually irrelevant. It is a statement about the speaker's present circumstances in their present jurisdiction, offered as a statement about a system that will outlive both. It also mistakes the unit of analysis: the person exposed by an address record is often not the person who disclosed it, as the OPM references and the 23andMe relatives show.

“Privacy trades off against security.” Sometimes it does, and those cases should be argued on their specifics. But the framing conceals that most privacy failures here are security failures — unpatched software, absent access control, credential reuse — and that the largest single reduction in breach impact available to any controller is holding less. The trade-off is real at the margin of investigative access; it is largely fictional at the margin of retention.

“Users consented.” Consent to a service is not consent to every downstream inference and resale, and the Grindr cases show the gap. Where the disclosure is a condition of receiving housing, healthcare, or employment, the word is being used for something that is not a choice.

Open checks before this note's status is reconsidered:

  • Confirm the Vastaamo extortion figures against the district court judgment rather than press reporting
  • Check whether the Norwegian Grindr fine survived appeal and at what amount
  • Find a Swedish-language primary source for the skyddad folkbokföring threshold; the current footnote leans on a secondary summary
  • Re-read the OPM inspector general report before the 21.5 million figure is cited anywhere else in the vault

Regulatory setting

The GDPR already treats most of the categories above as special: Article 9 covers health, sexual orientation, and genetic and biometric data, and Article 10 handles criminal-offence data on a separate and stricter footing. The Swedish supervisory authority IMY publishes guidance that private actors routinely misread as permitting what it merely declines to prohibit. On the search side, GC and Others C-136/17 establishes that a search engine handling special category data through indexing is not thereby exempt, though it must weigh the public interest in access.

The archived judgment sits at sources/2019-09-24-gc-and-others-c-136-17.pdf; the Vastaamo district court decision, in Finnish, at sources/2023-04-vastaamo-district-court.pdf. Both are cited from this note's provenance inventory rather than inline, because they inform the whole argument rather than a single sentence.

Notes

  1. S. and Marper v. United Kingdom, applications 30562/04 and 30566/04, Grand Chamber judgment of 4 December 2008. Archived at sources/2008-12-04-s-and-marper-v-uk.pdf.
  2. Threshold and effect of sekretessmarkering and skyddad folkbokföring, summarised from Skatteverket's public guidance; see the open check above, this currently rests on a secondary summary rather than the statute.

SPECIMEN 1 — search result list (static rendering of the finder's list for the query priv; press / for the live one)

  • Case for privacy and security synthesis stable 36 cited by title · alias “why privacy matters”
  • Privacy threat modeling concept stable 21 cited by title
  • Apple Private Cloud Compute entity stable title · heading “What the privacy claim actually is”
  • Data as coercive power concept stable body — “…the conversion of private fact into leverage does not require the holder to…”
  • Are Swedish mobile-extraction filters disclosed at trial? question working tag privacy · body

Why the match is shown. With full text client-side, a query hits titles, aliases, tags, headings and prose. Naming which one matched is what stops a body-text hit from looking like a mis-ranked title hit.

Order. Title and alias, then tag, then heading, then body, with a small nudge from inbound link count so the hub you probably meant outranks the note that mentions it once.

Never alphabetical. 554 titles in A–Z order is a list that answers no question anyone asks. The finder's empty state offers the trail, the open frontier, and facets instead.

SPECIMEN 2 — tag page, #privacy (240 notes)

#privacy

240 notes · the vault's largest tag. Grouped by type, because at this size the type is the only cut that makes the list navigable. Within a group, most recently edited first.

Co-occurring tags — the practical way to cut 240 down. Counts are the intersection, not the tag's own size.

security 58 Sweden 51 surveillance 24 law 22 children 19 EU 17 digital-forensics 14 AI 11 VPN 9

SPECIMEN 3 — a 90-word source note, entire. The apparatus must not outweigh the note.

ASA statement on p-values

source stable updated no review scheduled

The ASA issued this statement in 2016 to address widespread misuse of statistical significance and p-values. The local PDF is the association's official release. The statement defines a p-value in relation to a specified statistical model. It says a p-value does not measure the probability that the studied hypothesis is true, the probability that chance alone produced the data, the size or importance of an effect, or the strength of evidence by itself. The statement supports the comparison in Probabilistic interpretations of beyond reasonable doubt.

Provenance — 2 entries, listed inline rather than collapsed. A disclosure widget over two items is friction for nothing.

Tags statistics 18 scientific-method 12 evidence 31

Cited by 4 · Probabilistic interpretations of beyond reasonable doubt, False accusations as an epistemic risk, Operationalizing content moderation accuracy in the DSA, Evidence standards

On a note this short the outline rail is absent (there are no headings to outline) and the connections fold into a single block under the prose. The header strip is the only apparatus that always appears, because judging the note is the one job that does not scale with its length.

SPECIMEN 4 — a question note: the research frontier as first-class content

Are Swedish mobile-extraction filters disclosed at trial?

question working updated review 2026-12-01 7 sources 5 cited by

When Swedish police extract a phone with Cellebrite or an equivalent tool, the acquisition is broad and the material presented in the case file is a filtered subset. The question is whether the filtering criteria — keywords, date ranges, applications, contact selectors — reach the defence at all, and whether a court has ever ruled on a demand for them.

Question What would settle this

A published judgment, or a documented refusal, in which a defence request for the extraction parameters was granted or denied. Failing that: a Cellebrite Physical Analyzer report template showing whether the filter set is recorded in the exported artefact at all. A practitioner's account is weaker but would establish the baseline practice.

What is already known. The tooling records the selectors used; that is a property of the report format rather than a legal requirement. Swedish pre-trial disclosure runs on förundersökningsprotokollet, which contains what the investigation deems relevant, with the surrounding material available on request under the principle of partsinsyn. Whether extraction parameters count as material or as method is the hinge, and the vault has found no case addressing it.

  • Search the appellate database for bevisning combined with tömning av mobiltelefon
  • Ask a defence practitioner whether the parameter set has ever been produced
  • Confirm the tool records the selectors (it does; see the Physical Analyzer manual)

Blocked on the same evidence: Extraction proportionality review.

Wanted page — where a redlink lands

Extraction proportionality review+

No note yet. This subject is wanted, not broken: three notes already argue from it, which is the evidence that it should exist.

Linked from Case for privacy and security, Are Swedish mobile-extraction filters disclosed at trial?, Rättssäkerhet in Swedish criminal cases

SPECIMEN 5 — a working note. Status is not a badge; the gap is written out.

UK Online Safety Act

entity working updated 14 sources

Known gap The note describes the duties as enacted and the first two Ofcom codes. It does not yet cover the age-assurance guidance that took effect in July 2026, and the section on categorised services still assumes the draft thresholds. Do not cite this note for what a service must do today; cite it for what the Act requires.

The Act imposes duties of care on user-to-user services and search services with links to the United Kingdom, enforced by Ofcom through codes of practice rather than by direct statutory specification. The design of the enforcement matters more than the drafting: the codes are where the obligations become concrete, and they are amendable without returning to Parliament.

The freshness field above reads overdue, computed against today's date from review_after. A note can be stable and overdue at once, so the two are rendered as separate facts rather than merged into a single health indicator.