Brief note — outside the design

What the design must do. Prose is the product. The apparatus exists to tell a reader, before they invest in 5,000 words, what kind of thing this is and how much weight it will bear, then get out of the way. Nine types, four statuses, a separate freshness schedule, a 0–66-entry provenance inventory and claim-level footnotes all have to be legible without producing a compliance dashboard.

Three central decisions

  1. Apparatus scales inversely with warranty. A stable, in-date note carries one line of metadata under the title and nothing else. A working note's known gap is not a badge: it is a block in the prose measure, in the prose voice, above the argument it qualifies, because a reader who does not see the gap before reading may cite the note. stale uses the same block with heavier rules. 432 of 554 notes are stable, so the common page is nearly bare and the 119 working notes earn their interruption.
  2. A grammar of line, not of colour. Solid means written, resolved, asserted. Dashed means open, wanted, overdue. A doubled hairline means someone else's voice. So question notes, redlinks and an overdue review share one dashed vocabulary; source notes share the doubled rule with block quotes. The file is monochrome by construction.
  3. Type is a sentence, not a badge. Every note head reads SYNTHESIS — a conclusion this vault asserts. The gloss is the legend, printed where it is needed. A five-group stance mark repeats in every list, so a result set reads as "three claims, eleven pieces of evidence, one open gap" before any title is read.

Argument shape

A hairline in the outer gutter marks each paragraph carrying a claim-level citation. Scanning the margin of a long note shows which passages rest on evidence and which are the vault's own connective reasoning.

Rejected

Colour-coded type chips (fail greyscale; nine colours are unlearnable). Tufte sidenotes — 124 notes have footnotes, and full citations set beside the prose would outweigh it. A metadata panel above the title. Any icon restating a word already on the page.

Uncertain

Whether the gutter hairline reads as "cited" without its one line of explanation at the notes section. Whether five stance marks are four too many and the type word alone would do. Whether a 66-entry provenance inventory belongs at the foot or one click away.

the vault · 554 notes

Synthesisa conclusion this vault asserts, argued from its sources

Case for privacy and security

also called: why privacy matters · case for privacy

Stable — checked at its stated scope Updated 19 July 2026 Review due 13 January 2027 Built on 66 sources

Privacy is not a claim that a person has something shameful to hide. It is the ability to decide who can learn intimate facts about one’s life, relationships, movements, finances, health, politics, and vulnerabilities.

Security is the practical ability to keep those facts, accounts, devices, and services confidential, available, and accurate. Privacy without security leaks. Security without privacy can become a tightly controlled surveillance system.

The two are connected but not interchangeable. Privacy threat modeling should always ask both: who could obtain or alter this information, and who should not have been collecting it in the first place?

The core claim of this synthesis is that privacy limits the conversion of information into Data as coercive power. Across commercial breaches, spyware campaigns, government databases, health systems, dating platforms, and forensic extraction, the recurring pattern is the same: concentrated sensitive data becomes leverage when weak controls, covert access, or exploitative sharing expose it.

Why privacy is a right rather than a preference

Privacy protects autonomy, dignity, intimacy, association, bodily integrity, confidentiality, and the conditions for a self-authored life. People need confidential space to form relationships, deliberate, experiment, change their minds, seek care, and manage the boundaries between family, work, politics, and intimacy.

Treating privacy as a preference misdescribes what is at stake. A preference can be traded for convenience by the person who holds it. The ability to seek treatment, leave a marriage, or change one’s politics without an audience cannot be traded away in advance, because the person consenting does not know who will hold the record or what will be done with it a decade later. The asymmetry is structural: disclosure is instantaneous and effectively permanent, while the harm arrives later, from a party the discloser never dealt with, under rules that did not exist at the moment of collection.

This is why Data minimization is a stronger protection than consent. Consent allocates the decision to the moment of collection, which is the moment at which the person knows least about the eventual use. Minimization removes the material a later actor would need. The two are not alternatives — a system can do both — but they fail differently, and only one of them fails safe.

warningLawful collection does not bound the eventual reach

A lawful basis governs who may collect a dataset and for what stated purpose. It does not govern what a later breach, subpoena, corporate acquisition, or change of policy makes of the resulting corpus. Assess the corpus that now exists, not the authorisation that created it.

Why privacy is a safety issue

The clearest evidence that privacy is a safety property rather than an etiquette rule comes from cases where a disclosure produced a physical, measurable consequence. In the 2020 breach of the Finnish psychotherapy provider Vastaamo, an attacker obtained patient records including session notes and then extorted individual patients directly, demanding payment to keep their therapy notes unpublished.1 The mechanism required no further access: the credible threat that the notes could be sent to an employer, a spouse, or a public forum was itself the leverage.

The Vastaamo pattern generalises. Where a dataset describes something a person has arranged their life to keep separate — a diagnosis, a sexual history, an immigration status, an address withheld from a former partner — the leverage is created by the separation itself and not by any wrongdoing. This is where the “nothing to hide” argument fails as an argument rather than as a sentiment: it assumes the only reason to withhold information is culpability, and the case record shows the opposite. The people most exposed by a health-records breach are the ones who sought care.

The 2015 compromise of the United States Office of Personnel Management is the same shape at state scale. The stolen material was not payment data but background-investigation files: the interviews, foreign contacts, financial difficulties and personal histories of roughly 21.5 million people who had applied for a security clearance, together with millions of fingerprint records.2 A background investigation is, by construction, an inventory of exactly what would compromise a person. Concentrating those inventories in one system created a target whose value was proportional to the candour of the people who filled them in.

Privacy supports equal participation

Exposure is not distributed evenly, and this is the part of the argument most often left out. The cost of a leaked address is different for a person with a protected identity than for a person without one; the cost of a leaked sexual history is different where the conduct is criminalised; the cost of a leaked immigration status is different for someone whose right to remain is under review. A privacy regime evaluated only against the median user will look adequate while failing precisely the people for whom it was load-bearing.

The practical consequence is that a system’s privacy properties should be assessed against its most exposed plausible user rather than its typical one, in the same way that a structural load is assessed against a worst case rather than an average. That is a design rule, not a moral appeal, and it is testable: name the exposed population, name what the system reveals about them, and name who can obtain it.

Privacy is market infrastructure

Confidentiality is also an ordinary commercial input. Negotiating positions, salary data, supplier terms, unannounced products, litigation strategy and merger interest all depend on controlling who learns what and when. A firm that cannot keep these confidential does not merely suffer embarrassment; it loses the ability to transact on equal terms. Framing privacy purely as a consumer-protection question therefore understates the constituency that depends on it, and understates what is lost when confidentiality is weakened by default for everyone in order to reach a subset of criminal conduct.

A map from data to harm

The case record across the sources below is not a list of unrelated failures. It follows a repeatable sequence: data is collected for a stated purpose, concentrated in one system, exposed through breach or covert access or onward sharing, and then converted into leverage over the person it describes. The table below sets out the conversion mechanism for the classes of data that recur most often.

Data classes and the mechanism by which each is converted into leverage. Worked examples are drawn from the case studies below.
Data classWho seeks itConversion mechanismWorked example
Identity and contactFraud operatorsCredential stuffing, account takeover, impersonation23andMe, 2023
Location historyStalkers, employers, statesPattern-of-life reconstruction; presence at a place at a timeSpyFone, 2019
Health and therapy recordsExtortionistsThreat of disclosure to family, employer, or the publicVastaamo, 2020
Sexual and relationship dataExtortionists, hostile publicsExposure into a community that sanctions the conductAshley Madison, 2015
Security-clearance dossiersForeign intelligence servicesTargeting, recruitment, and coercion of named individualsOPM, 2015
Whole device contentsPolice, spyware operatorsFull-corpus extraction beyond the scope of the inquiryCellebrite; Pegasus

Two things follow. First, the mechanism is the same whether the actor is criminal, commercial or governmental; only the authorisation differs, and authorisation is not a technical control. Second, the point of intervention is concentration rather than exposure. Every case in the table would have been survivable at a smaller scale of aggregation, and none of them were prevented by the fact that the original collection was lawful.

From collection to coercion A left-to-right chain: collection, concentration, access failure, leverage, harm. Access failure branches into breach, covert access, and onward sharing. Collection Concentration Access failure Leverage Harm breach covert access onward sharing
The recurring sequence. Only the middle stage varies between a criminal breach, a spyware campaign, and a lawful data-sharing arrangement; the stages either side are identical. Rendered client-side from a Mermaid fence in the note source.

Case studies

Ten cases are held as separate event notes and summarised here only far enough to show the mechanism. Four are given below; Equifax, SpyFone, Grindr, Pegasus against El Faro, the Afghan relocation data leak, and VTech follow the same structure in the full note.

Ashley Madison, 2015

Account records from a dating service marketed for extramarital affairs were published in full, including email addresses, partial payment details and self-descriptions. The harm did not depend on the accuracy of the records: an address appearing in the dump was damaging whether or not the account had ever been used. This is the clearest available demonstration that exposure operates on inference rather than on fact.

Vastaamo, 2020

Psychotherapy records, including session notes, were taken from a Finnish provider and used to extort patients individually. It is the case most often cited in this vault because it collapses the distance between a database and a person: the material and the victim were the same thing.

OPM, 2015

Background-investigation files on 21.5 million clearance applicants and their referees were exfiltrated. The dataset was assembled by a government for a legitimate purpose under law, which is why it is the strongest counterexample to the argument that lawful collection is a sufficient safeguard.

23andMe, 2023

Credential stuffing against reused passwords gave access to profiles, and a relative-matching feature propagated the exposure outward to accounts that were never themselves compromised. Genetic data is the extreme case of a class this vault tracks generally: data about one person that is simultaneously data about people who never consented.

Why lawful extraction is still an ethical question

Mobile forensic extraction by police is lawful in most of the jurisdictions this vault covers, and the products that perform it are sold openly. Cellebrite and comparable tools recover a device’s full contents, including deleted material and material belonging to third parties who are not suspects and have no notice. The legal question — whether the seizure was authorised — and the proportionality question — whether the whole corpus was necessary to the inquiry — are separate, and only the first is routinely answered.

The unresolved part is procedural rather than technical. Where a tool applies a selective filter, the filter’s configuration determines what the court never sees, and it is not obvious that it is disclosed: that question is open as Are Swedish mobile-extraction filters disclosed at trial?. The related matter of what a device owner is told when a third party’s device is extracted is not yet written up as Forensic extraction consent in Sweden.

Objections

The strongest objection to the position argued here is that it treats confidentiality as close to absolute while real systems require lawful access for investigating serious crime. That objection is correct about the requirement and wrong about the inference: the vault’s position is not that access should be impossible, but that access mechanisms built for everyone are evaluated as if they were built for the target. The relevant comparison is not access against no access; it is targeted access against a standing capability, which has a different failure distribution.

A second objection is that the case studies over-select for catastrophe. This has force. The cases below are drawn from breaches large enough to be investigated and published, which excludes the routine disclosures that never surface. The direction of that bias is worth being explicit about: it inflates the visible severity of individual events and deflates the visible frequency of ordinary ones.

Personal data which are, by their nature, particularly sensitive in relation to fundamental rights and freedoms merit specific protection as the context of their processing could create significant risks to the fundamental rights and freedoms.

General Data Protection Regulation, recital 51

Regulatory setting

European law already encodes most of the distinction argued above. Article 9 of the GDPR treats health, sex life, political opinion and biometric data as a special category requiring a separate lawful basis, which is a legal recognition that some data classes convert into leverage more readily than others. Article 10 handles criminal-offence data separately again. What the regime does not do is constrain concentration as such: a controller with a valid basis under Article 9 may still assemble the corpus whose existence is the risk. The code path that matters in practice is not lawfulBasis() but retention, and retention is where enforcement is thinnest.

  • Confirm the Article 9 and Article 10 treatment against current IMY guidance (done at the July 2026 pass).
  • Re-check the retention-enforcement claim before the January 2027 review; it rests on a 2024 enforcement survey.
  • Decide whether the ten case studies should move to their own event notes and leave summaries here.

Notes

Claim-level citations. A hairline in the outer margin above marks each paragraph that carries one.

  1. Vastaamo breach and patient extortion — case summary and court reporting, archived sources/2026-02-11-vastaamo-case-summary.pdf.
  2. Committee on Oversight and Government Reform, report on the OPM data breach (2016), archived sources/2016-09-opm-oversight-report.pdf. Figures for affected individuals are the report’s own.
  3. Access Now and Citizen Lab, joint forensic report on Pegasus infections of El Faro journalists (2022), archived sources/2022-01-el-faro-forensic-report.pdf.

Built on

66 entries in the note’s provenance inventory — 41 archived on disk, 25 external. This says what informed the note as a whole; the notes above say what supports a particular sentence.

Show all 66 entries

Connections

14 notes cite this one. Six of them are claims, which is what makes this note load-bearing rather than merely linked.

Links out — 31

Wanted from this page — 3

Tags

Specimen — search results (the live field above renders this)

Specimen — question note (the frontier)

Questiona gap this vault admits, and wants closed

Are Swedish mobile-extraction filters disclosed at trial?

Open — nothing here is settled Updated 22 July 2026 Built on 4 sources

When Swedish police extract a seized phone, the tool can be configured to acquire a subset of the device rather than its full contents. The question is whether that configuration — which determines what the defence and the court never see — is recorded and entered into evidence, or whether it remains an operational detail internal to the forensic unit.

Why it matters

A selective filter is a form of pre-trial evidence selection performed by a party to the proceedings. If it is not disclosed, the defence cannot establish what was excluded, and Free evaluation of evidence in Sweden operates on a corpus whose boundaries were set by the prosecution side. The vault has a stake in this because two synthesis notes currently assume, without a source, that extraction is all-or-nothing.

What is already known

Vendor documentation confirms that selective profiles exist and are set before acquisition. Nothing in the material held here shows whether the resulting configuration is included in the forensic report served on the defence. One archived judgment mentions an extraction report without describing its scope, which is consistent with either answer.

questionThe proxy problem

Public prosecution statistics count extractions performed, not extractions whose scope was contested. A count of appeals raising the point would be a discovery measure, not a base rate: if the filter is undisclosed, no one is positioned to appeal it. Any answer built on P(appeal) measures visibility, not incidence.

What would settle it

  • Obtain a redacted forensic report from a concluded case and check whether the acquisition profile is stated.
  • Request the Polismyndigheten internal instruction on extraction scope under offentlighetsprincipen.
  • Confirm from vendor documentation that selective profiles exist. Done; archived.

Either outcome is publishable. A confirmed non-disclosure becomes a concept note on scope disclosure in forensic evidence; a confirmed disclosure practice closes the assumption in the two notes that depend on it. A finding that the answer cannot be reached from evidence this vault can obtain is also a result, and would leave this page a question and promote it to stable.

Specimen — working note with a known gap, and an overdue review

Concepta building block this vault defines, and argues from

Age assurance

Working — usable, with the gap stated below Updated 3 April 2026 Review overdue since 1 May 2026 Built on 19 sources

Age assurance is the family of techniques by which a service forms a belief about a user’s age. It spans self-declaration, document verification, payment-instrument inference, device-level attestation, and facial age estimation, and the term is used loosely in policy documents to cover all of them despite very different error profiles and very different data footprints.

The distinction that matters for Data minimization is whether the method requires the service to learn an identity in order to learn an age. Document verification does; a zero-knowledge attestation issued by a separate party does not. Policy instruments such as the UK Online Safety Act generally specify an outcome rather than a method, which leaves the data footprint to the deployer.

Error profiles

Facial age estimation returns a distribution rather than a value, so a deployment must choose a threshold, and the choice trades false exclusion of adults against false admission of minors. The operational consequence is not symmetric: an adult wrongly excluded complains, and a minor wrongly admitted does not, so the observed error signal is one-sided by construction. This is the same measurement problem described in Are Swedish mobile-extraction filters disclosed at trial? and in One-sided error visibility.

Specimen — source note, entire (some notes are 90 words)

Sourceevidence someone else produced, held here immutably

The ASA Statement on p-Values

Context, Process, and Purpose

Stable — describes its artifact accurately Updated 8 March 2026

The ASA issued this statement in 2016 to address widespread misuse of statistical significance and p-values. The local PDF is the association’s official release. The statement defines a p-value in relation to a specified statistical model. It says a p-value does not measure the probability that the studied hypothesis is true, the probability that chance alone produced the data, the size or importance of an effect, or the strength of evidence by itself. The statement supports the comparison in Probabilistic interpretations of beyond reasonable doubt.

Specimen — tag page, grouped by stance rather than alphabetically

Tagevery note carrying this tag

privacy

240 notes — 43% of the vault 18 open questions 31 overdue for review

At 240 notes an alphabetical list is unusable. Grouping by stance answers the question a reader actually arrives with: what does this vault claim about privacy, and what is it standing on?

Claims — 26 syntheses
Building blocks — 71 concepts and entities
Open gaps — 18 questions
Evidence — 125 source cards

Co-occurring tags