Synthesisa conclusion this vault asserts, argued from its sources
Case for privacy and security
also called: why privacy matters · case for privacy
Stable — checked at its stated scope Updated 19 July 2026 Review due 13 January 2027 Built on 66 sources
Privacy is not a claim that a person has something shameful to hide. It is the ability to decide who can learn intimate facts about one’s life, relationships, movements, finances, health, politics, and vulnerabilities.
Security is the practical ability to keep those facts, accounts, devices, and services confidential, available, and accurate. Privacy without security leaks. Security without privacy can become a tightly controlled surveillance system.
The two are connected but not interchangeable. Privacy threat modeling should always ask both: who could obtain or alter this information, and who should not have been collecting it in the first place?
The core claim of this synthesis is that privacy limits the conversion of information into Data as coercive power. Across commercial breaches, spyware campaigns, government databases, health systems, dating platforms, and forensic extraction, the recurring pattern is the same: concentrated sensitive data becomes leverage when weak controls, covert access, or exploitative sharing expose it.
Why privacy is a right rather than a preference
Privacy protects autonomy, dignity, intimacy, association, bodily integrity, confidentiality, and the conditions for a self-authored life. People need confidential space to form relationships, deliberate, experiment, change their minds, seek care, and manage the boundaries between family, work, politics, and intimacy.
Treating privacy as a preference misdescribes what is at stake. A preference can be traded for convenience by the person who holds it. The ability to seek treatment, leave a marriage, or change one’s politics without an audience cannot be traded away in advance, because the person consenting does not know who will hold the record or what will be done with it a decade later. The asymmetry is structural: disclosure is instantaneous and effectively permanent, while the harm arrives later, from a party the discloser never dealt with, under rules that did not exist at the moment of collection.
This is why Data minimization is a stronger protection than consent. Consent allocates the decision to the moment of collection, which is the moment at which the person knows least about the eventual use. Minimization removes the material a later actor would need. The two are not alternatives — a system can do both — but they fail differently, and only one of them fails safe.
A lawful basis governs who may collect a dataset and for what stated purpose. It does not govern what a later breach, subpoena, corporate acquisition, or change of policy makes of the resulting corpus. Assess the corpus that now exists, not the authorisation that created it.
Why privacy is a safety issue
The clearest evidence that privacy is a safety property rather than an etiquette rule comes from cases where a disclosure produced a physical, measurable consequence. In the 2020 breach of the Finnish psychotherapy provider Vastaamo, an attacker obtained patient records including session notes and then extorted individual patients directly, demanding payment to keep their therapy notes unpublished.1 The mechanism required no further access: the credible threat that the notes could be sent to an employer, a spouse, or a public forum was itself the leverage.
The Vastaamo pattern generalises. Where a dataset describes something a person has arranged their life to keep separate — a diagnosis, a sexual history, an immigration status, an address withheld from a former partner — the leverage is created by the separation itself and not by any wrongdoing. This is where the “nothing to hide” argument fails as an argument rather than as a sentiment: it assumes the only reason to withhold information is culpability, and the case record shows the opposite. The people most exposed by a health-records breach are the ones who sought care.
The 2015 compromise of the United States Office of Personnel Management is the same shape at state scale. The stolen material was not payment data but background-investigation files: the interviews, foreign contacts, financial difficulties and personal histories of roughly 21.5 million people who had applied for a security clearance, together with millions of fingerprint records.2 A background investigation is, by construction, an inventory of exactly what would compromise a person. Concentrating those inventories in one system created a target whose value was proportional to the candour of the people who filled them in.
Privacy supports equal participation
Exposure is not distributed evenly, and this is the part of the argument most often left out. The cost of a leaked address is different for a person with a protected identity than for a person without one; the cost of a leaked sexual history is different where the conduct is criminalised; the cost of a leaked immigration status is different for someone whose right to remain is under review. A privacy regime evaluated only against the median user will look adequate while failing precisely the people for whom it was load-bearing.
The practical consequence is that a system’s privacy properties should be assessed against its most exposed plausible user rather than its typical one, in the same way that a structural load is assessed against a worst case rather than an average. That is a design rule, not a moral appeal, and it is testable: name the exposed population, name what the system reveals about them, and name who can obtain it.
Privacy is market infrastructure
Confidentiality is also an ordinary commercial input. Negotiating positions, salary data, supplier terms, unannounced products, litigation strategy and merger interest all depend on controlling who learns what and when. A firm that cannot keep these confidential does not merely suffer embarrassment; it loses the ability to transact on equal terms. Framing privacy purely as a consumer-protection question therefore understates the constituency that depends on it, and understates what is lost when confidentiality is weakened by default for everyone in order to reach a subset of criminal conduct.
A map from data to harm
The case record across the sources below is not a list of unrelated failures. It follows a repeatable sequence: data is collected for a stated purpose, concentrated in one system, exposed through breach or covert access or onward sharing, and then converted into leverage over the person it describes. The table below sets out the conversion mechanism for the classes of data that recur most often.
| Data class | Who seeks it | Conversion mechanism | Worked example |
|---|---|---|---|
| Identity and contact | Fraud operators | Credential stuffing, account takeover, impersonation | 23andMe, 2023 |
| Location history | Stalkers, employers, states | Pattern-of-life reconstruction; presence at a place at a time | SpyFone, 2019 |
| Health and therapy records | Extortionists | Threat of disclosure to family, employer, or the public | Vastaamo, 2020 |
| Sexual and relationship data | Extortionists, hostile publics | Exposure into a community that sanctions the conduct | Ashley Madison, 2015 |
| Security-clearance dossiers | Foreign intelligence services | Targeting, recruitment, and coercion of named individuals | OPM, 2015 |
| Whole device contents | Police, spyware operators | Full-corpus extraction beyond the scope of the inquiry | Cellebrite; Pegasus |
Two things follow. First, the mechanism is the same whether the actor is criminal, commercial or governmental; only the authorisation differs, and authorisation is not a technical control. Second, the point of intervention is concentration rather than exposure. Every case in the table would have been survivable at a smaller scale of aggregation, and none of them were prevented by the fact that the original collection was lawful.
Case studies
Ten cases are held as separate event notes and summarised here only far enough to show the mechanism. Four are given below; Equifax, SpyFone, Grindr, Pegasus against El Faro, the Afghan relocation data leak, and VTech follow the same structure in the full note.
Ashley Madison, 2015
Account records from a dating service marketed for extramarital affairs were published in full, including email addresses, partial payment details and self-descriptions. The harm did not depend on the accuracy of the records: an address appearing in the dump was damaging whether or not the account had ever been used. This is the clearest available demonstration that exposure operates on inference rather than on fact.
Vastaamo, 2020
Psychotherapy records, including session notes, were taken from a Finnish provider and used to extort patients individually. It is the case most often cited in this vault because it collapses the distance between a database and a person: the material and the victim were the same thing.
OPM, 2015
Background-investigation files on 21.5 million clearance applicants and their referees were exfiltrated. The dataset was assembled by a government for a legitimate purpose under law, which is why it is the strongest counterexample to the argument that lawful collection is a sufficient safeguard.
23andMe, 2023
Credential stuffing against reused passwords gave access to profiles, and a relative-matching feature propagated the exposure outward to accounts that were never themselves compromised. Genetic data is the extreme case of a class this vault tracks generally: data about one person that is simultaneously data about people who never consented.
Why lawful extraction is still an ethical question
Mobile forensic extraction by police is lawful in most of the jurisdictions this vault covers, and the products that perform it are sold openly. Cellebrite and comparable tools recover a device’s full contents, including deleted material and material belonging to third parties who are not suspects and have no notice. The legal question — whether the seizure was authorised — and the proportionality question — whether the whole corpus was necessary to the inquiry — are separate, and only the first is routinely answered.
The unresolved part is procedural rather than technical. Where a tool applies a selective filter, the filter’s configuration determines what the court never sees, and it is not obvious that it is disclosed: that question is open as Are Swedish mobile-extraction filters disclosed at trial?. The related matter of what a device owner is told when a third party’s device is extracted is not yet written up as Forensic extraction consent in Sweden.
Objections
The strongest objection to the position argued here is that it treats confidentiality as close to absolute while real systems require lawful access for investigating serious crime. That objection is correct about the requirement and wrong about the inference: the vault’s position is not that access should be impossible, but that access mechanisms built for everyone are evaluated as if they were built for the target. The relevant comparison is not access against no access; it is targeted access against a standing capability, which has a different failure distribution.
A second objection is that the case studies over-select for catastrophe. This has force. The cases below are drawn from breaches large enough to be investigated and published, which excludes the routine disclosures that never surface. The direction of that bias is worth being explicit about: it inflates the visible severity of individual events and deflates the visible frequency of ordinary ones.
Personal data which are, by their nature, particularly sensitive in relation to fundamental rights and freedoms merit specific protection as the context of their processing could create significant risks to the fundamental rights and freedoms.
General Data Protection Regulation, recital 51
Regulatory setting
European law already encodes most of the distinction argued above.
Article 9 of the GDPR treats health, sex life,
political opinion and biometric data as a special category requiring a
separate lawful basis, which is a legal recognition that some data classes
convert into leverage more readily than others. Article 10 handles
criminal-offence data separately again. What the regime does not do is
constrain concentration as such: a controller with a valid basis under
Article 9 may still assemble the corpus whose existence is the risk. The
code path that matters in practice is not lawfulBasis() but
retention, and retention is where enforcement is thinnest.
- Confirm the Article 9 and Article 10 treatment against current IMY guidance (done at the July 2026 pass).
- Re-check the retention-enforcement claim before the January 2027 review; it rests on a 2024 enforcement survey.
- Decide whether the ten case studies should move to their own event notes and leave summaries here.
Notes
Claim-level citations. A hairline in the outer margin above marks each paragraph that carries one.
- Vastaamo breach and patient extortion — case
summary and court reporting, archived
sources/2026-02-11-vastaamo-case-summary.pdf. ↩ - Committee on Oversight and Government Reform, report on
the OPM data breach (2016), archived
sources/2016-09-opm-oversight-report.pdf. Figures for affected individuals are the report’s own. ↩ - Access Now and Citizen Lab, joint forensic report on
Pegasus infections of El Faro journalists (2022), archived
sources/2022-01-el-faro-forensic-report.pdf. ↩
Built on
66 entries in the note’s provenance inventory — 41 archived on disk, 25 external. This says what informed the note as a whole; the notes above say what supports a particular sentence.
2026-02-11-vastaamo-case-summary.pdfon disk2016-09-opm-oversight-report.pdfon disk2022-01-el-faro-forensic-report.pdfon disk2024-03-imy-article-9-guidance.htmlon disk2023-10-23andme-credential-stuffing-notice.htmlon disk- eur-lex.europa.eu — Regulation (EU) 2016/679, consolidated text
- edps.europa.eu — opinion on data minimisation in large-scale systems
- citizenlab.ca — Pegasus targeting methodology
Show all 66 entries
2019-09-spyfone-ftc-complaint.pdfon disk2015-07-ashley-madison-incident-timeline.htmlon disk2017-09-equifax-gao-report.pdfon disk2021-08-afghan-relocation-disclosure.htmlon disk2015-11-vtech-breach-notice.htmlon disk2020-03-grindr-dpa-decision.pdfon disk- ftc.gov — stalkerware enforcement actions
- datatilsynet.no — decision on advertising identifiers
- and 50 further entries
Connections
14 notes cite this one. Six of them are claims, which is what makes this note load-bearing rather than merely linked.
Cited by — 14
- Android app distribution trust modelssynthesis · stable
- Mandatory parental surveillance of adolescentssynthesis · working
- Data as coercive powerconcept · stable
- Age assuranceconcept · working
- Are Swedish mobile-extraction filters disclosed at trial?question · open
Links out — 31
- Privacy threat modelingconcept · stable
- Data minimizationconcept · stable
- Cellebriteentity · stable
- 23andMe data breachevent · stable
- ASA statement on p-valuessource · stable
Wanted from this page — 3
- Forensic extraction consent in Swedennamed here, not yet written
- Retention enforcement under GDPRnamed here, not yet written
- Protected identity in Swedennamed here, not yet written