“I have nothing to hide, so I have nothing to fear.”

It is one of the most common things people say when the subject of privacy comes up. It sounds reasonable. It feels reassuring. And it is, unfortunately, one of the most dangerous ideas of our digital age — not because it is dishonest, but because it misunderstands what privacy is actually for.

Privacy is not a shield for wrongdoers. It is not a preference for the paranoid. Privacy is about who holds the power to define you — today, tomorrow, and in a future that neither you nor anyone else can fully predict. The data being collected about you right now will outlast the political conditions, the companies, and the governments under which it was gathered. That is the uncomfortable truth that makes privacy not a personal quirk, but a matter of genuine public importance.

The Machine Behind Every Click

When you open a webpage, something happens in the milliseconds before the page fully loads that almost nobody sees. A packet of information about you — your location, what you are reading, inferences about your health, your religion, your sexual orientation, your politics — is broadcast to hundreds or thousands of companies who bid, in real time, for the right to show you an advertisement. The Irish Council for Civil Liberties found that the average European has their personal data broadcast in this way roughly 376 times every single day.

This system is not a side effect of the modern internet. It is its business model. In 2026, the global digital advertising market is on track to surpass one trillion dollars for the first time in history. Google, Meta, and Amazon alone control over 62% of all global digital ad spending. All of it is powered by data about you. As Harvard professor Shoshana Zuboff put it: the product is not the advertisement you see. The product is you.

Behind the platforms sits a parallel industry most people never encounter directly: data brokers. These companies aggregate information from hundreds of sources — public records, social media, purchase histories, location data — and combine it into detailed profiles covering your age, income, health conditions, political beliefs, and family status. They sell these profiles to advertisers, insurers, employers, and anyone else willing to pay. They have no relationship with the people they profile. They are under no obligation to tell you what they hold. And opting out is, by design, nearly impossible.

The trackers themselves are invisible. Tracking cookies follow you across the web. Browser fingerprinting identifies your device even in private browsing mode. Your phone’s location is mapped throughout the day — to the doctor, to the mosque, to a political rally — and sold. A Washington Post investigation found that a single iPhone transmitted data to up to 5,400 trackers in a single week, including companies embedded inside apps from Nike, Spotify, and Yelp.

Read more: The $1 Trillion Trap: How Ad Tech Owns the Internet in 2026

It’s Not Just Ads

Knowing a great deal about someone is not the same as merely selling them things they might want. It also means knowing exactly which emotional buttons to press.

The Cambridge Analytica scandal gave the world its clearest look at how behavioural profiling can be turned into a political weapon. Data harvested from around 87 million Facebook profiles was used to build psychographic models for political campaigns — identifying voters’ anxieties and targeting them with messages carefully designed to exploit those fears. This was not a one-off breach. It was the system working as designed, pushed one step further.

The consequences of mass data collection are not always political. They can be immediate and physical. Data broker profiles have been used by stalkers and abusers to find the new addresses of people who fled them. In June 2025, a gunman in Minnesota found with a list of people-search broker sites had compiled a dossier on 45 state legislators. The tools that sell you shoes also, under different circumstances, enable people to find and harm you.

There is also a subtler effect, harder to see but just as real: the chilling effect. Studies consistently show that awareness of being watched makes people less willing to express minority opinions, search for controversial information, or participate in political activism. You do not have to be doing anything wrong for surveillance to change your behaviour. The mere possibility is enough. A society in which people self-censor is not a free society, even if no one has explicitly forbidden anything.

Read more: Why Privacy Still Matters for All of Us

Today’s Data, Tomorrow’s Problem

Here is the argument that the “nothing to hide” response cannot answer: the infrastructure being built today will be inherited by whoever comes next. Data does not expire when governments change. Surveillance systems do not dismantle themselves when political conditions shift.

History makes this concrete. IBM’s German subsidiary leased tabulation machines to Nazi Germany that helped process census data identifying Jews under the Nuremberg laws. In East Germany, the Stasi maintained files on around six million people — roughly a third of the entire population — using roughly 91,000 employees and hundreds of thousands of informants. Their goal, as one former director put it, was to know everything about everyone. When the archive was finally opened after reunification, it occupied 48,000 filing cabinets. A single modern government server holds data that, if printed, would dwarf that entirely.

This is not ancient history. Moscow has repeatedly used its metro facial recognition network to arrest peaceful protesters and draft evaders. In Xinjiang, China’s surveillance apparatus — cameras, facial recognition, mandatory phone-monitoring apps, DNA collection — has been used to detain an estimated one million Uyghurs without trial. And the EU itself is not immune: between September 2024 and September 2025, London’s Metropolitan Police scanned more than three million faces using live facial recognition cameras, resulting in 962 arrests. A planned independent audit was postponed indefinitely.

Surveillance infrastructure does not cause authoritarianism. But it makes authoritarianism permanent. Once a regime has the tools to monitor every conversation, every assembly, every transaction, the ability of citizens to organise and reclaim power largely disappears. As Phil Zimmermann — the engineer who created PGP encryption, and who nearly went to prison for it — has put it: we have never before lived in a world where governments have omniscience. It is not clear that democracy can survive it.

Even in stable democracies, the risk is not hypothetical. It is a question of what happens to today’s surveillance infrastructure under tomorrow’s leadership. No one building it now can guarantee the conditions under which it will eventually be used.

Read more: Privacy Can’t Wait: Phil Zimmermann Was Right

The Law Helps, But Not Enough

Europe has stronger privacy protections than almost anywhere else on earth. The GDPR gave citizens real rights: to know what data is held about them, to request deletion, to object to processing. The EU AI Act, which becomes broadly applicable in August 2026, bans live biometric surveillance in public spaces in most circumstances, prohibits social scoring, and restricts the scraping of faces from the internet. These are meaningful achievements.

But the law has limits. Enforcement is uneven and under-resourced. Key concepts remain open to interpretation. Cross-border data flows create gaps regulators cannot easily close. And some of the most consequential data collection — the real-time bidding system that broadcasts your data 376 times a day — continues largely unchecked, because no regulator has yet managed to shut it down at scale.

The United States still has no coherent federal privacy framework. Most of the data tracking and digital surveillance an average person experiences daily is technically legal in most jurisdictions. Regulation is necessary — but it is not sufficient on its own.

What Pretty Simple Privacy Stands For

Pretty Simple Privacy exists because the gap between “I know this is a problem” and actually doing something about it remains stubbornly wide — and because bridging that gap does not require a degree in computer science.

We believe privacy is not a luxury for the technically sophisticated. It is a precondition for living a life that is not pre-shaped by someone else’s record of you — a record built without your knowledge, sold without your consent, and stored indefinitely for purposes you cannot control.

We are critical of the systems and companies that profit from mass surveillance, and we will not pretend otherwise. We recommend only tools we have personally tested. We are precise in our claims — “source-available” is not the same as “open source,” and we will say so. We do not recommend tools with advertising business models or data-selling practices. We believe in benefits, not just risks: a privacy-respecting browser is also faster, cleaner, and less manipulative than the alternative. These are not sacrifices. They are upgrades.

Our editorial standard is simple: would we recommend this to someone we care about? If the answer is yes, it goes on the site. If it is not, it does not.

Simple Steps You Can Take Today

None of what is described on this page requires panic or paralysis. The tools to meaningfully reduce your exposure exist, they work, and most of them are free.

Switching to a privacy-respecting browser takes five minutes. Replacing Google with a search engine that doesn’t profile you takes thirty seconds. Using a VPN from a provider that doesn’t log your traffic costs less per month than a coffee.

These steps will not make you invisible. But they will significantly reduce the amount of data flowing to companies that trade in it — and they will do so without meaningful friction in your daily life.

Explore the Simple Privacy Fixes directory — curated tools, plain explanations, no jargon.


From the Blog

Further reading from the Pretty Simple Privacy blog.


Quote

Mastodon
Scroll to Top