Most of us have heard the argument before, usually said with a shrug: “I have nothing to hide, so I have nothing to fear.” It sounds reasonable. It feels reassuring. And it is, unfortunately, one of the most dangerous ideas of our digital age — not because it is dishonest, but because it fundamentally misunderstands what privacy is actually for.
Privacy is not about hiding secrets. It is about who holds the power to define you — today, tomorrow, and in a future that neither you nor anyone else can fully predict. The data being collected about you right now will outlast the political conditions, the companies, and the governments under which it was gathered. That is the uncomfortable truth that makes privacy not a personal preference, but a matter of genuine public importance.
The Invisible Auction Behind Every Click
When you open a webpage, something happens in the milliseconds before the page fully loads that almost nobody sees. A packet of information about you — your location, what you are reading, inferences about your health, your religion, your sexual orientation, your politics — is broadcast to hundreds or thousands of companies who bid for the right to show you an advertisement. This system is called Real-Time Bidding, or RTB, and it is the invisible engine powering the modern internet.
The Irish Council for Civil Liberties found that the average European has their personal data broadcast in this way roughly 376 times every single day. In the United States, that figure rises to around 747 times. Google’s RTB system alone runs across some 33.7 million websites and the majority of smartphone apps, and it authorises nearly 4,700 separate companies to receive data about American users — including firms based in Russia and China, where governments can legally compel companies to hand over that data.
Feeding into this ecosystem are data brokers — largely invisible companies whose entire business model is collecting and selling information about people. Firms like Acxiom, Experian and Oracle Data Cloud compile dossiers containing thousands of data points per person, sourced from loyalty cards, public court records, location data harvested from smartphone apps, and each other. They package these profiles into commercial products and sell them to marketers, insurers, employers, debt collectors and political campaigns. In 2022, the US Federal Trade Commission sued one broker, Kochava, for selling precise location data that could pinpoint people’s visits to reproductive-health clinics, addiction-recovery centres and places of worship. The data was accurate to within about ten metres.
Harvard professor Shoshana Zuboff calls this economic order “surveillance capitalism” — a system in which human experience itself is claimed as raw material, processed into predictions about future behaviour, and sold. The product is not the advertisement you see. The product is you.
From Advertising to Manipulation
Knowing a great deal about someone is not the same as merely selling them things they might want. It also means knowing exactly which emotional buttons to press. The Cambridge Analytica scandal, which broke publicly in 2018, gave the world its clearest look at how behavioural profiling can be turned into a political weapon. Data harvested from around 87 million Facebook profiles — gathered through a personality quiz — was used to build psychographic models for political campaigns, identifying voters’ anxieties and targeting them with messages carefully designed to exploit those fears. Facebook was fined five billion dollars by the US Federal Trade Commission. Meta later agreed to pay 725 million dollars to settle a related class-action lawsuit.
But the manipulation does not require bad actors operating in secret. Internal Facebook documents leaked in 2021 by whistleblower Frances Haugen revealed that the platform had deliberately weighted the “angry” reaction emoji five times more heavily than a simple “like” in its algorithm — because anger drives more engagement, and engagement drives more advertising revenue. Haugen told the US Senate that the company’s own data showed this was amplifying misinformation and, in some parts of the world, “fanning ethnic violence.” The algorithm was not broken. It was working exactly as designed.
Over time, the most insidious effect of this system may not be any single act of manipulation but something quieter: normalisation. Surveillance that would have seemed extraordinary a generation ago — every search query logged, every physical location tracked, your face scanned as you walk down a busy street — gradually becomes the wallpaper of daily life. We stop noticing. And when we stop noticing, we stop questioning it.
The World Is Watching
Digital surveillance and physical surveillance are no longer separate worlds. Between September 2024 and September 2025, London’s Metropolitan Police scanned more than three million faces using live facial recognition cameras deployed across the city, resulting in 962 arrests. By early May 2026, the Met had already scanned around 1.7 million faces in that year alone — an 87% increase on the equivalent period the year before — while a planned independent audit by the UK Information Commissioner’s Office was postponed indefinitely.
In the United States, New Orleans became the first city known to operate a live facial-recognition network — but with a twist that should give everyone pause: the system was not run by the police, but by a private nonprofit using more than 5,000 privately owned cameras. The New Orleans Police Department was quietly receiving real-time facial-recognition alerts for two years before the arrangement was publicly exposed by the Washington Post in 2025. Meanwhile, a company called Flock Safety operates a network of automatic licence plate readers across more than 5,000 US communities, performing over 20 billion vehicle scans per month. That data has been accessed by federal immigration authorities, and in at least one documented case was used to track a woman suspected of crossing state lines to seek an abortion.
The EU has pushed back harder than most. In 2024, the Dutch Data Protection Authority fined Clearview AI — a company that scraped over 30 billion facial images from the internet to build a searchable identification database — €30.5 million for violating GDPR. The EU AI Act, which becomes broadly applicable in August 2026, bans live biometric surveillance in public spaces by police in most circumstances, along with social scoring and the scraping of faces from the internet. These are meaningful protections. But the law also contains significant exceptions, and its enforcement will depend on political will that cannot be guaranteed.
Today’s Data, Tomorrow’s Rulers
Here is the argument that cuts deepest, and the one that the “nothing to hide” response cannot answer: the infrastructure being built today will be inherited by whoever comes next. Data does not expire when governments change. Surveillance systems do not dismantle themselves when political conditions shift.
History is instructive. IBM’s German subsidiary leased punch-card tabulation machines to Nazi Germany that helped process census data identifying Jews under the Nuremberg laws. In East Germany, the Stasi maintained files on around six million people — roughly a third of the entire population — using a network of roughly 91,000 employees and hundreds of thousands of informants. The goal, as one former director put it, was to know everything about everyone. The Stasi archive, when finally opened after reunification, occupied 48,000 filing cabinets. A single modern government server holds data that, if printed, would fill an estimated 42 trillion.
This is not a distant or hypothetical risk. Moscow has repeatedly used its metro facial-recognition network to arrest peaceful protesters and draft evaders; the European Court of Human Rights ruled in 2023 that this practice violated fundamental human rights. In Xinjiang, China’s surveillance apparatus — combining cameras, facial recognition, mandatory phone-monitoring apps and DNA collection — has been used to detain an estimated up to one million Uyghurs without trial.
Even in stable democracies, mass surveillance produces a documented chilling effect. Studies have consistently shown that awareness of being watched makes people less willing to express minority opinions, search for controversial information, or participate in political activism. Privacy is not just a personal right. It is the precondition for a free public sphere.
There is also a more immediate, personal dimension. Data broker profiles have been used by stalkers and abusers to find the new addresses of people who fled them. In June 2025, a gunman in Minnesota found with a handwritten list of people-search broker sites had compiled a dossier on 45 state legislators. The internet does not forget — and sometimes, that is genuinely dangerous.
What You Can Do
None of this means panic or paralysis. But it does mean making deliberate choices. Use a privacy-respecting browser and search engine. Think carefully before granting apps permission to access your location, contacts or camera. Be thoughtful about what you share publicly — not because you are doing anything wrong, but because you cannot predict the context in which that information might one day be read. Support the organisations and legislators working to enforce strong privacy law, and pay attention to how the EU AI Act is actually implemented in the coming years.
The right to privacy is not about having secrets. It is about retaining the ability to live a life that is not pre-shaped by someone else’s record of you — a record built without your knowledge, sold without your consent, and stored indefinitely for purposes you cannot control. That is a right worth defending, precisely because you have nothing to hide.
Key Takeaways
- Every time you open a webpage, your personal data is broadcast to hundreds or thousands of companies in real time — the average European experiences this around 376 times a day.
- Data brokers compile thousands of data points about each of us and sell them to advertisers, insurers, employers and, sometimes, to people with harmful intentions.
- Live facial recognition is already operating at scale in the UK, the US and authoritarian states — and private surveillance networks are quietly merging with public law enforcement.
- The “nothing to hide” argument misses the point: data collected under today’s governments will be inherited by tomorrow’s — and history shows what can happen when that data is in the wrong hands.
- The EU AI Act and GDPR offer real but imperfect protections. Meaningful privacy also requires personal choices, informed citizens and vigilant enforcement.
Photo: Patrick via Pexels
