Neural network of glowing eyes connected by blue and gold light strands in space

Who Is Watching, and Why?

There is a particular kind of unease that creeps up on you somewhere around the third time your phone suggests a shop you were only thinking about visiting. It is not fear exactly. It is more the sensation of being read by something that has never met you.

We talk about being tracked as though it were one thing done by one entity for one reason. It is not. There are three quite different watchers, and they behave in quite different ways.

The commercial watcher

Google, Amazon, Meta, and the sprawling advertising exchanges sitting behind them. The purpose here is almost disappointingly ordinary. They want to predict what you will buy, and then sell that prediction to somebody who wants to sell you something.

The danger is not that a person somewhere is reading about your Tuesday. The danger is that nobody is. Your data sits inside inference engines that quietly shape your insurance quote, your credit decision, the price you are shown for a flight, without a single human being ever glancing at it. There is no villain in the room. That is rather the problem. You cannot appeal to a system that has no idea it made a judgement about you.

The state watcher

Intelligence services and police forces, operating under legal frameworks that vary enormously in quality from one country to the next. In the United Kingdom the Investigatory Powers Act grants fairly broad reach, with judicial oversight that critics describe as a rubber stamp and defenders describe as proportionate. Reasonable people genuinely disagree about where that balance sits.

What is not really in dispute is that the oversight was designed for an era of individual warrants against individual suspects, not for bulk collection against everybody, sorted afterwards.

The merge

This is the genuinely troubling one, and it gets far less attention than it deserves.

States increasingly buy from commercial data brokers what they would otherwise need a warrant to collect. Location histories, purchase records, movement patterns, all bought on the open market. No judge, no suspicion, no paperwork. Data protection law was largely built on the assumption that these two worlds stayed politely separate. They no longer do.

So what actually helps?

Three levers, roughly in order of how much difference they make.

Structural law comes first. Purpose limitation with real consequences attached. Data minimisation as a default rather than an aspiration. Above all, meaningful restriction on the secondary sale of personal data, because that is the pipe through which almost everything else flows. GDPR gestures in this direction. Enforcement remains the weak link, and fines that a large company treats as a cost of doing business are not enforcement at all.

Architecture comes second. Encryption, processing that happens on your own device rather than in somebody’s data centre, federated learning where the model travels to the data instead of the data travelling to the model. Systems built so that the sensitive material never pools in one place to begin with. Apple’s push toward on device processing is partly principle and partly marketing, and honestly it does not matter which. It is the right shape.

Personal practice comes third. VPNs, ad blockers, careful account hygiene, a bit of thought about what you agree to. All useful. But individual precaution does not scale into a solution, and we should be clear eyed about that. If privacy becomes a hobby for the technically confident, it has quietly stopped being a right and become a luxury good.

The uncomfortable part

Here is the tension nobody enjoys admitting. The same aggregation of data that enables surveillance also enables medical research, fraud detection, epidemiology, and the artificial intelligence tools that many of us now use daily and would be reluctant to give up.

I say that as someone who uses these tools constantly and finds them genuinely valuable. Ask anyone living with a long term condition whether large scale health data analysis is a threat or a lifeline and you will get a more complicated answer than the privacy debate usually allows for.

There is no clean way to have the benefits without the risks. Anyone selling you that is selling you something.

Where that leaves us

What there is, and what we should be arguing about far more loudly, is the question of who holds the data, for how long, on what basis, and whether you can find out and object.

Freedom in the coming decades probably does not survive by staying invisible. That option has largely closed. It survives by making the watchers accountable and legible. By insisting that observation runs in both directions, that we can see the systems that see us, and that somebody carries responsibility when those systems get it wrong.

Asymmetry is the real enemy here, not observation itself. A society where you are perfectly transparent to institutions that remain opaque to you is not free, whatever else it may be. A society where you are known but the knowing is bounded, documented and answerable is a different proposition entirely.

That is the future worth building. Not a retreat from technology, which is neither possible nor desirable, but a determined insistence that it faces us as well as watches us.

John Scotter Avatar

Published by

Leave a comment