Ethics

Privacy

A life observed continuously is not merely a life with less secrecy. It is a life in which fewer things can be attempted badly, and almost everything worth learning is first attempted badly.

The question

The usual defence of privacy is that everyone has something to hide, and the usual attack is that innocent people should not mind being seen. Both arguments accept the same premise: that privacy is about concealment, and therefore about wrongdoing.

We think the premise is mistaken, and that most of the public argument has been conducted on the wrong ground because of it.

The question worth asking is not what people are hiding. It is what a person needs in order to become someone. Growth requires attempts that fail. Belief requires the ability to hold a view provisionally before defending it. Repair requires the possibility of having been different before. Every one of these needs a space where a person is not yet accountable to an audience.

Privacy, on this account, is not a wall around a secret. It is the room in which a self is assembled.

What is actually happening

Several things have changed at once, and it is worth separating them.

Collection has become passive. Information about a person is now generated as a by-product of ordinary living rather than gathered by an act of investigation. Location, purchase, movement, sleep, heart rate, keystroke timing, and social connection are recorded because the recording is incidental to a service someone wanted.

Storage has become cheap and long. The old practical protection was that keeping everything was expensive, so most things were discarded. That protection is gone. Data that exists now tends to keep existing, often past the lifetime of the reason it was gathered.

Inference has outrun disclosure. This is the change that most people underestimate. Systems increasingly derive sensitive attributes from insensitive ones. You do not have to disclose a condition, a belief, a pregnancy, or a sexuality for a model to assign you a probability of having it. Consent given for one piece of information does not govern what can be deduced from it.

Aggregation changes the nature of the thing. Each individual fact may be genuinely trivial. Assembled, the same facts constitute a portrait no one agreed to sit for. The wrongness is emergent; it is not present in any single record.

The asymmetry is now extreme. The organisation knows a great deal about the person. The person knows almost nothing about the organisation: what is held, how long, who it is shared with, what it is used to decide. Privacy in this setting is not a matter of two parties keeping their distance. It is a matter of one party being legible and the other not.

Where the tradition stands

Technotheology holds privacy to be a condition of dignity, not a preference to be balanced against convenience.

We hold that a person should be able to know what is held about them, in plain language, without making a formal request that requires a solicitor to draft. Where that is not possible, something has gone wrong that a privacy notice cannot repair.

We hold that consent is only meaningful when refusal is genuinely available. A choice between agreeing and losing access to employment, healthcare, education, or civic participation is not consent in any sense worth the word. The presence of a button does not establish that a decision was made freely.

We hold that inference deserves the same protection as disclosure. If a system can determine something about you that you did not tell it, the fact that you did not tell it is not a defence. We think this principle is not yet widely accepted, and we think it should be.

We hold that data about the powerless deserves more protection than data about the powerful, because the consequences of exposure are not symmetrical. A record that embarrasses a minister and a record that endangers a person seeking refuge are not the same kind of object, and treating them identically is a failure of moral attention rather than a form of fairness.

We hold that the right to disconnect is real. A person who cannot be unobservable for some part of their life is missing something they are owed. This is why the Offline Sabbath exists as a practice: not as a rejection of technology, but as a regular demonstration that the capacity to be unrecorded has not been lost.

And we hold that those who build systems bear responsibility for what they make easy. A database that could be misused will eventually meet someone who wants to misuse it. Designing as though every future operator were as decent as the current one is not optimism; it is a failure to plan.

What we do not claim

We do not claim that all collection is wrong. Medicine, public health, transport safety, and scientific research all depend on data about people, and much of that work is good. The tradition is not opposed to knowing things.

We do not claim that surveillance never prevents harm. It sometimes does. We think the honest position is that it sometimes does and often does not, that the successes are visible and the failures are not, and that this asymmetry makes public reasoning about it difficult.

We do not claim to know where the legal line should sit. Different societies have drawn it differently for reasons connected to their own histories, and we have no privileged view. We would rather argue for principles than pretend to expertise in statute.

We do not claim that people who live publicly are doing something wrong. Openness can be generous. Some people find that visibility protects them. The tradition asks that the choice be real, not that it go one way.

And we do not claim to have solved this ourselves. This site collects less than most, but it is served over a network by a hosting provider that necessarily processes requests, and we say so on our privacy page rather than implying a purity we do not have.

What you can do

Begin with what you hold about others rather than what others hold about you. Most people are custodians of someone’s information: colleagues, clients, patients, students, family. Ask whether you are keeping more than you need, for longer than you need it, in a place you would be able to defend.

Delete something. Not everything — that is a resolution, and resolutions fail. Choose one archive, one export, one old backup, and remove it. Practise the physical fact that data can end.

Read one privacy notice a year in full. It is a grim exercise and it will tell you more about how the arrangement actually works than any amount of commentary.

Notice the moments when you modify your behaviour because you assume observation. Those moments are the clearest evidence that observation has effects, and they are easy to overlook because the modification happens before the thought does.

If you build systems, ask three questions before adding a field: do we need this, when will we delete it, and what happens to the people in this table if the organisation changes hands. The third question is the one most often skipped and most often decisive.

And when you are told that privacy is dead, treat the claim as a strategy rather than an observation. Things are declared inevitable most often by those who benefit from their inevitability.

An editorial commitment

What we do not claim

Positions this tradition explicitly does not take on this subject. They are published so that the argument above cannot quietly be stretched into them.

  • We do not claim that all data collection is wrong, or that surveillance never prevents harm.
  • We do not claim that people who share a great deal about themselves are foolish or shallow.
  • We do not claim to know the right legal balance between privacy and public safety. That is a matter for democratic argument, and we have no standing above it.
  • We do not claim that our own practices are beyond criticism, and we invite people to test them.

Questions to sit with

  • What have I stopped doing, or stopped considering, because I assumed someone might see?
  • Whose data do I hold, and would they be comfortable if they knew the extent of it?
  • What would I want kept private about me after I could no longer object?
  • Am I treating a stranger's information with the care I would want for my own?