DataSovereigntyProtection

The Harvest โ€” what our data becomes, and how a people take it back

What is actually taken from a phone, how it travels from an app to a buyer, how repetition edits a mind, and what a person and a country can really do about it. The shadow named here is a mechanism โ€” unaccountable data power โ€” never a people.

✦ reviewed 100·22 July 2026·161 min read

Contents
  1. The phone on the bedside table
  2. What is actually taken
  3. Location โ€” the most revealing thing you carry
  4. The microphone โ€” the myth that costs us the argument
  5. Camera and face
  6. The sensors nobody asks permission for
  7. Contacts, and the fact that consent is not individual
  8. Behaviour โ€” the layer that makes the microphone unnecessary
  9. Three surfaces people forget: the television, the classroom, the genome
  10. The chain โ€” the journey of one tap
  11. Link 1 โ€” the software development kits inside the app
  12. Link 2 โ€” the advertising identifier
  13. Link 3 โ€” the real-time bidding auction
  14. Link 4 โ€” the broker who simply listens
  15. Link 5 โ€” the buyer, and the step that turns merchandise into a person
  16. Where the law currently stands on this chain
  17. The casebook
  18. Function creep โ€” the pattern this study is built on
  19. Automated suspicion turned on citizens โ€” and stopped
  20. The collection itself as the hazard
  21. Intimate data through ordinary plumbing
  22. The state and the market, connected
  23. The surveillance-for-hire market โ€” and the fabrication case
  24. The correction the casebook must make about itself
  25. How repetition edits a mind
  26. The documented core
  27. What ranking does with that machinery
  28. What is contested โ€” stated plainly, because the honest version is more useful
  29. Four myths this section retires
  30. The honest threat model
  31. The scenario
  32. Two things called "influence operations" โ€” and conflating them is the field's biggest error
  33. The four levers โ€” stated precisely, without inflation
  34. The legal-compulsion question โ€” answered even-handedly, because that is the only way it holds
  35. The live case: what is established, and what is not
  36. What ownership remedies actually accomplish
  37. Romania โ€” the case that proves why the adversary cannot be a nation
  38. The measurement problem โ€” and what this study argues instead
  39. What the scenario justifies, and what it does not
  40. What protects a person
  41. Tier 1 โ€” twenty minutes, most of the benefit
  42. Tier 2 โ€” one evening, high effect
  43. Tier 3 โ€” situational, and the highest stakes
  44. The rungs below "open Settings"
  45. What protects a country
  46. The measures with evidence behind them, ranked by leverage
  47. What India specifically holds today, and what it does not
  48. Why censorship and shutdowns fail โ€” and endanger the people they claim to protect
  49. Building a house that collects nothing
  50. The architecture
  51. The hard trade-offs, stated without flinching
  52. How a platform proves its claims instead of asserting them
  53. Awakening โ€” the teaching design the evidence supports
  54. What works
  55. What backfires
  56. The teaching sequence, in order
  57. Where we take the greatest care
  58. What this study does not know
  59. What is genuinely contested, and is published as contested
  60. What we refuse to claim
  61. Method notes we hold ourselves to
  62. The vow
  63. Sources
The Harvest โ€” what our data becomes, and how a people take it back ยท Studies ยท Sathya Yugam
โ† All studies
เคคเคฎเคธเฅ‹ เคฎเคพ เคœเฅเคฏเฅ‹เคคเคฟเคฐเฅเค—เคฎเคฏ

The Harvest

What our data becomes โ€” and how a people take it back.

A Sathya Yugam study A mechanism, never a people Draft ยท offered in service Documented ยท contested ยท corrected

How to read this study โ€” please begin here. This study is written to be checked, not believed. Every claim in it carries one of three grades, and the grade is stated in the sentence rather than hidden in a footnote: documented (a court, a regulator, a peer-reviewed measurement or a primary record establishes it); contested (serious researchers disagree, and we say so even when the disagreement weakens our own argument); and corrected (a widely repeated claim that the evidence does not support, including several that people repeat because they care). Where a figure comes from a company's own marketing, a party's pleading or an untested indictment, we label it as such โ€” including when it is on our side of the argument.

One rule governs the whole document, and it is not diplomacy โ€” it is the central analytical fact. The shadow here is never a people, a nation, a faith or a race. We name companies, governments, laws, courts and cases exactly as the public record names them; refusing to do that would be cowardice, not kindness. But the adversary this study identifies is a mechanism: unaccountable data power, engagement optimisation, and the untended survival-mind. Every capability described below is one that any actor holding that data could exercise โ€” a state, a company, a police force, an employer, a stalker, a well-funded pressure group. When we name a law of one country, we name its analogues elsewhere in the same breath, because the finding is that every host state holds a lever.

And one measurement warning, because it governs every number that follows. Every quantity in this study is a floor, not a census: the largest figures are reconstructions from industry data whose source is confidential and which excludes some of the largest platforms; the broker registries are self-declarations by firms that chose to register; and no government anywhere publishes a count of who holds what. Where we could not verify something, we have dropped it or flagged it as unconfirmed. Where the honest answer is "nobody knows", that is what Section 11 says.

Finally, the promise this study makes about its own remedies: not one of them requires anyone to be silenced. Every fact in this document โ€” including the reassuring ones โ€” exists because someone was free to look and free to publish. A remedy that would have suppressed the exposรฉ would have suppressed the debunk with it.


The phone on the bedside table

There is a small rectangle of glass on the table beside where you sleep. It has been there for years. It knows what time you stopped scrolling last night and what time you reached for it this morning, and the gap between those two numbers is a fair estimate of how well you slept. It knows the ceiling above your bed as a set of coordinates accurate to a few metres. It knows the route you take to work, the shop you stop at on the way, the temple or church or mosque you pass and whether you go in, the clinic you visited twice in March, and the house you drove to at eleven at night when someone in your family was ill.

None of this required anyone to break in. You gave permission, once, in a dialogue box, years ago, while trying to get to something else.

This study is not written to frighten you about that. Fear is a poor instrument; it makes people either freeze or perform outrage, and neither of those changes anything. It is written because something specific and understandable is happening, and because the true version of it is more interesting โ€” and far more actionable โ€” than the version people repeat to each other.

Here is the shape of the true version, in four parts.

First: very little of this is theft in the ordinary sense. The overwhelming majority of what leaves your phone leaves lawfully, through a boring commercial pipeline built for advertising. The single most consequential fact in this entire field is that a "free" app is not free: it is paid for with a continuous, automated broadcast of who and where you are. Peer-reviewed measurement of nearly two million free Android apps found a median of 11 tracker hosts from 5 distinct companies inside the ordinary app, with 91.37% carrying at least one (Kollnig et al., Internet Policy Review 10(4), 2021).

Second: the thing most people fear is the thing least supported by evidence โ€” and the true mechanism is worse. Your phone is almost certainly not secretly listening to your conversations in order to sell you shoes. The largest study ever built to test that question โ€” 17,260 Android apps, analysed both statically and dynamically โ€” found no app covertly activating the microphone. We spend a long section on this below, because getting it right is the credibility test for everything else. The short version: they are not listening because they do not need to. Inference from your location, your purchases, your browsing and the people around you is cheaper, more accurate, more scalable and far more legally defensible than audio. "They aren't listening" is not reassurance. It is a description of a system that has outgrown the need.

Third: the danger is almost never in the moment of collection. It is in what the data becomes later, in someone else's hands. This is the load-bearing idea of the whole study, and it has a name: function creep. Data gathered for one benign purpose is repurposed by a new owner, a new government, a new contract, or a court order. The best-documented instance is sober and unglamorous. In 1943, with census confidentiality suspended under the Second War Powers Act, the United States Census Bureau supplied the Secret Service with names and addresses of people of Japanese ancestry in the Washington DC area โ€” data collected to apportion seats in Congress, used for internment (Seltzer & Anderson, "The Dark Side of Numbers", Social Research 68(2), 2001; the Bureau acknowledged the block-level role in 2000 and the individual-level disclosure after 2007). No one who filled in that form did anything wrong. No one who designed it intended that. The data outlived the intention. Data always outlives the intention โ€” and note what makes this case so powerful: the collectors were not villains, and the promise of confidentiality was sincere when it was made. A statute erased it within months. No collector's good intentions survive the next emergency law, which is true of every government the readers of this study live under.

Fourth: this is not hopeless, and it is not new. Courts have struck this down. The District Court of The Hague voided an entire welfare-surveillance statute in February 2020. India's own Supreme Court struck down Section 57 of the Aadhaar Act in September 2018 expressly on function-creep grounds. The US Supreme Court held on 29 June 2026 that acquiring geofence location data is a Fourth Amendment search. A regulator banned the sale of sensitive location data outright. A period-tracking app was ordered to stop leaking pregnancy events to advertisers. These are not victories in a war that is over; they are proof that the mechanism is answerable โ€” which is the only thing you actually need to know before you begin.

So read this steadily. You will find that several things you were angry about are not true, and several things you never thought about are. That is a good trade. A person who knows precisely what is happening is not frightened. They are simply awake โ€” and an awake population is the only defence that has ever worked.


What is actually taken

Location โ€” the most revealing thing you carry

A location trail is not a list of places. It is a reconstruction of a life, and the mathematics of that is settled. De Montjoye, Hidalgo, Verleysen and Blondel studied fifteen months of mobile-carrier records for 1.5 million people at hourly resolution: two randomly chosen points made over 50% of traces unique; four made 95% unique; eleven made every single trace unique. Coarsening the data barely helped. The authors noted their method probably understates the risk, because a real adversary would choose the most distinctive points rather than random ones (Scientific Reports 3:1376, 25 March 2013).

State that finding precisely, because the slogan version is wrong and the wrong version gets the whole field dismissed. Unicity is not identification. Four points make your trace unique within that dataset; they do not by themselves supply your name. Naming requires linking to an outside source. The honest version is more alarming than the slogan, not less โ€” because the outside source is trivial. The two most frequent points in almost every trail are a home and a workplace, and both are matchable against ordinary public records. A police user of the Fog Data Science system put it plainly, in a document obtained by the Electronic Frontier Foundation: "if we are good at what we do, we should be able to figure out the owner."

The scale is industrial. The US Federal Trade Commission's December 2024 complaint alleged that Gravy Analytics and its subsidiary Venntel obtained roughly 17 billion location signals a day from around one billion mobile devices, sold data that was not anonymised, and derived sensitive characteristics including health decisions, political activity and religious viewpoints. Fog Data Science sold US local police forces a searchable database it claimed covered over 250 million devices generating 15 billion signals a day, for $6,000โ€“$9,000 a year including 100 queries a month; the California Highway Patrol paid $7,500 plus $2,400 for 500 extra monthly queries (EFF, 31 August 2022).

And the collection surface is not what people assume. It is usually not the GPS chip, and often not even a tracking library inside the app you opened. GPS is a one-way, receive-only system: your handset listens to satellites and computes a position locally, transmitting nothing back. Every location that leaves your phone leaves because software or a network sends it โ€” and the dominant sender today is the advertising auction, which is the subject of the next section.

What this looks like when someone points it at one person. In October 2024, a private investigator hired by Atlas Data Privacy obtained a trial of Babel Street's Locate X by asserting he might do government contract work; a salesperson reportedly replied "that's good enough" and "they don't actually check." The demonstration showed more than 700 markers over a single reproductive-health clinic in the southern United States, and then followed one device through a day: a residence in Alabama, a hardware store, a highway, a petrol station, a church, roughly two hours at a clinic in Florida, and home again (404 Media and KrebsOnSecurity, 23 October 2024). Two precisions the record requires: a separate demonstration used a geofence to identify a likely clinic employee and follow them home โ€” the two should not be fused, or the account becomes the sensationalism it is criticising. And KrebsOnSecurity states plainly that it remains unclear precisely how Babel Street obtains this abundance of mobile location data; public-records documents show it re-hosts Venntel data, but the full supply chain is unconfirmed.

The machine sorts every congregation โ€” and the harmed party is always a worshipper. Two ordinary devotional applications sit at the centre of this record, and the lesson is emphatically not about those faiths. In November 2020 Motherboard reported that Muslim Pro โ€” a prayer-times and qibla-direction utility with more than 98 million downloads โ€” along with apps including Accupedo, Global Storms and CPlus for Craigslist, sent location data to the broker X-Mode, which licensed data to contractors working with military services. Muslim Pro said it was "immediately terminating our relationships with our data partners โ€” including with X-Mode"; Apple and Google banned X-Mode from their stores in December 2020. In July 2021 a Catholic outlet published an analysis of commercially available app signal data which it said identified a senior US church official, who resigned the same day โ€” and the Washington Post reported on 9 March 2023 that a Denver nonprofit, Catholic Laity and Clergy for Renewal, spent roughly $4 million between 2018 and 2021 buying app data it said came from dating and social apps, cross-referencing it against church residences to identify priests. In the same period a broker's own segment list carried an audience called "Christian church goers", and the FTC's list of sensitive destinations names religious organisations alongside clinics and shelters. These are not four stories about four faiths. They are four instances of one sorting machine, and the named actors are X-Mode, Outlogic, InMarket, Babel Street, Gravy Analytics and the exchanges that carry them. One care the record demands: in the individual clergy case the specific supply chain was never proven โ€” the outlet named no vendor, and one named app has publicly said its data could not leak in the manner described. The capability is real and was funded; the chain in that one case remains alleged. Say it that way, because getting the chain wrong is how a true warning gets discredited.

And note what the remedy is not. The natural emotional reaction to that case is to want the publication stopped. That is the wrong remedy and a dangerous one โ€” it would be turned against exactly the reporting that exposed every other case in this document. The fix belongs at the supply layer: consent, deletion rights, and bans on the brokerage of sensitive-location data. This study takes the same position on the Aadhaar reporting: when the Unique Identification Authority of India responded to The Tribune's January 2018 story by filing a criminal complaint that named the reporting journalists, that was a censorship remedy, and we name it as an anti-pattern rather than mention it in passing.

The capability is content-neutral, which is the whole point. In a 2021 sales pitch reported by The Intercept in April 2022, the firm Anomaly Six demonstrated tracking the commutes of CIA and NSA personnel using commercial phone data โ€” 183 markers representing phones that had visited both agencies. The Intercept states plainly that it was not able to corroborate the firm's claims about its data or capabilities, which were made in a sales pitch; the company's claim to track some three billion devices is marketing, not audit. But the category is corroborated elsewhere: the Irish Council for Civil Liberties and Cracked Labs published a May 2021 Microsoft Xandr data-marketplace list running to 19,956 pages and 651,463 segments, including segments for defence-aerospace employees at Airbus, engineers at BAE Systems, employees of the firm that maintains the UK nuclear submarine fleet, army, navy and air force personnel in France, Germany and the UK, judges, politicians, and people whose location placed them within six miles of a military base. The same purchase that locates a clinic visitor locates a union meeting, a mosque, a rally, a barracks and a shelter. That is why it must be blocked at collection rather than curated by category.

Finally, two channels that ignore your settings entirely. Wi-Fi: Rye and Levin showed that Apple's Wi-Fi Positioning System could be queried by an unprivileged attacker to build a worldwide snapshot of access-point locations, accumulating over 2 billion geolocated network identifiers within a year โ€” and because travel routers and satellite terminals move with their owners, they were able to track devices entering and leaving conflict zones (IEEE Symposium on Security and Privacy, 2024). Phone-network signalling: the SS7 system is built on inter-operator trust, so location queries from a foreign network are honoured by default; Karsten Nohl demonstrated tracking "from virtually anywhere in the world" at roughly 70% success in 2014, and CISA's Kevin Briggs told the US Federal Communications Commission in 2024 of numerous attempts to obtain location, voice and text and to deliver spyware. And Quartz reported on 21 November 2017 that Android phones had been sending nearby cell-tower identifiers to Google since early that year even with location services off and no SIM inserted; Google confirmed it, said the data was never used or stored, and stopped requesting the identifier.

Turning off location is worth doing. Believing it makes you invisible is dangerous for anyone whose safety depends on it โ€” and no app setting, permission toggle or operating-system update reaches the carrier signalling layer at all. That is precisely why carrier signalling is a public-infrastructure question rather than a personal-hygiene one; and it is also why personal hygiene is still worth doing, because it defeats the layer that produces most everyday harm.

The microphone โ€” the myth that costs us the argument

This is the section that decides whether the rest of this study is believed.

On attribution, and on the absence of evidence. Where this study says a mechanism was used, the record shows it. Where the record shows only that it could be, we say so. The largest study ever run found no evidence that phones covertly record conversations โ€” but its method could not have detected speech transcribed on the device itself; and in several cases in this document (who operated a spyware infection, where a location product sources its data, which supply chain identified a named individual) the honest answer is that it is documented that someone could, and not established who did.

The belief is near-universal: my phone listens to my conversations and serves me ads about them. Almost everyone has a story. The story feels like proof.

What the research actually found. Elleen Pan, Jingjing Ren, Martina Lindorfer, Christo Wilson and David Choffnes analysed 17,260 Android apps drawn from four app stores, filtered to apps declaring camera or audio permission, using combined static and dynamic analysis โ€” published as "Panoptispy: Characterizing Audio and Video Exfiltration from Android Applications", PoPETs 2018(4). They found no evidence of any app unexpectedly activating the microphone or exfiltrating audio. In Christo Wilson's words: "There were no audio leaks at all โ€” not a single app activated the microphone."

Now state the limits in the same breath, because that is what makes the finding unbreakable. The authors published their own limitations and any honest citation must repeat them: the testing used automated exploration, which does not interact with apps the way a human does; controlled experiments do not replicate real environmental conditions; traffic can be deliberately obfuscated; and, most importantly, the method detected media in network traffic by file signature โ€” so an app that transcribed speech to text on the device and transmitted only the text would not have been detected as an audio leak. The study is also from 2018. So the correct claim is: the largest empirical test found no evidence of covert audio exfiltration, and the authors note their method could not have detected on-device transcription. That is a finding of absence, not a proof of impossibility โ€” and stated that way it cannot be broken by one counterexample. Stated as "no, it never happens", it can.

What they found instead was worse, and almost nobody talks about it. Third-party libraries that record and upload screenshots and video of the screen, without informing the user and without requiring any permission. (Two contemporaneous write-ups of that paper give different counts of how many apps had this potential; we therefore quote no number.) The named case is concrete: during testing, the GoPuff delivery app's screen interaction was recorded and transmitted to a domain affiliated with the mobile analytics firm Appsee. The captured video included a screen where personal information โ€” in the test, a postcode โ€” was typed. GoPuff's privacy policy did not disclose it. After the researchers made contact, GoPuff added a notice and removed the Appsee library. As Choffnes put it: "We found that every app has the ability to record your screen and anything you type... username and password, because it can record the characters you type before they turn into those little black dots."

One qualifier is mandatory here, or we manufacture a new myth while debunking an old one. The mechanism is a library inside an app capturing that app's own interface โ€” not a device-wide recorder watching everything you do, and not other apps. Capturing the whole device screen on Android requires a system permission that raises a consent dialogue. The accurate sentence is: an app, and any library inside it, can record its own screen โ€” everything you type into that app โ€” with no permission prompt and no notice.

The real, documented microphone scandal is a different shape entirely: false wakes, plus undisclosed human review.

  • Google, 10 July 2019. The Belgian broadcaster VRT NWS published an investigation based on more than 1,000 Google Assistant audio excerpts handed over by a Dutch-language contract reviewer. 153 were unintended โ€” captured with no wake word, triggered by similar-sounding words or mistaken button presses. The clips included bedroom conversations, parent-child discussions, arguments, medical queries, professional calls containing account numbers and passwords, and one reviewer described a woman in evident distress. Google said the work covered about 0.2% of all audio fragments and that files were not linked to identifiable information โ€” but VRT journalists identified real people from addresses, names and companies spoken inside the supposedly anonymised clips, and confronted them with their own recordings.
  • Hamburg, 2 August 2019. Data protection commissioner Johannes Caspar opened a GDPR Article 66 urgency procedure โ€” the first use of that emergency power since the regulation took effect โ€” ordering Google's human review of Assistant audio halted for up to three months.
  • Apple, Julyโ€“August 2019. A whistleblower told The Guardian that contractors "grading" Siri regularly heard confidential medical information, drug deals and recordings of people having sex, often from accidental activations. Apple said fewer than 1% of daily activations were used for grading and that requests were not associated with an Apple ID; the whistleblower said identifying details were nonetheless audible. Apple suspended the programme and published an unusual apology on 28 August 2019: "As a result of our review, we realize we haven't been fully living up to our high ideals, and for that we apologize." It committed to no longer retaining Siri audio by default, to strictly opt-in and revocable human review, to review by Apple employees only, and to deletion of inadvertent triggers.
  • Microsoft, 7 August 2019. Motherboard reported contractors reviewing audio from Skype's translation feature and from Cortana commands โ€” intimate conversations, weight-loss and relationship discussions, full home addresses, sexually explicit material. The core documented gap: the privacy documentation did not state that human beings would listen.
  • Amazon, 31 May 2023 โ€” the strongest legal finding, and it is about children. The US Department of Justice, on behalf of the FTC, filed a complaint alleging that Amazon repeatedly assured users and parents they could delete Alexa voice recordings and geolocation, but retained some for years and used them to improve the Alexa algorithm, in violation of the children's privacy rule and Section 5. The technically striking allegation: even when parents requested deletion of a child's recordings, Amazon retained the derived transcripts, stored with persistent identifiers linked to the child's account, without telling parents. A proposed stipulated order, later entered by the court, imposed a $25 million civil penalty plus deletion of inactive child accounts, overhauled deletion practices and a geolocation privacy programme. Amazon did not admit the allegations, and the agency's observation that children's speech patterns make the retained corpus commercially valuable is a statement in its pleading, not an independent finding.
  • Apple again โ€” Lopez v. Apple Inc. The class covered owners of Siri-enabled devices whose confidential communications were allegedly captured through an unintended activation between 17 September 2014 and 31 December 2024. Apple settled for $95 million (announced January 2025, final approval October 2025), with claimants eligible for up to $20 per device on up to five devices; reported actual per-device payments were substantially lower. Apple denies all allegations and any unlawful conduct โ€” a settlement is not a finding of liability. On 8 January 2025 Apple stated: "Apple has never used Siri data to build marketing profiles, never made it available for advertising, and never sold it to anyone for any purpose."

The one story people cite as proof, and why it is not. In August 2024, 404 Media obtained a Cox Media Group pitch deck marketing "Active Listening" โ€” ad targeting that would "capture real-time intent data by listening to our conversations" โ€” naming Facebook, Google, Amazon and Bing as partners and claiming behavioural and voice data from "470+ sources". Google removed the firm from its advertising partners programme after being shown the deck. Amazon said it "has never worked with CMG on this program and has no plans to do so." Meta said the firm was a general marketing partner, not a partner on that programme, and pointed to its standing policy against microphone-based ad targeting. The claims were deleted from the company's website. No regulator finding, court judgment, technical audit or independent verification has established that the capability existed or ran. It is evidence that a vendor pitched a story. Do not upgrade a pitch deck into a finding โ€” and note the deck's own text: 470+ sources of behavioural data. The audio claim was the garnish on a behavioural product.

Two related corrections, because they are constantly conflated.

  • "Facebook admitted it listens." No. Bloomberg reported on 13 August 2019 that Facebook paid hundreds of contractors to transcribe Messenger audio clips โ€” from users who had themselves switched on transcription for their voice messages. The real, narrower wrong is that the opt-in disclosure said nothing about human listeners. That is a consent-disclosure failure, not ambient capture. Describing it as the latter destroys the credibility of the accurate complaint.
  • "Ultrasonic beacons in TV ads are tracking your household." Arp, Quiring, Wressnegger and Rieck measured this properly (IEEE EuroS&P 2017). Real: SilverPush receiver code grew from 6 known app samples in April 2015 to 234 by publication, listening in the background at 18โ€“20 kHz; beacons were found in 4 of 35 retail stores across two European cities. Not real: after analysing more than 140 hours of media from seven countries they found zero beacons in actual TV audio, and noted that streaming audio compression undermines the technique. The FTC sent warning letters to 12 app developers in March 2016; SilverPush exited the business; Google required disclosure from May 2017. One legal precision frequently reported backwards: in Satchell v. Sonic Notify / Signal360 and the Golden State Warriors, the court in March 2017 dismissed the claims against all three defendants, with leave to amend, finding the plaintiff had not alleged that the contents of any private communication were actually acquired. No court has ever entered a final judgment that an ultrasonic beacon system unlawfully captured conversation content. Note also how fast that one died: disclosure requirements and platform policy pushed a whole technique out of the market in under eighteen months, with nobody silenced.

Now the sharp point โ€” the reason this section exists.

Not-listening is not innocence. It is efficiency.

Continuous ambient audio would be the most expensive option available (bandwidth, storage, transcription compute), the most detectable (measurable in data volume and battery), and the most legally exposed (wiretapping statutes in many jurisdictions carry criminal liability). Meanwhile, inference from ordinary behavioural exhaust โ€” your location trail, your purchases, your browsing, your app opens, your contact graph, whose phone is repeatedly near yours โ€” is cheap, lawful, already built, and more accurate than speech, because it captures what you do rather than what you say. The FTC's September 2024 staff report, "A Look Behind the Screens", built on orders issued to nine companies, concluded that the monetisation of personal data has created a market for commercial surveillance with inadequate guardrails. None of that requires a microphone.

And there is a third explanation for the uncanny ad that nobody likes hearing: the frequency illusion. An ad you would have scrolled past becomes salient because the topic is live in your mind. That is not a dismissal โ€” the first two mechanisms are real and industrial โ€” but an honest account has to include it.

So the sentence to carry out of this section is not "relax, they aren't listening." It is: they aren't listening, and that should worry you more, because it means the surveillance has become efficient enough not to need your voice. Chasing the microphone myth spends the public's entire supply of alarm on the wrong organ โ€” and every hour spent arguing about it is an hour not spent on the bid stream, which is where the harvest actually happens.

Camera and face

People fear the camera intuitively and misjudge it systematically. The documented record shows very little covert filming by ordinary apps, and a great deal of harm from three other mechanisms.

Mechanism one: institutions that already hold the camera. In Robbins v. Lower Merion School District, a Pennsylvania school district issued 2,300 laptops running remote-activation theft-tracking software. Forensic recovery in the litigation found at least 66,503 images in total, of which 30,564 were webcam photographs and 27,428 were screenshots, with an unknown further number deleted by district staff; activation evidence was found on 177 laptops across 2008โ€“2010. One student was confronted by an assistant principal over conduct seen in a webcam image taken in his home. A second student had 469 webcam photos and 543 screenshots taken over roughly two months and was told only five months after it stopped. The district settled for $610,000 in October 2010. On 17 August 2010 the US Attorney announced no criminal charges โ€” no evidence anyone had acted with criminal intent beyond a reasonable doubt. The forensic record is complete; the accountability is what was missing.

In May 2023 the FTC alleged that Ring gave employees and outsourced contractors unrestricted ability to download, view and share customer videos, including footage of bedrooms and children's bedrooms; that one employee viewed thousands of recordings belonging to female users over several months, stopping only when a colleague noticed; and that the company failed until January 2018 to obtain consent for human review of recordings used to train algorithms. Ring paid $5.8 million and โ€” critically, and this is the most transferable remedy in the whole casebook โ€” was ordered to delete not only the unlawfully reviewed videos but the data products, models and algorithms derived from them. Ring settled without admitting liability. Note precisely where the fault lies: the mechanism is a corporate decision to grant unrestricted access to an outsourced workforce. Any actor holding that access could do the same. The nationality of the contractors is not the hazard and must never be presented as one. In a separate 2021 incident, a group obtained super-admin access to a cloud camera vendor, Verkada, and held network access for about 36 hours; reporting put the exposure at approximately 150,000 cameras inside hospitals, jails, schools and factories, and the company later stated that 95 customers' video and image data was accessed.

Mechanism two: images we published ourselves, scraped. Clearview AI built a face-search engine from images scraped from the open web. Every figure the company gives for its database size โ€” 3 billion in 2020, 10 billion in 2021โ€“22, 30 billion in 2023, 50 billion-plus more recently โ€” is the company's own marketing claim, never independently audited. This study applies to it the same rule it applies to Cambridge Analytica: a vendor's boasts are the least reliable evidence in any case. Regulators fined it regardless โ€” Italy โ‚ฌ20m, Greece โ‚ฌ20m, France โ‚ฌ20m plus overdue-compliance penalties, the Netherlands โ‚ฌ30.5m with a warning of personal director liability, and the UK more than ยฃ7.5m. Almost none of it has been paid; the privacy group noyb filed a criminal complaint in October 2025 precisely because the fines went uncollected. (The UK penalty was set aside on jurisdictional grounds in October 2023 and the jurisdictional question went on appeal; our verification pass could not confirm the appellate disposition, so we do not report the penalty as reinstated.) Meanwhile the company held government contracts through the same period. Announcing a penalty is not the same as enforcing one.

Where enforcement did bite, it came from an unexpected place: a single US state statute. On 9 May 2022 the company settled a case brought under the Illinois Biometric Information Privacy Act, agreeing to a permanent, nationwide bar on making its faceprint database available to most private entities and individuals anywhere in the United States. In the consolidated class action, the court granted final approval on 20 March 2025 to a settlement in which class members receive a 23% ownership stake in the company (valued around $51.75 million) โ€” because a cash settlement would have bankrupted it. Per-person recovery is expected to be negligible. The harm exceeded the company's entire value. Consumer face-search is now a retail product: PimEyes, launched in Poland in 2017 and since relocated through Seychelles and Dubai corporate structures, searches the open web for other images of a given face; complaints and proceedings have been opened in the UK, Germany and Illinois, but no fine or final decision against it is documented in the public record โ€” a striking contrast. Harvard students demonstrated chaining smart glasses to that service and to people-search databases to obtain strangers' names, phone numbers and home addresses.

Mechanism three: children's photographs, and what is now made from them. Human Rights Watch found identifiable photographs of Brazilian children (10 June 2024) and Australian children (July 2024) in LAION-5B, the scraped dataset used to train widely deployed image models โ€” birth photos, birthday parties, school presentations, some with names in the caption or the address. Some came from sources with restrictive privacy settings, including unlisted video uploads. HRW reviewed less than 0.0001% of the dataset. By 3 September 2024 the dataset's stewards had removed links for 720 identified Australian and Brazilian children.

The Internet Watch Foundation reports that fine-tuning can produce deepfakes of a specific named child from as few as 20 existing images, in as little as 15 minutes. Its 2025 figures: 8,029 AI-generated images and videos assessed as depicting realistic child sexual abuse, and a catastrophic shift in format โ€” 3,443 AI-generated videos in 2025 against 13 in 2024. Sixty-five per cent of those videos fell into the most severe classification under UK law. Girls were the subjects of 97% of AI-generated images assessed. Confirmed AI-generated abuse webpages rose about 400% between the first half of 2024 and the first half of 2025. The Foundation notes that models can be fine-tuned on existing abuse imagery, directly re-victimising identified survivors. The Tech Transparency Project puts "nudification" apps at more than $122 million lifetime revenue across 483 million downloads. In July 2026 the San Francisco City Attorney was reported to have sent cease-and-desist letters to Apple and Google naming thirteen such apps; on that reporting, three of the eight named on one store were removed and ten of the thirteen remained available. (We flag that last item as reported rather than independently verified, and we have dropped two related figures our verification pass could not open.)

Twenty images is the exposure budget. That is the single most useful number a parent can carry out of this section โ€” and the remedies are concrete: share children's images in closed groups rather than public feeds; strip location metadata; and if an intimate deepfake of an adult or a child appears, use StopNCII (adults) or NCMEC's Take It Down (under-18s), both of which compute a cryptographic hash on your own device so participating platforms can block the image without you ever uploading it.

Law has arrived, and it carries its own risk. The US TAKE IT DOWN Act was signed on 19 May 2025, criminalising publication or threatened publication of non-consensual intimate imagery including AI "digital forgeries"; covered platforms had until 19 May 2026 to build a notice-and-removal process that pulls a reported image within 48 hours and makes "reasonable efforts" on identical copies. The UK's Online Safety Act 2023 extended the offence to images that "appear to show" a person, and the Data (Use and Access) Act 2025 added an offence of creating or requesting creation of a purported intimate image without consent. South Korea's 2024 amendments raised maximum penalties to roughly three years for possession or viewing and seven for creation or distribution. The EU AI Act's Article 5(1)(e) bans building or expanding facial recognition databases through untargeted scraping of internet or CCTV images, applicable from 2 February 2025. And this study names the cost of its own remedy: a 48-hour takedown duty with a "reasonable efforts" copy standard and a regulator behind it pushes small and encrypted services toward removing first and asking later. The concrete abuse vectors are bad-faith notices used against journalists; survivors who repost their own evidence being swept up; and services that cannot inspect content at all. That risk was flagged during passage rather than proven in practice โ€” we record it as a risk, and we hold the framing: support the offence, and demand the fences.

On face-recognition error, the honest picture is two-tiered โ€” and one popular statistic is wrong. "Face recognition misidentifies Black women about 35% of the time" is usually attributed to Gender Shades (Buolamwini & Gebru, 2018). That study measured gender classification on three commercial facial-analysis systems โ€” up to 34.7% error for darker-skinned women versus 0.8% for lighter-skinned men. It says nothing directly about whether a system can match your face to a mugshot. Both findings are real and damning; conflating them lets vendors dismiss the whole critique on a technicality, which has repeatedly happened. The correct evidence on identification is NIST Interagency Report 8280 (December 2019): 189 mostly commercial algorithms from 99 developers, tested against 18.27 million images of 8.49 million people. "Across demographics, false positive rates often vary by factors of 10 to beyond 100 times." On high-quality photographs, false positives were highest for West and East African and East Asian faces and lowest for Eastern Europeans โ€” "however, with a number of algorithms developed in China this effect is reversed, with low false positive rates on East Asian faces." That reversal is the single most important sentence in the report. Bias here is a training-data artefact, not a property of anyone's face. No population's faces are harder to recognise; some populations are absent from the training set and over-represented in the mugshot database. The machine is not describing a people. It is describing its own diet.

What that error costs a person. Detroit police arrested Robert Williams outside his home in January 2020, in front of his wife and two young daughters, on a false match between a store surveillance still and his driver's licence photo; he was held about 30 hours. On 28 June 2024 the case settled for $300,000 plus binding policy: no arrest based solely on a face-recognition result or on a photo lineup derived from one; no lineup from a face-recognition lead without independent reliable evidence; mandatory officer training; and an audit of every case from 2017 to 2023 in which face recognition supported an arrest warrant. No agency is required to record face-recognition-driven arrests, so a national total is not knowable from public data โ€” treat any specific national figure with caution, including ones that support this study's argument.

And the objection has to move with the evidence. The Metropolitan Police report that between September 2024 and September 2025, 203 live facial recognition deployments produced 2,077 alerts and 962 arrests, with 10 false positives and no arrests arising from a false alert, against more than three million faces scanned. The National Physical Laboratory's 2023 independent evaluation found roughly 1 in 6,000 falsely matched at that operational threshold, with no statistically significant race or gender bias โ€” with the crucial caveat that equitability is threshold-dependent and does not transfer to other vendors or deployments. (Of the ten reported false alerts, eight involved Black people; that sample is far too small to support a statistical claim in either direction and must not be reported as one.) So the strongest honest objection to live facial recognition is no longer accuracy. It is that three million people were scanned without suspicion, against a watchlist and a threshold set without public consent โ€” and accuracy gains make suspicionless scanning more attractive, not less.

Two more corrections this section owes you. First, the camera indicator dot. Since iOS 14 the green and orange dots are drawn by the operating system from sensor-activity data and cannot be suppressed by ordinary applications; Android 12 added equivalents. On 19 February 2026 Jamf published analysis showing that Intellexa's Predator spyware suppresses both dots with a single hook into a system process โ€” and Jamf is explicit about the precondition: the technique "requires a device to first be fully compromised, including kernel-level access." So: trust the dot for ordinary app-store risk; do not rely on it alone if you are a plausible target for commercial spyware, and use a physical slider on laptop and external webcams, because that is the only defence that survives a full compromise. Second, the stale scare-statistics. "96% of all deepfakes are pornography" comes from a September 2019 snapshot of 14,678 videos. Quoting it now is wrong twice over: the ecosystem is orders of magnitude larger, and the victim profile has shifted from celebrities to ordinary women, colleagues and schoolgirls. The stale statistic understates today's harm while sounding alarming. Likewise the widely recirculated forecast that "sharenting" will cause two-thirds of identity fraud against young people by 2030: that is a 2018 bank projection with no published methodology, dataset or validation. Quote it as an unverified projection, or not at all. The evidenced harms of posting children's images are different and much better documented โ€” presence in AI training corpora, and use as source material for AI-generated abuse imagery.

The sensors nobody asks permission for

Revoking microphone permission does not close the audio channel entirely, because the motion sensors need no permission at all on either major platform and are reachable from web content.

  • Gyrophone (Michalevsky, Boneh & Nakibly, USENIX Security 2014): the tiny gyroscopes in a phone are sensitive enough to register acoustic signals nearby. The captured signal carries only very low-frequency information, but signal processing plus machine learning made it sufficient to identify speaker characteristics and parse some speech. Honest calibration: this is low-fidelity โ€” speaker identification and constrained-vocabulary recognition, not transcription of an ordinary conversation, with no evidence of commercial deployment.
  • Spearphone (Anand et al., ACM WiSec 2021): speech played through a phone's own loudspeaker propagates through the device body into the accelerometer, which requires no permission. Off-the-shelf machine learning achieved gender classification above 90% and speaker identification above 80%; a later attack reconstructed arbitrary audio played on the loudspeaker. The critical limit, frequently lost in coverage: these attacks target audio produced by the device's own speaker โ€” the other side of a call, an assistant's reply, a voice message โ€” not what you say to a person beside you.
  • The mitigation has already been defeated in research. A rate limit was imposed on permission-free access to these sensors; a 2025 paper (STAG) deliberately induces temporal misalignment between two sensors and fuses their streams to resample above the cap. No public reporting indicates this is deployed in the wild; it is a research capability and must be described as one.

The lesson is architectural, not alarming. The permission model you were taught to rely on โ€” "I'll just deny microphone access" โ€” is a partial defence against a category of app-level risk, and not a wall. Permissions govern the sensors somebody thought to name. They do not govern inference from sensors nobody thought to name, and the list of sensors keeps growing.

Contacts, and the fact that consent is not individual

The most efficient way to take data about you has never been to take it from you. It is to take it from the people who know you.

Between 2013 and 2015, an app called "thisisyourdigitallife" was installed by roughly 270,000 people. Facebook's then-permitted friends API turned that into data on up to 87 million profiles โ€” people who never installed anything and never consented. (Press reporting in March 2018 put the figure at 50 million; Facebook's own first estimate, published 4 April 2018, was up to 87 million.) The researcher's firm transferred it to SCL/Cambridge Analytica in breach of platform terms. Facebook did not sell the data โ€” and the precision matters enormously, because the actual failure was permissive architecture plus non-enforcement, which is a far more common and far more fixable failure than corrupt sale. The UK regulator, which seized 42 laptops, 31 servers and about 700 TB of data, found that the harvested fields functioned as a join key onto pre-existing commercial and voter databases rather than as a standalone weapon.

Then there is the graph without any content in it. AT&T disclosed on 12 July 2024 that records of calls and texts for "nearly all" its wireless customers โ€” and customers of smaller operators on its network โ€” for a six-month window in 2022 had been downloaded from its cloud data warehouse. The files contained the phone numbers called and texted, counts and durations, plus, for a subset, cell-site identifiers revealing approximate location. No content was taken. The intrusions across that 2024 cluster of cloud-warehouse breaches exploited customer credentials stolen by information-stealing malware where multi-factor authentication was not enforced. The company reportedly paid roughly $370,000 for a deletion video โ€” a promise with no verification value whatsoever.

Content is the least interesting layer. Who you call, how often, for how long, and from where reconstructs your family, your workplace, your affair, your union organising, your lawyer, your doctor, your journalist source. The US Privacy and Civil Liberties Oversight Board's report of 23 January 2014 on bulk telephone metadata is the definitive statement of what that layer is worth to a state โ€” and, revealingly, of what it delivered: "we have not identified a single instance involving a threat to the United States in which the program made a concrete difference in the outcome of a counterterrorism investigation."

The structural point, and it is one of the two or three most important sentences in this study: you cannot consent your way out of a social graph. Your caution protects you only as far as the least cautious person in your address book. Consent is not individual, because data is relational.

Behaviour โ€” the layer that makes the microphone unnecessary

The clickstream, sold by the company you bought for protection. A joint Motherboard/PCMag investigation published 27 January 2020 showed that Avast's Jumpshot subsidiary marketed "Every search. Every click. Every buy. On every site" โ€” derived from browser-extension and antivirus telemetry across roughly 100 million devices, sold to corporate clients. The data was nominally de-identified but included timestamped URL-level click streams. State the re-identification claim precisely: researchers demonstrated that a buyer holding its own timestamped transaction records could join them to the click stream and single out individuals; whether any buyer actually did so has not been established. Jumpshot was shut down three days later. The FTC's order of 22 February 2024 imposed $16.5 million, banned the company from selling or licensing browsing data for advertising, and required deletion of the transferred data and of models derived from it.

The identity graph. Oracle's chairman stated in 2016 that there were five billion people in the Oracle ID Graph, an identity-resolution product described as letting customers track individuals across devices and channels. In August 2022 three researchers and campaigners filed a class action alleging surveillance of people with no relationship to Oracle; the case settled, widely reported at $115 million, with objections and appeals following.

The segments, and the price. A Dun & Bradstreet list live in October 2023 contained 130,293 segments, including "Government โ€“ Intelligence and Counterterrorism" in sixteen European countries, senior military officers, and military spouses and families; the US edition contained 38,786 segments including defence-department workers. The same lists carry segments indicating depression, chronic pain, substance abuse, likely survivors of sexual abuse, sexual orientation, gambling and debt โ€” which is to say, the classic recruitment levers of human intelligence, sold retail. And a Duke University team, funded by the United States Military Academy, approached brokers from both a .org and a .asia domain and obtained non-public, individually identified, sensitive data on active-duty servicemembers, their families and veterans โ€” including health data, financial data and information about religious practice โ€” for as little as $0.12 per record. Brokers' checks on who the buyer was were inconsistent, and the inconsistency persisted when the buyer appeared to be outside the United States.

Here is what this reveals about you. Everything the microphone would have told them, plus your intentions before you speak them. A pregnancy is visible in purchase and search behaviour weeks before it is announced. A relapse is visible in location. A job hunt is visible in browsing. A diagnosis is visible in the route you take on a Tuesday afternoon.

Three surfaces people forget: the television, the classroom, the genome

The television. Automatic content recognition is the deployed, industrial, screen-level equivalent of everything above, sitting in hundreds of millions of living rooms. A black-box audit of Samsung and LG televisions presented at the ACM Internet Measurement Conference in 2024 ("Watching TVs Watching Us") found that content recognition continues to operate even when the television is used purely as an external display over HDMI โ€” that is, it fingerprints content the television did not stream, including a laptop or a games console โ€” with measurable differences between the US and UK implementations. Critically for the remedy: opting out did stop transmission to the recognition servers. An earlier US enforcement action established the pattern: a manufacturer paid $2.2 million over collecting second-by-second viewing data from millions of televisions and selling it for audience measurement and targeting. Content recognition needs no microphone, no app, no permission and no advertising identifier โ€” and it is opt-outable. It is simultaneously among the most invasive and the most fixable things in this study, which makes it the best teaching example we have: go into your television's settings tonight and turn it off.

The classroom. Human Rights Watch's report of 25 May 2022, "How Dare They Peep into My Private Life?", analysed 163 education technology products endorsed by 49 governments for children's use during the pandemic. 145 of them โ€” 89% โ€” surveilled or could surveil children, sending data to 196 third parties, overwhelmingly advertising technology. Of 73 apps analysed for identifiers, 41 could collect advertising IDs, 21 (29%) collected precise GPS, and 14 accessed "inescapable" identifiers โ€” a device's network hardware address or its equipment identity number โ€” that persist even after a factory reset. Only one government of those studied avoided endorsing products with identified privacy risks, and 39 of 42 governments that built their own products created systems that risked children's rights. That single study repairs three gaps at once: children, school surveillance, and an evidence base that is otherwise overwhelmingly Anglo-American โ€” it covers 49 countries, not five. And note the finding inside the finding: an identifier that survives a factory reset survives resale, so a second-hand phone is not a fresh start.

The genome. Every other harm in this study is about a person's behaviour. Genetic data is about their relatives, including the ones not yet born; consent is structurally impossible, because when you spit in a tube you disclose for your siblings, your parents and your children. In October 2023 a credential-stuffing compromise at 23andMe affected roughly 6.9 million users โ€” about half the customer base โ€” and the attackers specifically compiled and offered for sale lists targeting people of Ashkenazi Jewish and Chinese descent. That is not identity theft; that is ethnic target-list construction from a consumer genealogy product, and it is the sharpest possible illustration of this study's rule: the capability is in the data, and the buyer supplies the intention. The company filed for Chapter 11 bankruptcy protection on 23 March 2025, and the genetic database of some 15 million people became a bankruptcy asset โ€” bid at $256m, rebid, and finally acquired for $305m by a nonprofit founded by a company co-founder, closing on 14 July 2025. The UK regulator fined the company ยฃ2.31 million in June 2025 for inadequate protections including absent multi-factor authentication and slow breach response.

Why the genome case belongs at the centre of this study and not at its margin. It is the cleanest proof of the strongest structural claim we make: a promise made by a company is only as durable as the company. The privacy policy a customer agreed to in 2018 was, in 2025, an asset in a bankruptcy estate. No fine, no consent form, no encryption addressed that. Only not collecting would have.


The chain โ€” the journey of one tap

Picture the tap. You open a free game on a bus. Between your finger touching the glass and the first frame appearing, the following happens, in under 200 milliseconds.

Link 1 โ€” the software development kits inside the app

The app is not one program. It is your developer's code plus a stack of third-party kits: an ad network, an analytics library, a crash reporter, an attribution tracker. Median: 11 tracker hosts from 5 distinct companies per Android app; 91.37% of apps carry at least one; the maximum observed in a single app was 45 companies โ€” and among the 68 apps referencing more than 40, 34 were photo editors and 21 were dating apps (Kollnig et al., 2021, analysing nearly two million free apps).

You were almost certainly never asked. In a representative sample of 1,201 apps from the UK Google Play Store, only 9.9% asked for any form of consent, and only 42 apps โ€” 3.5% of the sample โ€” gave a genuine choice to refuse. Of those that asked, 43.7% offered a single "accept" button and a further 20.2% exited immediately on refusal. Apps contacted an average of 2.9 tracker hosts at first launch before any interaction at all, and 58.6% contacted at least one Google domain (Kollnig et al., SOUPS 2021). The paper's own careful conclusion is "potentially widespread violations" of European and UK law โ€” not proven violations.

And iPhones are not a sanctuary. A study of 12,000 iOS and 12,000 Android apps found a median of 3 tracking libraries per app on both platforms; 88.73% of Android and 79.35% of iOS apps contained at least one. The authors concluded that neither platform was clearly better across the dimensions studied.

Link 2 โ€” the advertising identifier

To sell an ad, the kit needs a name for you. It uses the platform's advertising identifier โ€” a resettable pseudonym. Resetting it is largely theatre when the same app also ships a permanent identifier. Of 3,454 children's Android apps found sharing the resettable identifier with advertisers, 66% also transmitted other, non-resettable persistent identifiers, which the authors concluded negates any privacy-preserving property of the reset (Reyes et al., 2018, analysing 5,855 of the most popular free children's apps).

Apple's App Tracking Transparency (2021) genuinely killed the cross-app identifier for third parties. It did not remove the trackers. In a before-and-after comparison of 1,759 UK App Store apps, the median number of tracking libraries stayed at 3, apps containing at least one rose from 86.39% to 87.52%, and the average number of tracking domains contacted at first launch rose from 4.0 to 4.7. Researchers found nine apps computing a shared cross-app identifier from device characteristics sent to an analytics provider's servers โ€” a fingerprint by another name, in breach of Apple's own rules; reported in November 2021, the behaviour persisted in February 2022, now additionally encrypted. (And the popular "96% of users opted out" figure is wrong: it came from an early measurement with a different denominator. Measured against users who actually saw the prompt, roughly half consent globally.) On 31 March 2025 France's competition authority fined Apple โ‚ฌ150,000,000 for abuse of dominance in how it implemented the framework โ€” holding the objective legitimate but the implementation neither necessary nor proportionate, noting that refusing tracking took one tap while consenting required a second confirmation, and that until iOS 15 Apple did not ask consent for its own apps at all. That is the general law worth carrying: a privacy remedy designed by a gatekeeper concentrates power in the gatekeeper.

The other promised fix is gone. On 22 April 2025 Google announced it would maintain third-party cookies in Chrome with no standalone prompt, and on 17 October 2025 it retired eleven Privacy Sandbox technologies across Chrome and Android, citing "low levels of adoption". The UK Competition and Markets Authority closed its four-year investigation into them the same day. Any strategy still built around "the cookieless future" is planning for a world that was cancelled.

Link 3 โ€” the real-time bidding auction

Now the ad slot goes to auction. A bid request is broadcast: your advertising identifier, your IP address, your device model, the app you are in, often your coordinates, and whatever segments have been attached to you. Every participating bidder receives it โ€” including the ones that lose.

How many recipients? Google's own published vendor lists name 2,051 entities that may receive data from its US auctions and 1,102 for Europe; Microsoft states 1,647 firms may receive data from its Xandr auctions. Because a single slot is often auctioned by several exchanges at once, one impression can reach many more buyers than any single list suggests. There is no gatekeeping on who may operate a demand-side platform and thereby receive the feed directly. Industry documentation itself concedes that after a broadcast "there is no technical way to limit the way data is used" โ€” a conclusion echoed by 27 EU supervisory authorities and the UK regulator.

How often? The Irish Council for Civil Liberties reconstructed the volume at 178 trillion broadcasts a year about people in the US and Europe, or 747 exposures per day for the average US internet user and 376 for the average European (16 May 2022). Use the right verb. This is a careful estimate, not a measurement: the methodology note records that the underlying volume comes from industry figures whose source is confidential, divided by population with an assumption about how many people are online โ€” and the organisation states plainly that the figure is a low estimate because the dataset excludes two of the largest platforms. The defensible claim is the order of magnitude: hundreds of broadcasts per person per day. The structural evidence beside it โ€” Google's own list of 2,051 US recipients โ€” needs no caveat at all, and that is the number to argue from.

And the consent framework built to make this lawful was itself found unlawful. On 2 February 2022 the Belgian Data Protection Authority found the advertising industry's Transparency and Consent Framework โ€” the mechanism encoding your preferences into a short string passed through the auction protocol โ€” in breach of the GDPR, fined the trade body โ‚ฌ250,000 and ordered corrective measures. The Court of Justice of the European Union subsequently ruled in Case C-604/22 (7 March 2024) that such a string is personal data where it can be linked to an identifier such as an IP address, and that a sectoral body is a joint controller for it. (We cite this by case reference; the judgment text was not directly retrieved in our verification pass.)

Link 4 โ€” the broker who simply listens

Here is the link almost nobody knows about, and it is the one that makes "just use trustworthy apps" a weak defence. A broker does not need to be inside your app. It only needs to bid โ€” and lose.

On 3 December 2024 the FTC alleged that Mobilewalla bid into real-time auctions and kept the data in the bid request even when it did not win โ€” collecting, between January 2018 and June 2020, more than 500 million unique advertising identifiers paired with precise location, retained indefinitely and sold on. It built audience segments from women visiting pregnancy centres, and produced a June 2020 report analysing people who protested the death of George Floyd, inferring their racial backgrounds and whether they lived in the cities where they protested. The agency noted this was the first time it had alleged that harvesting bid-stream data was an unfair practice. The proposed order bans the company from collecting or retaining auction data for any purpose other than participating in the auction.

One month later, the mechanism was proved in public. In January 2025, hacked files from Gravy Analytics surfaced, listing thousands of ordinary apps whose users' locations appeared in the broker's data โ€” a match-three game, a dating app, a fitness tracker, pregnancy trackers, prayer apps, on both major platforms. The researcher who reviewed the data assessed that it came predominantly from the bid stream rather than from kits the developers installed โ€” meaning many named developers had no commercial relationship with the broker and no way to know (404 Media, 9 January 2025).

That is the whole architecture in one sentence: any app that shows a programmatic advertisement can leak a coordinate into an auction that hundreds of companies observe. Which also means that blaming individual developers misdirects reform away from the ad-exchange layer, where the fix belongs โ€” and that the cheapness cuts both ways. A market this cheap is one whose leak point is a single message format at a handful of exchanges.

Link 5 โ€” the buyer, and the step that turns merchandise into a person

And then it is simply merchandise. Advertisers, obviously. Local police: one vendor had at least 18 documented state and local law-enforcement clients, at $6,000โ€“$9,000 a year, with no limits on individual officers' use and no routine auditing. Federal agencies: the US Department of Homeland Security's Inspector General reported in September 2023 that three of its components did not adhere to departmental privacy policies or to the E-Government Act of 2002, which requires an approved privacy impact assessment before privacy-sensitive technology is procured โ€” and that the department had no policy on commercial telemetry data at all. (The report's specific contract figures could not be re-verified in our pass and are omitted.) Anyone with a plausible story: the surveillance trial obtained by asserting contemplated government work. Anyone with twelve cents: the Duke purchase.

Two peer-reviewed results anchor the re-identification question, and both must be stated exactly. De Montjoye et al. (2013): four spatio-temporal points uniquely identify 95% of individuals in a 1.5-million-person mobility dataset. Rocher, Hendrickx and de Montjoye (Nature Communications, 2019) built a generative model estimating that 99.98% of Americans would be correctly re-identified from 15 demographic attributes, and 79.4% of Massachusetts residents from postcode, date of birth, gender and number of children โ€” concluding that release-and-forget de-identification is unlikely to meet the European standard. Both establish uniqueness, not naming. Turning a unique trace into a person requires auxiliary information, which in practice is abundant but is a step, not an automatic consequence. (The 99.98% figure is a modelled probability, publicly contested in the peer-reviewed literature, and it is a demographic result rather than a location one.) Regulators have adopted the substance: the FTC states plainly that raw location tied to a mobile advertising identifier "is not anonymized", and notes that companies exist which will do the matching.

Do not overcorrect into fatalism. Aggregation can fail badly โ€” a fitness company published a global heatmap of two years of aggregated activity in November 2017, and in January 2018 an Australian National University student, Nathan Ruser, showed it outlined military bases in Syria, forward operating bases in Afghanistan and a naval base in Scotland; in October 2024 Le Monde showed the same app exposed movements of security teams protecting two heads of state. And "aggregate" commercial data has been sold in a form that is not aggregate in any protective sense: Motherboard bought a week of foot-traffic data covering more than 600 Planned Parenthood facilities for just over $160, showing where visitors came from at census-block level, how long they stayed and where they went next. But properly designed release โ€” genuine coarsening to populations rather than devices, noise-added statistics, on-device computation, short retention โ€” is qualitatively different from selling identifier-keyed traces. The correct posture is: distrust the word "anonymised", demand the method, and prefer designs where the precise coordinate never leaves the handset.

Where the law currently stands on this chain

  • California's Delete Act produced DROP, the Delete Request and Opt-out Platform, available to California residents from 1 January 2026, with brokers required to begin processing deletion requests on 1 August 2026 and thereafter at least every 45 days. It is the first universal-delete mechanism anywhere. It is also a 2026 right, not a 2024 one, and it does not reach the bid stream. The registry lists 545 registered brokers for 2025; on their own disclosures, 88 collect precise geolocation, 19 collect minors' personal information, and 10 collect reproductive health care data.
  • PADFAA (US, effective 23 June 2024) makes it unlawful for a data broker to make Americans' personally identifiable sensitive data available to a "foreign adversary country" or an entity at least 20% owned by one โ€” with sensitive data expressly including precise geolocation, health, biometric, genetic and financial data, private communications, information about anyone under 17, race and religion, and information revealing service in the armed forces. There is no private right of action, and no publicly announced enforcement action under it could be located. It prohibits a flow, which is not the same as stopping it, and it regulates only the last hop. Say the harder thing plainly: a law framed around foreign adversaries is a partial remedy for a mechanism that is overwhelmingly domestic in every country where it operates.
  • The US Data Security Program (final rule December 2024, effective 8 April 2025) is sharper. Its bulk thresholds cover genomic data on more than 100 US persons; other biometric or precise geolocation data on more than 1,000; health or financial data on more than 10,000; covered identifiers on more than 100,000. Critically, the rule applies "regardless of whether the data is anonymized, pseudonymized, de-identified, or encrypted." That is a federal regulation refusing the anonymisation defence, and it is the most quotable sentence in the whole legal record.
  • India's Digital Personal Data Protection Act 2023 requires itemised notice in English and all 22 scheduled languages โ€” but creates no "sensitive personal data" category at all: precise geolocation is treated like any other personal data, and Section 17 permits broad exemptions for instrumentalities of the State. Section 8 below sets out what an Indian reader can use today.

The casebook

Only legally established or thoroughly investigated matters. Each entry names the date, the actor, the mechanism, the harm and the outcome. Where something is an allegation, an indictment or a settlement without admission, it says so.

Function creep โ€” the pattern this study is built on

1943 โ€” a census bureau to a security service. Confidentiality protections on US census data were suspended in March 1942 under the Second War Powers Act and not restored until 1947. Historians Margo Anderson and William Seltzer documented, in papers published in 2000 and 2007, that the Bureau provided neighbourhood-level tabulations to the War Department to support exclusion and โ€” in the later finding, from recovered documents โ€” individually identifying information on 79 named people of Japanese ancestry in the Washington DC area to the Secret Service. The Bureau publicly acknowledged the block-level role in 2000 and the microdata disclosure after 2007. This is the load-bearing case, and its power is in the framing: the collectors were not villains, the promise of confidentiality was sincere when made, and a statute erased it within months.

1940 โ€” a civil registration system, in the Netherlands. An unusually complete population registration system, plus a near-unforgeable identity card the Dutch government had rejected in March 1940 as contrary to Dutch tradition, was implemented after the occupation; the occupation authorities built a central register of Jews linked to municipal registries. Roughly 27% of Jewish residents of the Netherlands survived, against far higher proportions in Belgium and France. Essential honesty: historians โ€” notably Marnix Croes (2006) โ€” attribute the Dutch outcome to several interacting causes: geography, the absence of an escape route, the structure of the occupation administration, and the efficiency of registration. The registry is a documented and significant factor. It is not a monocausal explanation, and this study does not claim it is. And the actor must be named precisely: an occupying regime and the administrative apparatus it captured. Never a people, never a nation's population, never a faith.

2016โ€“2018 โ€” Aadhaar, India. Confirmed: the identity authority acknowledged in November 2017 that around 210 government websites had published Aadhaar numbers with names and addresses; a May 2017 Centre for Internet and Society study estimated roughly 130โ€“135 million Aadhaar numbers and 100 million bank account numbers exposed via four government scheme portals; The Tribune reported on 4 January 2018 that for โ‚น500 an intermediary supplied credentials giving access to demographic details through a misused administrative search facility. Not confirmed: no verified compromise of biometric templates in the central repository has ever been established, and the widely circulated October 2023 claim that "815 million Indians' data" was for sale referred to health-testing records, not the identity repository. Outcome: in the Aadhaar judgment of 26 September 2018 the Supreme Court of India upheld the scheme for subsidies and tax filing but struck down Section 57 โ€” ending private-sector power to compel Aadhaar authentication โ€” and struck down mandatory linking to bank accounts and mobile connections, expressly on function-creep and proportionality grounds. Overstating the biometric-breach story hands the strongest counter-argument to anyone defending centralised identity โ€” and the true story is more than sufficient, because India's own Supreme Court made the function-creep argument for us.

Automated suspicion turned on citizens โ€” and stopped

5 February 2020 โ€” SyRI, Netherlands. The District Court of The Hague held that the risk-indication legislation violated Article 8 of the European Convention on Human Rights โ€” insufficient transparency, verifiability and safeguards for the fusion of tax, benefit, housing, education and debt data. The legislation was voided; the government did not appeal.

December 2021 โ€” the Dutch childcare-benefits affair. The Dutch data protection authority fined the Tax Administration โ‚ฌ2.75 million for processing applicants' (dual) nationality unlawfully and discriminatorily as a fraud-risk indicator. Tens of thousands of families were pursued for tens of thousands of euros. At least 1,115 children of affected families were placed in out-of-home care during the period โ€” later counts run above 2,000 โ€” though official research did not establish that the affair caused the removals. The cabinet resigned on 15 January 2021. Note the shape of the mechanism, and report the sorting without reproducing it: the harmed parties were dual-national families, the mechanism was a risk rule, the named actor is a tax administration.

2016โ€“2023 โ€” Robodebt, Australia. From July 2016 the government matched welfare records against annual tax-office income data and "averaged" it across fortnights, generating debts from a statistical artefact and reversing the onus of proof. Approximately 470,000 debts were wrongly raised. The Federal Court approved an A$1.872 billion settlement on 11 June 2021; the Royal Commission reported on 7 July 2023, calling it "a costly failure of public administration, in both human and economic terms". On deaths: the Commission recorded evidence of severe distress and of people who died after receiving notices, but made no finding of causation. This study does not assert one. State the proven administrative crime; do not borrow a death toll you cannot source.

The collection itself as the hazard

7 September 2017 โ€” Equifax. Attackers exploited a vulnerability in Apache Struts disclosed on 7 March 2017 and flagged to the company the next day; the patch was never applied to the consumer-dispute portal. A lapsed TLS certificate on a traffic-inspection device meant that exfiltration went unseen for 76 days. The identity files of 147.9 million Americans were taken, plus UK and Canadian records โ€” from people who were never its customers. The settlement with the FTC, the CFPB and 50 states and territories, announced 22 July 2019, was at least $575m and up to $700m; the UK regulator fined the British subsidiary ยฃ11,164,400 in October 2023. On attribution, carefully: the US Department of Justice indicted four members of China's People's Liberation Army in February 2020 โ€” an untested allegation: no trial, no conviction, no defendant in custody, denied by the government named. The mechanism, which is the point, is an unpatched public portal at a company holding files on people who never chose to deal with it โ€” and any actor who reached that portal would have obtained the same files. A reader can act on an unpatched server and an expired certificate. Nobody can act on an indictment.

Before you conclude that a fine measures an injury, read this. We can document the capability and the exposure; we very often cannot document the injury. No court has found that the psychotherapy-clinic breach or the automated-debt scheme caused a death. No national count of wrongful facial-recognition arrests exists, because no agency is required to record one. And the 147.9 million identity files taken from Equifax have never been seen for sale โ€” which means the damage from a catastrophic loss of personal data may be entirely real and still unmeasured. The compensation record says the same thing: that settlement's alternative-cash fund was capped at $31m across up to 147 million claimants, and the regulator publicly warned that so many people had claimed the $125 that payments would be "a small amount". The honest lesson is bleaker than the myth: a catastrophic loss of 147.9 million identity files produced neither meaningful compensation nor traceable criminal harm. The damage is unpriced and possibly unmeasurable, which is exactly why it recurs.

21 October 2020 โ€” Vastaamo, Finland. Intrusions in 2018 and 2019 exploited an exposed database with weak protection at a psychotherapy clinic chain. About 33,000 patients' records were taken, including names, addresses, national identity numbers and verbatim therapist notes covering suicide attempts, abuse and intimate disclosures. The attacker demanded 40 bitcoin from the company, then emailed roughly 30,000 individual patients demanding โ‚ฌ200โ€“500 each, and published at least 300 patients' notes when refused. Finland's Data Protection Ombudsman fined the company โ‚ฌ608,000; the perpetrator was convicted on 30 April 2024 and sentenced to six years and three months. Honesty note: Finnish media and victim advocates reported suicides among victims and authorities discussed the connection publicly, but no court has made a causal finding โ€” reported harm, not proven causation.

Intimate data through ordinary plumbing

A period-tracking app promised to keep health data private while sending events identifying menstruation and pregnancy intent to four analytics and advertising services; the FTC's order was final on 22 June 2021. Note the chronology, because it is routinely reversed: the complaint was January 2021 and the order June 2021 โ€” before the US Supreme Court's Dobbs decision of 24 June 2022. This is a before-and-after pattern, not an after-Dobbs one. A discount-prescription service paid $1.5m in February 2023 in the first enforcement of the Health Breach Notification Rule; a fertility app paid $100,000 in May 2023 and accepted a permanent ban on sharing user health data for advertising, for sharing cycle dates, temperatures, pregnancy status and hormone results through third-party kits. On 9 January 2024 the FTC entered what it described as its first order banning the sale of sensitive location data, against X-Mode Social / Outlogic, covering visits to reproductive health clinics, places of worship and LGBTQ+ venues; nine days later it banned InMarket Media from selling precise location, a company that maintained nearly 2,000 audience segment lists and retained geolocation for five years. In Norway, the data protection authority fined Grindr NOK 65 million (~โ‚ฌ6.5m) on 29 September 2023 for sharing users' GPS location, IP address, advertising identifier and app identity โ€” from which sexual orientation is inferable as special-category data โ€” with advertising partners without valid consent; the underlying technical testing by the Norwegian Consumer Council ("Out of Control", January 2020) found ten popular apps transmitting data to at least 135 third parties.

And the case that should end the phrase "but this app is for protection". In December 2021 The Markup found that Life360, a family-safety app marketed to parents with about 33 million users, sold precise location to roughly a dozen brokers. Data revenue grew from $693,000 in 2016 to about $16 million in 2020 โ€” nearly 20% of annual revenue โ€” plus $6 million from an insurance-analytics buyer. The chief executive said data was "an important part of our business model that allows us to keep the core Life360 services free." The app people install precisely to protect a child was itself a broker feed. Protective intent is not a protective architecture.

The state and the market, connected

29 April 2024 โ€” the four US carriers. The FCC issued forfeiture orders totalling nearly $200 million under the customer-proprietary-network-information statute. The mechanism: carriers sold access to "location information aggregators", who resold to location-based service providers; a prison-phone vendor used that chain, and a county sheriff used it to track individuals without legal process โ€” the abuse that triggered a US Senator's 2018 letters. Status caveat, and it is load-bearing: the carriers challenged these forfeitures across multiple federal circuits and at least one has been disturbed on appeal. Do not report the amounts in the flat past tense as collected.

Bulk telephone metadata. The Privacy and Civil Liberties Oversight Board reported in January 2014 that the programme had not made a concrete difference in a single counterterrorism outcome; an appeals court held in May 2015 that the statute never authorised bulk collection, and legislation ended it the following month. Even the successor targeted programme malfunctioned: in June 2018 the National Security Agency purged every call detail record it had collected since 2015 because of technical irregularities that produced records it was not authorised to receive, and the programme was shelved in 2019.

European data retention โ€” and the honest update. The Court of Justice invalidated the Data Retention Directive in 2014 and struck down general and indiscriminate national retention in 2016. But that is not the current position. From 2020 the Court substantially retreated: it now permits targeted and geographically limited retention, general retention of IP addresses for serious crime and national security, and expedited retention; a 2022 judgment reaffirmed that, and a 2024 judgment upheld IP-to-identity linkage for copyright enforcement. The principle held; the prohibition narrowed. Publishing the 2016 position as current is exactly the kind of error that lets an opponent discredit an entire argument.

22 August 2022 โ€” a remote-proctoring room scan. A chemistry student was required to pan his webcam around his bedroom before a remote exam; the scan was recorded and retained by a third-party proctoring vendor. The court held the university a state actor, found a reasonable expectation of privacy in the bedroom, and held that the student's privacy interest in his home outweighed the university's interest in scanning it. Important limit: the constitutional provision binds government actors, so this does not directly constrain private universities or employers. The parallel private-sector constraint is state biometric law โ€” the same Illinois statute that produced a $650m face-tagging settlement and forced the Clearview settlement.

29 June 2026 โ€” geofence warrants. A geofence or "reverse" warrant asks a provider for every device in an area and time window; Google reported 982 such demands in 2018, 8,396 in 2019 and 11,554 in 2020, by which point they were about a quarter of all law-enforcement requests to the company. The circuits split, and on 29 June 2026 the US Supreme Court held 6-3 that officers conducted a Fourth Amendment search when they acquired a defendant's Google location data, because an individual has a reasonable expectation of privacy in cellphone location information. The Court vacated and remanded rather than declaring geofence warrants unlawful in every case. It builds on Carpenter v. United States (2018), which required a warrant for 127 days of historical cell-site location information. A related, non-legal shrinkage matters more than either ruling: on 12 December 2023 Google announced that Timeline data would be stored on the device rather than in its cloud, with the auto-delete default dropping from 18 months to three. The company has not stated that it can no longer answer such demands, so "geofence warrants are dead" is an inference, not a fact. The honest statement: the central store those warrants targeted has been substantially reduced โ€” and a default change plus on-device computation removed a surveillance capability more effectively than years of litigation.

The surveillance-for-hire market โ€” and the fabrication case

2016โ€“2025 โ€” NSO Group and Pegasus. Amnesty International's Security Lab and Citizen Lab documented zero-click infection chains. In the July 2021 Pegasus Project, forensic examination of 67 phones from a leaked list found 37 with confirmed infection or attempted infection. The widely quoted 50,000 figure is not an infection count โ€” it was a leaked list of numbers apparently selected as of interest, and Amnesty explicitly stated it never presented that list as an infection list. Use 37 of 67. Confirmed targets over the years include a human rights defender in the UAE, associates and the fiancรฉe of Jamal Khashoggi, Mexican journalists and anti-corruption researchers, Catalan politicians and Salvadoran journalists. A US jury awarded roughly $444,719 compensatory and $167 million punitive damages against the company in May 2025 in the messaging-platform case; in October 2025 the court granted a permanent injunction barring the company from targeting that one platform โ€” a single-platform order that leaves its government customers and other platforms untouched โ€” and reduced the punitive award to roughly nine times compensatory. Honest gap: attribution of specific infections to specific government customers is often inferential; in India, a Supreme Courtโ€“appointed technical committee reported in August 2022 that malware was found on 5 of 29 phones examined but that it could not conclusively confirm Pegasus, and recorded that the government did not cooperate.

The case where data stopped being taken from people and started being put into them. In the Bhima Koregaon prosecutions in India, the Massachusetts digital-forensics firm Arsenal Consulting determined that incriminating documents โ€” including a letter purporting to plan an assassination โ€” were planted on the devices of the accused Rona Wilson and Surendra Gadling through a phishing-delivered intrusion, rather than authored by them; the security firm SentinelOne subsequently reported a connection between the infrastructure used and the police force involved, and the Washington Post reported in December 2022 that evidence was also planted on the computer of Stan Swamy, who died in custody in July 2021. Every other case in this casebook is about exposure. This one is about fabrication โ€” and no amount of "collect nothing" protects against it. Only device integrity, independent forensics and a right to have evidence examined do. It also belongs here for a second reason: it is a case in the country this study is written for, and it is better forensically documented than most of the Western cases beside it.

1 September 2021 โ€” a stalkerware company removed from the market. The FTC banned a company and its named chief executive from the surveillance business outright โ€” the first such ban it had obtained. The product harvested photos, messages, browsing history and location without the device owner's knowledge, stored data unencrypted, and transmitted purchaser passwords in plain text; the order required notifying device owners that the app had been secretly installed. (The ban is reported to have survived a later petition to vacate; we record that as reported rather than verified.) This is the remedy that works: it removed the capability rather than pricing it.

And the harm nearest to an ordinary reader's life. The adversary in most people's data lives is not a broker or a state. It is a husband, a father, a brother, an ex. A 2014 survey of US domestic-violence shelters found that 75% reported working with people who had been tracked by abusers using stalkerware. In a 2014 US federal case, a man installed a roughly $40 remote-access trojan on a former classmate's laptop, captured images through her webcam and demanded more under threat of publication; he was sentenced to 18 months, and pleaded to hacking 100โ€“150 women, including a 14-year-old. And the family-safety app above works exactly as advertised for a controlling partner or parent. The single most life-relevant instruction in this entire study is in Section 7, item 11, and we have moved it out of the footnotes on purpose: if you suspect stalkerware, do not delete it first.

The correction the casebook must make about itself

Cambridge Analytica. The data flow is documented. The mind control is not. The UK regulator, which seized the servers, reported that the systems relied on standard commercial datasets and voter files; that the data analysis techniques used were in the main commonly available and routinely used by other entities; that the firm's boast of thousands of data points on hundreds of millions of adults may have been an exaggeration; and that there was a degree of scepticism inside the firm as to the accuracy or reliability of the processing being undertaken. (We paraphrase these findings rather than quote them, because our verification pass did not open the source letter.) The regulator further found that the harvested data could not have been used in the Brexit referendum, because it concerned US-registered voters, and found no evidence the firm worked on the official referendum campaign. Expert testimony to Parliament was that personality-from-likes correlations were too weak to support the claimed effect.

The penalties, correctly attributed โ€” this matters, because the error is universal. The $5 billion penalty of 24 July 2019 was against Facebook, for violating its 2012 consent order; two of five Commissioners dissented that it was too weak. The SEC separately took $100 million for misleading investors. The ยฃ500,000 UK fine was against Facebook, not Cambridge Analytica โ€” the maximum available under the pre-GDPR statute, settled in October 2019 with no admission of liability. Meta settled the private class action for $725 million. Total: about $5.8 billion. And the fact that says the most: when the $5 billion figure was first reported on 12 July 2019, Facebook's share price rose. The market read the largest privacy penalty in history as cheap.

So say instead: up to 87 million people's data moved without their knowledge, no individual was meaningfully held to account, the maximum available European fine was set by an obsolete statute, and the vendor's own claims were the least reliable evidence in the entire case.

And one myth to kill because it is repeated in good faith by people who care. "A period-tracking app's data was subpoenaed and used to prosecute someone for an abortion in the United States." No such prosecution has been documented. The case invariably cited โ€” Nebraska, 2022 โ€” used Facebook Messenger conversations obtained by search warrant served on Meta, not menstrual-app data; the investigation began from a report about the disposal of remains, and the daughter had shown her own messages to a detective before the warrant issued. The real, documented risk from health apps is different and is proven by enforcement rather than prosecution: two apps leaked cycle and pregnancy data to advertising and analytics kits, and two location brokers sold traces of visits to reproductive-health clinics. Argue from the orders, which are established fact.


How repetition edits a mind

There is a body of cognitive science here that is old, replicated and boring โ€” and therefore trustworthy. There is also a popular sequel to it that is exciting and largely unsupported. The whole value of this section is in keeping them apart.

The documented core

Repetition makes a statement feel truer. Hasher, Goldstein and Toppino (1977) had participants rate plausible statements across three sessions two weeks apart; repeated statements were rated more valid than new ones. Dechรชne, Stahl, Hansen and Wรคnke pooled 51 studies in a meta-analysis and confirmed the effect. The proposed mechanism is processing fluency: repeated material is easier to process, and the mind misreads that ease as a signal of truth. Nearly fifty years of replication.

Knowing the truth does not protect you. Fazio, Brashier, Payne and Marsh (2015) tested statements that participants demonstrably knew the correct answer to, verified by a separate assessment. Repetition still increased truth ratings. They named it "knowledge neglect" โ€” the failure to consult stored knowledge when a claim arrives fluently. This directly refutes the intuition that education or expertise immunises anyone, including the author of a study like this one.

It works on implausible claims too, with one boundary. Fazio, Rand and Pennycook (2019) found repetition increased perceived truth equally for plausible and implausible statements. The boundary: extreme implausibility blunts the effect โ€” only a small degree of potential plausibility is needed for repetition to work.

The dose-response curve is logarithmic and does not flatten. Hassan and Barber (2021) showed statements up to 9 times and up to 27 times. Perceived truthfulness rose logarithmically โ€” the biggest single jump is from the first exposure to the second โ€” with each further repetition adding less, but the curve did not flatten to zero within the range tested.

And it has been demonstrated in exactly the shape of a phone. Fazio, Pillai and Patel (2022) sent participants true and false trivia statements by text message over 15 days, at frequencies from 1 to 16 repetitions. Repetition increased belief, largest on early exposures, with continued smaller gains thereafter. Not a lab session โ€” a little at a time, embedded in ordinary life, across a fortnight. It decays, but slowly: a registered-report longitudinal study measured the repeated-minus-new truth gap at 0.68 immediately, 0.39 after one day, 0.27 after one week and 0.14 after one month, all statistically significant.

And it does not only change what feels true. It changes what feels acceptable. Pillai, Fazio and Effron (2023) ran a longitudinal experiment with headlines describing corporate wrongdoing. Repeatedly encountered descriptions were rated both truer AND less unethical than novel ones, with affective response mediating the moral softening. Familiarity dulled moral objection to the same conduct. Of everything in this section, that finding deserves the longest pause โ€” because it is the mechanism by which a population stops minding something it once would have marched about.

Mere exposure: familiarity alone increases liking, with no argument at all. Zajonc (1968) showed that repeated exposure to a neutral stimulus increased liking with zero persuasive content; a 1989 meta-analysis of over 200 experiments confirmed the effect is robust. And frequency-of-exposure masquerades as frequency-in-the-world: Tversky and Kahneman (1973) showed that people estimate probability by how easily instances come to mind, and Schwarz and colleagues (1991) refined it โ€” it is the subjective ease of retrieval, not the number of instances retrieved, that drives the judgement.

What ranking does with that machinery

Moral-emotional language increases sharing โ€” and mostly within one's own side. Brady, Wills, Jost, Tucker and Van Bavel (2017) analysed 563,312 tweets on gun control, same-sex marriage and climate change. Each additional moral-emotional word increased diffusion by roughly 20%. Amplification was strong within networks and weak between them: moral contagion is bounded by group membership.

Engagement-based ranking demonstrably amplifies anger โ€” and users say it makes them feel worse. Milli, Carroll, Wang, Pandey, Zhao and Dragan ran a preregistered audit in February 2023 with 806 US users, comparing an engagement-based feed against a reverse-chronological baseline drawn from the same sources. The engagement feed amplified anger (+0.47 SD), anxiety (+0.23 SD) and sadness (+0.22 SD); for political posts, anger amplification reached +0.75 SD, with out-group hostility +0.24 SD. Participants reported feeling worse about their political out-group after the engagement feed, and rated its political posts as less valuable than the chronological feed's. This is the cleanest causal evidence in the whole area, because the content pool was held constant and only the ranking changed.

Facebook's own documents show the same thing at population scale. The 2021 disclosures by Frances Haugen documented that the 2018 "Meaningful Social Interactions" News Feed change, which upweighted reshares and comments, was internally associated with increased anger on the platform and declining perceived feed quality, and that internal proposals to fix it were declined out of concern for engagement. Reaction emoji were weighted five times a Like, and a 2019 internal analysis found that posts drawing angry reactions were disproportionately likely to contain misinformation, toxicity and low-quality news. The angry weight was eventually reduced to zero. (We deliberately give no month for that reduction: published accounts differ and the commonly circulated chronology is internally inconsistent. Cite the substance, which is strong, not a date that is not.)

This is the most important claim in this section, and it needs no foreign actor at all. A single ranking-weight decision, made for commercial reasons by people who were not trying to do harm, measurably shifted the emotional climate of a population.

And recommender audits can produce alarming results in hours. Amnesty International (7 November 2023) ran more than 30 automated accounts posing as 13-year-olds in Kenya and the USA, plus manual accounts in Kenya, the Philippines and the USA. After 5โ€“6 hours, almost one in two videos served to the automated accounts were mental-health related and potentially harmful โ€” roughly ten times the volume served to accounts showing no such interest. In the manual tests, between 3 and 20 minutes after engaging with mental-health content, more than half of the recommendation feed related to mental-health struggles, including videos romanticising or normalising suicide.

What is contested โ€” stated plainly, because the honest version is more useful

Recommender radicalisation. This is genuinely contested, and the best-identified studies point away from the algorithm as prime mover for the average user. Ledwich and Zaitsev (2020) found the recommender favoured mainstream media over radical channels โ€” but measured logged-out, non-personalised recommendations, its central weakness. Ribeiro et al. (2020) found commenter migration toward more extreme channels โ€” evidence of a pathway, not proof the algorithm caused it. Hosseinmardi et al. (2021), tracking over 300,000 Americans, found far-right consumption was a small, stable share, correlated with off-platform consumption, with "no evidence that engagement with far-right content is caused by YouTube recommendations systematically." A 2024 follow-up using counterfactual bots found that following the recommender exclusively produced less partisan consumption than replaying real user behaviour, with the sidebar "forgetting" acquired partisan preference within about 30 videos. And Chen, Nyhan, Reifler, Robertson and Wilson (2023) found exposure to alternative and extremist channels was concentrated in people with high pre-existing resentment, and reached largely via subscriptions and external links rather than recommendations. What survives: a small, high-susceptibility minority receives very heavy exposure and can be escalated. That is a real duty-of-care problem. It is not the universal one.

Microtargeting effectiveness. Contested, and it cuts both ways. Matz, Kosinski, Nave and Stillwell (2017) reached over 3.5 million people and reported psychologically matched ads producing up to 40% more clicks and up to 50% more purchases; Eckles, Gordon and Johnson (2018) formally challenged the internal validity, since users were not randomised individually and the platform's own delivery optimisation is a live confound. Tappin et al. (2023), with 32,695 US adults and 74 messages, found microtargeting beat naive strategies under favourable conditions but in the harder scenario was no better than simply finding the single best message for everyone. Coppock, Hill and Vavreck (2020), across 49 real ads and 59 experiments, found the average persuasive effect of political advertising is small and โ€” critically โ€” homogeneous across partisanship, tone, timing and context, which leaves little room for targeting to exploit. Hackenburg and Margetts (2024) found machine-generated microtargeted political messages were not substantially more persuasive than well-chosen untargeted ones. And the best evidence on campaign persuasion generally, Kalla and Broockman's 2018 meta-analysis of 49 field experiments, found near-zero average persuasive effects of campaign contact in general elections โ€” with two precisions routinely lost: it measures campaign contact rather than digital targeting, and the authors explicitly find non-zero effects in primaries, on ballot measures, and where candidates take unpopular positions.

Influence-operation persuasion: measured, and close to zero. Eady, Paskhalis, Zilinsky, Bonneau, Nagler and Tucker (2023) linked a three-wave panel of 1,496 US Twitter users to 1.2 billion posts in their actual timelines across the 2016 campaign. Exposure was extraordinarily concentrated: 1% of users received 70% of all exposures; 10% received 98%. In the final campaign month the average respondent saw about 4 such posts per day against 106 from national news media and 35 from politicians, and exposure was roughly nine times higher among strongly-identifying Republicans โ€” that is, concentrated on people already voting that way. Regression and equivalence testing found no significant relationship between exposure and changes in issue positions, perceived polarisation, or vote choice. The authors themselves warn against over-reading it: one platform only, and it says nothing about second-order harms such as damage to faith in electoral integrity.

Large platform field experiments repeatedly find near-zero attitudinal effects. In the 2020 US election study collaboration: switching users to a reverse-chronological feed for three months increased exposure to political and untrustworthy content and cut time on platform, yet "did not significantly alter levels of issue polarization, affective polarization, political knowledge, or other key attitudes". Removing reshares for three months cut untrustworthy-source exposure and news knowledge but did not significantly affect polarisation. Reducing like-minded content by about a third across 23,377 users had no measurable effects on eight preregistered attitudinal measures. Deactivating 19,857 Facebook and 15,585 Instagram accounts for six weeks before the election produced effects that were "precisely estimated and close to zero".

This study cites those nulls against its own thesis, deliberately. If our epistemic standard is "show me the measured effect", it must apply to us too. Those experiments have real limits โ€” a three-to-six-week window, election-period ceiling effects, and collaboration with the platform being studied, on that platform's data โ€” but they aim directly at the lever the next section describes, and omitting them while citing the exposure study approvingly would be exactly the selectivity we criticise in others.

Filter bubbles. Budak, Nyhan, Rothschild, Thorson and Watts (Nature, June 2024) reviewed the behavioural evidence and identified three specific misperceptions in public discourse: that average exposure to problematic content is high; that algorithms are largely responsible for that exposure; and that social media is a primary cause of broad social problems such as polarisation. The documented pattern is low average exposure to false and inflammatory content, heavily concentrated in a narrow fringe with strong prior motivation to seek it. Their recommendation is not complacency โ€” it is to hold platforms accountable for the tail of the distribution, where consumption and risk are actually concentrated.

Four myths this section retires

  • "The 2014 emotional contagion experiment proved platforms can control emotions." Kramer, Guillory and Hancock manipulated the feeds of 689,003 users for one week, suppressing either positive or negative emotional posts. Emotional word use shifted in the predicted direction โ€” by about 0.1 percentage points, among the smallest effect sizes ever reported in a headline psychology paper. Cite it for consent failure, not emotional control: the journal issued an Editorial Expression of Concern on 3 July 2014 because the study relied on a data-use policy in place of informed consent. Its true significance is that it is the definitive public record of an operator covertly running a mood experiment on 689,003 people.
  • "False news spreads through structurally different, bot-driven pathways." Vosoughi, Roy and Aral (2018) analysed about 126,000 fact-checked cascades among some 3 million people: false stories were 70% more likely to be retweeted, and truth about six times slower to reach 1,500 people. They themselves found that bots amplified true and false news equally โ€” humans did the differential spreading. And Juul and Ugander (2021) re-analysed the identical dataset, matching cascades on size, and found the "deeper, broader" structural differences largely vanish: what differs is basic infectiousness, not the architecture of diffusion.
  • "Correcting misinformation backfires." Wood and Porter (2019) ran five experiments with more than 10,100 subjects across 52 issues โ€” including exactly the polarised topics where backfire should be most likely โ€” and found no correction capable of triggering backfire; corrections generally moved attitudes toward accuracy. The robust finding in this area is the weaker continued influence effect: retracted misinformation keeps partially influencing reasoning โ€” which argues for better-designed corrections, not for giving up.
  • "Subliminal messages implant beliefs." The founding claim โ€” a 1957 report that flashing "Eat Popcorn" raised cinema sales โ€” was admitted by its author in a 1962 interview to have been a fabrication devised to attract clients. Decades of replication attempts have not produced reliable subliminal persuasion. What is real is the ordinary, fully visible mere-exposure effect. The danger is visible repetition, not hidden frames.

The honest threat model

Put the documented and the contested together and you get a threat model that is neither comforting nor hysterical.

Not "one clever targeted message flips a vote." The evidence against that is strong and comes from people who went looking for the opposite.

But "months of low-dose repetition shift the felt baseline of what is true, what is normal, and what is tolerable โ€” with the deepest effects on a small, heavily exposed minority, and with moral objection softening alongside belief."

Anyone who tells you a single targeted message can rewire a population is selling something. Anyone who tells you repetition is harmless has not read Fazio.


The scenario

This is the reason a study like this gets commissioned, so let us state it without decoration.

An ordinary application. Not a political one โ€” a music app, a video app, a payments app, a game. Used daily, by tens or hundreds of millions of people in one country. Owned, or substantially influenced, from outside that country. Holding, by ordinary commercial design, that population's location, behaviour, social graph and attention. And then, over eight or twelve or eighteen months, a slow drift in how those people feel about their own institutions, their own courts, their own police, their own leaders, their own neighbours โ€” with no fake accounts, no forged documents, no detectable campaign, and no single moment anyone could point to.

That is the risk. It is structural. And the honest case for taking it seriously does not require exaggerating a single fact โ€” which is fortunate, because exaggerating it is the fastest way to lose the argument.

Two things called "influence operations" โ€” and conflating them is the field's biggest error

The first is the outsider campaign. Fake accounts, cloned news sites, troll farms. It is extensively documented. A US federal grand jury indicted 13 Russian nationals and 3 Russian entities in February 2018 โ€” and this study must say what an indictment is: an allegation, never tested. None of the individuals was extradited or tried, and the prosecution moved to dismiss the case against the corporate defendant in March 2020 rather than proceed to trial. Two independent analyses released by the US Senate Select Committee on Intelligence in December 2018 documented sustained targeting of divisive themes โ€” race, immigration, guns โ€” with dedicated pages built for specific communities. The scale, honestly framed: in prepared testimony to the Senate in October 2017, Facebook's general counsel estimated that content from 120 linked pages was served directly to roughly 29 million Americans, with resharing bringing potential exposure to about 126 million โ€” and in the same testimony characterised this as approximately 0.004% of feed content, roughly 1 piece in 23,000.

Later operations are larger and no more effective. In August 2023 Meta removed 7,704 accounts, 954 pages, 15 groups and 15 Instagram accounts in what it described as the largest known cross-platform covert influence operation in the world, active across more than 50 platforms. Google's threat analysts disrupted over 50,000 instances in 2022 and over 65,000 in 2023, noting that 80% of the channels had zero subscribers, 65% of the videos had fewer than 100 views and 30% had none โ€” and assessing that the operation "achieves practically no organic engagement from real viewers". In September 2024 the US Department of Justice seized 32 domains used to clone real news outlets, including a spoofed newspaper domain, with an affidavit reproducing internal planning documents; European researchers had already documented the operation cloning at least 17 real outlets. And takedowns do not kill it: analysts found twelve replacement websites created within 24 hours of the seizures, carrying migrated archives and sharing identical analytics identifiers with the seized domains, publishing at pre-seizure pace โ€” and still with no evidence of widespread amplification.

Its measured persuasive effect, on the best available evidence, is close to zero. The operation is real, criminal and deliberate. The persuasion is not demonstrated. The harm is pollution and enforcement cost.

The second thing is structurally different and far less studied: the owner of the pipe. An owner does not need fake accounts. It does not need to buy ads. It does not need to evade detection, because there is nothing to detect โ€” every action it takes is indistinguishable from ordinary product work.

The four levers โ€” stated precisely, without inflation

The temptation is to say these are "owner-only capabilities no outside propagandist has". That is too absolute and a critic will break it: any advertiser can run randomised creative tests through an ad platform and measure conversion; researchers run field experiments; the ad system sells behavioural segments built from the same first-party data. The real distinction is depth and scope: an owner can act on ORGANIC RANKING, for the whole population, with no disclosure and no spend. An outsider can only test paid creative against the segments the owner chooses to sell. That version is defensible, and it is still devastating.

Lever 1 โ€” ranking control. Not censorship. Weighting. The internal documents above show a single ranking-weight decision measurably shifting platform-wide emotional tone. No content was removed, nothing was banned, nobody was silenced, and the emotional climate of a population moved. Nothing about that requires a foreign owner. It is the ordinary operation of a commercial ranking system, and it is the strongest documented fact in this section precisely because it needs no villain.

Lever 2 โ€” manual promotion. In January 2023 Forbes reported internal TikTok documents describing "heating" โ€” boosting videos into the recommendation feed "through operation intervention to achieve a certain number of video views". Documented stated purposes: attracting influencers, promoting diverse content, pushing important information. Forbes also reported that employees had heated their own accounts and those of personal contacts, one reaching over three million views. The company confirmed the tool exists while framing its scale: heated videos are approximately 0.002% of videos in the US feed, and only a small number of US-based staff can approve US promotions. We do not claim "equivalents at every major platform" โ€” that assertion is undocumented, and this study does not make undocumented assertions. What is documented is that at least one platform of this scale has a confirmed manual promotion tool with no ad-library entry and no user-visible label. That is enough.

Lever 3 โ€” silent experimentation on a whole population. The definitive public record is the 2014 emotional contagion study: an operator manipulated the emotional valence of 689,003 users' feeds for a week without individual consent. Cite it for what it proves. The measured emotional effect was tiny. The capability it demonstrates is enormous: an operator can run a randomised trial on hundreds of thousands of real people, measure the causal effect of a content change on real behaviour, and deploy the winner โ€” before anyone outside knows an experiment happened. An outside actor can never do this. It can only guess, buy, and hope.

Lever 4 โ€” knowing precisely who is persuadable. The owner's first-party behavioural data identifies which specific users are movable on which topics; an outside actor must buy coarse segments and guess. And the Cambridge Analytica affair is the proof of the asymmetry, in the direction people do not expect: an outsider's attempt at this lever, built on data from up to 87 million profiles harvested through the platform's own friends API, was found by the regulator that seized its servers not to have delivered the capability it advertised. The platform holding the original data has all four levers natively, and has never needed to advertise anything.

The legal-compulsion question โ€” answered even-handedly, because that is the only way it holds

The argument that gets made is: a company headquartered in country X can be legally compelled by X's government to hand over data or to assist intelligence work. That argument is correct. It is also universal, and pretending otherwise destroys it.

  • PRC National Intelligence Law (2017), Article 7: any organisation or citizen shall support, assist and cooperate with state intelligence work according to law; Article 14 empowers intelligence agencies to demand that support. Analysts note the law leaves "organisations" undefined as to foreign entities and provides no clear right of refusal or remedy.
  • US CLOUD Act (2018): requires US providers to produce stored customer data on servers they own and operate anywhere in the world, subject to limited challenge, and creates executive agreements with foreign governments โ€” a mechanism European data protection authorities have flagged as in tension with the GDPR.
  • US FISA Section 702: authorises warrantless targeting of non-US persons abroad and compels assistance from US communication service providers, who receive compensation and immunity from suit. It was reauthorised for two years on 20 April 2024, with a broadened provider definition that critics argued could sweep in ordinary businesses handling communications equipment.
  • And compulsion powers are documented to be over-used even where judicial oversight exists. Court-reviewed audits found that between 2020 and early 2022, FBI personnel conducted more than 278,000 queries of Section 702 databases that did not meet the applicable legal standard โ€” including queries relating to protesters and, in some instances, members of Congress. Following remedial measures the Bureau reported non-compliant querying dropped by more than 95% by 2022, and the shorter two-year reauthorisation was itself a product of that controversy.

The systems differ meaningfully in judicial review, in remedy, and in the possibility of public disclosure, and that difference matters โ€” it is not a rhetorical concession. But the underlying structure is universal: the host state has a lever. Relocating data changes who holds the lever, not whether one exists. This is a structural property of where a company lives. It is not a trait of a people. Any citizen of any country is subject to a version of this, and any country's population is equally the object of some other country's version.

The live case: what is established, and what is not

Documented and serious. Forbes reported in October 2022 that a ByteDance internal audit team planned to use TikTok data to monitor the location of specific US citizens; in December 2022 an internal company investigation confirmed that employees had improperly accessed the IP address and user data of multiple Forbes journalists in an attempt to identify leak sources by checking whether reporters had been in the same locations as staff. Four employees were dismissed โ€” two in China and two in the US โ€” and a senior executive resigned. BuzzFeed News reported in June 2022 on leaked internal audio in which staff stated that China-based engineers had access to US user data. The heating tool above is confirmed by the company. And The Guardian reported leaked 2019 moderation guidelines restricting certain political content, which the company said were early global rules since replaced by locally customised versions; a separate leaked policy instructed moderators to suppress recommendations of users deemed "ugly, poor, or disabled", for which the company apologised.

Not established. Covert political content manipulation of Western users. Citizen Lab's March 2021 technical comparison of the app and its domestic sibling found no observation of either app collecting contact lists, photos, audio, video or geolocation without permission, and found that while the domestic app restricts political terms in search, the international one restricted none of the keywords tested. The researchers stated their evidence was inconclusive as to whether the app censors user posts โ€” and flagged the crucial epistemic point in both directions: server-side configuration and dynamic code loading mean client-side analysis cannot rule out hidden behaviour, so it cannot prove safety either. The hashtag-ratio studies purporting to show geopolitical skew are weak evidence: hashtag counts are lifetime totals, confounded by a much younger user base, and cannot distinguish curation from organic composition.

What the law actually decided. The frequently cited standalone bill passed the US House on 13 March 2024 and then died in the Senate; the law actually enacted was a division of the national-security supplemental signed 24 April 2024, with a 270-day divestiture window. In TikTok Inc. v. Garland, decided 17 January 2025, the Supreme Court held unanimously, per curiam, that the Act survived First Amendment review โ€” relying on the government's content-neutral interest in preventing a foreign adversary from collecting the personal data of tens of millions of US users, and holding that Congress would have enacted the law "based on the data justification alone." The Court acknowledged the separate concern about covert alteration of platform content but did not rest on it. So the Court did not confirm content manipulation. It confirmed the data risk. Anyone citing that judgment as judicial proof of political manipulation is citing it wrong.

And here is the fact that makes this study's own point better than any argument could. Enforcement was repeatedly deferred through 2025, with a divestiture deal closing on 22 January 2026 under which three investors each hold roughly 15% of a US joint venture โ€” and the original owner retained 19.9%, just under the statute's 20% control threshold. An ownership remedy that leaves the original owner at 19.9% is the sharpest available evidence that ownership remedies answer "who holds it" and not "why is it held at all."

What ownership remedies actually accomplish

India, 2020. On 29 June 2020 the Ministry of Electronics and Information Technology blocked 59 apps including TikTok under Section 69A of the Information Technology Act, 2000, on the stated ground that they were engaged in activities prejudicial to the sovereignty and integrity of India โ€” and the stated rationale expressly named data: the compilation, mining and profiling of Indian users' data. Further tranches followed through 2020, and a further 54 apps in February 2022. One honest deflation: the July tranche consisted overwhelmingly of clones and "Lite" variants of apps already blocked in June, so counting them as distinct additions inflates the headline; say "four tranches through 2020", not a bare total.

And this study is obliged by its own charter to say the harder thing about that remedy. Rule 16 of the Blocking Rules keeps the orders confidential, so the specific findings against each app were never published. Digital rights groups objected that the Supreme Court's Shreya Singhal judgment contemplates reasoned, reviewable blocking. Blocking orders that are secret, unreasoned and unreviewable are a censorship instrument regardless of which government holds them. That is not a footnote to the remedy. It is a property of it.

And the deeper limitation is arithmetic. Removing a foreign-owned app removes one collector. It does not remove the collection. The same categories of behavioural, location and contact data continue to be gathered and traded by domestic apps, kits, advertising exchanges and brokers under the identical business model described earlier. The US Supreme Court upheld a law about one owner, not a law about data collection. Ownership-based remedies are narrow by construction.

The European Union is testing the owner-risk theory in the open, under law. On 17 December 2024 the European Commission opened formal Digital Services Act proceedings against TikTok over election-integrity risk management, following the Romanian presidential first round of 24 November 2024. The investigation covers the platform's recommender systems and its policies on political advertising, with a retention order freezing relevant data for EU national elections. The Commission can compel access to algorithms, and states plainly that opening proceedings does not prejudge the outcome. (Two honesty flags: our verification pass could not open the Commission's release, so the specific article numbers are not reproduced here; and that proceeding was opened some nineteen months before this study was written, so its current status must be checked by the reader rather than assumed from this page.)

Romania โ€” the case that proves why the adversary cannot be a nation

Romania's Constitutional Court annulled the first round of the presidential election on 6 December 2024, citing declassified intelligence which asserted that a coordinated online campaign had promoted one candidate, characterised by the national defence council as matching patterns seen in Russian operations. The evidence for that assertion was never subjected to adversarial testing. We report what was asserted, and then we report that.

Then, two weeks later, on 20 December 2024, Romanian investigative reporting alleged that the governing party had itself paid for an influencer campaign on the same platform that the same defence council had described as "identical" to the campaign attributed to Russia. (We give this as reported; a final citation should name the outlet, and "Romanian investigative reporting" is not a source.)

That single fact is the most important one in this section. The same playbook, on the same platform, in the same election, allegedly run by a domestic governing party. Which is precisely why the adversary in this study cannot be a nation, a people or a faith: the mechanism is available to everyone, and everyone reaches for it.

And the record must be brought current, or a reader who knows the outcome will conclude the study is either stale or concealing it: the election was re-run in May 2025 and won by Nicuศ™or Dan; the candidate at the centre of the annulment was barred from the re-run and subsequently placed under criminal investigation.

The measurement problem โ€” and what this study argues instead

Ben Nimmo's Breakout Scale (Brookings, September 2020) grades operations on six observable categories, from confinement to a single community up to triggering a policy response, concrete action, or calls to violence. An honest attribution: this is a measurement framework, not an empirical study, and it does not have "findings".

The following is therefore this study's own argued thesis, labelled as such rather than borrowed: the most reliably measurable effect of an influence operation is not what it does to a population's beliefs. It is what it provokes from that population's government. Annulled elections. App bans. Secret blocking orders. Emergency powers. Category 6 on that scale is defined as triggering a policy response โ€” so an operation can "succeed" by producing an official reaction disproportionate to its measured effect. Every remedy in this study must be tested against one question: does this response cost the adversary more than it costs us?

And nobody outside the platforms can currently check any of this. Every credible finding in this section traces to one of exactly four sources: a leak; a prosecution; a voluntary company disclosure (unaudited, and shaped by the discloser); or a rare data partnership conducted with the platform being studied, on its data. That is not an evidence base; it is a run of luck. And that research window is closing, checkably: one major platform terminated free academic API access in 2023, and the leading public transparency tool was shut down in August 2024 and replaced by a more restrictive alternative. The exposure study cited above could not be run again today on comparable terms.

The counterweight is legal, and it exists in exactly one place. The EU Digital Services Act creates a vetted-researcher data access right for very large platforms and mandates independent audits; the delegated act was adopted in July 2025 and the mechanism became operational in late 2025, so the right does not merely exist on paper โ€” the live questions are uptake, scope and how many applications have actually been granted. The US analogue has been introduced repeatedly and never enacted. Outside that one regime there is no general legal right for independent researchers to test claims about ranking systems. And a study arguing for transparency must price transparency's own cost: mandatory researcher access is itself a data-protection risk if scoped badly. The remedy needs its own privacy floor.

What the scenario justifies, and what it does not

It does not justify claiming that a population's beliefs have been secretly rewritten. The evidence above is unambiguous: the best-identified field experiments โ€” including experiments aimed directly at ranking, the very lever this section describes โ€” repeatedly find attitudinal effects that are small, near-zero, or precisely estimated as null. We cite them against ourselves on purpose.

It does not justify treating a company's country of origin as evidence of intent, or a people as an adversary. The compulsion structure is universal; the playbook is domestic as often as foreign.

It does not justify secret blocking orders, unreviewable bans, or remedies at the publication layer. Those are censorship instruments regardless of who holds them, and the fix belongs at the supply layer instead.

What it does justify is precise, and it is enough. A single organisation controls the ranking function for a population's daily attention. It can change that function silently. It can test the change on the population first, without notice or consent โ€” this is documented, at n=689,003. It can promote chosen content with no label and no ad-library entry โ€” this is documented and company-confirmed. It knows, from the population's own behaviour, exactly who is movable. It is subject to legal compulsion by whichever state it lives in โ€” as every such company everywhere is. And no one outside it can verify any of this, except in one jurisdiction, under a mechanism that only began operating in late 2025.

That is not a proven harm. It is an unaudited concentration of power over a population's inner weather โ€” and the reason to act is not that we have measured the damage, but that we have no instrument capable of measuring it. The structural risk argument does not need exaggeration to stand. It stands better without it.


What protects a person

A study that documents this much and offers nothing converts alarm into fatalism, which serves the mechanism it is trying to expose. So here is the ranked playbook โ€” tiered by effort, and honest about ceilings. Nothing below asks you to leave modern life. Most of it takes an afternoon, once.

Tier 1 โ€” twenty minutes, most of the benefit

1. Delete or reset the advertising identifier โ€” and prefer deleting. On Android: Settings โ†’ Privacy โ†’ Ads, and choose Delete advertising ID rather than merely resetting it. On iOS: Settings โ†’ Privacy & Security โ†’ Tracking, and turn off Allow Apps to Request to Track. Remember the ceiling from the measurement literature: where an app also ships a permanent identifier, a reset is largely theatre โ€” which is why deletion, and the network-layer step below, matter more than the toggle.

2. Uninstall rather than deny. The app you do not have cannot ask again, cannot update its way back into a permission, and cannot carry a tracking kit you never inspected. Go through your home screen and remove everything you have not opened in three months. This is the single highest-yield twenty minutes in the whole list, because it removes collection surfaces instead of negotiating with them.

3. Turn precise location off for everything that does not need metres. On iOS: Settings โ†’ Privacy & Security โ†’ Location Services, then per app set "While Using" and switch Precise Location off. On Android: Settings โ†’ Location โ†’ App permissions, set "Allow only while using the app" and turn off "Use precise location". News, shopping, weather, timezone and delivery-tracking all work from a city or a grid cell. Precise location should be a short list you can recite from memory.

4. Turn off the scanners that keep reporting when location is "off". On Android: Settings โ†’ Location โ†’ Location services, then turn off Wi-Fi scanning and Bluetooth scanning. On iOS: Settings โ†’ Privacy & Security โ†’ Location Services โ†’ System Services, turn off networking and wireless entries where offered, plus Significant Locations โ€” and clear its history.

5. Turn off or shrink Location History / Timeline. Google began moving Timeline onto the device in December 2023, with the auto-delete default dropping from 18 months to three and Location History remaining off by default. Check yours: off, or three-month auto-delete. This is the strongest existing proof that architecture beats policy โ€” a default change and on-device computation removed a surveillance capability more effectively than years of warrant litigation.

Tier 2 โ€” one evening, high effect

6. Block at the network layer. Encrypted DNS with a tracker blocklist, or an on-device filtering VPN. This is the only defence that survives whatever any kit does, because it applies to every app at once and does not depend on a permission an app can route around.

7. Check the trackers before you install. Exodus Privacy (reports.exodus-privacy.eu.org) lists the trackers found inside an Android app. Thirty seconds, and it is the highest-signal check available to a non-expert. If a torch app carries eleven trackers from five companies, you have learned everything you need.

8. Search your own face. Run your photograph through the consumer face-search engines and see what a stranger sees, then use each service's opt-out or removal process โ€” and do the same for the people-search sites those results lead to. This takes an evening, and it is the only way to know your actual exposure rather than your imagined one.

9. Learn your camera and microphone indicators, and the kill switch. iOS 14 and later show an orange dot for the microphone and a green dot for the camera; Android 12 and later show equivalents and add system-wide microphone and camera toggles in Quick Settings. The dots are drawn by the operating system and cannot be suppressed by any ordinary application. Honest ceiling: commercial spyware with kernel-level access can suppress them. For ordinary risk, trust the dot; if you are a plausible target for a commercial implant, do not rely on it alone, and use a physical cover on laptop and external webcams.

10. Strip metadata before sending files outside the big platforms. Photos can carry exact coordinates, a timestamp and a device identifier. The major social platforms are commonly reported to strip this metadata from the file other users can download โ€” we flag that as not independently verified in our pass, so treat it as unconfirmed and behave as though metadata may survive. The live risk in any case is the file sent as a file: email attachments, cloud-drive links, "send as document" in chat apps, marketplace listings, forums that do not sanitise uploads, and any site you host yourself. On iOS: share sheet โ†’ Options โ†’ turn Location off. On Android: open the photo โ†’ Details โ†’ Remove location. On a desktop: exiftool -all= file.jpg, or the file-properties "Remove Properties" dialog. Note the residual: stripping protects you from other users. It does not protect you from the platform, which reads and retains your original metadata on upload. The mechanism is court-proven โ€” in 2012 investigators pulled location coordinates from photographs posted on defaced pages, corroborated by matching against holiday photos, and made an arrest, with no legal process needed for the identification at all.

Tier 3 โ€” situational, and the highest stakes

11. If you suspect stalkerware, do not delete it first. Removal can alert the person who installed it and escalate physical danger. Use a different, safe device to contact a domestic-violence service โ€” in the US, the National Network to End Domestic Violence's Safety Net project; internationally, the Coalition Against Stalkerware maintains a resource list; in India, the women's helpline 181 and the police helpline 1091. Preserve evidence, then plan removal with support. Check for unfamiliar device-administrator apps, unexplained battery drain, a shared family account you did not set up, and unwanted Bluetooth trackers โ€” both major phone platforms now surface unknown-tracker alerts.

12. If you are at elevated risk โ€” journalist, survivor, organiser, clinician, official, or anyone attending anything they would not want reconstructed โ€” treat the phone as a beacon, not a tool. Leave it at home or in a shielded pouch for sensitive movements; use a separate device with no personal accounts. Airplane mode does not undo a trail already recorded, and no single toggle reaches the carrier or signalling layer. And be honest about a limit in this advice: in India and in over a hundred other countries, identity documents are required to obtain a SIM, so an anonymous line is not an option most readers have. The remedy there is legal and collective, not personal.

13. If you or your child is targeted by an intimate deepfake: use StopNCII.org (adults) or NCMEC's Take It Down (under-18s). Both generate a cryptographic hash of the image on your own device, so participating platforms can block it without you ever uploading the picture. In the US, covered platforms have been required since 19 May 2026 to operate a notice-and-removal process โ€” the reported image within 48 hours, plus reasonable efforts on identical copies โ€” with a complaint route to the FTC if they do not. In the UK, the Revenge Porn Helpline for adults and the Internet Watch Foundation for imagery of under-18s.

14. Exercise the deletion rights that exist where you live. In California, use DROP, the Delete Request and Opt-out Platform, open to residents since 1 January 2026 โ€” one request reaches every registered broker, and brokers must begin processing those deletions from 1 August 2026. Everywhere else, file individual deletion requests with the brokers named in the enforcement record โ€” Outlogic/X-Mode, InMarket, Gravy Analytics, Venntel, Mobilewalla, Kochava โ€” and keep the confirmations. In the EU and UK, send Article 15 access and Article 17 erasure requests to the brokers, not only to the apps: the brokers are where the joins happen. In India, see the next section.

15. Pause before sharing. Prompting yourself to consider accuracy measurably improves the quality of what you subsequently share โ€” small effects with a mixed replication record, but free. Three seconds: is this actually true, or just satisfying?

The rungs below "open Settings"

Every step above assumes a menu you can navigate, in a language you read, on a phone that is yours. For hundreds of millions of people none of those three things is true. The household may own one phone, usually held by a man. The transaction may be performed by an operator at a service centre, a ration shop or a bank correspondent, who holds the device and the fingerprint. Cheap handsets ship with preinstalled apps that cannot be removed. And a second-hand phone is not a fresh start: the education-technology research above found identifiers that persist even after a factory reset.

So the advice that survives illiteracy and shared ownership is physical and social, not technical: do not hand over an unlocked phone โ€” hand over what is asked for and nothing more; know that the operator's device keeps a log; ask for the paper receipt; before selling a phone, sign out of your accounts before wiping it and remove the SIM; after buying one, reset it yourself and check for device-administrator apps, accessibility services and management profiles you did not install. And if a notification on a shared screen could put you in danger, the remedy is not "delete your ad ID" โ€” it is disappearing notifications, a locked or hidden app, and a route to help that does not leave a trace on that screen.

The one-paragraph version, for a poster. Delete your advertising ID. Uninstall the apps you do not use. Turn precise location off for everything that does not need metres. Turn off Wi-Fi and Bluetooth scanning. Block trackers at the DNS layer. Check an app on Exodus before you install it. Learn what the green and orange dots mean. Strip photo metadata before you email a file. Turn off your television's content recognition. And know that none of this reaches your carrier โ€” which is why the rest of this study is about law and architecture, and not about you.


What protects a country

The measures with evidence behind them, ranked by leverage

1. Strip the identifying fields from the bid request. This is the highest-leverage single move in the entire document, and it is narrow, technical and enforceable at a handful of exchanges rather than against thousands of downstream firms: bar unique identifiers, high-resolution timestamps, precise location and free-form extensions from being broadcast in an auction message. It fixes the leak at the source, touches no speech, and removes no content. Note carefully what it replaces: the intuitive fix โ€” licensing who may operate a demand-side platform โ€” becomes licensing who may reach an audience. Ordering the two bodies that set the bid-request format to strip identifying and linkable fields makes the identity of the recipient irrelevant, which is a better answer than deciding who deserves to be a recipient.

2. Ban retention of bid-request data you did not win. The theory in the Mobilewalla order โ€” the first time a regulator alleged that harvesting the auction itself is an unfair practice โ€” is the most surgical remedy in the record. It is a single sentence of law, it closes the channel that kit-focused reform misses entirely, and it is buyer-agnostic: it does not care about the nationality of the company doing the retaining.

3. Legislate minimisation, not consent theatre. Bar collection and sale of precise location beyond what the requested service actually needs. Nine apps in ten never ask for consent; most of the ones that do offer a single "accept" button. A consent regime regulates a dialogue box. A minimisation regime regulates the data.

4. Make deletion reach derived data. The Alexa case exists because deleting a child's voice recording left the derived transcript in place, tied to a persistent identifier. The Ring and Avast orders went further and required deletion of the models and algorithms derived from unlawfully obtained data. A trained model is a copy of what it consumed. Any deletion law that stops at the raw file is theatre.

5. Create a broker registry with a single universal deletion channel. Vermont pioneered registration in 2018; California's Delete Act added the universal mechanism, and the published registry immediately produced citable numbers โ€” 545 brokers, 88 admitting precise geolocation, 19 admitting minors' data, 10 admitting reproductive health data. One request that reaches every broker is worth more than a hundred individual rights nobody has time to exercise. Draft it narrowly: a broadly drafted registry is a licence to compile information, which is one drafting session away from a press register.

6. Give people a private right of action. A single US state's biometric statute โ€” with statutory damages, and no requirement to prove separate injury โ€” produced a permanent nationwide ban on one company selling its faceprint database to private entities. Five European regulators, fining roughly โ‚ฌ90 million between them, produced almost no payment and no equivalent behavioural change. This is the single clearest comparative result in the study.

7. Give the regulator power to ban a practice, and to remove an actor. The first-ever ban on selling sensitive location data, and the permanent ban of a stalkerware company and its named chief executive from the surveillance business, did what no fine achieves: they removed the capability rather than pricing it.

8. Close the purchase loophole. After the 2018 and 2026 rulings, the state needs a warrant to compel location data โ€” while buying the same trail on the open market has needed nothing. A "the Fourth Amendment is not for sale"-style rule is the missing half of the constitutional ruling, and every jurisdiction has this hole. A government that fines a data broker and then buys from it has cancelled its own law.

9. Fix the enforcement gap, not the law. Roughly โ‚ฌ90 million in European penalties against one face-scraping company went largely uncollected because there is no working cross-border mechanism to reach a non-EU firm's assets. Reciprocal enforcement arrangements, and conditioning government procurement on having paid outstanding privacy penalties, would do more than another regulation.

10. Preserve and use emergency powers โ€” narrowly. One European authority halted continent-wide human review of voice-assistant recordings within weeks, using an emergency provision for the first time. For a live data flow, speed matters more than penalty size. And the honest note this study owes: an emergency power to order processing stopped sits in the same constitutional slot as an emergency power to order data handed over โ€” which is exactly what a war-powers statute did to census confidentiality in 1942. Emergency powers should be narrow, time-limited, judicially reviewable, and capable only of stopping processing, never of compelling disclosure.

11. Mandate researcher access and independent audit. The four-source evidence problem above is the argument. The European risk-assessment, independent-audit and vetted-researcher provisions are the existing template, operational since late 2025. The counter-example is what happened when access closed: a major platform ended free academic access in 2023 and the leading public transparency tool shut down in August 2024. Note the cost honestly: mandatory researcher access is itself a data-protection risk if scoped badly, and needs its own privacy floor.

12. Require an opt-out to a non-personalised feed, and make it sticky. The platform experiments showed a chronological feed cuts time-on-platform sharply with no measurable attitudinal harm โ€” meaning a genuine choice is technically trivial and costs the platform revenue, which is precisely why it must be a legal duty rather than a setting buried three menus deep.

13. Publish the levers. Require a public ranking change log and experiment register; require every manually promoted item to be visibly labelled and archived exactly as paid advertising is; require publication of the matching threshold and an independent equitability evaluation for any deployed facial recognition, plus quarterly deployment statistics โ€” scans, alerts, false alerts, arrests, watchlist size and composition. The harm in the ranking documents was not that a change was made. It was that nobody outside could see it happen.

14. Apply data minimisation to the state itself. This is the test of good faith. A minimisation duty that binds a shopping app but exempts a ministry inverts the logic of every privacy judgment ever written โ€” and the record shows why: the census case of 1943, the population registry of 1940, and three democracies that automated welfare suspicion against their own citizens and were each stopped by a court or a regulator. Emergency data powers must expire by default, not by later goodwill: confidentiality suspended in March 1942 was not restored until 1947, and inside that window names and addresses moved.

15. Fix the network layer. Carrier signalling reform is public-safety infrastructure: no app setting, permission or operating-system update reaches it. Treat network-layer location as a regulated category in its own right โ€” you cannot uninstall your carrier.

What India specifically holds today, and what it does not

This section is written for the Indian reader, and it is the most immediately useful part of the study for them.

The constitutional floor is stronger than the statutory one. Puttaswamy (24 August 2017, nine judges, unanimous) made privacy a fundamental right and supplied a proportionality test โ€” legality, legitimate aim, necessity and proportionality, plus procedural safeguards against abuse. This is enforceable now, by writ petition under Article 226 in any High Court or Article 32 in the Supreme Court, without waiting for any statute to commence.

The statute is real but is not yet switched on. The Digital Personal Data Protection Act received assent on 11 August 2023. The final Rules were notified on 13 November 2025 โ€” the January 2025 document was a draft. Commencement is staggered: the Board machinery took effect immediately; Consent Manager registration opens 13 November 2026; and the substantive obligations โ€” consent notices, security, breach reporting, retention, children's data, Significant Data Fiduciary duties, rights and cross-border rules โ€” commence on 13 May 2027.

What the Act gives, and what it withholds. Four rights: access to a summary of data processed and the identities of third parties it was shared with; correction, completion, updating and erasure; grievance redressal; and nomination. Consent must be free, specific, informed, unconditional and unambiguous, with notice available in English and any of the 22 scheduled languages. There is no data portability and no right against solely automated decision-making. Portability existed in India's own withdrawn 2019 Bill and was dropped. Data principals also carry statutory duties, and a false or frivolous complaint can attract a penalty of up to โ‚น10,000 โ€” a provision with no European analogue. Penalties fund the treasury, not the victim: up to โ‚น250 crore for a security failure resulting in a breach, โ‚น200 crore for failure to notify, โ‚น200 crore for children's-data breaches, all credited to the Consolidated Fund of India. The Act contains no compensation right.

Correct the common overstatement. Section 44(2) will omit IT Act section 43A โ€” the compensation route for negligent handling of sensitive personal data โ€” but section 44 has not been brought into force. As of July 2026, section 43A and the 2011 rules under it are still law and still usable. And even after commencement, IT Act section 43 (unauthorised access, downloading and data extraction, with compensation before an adjudicating officer) is untouched, as are sections 66E, 72 and 72A. Do not tell Indians they have no compensation route; tell them which one to use.

The regulator is not yet there. The Data Protection Board is a government-appointed quasi-judicial body that cannot make its own regulations โ€” rule-making stays with the Central Government, unlike the securities, telecom and competition regulators. Reporting in April 2026 found it yet to become fully operational owing to delays in appointing its leadership and members. Appeals lie to the telecom disputes tribunal and thence to the Supreme Court. There is currently no live enforcement docket and no reported penalty.

The exemption architecture is the real domestic gap, and it must be named as plainly as any foreign risk. Section 17(2)(a) empowers the Central Government to exempt any instrumentality of the State from the Act by notification, on grounds of sovereignty and integrity, security of the State, friendly relations with foreign States, public order, or preventing incitement to a cognizable offence relating to any of these. Section 17(1)(c) exempts processing for the prevention, detection, investigation or prosecution of any offence โ€” arguably the largest carve-out in the section. Section 17(5) lets the Government, for five years from commencement, declare any provision inapplicable to any class of fiduciary. And section 17(4) disapplies the storage-limitation duty for State processing under the legitimate-use ground covering a subsidy, benefit, service, certificate, licence or permit. That is precisely the welfare and identity data. The one existing check: notifications must be laid before both Houses. (A correction on a common misattribution: Justice B.N. Srikrishna's "Orwellian State" warning was made in December 2019 about the 2019 Bill, not about the 2023 Act. The honest sentence is that he warned in December 2019 that the government's redraft of his committee's bill could turn India into an Orwellian State, and that the exemption architecture he objected to survived into the 2023 Act.)

The transparency trade is contested and must be reported as contested. Section 44(3) replaced the Right to Information Act's section 8(1)(j) โ€” which exempted personal information only where disclosure bore no relationship to public activity or would be an unwarranted invasion of privacy, and which carried an express larger-public-interest override plus a "cannot be denied to Parliament" test โ€” with the bare words "information which relates to personal information." The Government's position is that section 8(2) still supplies the override; opposition members and the Internet Freedom Foundation contend that section 8(2) is a weaker, discretionary provision that does not reproduce the deleted tests, and note that nothing replaces the Parliament proviso. This is an unresolved legal contest. Report it as one โ€” and keep filing RTIs, because a refusal citing the amendment is appealable.

What India got right, and what other countries should study.

  • The negative list. Section 16 permits transfer of personal data to any country by default, unless the Central Government notifies a destination as restricted. No adequacy whitelist, no standard contractual clauses. India did not "close its borders to data" โ€” that myth is backwards. Real, enforced localisation in India is sectoral: the Reserve Bank's April 2018 direction requires payment system data to be stored in India, with later clarifications permitting offshore processing provided the data is deleted abroad and returned within a day. Note what that rule is for: regulator access, not citizen protection.
  • The Consent Manager. The Rules create a licensed, registered intermediary โ€” an Indian-incorporated company with a minimum net worth, registered with the Board, obliged to act in a fiduciary capacity toward the data principal, keeping consent records for years and enabling withdrawal as easily as consent was given. This is the most exportable idea in Indian data law: one neutral, regulated place where a person can see and revoke every consent they have given, instead of hunting through fifty privacy dashboards. It is also the piece most likely to fail quietly if nobody registers โ€” which is why the November 2026 date matters.
  • Algorithmic due diligence. Rule 12 requires a Significant Data Fiduciary to conduct a Data Protection Impact Assessment and an audit at least once every twelve months, and to observe due diligence to verify that algorithmic software it deploys for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data is not likely to pose a risk to the rights of Data Principals. This is one of the first binding statutory duties anywhere requiring a company to check that its own ranking and recommendation software does not endanger users' rights โ€” the exact mechanism this study is about. Its weakness: nothing requires publication, so the public cannot see the finding.
  • Concrete clocks. On a breach: intimate affected data principals without delay, describing the breach and the mitigation steps they should take; initial intimation to the Board without delay and a detailed report within 72 hours. On rights requests: a 90-day response cap.
  • And one honest contradiction inside the same instrument: Rule 8(3) requires personal data, traffic data and logs to be retained for at least one year unless another law requires longer. A data-protection rule that mandates keeping more data. Name it rather than celebrating the Rules wholesale โ€” and note the design fix: separate identity data from behavioural logs, so the retained logs are not a re-identifiable dossier. (A related dormancy-erasure clock is reported inconsistently in secondary sources; we print no number for it.)

And the shortest breach clock in the world. CERT-In's directions of 28 April 2022 require system clocks synchronised to national time servers; reporting of specified incidents within six hours of noticing them; logs maintained for a rolling 180 days; and data centres, virtual private server providers, cloud and VPN providers to retain subscriber names, addresses, contact numbers, email, IP addresses allotted, period of hire, purpose and ownership pattern for five years after cancellation. Correct the myth in the same breath: India never banned VPNs, and using one remains lawful. The directions' own FAQs state that they do not apply to enterprise or corporate VPNs; several consumer providers removed their physical Indian servers in 2022 rather than log users โ€” a commercial and ethical decision by companies, not a prohibition by India. The real objection is the logging mandate itself, which converts privacy tools into identity registries โ€” a capability any state holding such records would have.

What an Indian citizen can actually use today (as of July 2026): an Article 226 or Article 32 writ invoking Puttaswamy proportionality; IT Act sections 43 and 43A plus the 2011 rules; RTI, subject to the contested amendment; the Grievance Officer every significant intermediary must publish, then a Grievance Appellate Committee; the Reserve Bank's Ombudsman for payment and UPI disputes; the telecom, securities and consumer fora as applicable; and CERT-In's incident channel. Telling people they are protected when the protection commences in 2027 produces false comfort and then cynicism. The accurate message: your strongest tool right now is the Constitution and the courts โ€” and there is a window, before the duties bite, in which to demand that the Board be properly staffed through a transparent selection process, with fixed protected tenure and its own rule-making power.

One more thing every Indian reader already half-knows, told accurately. There is no publicly confirmed compromise of the central Aadhaar biometric repository, and biometrics in particular have never been shown to have leaked from it. What is documented is downstream: around 210 government websites publishing Aadhaar numbers with names and addresses; an estimated 130โ€“135 million numbers exposed through four government scheme portals; and paid access to an administrative search facility, which the authority called misuse of a grievance-redressal facility rather than a database breach โ€” and to which it responded by filing a criminal complaint naming the journalists, which press-freedom bodies condemned and which this study names as an anti-pattern. The 2023 claims about 815 million records referred to a health dataset, not the identity repository. Overstating this destroys the true and serious finding โ€” that a national identifier propagated into hundreds of poorly secured downstream systems โ€” and hands the strongest counter-argument to anyone defending centralised identity. India's own Supreme Court identified the danger by name and acted on it. Practical consequence for the reader: a shop, gym, private bank or app generally cannot compel Aadhaar authentication. Where an ID is genuinely required, use masked Aadhaar or an offline-verifiable QR or XML, not the number. And one gap we must name rather than paper over: the risk an ordinary reader is likeliest to meet is not that biometrics leak, but that authentication fails โ€” for worn fingerprints, for the elderly, for a poor network โ€” and that a benefit stops. The exclusion literature on that is substantial; our verification pass could not confirm the specific figures and cases, so we report the shape of the harm and decline to print numbers we have not read in a primary source.

Why censorship and shutdowns fail โ€” and endanger the people they claim to protect

Start with the fact that decides the argument. Every single finding in this study โ€” including the reassuring ones โ€” exists because someone was free to acquire data and publish what they found:

  • A student analysed a public fitness heatmap and found military bases.
  • Journalists bought a week of clinic foot-traffic data for $160 to prove it was purchasable.
  • A civil-liberties organisation used public-records requests to expose a police location vendor and quote its users' own words.
  • A privacy firm hired an investigator to obtain a surveillance trial and demonstrate that the vetting was theatre.
  • Researchers reverse-engineered 17,260 apps and produced the study that debunks the listening myth.
  • Analysts read a leaked broker dataset and worked out that the leak was the ad auction, not the apps.
  • Reporters obtained internal documents describing a manual promotion tool and a ranking change.
  • A whistleblower carried out the documents proving an operator had measured its own outrage amplification.

A law empowering anyone to order down "harmful information", "misinformation", or "location information that endangers people" would be aimed first at every person in that list. Not at the brokers. The brokers publish nothing.

Now the specific failures, each with its mechanism.

1. Takedown is a treadmill; the data is not deleted, only the visible copy. Twelve replacement sites appeared within a day of a 32-domain seizure, sharing analytics identifiers with the originals, and publication continued at the same pace. Counting removed accounts as a success metric rewards volume-chasing on both sides โ€” while the underlying auction keeps running.

2. Ownership remedies answer the wrong question. A country can remove one collector and leave the collection untouched. The question is not "who holds it." It is "why is it held at all."

3. Confidential blocking is a power that outlives the government that created it. When blocking orders are secret by rule, the affected user is never told why content vanished, cannot verify the necessity, and cannot appeal โ€” and a future administration inherits an unreviewable power over speech. The remedy for opacity is publication and due process, not fewer lawful orders, and it costs security agencies nothing they legitimately need. Blocking statistics, user notice and a route of appeal should be the price of holding the power at all.

4. Traceability mandates require breaking encryption for everyone. A duty to identify the "first originator" of a message cannot be met without dismantling end-to-end encryption for every user of that service โ€” including the survivors, sources, lawyers, clinicians and dissidents the same government says it wants to protect.

5. Age verification tied to government ID builds the honeypot it claims to prevent. It forces every user to be identified at the exact chokepoint of speech, creates a new mandatory identity database, and is directly usable to silence anonymous dissent โ€” requiring every adult to be identified in order to protect every child. Prefer attribute assertions ("this person is over 18"), on-device age estimation with no retention, verifiable-parent tokens, default-private minor accounts, and enforcement against the ad networks and stores distributing nudification apps. A reader who accepts this study's case on children must not walk from it into supporting mandatory identity for everyone.

6. Government "fact-check" powers are repetition engines with a monopoly. Where a government takes the power to designate content about its own business as false and require its removal, it acquires exactly the mechanism this study describes: the illusory-truth effect works on true claims as well as false ones. A state agency empowered to designate falsehood and compel deletion is the remedy most reliably repurposed against journalists, minorities and opposition. (We deliberately do not cite a specific judgment here: our verification pass could not confirm the current appellate status of the case usually cited, and a study about precision cannot print a citation it has not read.)

7. Mandating ambient monitoring for safety builds the exact infrastructure the myth fears. A legal duty to listen, to scan, or to match on the device hands that capability to whoever holds power next, and is trivially repurposed. And "misinformation about surveillance" must never be made punishable โ€” a state empowered to punish false claims about surveillance is empowered to punish true ones.

8. "Data broker" definitions written broadly reach researchers and reporters. An outright ban on disseminating location data would, on its face, sweep in the heatmap analysis, the $160 purchase, the records requests, the trial demonstration and the breach analysis โ€” every one of which is why the public knows any of this. Journalism, academic research and security research need explicit statutory carve-outs, and anti-reverse-engineering clauses and broad computer-misuse statutes must not be allowed to suppress the debunk along with the exposรฉ. Restrict the commercial sale and the government purchase; define "broker" narrowly enough that it cannot reach a reporter or a laboratory.

9. Restricting sensor access or analytics kits "to approved apps" entrenches the incumbents. The same gate that blocks a beacon library blocks the independent researchers who found it, and strengthens firms with their own first-party data โ€” which is precisely what a competition authority found when it fined a platform โ‚ฌ150m over its privacy remedy. Prefer mandatory disclosure, operating-system indicators, rate limits and guaranteed researcher access.

10. On shutdowns, state the limit of our own evidence. This study carries no measured efficacy data on internet shutdowns, and does not claim any. What can be said structurally: a shutdown removes nothing from any database already assembled, stops no auction, deletes no broker record โ€” and it removes the population's ability to document what is being done to them, disables crisis and helpline access, and severs the exact evidence channel that produced every case in this document. It is a remedy applied to the visible layer of a harm that lives in the invisible one.

11. And the trap inside the good remedy. A protected-places list โ€” clinics, places of worship, shelters, unions, military sites โ€” is useful now, and it is also a government-defined map of who is vulnerable, which a future administration can shorten. Prefer minimisation of ALL precise location over enumerated protected categories, so that protection does not depend on remaining on someone's list. Similarly, the 48-hour notice-and-removal machinery built for image-based sexual abuse is the strongest tool victims have ever had and the strongest censorship lever built this decade. Support the offence; demand the fences โ€” penalties for knowingly false notices, a public-interest and artistic-expression defence, published transparency reports on volumes and reversals, provenance standards, liability for advertising nudification tools, and no obligation that can only be met by breaking end-to-end encryption or by scanning on the device.

12. Finally: protect the people who find this out. Security researchers and journalists need a statutory safe harbour. A criminal complaint naming the reporter who disclosed an access flaw is the model of what not to do โ€” it chills exactly the disclosure that lets a system be fixed.

The through-line. Every remedy in the ranked list above constrains collection, retention and sale. Not one of them requires anyone to be silenced, and not one of them can be repurposed against a dissident. That is not a coincidence. It is the selection criterion.


Building a house that collects nothing

The architecture

Collect nothing you do not need, because the cheapest compliance is the absence of data. No warrant, intelligence demand, breach, acquisition, rogue employee or future owner can reach data you never stored. Every case in the casebook began with a collection decision that could have gone the other way at no cost to the product.

  • Compute on the device and transmit a derived answer, never the raw signal. A prayer app needs a qibla bearing and prayer times, not a latitude and longitude to five decimals sent to a server. A weather app needs a grid cell. A delivery app needs a street, once, at the moment of delivery โ€” not a continuous trail. A fitness app needs a distance, not a route uploaded to a heatmap.
  • Ship with zero third-party kits where the product allows it. Where you cannot, make no network call to any tracker before the user has actually chosen, configure every kit to its data-minimising setting (most default to maximal collection), and read your own bid requests and strip the location fields. The 2025 broker breach showed developers being made into surveillance surfaces without their knowledge โ€” and only the developer can close that.
  • Never use a stable device or advertising identifier as the join key for anything sensitive. That identifier is the join key for the entire external market.
  • Separate identity from behaviour. Where law forces log retention โ€” as India's Rule 8(3) does โ€” keep those logs incapable of re-identifying a person on their own.
  • Publish a retention schedule and enforce it in code with automatic expiry. The 2024 carrier exposure covered call metadata from 2022 still sitting in a warehouse in 2024. Retention you have to remember to enforce is not a retention policy; it is hope.
  • Enforce purpose limitation cryptographically and organisationally, not contractually. Separate stores per purpose. Per-purpose access scopes and keys. Logged, reviewable access. A documented refusal path for out-of-purpose requests. The census case, the population registry and the welfare-fraud cases all show a written purpose limitation surviving exactly as long as the institution that wrote it.
  • Treat a trained model as containing its training data. Two orders have already required deletion of the models and algorithms derived from unlawfully obtained data. Build the pipeline so you could actually comply โ€” provenance tracked per training run, and the ability to retrain from a clean corpus.
  • Strip metadata on ingest, and log that you did.
  • Design for the false wake. Detect probable accidental activations, discard them automatically, and never route them to human review. That was the concession extracted by journalism in 2019; it should be a baseline, not a scandal response.
  • Enforce multi-factor authentication on every third-party data warehouse and SaaS tenant, and rotate credentials. The entire 2024 cloud-warehouse breach cluster ran on stolen customer credentials where MFA was not enforced. This is the highest-yield single security control in the casebook.
  • If you monetise with advertising, prefer contextual placement over behavioural โ€” it does not require the bid request to carry a person.
  • And do not request the microphone permission you do not use. An app requesting the microphone with no audio feature is the exact pattern that triggered a regulator's warning letters in 2016.

The hard trade-offs, stated without flinching

Anyone who says a zero-collection architecture has no costs is doing the same thing the ad industry does with the word "anonymised". Here are the costs.

Trade-off 1 โ€” child safety and abuse detection without data. The harm is measured and it is growing: 8,029 AI-generated child sexual abuse images and videos in 2025, including 3,443 videos against 13 the year before, 65% of those videos at the most severe classification, 97% depicting girls. A platform that stores nothing and can read nothing has less capability to detect abuse proactively. That is a real, non-rhetorical loss and this study says so. What works without building the surveillance architecture: victim-controlled hash matching, where the hash is computed on the victim's own device and the image never leaves it โ€” that is the design pattern to generalise; report-driven review, resourced properly, since most detection in practice comes from user reports and the failure is usually queue capacity, not sensing capability; metadata-light abuse signals such as account age, rate of new-contact initiation, mass-messaging patterns and payment-rail signals, none of which requires reading content; and design that removes the vector โ€” no adult-stranger-to-minor discovery surface, no default-public child accounts, no proximity search for minors. What to refuse: scanning mandates on the device. They are the surveillance architecture, installed on every phone, for whoever holds power next. Honest statement: this is a genuine capability reduction, accepted deliberately, in exchange for not building a machine that reads everyone's messages. Say that out loud rather than pretending the trade does not exist.

Trade-off 2 โ€” spam and abuse without identity. No identity means cheap accounts, and cheap accounts mean spam, brigading and sockpuppets. The mitigations are proof-of-work, rate limits, cost signals, invitation graphs, webs of trust and paid tiers โ€” and every one of them excludes someone: the person with no money, no invitation, no reputation, or an old phone. That exclusion is a real harm falling on real people, usually the poorest. It should be chosen with open eyes, mitigated with fee waivers and alternative paths, and never solved by demanding government ID, which relocates the harm and enlarges it. Note also the weak empirical case for identity mandates as an anti-manipulation tool: the largest study of false-news diffusion found bots amplified true and false news at the same rate. Humans did the differential spreading.

Trade-off 3 โ€” discovery without profiling. Contextual relevance, self-declared interests, explicit subscriptions, chronological ordering, human curation and collaborative signals that never leave the device can all substitute โ€” but they are worse at the specific thing behavioural profiling is good at: keeping someone scrolling. The evidence is unambiguous and it comes from the platforms' own experiments: a chronological feed cut time on platform sharply. That is the price, and it is measured in revenue. It is also why this must be a legal duty rather than a voluntary setting: a company that ships it alone is punished by the market.

Trade-off 4 โ€” money. Quantify it honestly. A family-safety app with about 33 million users grew data revenue from $693,000 in 2016 to roughly $16 million in 2020 โ€” nearly 20% of annual revenue โ€” plus $6 million from an insurance-analytics buyer, meaning location data flowing into a pricing pipeline and not merely an advertising one. That is what a company gives up when it stops. A house that collects nothing must find the money elsewhere โ€” subscription, donation, public funding, a paid professional tier โ€” and should publish its revenue model openly, so users know what is paying for the thing they are using.

Trade-off 5 โ€” you will be slower and less "smart". On-device computation is slower on old hardware, personalisation is worse at the start, and features that depend on a global behavioural model are simply unavailable. Some of that is a real product cost. Some of it is a product that respects the user.

Trade-off 6 โ€” the metadata you cannot refuse. Be honest about the floor. You cannot send a push notification without the platform's push service seeing that your app notified this device at this time โ€” and those records are exactly the kind a state can compel, from two companies, for every app that uses them. Server logs, IP addresses, the server name in a TLS handshake, content-delivery networks, app-store install telemetry and crash reports arrive whether you want them or not. And payment processors see your donors, which for a project funded by a giving vow is a disclosure to make in the donation flow rather than in a policy nobody reads. Account recovery without an email address or phone number, and abuse moderation without identity, are the two hardest problems in privacy engineering, and the two questions any serious reviewer will ask first. Say all of this before someone else does.

How a platform proves its claims instead of asserting them

Every reassuring statement quoted in this study came from a company about itself, and none of it was independently audited. The remedy is not better assertions. And note the discipline this cuts both ways: if we treat company reach figures as inflated, we must apply the same discount to company reassurance figures โ€” "practically no organic engagement", "0.002%", "less than 0.2 per cent". They come from the same source with the same interest.

  1. Publish a plain-language data map: every kit, every field, every recipient, updated when it changes, with a diff history. The most damning fact across all these cases is that no user, and often no developer, could have known.
  2. Publish the ranking change log and the experiment register: every change to the ranking function and every A/B test run on users โ€” date, population affected, metric optimised, outcome. This turns an invisible lever into an accountable one at almost no engineering cost.
  3. Label and archive every manually promoted item, exactly as paid advertising is archived. This is the specific capability that distinguishes an owner from an outsider; making it visible removes the asymmetry without removing the tool.
  4. Do the algorithmic due diligence even if no law designates you โ€” and publish the summary. India's Rule 12 requires the assessment; no statute requires publication. Publishing anyway is the transparency remedy, and it is a competitive signal.
  5. Red-team your own recommender with counterfactual accounts โ€” replay synthetic user journeys, measure what the system serves under each signal, and publish the audit. This is capability testing you can run before a regulator or an NGO runs it on you.
  6. Open-source the client and ship reproducible builds, so that "we compute on the device" is checkable rather than promised.
  7. Commission third-party audits and publish the reports, not attestations. An unpublished audit is a private reassurance.
  8. Publish a transparency report of government demands received, complied with and refused, with aggregate counts. Where blocking and takedown orders are confidential by rule, company-published aggregates are one of the few lawful sources of daylight.
  9. Make deletion verifiable. Show the user what was deleted, when, and what derived artefacts โ€” transcripts, embeddings, model contributions โ€” were deleted with it.
  10. Invite researchers, with a safe harbour: a written, binding commitment not to pursue good-faith security and privacy research.
  11. Publish honest denominators. "126 million exposed" and "0.004% of feed content" were the same finding, and only one of them entered public memory. Never publish reach without share.

And the only claim that is ever verifiable: open source, plus reproducible builds, plus published responses to legal demands. "We collect nothing" is a marketing sentence until a court order arrives and you can show that you had nothing to hand over.


Awakening โ€” the teaching design the evidence supports

What works

Technique-recognition prebunking. Roozenbeek, van der Linden, Goldberg, Rathje and Lewandowsky (2022) ran six randomised controlled studies (n=6,464) plus a field study on YouTube (n=22,632) using five short videos teaching manipulation techniques โ€” emotionally manipulative language, incoherence, false dichotomies, scapegoating and ad hominem. Recognition of those techniques improved across political affiliations. Teach the technique, not the verdict on a given story.

Accuracy prompts. Simply prompting people to consider accuracy improved the quality of what they subsequently shared, in survey experiments and a field experiment. Report it honestly: small effects with a mixed replication record outside the original samples. Still the cheapest intervention that exists.

Corrections. Correct falsehoods; backfire is rare and not a general phenomenon. The robust residue is the continued influence effect โ€” retracted information keeps partially influencing reasoning โ€” which argues for better-designed corrections (state the truth, explain the mechanism of the falsehood, do not merely negate), not for silence.

Frequency literacy โ€” the specific lesson this study can teach that almost nobody else is teaching. The biggest single jump in believing something is from the first to the second exposure, and returns are largely exhausted by around nine. The teachable habit follows directly: when a claim feels familiar and obviously true, that is precisely the moment to check where you first met it. Familiarity is not evidence. And: reading the same claim in four places that all reshare each other is one exposure repeated, not four independent confirmations.

Show people their own data. Every demonstration that moved policy was a data demonstration: the heatmap that outlined bases; the $160 purchase that mapped clinic visitors; the trial that followed one phone from a home to a clinic and back; the leaked broker file with familiar app names in it. Be honest about the limit: no study cited here measures the effect of showing an individual their own trail on that individual's subsequent behaviour. What we know is that these demonstrations changed institutional behaviour. The individual version โ€” run your own face through a face-search engine; open Exodus and look at the app you use most; open your own location timeline; open your television's settings โ€” is the same move at personal scale, and we offer it as a reasoned design choice, not as an evidenced intervention.

And the conclusion the evidence actually supports, even though it is counterintuitive for a study: win the defaults, not only the argument. A single operating-system prompt changed the tracking behaviour of hundreds of millions of people in weeks. A single default change moved location history onto the device and cut its retention from eighteen months to three. No privacy curriculum in history has done anything comparable. Teaching matters โ€” it is how defaults get demanded and how myths get corrected, which no enforcement action can do โ€” but a campaign that ends in a better-informed person and an unchanged default has won the smaller half.

What backfires

"Spot the fake news" games. Modirrousta-Galian and Higham (2023) reanalysed five studies of the widely deployed inoculation games using signal-detection analysis, which separates discrimination from response bias. The games "did not improve discrimination, but rather elicited more false responses to all news items" โ€” players became more sceptical of everything, including true reporting. A 2025 follow-up reached the same conclusion on Indian true and fake news headlines, so this is not an artefact of Western samples. Therefore: measure discrimination, never "reduced belief in fake headlines", before declaring any resilience programme a success. An intervention that manufactures blanket distrust of journalism is not a defence. It is a second injury.

Alarm aimed at the wrong organ. The microphone myth is the case study. It absorbs the public's entire supply of fear and points it at a sensor the evidence does not implicate, while the actual channel โ€” an auction message broadcast to thousands of recipients โ€” goes unnamed and unregulated.

Overstating a true finding. "Four data points identify 95% of people" is the most-repeated sentence in this field, and it is wrong in a way that lets data buyers dismiss the whole discipline as hype. The precise version โ€” unicity within a dataset, plus a trivially available auxiliary source, plus a police officer's own note that "if we are good at what we do, we should be able to figure out the owner" โ€” is more alarming, not less. Precision is not caution. Precision is the weapon.

Fear without a handhold. A document that proves everything is compromised and offers no achievable step produces fatalism, and fatalism serves the harvest. That is why every section of this study ends with what to do, and why the playbook is ranked by effort rather than by severity.

And the single most consequential thing this study must not do. Every repetition study cited here repeats true and false items alike, and belief rises in both. Repetition does not defeat truth-detection; it degrades the truth signal. If the teaching lands as "distrust anything repeated", we will have produced exactly the blanket cynicism the inoculation games produced. The correct lesson is narrower and harder: familiarity is not evidence โ€” for a claim in either direction. Check the first source. Count the independent ones.

The teaching sequence, in order

  1. Start with the debunk, not the threat. Open with the microphone, because it is the belief the audience already holds, and correcting it earns the right to be believed on everything after. Then say the sentence that reframes the whole study: nobody is listening, because they no longer need to.
  2. Teach the mechanism once, concretely: an app shows an ad; a message describing you and where you are is broadcast to an auction; thousands of companies may receive it; there is no technical control over what any of them keep. Five sentences. Everything else hangs off it.
  3. Teach frequency: familiarity is not evidence; the second exposure does most of the work; four reshares of one claim is one exposure.
  4. Teach the technique-recognition set โ€” emotional manipulation, false dichotomy, scapegoating, incoherence, ad hominem โ€” and add one this study is uniquely placed to teach: the missing denominator.
  5. Show them their own data โ€” the app permission list, the trackers inside their most-used app, the face search, the location timeline, the television setting.
  6. Hand them the ranked playbook, and stop.
  7. End on the working safeguard: public attention. It is not a metaphor. The documented remedies in this study were produced by a broadcaster's leak, a whistleblower's disclosure, an organisation's records request, a journalist's $160 purchase, a student's afternoon with a public heatmap, and a regulator who read the resulting coverage. The measurement is the infrastructure of accountability โ€” and it is also the only thing that corrects the myths.

Where we take the greatest care

What this study does not know

We do not know the denominator. Every case above surfaced because a leak, a journalist, a whistleblower, a breach or a regulator happened to catch it. There is no reason to believe they are representative. The enforcement rate is a rounding error, and saying so makes this study more credible, not less.

We do not know the long-run effect of ranking on a population. Every reassuring null in the scenario section comes from a three-to-six-week window, on consenting adults, in one country, in one election, in studies run in collaboration with the platform being studied. The repetition science predicts accumulation over months and years. Nobody has measured that. That hole is the honest centre of this study.

The evidence base is overwhelmingly American, British and European. Almost every case, statute, regulator and remedy above comes from those jurisdictions. For most readers of a study published in several languages, none of it applies directly. India appears substantially; the one genuinely global dataset here is a study of education technology across 49 countries. Africa, Latin America and most of Southeast Asia are absent. The bid stream is global. Our evidence is not.

We have almost no measured evidence on intimate-partner and family tracking outcomes โ€” the likeliest real location harm in an ordinary reader's life, which is why we moved the safety instruction forward despite the thin evidence; employer and exam-proctoring surveillance; kids' smartwatches; the resale layer where images and faceprints move between brokers; internet-shutdown efficacy; and closed encrypted messaging, where the dominant misinformation channel in much of the world has no ranking algorithm at all โ€” but where the repetition mechanism transfers perfectly, and forwarding limits are a documented non-censorship remedy.

And there is a whole half of the subject we did not prove. This study shows that data is taken. It does not show, end to end and with verified sources, what it costs a person in money: insurance pricing, credit scoring, welfare exclusion, employment monitoring, price discrimination. Those chains exist and are partly documented in the public record; our verification pass could not confirm the specific cases, figures and orders, so we have left them out rather than print them. A reader is entitled to know that the strongest emotional argument available to us โ€” here is the day your premium rose and here is why โ€” is the one we could not verify in time.

We do not know what the successor identifier layer is doing. This study is organised around device advertising identifiers, which is where the industry was. Hashed-email identifiers, server-side tagging, conversion endpoints and probabilistic fingerprinting route around every identifier-level remedy discussed here โ€” which is why identifier-level fixes keep failing, and why this document dates within a year unless it is revised.

What is genuinely contested, and is published as contested

QuestionStatus
Did psychographic microtargeting decide an election?No regulator or peer-reviewed study establishes it. The regulator that seized the servers concluded the modelling relied on standard commercial datasets and commonly available techniques, that the headline "data points" boast may have been an exaggeration, that there was internal scepticism about the accuracy of the processing, and that the harvested data concerned US-registered voters and could not have been used in the Brexit referendum. The theft was real; the mind control was not established.
Do recommender systems radicalise ordinary users?Contested; the best-identified studies point away from the algorithm as prime mover for the average user, and toward pre-existing demand plus subscriptions and off-platform links. A small, heavily exposed, high-susceptibility minority remains a real duty-of-care problem. Platform-specific and largely pre-short-video-era.
Does any given platform covertly manipulate political content for foreign users?Alleged and structurally plausible; not established in the public record. Client-side analysis cannot see server-side ranking, so it cannot prove safety either. The US Supreme Court declined to rest on this rationale.
Are 99.98% of a population re-identifiable from 15 attributes?A modelled probability of uniqueness, publicly contested in the peer-reviewed literature, not retracted. And it is a demographic result, not a location one.
Is unrecognised exposure a stronger driver of liking than recognised exposure?Contested, and it sits awkwardly beside the subliminal debunk. Scope it to liking of neutral stimuli in a laboratory; it has never been shown to change purchases, beliefs or votes.
Does false news travel through structurally different pathways?Contested; a size-matched reanalysis finds basic infectiousness, not a distinct diffusion architecture โ€” and bots amplified true and false news at the same rate.
Did India's RTI amendment remove the public-interest override?Unresolved. The Government says section 8(2) supplies it; opposition members and civil society say it does not.
What is the status of the US carrier forfeiture orders?Unresolved on appeal. Do not use the past tense.

What we refuse to claim

  • That anyone's phone is secretly recording their conversations to sell ads.
  • That troll farms flipped an election. The operations were real, deliberate and in some cases criminal; the persuasion was not demonstrated.
  • That a leaked pitch deck is evidence of a deployed capability. A marketing document is a marketing document.
  • That a company's marketing figure โ€” three billion devices, five billion people, fifty billion faces โ€” is a measurement. Every one of them is unaudited.
  • That an indictment is a conviction. Charging documents in this file were never tested at trial, and in one instance the prosecution moved to dismiss rather than proceed.
  • That a settlement is a finding of liability. The largest headline numbers here โ€” $95 million, $25 million, $5.8 million, $115 million โ€” were paid without admission.
  • That any national biometric vault has been breached. The documented failure is downstream propagation into poorly secured systems, which is serious enough, and is what that country's own supreme court acted on.
  • That an automated welfare system caused a specific number of deaths, or that a benefits scandal caused a specific number of child removals. Both inquiries documented severe harm; neither established causation.
  • That the "four points identify 95%" finding attaches a name. It is unicity.
  • That removing a foreign-owned app protects a population's data.
  • That any people, any faith, any nation's population, or any race is the adversary in this study.

Method notes we hold ourselves to

  • "No evidence found" is not "proven impossible." The largest test of covert audio used a method that could not have detected on-device transcription. The largest study of foreign-influence exposure did not detect effects; with 70% of exposure inside 1% of the sample, it is underpowered to rule out small ones.
  • Allegation hygiene. Where a complaint is quoted, we write "the agency alleged". Where an order is proposed, we say so. Where a settlement carries no admission, we say so in the same paragraph as the money โ€” never in a footnote.
  • Date-stamp everything that decays. "Remained pending", "still in litigation", "the agency stated it had stopped" โ€” every such sentence needs an explicit as of or it becomes false in translation without anyone editing it. A study whose whole argument is that precision protects credibility cannot afford claims that rot untouched.
  • Apply the discount in both directions, to company reassurance as well as company reach.
  • And one claim we dropped entirely. A vendor experiment frequently cited as corroborating the microphone debunk could not be verified โ€” the write-up is no longer online at any retrievable address, and the secondary attributions were unreachable. We removed it and rely on the peer-reviewed study instead. If a reader raises it, that is the honest answer.

The vow

We name a mechanism, never a people.

Where the record names an actor, we name the actor: a company, an agency, a court, a statute, a named executive, a named officer's note in a file. Where the record names a nation's law, we name the law โ€” and we name its analogues elsewhere in the same breath, because the finding is that every host state holds a lever, and relocating data changes who holds it, not whether one exists.

The clearest evidence for this vow is technical, and it is in the face-recognition record above: error rates vary by factors of ten to beyond a hundred across demographic groups โ€” and the pattern reverses for algorithms trained on different data. No people's faces are harder to recognise. The error follows whoever was in the training set. The machine is not describing a population. It is describing its own diet.

The same is true of every capability in this document. A prayer app became a collection surface not because of what its users believed but because of a tracking kit. A family-safety app sold children's coordinates not out of malice but out of a revenue line. A school photographed students in their bedrooms not by conspiracy but by a default setting nobody audited. A welfare system accused hundreds of thousands of citizens not from cruelty but from an averaging formula and an inverted burden of proof. A stalkerware detection map shows where a security product is sold, not where people spy on one another.

And the harm, when it lands, lands on worshippers, on patients, on children, on survivors, on organisers, on soldiers and on the officials who are supposed to be protecting them โ€” impartially, because the capability is in the data, not in the buyer's intentions.

That is why the remedies in this study are minimisation, deletion, consent, transparency, researcher access and due process โ€” and never silence. Every fact in this document, including every reassuring one, exists because someone was free to look and free to publish. A remedy that would have suppressed the exposรฉ would have suppressed the debunk with it.

We do not ask anyone to be quiet. We ask that less be taken.

เคคเคฎเคธเฅ‹ เคฎเคพ เคœเฅเคฏเฅ‹เคคเคฟเคฐเฅเค—เคฎเคฏโ€” from darkness, lead me to light. May every soul be free to look, free to speak, and free to be left alone.


Sources

Everything asserted above can be checked below. We have grouped the sources by what they establish, and named each one by author or institution, with a date and a location. Where a source is a company's own publication, a party's pleading, or an untested charging document, that is stated in the body text beside the claim it supports โ€” not hidden here. Where our verification pass could not open a primary document, the claim was dropped or marked unconfirmed rather than dressed in a citation.

Re-identification and the mathematics of a trail

  • de Montjoye, Hidalgo, Verleysen & Blondel, "Unique in the Crowd: The privacy bounds of human mobility," Scientific Reports 3:1376 โ€” 25 March 2013 โ€” https://www.nature.com/articles/srep01376
  • Rocher, Hendrickx & de Montjoye, "Estimating the success of re-identifications in incomplete datasets using generative models," Nature Communications 10:3069 โ€” 23 July 2019 โ€” https://www.nature.com/articles/s41467-019-10933-3

Measurement โ€” what is actually inside an ordinary app

  • Kollnig, Binns, Van Kleek, Lyngs, Zhao, Tinsman & Shadbolt, "Before and after GDPR: tracking in mobile apps," Internet Policy Review 10(4) โ€” 2021 โ€” https://arxiv.org/pdf/2112.11117
  • Kollnig, Binns, Dewitte, Van Kleek, Wang, Omeiza, Webb & Shadbolt, "A Fait Accompli? An Empirical Study into the Absence of Consent to Third-Party Tracking in Android Apps," SOUPS โ€” August 2021 โ€” https://arxiv.org/pdf/2106.09407
  • Kollnig, Shuba, Binns, Van Kleek & Shadbolt, "Are iPhones Really Better for Privacy?" PoPETs 2022(2):6โ€“24 โ€” 2022 โ€” https://arxiv.org/abs/2109.13722
  • Kollnig, Shuba, Van Kleek, Binns & Shadbolt, "Goodbye Tracking? Impact of iOS App Tracking Transparency and Privacy Labels," ACM FAccT โ€” June 2022 โ€” https://arxiv.org/abs/2204.03556
  • Reyes, Wijesekera, Reardon, Elazari, Razaghpanah, Vallina-Rodriguez & Egelman, "Won't Somebody Think of the Children? Examining COPPA Compliance at Scale," PoPETs 2018(3) โ€” 2018 โ€” https://petsymposium.org/popets/2018/popets-2018-0021.pdf
  • Pan, Ren, Lindorfer, Wilson & Choffnes, "Panoptispy: Characterizing Audio and Video Exfiltration from Android Applications," PoPETs 2018(4) โ€” 2018 โ€” https://petsymposium.org/popets/2018/popets-2018-0030.php and https://recon.meddle.mobi/panoptispy/
  • Northeastern Global News, "Is your smartphone spying on you?" โ€” 6 July 2018 โ€” https://news.northeastern.edu/2018/07/06/is-your-smartphone-spying-on-you/
  • Gizmodo (Hill / Fussell), "These Academics Spent the Last Year Testing Whether Your Phone Is Secretly Listening to You" โ€” 3 July 2018 โ€” https://gizmodo.com/these-academics-spent-the-last-year-testing-whether-you-1826961188

The bid stream โ€” the auction that carries you

  • Ryan & Christl, Irish Council for Civil Liberties / Cracked Labs, "Europe's hidden security crisis" and "America's hidden security crisis" โ€” 14 November 2023 โ€” https://www.iccl.ie/wp-content/uploads/2023/11/Europes-hidden-security-crisis.pdf and https://www.iccl.ie/wp-content/uploads/2023/11/Americas-hidden-security-crisis.pdf
  • Johnny Ryan / ICCL, "The Biggest Data Breach" โ€” the real-time-bidding scale estimate, published with its own methodology caveat โ€” 16 May 2022 โ€” https://www.iccl.ie/news/iccl-report-on-the-scale-of-real-time-bidding-data-broadcasts-in-the-u-s-and-europe/
  • Belgian Data Protection Authority, decision on IAB Europe and the Transparency and Consent Framework (โ‚ฌ250,000) โ€” 2 February 2022 โ€” https://www.dataprotectionauthority.be/citizen/iab-europe-held-responsible-for-a-mechanism-that-infringes-the-gdpr
  • Court of Justice of the European Union, Case C-604/22 (IAB Europe) โ€” 7 March 2024 โ€” cited by case reference; the judgment text was not retrieved in our verification pass.
  • Anthony Chavez, Google, "Update on Plans for Privacy Sandbox Technologies" โ€” 17 October 2025 โ€” https://privacysandbox.google.com/blog/update-on-plans-for-privacy-sandbox-technologies
  • Autoritรฉ de la concurrence (France), decision 25-D-02, โ‚ฌ150,000,000 fine on Apple over the implementation of App Tracking Transparency โ€” 31 March 2025 โ€” https://www.autoritedelaconcurrence.fr/en/press-release/targeted-advertising-autorite-de-la-concurrence-imposes-fine-eu150000000-apple
  • AppsFlyer, "Mobile Ad Market Thrives 4 Years After ATT" โ€” 24 April 2025 โ€” https://www.appsflyer.com/company/newsroom/pr/post-att-growth/

Brokers, buyers and the price list

  • Bennett Cyphers, Electronic Frontier Foundation, "Inside Fog Data Science, the Secretive Company Selling Mass Surveillance to Local Police" โ€” 31 August 2022 โ€” https://www.eff.org/deeplinks/2022/08/inside-fog-data-science-secretive-company-selling-mass-surveillance-local-police
  • Joseph Cox, VICE Motherboard, on SafeGraph "Patterns" data covering reproductive-health facilities โ€” 3 May 2022 โ€” https://www.vice.com/en/article/m7vzjb/location-data-abortion-clinics-safegraph-planned-parenthood
  • Joseph Cox, 404 Media, "Candy Crush, Tinder, MyFitnessPal: See the Thousands of Apps Hijacked to Spy on Your Location" โ€” 9 January 2025 โ€” https://www.404media.co/candy-crush-tinder-myfitnesspal-see-the-thousands-of-apps-hijacked-to-spy-on-your-location/
  • Brian Krebs, "The Global Surveillance Free-for-All in Mobile Ad Data" (Babel Street's Locate X) โ€” 23 October 2024 โ€” https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/
  • Joseph Cox, 404 Media, "Inside the U.S. Government-Bought Tool That Can Track Phones at Abortion Clinics" โ€” 23 October 2024 โ€” https://www.404media.co/inside-the-u-s-government-bought-tool-that-can-track-phones-at-abortion-clinics/
  • Sherman, Barton, Klein, Kruse & Srinivasan, "Data Brokers and the Sale of Data on U.S. Military Personnel," Duke Sanford School of Public Policy (funded by the United States Military Academy) โ€” November 2023 โ€” https://techpolicy.sanford.duke.edu/data-brokers-and-the-sale-of-data-on-us-military-personnel/
  • Joseph Cox & Dhruv Mehrotra, 404 Media / WIRED, on advertising data and military personnel in Germany โ€” 11 February 2025 โ€” https://www.404media.co/eskimi-2/ and https://www.wired.com/story/rtb-location-data-us-military/
  • Sam Biddle & Jack Poulson, The Intercept, "American Phone-Tracking Firm Demo'd Surveillance Powers by Spying on CIA and NSA" โ€” 22 April 2022 โ€” https://theintercept.com/2022/04/22/anomaly-six-phone-tracking-zignal-surveillance-cia-nsa/
  • Jon Keegan & Alfred Ng, The Markup, "The Popular Family Safety App Life360 Is Selling Precise Location Data on Its Tens of Millions of Users" โ€” 6 December 2021 โ€” https://themarkup.org/privacy/2021/12/06/the-popular-family-safety-app-life360-is-selling-precise-location-data-on-its-tens-of-millions-of-user
  • Joseph Cox, VICE Motherboard, "Muslim Pro Stops Sharing Location Data After Motherboard Investigation" โ€” 16โ€“17 November 2020 โ€” https://www.vice.com/en/article/g5bq89/muslim-pro-location-data-military-xmode
  • Michelle Boorstein and colleagues, The Washington Post, "Colorado Catholic group bought app data that tracked gay priests" โ€” 9 March 2023 โ€” https://www.washingtonpost.com/dc-md-va/2023/03/09/catholics-gay-priests-grindr-data-bishops/
  • Katz-Lacabe, Golbeck & Ryan v. Oracle America, Inc., No. 3:22-cv-04792 (N.D. Cal.), complaint filed 19 August 2022; reported $115m settlement โ€” https://www.classaction.org/media/katz-lacabe-et-al-v-oracle-america-inc.pdf
  • California Privacy Protection Agency, Data Broker Registry and the Delete Request and Opt-out Platform (DROP) โ€” accessed July 2026 โ€” https://cppa.ca.gov/data_broker_registry/ and https://cppa.ca.gov/data_brokers/
  • Forbrukerrรฅdet (Norwegian Consumer Council), "Out of Control: How consumers are exploited by the online advertising industry" โ€” 14 January 2020 โ€” https://fil.forbrukerradet.no/wp-content/uploads/2020/01/2020-01-14-out-of-control-final-version.pdf
  • Stuart A. Thompson & Charlie Warzel, "Twelve Million Phones, One Dataset, Zero Privacy," The New York Times Privacy Project โ€” 19 December 2019 โ€” https://www.nytimes.com/interactive/2019/12/19/opinion/location-tracking-cell-phone.html

Enforcement โ€” United States

  • FTC, order prohibiting X-Mode Social / Outlogic from selling sensitive location data โ€” 9 January 2024 โ€” https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data
  • FTC, action against Gravy Analytics and Venntel โ€” 3 December 2024 โ€” https://www.ftc.gov/news-events/news/press-releases/2024/12/ftc-takes-action-against-gravy-analytics-venntel-unlawfully-selling-location-data-tracking-consumers
  • FTC, action against Mobilewalla โ€” the first allegation that harvesting bid-stream data is an unfair practice โ€” 3 December 2024 โ€” https://www.ftc.gov/news-events/news/press-releases/2024/12/ftc-takes-action-against-mobilewalla-collecting-selling-sensitive-location-data
  • FTC, settlement with Kochava and Collective Data Solutions โ€” reported 4 May 2026; our pass could not open the release, so entry of the order by the District Court is recorded here as reported and unconfirmed โ€” https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-ban-kochava-subsidiary-selling-sensitive-location-data-settle-charges-they-sold-location-data
  • FTC, "FTC Order Will Ban Avast from Selling Browsing Data for Advertising Purposes" โ€” 22 February 2024 โ€” https://www.ftc.gov/news-events/news/press-releases/2024/02/ftc-order-will-ban-avast-selling-browsing-data-advertising-purposes-require-it-pay-165-million-over
  • FTC, "FTC Bans SpyFone and CEO from Surveillance Business" โ€” 1 September 2021 โ€” https://www.ftc.gov/news-events/news/press-releases/2021/09/ftc-bans-spyfone-ceo-surveillance-business-orders-company-delete-all-secretly-stolen-data
  • FTC, "FTC Says Ring Employees Illegally Surveilled Customersโ€ฆ" (including the order to delete models and algorithms derived from unlawfully reviewed video) โ€” 31 May 2023 โ€” https://www.ftc.gov/news-events/news/press-releases/2023/05/ftc-says-ring-employees-illegally-surveilled-customers-failed-stop-hackers-taking-control-users
  • FTC and DOJ, complaint against Amazon over children's Alexa recordings, matter 192-3128 โ€” 31 May 2023 โ€” https://www.ftc.gov/news-events/news/press-releases/2023/05/ftc-doj-charge-amazon-violating-childrens-privacy-law-keeping-kids-alexa-voice-recordings-forever
  • FTC, final order in the Flo Health matter โ€” 22 June 2021 โ€” https://www.ftc.gov/news-events/news/press-releases/2021/06/ftc-finalizes-order-flo-health-fertility-tracking-app-shared-sensitive-health-data-facebook-google
  • FTC, settlement with Zoom over encryption representations โ€” 9 November 2020 โ€” https://www.ftc.gov/news-events/news/press-releases/2020/11/ftc-requires-zoom-enhance-its-security-practices-part-settlement
  • FTC, warning letters to app developers using SilverPush code โ€” 17 March 2016 โ€” https://www.ftc.gov/news-events/news/press-releases/2016/03/ftc-issues-warning-letters-app-developers-using-silverpush-code
  • FTC, "$5 Billion Penalty and Sweeping New Privacy Restrictions on Facebook" โ€” 24 July 2019 โ€” https://www.ftc.gov/news-events/press-releases/2019/07/ftc-imposes-5-billion-penalty-sweeping-new-privacy-restrictions
  • FTC, "Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States" โ€” 22 July 2019 โ€” https://www.ftc.gov/news-events/news/press-releases/2019/07/equifax-pay-575-million-part-settlement-ftc-cfpb-states-related-2017-data-breach
  • FTC Staff Report, "A Look Behind the Screens: Examining the Data Practices of Social Media and Video Streaming Services" (Section 6(b)) โ€” September 2024 โ€” https://www.ftc.gov/reports/look-behind-screens-examining-data-practices-social-media-video-streaming-services
  • FCC, forfeiture orders against AT&T, Sprint, T-Mobile and Verizon (~$200m) โ€” 29 April 2024 โ€” challenged by the carriers; appellate status unresolved as of July 2026 โ€” https://docs.fcc.gov/public/attachments/DOC-402213A1.pdf
  • DHS Office of Inspector General, OIG-23-61, on CBP, ICE and Secret Service procurement of commercial telemetry data โ€” September 2023 โ€” the finding is cited; its specific figures were not re-verified and are omitted โ€” https://www.oig.dhs.gov/sites/default/files/assets/2023-09/OIG-23-61-Sep23-Redacted.pdf
  • Public Law 118-50, Division I โ€” Protecting Americans' Data from Foreign Adversaries Act of 2024, 15 U.S.C. 9901 โ€” approved 24 April 2024 โ€” https://www.congress.gov/118/plaws/publ50/PLAW-118publ50.htm
  • US Department of Justice, National Security Division, Data Security Program (Executive Order 14117; 28 C.F.R. Part 202, including ยง 202.206) โ€” effective 8 April 2025 โ€” https://www.justice.gov/nsd/data-security and https://www.ecfr.gov/current/title-28/part-202
  • Congressional Research Service LSB11314, "The TAKE IT DOWN Act" โ€” 2025 โ€” https://www.congress.gov/crs-product/LSB11314

Courts

  • Chatrie v. United States, No. 25-112 โ€” decided 29 June 2026 โ€” https://www.supremecourt.gov/opinions/ (docket summary: https://www.scotusblog.com/cases/case-files/chatrie-v-united-states/)
  • Carpenter v. United States, 585 U.S. 296 โ€” 22 June 2018
  • TikTok Inc. v. Garland, 604 U.S. ___ (per curiam) โ€” 17 January 2025 โ€” https://www.supremecourt.gov/opinions/24pdf/24-656_ca7d.pdf ; Congressional Research Service LSB11261 โ€” https://www.everycrsreport.com/reports/LSB11261.html
  • ACLU of Illinois, settlement in ACLU et al. v. Clearview AI (permanent nationwide bar under the Illinois Biometric Information Privacy Act) โ€” 9 May 2022 โ€” https://www.aclu.org/press-releases/big-win-settlement-ensures-clearview-ai-complies-with-groundbreaking-illinois
  • National Law Review, on the Clearview class settlement granting class members an equity stake (final approval, N.D. Ill., 20 March 2025) โ€” March 2025 โ€” https://natlawreview.com/article/first-bipa-litigation-class-members-receive-equity-clearview-ai
  • ACLU, Williams v. City of Detroit โ€” settlement and binding policy terms on facial recognition โ€” 28 June 2024 โ€” https://www.aclu.org/press-releases/civil-rights-advocates-achieve-the-nations-strongest-police-department-policy-on-facial-recognition-technology
  • Ogletree v. Cleveland State University (N.D. Ohio) โ€” 22 August 2022 โ€” https://caselaw.findlaw.com/court/us-dis-crt-n-d-ohi-eas-div/2109381.html
  • Lopez v. Apple Inc., N.D. Cal. No. 4:19-cv-04577-JSW โ€” $95m Siri settlement, final approval October 2025, no admission of liability โ€” https://www.lopezvoiceassistantsettlement.com/
  • District Court of The Hague, NJCM et al. v. Netherlands (SyRI), ECLI:NL:RBDHA:2020:1878 โ€” 5 February 2020 โ€” https://www.escr-net.org/caselaw/2020/nederlands-juristen-comite-voor-mensenrechten-et-al-v-netherlands-eclinlrbdha20201878/
  • Prygodicz v Commonwealth of Australia (No 2) [2021] FCA 634 โ€” 11 June 2021 โ€” https://www.judgments.fedcourt.gov.au/judgments/Judgments/fca/single/2021/2021fca0634
  • Supreme Court of India, K.S. Puttaswamy v. Union of India (privacy, nine judges) โ€” 24 August 2017 โ€” https://www.scobserver.in/cases/puttaswamy-v-union-of-india-fundamental-right-to-privacy-case-background/
  • Supreme Court of India, K.S. Puttaswamy v. Union of India (Aadhaar), striking down section 57 on function-creep and proportionality grounds โ€” 26 September 2018 โ€” https://main.sci.gov.in/supremecourt/2012/35071/35071_2012_Judgement_26-Sep-2018.pdf

Enforcement โ€” Europe and elsewhere

  • Autoriteit Persoonsgegevens (Netherlands), โ‚ฌ30.5m fine on Clearview AI โ€” 3 September 2024 โ€” https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for-facial-recognition
  • UK Information Commissioner's Office, Clearview AI enforcement notice and monetary penalty notice โ€” 18 May 2022 โ€” https://ico.org.uk/action-weve-taken/enforcement/clearview-ai-inc-mpn/
  • noyb, criminal complaint against Clearview AI over unpaid penalties โ€” October 2025 โ€” https://noyb.eu/en/criminal-complaint-against-facial-recognition-company-clearview-ai
  • Autoriteit Persoonsgegevens, "Tax Administration fined for discriminatory and unlawful data processing" (โ‚ฌ2.75m) โ€” December 2021 โ€” https://www.autoriteitpersoonsgegevens.nl/en/current/tax-administration-fined-for-discriminatory-and-unlawful-data-processing
  • Datatilsynet (Norway), "Record fine in the Grindr case confirmed" (NOK 65m) โ€” 29 September 2023 โ€” https://www.datatilsynet.no/en/news/news-2023/record-fine-grindr-confirmed/
  • Office of the Data Protection Ombudsman (Finland), โ‚ฌ608,000 fine on Vastaamo โ€” December 2021 โ€” https://tietosuoja.fi/en/-/psychotherapy-centre-vastaamo-issued-with-an-administrative-fine
  • TechCrunch (Natasha Lomas), "Google ordered to halt human review of voice AI recordings over privacy risks" โ€” the Hamburg authority's GDPR Article 66 urgency procedure โ€” 2 August 2019 โ€” https://techcrunch.com/2019/08/02/google-ordered-to-halt-human-review-of-voice-ai-recordings-over-privacy-risks/
  • EU Artificial Intelligence Act, Article 5 (including 5(1)(e), untargeted scraping to build facial-recognition databases), applicable 2 February 2025 โ€” https://artificialintelligenceact.eu/article/5/
  • Royal Commission into the Robodebt Scheme (Australia), Final Report โ€” 7 July 2023 โ€” https://robodebt.royalcommission.gov.au/publications/report

Voice assistants and the microphone record

  • VRT NWS, "Google employees are eavesdropping, even in Flemish living rooms" โ€” 10 July 2019 โ€” https://www.vrt.be/vrtnws/en/2019/07/10/google-employees-are-eavesdropping-even-in-flemish-living-rooms/
  • Apple Newsroom, "Improving Siri's privacy protections" โ€” 28 August 2019 โ€” https://www.apple.com/newsroom/2019/08/improving-siris-privacy-protections/
  • Apple Newsroom, "Our longstanding privacy commitment with Siri" โ€” 8 January 2025 โ€” https://www.apple.com/newsroom/2025/01/our-longstanding-privacy-commitment-with-siri/
  • MIT Technology Review, on The Guardian's Siri grading whistleblower โ€” 29 July 2019 โ€” https://www.technologyreview.com/2019/07/29/134008/apple-contractors-hear-confidential-details-from-siri-recordings/
  • Joseph Cox, Motherboard / VICE, "Microsoft Contractors Listen to Skype Calls" โ€” 7 August 2019 โ€” https://www.vice.com/en/article/microsoft-contractors-listen-to-skype-calls/
  • Sarah Frier, Bloomberg, "Facebook Paid Hundreds of Contractors to Transcribe Users' Audio" โ€” 13 August 2019 โ€” https://www.bloomberg.com/news/articles/2019-08-13/facebook-paid-hundreds-of-contractors-to-transcribe-users-audio
  • TechCrunch, "Amazon's Echo will send all voice recordings to the cloud starting March 28" โ€” 15 March 2025 โ€” https://techcrunch.com/2025/03/15/amazons-echo-will-send-all-voice-recordings-to-the-cloud-starting-march-28/
  • 404 Media, "Here's the Pitch Deck for 'Active Listening' Ad Targeting" (Cox Media Group) โ€” a marketing document, not a finding โ€” 26 August 2024 โ€” https://www.404media.co/heres-the-pitch-deck-for-active-listening-ad-targeting/

Sensors and side channels

  • Arp, Quiring, Wressnegger & Rieck, "Privacy Threats through Ultrasonic Side Channels on Mobile Devices," IEEE EuroS&P 2017, pp. 35โ€“47 โ€” 2017 โ€” https://mlsec.org/docs/2017a-eurosp.pdf
  • Michalevsky, Nakibly & Boneh, "Gyrophone: Recognizing Speech from Gyroscope Signals," USENIX Security โ€” 2014 โ€” https://crypto.stanford.edu/gyrophone/
  • Anand, Wang, Liu, Saxena & Chen, "Motion Sensor-based Privacy Attack on Smartphones" (Spearphone, ACM WiSec 2021) โ€” arXiv:1907.05972 โ€” https://arxiv.org/abs/1907.05972
  • Najeeb, Rafay, Bhatti & Alizai, "Glitch in Time: Exploiting Temporal Misalignment of IMU For Eavesdropping" (STAG), AsiaCCS 2025 โ€” arXiv:2409.16438 โ€” a research capability, with no public reporting of deployment in the wild โ€” https://arxiv.org/abs/2409.16438
  • Rye & Levin, "Surveilling the Masses with Wi-Fi-Based Positioning Systems," IEEE Symposium on Security and Privacy 2024 โ€” arXiv, 23 May 2024 โ€” https://arxiv.org/abs/2405.14975
  • Jamf Threat Labs, "How Predator spyware defeats iOS recording indicators" โ€” 19 February 2026 โ€” https://www.jamf.com/blog/predator-spyware-ios-recording-indicator-bypass-analysis/
  • Keith Collins, Quartz, on Android cell-tower identifier collection with location services off โ€” 21 November 2017 โ€” https://qz.com/1131515/google-collects-android-users-locations-even-when-location-services-are-disabled

Face, children and image abuse

  • NIST Interagency Report 8280, "Face Recognition Vendor Test Part 3: Demographic Effects" (Grother, Ngan, Hanaoka) โ€” December 2019 โ€” the source of the finding that the demographic error pattern reverses for algorithms trained on different data โ€” https://nvlpubs.nist.gov/nistpubs/ir/2019/nist.ir.8280.pdf
  • Buolamwini & Gebru, "Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification," PMLR 81 โ€” 2018 โ€” a study of gender classification, not identification โ€” https://proceedings.mlr.press/v81/buolamwini18a/buolamwini18a.pdf
  • Metropolitan Police Service, live facial recognition statistics and the National Physical Laboratory evaluation โ€” accessed July 2026 โ€” https://www.met.police.uk/police-forces/metropolitan-police/areas/about-us/about-the-met/facial-recognition-technology/
  • Human Rights Watch, "Brazil: Children's Personal Photos Misused to Power AI Tools" โ€” 10 June 2024 โ€” https://www.hrw.org/news/2024/06/10/brazil-childrens-personal-photos-misused-power-ai-tools
  • Human Rights Watch, "720 Australian and Brazilian Children Better Protected from AI Misuse" โ€” 3 September 2024 โ€” https://www.hrw.org/news/2024/09/03/720-australian-and-brazilian-children-better-protected-ai-misuse
  • Internet Watch Foundation, research on AI-generated child sexual abuse imagery โ€” 2026 โ€” https://www.iwf.org.uk/about-us/why-we-exist/our-research/how-ai-is-being-abused-to-create-child-sexual-abuse-imagery/
  • Engadget and Malwarebytes Labs, on the San Francisco City Attorney's cease-and-desist letters to Apple and Google over nudification apps โ€” July 2026 โ€” https://www.engadget.com/2217578/apple-and-google-ordered-by-san-francisco-attorney-to-take-action-against-nudify-apps/
  • Kaspersky Securelist, "The State of Stalkerware" โ€” a vendor detection count, which is a floor and a map of where a product is sold, not a prevalence estimate โ€” 13 March 2024 โ€” https://securelist.com/state-of-stalkerware-2023/111169/

The television, the classroom and the genome

  • "Watching TVs Watching Us" โ€” black-box audit of automatic content recognition on Samsung and LG televisions, ACM Internet Measurement Conference 2024 โ€” arXiv:2409.06203 โ€” https://arxiv.org/abs/2409.06203
  • Human Rights Watch, "How Dare They Peep into My Private Life? Children's Rights Violations by Governments that Endorsed Online Learning During the Covid-19 Pandemic" โ€” 25 May 2022 โ€” https://www.hrw.org/report/2022/05/25/how-dare-they-peep-my-private-life/childrens-rights-violations-governments
  • The 23andMe record โ€” the October 2023 credential-stuffing compromise, the Chapter 11 filing of 23 March 2025, the sale completed 14 July 2025, and the UK Information Commissioner's ยฃ2.31m penalty of June 2025 โ€” https://en.wikipedia.org/wiki/23andMe (consolidated summary; the underlying regulator and court documents are the primary record)

Repetition, belief and ranking

  • Hasher, Goldstein & Toppino, "Frequency and the conference of referential validity" โ€” 1977 โ€” https://doi.org/10.1016/S0022-5371(77)80012-1
  • Dechรชne, Stahl, Hansen & Wรคnke, "The truth about the truth: a meta-analytic review of the truth effect" (51 studies) โ€” 2010 โ€” https://doi.org/10.1177/1088868309352251
  • Fazio, Brashier, Payne & Marsh, "Knowledge does not protect against illusory truth" โ€” 2015 โ€” https://doi.org/10.1037/xge0000098
  • Fazio, Rand & Pennycook, "Repetition increases perceived truth equally for plausible and implausible statements" โ€” 2019 โ€” https://pubmed.ncbi.nlm.nih.gov/31420808/
  • Pennycook, Cannon & Rand, "Prior exposure increases perceived accuracy of fake news" โ€” 2018 โ€” https://doi.org/10.1037/xge0000465
  • Hassan & Barber, "The effects of repetition frequency on the illusory truth effect" โ€” 2021 โ€” https://doi.org/10.1186/s41235-021-00301-5
  • Fazio, Pillai & Patel, "The effects of repetition on belief in naturalistic settings" โ€” the fifteen-day text-message study โ€” 2022 โ€” https://doi.org/10.1037/xge0001211
  • Henderson et al., "The Trajectory of Truth: A Longitudinal Study of the Illusory Truth Effect," Journal of Cognition โ€” 2021 โ€” https://journalofcognition.org/articles/10.5334/joc.161
  • Pillai, Fazio & Effron, "Repeatedly Encountered Descriptions of Wrongdoing Seem More True but Less Unethical," Psychological Science โ€” 2023 โ€” https://doi.org/10.1177/09567976231180578
  • Brady, Wills, Jost, Tucker & Van Bavel, "Emotion shapes the diffusion of moralized content in social networks," PNAS โ€” 2017 โ€” https://doi.org/10.1073/pnas.1618923114
  • Vosoughi, Roy & Aral, "The spread of true and false news online," Science 359:1146โ€“1151 โ€” 2018 โ€” https://pubmed.ncbi.nlm.nih.gov/29590045/
  • Juul & Ugander, "Comparing information diffusion mechanisms by matching on cascade size," PNAS โ€” 2021 โ€” https://www.pnas.org/doi/10.1073/pnas.2100786118
  • Milli, Carroll, Wang, Pandey, Zhao & Dragan, "Engagement, user satisfaction, and the amplification of divisive content on social media," PNAS Nexus 4(3) pgaf062 โ€” 2025 โ€” https://academic.oup.com/pnasnexus/article/4/3/pgaf062/8052060
  • Kramer, Guillory & Hancock, "Experimental evidence of massive-scale emotional contagion through social networks," PNAS โ€” 2014 โ€” with the PNAS Editorial Expression of Concern of 3 July 2014 โ€” https://doi.org/10.1073/pnas.1320040111 and https://www.pnas.org/doi/10.1073/pnas.1412469111
  • The Wall Street Journal, "The Facebook Files" โ€” from 15 September 2021 โ€” https://www.wsj.com/articles/facebook-algorithm-change-zuckerberg-11631654215
  • Merrill & Oremus, The Washington Post, on the weighting of the angry reaction โ€” 26 October 2021 โ€” https://www.washingtonpost.com/technology/2021/10/26/facebook-angry-emoji-algorithm/

Persuasion, influence operations, and the findings that cut against us

  • Eady, Paskhalis, Zilinsky, Bonneau, Nagler & Tucker, "Exposure to the Russian Internet Research Agency foreign influence campaign on Twitter in the 2016 US electionโ€ฆ," Nature Communications 14:62 โ€” 9 January 2023 โ€” https://www.nature.com/articles/s41467-022-35576-9
  • Guess et al., "How do social media feed algorithms affect attitudes and behavior in an election campaign?", Science โ€” 2023 โ€” https://doi.org/10.1126/science.abp9364
  • Guess et al., "Reshares on social media amplify political news but do not detectably affect beliefs or opinions," Science โ€” 2023 โ€” https://doi.org/10.1126/science.add8424
  • Nyhan et al., "Like-minded sources on Facebook are prevalent but not polarizing," Nature 620 โ€” 2023 โ€” https://doi.org/10.1038/s41586-023-06297-w
  • Allcott, Gentzkow et al., "The effects of Facebook and Instagram on the 2020 election: A deactivation experiment," PNAS 121 โ€” 2024 โ€” https://www.pnas.org/doi/10.1073/pnas.2321584121
  • Budak, Nyhan, Rothschild, Thorson & Watts, "Misunderstanding the harms of online misinformation," Nature 630(8015):45โ€“53 โ€” June 2024 โ€” https://www.nature.com/articles/s41586-024-07417-w
  • Matz, Kosinski, Nave & Stillwell, "Psychological targeting as an effective approach to digital mass persuasion," PNAS โ€” 2017 โ€” with the Eckles, Gordon & Johnson critique of 2018 โ€” https://www.pnas.org/doi/10.1073/pnas.1710966114 and https://www.pnas.org/doi/10.1073/pnas.1805363115
  • Tappin, Wittenberg, Hewitt, Berinsky & Rand, "Quantifying the potential persuasive returns to political microtargeting," PNAS โ€” 2023 โ€” https://www.pnas.org/doi/10.1073/pnas.2216261120
  • Coppock, Hill & Vavreck, "The small effects of political advertising are small regardless of context, message, sender, or receiver," Science Advances โ€” 2020 โ€” https://doi.org/10.1126/sciadv.abc4046
  • Kalla & Broockman, "The Minimal Persuasive Effects of Campaign Contact in General Elections," American Political Science Review 112(1):148โ€“166 โ€” February 2018 โ€” measuring campaign contact, with non-zero effects in primaries and ballot measures โ€” https://doi.org/10.1017/S0003055417000363
  • Ben Nimmo, "The Breakout Scale: Measuring the impact of influence operations," Brookings โ€” September 2020 โ€” a measurement framework, not an empirical study โ€” https://www.brookings.edu/articles/the-breakout-scale-measuring-the-impact-of-influence-operations/
  • Google Threat Analysis Group, DRAGONBRIDGE disruption bulletins โ€” 26 January 2023 and Q1 2024 โ€” company disclosures, unaudited โ€” https://blog.google/threat-analysis-group/over-50000-instances-of-dragonbridge-activity-disrupted-in-2022/ and https://blog.google/threat-analysis-group/google-disrupted-dragonbridge-activity-q1-2024/
  • Meta, "Raising Online Defenses Through Transparency and Collaboration" โ€” 29 August 2023 โ€” https://about.fb.com/news/2023/08/raising-online-defenses/
  • US Department of Justice, "Justice Department Disrupts Covert Russian Government-Sponsored Foreign Malign Influence Operation" โ€” an affidavit contains allegations โ€” 4 September 2024 โ€” https://www.justice.gov/archives/opa/pr/justice-department-disrupts-covert-russian-government-sponsored-foreign-malign-influence
  • DFRLab, "Doppelganger websites persist one month following US government seizures" โ€” 9 October 2024 โ€” https://dfrlab.org/2024/10/09/doppelganger-websites-persist/
  • EU DisinfoLab, "Doppelganger โ€” Media clones serving Russian propaganda" โ€” 27 September 2022 โ€” https://www.disinfo.eu/doppelganger
  • US Senate Select Committee on Intelligence, two independent analyses of Internet Research Agency social-media tactics โ€” 17 December 2018 โ€” https://www.intelligence.senate.gov/2018/12/17/press-new-reports-shed-light-internet-research-agency-e2-80-99s-social-media-tactics/
  • Privacy and Civil Liberties Oversight Board, "Report on the Telephone Records Program Conducted under Section 215" โ€” 23 January 2014 โ€” https://documents.pclob.gov/prod/Documents/OversightReport/ec542143-1079-424a-84b3-acc354698560/215-Report_on_the_Telephone_Records_Program.pdf
  • UK Information Commissioner's Office, conclusion of the investigation into data analytics for political purposes โ€” October 2020 โ€” the ICO's findings are paraphrased in this study, not quoted โ€” https://ico.org.uk/action-weve-taken/investigation-into-data-analytics-for-political-purposes/

Resilience and teaching

  • Roozenbeek, van der Linden, Goldberg, Rathje & Lewandowsky, "Psychological inoculation improves resilience against misinformation on social media," Science Advances 8(34) eabo6254 โ€” 2022 โ€” https://doi.org/10.1126/sciadv.abo6254
  • Modirrousta-Galian & Higham, "Gamified inoculation interventions do not improve discrimination between true and fake news," Journal of Experimental Psychology: General โ€” 2023 โ€” the finding that matters most to anyone designing a programme โ€” https://doi.org/10.1037/xge0001395
  • Pennycook, Epstein, Mosleh, Arechar, Eckles & Rand, "Shifting attention to accuracy can reduce misinformation online," Nature โ€” 2021 โ€” https://doi.org/10.1038/s41586-021-03344-2
  • Wood & Porter, "The Elusive Backfire Effect: Mass Attitudes' Steadfast Factual Adherence," Political Behavior 41(1):135โ€“163 โ€” 2019 โ€” https://doi.org/10.1007/s11109-018-9443-y
  • Amnesty International, "Driven into Darkness: How TikTok's For You Feed Encourages Self-Harm and Suicidal Ideation" (POL 40/7350/2023) โ€” 7 November 2023 โ€” https://www.amnesty.org/en/documents/pol40/7350/2023/en/
  • Pratkanis, "The Cargo-Cult Science of Subliminal Persuasion," Skeptical Inquirer 16(3):260โ€“272 โ€” 1992

Platform ownership, apps and states

  • Emily Baker-White, Forbes, "TikTok Spied On Forbes Journalists" โ€” 22 December 2022 โ€” https://www.forbes.com/sites/emilybaker-white/2022/12/22/tiktok-tracks-forbes-journalists-bytedance/
  • Emily Baker-White, Forbes, "TikTok's Secret 'Heating' Button Can Make Anyone Go Viral" โ€” 20 January 2023 โ€” https://www.forbes.com/sites/emilybaker-white/2023/01/20/tiktoks-secret-heating-button-can-make-anyone-go-viral/
  • Citizen Lab, "TikTok vs Douyin: A Security and Privacy Analysis" โ€” 22 March 2021 โ€” the study that found no covert collection and said client-side analysis cannot prove safety either โ€” https://citizenlab.ca/2021/03/tiktok-vs-douyin-security-privacy-analysis/
  • Donald Clarke / Lawfare, analysis of the PRC National Intelligence Law, articles 7 and 14 โ€” 2017 โ€” https://www.lawfaremedia.org/article/beijings-new-national-intelligence-law-defense-offense
  • US CLOUD Act, 18 U.S.C. ยง 2713 โ€” 2018 โ€” overview: https://en.wikipedia.org/wiki/CLOUD_Act
  • Foreign Intelligence Surveillance Act ยง 702 and the Reforming Intelligence and Securing America Act, 20 April 2024, with the FISC-documented compliance findings โ€” overview: https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act
  • Amnesty International Security Lab, "Forensic Methodology Report: How to catch NSO Group's Pegasus" โ€” 18 July 2021 โ€” https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/
  • CyberScoop, on WhatsApp Inc. v. NSO Group โ€” the permanent injunction and the reduction of punitive damages โ€” 17 October 2025 โ€” https://cyberscoop.com/whatsapp-wins-injunction-against-nso-group-spyware-damages-reduced/
  • Arsenal Consulting, SentinelOne and The Washington Post (December 2022) on the planting of evidence in the Bhima Koregaon prosecutions โ€” consolidated record: https://en.wikipedia.org/wiki/2018_Bhima_Koregaon_violence (the forensic reports are the primary documents)

India

  • Press Information Bureau (Government of India), "DPDP Rules, 2025 Notified" (G.S.R. 846(E)) โ€” November 2025 โ€” https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf
  • Digital Personal Data Protection Act 2023, section 17 (exemptions) โ€” 11 August 2023 โ€” https://indiankanoon.org/doc/180784190/
  • Digital Personal Data Protection Act 2023, section 44 (omissions, and the substitution in the Right to Information Act) โ€” https://www.dpdpa.com/dpdpa2023/chapter-9/section44.html
  • S.S. Rana & Co., "MeitY Notifies Final Digital Personal Data Protection Rules 2025" โ€” November 2025 โ€” https://ssrana.in/articles/meity-notifies-final-digital-personal-data-protection-rules-2025/
  • SFLC.in, "DPDP Rules, 2025: Significant Data Fiduciaries and Data Transfers" โ€” 2025 โ€” https://sflc.in/dpdp-rules-2025-significant-data-fiduciaries-and-data-transfers/
  • SFLC.in, "Data Protection Board of India: A watchdog without teeth" โ€” 2023 โ€” https://sflc.in/data-protection-board-of-india-a-watchdog-without-teeth/
  • Mondaq, "India's Data Protection Board: The Enforcer That Isn't There Yet" โ€” 17 April 2026 โ€” https://www.mondaq.com/india/data-protection/1774316/indias-data-protection-board-the-enforcer-that-isnt-there-yet
  • Internet Freedom Foundation, "Section 44(3) and the Systematic Dismantling of the RTI Act" โ€” April 2025 โ€” the contested reading, published here as contested โ€” https://internetfreedom.in/section-44-3-and-the-systematic-dismantling-of-the-rti-act-a-fact-check-to-ashwini-vaishnaw/
  • CERT-In, Directions under section 70B(6) of the Information Technology Act 2000 โ€” 28 April 2022 โ€” https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf ; summary including the FAQ clarifications โ€” https://www.azbpartners.com/bank/cert-in-directions/
  • Reserve Bank of India, "Storage of Payment System Data" โ€” 6 April 2018, with FAQs of 26 June 2019 โ€” https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244 and https://www.rbi.org.in/scripts/FAQView.aspx?Id=130
  • Centre for Internet and Society (Amber Sinha & Srinivas Kodali), "Information Security Practices of Aadhaar (or lack thereof)" โ€” May 2017, updated November 2018 โ€” https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information
  • The Tribune (India), report on paid access to an Aadhaar administrative portal โ€” 4 January 2018 โ€” https://www.tribuneindia.com/news/archive/nation/rs-500-10-minutes-and-you-have-access-to-billion-aadhaar-details-523361
  • Internet Freedom Foundation, statement on the 2020 app-blocking orders and the confidentiality rule โ€” July 2020 โ€” https://internetfreedom.in/59-apps-blocked-our-statement-and-initial-action/

Historical function creep โ€” the load-bearing cases

  • Seltzer & Anderson, "The Dark Side of Numbers: The Role of Population Data Systems in Human Rights Abuses," Social Research 68(2):481โ€“513 โ€” Summer 2001 โ€” https://philpapers.org/rec/SELTDS ; supporting documents โ€” https://sites.uwm.edu/margo/statistical-confidentiality-and-human-rights/
  • Croes, "The Holocaust in the Netherlands and the Rate of Jewish Survival," Holocaust and Genocide Studies 20(3) โ€” Winter 2006 โ€” the multicausal analysis this study relies on, and does not simplify โ€” https://doi.org/10.1093/hgs/dcl022
  • Anne Frank House, "The Dutch government makes carrying an identity card compulsory" โ€” https://www.annefrank.org/en/timeline/27/the-dutch-government-makes-carrying-an-identity-card-compulsory/

Breaches, architecture and the rest

  • Mandiant / Google Cloud, advisory on the 2024 cloud-warehouse customer-credential breach cluster โ€” 10 June 2024 โ€” https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion
  • AT&T, customer notice and Form 8-K on the illegal download of call and text records โ€” 12 July 2024 โ€” https://about.att.com/story/2024/addressing-illegal-download.html
  • Electronic Frontier Foundation, "Privacy on the Map: How States Are Fighting Location Surveillance" โ€” April 2025 โ€” https://www.eff.org/deeplinks/2025/04/privacy-map-how-states-are-fighting-location-surveillance
  • Electronic Frontier Foundation, "The FTC Forces Ring to Take User Privacy Seriously" โ€” on algorithmic disgorgement โ€” June 2023 โ€” https://www.eff.org/deeplinks/2023/06/ftc-forces-ring-take-user-privacy-seriously

Where to go if you need help now

  • Image-based abuse: StopNCII.org (adults) and NCMEC's Take It Down (under-18s) โ€” both compute the image hash on your own device, so the picture never leaves it โ€” https://stopncii.org/ and https://takeitdown.ncmec.org/
  • Stalkerware and tech-enabled abuse: the Coalition Against Stalkerware's resource list, and the National Network to End Domestic Violence's Safety Net project. Contact them from a different device, and do not remove suspected stalkerware first โ€” https://stopstalkerware.org/ and https://www.techsafety.org/
  • Before you install anything: Exodus Privacy, which lists the trackers found inside an Android application โ€” https://reports.exodus-privacy.eu.org/
  • In India: the grievance officer every significant intermediary must publish, then the Grievance Appellate Committee; CERT-In's incident channel; the RBI Ombudsman for payment disputes; and, for anything constitutional, a writ petition under Article 226 or 32 invoking Puttaswamy โ€” https://www.cert-in.org.in/ and https://www.grievance.gac.gov.in/

A closing note on method. Where a date is a best estimate, we have said "around". Where a matter is on appeal or a status may have changed since July 2026, we have said so in the sentence rather than in a footnote. Where our verification pass could not open a primary document โ€” a district court's entry of a stipulated order, an inspector-general's contract figures, a commission's article numbers, a tribunal's disposition โ€” we dropped the claim or marked it unconfirmed, and we have said which. No date, figure, case or source in this study has been invented, and where we could not check something we have preferred an admitted gap to a confident sentence. That preference is the whole method, and it is the only thing that makes the rest of it worth reading.

Share your thoughts

Send an opinion, a suggestion, or a word of thanks on this study.