.webp)
Digital privacy is becoming one of the defining issues of the modern age as governments and companies gain unprecedented access to personal data. While surveillance can support national security, crime prevention and cybersecurity, unchecked monitoring risks eroding civil liberties, free expression and public trust. Experts including Bruce Schneier, Jonathon Penney, Daniel Solove and Meredith Whittaker argue that strong oversight, proportionality, encryption and clear legal safeguards are essential to balance security with individual privacy rights today.

Every smartphone location ping, online search, payment, facial scan and social-media interaction can become part of a digital record. For governments, such information can help investigate terrorism, cybercrime, fraud and serious criminal activity. For businesses, it can improve services, detect abuse and personalize products. But the same infrastructure can also create something far more powerful: the ability to observe, profile, predict and influence individuals at unprecedented scale.
This is the central tension of the digital age: How much surveillance should society accept in exchange for security, and where should the boundary of individual privacy be drawn?
The debate has become more urgent as artificial intelligence, facial recognition, location tracking, data brokers and large-scale analytics make surveillance faster, cheaper and increasingly automated.
International human-rights law recognizes privacy as a fundamental right. Article 17 of the International Covenant on Civil and Political Rights (ICCPR) protects individuals against arbitrary or unlawful interference with their privacy, family, home and correspondence.
Importantly, this does not prohibit every form of government surveillance. Authorities may interfere with privacy for legitimate purposes, including national security and crime prevention, but international standards require that such measures satisfy principles including legality, necessity and proportionality. The UN Human Rights Committee has emphasized that even surveillance authorized by domestic law should be reasonable, necessary and proportionate to the legitimate objective being pursued.
That distinction is critical. A targeted wiretap authorized by a court during an investigation is very different from collecting information about millions of people simply because technology makes it possible.
Modern threats increasingly operate through digital systems. Terrorist networks communicate online, criminal organizations use encrypted platforms, cybercriminals move money internationally, and foreign intelligence operations target telecommunications networks.
Digital evidence can therefore be indispensable.
Yet one of the most revealing recent cybersecurity incidents demonstrated that strong privacy technology can actually strengthen national security rather than weaken it.
Following the Salt Typhoon cyberattacks on major U.S. telecommunications companies, attributed by U.S. authorities to China-linked hackers, the U.S. Cybersecurity and Infrastructure Security Agency advised senior government and political figures to use end-to-end encrypted communications rather than ordinary calls and text messages. The breach reportedly affected at least eight U.S. telecommunications and infrastructure companies and exposed significant communications metadata.
The episode exposes an important contradiction in the traditional privacy-versus-security argument: weakening communication security so authorities can gain access can potentially create vulnerabilities that foreign intelligence services, criminals and hackers can exploit as well.
Bruce Schneier, Lecturer in Public Policy at Harvard Kennedy School and Fellow at Harvard’s Berkman Klein Center for Internet & Society, has long argued that technology is changing surveillance from something resource-intensive into something that can operate continuously and automatically.
In 2026, Schneier and legal scholar Jonathon Penney warned that AI-powered surveillance could dramatically expand governments’ and institutions’ ability to track public and private behaviour, automatically identifying activities, linking them with identities and retaining the resulting information.
The risk is not simply that someone might discover wrongdoing. Persistent surveillance can alter the behaviour of perfectly law-abiding citizens.
People may avoid visiting certain websites, attending protests, researching controversial subjects or communicating with particular groups simply because they believe their activities are being recorded.
That behavioural change is known as the “chilling effect.”
Jonathon Penney, Associate Professor and York Research Chair in Artificial Intelligence, Data Governance, and the Law at Osgoode Hall Law School, studies precisely this phenomenon.
His research examines how awareness or fear of surveillance can cause people to censor themselves even when they are doing nothing illegal. In a 2026 discussion of his work, Penney highlighted examples such as people hesitating before searching for information about protests, government corruption or other sensitive subjects because they fear that their digital activities could be monitored.
The implication is significant: privacy protects more than secrets. It provides psychological and social space in which people can explore ideas, develop beliefs and participate in democratic society without assuming that every action will become part of a permanent record.
Governments are no longer the only institutions capable of constructing detailed profiles of citizens.
Technology companies, advertising networks, apps, data brokers and online platforms collect enormous quantities of behavioural data.
A 2024 U.S. Federal Trade Commission investigation into nine major social-media and video-streaming companies found extensive collection, tracking, sharing and monetization of personal information. The FTC said some companies could retain large quantities of data indefinitely and collected information not only about users but, in some circumstances, non-users as well.
That commercial ecosystem raises a major public-policy question: if private companies build extraordinarily detailed profiles, governments may not always need to develop surveillance infrastructure themselves.
Daniel J. Solove, Bernard Professor of Intellectual Property and Technology Law at George Washington University Law School, has warned that corporate “digital dossiers” can potentially strengthen government surveillance because enormous quantities of personal information have already been assembled by the private sector.
Solove rejects the simplistic idea that society must choose either privacy or security. His work argues that effective security measures and meaningful privacy protections can coexist when surveillance is properly regulated and overseen.
Facial recognition demonstrates another difficulty.
The technology can help identify suspects, locate missing persons or secure borders. But inaccurate matches can also expose innocent people to questioning, investigation or detention.
A major National Institute of Standards and Technology (NIST) evaluation of 189 facial-recognition algorithms from 99 developers found demographic differences across many systems. In some one-to-one tests, false-positive rates differed between demographic groups by factors ranging from 10 to more than 100, depending on the algorithm. NIST continues to publish demographic-performance information as facial-recognition systems develop.
This illustrates why simply asking whether governments should be allowed to use surveillance technology is insufficient. Policymakers must also ask how accurate it is, who is affected when it fails, how long information is stored and who can challenge an incorrect decision.
The European Union's AI Act offers one emerging regulatory approach.
The legislation generally prohibits real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, while permitting narrowly defined exceptions, including searching for certain missing or abducted people, responding to serious and imminent threats, or locating suspects in specified serious crimes.
Even where exceptions apply, the system incorporates requirements involving necessity, proportionality, geographic and temporal limits, fundamental-rights assessments and, generally, prior judicial or independent authorization.
Rather than banning security technology completely, the framework attempts to distinguish targeted surveillance from indiscriminate surveillance.
Another major battlefield is encryption.
Governments worldwide have argued that criminals can exploit encrypted communications, creating what law-enforcement agencies sometimes describe as a “going dark” problem.
But Meredith Whittaker, President of the Signal Foundation, argues that encryption cannot realistically be weakened only for criminals. Her position is that introducing mechanisms allowing third parties to inspect private communications creates vulnerabilities affecting everyone who depends on the same system.
This is why the encryption debate extends beyond privacy. Journalists, government officials, businesses, soldiers, healthcare professionals and ordinary citizens all depend on secure communications.
Public concern shows that the issue remains unresolved. In a Pew Research Center survey of 5,101 U.S. adults, 71% said they were concerned about how the government uses data collected about them, while 79% said they had little or no control over information collected by government agencies. At the same time, majorities considered several forms of law-enforcement access acceptable during criminal investigations, illustrating that the public does not necessarily oppose surveillance itself, it wants boundaries around its use.
The future of digital privacy therefore should not be framed as a choice between “total privacy” and “total security.”
A sustainable model requires surveillance to be targeted, legally authorized, necessary, proportionate, independently supervised, transparent where possible and open to meaningful challenge. Data collection should have defined purposes and retention limits, while especially intrusive technologies such as facial recognition and AI surveillance require stronger safeguards.
Technology has given governments and corporations an extraordinary ability to see into people's lives. The defining question of the next decade will not be whether societies possess that capability.
They already do.
The real question is whether democratic institutions can develop rules strong enough to ensure that the power to watch does not become the power to control.
For questions or comments write to contactus@bostonbrandmedia.com