Back to Bookshelf
Privacy Is Power cover

Privacy & Trust

Privacy Is Power

Carissa Véliz · 2020

Why and how you should take back control of your data. Personal data is valuable because it confers power over people, not because it can be sold, which makes holding more of it than necessary an accumulating liability.

Central Thesis

"Even more than monetary gain, personal data bestows power on those who collect and analyse it, and that is what makes it so coveted."

Personal data isn't valuable primarily because it can be sold, it's valuable because it confers power. Google and Facebook aren't, technically, in the business of selling data, they're in the business of selling the power to influence you, to predict behavior and show the exact message that will move it. Once understood this way, "privacy vs. free service" stops being the right frame, the actual trade is autonomy vs. someone else's power over you. Data enables both soft power (algorithms, targeted ads, personalized narratives) and hard power (blackmail, discrimination, denial of insurance or employment).

Why "Anonymized" Data Usually Isn't

Latanya Sweeney showed 87% of Americans can be uniquely identified with just three data points, birth date, gender, zip code. A separate study found four spatiotemporal data points uniquely identify 95% of individuals in a mobility dataset. Researchers de-anonymized Netflix's "anonymized" 10-million-rating dataset by cross-referencing it with public IMDb reviews, exposing a lesbian mother's viewing history and prompting a lawsuit. Anonymized, on its own, is not a safety guarantee once a dataset is rich enough, and a personal photo library, tagged with faces, locations, and timestamps, is about as rich as datasets get.

Toxic Data: The Asbestos Analogy

Security expert Bruce Schneier's framing, adopted and extended: data is a toxic asset. Cheap to collect, genuinely useful short-term, quietly dangerous to hold, because attackers only need to succeed once while defenders must defend every entry point forever. The Ashley Madison breach (30+ million users) led to blackmail, job losses, and suicides regardless of whether the underlying behavior was itself serious, the leak was the harm. "The default... should be not to collect data, or only to collect the minimum necessary." Holding data you don't strictly need is not a neutral choice, it's accumulating liability.

Facial Recognition, Consent, and Unpaid Labor

Facebook's "Tag Suggestions," when a user confirmed "Is this Jack?", wasn't just a UI convenience, it was unpaid labor training a facial recognition model the user never explicitly agreed to build, later reusable far outside the original context. Ask before posting a photo of someone else, untagging isn't sufficient protection once facial recognition can re-identify someone regardless, and children in particular are owed privacy, uploading photos of other people's kids without parental consent is a real violation, not a triviality.

Design Principles for Products, Not Just Individuals

  • Choose "dumb" over "smart" by default — don't run continuous background analysis (location, face detection) unless it's the specific feature the user invoked.
  • Defaults matter more than settings — most people never touch settings, so the privacy-protective choice must be the default, opt-in, not opt-out.
  • Business model is a proxy for trustworthiness — if a company's revenue depends on exploiting the data it collects, that's a structural conflict of interest no privacy policy can fully resolve. This is the strongest available argument for a subscription-funded model as a trust signal in itself.
  • Véliz explicitly names "a few businesses starting to offer privacy as a competitive advantage" as one of the forces that can erode big tech's data-driven power, treating it as a real lever, not a niche marketing angle.

Quick-Use Summary

The idea in one sentence: personal data is valuable primarily because it confers power over the people it describes, which means holding more of it than strictly necessary is an accumulating liability, a toxic asset, not a neutral byproduct of running a good product.

The three most applicable concepts:

  1. Privacy as a structural, defensible moat — a subscription-funded business model is a genuine trust signal an ad-funded incumbent can't easily copy without changing its own business model.
  2. Data minimization by default, especially for facial recognition, process AI tagging on-device where possible, and never use silent confirmations to train a pooled, cross-user model.
  3. Consent norms for photos of other people, especially children, treat third-party subjects' privacy as a real design constraint, not just the uploader's preference.