The Cycle of Digital Surveillance — in Plain Words

The beginning — you just live. You wake up. Check your phone. Read the news. Buy coffee with a card. Search for something online. Watch a video. Write a message to a friend. You just live your life. But each of these actions leaves a trace. Not because you did something wrong. But because the system is built that way.

Step 1 — Collection

Your phone knows where you are. The browser knows what you search for. The store knows what you buy. The bank knows how much you spend and when. Apps know when you sleep and when you wake up. Each platform collects its piece of your life. Individually this seems harmless.

Step 2 — Aggregation

Now imagine that all these pieces are gathered in one place. There are companies — no one sees them — whose only job is to connect the dots. They take data from dozens of sources and glue it into one profile. Your profile. In this profile it is no longer simply «a person who searches for trainers». There — a man of 30, lives in Estonia, Russian-speaking, works in construction, income average, political views moderate, health — was interested in the topic of blood pressure three months ago, relationships — was looking for anniversary gifts, finances — twice looked at loan offers. You have never seen this profile. But it exists.

Step 3 — Trade

This profile is sold. Fast. Automatically. In milliseconds. When you open any site — at the moment the page loads a lightning-fast auction takes place. Dozens of companies simultaneously place bids for the right to show you advertising. They know who you are. They pay for access to you. You do not know about it. The page simply loads.

Step 4 — Influence

Advertising is only the tip of the iceberg. The same profile is used to decide — to give you a loan or not. What price to show for a plane ticket. Which news you will see first. What content ends up in your feed and what does not. The algorithm knows what angers you. What frightens you. What tempts you. And uses this — not to harm you deliberately — but simply to keep you on the platform longer. Because the longer you are there — the more data. The more expensive your profile.

Step 5 — The closed loop

You see content the system chose for you. You react. Your reaction — new data. The profile updates. The loop closes. You think you choose what to watch and what to believe. But the choice was already made before you — on the basis of your own profile.

What this means in practice This is not a conspiracy theory. It is a business model. No one specifically watches you in particular. The system simply works automatically for everyone at once. Billions of profiles. Trillions of transactions a day. You are not a victim. You are a resource.

How to get out of the loop Completely — impossible. Partially — possible. The first step — awareness. To understand that the loop exists. The second step — tools. VPN, tracker blockers, encrypted mail. They do not make you invisible — but they reduce the amount of data you give away. The third step — rights. In Europe there is GDPR. You have the right to know what is stored about you. You have the right to demand deletion. You have the right to file a complaint if your rights are violated. This is slow. It requires effort. But it works. The system counts on most people not looking into it. Simply because it is difficult and there is no time.

Those who do not give up — change the rules for everyone.

The main GDPR articles for filing a request

Your rights as a data subject

Article 15 — The right of access. You have the right to know what is stored about you, where it was obtained, to whom it is transferred and on what basis it is processed. The company is obliged to respond within 30 days. Article 16 — The right to rectification. If data about you is inaccurate or incomplete — you have the right to demand its correction. Article 17 — The right to erasure. The right to be forgotten. You demand the deletion of all data. The company is obliged to comply if there is no legal basis for storage. Article 18 — The right to restriction of processing. While a matter is being resolved — you can demand that the processing of data be frozen. It may be stored — but not used. Article 20 — The right to portability. You have the right to receive your data in a machine-readable format and transfer it to another operator. Article 21 — The right to object. You can object to the processing of data for the purposes of direct marketing or profiling. The company is obliged to stop immediately. Article 22 — The right to protection from automated decisions. If a decision is made by an algorithm without human involvement and significantly affects you — you have the right to an explanation and review. Decisions about content visibility, made by an algorithm — fall under this article.

Companies’ obligations

Article 5 — Principles of processing. Data must be processed lawfully, transparently, for a specific purpose, in a minimally necessary manner, accurately and securely. Article 6 — Legal basis. The company is obliged to have one of six bases for processing — consent, contract, legal obligation, vital interests, public interest or legitimate interest. Without a basis — a violation. Article 9 — Special categories of data. Political views, health, religion, biometrics — require explicit consent. Processing without it is prohibited. Article 12 — Transparency. The company is obliged to answer requests clearly, accessibly and on time. Ignoring or evasive answers — a violation. Article 13/14 — Informing. When collecting data the company is obliged to communicate who collects it, why, on what basis and how long it is stored. Article 25 — Protection by default. The system must be designed with minimal data collection from the outset. Fingerprinting before authentication — a direct violation. Article 37 — DPO. Companies are obliged to have a person responsible for data protection with a real contact.

Transfer of data abroad

Articles 44–49 — Chapter V. Transfer of data to third countries is permissible only if the country has an adequacy decision from the European Commission or standard contractual clauses apply. Russia does not have an adequacy decision. The transfer of an EU resident’s data to Russia without a legal basis — a direct violation of Chapter V.

Where to complain

Article 77 — The right to complain to a regulator. Every EU resident has the right to file a complaint with the supervisory authority of their country. Estonia — AKI aki.ee Ireland — DPC dataprotection.ie (for Meta, Google, Apple) France — CNIL (for French companies — Criteo, Sparteo, Didomi) Article 78 — The right to judicial remedy. If the regulator does not act — you have the right to go to court. Article 82 — The right to compensation. If a violation caused material or moral damage — you have the right to compensation from the company. Article 83 — Fines. These are the teeth of GDPR. Without it everything else would be merely recommendations.

Draw your conclusions, ladies and gentlemen

History shows: one complaint can change the practice for millions.

  • Gonzalo Fuentes v. Google — the right to be forgotten, 2014. A Spaniard discovered that Google showed in its search results an old article about his debts, which had long been paid off. He complained to the Spanish regulator. The case reached the Court of Justice of the European Union. The result — Google is obliged to delete links to outdated or irrelevant information at the request of EU citizens. This became the right to be forgotten, now enshrined in GDPR Article 17. One Spaniard changed how search works for 450 million Europeans.
  • The Belgian case against Facebook — the cookie wall, 2020. The Belgian regulator filed a suit against Facebook following a complaint from one user who discovered that Facebook was tracking him even when he was not logged in and was not a user of the platform. The result — a ban on tracking people who are not Facebook users without explicit consent. Facebook was forced to change the tracking mechanics across Europe.
  • Neumann v. Amazon Alexa, 2021. A German user requested from Amazon all the data collected by his voice assistant Alexa. Amazon sent another person’s data — someone else’s voice recordings, addresses, purchases. A complaint to the German regulator BfDI. The investigation revealed a systemic problem with data processing. The result — Amazon was fined 746 million euros in Luxembourg for the combination of violations. One of the largest fines in GDPR history.

The case against Google Analytics — the Austrian precedent

  1. An Austrian activist complained that a site using Google Analytics transferred his data to the US without adequate protection after the cancellation of the Privacy Shield. The Austrian regulator DSB found the use of Google Analytics to be a GDPR violation. The result — a wave of similar decisions across Europe. France, Italy, Denmark, Finland — all found Google Analytics to be a violation. Hundreds of thousands of sites were forced to change analytics tools. One request — changed the standards of web analytics across Europe.
  • The Clearview AI case — biometrics, 2021–2022. Several private individuals in different EU countries complained about a company that, without consent, collected billions of photographs from the internet to create a biometric-identification database. The result — fines in Italy, France, Greece, the United Kingdom. The company is obliged to delete the data of European citizens. The total fines exceeded 100 million euros.

What unites all these cases? None of these people was a lawyer. Was not an activist with resources. Did not have a team. They simply noticed a violation. Recorded it. Filed a complaint. And did not back down when it got hard. The system always counts on a person’s fatigue. On them giving up. On it being too long and too difficult.

Those who do not give up — change the rules for everyone.

← All journal entries