Where GDPR Came From. The Story Few Know in Full
“To understand why this law is needed — you have to understand what was happening before it. Because GDPR did not appear out of thin air. It was written by people who saw concrete things.”
The internet in the nineties was different
When the network first became widely available — no one thought of data as a value. People visited sites, read, left. No accounts, no personalisation, no tracking. The internet was like a library — you take a book, read it, put it back. The library does not know who you are or what you were looking for. Then advertising appeared. The first advertising banner on the internet appeared in 1994. The company AT&T bought space on the site HotWired. The banner was simple — just a picture. 44% of everyone who saw it clicked. Today the average figure is less than 0.1%. People stopped clicking because there became too much advertising and it stopped being interesting. And this is where the story that led to GDPR begins. The advertising market ran into a problem. Banners do not work if they are shown to everyone indiscriminately. You need to show the right advertising to the right person at the right moment. For this you need to know who this person is. What interests them. Where they live. How old they are. What they searched for yesterday. What they are thinking about today. Thus the surveillance industry was born. Not all at once. Gradually. Step by step — each of which seemed harmless.
First came cookies
- An engineer named Lou Montulli works at the company Netscape. He needs to solve a technical task — how to make an online store remember what is in your cart while you move between pages. He invents cookies — small text files that a site saves in your browser. The idea was absolutely innocent. A technical tool for the user’s convenience. But very quickly someone realised that this tool could be used differently. If the same cookie can be read from different sites — a person can be tracked across the whole internet. Not on one site. On all sites simultaneously. Thus third-party cookies appeared. You visit a news site. Then a store site. Then a forum. On each of them a small script from an advertising company loads unnoticed — and this company sees your whole route. It builds a profile. It knows more about you than you think. Lou Montulli later said he regrets how his invention was used. He wanted to make a shopping cart. What came out was a tool of global surveillance.
Then came Google
- Two Stanford graduate students — Larry Page and Sergey Brin — launch a search engine. For the first few years they are on principle unwilling to have advertising. In their academic paper they wrote outright that a search engine funded by advertising would by its nature be biased and against users’ interests. Two years later they launched an advertising platform. Not because they became bad people. Because money was needed. Because investors wanted a return. Because the system works exactly like that. And Google did something ingenious from a business standpoint and destructive from a privacy standpoint. It linked search queries to advertising. You search «symptoms of diabetes» — and the advertising knows about it. You search «how to file for divorce» — the algorithm remembered it. You search «cheap flights to Berlin» — and an hour later on another site you see advertising for hotels in Berlin. This was new. Before this, advertising was contextual — on a site about cars, advertising for cars was shown. Now advertising became personal — you were shown what you searched for, what you thought about, what you wanted. People perceived this as convenience. No one asked permission.
Then came Facebook
- Mark Zuckerberg launches a social network for Harvard students. A few years later there are already a billion people on it. And each of them voluntarily tells everything about themselves. Name. Age. City. Work. Relationships. Political views. Religion. What they like. What they dislike. Who they are friends with. Where they go on holiday. What they think about the news. How they react to different content — get angry, laugh, feel sad. Facebook did not merely collect this data. It learned to predict a person’s behaviour on its basis. A 2013 study showed that Facebook’s algorithm can determine a person’s political views more accurately than their friends — simply from likes. It can determine sexual orientation. Level of intelligence. Predisposition to depression. A person thought they were just liking cats. The algorithm was building their psychological portrait. And this portrait was sold.
Cambridge Analytica. The moment when everything became visible
- Journalists from the Guardian and the New York Times publish an investigation. The following emerges. The company Cambridge Analytica obtained the data of 87 million Facebook users. It did not hack — it obtained it through an app that users installed themselves. The app was called a «psychological test» — people voluntarily took it, without reading the terms. The terms stated that the data was transferred to third parties. Cambridge Analytica used this data for political campaigns. They built psychological profiles of voters and showed them targeted political messages — different ones for different personality types. To an aggressive person — one thing. To an anxious one — another. To an indecisive one — a third. They worked on Donald Trump’s election campaign in 2016. On the Brexit campaign in the United Kingdom. On elections in dozens of other countries. 87 million people did not know that their psychological profiles were being used to change their political behaviour. This was the moment when the abstract conversation about data became concrete. People realised — this is not about advertising for trainers. This is about who becomes president. This is about how a country votes. This is about democracy. Zuckerberg was summoned to the US Congress. Two days of questioning. Senators asked how Facebook works — and it was clear that most of them did not really understand what the internet is. Zuckerberg answered politely and evasively. Facebook paid a fine of 5 billion dollars. 5 billion sounds like a lot. For a company with an annual revenue of 70 billion — it is a quarter’s marketing spend. Nothing fundamentally changed.
Europe watched all this and made a decision
While in the US they got off with fines and promises — in Europe other work was going on. As early as 2012 the European Commission was developing a new law. It was to replace the outdated directive of 1995 — written back when most of the current technologies did not exist. The work took six years. 4,000 amendments. Lobbyists from technology companies spent hundreds of millions of euros to soften the law or block it. It did not work. On 25 May 2018 GDPR took effect. What changed on that day? Before GDPR a company could collect your data simply because you visited a site. Without asking. Without explaining. Without giving you the possibility to refuse. After GDPR — a company is obliged to obtain your consent before collecting anything beyond what is technically necessary. Obliged to explain why. Obliged to say to whom it transfers. Obliged to delete on your demand. Obliged to show everything it stores — if you ask. The fines became real. Up to 4% of a company’s global annual turnover. For Google that is billions. For a small shop — also serious money. The first large GDPR fine was received by Google — 50 million euros. From the French regulator. For not explaining clearly enough to users how their data is used for advertising. Amazon received 746 million euros. WhatsApp — 225 million. Meta — 1.2 billion. This is no longer a quarter’s marketing spend. This is the beginning of a conversation between equals.
But here is what is important to understand
GDPR did not solve the problem. It created a tool. Do you feel the difference? The law exists. The rights exist. But rights work only when people know about them and use them. Cookie banners appeared — but most of them are designed so that you press «accept all». Privacy policies exist — but their average length is about 2,500 words of legal language. Rights of access to data exist — but most companies stay silent in the hope that a person will not insist. I am running 15 active cases against advertising brokers. Not because I want war. Because the only thing that makes the system work is when people begin to use the rights they already have. Cambridge Analytica no longer exists — the company closed after the scandal. But the methods it used live on. In other companies. Under other names. With the same data. The story of GDPR is a story about how long you can do something wrong until people start to look. And about what happens when they do look. Are you looking?
How your data turns into money. The full chain
Let us start with a question that seems simple. Why is Google free? Why is Facebook free? Why do Instagram, TikTok, Gmail, YouTube — all of it — cost you not a cent? Thousands of engineers, billions of servers, an infrastructure serving half the planet — and all of it for nothing? No. Not for nothing. The currency is simply different. When a product is free — the goods are you. More precisely, not you yourself. Your attention. Your behaviour. Your desires. Your fears. All of it is packaged, sorted and sold. Every second. While you read this article. To understand exactly how — you have to go through the whole chain from beginning to end.
Step one. Collection
You open a browser. Visit any site — news, a store, recipes, a weather forecast. It does not matter which. At the moment the page loads, something happens that you do not see. The browser sends requests. Not one. Dozens. Sometimes hundreds. Each request goes to a different company. Advertising platforms. Analytics services. Behaviour trackers. All of this happens in milliseconds — faster than the page manages to load. What exactly do they receive? Your IP address — from it one can determine the city, the provider, sometimes the district. The type of device and browser. Screen resolution. Installed fonts. Time zone. System language. Time of day. Where you came to this site from. How long you look at each element of the page. Where your gaze stops. How the mouse moves. How fast you scroll. All of this together is called a fingerprint — a digital fingerprint. It is as unique as a real fingerprint. And unlike a cookie — it cannot be deleted. Clearing the browser does not help. Switching tabs does not help. It is formed anew on every visit — and each time it matches the previous one. You think you are anonymous. The system knows it is you again. And this is only the beginning of the collection. Further — deeper. If you have an account — everything you ever entered is added. Name, age, email, phone number. Purchase history. Search history. Correspondence — yes, in some services it is analysed by algorithms. Photographs you uploaded — they pass through computer vision. Geolocation — if you allowed access, the system knows where you were every day for the last several years. If you have a smartphone with apps — data is collected even when you are not using a specific app. The accelerometer records how you hold the phone. The microphone in some cases is activated to analyse the surroundings. The contact list, calendar, list of installed apps — all of this is interesting to advertising systems because it says more about you than you think. One fact illustrates this well. Researchers showed that from the list of installed apps one can predict with high accuracy — whether a person has diabetes. Not because there is an app «I have diabetes». But because a certain combination of apps — a calorie counter, a medication reminder, a blood-sugar monitoring app, certain news sources — statistically correlates with the diagnosis. Data says about you what you do not say yourself.
Step two. Enrichment
The collected data is raw material. On its own it is worth little. Value appears when it is combined. Here data brokers take the stage. These are companies most people have never heard of — but which know more about you than your loved ones. Acxiom. Experian. Oracle Data Cloud. Epsilon. Quantcast. LexisNexis. Their business is to collect data from all possible sources and combine it into a single profile. Where do they get the data? They buy it from sites and apps. They receive it from store loyalty programmes — every time you use a discount card, the transaction is recorded and sold. They take it from public registers — real-estate registers, court documents, vehicle data. They buy it from banks and insurance companies — in those countries where it is allowed. They collect it from social networks. They buy it from other brokers. All of this is combined into one profile. What does a broker end up knowing about the average resident of Europe? Name, address, age, marital status, children — their age and sex. Income — exact or approximate. Type of housing — owned or rented. What car. What loans. What illnesses — inferred from pharmacy purchases and search queries. Political views. Religious beliefs. Sexual orientation — inferred from behavioural patterns. Psychological personality type. Risk propensity. Level of anxiety. How susceptible you are to impulsive purchases. The company Acxiom publicly states that it has data on 2.5 billion people. That is a third of the planet’s population. Each of them has — on average — 1,500 separate characteristics in the profile. You are in this database. With high probability — for a long time already.
Step three. The auction
Now the most interesting part. How exactly this data turns into money — in real time, right now, while you read. When you open a page with an advertising slot — an auction happens in a fraction of a second. It is called RTB — Real Time Bidding. In 100 milliseconds — that is faster than an eye blinks — dozens of advertisers receive information about you and place bids for the right to show you advertising. What does this information look like? The advertiser receives a package of data: age, sex, city, interests, purchase history, psychographic profile, income level, probability of making a purchase in the next 24 hours. All of this — without your name, formally anonymous. But de-anonymising such a profile is not hard if desired. Whoever bids more shows the advertising. An insurance company is ready to pay more for you if you recently searched for information about illnesses. A car dealership pays more if you watched car reviews. A casino pays a great deal for people with a certain psychological profile — prone to risk and impulsive decisions. You do not see this auction. You see only the result — advertising that seems surprisingly precise. And here are the figures that make it clear. The average cost of showing advertising to an ordinary user — fractions of a cent. But the cost of showing advertising to a person with the right profile — can be dozens of times higher. The advertiser pays not for the space on the page. It pays for access to a specific person at a specific moment of their life. Google earns about 200 billion dollars a year on advertising. Facebook — about 120 billion. This is not money for beautiful sites. This is money for you. For your behaviour. For your data. Divide 200 billion by the number of Google users — and you get roughly how much you are worth to them per year. A few hundred dollars. Every year. Silently. Without your knowledge.
Step four. Application
Advertising is only the most visible application. Beneath the surface something more serious happens. Insurance. Insurance companies in a number of countries already use behavioural data to calculate tariffs. How you drive a car — data from the phone. How you eat — data from delivery apps. How regularly you sleep — data from a smart watch. All of this affects the price of insurance. You did not know this when you installed a step-counting app. Lending. Classic credit scoring looks at your financial history. The new kind looks at everything else. In which district you live. From which phone you log into the banking app. At what time of day. How fast you fill in the application form. One large fintech company publicly stated that people who fill in an application in lowercase letters are statistically more reliable borrowers than those who write in caps lock. This sounds like a joke. It is not a joke. Hiring. More and more companies use algorithms for the initial screening of candidates. The algorithm looks at public data — social networks, publications, online activity. Sometimes it buys data from brokers. A CV may be perfect — but if the digital profile did not please the algorithm, it will not reach a live person in HR. You will never know why. Pricing. This is called dynamic pricing — and it already works. Airlines, hotels, online stores can show different prices to different people. The algorithm knows that you are flying to an important meeting and have no time to look for alternatives — the price is higher. The algorithm knows that you log in from an expensive device — the price is higher. You and your neighbour may see different prices for the same product at the same time. This is already happening. Not in theory.
Step five. The closed loop
There is one more level that is rarely discussed. Data is used not only to show you advertising. It is used to hold your attention. And that is already a different story. The algorithm knows what angers you. Knows what frightens you. Knows what makes you keep scrolling instead of closing the app. Facebook’s internal studies — which became public thanks to whistleblower Frances Haugen in 2021 — showed that the company knew: content provoking anger and anxiety keeps people in the app longer. And the algorithm deliberately showed more of such content. Not because it wanted to make people angry. Because angry people spend more time in the app. More time — more advertising. More advertising — more money. Your emotions are monetised. Your anxiety is a revenue line in someone’s spreadsheet. Research shows that the algorithmic feeds of social networks correlate with a rise in anxiety disorders in teenagers. Correlate with the polarisation of society — because the algorithm shows people content that confirms their existing views, making them more radical. Correlate with the spread of disinformation — because false news provokes stronger emotions and the algorithm promotes it. All of this is a side effect of the monetisation of attention. No one planned to make society more anxious and polarised. That is simply how the model works.
How much you are worth. Concretely
Let us end this block with concrete figures. Because abstractions are easy to ignore. The cost of an ordinary person’s basic profile at a data broker — from 0.001 to 0.5 dollars. It sounds like little. But there are billions of such profiles. And they are sold again and again to different buyers. The cost of the profile of a person with a specific diagnosis — diabetes, oncology, mental disorders — is dozens of times higher. Because pharmaceutical companies are ready to pay a lot for access to such people. The cost of the profile of a person at the moment of making an important financial decision — buying real estate, divorce, job loss — is even higher. Because at this moment the person is vulnerable and more prone to impulsive decisions. Data brokers are a multi-billion-dollar industry. The global data market is estimated at about 300 billion dollars a year and continues to grow. All this money is earned on information that people left without thinking. By clicking «accept all». By installing an app without reading the terms. By getting a loyalty card in exchange for a five-percent discount. Five percent off coffee. In exchange for a profile that is sold again and again over the years. This is not an accusation in anyone’s direction. This is simply how the system is arranged. And now you know how it is arranged. Knowledge is the first step. The second step — to decide what to do about it. About the rights you already have — read on.
Your rights under GDPR. Not an abstraction — an instruction
There is one thing companies very much do not want you to know. You already have rights. Right now. There is no need to hire a lawyer. No need to go to court. No need to understand legislation. You only need to know exactly what you have — and how to use it. GDPR gives a person eight rights. I will go through each — not as a legal norm, but as a living tool. What it means in practice. When it works. What to do if there is no response. Let us start with the most important.
Right one. The right to know
Articles 13 and 14 of GDPR say the following. Any company that collects your data is obliged to tell you about it. In advance. In clear language. Not in a forty-page document in fine print — but clearly and accessibly. What exactly are they obliged to communicate? What data they collect. Why — a concrete purpose, not a vague «improving the service». On what basis — your consent, legitimate interest, performance of a contract. How long they store it. To whom they transfer it — a list of specific recipients. How you can withdraw consent. Now look at any privacy policy you have seen. How many clear answers to these questions are really there — and how much legal fog that technically answers the question but in fact explains nothing? This is a violation. Not gross, not always pursued — but a violation. And you have the right to demand clarity. What to do right now. Open the privacy policy of any service you use regularly. Try to find the answer to a simple question: to whom specifically is my data transferred? If there is no answer — that is already a conversation.
Right two. The right of access
Article 15. This is one of the most powerful rights — and one of the most rarely used. You can write to any company and demand that they show everything they store about you. Absolutely everything. This is called a Subject Access Request. The company is obliged to respond within one month. For free. Without an explanation of the reason on your part — you are not obliged to explain why you need it. What must they send? A full list of the data they store. Where they got it — collected it themselves or bought it from someone. To whom they transferred it. On what basis they process it. How long they will store it. What happens when people make such a request? Sometimes a letter arrives with a file of several gigabytes. Google, for example, allows you to download an archive of all your data through the Google Takeout service. There will be the history of every search query for years. Every place you were with geolocation on. Every video you watched on YouTube. Every email in Gmail. Every contact. People who did this for the first time — describe it as a gut punch. Not because the data is being used against them right now. But because you see the scale — and understand that it accumulated over years without your conscious participation. Sometimes the company stays silent. This too is a violation — Article 12(3) of GDPR. A month has passed, there is no response — you have the right to complain to the supervisory authority. In Estonia this is AKI — the Data Protection Inspectorate. A complaint is submitted online, for free, in Estonian or English. From my practice. I submitted 15 requests to advertising brokers. Several stay silent to this day. This is not a dead end — it is the beginning of a conversation with the regulator. A company’s silence in itself is a documented violation. What to do right now. Choose one company — the one you trust your data to most. Write to them at the address stated in the privacy policy. The text is simple: «On the basis of Article 15 of EU Regulation 2016/679 (GDPR), I request that you provide me with access to all personal data that you process concerning me. Please state the purposes of the processing, the categories of data, the recipients to whom the data has been transferred, and also the planned storage periods.» That is all. You send it — you wait a month. You look at what arrives.
Right three. The right to rectification
Article 16. If data about you is inaccurate — you can demand that it be corrected. This sounds simple. But there is a nuance that few know. Data about you may be inaccurate not because someone made a mistake on entry. But because an algorithm drew a conclusion that does not correspond to reality. The system decided that you belong to a certain demographic group — wrongly. The algorithm assigned you a psychographic type — incorrectly. Credit scoring is calculated on the basis of data that is outdated or has nothing to do with you. You have the right to dispute this. And the company is obliged either to correct it — or to explain why it considers the data correct. In practice this is harder than it seems because companies often do not disclose exactly what conclusions they drew about you. But the very fact that such a right exists already changes the balance.
Right four. The right to erasure
Article 17. Known as the «right to be forgotten». Perhaps the most famous right in GDPR — and the most misunderstood. You can demand that your data be deleted. The company is obliged to do this if at least one condition is met. The data is no longer needed for the purpose for which it was collected. You withdraw consent and there is no other legal basis for processing. You object to the processing and there are no legal grounds to continue. The data was processed unlawfully. What does this mean in practice? If you closed an account in some service — they have no right to store your data indefinitely. If the company collected data on the basis of your consent — and you withdraw that consent — the data must be deleted. An important nuance. The right to erasure is not absolute. There are exceptions — for example, if the data is needed to fulfil legal obligations, or for defence in a legal dispute, or for purposes of public interest. Companies sometimes abuse these exceptions — they say they cannot delete data on «legal grounds» without explaining which exactly. This too can be disputed. What to do right now. Recall the apps and services you stopped using — but never deleted the account. Go in and delete the account. Then send a request to delete all the data. Many companies delete the account but leave the data in the database — this is a violation.
Right five. The right to restriction of processing
Article 18. This is a right that few know — and which is sometimes more useful than erasure. You can demand that the company suspend the processing of your data — not delete it, but precisely freeze it. The data remains, but nothing is done with it. When is this useful? When you dispute the accuracy of the data — while the matter is being resolved, the processing must be stopped. When the processing is unlawful — but you do not want erasure, you want evidence for a complaint. When you no longer need the data — but you need it for legal claims. In practice this is a tool for those who have already entered into a dialogue with a company and want to lock in the situation.
Right six. The right to data portability
Article 20. This right sounds technical — but behind it stands an important idea. You can demand that the company give you your data in a machine-readable format. So that you can transfer it to another service. Why is this needed? Imagine you used some service for many years. You accumulated history, settings, contacts. You want to switch to a competitor — but all your data is locked in the old system. This is called vendor lock-in — the deliberate retention of a user through their own data. The right to portability says — no. Your data is your data. You have the right to take it and carry it away. This right is so far weakly used because few services genuinely compete for users at the level of data transfer. But the principle is important — and over time it will be applied more widely.
Right seven. The right to object
Article 21. One of the most practically important rights — especially in the context of advertising. You can at any moment object to the processing of your data for the purposes of direct marketing. Not merely unsubscribe from a mailing. But demand that they stop using your data for any advertising purposes. The company is obliged to fulfil this demand. Without questions. Without explanations on your part. Immediately. There is a broader application of this right. If a company processes your data on the basis of «legitimate interest» — and this is a very popular basis that companies abuse — you can object to this. The company must then either prove that its interest outweighs your rights, or stop the processing. What to do right now. Go into the settings of any social network you use. Find the section about advertising and data. Withdraw all permissions to use data for targeted advertising. This will not delete the data — but it will stop its use for the advertising auctions we discussed last time.
Right eight. The right not to be subject to automated decisions
Article 22. This is a right that needs to be discussed separately — because it is becoming more important every year. You have the right not to be subject to a decision made solely automatically — without human involvement — if this decision significantly affects you. What does this mean in practice? A bank refused a loan — the algorithm decided you were unreliable. An insurer raised the tariff — the system calculated that you were high-risk. An employer did not invite you to an interview — the recruiting algorithm filtered out the CV. A platform blocked an account — automatic moderation fired erroneously. In all these cases you have the right to demand that the decision be reviewed by a live person. Not an algorithm. A person. And you have the right to know the logic by which the decision was made. Not the algorithm’s source code — but a clear explanation of why exactly such a decision. This right is violated constantly. Companies make automatic decisions about people — and do not consider it necessary to explain. Because most people do not know that they have the right to ask. Now you know.
What to do if your rights are violated
Let us go through this step by step. Not abstractly — a concrete algorithm of actions. Step one. Record. Save all letters, screenshots, dates. If a company did not respond to a request — record the date of sending and the date when the one-month deadline expired. This is your evidence base. Step two. Remind. Sometimes companies do not respond simply because the request reached the wrong person or got lost. Send a repeat letter noting that the first was sent on such-and-such a date and the response deadline has expired. Step three. A complaint to the supervisory authority. In Estonia — AKI, Andmekaitse Inspektsioon. The site aki.ee. A complaint is submitted online, for free. You need to describe the situation, attach the correspondence, indicate which right was violated. AKI is obliged to consider the complaint and respond. Step four. If the violation is serious — you can go to court. This already requires a lawyer. But GDPR provides for the right to compensation for real damage caused by the violation — this is Article 82. An important clarification. Most situations are resolved at the third step. When a company receives a signal that the regulator is looking — it often finds a way to answer a request it ignored for three months.
Why this matters not only for you
When a person files a complaint with AKI — they are not merely solving their own problem. The regulator sees a pattern. If one company receives ten complaints about one and the same violation — this is no longer chance. It is a systemic problem that requires investigation. Every complaint is data for the regulator. Every request for access to data is a signal to a company that people are beginning to look. Every refusal of advertising cookies is one profile fewer in a broker’s database. The system is arranged so that you feel yourself one against all. One person against a corporation with a legal department and lobbyists in Brussels. But GDPR is arranged differently. It is written on the assumption that you have enough rights. You only need to start using them. Eight rights. One regulator. One request you can start with today. The system works when people believe in it; that is enough to try. Try.