Privacy Is Sovereignty

Why Control Over Disclosure Is Essential to Human Freedom in the Digital Age


In my illustration entitled “The Data Shadow Reclaimed” – A citizen’s enormous digital shadow—formed from messages, purchases, movements, relationships and biometric records—is being pulled toward centralized data towers.


Twenty Years After “A Cypherpunk’s Manifesto”

Twenty years ago today, on March 9, 1993, Eric Hughes published A Cypherpunk’s Manifesto.

Its opening proposition remains one of the most important statements in the history of digital freedom:

“Privacy is necessary for an open society.”

Hughes understood that electronic communication would transform privacy from a question concerning letters, telephone calls and physical rooms into a question of computer architecture.

As communication became digital, privacy would have to become digital.

As transactions moved onto computer networks, people would require ways to exchange information without unnecessarily revealing their identities.

As institutions accumulated larger databases, the individual would require technological methods of establishing boundaries around personal information.

His distinction between privacy and secrecy was especially important.

Privacy does not mean that nobody knows anything about us.

It means that we possess meaningful control over what is revealed, to whom it is revealed and under what circumstances.

When I introduced Cypherpunkism on October 10, 2010, I extended this principle into a broader philosophy of Digital Sovereignty.

In The Cypherpunkist Manifesto, I expressed the principle directly:

Privacy is sovereignty over disclosure.

The Eight Principles of Cypherpunkism subsequently established Privacy as the first of eight interdependent principles:

Every individual should possess meaningful control over the disclosure of personal information.

This article develops that principle more fully.

Privacy is not merely a preference.

It is not a luxury.

It is not simply the absence of observation.

Privacy is the power to establish boundaries around one’s identity, relationships, thoughts, communications and activities.

It is the authority to decide which parts of oneself enter the knowledge of other people and institutions.

Without that authority, the individual may remain physically free while becoming informationally subordinate.


Privacy Is Not Secrecy

The most common misunderstanding of privacy begins with the assumption that a private person must be concealing wrongdoing.

This produces the familiar argument:

“If you have nothing to hide, why should you care about privacy?”

But every ordinary person has things he does not disclose to everyone.

A person closes the door to his home.

He speaks differently with his family than with strangers.

He does not publish every medical record.

He does not reveal every financial transaction.

He does not invite an unknown observer into every private conversation.

He may explore an unfamiliar political, religious or philosophical idea before deciding whether he believes it.

He may make mistakes that should not define his identity permanently.

These boundaries do not demonstrate guilt.

They demonstrate personhood.

Secrecy attempts to conceal the existence of information.

Privacy governs its appropriate disclosure.

A medical record is not necessarily secret. It is known to the patient and may be disclosed to a doctor, specialist or insurer.

Its privacy arises from the fact that it is not automatically available to employers, advertisers, neighbours and the general public.

A financial transaction may be known to the parties involved and to institutions legitimately required to process it.

That does not mean every person should possess an unrestricted view of someone else’s financial life.

A private conversation is known to its participants.

Its privacy consists of the boundary separating those participants from everyone else.

Privacy does not mean that information is never revealed. It means that disclosure remains limited by purpose, context and consent.


The Sovereignty of the Boundary

Every human being possesses boundaries.

The body is a boundary.

The home is a boundary.

Private property is a boundary.

Confidential communication is a boundary.

Personal memory is a boundary.

Individual sovereignty requires some authority over these boundaries.

A person who cannot determine who enters his home does not meaningfully control his home.

A person who cannot determine who reads his correspondence does not meaningfully control his correspondence.

A person who cannot influence how his identity is recorded, combined, analyzed and disclosed does not meaningfully control his digital identity.

Digital civilization is creating another boundary:

The informational boundary of the individual.

This boundary surrounds:

  • personal identity;
  • communications;
  • relationships and associations;
  • location;
  • financial activity;
  • medical information;
  • professional history;
  • photographs and recordings;
  • searches and reading habits;
  • political and religious interests;
  • and the accumulated history of online behaviour.

The individual produces fragments of this information whenever he uses digital systems.

One fragment may appear harmless.

A location at one moment.

One purchase.

One search.

One photograph.

One friendship.

One website visit.

But fragments can be combined.

The resulting profile may reveal far more than the individual knowingly disclosed in any single interaction.

Digital sovereignty therefore requires more than control over individual facts.

It requires some protection against unlimited aggregation, permanent linkage and unrestricted secondary use.

The power to collect fragments can become the power to reconstruct a person.


Privacy Preserves the Freedom to Think

Human thought requires private space.

People do not arrive at every belief immediately.

They explore.

They question.

They contradict themselves.

They investigate ideas they may ultimately reject.

They speak tentatively before speaking publicly.

This private process is essential to intellectual independence.

If every question is recorded, every search attached to a permanent identity and every unfinished thought preserved indefinitely, people may become afraid to explore.

They may avoid controversial books.

They may avoid unfamiliar political ideas.

They may refuse to investigate sensitive medical conditions.

They may speak only in ways that appear acceptable to whoever may eventually examine the record.

No authority needs to issue a direct prohibition.

The awareness of observation can produce self-censorship.

Surveillance does not merely record behaviour. It changes behaviour.

A society can therefore lose freedom without formally abolishing speech.

People may retain the legal right to speak while gradually losing the private space required to develop independent thoughts worth expressing.

Privacy protects the period before publication.

It protects intellectual experimentation.

It allows the individual to become a person rather than merely perform an approved identity before an invisible audience.


Privacy Preserves Freedom of Association

Freedom does not consist only of what a person says.

It also concerns whom he meets, supports, consults, worships with, organizes beside and considers a friend.

Associations reveal identity.

A list of contacts may reveal political beliefs.

Location records may reveal religious attendance.

Financial records may reveal charitable support.

Communication patterns may reveal membership in a professional, medical or political group even when the contents of communications remain unread.

This is why metadata matters.

Information about who communicated, when communication occurred, where the participants were located and how frequently they interacted can reveal the structure of a person’s life.

Content may tell an observer what was said.

Metadata may tell the observer who matters.

When every association can be reconstructed, people may avoid lawful but unpopular groups.

They may hesitate to consult journalists, lawyers, doctors, activists or religious leaders.

They may associate only with those whose approval appears socially safe.

Private association is part of a pluralistic society because people must be able to gather before they are powerful, popular or universally accepted.


Privacy Protects Contextual Identity

Human identity is contextual.

A person does not present exactly the same aspect of himself in every situation.

He may be a parent at home.

A professional at work.

A patient at a hospital.

A student in a classroom.

A voter in a political discussion.

A writer under a pen name.

These identities are not necessarily deceptive.

They reflect the fact that different relationships justify different forms of disclosure.

Information given in one context should not automatically become available in every other context.

A person may disclose a medical condition to a doctor without consenting to its use by an advertiser.

He may provide an address for delivery without consenting to permanent location profiling.

He may share a photograph with friends without intending it to become part of a commercial identification database.

He may participate in a discussion under a pseudonym without attempting to defraud anyone.

The movement of information from one context into another can violate privacy even when the original disclosure was voluntary.

Consent to one use is not consent to every use.

Digital systems often erase contextual boundaries because databases can be copied, combined and searched at almost no visible cost to the person being described.

Cypherpunkism therefore supports contextual identity, pseudonymity and selective disclosure where complete legal identification is unnecessary.

A person should be able to prove what an interaction requires without exposing everything else about himself.

He may need to prove that he is authorized without revealing his complete identity.

He may need to prove that he meets an age requirement without revealing his date of birth.

He may need to prove membership without revealing unrelated personal information.

Cryptographic systems may increasingly make such forms of selective disclosure possible.

The future of identity should not be a choice between total anonymity and total exposure.

It should include the ability to reveal what a particular relationship legitimately requires.


The Failure of the “Nothing to Hide” Argument

The “nothing to hide” argument fails because it begins with the wrong question.

It asks whether an individual has committed an act he wishes to conceal.

Privacy asks broader questions:

  • Who possesses information?
  • How was it obtained?
  • Was its collection necessary?
  • Is it accurate?
  • How long will it be retained?
  • With whom will it be shared?
  • Can it be combined with other records?
  • Can it be used to exclude, manipulate or discriminate?
  • Can the individual correct it?
  • What happens when the institution controlling it changes?

A person may have nothing criminal to hide and still have much to lose.

Incorrect information can produce an incorrect judgment.

Accurate information can be removed from its context.

Old information can be treated as though it describes the present.

Lawful behaviour can be interpreted suspiciously.

Personal information can be used for manipulation.

A database created for convenience can later be used for control.

An institution trusted today may be acquired, compromised or politically transformed tomorrow.

The individual does not know every future observer or every future purpose.

The question is not merely whether I have something to hide. The question is why another party should possess unlimited power to know.

Governments protect classified information.

Corporations protect trade secrets.

Banks secure financial systems.

Institutions understand that control over information creates power.

The same principle should not be denied to the individual.


Government Surveillance and Corporate Surveillance

Privacy debates frequently concentrate upon government surveillance.

This concern is justified.

Governments possess powers that private organizations ordinarily do not.

They can investigate.

They can compel disclosure.

They can restrict movement.

They can prosecute and punish.

A government with unrestricted access to communications, associations and personal records may acquire an extraordinary ability to identify and suppress opposition.

But corporate surveillance also deserves scrutiny.

Commercial platforms increasingly mediate communication, search, publication, commerce and social relationships.

Their databases may reveal more about an individual’s daily life than many government records.

The fact that information was initially provided to a company does not eliminate the possibility of coercion or dependency.

Participation in modern society may increasingly require the use of particular technological systems.

Formal consent becomes less meaningful when declining means exclusion from communication, employment, commerce or essential services.

The objective of Cypherpunkism is therefore not to transfer sovereignty from the state to the corporation.

Neither government nor corporation should become the unquestioned sovereign of digital identity.

Both should be constrained by legitimate purpose, proportionality, transparency, security and meaningful individual rights.

Where possible, technological architecture should reduce the amount of information either must be trusted to hold.


Collection Is an Exercise of Power

Institutions often treat the collection of information as harmless until abuse occurs.

But collection itself changes the balance of power.

Once information has been collected, it can be searched.

It can be copied.

It can be transferred.

It can be combined with other information.

It can be stolen.

It can be demanded by authorities.

It can be retained after its original purpose has disappeared.

A promise not to misuse information is valuable.

But information that was never collected cannot be leaked, stolen or repurposed.

The strongest protection for unnecessary data is not to possess it.

Cypherpunkism therefore supports data minimization.

A system should ask:

  • Is this information genuinely required?
  • Can the same function be performed with less information?
  • Can identifying information be separated from operational information?
  • Can information remain on the user’s device instead of a central database?
  • Can the record be deleted after its legitimate purpose ends?
  • Can cryptography verify a claim without revealing the underlying personal data?

The default assumption of digital systems should not be that every available fact deserves to be collected.

Technological capability does not create moral entitlement.

What can be collected is not necessarily what should be collected.


Consent Must Be Meaningful

Many digital services claim permission through lengthy terms and privacy policies.

The individual is presented with a choice:

Accept everything or do not participate.

This may satisfy a formal requirement.

It does not necessarily create meaningful consent.

Meaningful consent requires that the individual can reasonably understand:

  • what information will be collected;
  • why it is required;
  • how it will be used;
  • how long it will be retained;
  • which other parties may receive it;
  • and what consequences follow from refusal.

Consent should also be specific.

Permission to perform one function should not silently become permission for unrelated future uses.

Nor should privacy depend entirely upon individuals navigating complicated settings after information has already been exposed.

The burden cannot rest entirely upon the user.

Privacy should increasingly become the default condition, not an obscure option hidden inside a system.


Privacy Must Be Designed Into Technology

A privacy policy describes what an organization promises to do.

A privacy-preserving architecture limits what the organization is capable of doing.

Both matter.

But they are not equivalent.

The concept of Privacy by Design, developed by Ann Cavoukian, argues that privacy should be incorporated proactively into information systems, organizational practices and infrastructure rather than added only after harm occurs.

This approach is compatible with Cypherpunkism.

Privacy should be considered before a database is created.

Before an identity requirement is imposed.

Before information is centralized.

Before permanent retention becomes the default.

Before users become dependent upon an architecture they cannot meaningfully leave.

The United States Federal Trade Commission’s 2012 privacy report similarly emphasized privacy by design, simpler choices and greater transparency.

In Europe, the European Commission has proposed a new data-protection framework intended to strengthen individual rights and obligations concerning the processing of personal data.

These legal and regulatory developments are important.

But Cypherpunkism adds a technological requirement:

Where privacy can be protected through architecture, it should not depend solely upon compliance.

Systems can reduce collection.

They can encrypt stored information.

They can keep keys under individual control.

They can separate identity from activity.

They can permit pseudonymous participation.

They can delete information after its purpose expires.

They can allow users to retrieve their information and leave.

They can distribute data rather than concentrating everything in one location.

The design of technology determines whether privacy remains a fragile promise or becomes a practical property.


Cryptography Makes Privacy Enforceable

Privacy requires boundaries.

In physical life, boundaries are created through walls, doors, envelopes, locks and distance.

Digital information does not naturally possess these protections.

It can be copied perfectly.

It can travel across the world instantly.

It can remain stored indefinitely.

It can be searched and analyzed by machines at enormous scale.

Cryptography creates digital boundaries.

Encryption can restrict access to the holders of appropriate keys.

Digital signatures can prove authorization without relying entirely upon physical identity.

Cryptographic protocols can enable verification while limiting unnecessary disclosure.

This is why privacy and cryptography are separate but inseparable principles of Cypherpunkism.

Privacy defines the boundary.

Cryptography protects it.

Privacy without protection is a request. Cryptography can make it a rule of the system.

Strong cryptography should therefore be available to ordinary people.

A citizen should be able to protect a personal message with technology comparable in principle to that used by governments, corporations and financial institutions.

Privacy must not become a privilege reserved for the powerful.


Privacy Does Not Abolish Accountability

Privacy technologies can be abused.

So can telephones.

So can roads.

So can money.

So can nearly every general-purpose technology.

The challenge is not to create a society without accountability.

The challenge is to preserve legitimate accountability without placing every person under permanent observation.

Cypherpunkism does not claim that every action should be anonymous.

It does not claim that courts should be denied evidence.

It does not deny that violent crime, theft, fraud and abuse require investigation.

It rejects the assumption that the existence of wrongdoing makes the entire population a legitimate object of continuous surveillance.

Accountability should be targeted.

It should be based upon legitimate authority.

It should be proportionate to the harm being addressed.

It should include oversight and methods of challenging abuse.

It should not require every lawful communication and association to be permanently recorded in advance.

Privacy and responsibility must coexist.

A free society should investigate particular wrongdoing without treating privacy itself as evidence of wrongdoing.


Privacy Is Relational

Personal information often concerns more than one person.

A photograph may reveal friends.

An address book reveals contacts.

A family record reveals relatives.

A genetic record may reveal information about biological family members.

A private conversation belongs morally to all its participants, even if one participant possesses the technical ability to publish it.

The individual’s responsibility therefore extends beyond protecting himself.

He should consider the privacy of others when uploading photographs, distributing correspondence, sharing contact information or placing collective records inside third-party systems.

Digital sovereignty includes the responsibility not to surrender another person’s sovereignty carelessly.

Privacy cannot survive as an individual practice alone.

It must also become a social norm.


In my illustration “The Data Shadow Reclaimed” work-in-progress – I sever the extraction cables and returns the data shadow to its rightful owner. It represents personal data as an extension of the individual rather than corporate property.


Seven Tests of Informational Sovereignty

A system that claims to respect privacy should be examined through seven practical tests.

1. The Collection Test

Does the system collect only the information genuinely necessary to perform its stated function?

2. The Disclosure Test

Can the individual determine which information is revealed and to whom?

3. The Context Test

Is information used within the context for which it was provided, or silently transferred into unrelated purposes?

4. The Security Test

Is sensitive information protected through strong security and cryptography, or merely surrounded by promises?

5. The Retention Test

Is information deleted when its legitimate purpose ends, or preserved indefinitely because storage is inexpensive?

6. The Control Test

Can the individual access, correct, retrieve and, where appropriate, remove information concerning himself?

7. The Power Test

Does the architecture protect the individual, or does it create an institution capable of observing and controlling him without meaningful restraint?

A privacy policy may answer these questions in words.

A sovereign system must increasingly answer them through design.


The Cypherpunkist Principle of Privacy

Cypherpunkism begins with the individual.

Not because the individual exists without obligations to others.

Not because institutions possess no legitimate authority.

Not because all information should be concealed.

It begins with the individual because digital systems are increasingly capable of making individuals transparent to institutions while those institutions remain opaque to the individuals they observe.

This imbalance must be resisted.

A digitally sovereign individual should possess meaningful influence over:

  • what information is collected about him;
  • which identities he uses in different contexts;
  • who can read his communications;
  • how his information is combined;
  • how long records are retained;
  • which secondary purposes are permitted;
  • and whether he can withdraw from a system without abandoning his entire digital life.

No single protection will accomplish this.

Law is necessary.

Ethical restraint is necessary.

Institutional oversight is necessary.

Education is necessary.

Competition and technological exit are necessary.

But cryptography and privacy-preserving architecture are also necessary.

The individual must not be asked to rely upon trust where systems can provide protection.


A Declaration of Informational Sovereignty

I am not merely the information that institutions have collected about me.

I am not merely a profile assembled from searches, purchases, locations and associations.

I am not required to expose every part of myself in order to participate in technological society.

I have the right to establish boundaries around my digital life.

I have the right to communicate privately.

I have the right to use strong cryptography.

I have the right to question why information is collected.

I have the right to distinguish one context of my life from another.

I have the right to use a pseudonym where complete identification is unnecessary.

I have the right to resist permanent and indiscriminate observation.

I have the right to expect that information disclosed for one purpose will not silently become an instrument for another.

I have the right to remain a human being rather than become merely an entry in someone else’s database.

With these rights comes responsibility.

I must protect the privacy of others.

I must secure the keys entrusted to me.

I must distinguish privacy from impunity.

I must understand the systems I use.

I must support technologies that minimize unnecessary collection.

I must remember that another person’s information is not mine to surrender carelessly.


Privacy Is Sovereignty

The struggle for privacy is not a struggle to disappear from society.

It is a struggle to participate without surrendering the self.

It is the struggle to communicate without inviting an unknown audience.

To associate without constructing a permanent map of every relationship.

To explore ideas without every question becoming part of an irreversible record.

To disclose information for one purpose without losing control of it forever.

To use technology without becoming transparent to those who operate it.

Privacy allows the individual to decide where the public person ends and the private person begins.

That boundary makes autonomy possible.

It makes independent thought possible.

It makes intimate relationships possible.

It makes political dissent possible.

It makes personal transformation possible.

The digital age must not abolish this boundary merely because machines make observation inexpensive.

Technology should strengthen the individual’s ability to determine what he reveals—not make disclosure the unavoidable price of participation.

Privacy is not the concealment of wrongdoing.

Privacy is the preservation of human boundaries.

Privacy is the freedom to decide who may know what.

Privacy is sovereignty over disclosure.


References and Foundational Influences

  1. United Nations. Universal Declaration of Human Rights, Article 12. 1948.
    https://www.un.org/en/about-us/universal-declaration-of-human-rights
  2. United Nations. International Covenant on Civil and Political Rights, Article 17. Adopted December 16, 1966; entered into force March 23, 1976.
    https://www.ohchr.org/en/instruments-mechanisms/instruments/international-covenant-civil-and-political-rights
  3. Warren, Samuel D., and Louis D. Brandeis. “The Right to Privacy.” Harvard Law Review, Vol. 4, No. 5, December 15, 1890, pp. 193–220.
    https://www.cs.cornell.edu/~shmat/courses/cs5436/warren-brandeis.pdf
  4. Westin, Alan F. Privacy and Freedom. Atheneum, 1967.
  5. Diffie, Whitfield, and Martin E. Hellman. “New Directions in Cryptography.” IEEE Transactions on Information Theory, Vol. 22, No. 6, 1976, pp. 644–654. DOI: 10.1109/TIT.1976.1055638.
    https://doi.org/10.1109/TIT.1976.1055638
  6. Chaum, David. “Security Without Identification: Transaction Systems to Make Big Brother Obsolete.” Communications of the ACM, Vol. 28, No. 10, 1985, pp. 1030–1044. DOI: 10.1145/4372.4373.
    https://chaum.com/security-without-identification/
  7. May, Timothy C. The Crypto Anarchist Manifesto. Written in 1988 and circulated electronically to the Cypherpunks mailing list in 1992.
    https://cryptochainuni.com/crypto-anarchist-manifesto/
  8. Hughes, Eric. A Cypherpunk’s Manifesto. March 9, 1993.
    https://cryptochainuni.com/cypherpunk-manifesto/
  9. Lessig, Lawrence. Code and Other Laws of Cyberspace. Basic Books, 1999.
    https://cyber.harvard.edu/publications/1999/Code_And_Other_Laws_Of_Cyberspace
  10. Solove, Daniel J. “‘I’ve Got Nothing to Hide’ and Other Misunderstandings of Privacy.” San Diego Law Review, Vol. 44, 2007, pp. 745–772.
    https://papers.ssrn.com/sol3/papers.cfm?abstract_id=998565
  11. Cavoukian, Ann. Privacy by Design: The 7 Foundational Principles. Information and Privacy Commissioner of Ontario, 2009.
    https://www.ipc.on.ca/en/media/1183/download?attachment=
  12. Nissenbaum, Helen. Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford University Press, 2010.
    https://www.sup.org/books/law/privacy-context
  13. Federal Trade Commission. Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers. March 2012.
    https://www.ftc.gov/reports/protecting-consumer-privacy-era-rapid-change-recommendations-businesses-policymakers
  14. European Commission. “Proposal for a Regulation on the Protection of Individuals with Regard to the Processing of Personal Data and on the Free Movement of Such Data.” COM(2012) 11 final, January 25, 2012.
    https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52012PC0011