Metadata Is Power

Why Protecting the Contents of a Message Is No Longer Enough


My illustration entitled: “The Digital Breadcrumb Trail” – I walk through a dark futuristic city, unknowingly leaving glowing footprints behind him. Each footprint contains a different data trace: location, time, device, contact, purchase or website visit.


The most revealing part of a communication may not be what was said.

It may be who communicated, when the communication occurred, where the participants were located, how frequently they interacted and which other people belonged to the same network.

This surrounding information is commonly described as metadata: data about other data. A telephone call has content, but it also produces records identifying the numbers involved, the time of the call, its duration and possibly the locations of the devices. An email contains a message, but it also has a sender, recipient, timestamp, subject line, routing information and technical identifiers. A photograph depicts something, but its file may contain the time, device and location at which it was created.

Each record may appear insignificant when examined alone. Collected over time and combined with other records, metadata can reconstruct the architecture of a person’s life.

It can reveal relationships without reading correspondence. It can identify routines without entering a home. It can expose religious, political, medical and professional associations without hearing a single conversation. It can show where a person sleeps, works, worships, travels and whom he contacts before or after an important event.

Metadata is therefore not merely administrative information surrounding meaningful content.

Metadata is a map of human behaviour, and whoever controls the map acquires power over the people represented within it.


The Metadata Debate After June 2013

The public importance of metadata became impossible to ignore in June 2013, when documents disclosed by Edward Snowden revealed previously secret surveillance activities conducted by the United States National Security Agency.

One of the first published documents was an order requiring Verizon Business Network Services to provide the telephone records of large numbers of customers. The records concerned communications metadata rather than the audio content of the calls. They included information such as originating and receiving telephone numbers, time, duration and other routing or identifying data.

The distinction between content and metadata quickly became central to the public defence of the program. Citizens were told that the government was not necessarily listening to the contents of every telephone call.

That distinction matters, but it should not end the debate.

Not listening to every conversation does not mean learning nothing about the people who participated. A sufficiently complete record of communication patterns can expose relationships, organizations and changes in behaviour. The surveillance of a network may sometimes reveal more than the interception of one isolated conversation.

The important question is not merely:

Did an observer hear what I said?

We must also ask:

What can an observer discover by studying when, where, how and with whom I communicate?


What Counts as Metadata?

Metadata exists throughout digital life. It is generated whenever systems must route communications, authenticate users, record transactions, organize files or operate networks.

Activity Possible Metadata Possible Inferences
Telephone call Numbers, time, duration, device and cell-tower location Relationships, routines, movements and changes in behaviour
Email Sender, recipients, timestamp, subject, IP address and routing information Professional networks, personal associations, location and organizational structure
Internet access IP address, connection time, device identifiers and requested services Identity, location, habits and patterns of online activity
Mobile device Cell towers, GPS coordinates, nearby networks and device identifiers Home, workplace, travel, meetings, worship and medical visits
Photograph Date, time, camera model, coordinates and editing history Where and when an image was created and possibly who was present
Financial transaction Parties, amount, location, time, merchant and transaction identifiers Income, interests, travel, health, beliefs and personal relationships
Social network Connections, reactions, login times, device information and location Communities, influence, interests, affiliations and social importance

Not every service collects every category, and not every inference will be accurate. But the general principle remains: digital activity produces records beyond the information users consciously intend to communicate.

Those records can become valuable precisely because people rarely think of them as disclosures.


The Envelope Analogy Is No Longer Sufficient

Metadata is sometimes compared to information written on the outside of an envelope. The letter inside represents content, while the names and addresses on the envelope represent metadata.

The analogy is useful, but incomplete.

A traditional envelope normally reveals one communication between one sender and one recipient. It is not automatically placed into a permanent database containing every letter sent or received by the population. It is not instantly combined with location records, financial transactions, address books and years of previous correspondence. It does not normally produce an interactive map showing an individual’s changing network of relationships.

Digital metadata is different because it can be collected continuously, retained inexpensively, searched instantly and analyzed at enormous scale.

The privacy significance of one record may be limited. The significance of millions of connected records is fundamentally different.

The envelope analogy describes the individual record. It does not describe the power created by universal collection and permanent aggregation.


Content Reveals Words; Metadata Reveals Structure

The content of a message tells an observer what was said. Metadata describes the structure surrounding the communication.

Suppose a person telephones an oncologist, speaks with a health-insurance provider and later calls close family members. Nobody needs to hear the conversations to form a sensitive inference.

Suppose a journalist receives repeated late-night calls from an employee inside a government department shortly before publishing a confidential story. The communications pattern may expose the probable source even when the calls are encrypted.

Suppose several citizens begin communicating with one another, travel to the same location and contact a political organization. Metadata may reveal the formation of a movement before the group makes any public declaration.

Suppose a person regularly visits a place of worship, a medical clinic, a lawyer’s office or the headquarters of a labour organization. Location records can reveal associations that the individual never entered into a form or communicated in a readable message.

These examples demonstrate why metadata should not be dismissed as information about communications rather than information about people.

Human lives possess structure. We live through relationships, routines, movements and associations. Metadata records that structure.


Aggregation Changes the Meaning of Information

The power of metadata arises partly from aggregation.

One telephone record may reveal little. A year of telephone records can reveal close relationships, professional networks and major changes in someone’s life. One location point may be insignificant. Thousands of location points can identify a home, workplace and daily routine.

Research published in 2013 by Yves-Alexandre de Montjoye and his colleagues demonstrated the identifying power of mobility data. In their dataset, four approximate spatiotemporal points were sufficient to uniquely identify 95 percent of individuals. The study showed how records that appear anonymous can become identifying when human movement patterns are sufficiently distinctive.

This creates a wider problem for privacy. Removing a person’s name from a dataset does not necessarily make the person anonymous. Identity may be reconstructed from patterns.

A regular nighttime location may indicate a home. A regular daytime location may indicate employment. Visits shared with known individuals may reveal relationships. Once one point in the pattern is connected to a legal identity, other records may follow.

Data that appears harmless in isolation can therefore become intimate through combination.

Metadata does not merely describe events. Aggregated metadata describes patterns, and patterns describe people.


Metadata and Freedom of Association

Privacy protects more than solitary individuals. It protects relationships and associations.

A democracy requires people to be able to speak with journalists, organize political opposition, consult lawyers, seek medical treatment and join religious or civic communities. Many of these activities are lawful but sensitive.

When the state or another powerful institution possesses a complete map of communication, it can identify the structure of a group without infiltrating meetings or reading messages. It can locate highly connected individuals, discover intermediaries and observe when new relationships emerge.

The resulting power may produce self-censorship even if no immediate punishment occurs.

A person who believes every contact will become part of a permanent government or corporate record may hesitate to approach a journalist. An employee may avoid reporting wrongdoing. A citizen may decline to join an unpopular political organization. A patient may delay contacting a sensitive medical service.

Surveillance alters behaviour because people anticipate how their records may later be interpreted.

The freedom to associate openly depends partly upon the freedom to associate without automatically constructing a permanent map for unknown observers.


Metadata and Location

Communication metadata increasingly includes information about location. Mobile telephones must connect to infrastructure, and that connection can create records showing where a device was operating.

Location metadata concerns more than geography. It can reveal behaviour.

Where a person spends the night may indicate home. Where he spends weekdays may indicate employment. Repeated visits may reveal medical treatment, political involvement, religious practice or an intimate relationship. Travel beside another device may suggest association even if the two owners never communicate electronically.

Location is also retrospective. When records are retained, an institution does not merely know where a person is now. It may reconstruct where that person was months or years earlier.

This creates a form of historical surveillance. Authorities no longer need to decide in advance whom to follow. They may collect information broadly and decide later whose movements deserve examination.

That reversal is politically significant.

Traditional targeted surveillance begins with a person or investigation and follows that subject. Mass metadata collection begins by recording the population and later searches within the accumulated history.

A database of past movements can become a time machine for institutional power.


Encryption Protects Content, Not Necessarily Metadata

In Cryptography Is Applied Freedom, I argued that encryption can transform privacy from an institutional promise into a property of technological architecture.

But cryptography does not automatically conceal everything.

An encrypted message may protect its contents while still revealing who sent it, who received it, when it was transmitted, the size of the message and the network locations involved. An observer who cannot read communications may still study traffic patterns.

This is known as traffic analysis. The observer examines the existence, timing, direction, frequency and volume of communication rather than its readable content.

Traffic analysis can identify important participants within a network. A sudden increase in communication may indicate an approaching event. Repeated contact between two otherwise unrelated organizations may expose coordination. Silence can also become meaningful when it represents a departure from an established pattern.

This does not make encryption unimportant. Strong encryption remains essential because readable content can be extraordinarily sensitive. But a complete philosophy of privacy cannot stop at content encryption.

Privacy-preserving systems must also consider:

  • what metadata is created;
  • which intermediaries receive it;
  • how long it is retained;
  • whether identifiers can be separated from activity;
  • whether routing patterns can be concealed;
  • and whether multiple records can be linked into one profile.

Cryptography protects the message. Metadata protection must also protect the surrounding relationship.


The Legal Distinction Between Content and Metadata

Law has often treated communications content as more sensitive than the records required to deliver that communication.

In the United States, the Supreme Court’s 1979 decision in Smith v. Maryland considered the use of a pen register that recorded telephone numbers dialled from a particular telephone. The Court concluded that the caller did not possess the same reasonable expectation of privacy in numbers conveyed to the telephone company as he might possess in the contents of the conversation.

That decision concerned limited telephone technology in the 1970s. Digital civilization has transformed the quantity, variety, persistence and analytical value of information conveyed to service providers.

Modern individuals disclose operational data to intermediaries whenever they use telephones, email, search engines, social networks, payment systems and cloud services. Much of this disclosure is not a meaningful choice. The service cannot function without receiving some of the information required to route or process the activity.

Treating every necessary disclosure to a machine or service provider as the abandonment of privacy would produce a dangerous result:

The more essential digital systems become, the fewer privacy expectations individuals would retain.

The legal protection of metadata must therefore consider modern scale and aggregation. A single dialled number is not equivalent to a comprehensive, searchable record of a person’s communications, movements and associations.

Legal categories developed for an earlier technological era should not automatically determine the boundaries of freedom in a networked society.


Retention Creates Future Power

Metadata collection cannot be evaluated only by asking how information will be used today. Retained information creates possibilities for future use.

The European Union’s 2006 Data Retention Directive required member states to ensure the retention of specified communications data for periods between six months and two years. The retained categories were intended to assist the investigation and prosecution of serious crime, while the contents of communications were excluded.

The purpose of fighting serious crime is legitimate. But broad retention still creates a profound structural question: should records concerning the communications and locations of entire populations be stored in advance of any individualized suspicion?

Once metadata exists, it can be requested, searched, copied, breached, sold, transferred or combined with other records. It may remain accessible after the original purpose has changed. A database created under one government may be inherited by another. A company trusted today may be acquired tomorrow.

Information collected for security may later be used for political control. Information collected for advertising may later be demanded by authorities. Information collected for convenience may become evidence in an entirely unrelated dispute.

The individual cannot know every future observer or every future purpose at the moment the record is created.

Retention is therefore an exercise of power even before anyone searches the database.


Government and Corporate Metadata

The current debate focuses heavily upon government surveillance, and rightly so. Governments possess legal powers of investigation, detention and punishment that private companies ordinarily do not.

Yet corporate metadata also deserves scrutiny.

Telecommunications companies possess calling and location records. Search engines possess histories of questions. social networks possess maps of relationships. Payment providers possess transaction histories. Online services record devices, login times and network addresses.

These databases may be used to personalize services, detect fraud, deliver advertising or improve security. Some collection may be operationally necessary. But commercial usefulness does not eliminate political significance.

Corporate and government surveillance can also reinforce one another. Governments may seek access to information originally collected by companies. Companies may be legally prohibited from revealing the requests they receive. Data gathered for one institutional purpose can become available for another.

Privacy Is Sovereignty established that Cypherpunkism does not seek to transfer authority from the state to the corporation or from the corporation to the state.

Neither government nor corporation should become the unquestioned sovereign of the individual’s digital relationships.

The institution controlling metadata controls a representation of human behaviour. That power must be limited regardless of whether the database is publicly or privately operated.


“Nothing to Hide” Misunderstands Metadata

The claim that innocent people have nothing to hide becomes especially weak when applied to metadata.

A person may have committed no wrongdoing while still having legitimate reasons to protect relationships, movements and routines. Journalists protect sources. Lawyers protect clients. Doctors protect patients. Businesses protect negotiations. Citizens protect political associations. Families protect intimate relationships.

Metadata can also be misunderstood. A telephone call to a criminal suspect does not establish participation in a crime. A visit to a medical specialist does not establish a diagnosis. Presence near a political demonstration does not establish membership in an organization.

Patterns produce inferences, and inferences can be wrong.

The person described by a metadata profile may not know that the profile exists, what conclusions were drawn or which decision was influenced by it. He may have no opportunity to explain context or correct error.

The correct question is not whether the individual has something criminal to conceal.

The correct questions are:

  • Who is collecting the metadata?
  • What authority permits its collection?
  • Is every retained category necessary?
  • How long will the records exist?
  • What conclusions may be inferred?
  • Who may gain access in the future?
  • Can the individual challenge inaccurate interpretations?
  • What prevents the database from being repurposed?

A person may have nothing criminal to hide and still possess a human life that should not be permanently mapped.


Targeted Investigation and Mass Collection

Cypherpunkism does not deny that metadata can possess legitimate investigative value. Communication records may help identify fraud, locate missing persons, establish criminal associations or investigate threats.

The usefulness of metadata is precisely why it requires safeguards.

There is a moral and political difference between obtaining relevant records during a targeted investigation and collecting the records of an entire population in advance. The first begins with a particular justification. The second begins with universal availability.

Legitimate access should be:

  • authorized by clear law;
  • directed toward a defined purpose;
  • necessary to that purpose;
  • proportionate to the suspected harm;
  • limited in duration and scope;
  • subject to independent oversight;
  • protected against unrelated secondary use;
  • and open to meaningful review when secrecy is no longer necessary.

Accountability does not require the elimination of privacy. Privacy does not require the elimination of legitimate investigation.

The challenge is to prevent the exceptional need to examine particular records from becoming a permanent justification for recording everyone.


My illustration “The Digital Breadcrumb Trail” work-in-progress – Surveillance drones follow the trail. Represents: Everyday digital activity continuously creates a record of movement and behaviour.


Metadata Minimization

The strongest way to prevent misuse of unnecessary metadata is not to collect it.

Systems should generate, retain and centralize only the information genuinely required for their legitimate functions. Data should not be preserved indefinitely merely because storage has become inexpensive.

Metadata minimization may include:

  • collecting fewer identifiers;
  • shortening retention periods;
  • separating identity from activity;
  • processing information locally where possible;
  • using temporary or rotating identifiers;
  • limiting linkability across services;
  • encrypting retained records;
  • restricting access through technical and legal controls;
  • and deleting information after its legitimate purpose ends.

Privacy cannot depend entirely upon users changing complicated settings after surveillance has already occurred. Metadata protection must be considered when networks, applications and protocols are designed.

An architecture that does not create an unnecessary record is stronger than a policy promising not to abuse it.


Eight Tests of Metadata Sovereignty

A system that claims to respect privacy should be examined through eight practical tests.

1. The Generation Test

What metadata does the system create as an unavoidable or deliberate consequence of participation?

2. The Necessity Test

Is every category genuinely required for the service, or is information collected merely because it may become valuable?

3. The Identification Test

Can records be connected to a legal identity, device, account, location or persistent pseudonym?

4. The Linkability Test

Can separate activities, services or contexts be joined into one profile?

5. The Retention Test

How long is metadata stored, and is it automatically deleted when its legitimate purpose ends?

6. The Access Test

Which employees, companies, governments and other institutions can obtain the records?

7. The Inference Test

What sensitive facts can be inferred even if the contents of communications remain protected?

8. The Power Test

Does metadata collection provide a necessary and proportionate function, or does it create an institution capable of reconstructing human life without meaningful restraint?

These questions reveal whether privacy exists throughout the system or ends at the boundary of encrypted content.


The Cypherpunkist Principle of Metadata

Cypherpunkism defines privacy as sovereignty over disclosure. Metadata complicates disclosure because individuals often reveal it indirectly by using systems necessary for modern life.

A person does not necessarily intend to reveal his social network when making a telephone call. He does not necessarily intend to reveal a medical concern when carrying a mobile device to a clinic. He does not necessarily intend to disclose his political beliefs when communicating with an organization.

The system creates records beyond the person’s immediate intention.

Digital Sovereignty therefore requires meaningful protection not only for what individuals deliberately say, but also for the patterns generated around their actions.

The Cypherpunkist principle is:

Protect the content, minimize the metadata and prevent patterns of ordinary life from becoming instruments of unrestricted institutional power.

This principle imposes responsibilities upon governments, corporations, designers and users.

Governments must distinguish targeted investigation from indiscriminate collection. Corporations must not treat every observable behaviour as information they are automatically entitled to retain. Designers must recognize that routing, logging and identification choices create political consequences. Users must understand that encrypted content may still leave visible patterns.

Privacy requires protection at every layer.


Metadata Is Power

Metadata is frequently described as though it were less important than content. In isolation, an individual record may indeed appear less revealing than the words of a conversation.

But digital power does not arise only from isolated records.

It arises from collection.

Retention.

Linkage.

Analysis.

Inference.

A database of metadata can expose relationships without reading messages, movements without following bodies and beliefs without asking questions. It can reconstruct the structure of a person’s life while leaving every individual communication encrypted.

The debate over privacy must therefore move beyond the narrow question of whether anyone is listening.

We must ask who possesses the map.

Who can search it.

Who can combine it with other maps.

Who can preserve it indefinitely.

And who can use it against the person whose life it describes.

Privacy protects the content of human communication.

Metadata protection preserves the structure of human association.

Both are necessary for Digital Sovereignty.

Content reveals what was said.

Metadata reveals who we are connected to.

Aggregated metadata reveals how we live.

Metadata is power.


References and Foundational Influences

  1. United Nations. Universal Declaration of Human Rights, Article 12. 1948. Available online.
  2. United Nations. International Covenant on Civil and Political Rights, Article 17. Adopted December 16, 1966; entered into force March 23, 1976. Available online.
  3. United States Supreme Court. Smith v. Maryland, 442 U.S. 735. 1979. Available online.
  4. European Parliament and Council of the European Union. “Directive 2006/24/EC on the Retention of Data Generated or Processed in Connection with the Provision of Publicly Available Electronic Communications Services or of Public Communications Networks.” March 15, 2006. Available online.
  5. Solove, Daniel J. “‘I’ve Got Nothing to Hide’ and Other Misunderstandings of Privacy.” San Diego Law Review, Vol. 44, 2007, pp. 745–772. Available online.
  6. Nissenbaum, Helen. Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford University Press, 2010. Publication information.
  7. European Commission. “Evaluation Report on the Data Retention Directive.” COM(2011) 225 final, April 18, 2011. Available online.
  8. United States Supreme Court. United States v. Jones, 565 U.S. 400. 2012. Available online.
  9. de Montjoye, Yves-Alexandre, César A. Hidalgo, Michel Verleysen and Vincent D. Blondel. “Unique in the Crowd: The Privacy Bounds of Human Mobility.” Scientific Reports, Vol. 3, Article 1376, March 25, 2013. DOI: 10.1038/srep01376.
  10. La Rue, Frank. “Report of the Special Rapporteur on the Promotion and Protection of the Right to Freedom of Opinion and Expression.” United Nations Human Rights Council, A/HRC/23/40, April 17, 2013. Available online.
  11. Greenwald, Glenn. “NSA Collecting Phone Records of Millions of Verizon Customers Daily.” The Guardian, June 6, 2013. Available online.
  12. Greenwald, Glenn, and Ewen MacAskill. “NSA PRISM Program Taps in to User Data of Apple, Google and Others.” The Guardian, June 7, 2013. Available online.
  13. Sim, Herbert R. “Cypherpunkism: A Philosophy of Digital Sovereignty.” October 10, 2010. Available online.
  14. Sim, Herbert R. “The Cypherpunkist Manifesto.” November 22, 2010. Available online.
  15. Sim, Herbert R. “The Eight Principles of Cypherpunkism.” October 10, 2011. Available online.
  16. Sim, Herbert R. “Privacy Is Sovereignty.” March 9, 2013. Available online.
  17. Sim, Herbert R. “Cryptography Is Applied Freedom.” June 17, 2013. Available online.