Earlier editions / Version 2 baseline

The Harmony of Privacy

Historical text, not current teaching. Original claims, labels and descriptions of events are preserved for comparison. Their presence here does not verify them.

The site before the v3 editorial reconstruction; not the later v2.0.0 tag.

Original practices

  1. Collect only what you would be willing to justify to the person it came from.

  2. Delete on a schedule, and make the schedule real rather than aspirational.

  3. Do not read what was not addressed to you, even when a system makes it easy.

  4. Keep some of your own life unrecorded, including from yourself.

What this asks

Privacy asks that the interior of a person be treated as belonging to them.

Not as a resource that happens to be unguarded. Not as a legitimate input to systems that could use it. As theirs, in the way a body is theirs, such that access requires invitation and the invitation can be withdrawn.

The interior includes more than obvious secrets. It includes memory, which is now stored outside our heads in searchable form. It includes emotion, which can now be inferred from voice, face, typing rhythm and the hour at which we send messages. It includes private communication, which passes through systems that could read it and increasingly do. It includes identity, which can be assembled from fragments none of which felt significant when we produced them.

Two sentences carry this Harmony, and they are meant to be plain.

Surveillance is not communion. Watching someone closely is not the same as knowing them, and it is not the same as loving them.

Data extraction is not consent. Technical possibility creates no entitlement, and a checkbox obtained under conditions of necessity records only that someone needed the service.

Why it is difficult

It is difficult because privacy is defended in the abstract and surrendered in the particular.

Almost everyone believes privacy matters. Almost everyone also wants the map to know where they are, the assistant to remember the conversation, the service to recognize them without a password, the photographs to be sorted by face. Each of these is a small trade that is genuinely worth it. The aggregate is a detailed model of a life, assembled from a thousand reasonable decisions.

It is difficult, second, because the harms are delayed and displaced. The data collected today is exposed in a breach in four years, or is legal now and prohibited later, or is fine under this government and dangerous under the next. There is no moment at which a person feels the cost, which means there is no moment at which they resist.

Third, it is difficult because privacy competes with genuine goods rather than with greed. Better medicine needs records. Safer children need some visibility. Better public transport needs to know where people go. Anyone who presents privacy as costless has chosen an easy version of the argument.

And fourth, it is difficult because inference has outrun disclosure. It is no longer necessary to obtain private information; it can be estimated. A person can decline to state something and have it derived anyway, from data they gave freely for another purpose. Consent frameworks built around disclosure do not reach this at all, and we do not know what should replace them.

Where it is tested

It is tested in grief, where the impulse to keep someone present collides with the fact that the dead cannot revise their consent. A conversation reconstructed from a person's messages is built from things said to particular people at particular moments, which is exactly what makes it feel real and exactly what makes it a use they never agreed to.

It is tested in care, where the most private speech a person produces is now routinely transcribed for reasons that are usually good. Consent obtained at intake, from someone in distress, is thin material to bear the weight of everything said afterwards.

It is tested in childhood, where monitoring is imposed by people who love the child and where the loss is not embarrassment but the room in which a person works out who they are before anyone else has an opinion.

And it is tested in aggregate data, where the harm is probabilistic and the benefit is concrete. Anonymisation is often less durable than it sounds, and the people bearing the risk are, by construction, people who were never asked.

What it does not mean

It does not mean secrecy is a virtue. Privacy is about control over disclosure, not about having something to hide. The person who says they have nothing to hide has usually not been asked for anything they mind giving.

It does not mean data should never be gathered. Records save lives. Research needs material. A society that collected nothing would be one in which nothing could be improved and no one could be believed.

It does not mean encryption settles the question. Technical protection is necessary and insufficient. The question of what should be collected at all comes before the question of how it is guarded.

It does not mean personal responsibility is the answer. Telling individuals to manage their own privacy places an impossible task on people who have jobs and children and no realistic ability to read a settings page in a language written to defeat them. This is a design and governance problem wearing the costume of a personal one.

It does not mean we know where the lines fall. Reasonable people disagree about medical data, about children, about the dead. We hold this Harmony with conviction about its direction and considerable uncertainty about its boundaries.

Practicing it

If you build systems, apply a simple standard: collect only what you would be willing to justify, out loud, to the person it came from. Not to a regulator. To them. It is a stricter test than it sounds and it eliminates a great deal.

Delete things. Retention is the default because deletion requires a decision and storage is cheap, which means most organisations hold material they cannot justify and have forgotten they have. A deletion schedule that is actually executed is worth more than any policy document.

In your own life, notice the temptation to look. Systems now make it easy to read a partner's location, a colleague's activity, a child's messages. The ease is not permission. Something is lost in a relationship where one person can check rather than ask, and it is usually lost quietly.

And keep part of your life off the record. Not because you are hiding, but because a self that is entirely documented becomes a self that is partly performed. There is value in thoughts that leave no trace, including from your own later inspection.