Privacy Manifesto: Difference between revisions
(→Preamble: changed points about surveillance) |
(→Preamble: changed "personal) |
||
(41 intermediate revisions by the same user not shown) | |||
Line 1: | Line 1: | ||
===Preamble=== | ===Preamble=== | ||
The purpose of this manifesto is to encourage and guide development of tools that enhance and extend people's ability to protect and project their privacy in the online world. We have used such tools in the natural world for as long as we've had the privacy technologies called clothing and shelter, and social norms for signaling and respecting personal intentions around privacy. We | The purpose of this manifesto is to encourage and guide development of tools that enhance and extend people's ability to protect and project their privacy in the online world. We have used such tools in the natural world for as long as we've had the privacy technologies called clothing and shelter, and social norms for signaling and respecting personal intentions around privacy. We are not close to having those yet the online world, which most of us have inhabited for less than two decades, and will likely be with us for centuries—if not millennia—to come. | ||
In the absence of those technologies and norms, it is easy for those with power to violate our personal privacy, and to rationalize those violations as well. In fact it is so easy to do both that violating privacy has become worse than rampant: it is normalized by a lucrative and easily rationalized business model that Shoshana Zuboff calls [https://www.publicaffairsbooks.com/titles/shoshana-zuboff/the-age-of-surveillance-capitalism/9781610395694/ surveillance capitalism] and Brett | In the absence of those technologies and norms, it is easy for those with power to violate our personal privacy, and to rationalize those violations as well. In fact it is so easy to do both that violating privacy has become worse than rampant: it is normalized by a lucrative and easily rationalized business model that [http://shoshanazuboff.com/ Shoshana Zuboff] calls [https://www.publicaffairsbooks.com/titles/shoshana-zuboff/the-age-of-surveillance-capitalism/9781610395694/ surveillance capitalism] and a purpose that [https://www1.villanova.edu/villanova/law/academics/faculty/Facultyprofiles/BrettFrischmann.html Brett Frischmann] and [https://www.rit.edu/directory/emsgsh-evan-selinger Evan Selinger] call [https://www.amazon.com/Re-Engineering-Humanity-Brett-Frischmann/dp/1107147093/ "re-engineering humanity."] In some countries, the extent of government surveillance comports with Orwell's worst fears. In other countries we are right to fear the same. | ||
In | In these early days, when personal privacy tech and norms are still at an embryonic stage, there are two ''pro forma'' ways for potential violators to claim they respect personal privacy. One is with a company privacy policy, which became common [https://books.google.com/ngrams/graph?content=privacy+policy&year_start=1800&year_end=2000&corpus=26&smoothing=3 starting] in the 1970s. While these are required of companies doing business in our digital age, they are easy for a company to ignore or to change at any time and without notice. The other is with a one-sided statement of terms, proffered most commonly by "notice and consent" banners on websites and detailed in thousands of words in legalese. These terms are what Friedrich Kessler, in [https://digitalcommons.law.yale.edu/fss_papers/2731/ a landmark in 1943 paper] called "contracts of adhesion." In the digital world, these kinds of contracts are typically proffered in take-it-or-leave-it ways, with no means for an individual to record their agreement or to audit the company's compliance to it. | ||
These policies, terms, and conditions are also as numerous and varied as the websites we visit and the apps and services we use. To read and consider all the policies and terms we encounter online would be more than a full-time job for all who accept those terms as a matter of course, which is why we don't bother. (A [http://lorrie.cranor.org/pubs/readingPolicyCost-authorDraft.pdf 2012 Carnegie Mellon study] says it would take 76 days per year just to read the privacy policies of the world's top 75 websites. Since terms tend to be at least as long as privacy policies, the actual time required to read both would be around double that.) | |||
The simple fact is that we need new tools — ''privacy tech'', and ''standards supporting that tech'' — on ''our'' side. There is no other way to | It is natural under these conditions for privacy advocates to look toward the government for new laws and regulations to relieve us from personal privacy violations by others. Necessary though it is (laws maintain civilization), there are two separate problems with looking for law alone to solve our privacy problems: | ||
1. New laws risk putting the regulatory cart in front of the horse and reins of tech and norms. This is what we already have with the [https://en.wikipedia.org/wiki/General_Data_Protection_Regulation GDPR], which presumes maximum agency for corporate "data controllers" and "data processors" and little agency for the "natural persons" the regulation calls "data subjects." All privacy for the individual is by the grace of companies and their policies and terms, to which individuals must agree, separately, one at a time, for all of them. And, while the [https://en.wikipedia.org/wiki/California_Consumer_Privacy_Act CCPA] in California gives people the right to get back the data horses that have been taken from private barns, it doesn't support the development of ways for people to protect what's in those barns in the first place. | |||
2. Absent constitutional protection of privacy as a right, existing law may be enough when there is little tech to lock our data barns. As Steve Wilson says in [https://www.constellationr.com/blog-news/last-thing-privacy-needs-new-laws The last thing privacy needs is new laws], "existing privacy law can substantially deal with Big Data." | |||
And none of this addresses the ability of governments everywhere covertly to harvest and process personal information as well. | |||
The simple fact is that we need new tools — ''privacy tech'', and ''standards supporting that tech'' — on ''our'' side. There is no other way to create privacy in the online world that begins to resemble what we have long enjoyed in the offline world. | |||
We also need for privacy as a right to be embedded in the constitutions of the world's governments — and for that right to extend beyond how and why personal data and metadata (data about data) is collected, shared, and used by others. For that there may be no better place to start than Brandeis and Warren's [https://en.wikipedia.org/wiki/The_Right_to_Privacy_(article) ''The Right to Privacy''], which the authors summarize as "the right to be let alone." That document has [https://scholarship.law.pitt.edu/cgi/viewcontent.cgi?article=1062&context=fac_articles done more than any other] to frame both lawmaking and legal decision making since it was published in 1890. | |||
Meanwhile, making the ''status quo'' less bad risks making it worse. Hence this manifesto. | |||
===Manifesto=== | ===Manifesto=== | ||
#Privacy is personal. Technically speaking, it's a ''root'' right. | #The digital world, connected by the Internet, is inhabited by human beings and not just by machines, governments and corporate entities. All of us have a right to be there, and to enjoy the same freedoms and forms of respect that we do in the physical world. | ||
#Privacy is also social and | #Privacy is personal. Technically speaking, it's a ''root'' right. If you have a right to exist, you have a right to privacy. | ||
#We each experience privacy as a state: | #Privacy is also social and political. [https://www.nytimes.com/2020/01/24/opinion/sunday/surveillance-capitalism.html Shoshana Zuboff in ''The New York Times'']: "The lesson is that ''privacy is public'' — it is a collective good that is logically and morally inseparable from the values of human autonomy and self-determination upon which privacy depends and without which a democratic society is unimaginable." But that doesn't mean privacy is ''not'' personal. | ||
# | #We each experience privacy as a state of possession: something as personal as our body's organs, though far more vulnerable. | ||
#To control one's privacy is to selectively conceal, disclose or project information about one's self outward into the world — and to obtain respect from others for that. | #To experience privacy is to also experience personal sovereignty, independence and agency. | ||
#Privacy is no less a right than those to life, liberty and the pursuit of happiness. (The right to privacy is also recognized in Aricle 12 of the United Nations' [http://www.un.org/en/universal-declaration-human-rights/ Universal Declaration of Human Rights].) | #To control one's privacy is to selectively conceal, disclose, or project information about one's self outward into the world — and to obtain respect from others for that. | ||
#Our agency —the ability to act with effect in the | #Privacy is no less a right than those to life, liberty, and the pursuit of happiness. (The right to privacy is also recognized in Aricle 12 of the United Nations' [http://www.un.org/en/universal-declaration-human-rights/ Universal Declaration of Human Rights].) | ||
#Privacy starts with what others don't know about us. To strangers we present first as human, but also as anonymous. (To be anonymous is to be nameless, not to be invisible.) | #Our agency —the ability to act with effect in the world — depends on maintaining and managing our privacy. (We operate at full agency, for example, when we tie our shoes, ride a bike, write something down, drive a car, or participate in a conversation.) | ||
#Privacy starts with what others don't know about us. To strangers, we present first as human, but also as anonymous. (To be anonymous is to be nameless, not to be invisible.) | |||
#Through anonymity, personal privacy is a public grace. It's why we don't wear a name badge when we walk down a city street. It helps all of us to ''not'' to know private information about all the other people we each see or meet. | #Through anonymity, personal privacy is a public grace. It's why we don't wear a name badge when we walk down a city street. It helps all of us to ''not'' to know private information about all the other people we each see or meet. | ||
#Not knowing much about most other people is an economic and political grace as well as a social one. | #Not knowing much about most other people is an economic and political grace as well as a social one. | ||
#Getting to know another person is to experience selective control of personal privacy by both parties. Friendship and intimacy are earned through selective and trusting personal disclosures of personal information that is essentially private. | #Getting to know another person is to experience selective control of personal privacy by both parties. Friendship and intimacy are earned through selective and trusting personal disclosures of personal information that is essentially private. | ||
#All social, economic and political graces arising from personal privacy require personal independence, sovereignty and agency over what others can learn about us, even though our control is far short of absolute. | #All social, economic, and political graces arising from personal privacy require personal independence, sovereignty and agency over what others can learn about us, even though our control is far short of absolute. | ||
#Having control over what we selectively disclose to others, in ways we can generally trust, allows social norms to grow around how personal privacy works. Though these norms differ by culture, they exist in all cultures. | #Having control over what we selectively disclose to others, in ways we can generally trust, allows social norms to grow around how personal privacy works. Though these norms differ by culture, they exist in all cultures. | ||
#Privacy ([https://www.oxfordlearnersdictionaries.com/definition/english/privacy says Oxford]) is "the state of being alone and not watched or interrupted by other people." This is possible in the natural world, where being alone and uninterrupted is at least a possibility for most people. However— | |||
#Like nature, the Internet came without privacy. | #Like nature, the Internet came without privacy. | ||
#The first privacy technologies we invented in the natural world were clothing and shelter. We did this when we first became human, dozens of millennia ago. | #The first privacy technologies we invented in the natural world were clothing and shelter. We did this when we first became human, dozens of millennia ago. | ||
Line 33: | Line 45: | ||
#It is now the norm — even in the presence of laws clearly forbidding it — for nearly every commercial website we visit to plant tracking beacons in our devices, so our lives can be examined and exploited by companies and governments that extract personal data and manipulate our lives for their purposes. This diminishes our agency and is an affront to our personal dignity. | #It is now the norm — even in the presence of laws clearly forbidding it — for nearly every commercial website we visit to plant tracking beacons in our devices, so our lives can be examined and exploited by companies and governments that extract personal data and manipulate our lives for their purposes. This diminishes our agency and is an affront to our personal dignity. | ||
#These problems must be solved with ''personal privacy tech'' and standards to support that tech. Privacy tech will create private spaces for ourselves online, and ways for signaling to others what is acceptable, and what is not, in respect to our privacy. | #These problems must be solved with ''personal privacy tech'' and standards to support that tech. Privacy tech will create private spaces for ourselves online, and ways for signaling to others what is acceptable, and what is not, in respect to our privacy. | ||
#Our privacy tech should support, among other activities, the ability to proffer terms to which others (be they individuals or organizations) can agree. This is simple [https://en.wikipedia.org/wiki/Freedom_of_contract freedom of contract], which has operated in human society offline for thousands of years, but is not yet normative in the online world. | |||
#Government regulations and corporate privacy policies at most can encourage personal privacy tech. They can't invent or provide it. | #Government regulations and corporate privacy policies at most can encourage personal privacy tech. They can't invent or provide it. | ||
#Standards are essential for personal privacy tech to operate at scale in the online world. This shouldn't be hard. The common protocols of the Net and the Web (TCP/IP, HTTP/S, IRC, FTP, et. al.) give us a good base to build on, and good models for how scale can work for each of us. | #Standards are essential for personal privacy tech to operate at scale in the online world. This shouldn't be hard. The common protocols of the Net and the Web (TCP/IP, HTTP/S, IRC, FTP, et. al.) give us a good base to build on, and good models for how scale can work for each of us. | ||
#New laws and regulations for protecting personal privacy online (e.g. the [https://eugdpr.org/ GDPR] and [https://en.wikipedia.org/wiki/EPrivacy_Regulation_%28European_Union%29 ePrivacy] in the E.U. and [https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201720180AB375 A.B. | #New laws and regulations for protecting personal privacy online (e.g. the [https://eugdpr.org/ GDPR] and [https://en.wikipedia.org/wiki/EPrivacy_Regulation_%28European_Union%29 ePrivacy] in the E.U. and [https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201720180AB375 A.B. 375—CCPA—]in California) are being instituted in the absence of the personal privacy tech and norms we should have had first. Thus they put the regulatory cart in front of the technology horse. Worse, they all tend to rely on [https://www.google.com/search?q=%22notice+and+consent%22 "notice and consent,"] a norm by which a site or service is always the first party, issuing a "notice" to which the individual must "consent." This requires that individuals must always be second parties to all agreements involving consent. Besides locking individuals into countless subordinate roles, each controlled by others, this offends the peer-to-peer nature of the Internet itself. | ||
#Worse, because these laws and regulations are being developed in the absence of personal privacy tech and norms, they assume that human beings are mere "data subjects" with no personal agency beyond "choices" provided by others. | #Worse, because these laws and regulations are being developed in the absence of personal privacy tech and norms, they assume that human beings are mere "data subjects" (GDPR) or "consumers" (CCPA) with no personal agency beyond "choices" provided by others. | ||
#At this early stage in the evolution of life online, the only record we have of our consent to notices online are cookies given by sites and their third parties to our browsers. These are assembled within our browsers into long DNA chains of personal information presented to every subsequent site we visit. While a consent cookie's main privacy purpose for a given site is to say whether or not the individual has consented to the site's notice, far more information from other cookies in that DNA chain is also being leaked to parties unknown by the individual (and in many cases also the site). This happens everywhere we go online, as a matter of course. As long as this system remains the status quo, we have no true personal privacy on the Web. | #At this early stage in the evolution of life online, the only record we have of our consent to notices online are cookies given by sites and their third parties to our browsers. These are assembled within our browsers into long DNA chains of personal information presented to every subsequent site we visit. While a consent cookie's main privacy purpose for a given site is to say whether or not the individual has consented to the site's notice, far more information from other cookies in that DNA chain is also being leaked to parties unknown by the individual (and in many cases also the site). This happens everywhere we go online, as a matter of course. As long as this system remains the status quo, we have no true personal privacy on the Web. | ||
#Even if today's online privacy laws are enforced, none will give us privacy any more than laws against indecent exposure will give us clothing. We need privacy tech of our own. | #Even if today's online privacy laws are enforced, none will give us privacy any more than laws against indecent exposure will give us clothing. We need privacy tech of our own. | ||
#Technologies and services that address corporate demand for claiming "GDPR compliance" (mostly by obtaining "consents" through "this site uses cookies" notices) serve only to mask the site's intent to continue tracking people for marketing purposes. As of | #Technologies and services that address corporate demand for claiming "GDPR compliance" (mostly by obtaining "consents" through "this site uses cookies" notices) serve only to mask the site's intent to continue tracking people for marketing purposes. As of this writing (December 2021), applied "notice and consent" at most commercial websites facilitate obedience to the letter the GDPR while violating its spirit. | ||
#The good guidance of [https://en.wikipedia.org/wiki/Privacy_by_design "Privacy by Design"] for organizations needs also to apply to privacy tech for individuals. | #The good guidance of [https://en.wikipedia.org/wiki/Privacy_by_design "Privacy by Design"] for organizations needs also to apply to privacy tech for individuals. | ||
#The [https://en.wikipedia.org/wiki/FTC_fair_information_practice The United States Federal Trade Commission's fair information practice principles (FIPPs)], which date back to this list of rights from a [https://aspe.hhs.gov/report/records-computers-and-rights-citizens July 1973 U.S. Government report] also provides good guidance, as does [https://epic.org/privacy/consumer/code_fair_info.html EPIC.org]: ''• There must be no personal data record-keeping systems whose very existence is secret. • There must be a way for a person to find out what information about the person is in a record and how it is used. • There must be a way for a person to prevent information about the person that was obtained for one purpose from being used or made available for other purposes without the person's consent. •There must be a way for a person to correct or amend a record of identifiable information about the person. • Any organization creating, maintaining, using, or disseminating records of identifiable personal data must assure the reliability of the data for their intended use and must take precautions to prevent | #The [https://en.wikipedia.org/wiki/FTC_fair_information_practice The United States Federal Trade Commission's fair information practice principles (FIPPs)], which date back to this list of rights from a [https://aspe.hhs.gov/report/records-computers-and-rights-citizens July 1973 U.S. Government report] also provides good guidance, as does [https://epic.org/privacy/consumer/code_fair_info.html EPIC.org]: ''• There must be no personal data record-keeping systems whose very existence is secret. • There must be a way for a person to find out what information about the person is in a record and how it is used. • There must be a way for a person to prevent information about the person that was obtained for one purpose from being used or made available for other purposes without the person's consent. •There must be a way for a person to correct or amend a record of identifiable information about the person. • Any organization creating, maintaining, using, or disseminating records of identifiable personal data must assure the reliability of the data for their intended use and must take precautions to prevent misuse of the data.'' To those we add, | ||
#There must be ways for individuals to secure and exercise all those rights, using standard and well-understood tools of their own. | #There must be ways for individuals to secure and exercise all those rights, using standard and well-understood tools of their own. | ||
#We do have some early forms of tech to work with, such as crypto, onion routing, PKI and VPNs. But those are too few, and (with the exception of VPNs) too hard for non-experts to use. None yet give us what clothing and shelter afford in the natural world: lots of ways, easily available to everyone, for concealing and exposing private spaces selectively, signaling how we want those private spaces respected, making clear what information we would like others to keep secret or to reveal (and to whom) — and for keeping track of agreements about all those things. | #We do have some early forms of tech to work with, such as crypto, onion routing, PKI, and VPNs. But those are too few, and (with the exception of VPNs) too hard for non-experts to use. None yet give us what clothing and shelter afford in the natural world: lots of ways, easily available to everyone, for concealing and exposing private spaces selectively, signaling how we want those private spaces respected, making clear what information we would like others to keep secret or to reveal (and to whom) — and for keeping track of agreements about all those things. | ||
#The challenge then, for all tech developers, is to create personal privacy technologies | #The challenge then, for all tech developers, is to create personal privacy technologies and means for establishing and enforcing norms based on those technologies. | ||
#Those technologies need to be, at their base, free and open. | #Those technologies need to be, at their base, free and open. | ||
#When Archimedes said, "Give me a place to stand, and I can move the earth," he was talking about a place that did not exist in his time | #When Archimedes said, "Give me a place to stand, and I can move the earth," he was talking about a place that did not exist in his time but does in ours. That place is the Internet. TCP/IP, the free and open protocol at the Internet's base, is a fulcrum sturdy enough to [https://medium.com/@dsearls/how-new-tools-for-people-are-more-leveraged-than-more-tools-for-business-93765ec14cec make everyone an Archimedes], given the right levers. Our mission is to provide those levers. | ||
#None of those levers can be imagined without standing on the side of the individual, and without personal privacy as the first consideration. | #None of those levers can be imagined without standing on the side of the individual, and without personal privacy as the first consideration. | ||
===Calls to Action=== | ===Calls to Action=== | ||
As with all free and open source code, every word in this manifesto is provisional and subject to improvement. | As with all free and open source code, every word in this manifesto is provisional and subject to improvement. It is also dedicated to the public domain through Creative Commons licence [https://wiki.creativecommons.org/wiki/CC0 CC0]. Members of ProjectVRM with editing powers can also work on this copy of the manifesto, in this wiki, or by contributing through [https://cyber.harvard.edu/lists/info/projectvrm the ProjectVRM mailing list]. | ||
Note: [https://medium.com/@dsearls/a-privacy-manifesto-e475d4d8792a a version of this, current on 5 July 2019, appeared in ''Medium'']. | |||
— Doc Searls | — Doc Searls |
Latest revision as of 09:56, 23 September 2024
Preamble
The purpose of this manifesto is to encourage and guide development of tools that enhance and extend people's ability to protect and project their privacy in the online world. We have used such tools in the natural world for as long as we've had the privacy technologies called clothing and shelter, and social norms for signaling and respecting personal intentions around privacy. We are not close to having those yet the online world, which most of us have inhabited for less than two decades, and will likely be with us for centuries—if not millennia—to come.
In the absence of those technologies and norms, it is easy for those with power to violate our personal privacy, and to rationalize those violations as well. In fact it is so easy to do both that violating privacy has become worse than rampant: it is normalized by a lucrative and easily rationalized business model that Shoshana Zuboff calls surveillance capitalism and a purpose that Brett Frischmann and Evan Selinger call "re-engineering humanity." In some countries, the extent of government surveillance comports with Orwell's worst fears. In other countries we are right to fear the same.
In these early days, when personal privacy tech and norms are still at an embryonic stage, there are two pro forma ways for potential violators to claim they respect personal privacy. One is with a company privacy policy, which became common starting in the 1970s. While these are required of companies doing business in our digital age, they are easy for a company to ignore or to change at any time and without notice. The other is with a one-sided statement of terms, proffered most commonly by "notice and consent" banners on websites and detailed in thousands of words in legalese. These terms are what Friedrich Kessler, in a landmark in 1943 paper called "contracts of adhesion." In the digital world, these kinds of contracts are typically proffered in take-it-or-leave-it ways, with no means for an individual to record their agreement or to audit the company's compliance to it.
These policies, terms, and conditions are also as numerous and varied as the websites we visit and the apps and services we use. To read and consider all the policies and terms we encounter online would be more than a full-time job for all who accept those terms as a matter of course, which is why we don't bother. (A 2012 Carnegie Mellon study says it would take 76 days per year just to read the privacy policies of the world's top 75 websites. Since terms tend to be at least as long as privacy policies, the actual time required to read both would be around double that.)
It is natural under these conditions for privacy advocates to look toward the government for new laws and regulations to relieve us from personal privacy violations by others. Necessary though it is (laws maintain civilization), there are two separate problems with looking for law alone to solve our privacy problems:
1. New laws risk putting the regulatory cart in front of the horse and reins of tech and norms. This is what we already have with the GDPR, which presumes maximum agency for corporate "data controllers" and "data processors" and little agency for the "natural persons" the regulation calls "data subjects." All privacy for the individual is by the grace of companies and their policies and terms, to which individuals must agree, separately, one at a time, for all of them. And, while the CCPA in California gives people the right to get back the data horses that have been taken from private barns, it doesn't support the development of ways for people to protect what's in those barns in the first place.
2. Absent constitutional protection of privacy as a right, existing law may be enough when there is little tech to lock our data barns. As Steve Wilson says in The last thing privacy needs is new laws, "existing privacy law can substantially deal with Big Data."
And none of this addresses the ability of governments everywhere covertly to harvest and process personal information as well.
The simple fact is that we need new tools — privacy tech, and standards supporting that tech — on our side. There is no other way to create privacy in the online world that begins to resemble what we have long enjoyed in the offline world.
We also need for privacy as a right to be embedded in the constitutions of the world's governments — and for that right to extend beyond how and why personal data and metadata (data about data) is collected, shared, and used by others. For that there may be no better place to start than Brandeis and Warren's The Right to Privacy, which the authors summarize as "the right to be let alone." That document has done more than any other to frame both lawmaking and legal decision making since it was published in 1890.
Meanwhile, making the status quo less bad risks making it worse. Hence this manifesto.
Manifesto
- The digital world, connected by the Internet, is inhabited by human beings and not just by machines, governments and corporate entities. All of us have a right to be there, and to enjoy the same freedoms and forms of respect that we do in the physical world.
- Privacy is personal. Technically speaking, it's a root right. If you have a right to exist, you have a right to privacy.
- Privacy is also social and political. Shoshana Zuboff in The New York Times: "The lesson is that privacy is public — it is a collective good that is logically and morally inseparable from the values of human autonomy and self-determination upon which privacy depends and without which a democratic society is unimaginable." But that doesn't mean privacy is not personal.
- We each experience privacy as a state of possession: something as personal as our body's organs, though far more vulnerable.
- To experience privacy is to also experience personal sovereignty, independence and agency.
- To control one's privacy is to selectively conceal, disclose, or project information about one's self outward into the world — and to obtain respect from others for that.
- Privacy is no less a right than those to life, liberty, and the pursuit of happiness. (The right to privacy is also recognized in Aricle 12 of the United Nations' Universal Declaration of Human Rights.)
- Our agency —the ability to act with effect in the world — depends on maintaining and managing our privacy. (We operate at full agency, for example, when we tie our shoes, ride a bike, write something down, drive a car, or participate in a conversation.)
- Privacy starts with what others don't know about us. To strangers, we present first as human, but also as anonymous. (To be anonymous is to be nameless, not to be invisible.)
- Through anonymity, personal privacy is a public grace. It's why we don't wear a name badge when we walk down a city street. It helps all of us to not to know private information about all the other people we each see or meet.
- Not knowing much about most other people is an economic and political grace as well as a social one.
- Getting to know another person is to experience selective control of personal privacy by both parties. Friendship and intimacy are earned through selective and trusting personal disclosures of personal information that is essentially private.
- All social, economic, and political graces arising from personal privacy require personal independence, sovereignty and agency over what others can learn about us, even though our control is far short of absolute.
- Having control over what we selectively disclose to others, in ways we can generally trust, allows social norms to grow around how personal privacy works. Though these norms differ by culture, they exist in all cultures.
- Privacy (says Oxford) is "the state of being alone and not watched or interrupted by other people." This is possible in the natural world, where being alone and uninterrupted is at least a possibility for most people. However—
- Like nature, the Internet came without privacy.
- The first privacy technologies we invented in the natural world were clothing and shelter. We did this when we first became human, dozens of millennia ago.
- The Internet we have today is barely more than two decades old, and we still lack the online equivalents of clothing and shelter. This is why most of us are still as naked and exposed on the Internet as we were in Eden. It's also why it has been easy for businesses and governments to exploit our exposed selves.
- It is now the norm — even in the presence of laws clearly forbidding it — for nearly every commercial website we visit to plant tracking beacons in our devices, so our lives can be examined and exploited by companies and governments that extract personal data and manipulate our lives for their purposes. This diminishes our agency and is an affront to our personal dignity.
- These problems must be solved with personal privacy tech and standards to support that tech. Privacy tech will create private spaces for ourselves online, and ways for signaling to others what is acceptable, and what is not, in respect to our privacy.
- Our privacy tech should support, among other activities, the ability to proffer terms to which others (be they individuals or organizations) can agree. This is simple freedom of contract, which has operated in human society offline for thousands of years, but is not yet normative in the online world.
- Government regulations and corporate privacy policies at most can encourage personal privacy tech. They can't invent or provide it.
- Standards are essential for personal privacy tech to operate at scale in the online world. This shouldn't be hard. The common protocols of the Net and the Web (TCP/IP, HTTP/S, IRC, FTP, et. al.) give us a good base to build on, and good models for how scale can work for each of us.
- New laws and regulations for protecting personal privacy online (e.g. the GDPR and ePrivacy in the E.U. and A.B. 375—CCPA—in California) are being instituted in the absence of the personal privacy tech and norms we should have had first. Thus they put the regulatory cart in front of the technology horse. Worse, they all tend to rely on "notice and consent," a norm by which a site or service is always the first party, issuing a "notice" to which the individual must "consent." This requires that individuals must always be second parties to all agreements involving consent. Besides locking individuals into countless subordinate roles, each controlled by others, this offends the peer-to-peer nature of the Internet itself.
- Worse, because these laws and regulations are being developed in the absence of personal privacy tech and norms, they assume that human beings are mere "data subjects" (GDPR) or "consumers" (CCPA) with no personal agency beyond "choices" provided by others.
- At this early stage in the evolution of life online, the only record we have of our consent to notices online are cookies given by sites and their third parties to our browsers. These are assembled within our browsers into long DNA chains of personal information presented to every subsequent site we visit. While a consent cookie's main privacy purpose for a given site is to say whether or not the individual has consented to the site's notice, far more information from other cookies in that DNA chain is also being leaked to parties unknown by the individual (and in many cases also the site). This happens everywhere we go online, as a matter of course. As long as this system remains the status quo, we have no true personal privacy on the Web.
- Even if today's online privacy laws are enforced, none will give us privacy any more than laws against indecent exposure will give us clothing. We need privacy tech of our own.
- Technologies and services that address corporate demand for claiming "GDPR compliance" (mostly by obtaining "consents" through "this site uses cookies" notices) serve only to mask the site's intent to continue tracking people for marketing purposes. As of this writing (December 2021), applied "notice and consent" at most commercial websites facilitate obedience to the letter the GDPR while violating its spirit.
- The good guidance of "Privacy by Design" for organizations needs also to apply to privacy tech for individuals.
- The The United States Federal Trade Commission's fair information practice principles (FIPPs), which date back to this list of rights from a July 1973 U.S. Government report also provides good guidance, as does EPIC.org: • There must be no personal data record-keeping systems whose very existence is secret. • There must be a way for a person to find out what information about the person is in a record and how it is used. • There must be a way for a person to prevent information about the person that was obtained for one purpose from being used or made available for other purposes without the person's consent. •There must be a way for a person to correct or amend a record of identifiable information about the person. • Any organization creating, maintaining, using, or disseminating records of identifiable personal data must assure the reliability of the data for their intended use and must take precautions to prevent misuse of the data. To those we add,
- There must be ways for individuals to secure and exercise all those rights, using standard and well-understood tools of their own.
- We do have some early forms of tech to work with, such as crypto, onion routing, PKI, and VPNs. But those are too few, and (with the exception of VPNs) too hard for non-experts to use. None yet give us what clothing and shelter afford in the natural world: lots of ways, easily available to everyone, for concealing and exposing private spaces selectively, signaling how we want those private spaces respected, making clear what information we would like others to keep secret or to reveal (and to whom) — and for keeping track of agreements about all those things.
- The challenge then, for all tech developers, is to create personal privacy technologies and means for establishing and enforcing norms based on those technologies.
- Those technologies need to be, at their base, free and open.
- When Archimedes said, "Give me a place to stand, and I can move the earth," he was talking about a place that did not exist in his time but does in ours. That place is the Internet. TCP/IP, the free and open protocol at the Internet's base, is a fulcrum sturdy enough to make everyone an Archimedes, given the right levers. Our mission is to provide those levers.
- None of those levers can be imagined without standing on the side of the individual, and without personal privacy as the first consideration.
Calls to Action
As with all free and open source code, every word in this manifesto is provisional and subject to improvement. It is also dedicated to the public domain through Creative Commons licence CC0. Members of ProjectVRM with editing powers can also work on this copy of the manifesto, in this wiki, or by contributing through the ProjectVRM mailing list.
Note: a version of this, current on 5 July 2019, appeared in Medium.
— Doc Searls