
You are reading this as your data is harvested. On average, your personal data is collected 271 times a day. I know who you are. I know what you are doing. I will look for you. I will find you.
Most of us think surveillance involves CCTV cameras, governments, police databases and, perhaps, the slightly creepy advert that follows us around the internet after we looked at a pair of shoes. We think of surveillance as something that happens to us, usually because somebody has decided to watch us. George Orwell gave us the ultimate version in 1984: Big Brother, the telescreen and a state that sees everything.
Except Big Brother has arrived in a rather different form.
Surveillance today is getting out of bed, checking your phone, making breakfast, driving to work, tapping a card, sending a message, going to the gym, collecting the children from school, watching television and going to sleep. It is not something separate from everyday life. It is increasingly built into everyday life.
That is the disturbing conclusion I take from a new 134-page white paper from the Web3 Foundation, Everyday Surveillance: What One Ordinary Day May Reveal About You. The researchers construct six model households in Britain and America and follow them through an ordinary 24 hours, asking a simple question: how much information could the systems surrounding these people collect, generate or infer?
The answer is an extraordinary amount.
Take Sam. He is 34, lives in Manchester, rents a flat, works in an office, owns a car, an iPhone and Apple Watch, watches a Samsung smart TV, uses Alexa, banks online, orders food, uses social media and has a smart meter. In other words, Sam is not some hyperconnected technology obsessive. He is just a bloke living in Manchester.
During one modelled day, Sam is connected with 68 organisations and around 271 processing events. His devices potentially produce more than 1,100 biometric and physiological readings, while the modelling produces around 21,600 Automatic Content Recognition screen captures from his television and estimates another 60 to 190 camera captures as he moves through the physical world.
Read that again. You sit on the sofa watching television and think you are watching the television. The television may be watching you.
That is where this paper becomes interesting because the issue is not simply the amount of information being generated. It is what happens when all those fragments start describing you. Your heart rate. Your sleep. Your medications. Your reproductive health. Your finances. Your browsing. Your photographs. Your contacts. Where you drive. What your children do at school. Whether somebody is at home. What political or religious content you consume.
Then comes the really interesting part: inference.
Systems can potentially use the information they have to infer things you never explicitly told them, including possible financial stress, health concerns, political leanings, sexuality, personality, interests and likely future behaviour.
That changes the debate completely because there are really three forms of information here. There is information you provide. There is information machines generate because you did something. Then there is information machines infer from everything else. That third category is where the world becomes fascinating, because your data shadow can potentially know things about you that you never knowingly disclosed.
A payment says where you bought lunch. Location says where you were. Your wearable says what your body was doing. Your television says what you watched. Your browsing suggests what interests you. Your social network says who you know. Individually, these things are almost meaningless. Joined together, they become a person. Increasingly, that person is not merely a historical record of what you did. It becomes a probabilistic prediction of what you will do next.
That is why the numbers buried deeper in the report are more interesting to me than the headline surveillance figures. The researchers examine 143 organisations. According to those organisations' own documentation, 83% describe using data for marketing, 80% describe combining data across different sources, 76% describe inference or profiling, 71% describe sharing with commercial partners and 66% state retention without a fixed period. At least 24% explicitly describe using user data to train or improve AI or machine-learning systems.
Think about the economics of that.
You use a service because you want something: a map, a payment, a television programme, a social network, a bank account or a school application. But the transaction does not necessarily finish when the service has been delivered. Across the paper's 1,280 primary uses, the researchers identify 4,283 additional potential documented uses, averaging 3.4 additional uses for each primary interaction.
The digital economy has therefore quietly changed the nature of exchange. You think the transaction is: I give you data so you can provide a service. The real transaction has become: I give you data for one purpose and that data becomes an input into an entirely different information economy.
And we agreed to this, didn't we? Of course we did. It was in the terms and conditions.
This is possibly my favourite finding in the whole report.
Across the six model households, the researchers identify 1,195 relevant document entries containing more than 5.38 million words. Depending upon the household, reading the privacy material governing one ordinary modelled day would take between 37 and 83 hours. For the Leeds family alone, there are 257 documents containing almost 1.19 million words, requiring around 83 hours to read.
Excellent.
Before taking the children to school, buying groceries and watching Netflix, please spend ten working days reviewing the contractual architecture of your existence. Then click: I agree.
This is why I have always found the idea of informed consent in the digital economy slightly absurd. Consent implies understanding. Understanding requires information. Information requires time. Yet the amount of legal documentation surrounding an ordinary digital existence has become so enormous that meaningful comprehension is practically impossible. We have created an economy based upon consent that almost nobody has the practical ability to understand.
Then there are the children, and this is where the paper becomes uncomfortable.
The model Leeds family is connected with 88 organisations, 25 of which have documentation indicating they may collect information relating to the children. The two children could generate around 100 school-camera captures in a day and 11,400 logged keystrokes during a school week, including keystrokes that may be retained even when the words were deleted and never sent.
The American model is different but hardly comforting.
Children can be monitored minute-by-minute on school devices, their location available through family-location services and their movements recorded by school cameras and number-plate systems. We worry about children spending too much time online. Perhaps we should also worry about how much time the online world spends watching our children.
There is another important finding because Europeans often comfort themselves with the idea that GDPR solved this. It didn't. It changed the rules governing data. It did not stop the creation of data.
The British models actually encounter more separately counted organisations than their American equivalents. The difference is architectural. Britain operates under a broad data-protection framework, while America combines federal sectoral rules with a patchwork of state legislation. The result is not a data-rich America versus a privacy-protected Britain. Both generate huge amounts of information, but the rules governing who can use it and what rights individuals have differ substantially. Regulation governs surveillance. It does not eliminate surveillance.
Now add AI.
This is where I think the paper becomes even more important. We spent the last twenty years creating enormous pools of behavioural data. Now we have created machines capable of analysing them. That combination fundamentally changes the value of the information.
Yesterday's database recorded that Chris bought something, travelled somewhere or watched something. Tomorrow's AI asks why Chris did those things, what they reveal about him and what he is likely to do next. That moves us from the internet of data collection towards an internet of behavioural prediction, and that is a very different internet.
The Web3 Foundation, unsurprisingly, believes the answer lies partly in changing the architecture. Its proposals are actually quite sensible: disclose less information by default, make fewer permanent copies, make permissions narrow and revocable, allow people to hold reusable digital proofs and, critically, enable systems to verify facts without demanding all of the underlying information.
That last point matters. A bank might need to know that your income exceeds a particular threshold. It does not necessarily need years of transaction history to establish that fact. A website might need to know that you are over eighteen. It does not necessarily need your date of birth, passport and permanent identity. The internet we built works largely by copying information. The internet we should build works by proving information. That sounds like a small distinction, but it is enormous because the great mistake of the digital age has been to assume that convenience requires disclosure.
It doesn't. What convenience requires is trust.
And that brings me back to banking. Banks have spent centuries acting as trusted intermediaries because money is ultimately a system of trust. The emerging digital economy needs the same thing for identity and data. We need mechanisms that allow people to prove who they are, what they are entitled to do and whether something about them is true without spraying their personal information across dozens of databases.
The Web3 Foundation is not arguing that every camera should disappear or every smart meter should be disconnected. Neither am I. These systems deliver real benefits. The paper explicitly acknowledges that cameras, healthcare systems, schools, connected devices and smart meters have legitimate purposes. The issue is the architecture we have created around them.
We designed the internet around collecting data because data was cheap to store, valuable to monetise and difficult to analyse at scale. AI removes that last constraint. Suddenly, everything we collected because perhaps it might be useful one day becomes useful, because machines can connect the fragments, find the patterns, infer the relationships and predict the behaviour.
Which brings us back to Orwell.
In 1984, Big Brother watches you through the telescreen. It is obvious, centralised and imposed by the state. Orwell's citizen knows that he is being watched.
Our version is cleverer.
Big Brother has come true, but there is no single Big Brother. There are potentially dozens of them during an ordinary day, scattered across televisions, watches, phones, cars, banks, schools, shops, cameras, apps and artificial intelligence systems. Each sees a fragment and, increasingly, technology allows those fragments to become a picture.
Orwell imagined that the great surveillance machine would be forced upon us. Instead, we bought the cameras ourselves, put them in our homes, strapped the sensors to our wrists, carried the tracking devices in our pockets, connected our cars, televisions, children and bank accounts to the network, clicked I agree and called it convenience.
Big Brother is watching you.
I know who you are. I know what you are doing. I will look for you. I will find you.
The twist Orwell never imagined is that we paid for Big Brother ourselves.
You can download the full report here: https://web3.foundation/media/documents/insights/everyday-surveillance-what-one-ordinary-day-may-reveal-about-you-w3f-wp2-.pdf
Chris M Skinner
Chris Skinner is best known as an independent commentator on the financial markets through his blog, TheFinanser.com, as author of the bestselling book Digital Bank, and Chair of the European networking forum the Financial Services Club. He has been voted one of the most influential people in banking by The Financial Brand (as well as one of the best blogs), a FinTech Titan (Next Bank), one of the Fintech Leaders you need to follow (City AM, Deluxe and Jax Finance), as well as one of the Top 40 most influential people in financial technology by the Wall Street Journal's Financial News. To learn more click here...