sovereignty

Who commands the data: the power that never needs to read you

Investigation · Digital power · Data access

Follow a message from the moment someone writes it to the price you will be shown three weeks later. Along that route you meet every position from which power over people is exercised today, and none of them needs to know your name.

▶ Listen to this article

On 15 January 2026 ChatGPT stopped working inside WhatsApp. Three months earlier Meta had rewritten the terms of its Business API, barring general-purpose conversational assistants from using that infrastructure whenever artificial intelligence is the primary service offered to the user. Copilot, Perplexity, Luzia and Poke left alongside ChatGPT, and a single assistant remained on the platform.

Told as a fight between giants, the episode loses its interesting part. A private company had decided who could reach three billion people; a public authority ordered it to reverse that decision; neither asked anything of those three billion people. To locate where power over data actually sits, it helps to stop watching the contenders and follow an ordinary object instead: a message somebody is about to send you.

data soveregnity Third-party data access: a messaging app icon treated as a gate controlled by a single operator
The gate: whoever runs the application decides which software gets to face the channel

Third-party data access: who decides who gets inside a conversation?

Before it is even written, that message depends on a decision taken elsewhere. Whoever runs the application establishes which software may face the channel, and that choice weighs more than any setting you can change in the privacy menu.

Opened in December 2025, the European Commission’s antitrust investigation moved quickly. On 9 February 2026 a statement of objections reached Meta, with the preliminary finding that excluding competitors amounted to an abuse of dominance. On 4 March access reopened behind a fee. In April the Commission replied with supplementary objections, holding that fee equivalent to the ban. In June it imposed interim measures ordering free restoration on the terms in force before 15 October 2025, within five working days. The file carries the number AT.41034 and was extended to Italy after the national competition authority intervened.

Meta defends the closure by arguing that the Business API exists to let companies serve their customers rather than to distribute general-purpose chatbots. Security enters the argument too, since every admitted provider receives verified phone numbers, interaction histories and a direct relationship with the user inside an environment the company says it cannot inspect. Reversing the frame, the Commission describes a refusal to supply access to infrastructure developed for third parties and previously open to them, inside a market forming right now where a position gained today becomes hard to contest tomorrow. Teresa Ribera tied the urgency to the speed of that market.

The same app, pushed the opposite way

While one proceeding forces it to reopen a channel, a regulation forces it to open another. Article 7 of the Digital Markets Act obliges gatekeepers to make basic messaging functions interoperable on a set schedule: messages and files between two users, then group chats, finally voice and video calls. BirdyChat, aimed at work contexts, and Haiket, built around voice messaging, arrived first. Optional and reversible, activation requires partners to adopt end-to-end encryption compatible with WhatsApp’s own.

Critics of that choice note that the protocol guards content in transit and says nothing about what happens at the ends of a conversation, where messages sit in the clear and every provider applies its own retention policy. Supporters answer that the alternative means leaving hundreds of millions of people inside a closed enclosure, and that interoperability remains the only lever capable of letting smaller, stricter services exist. Weighing on all of it is Meta’s infrastructural position in the data ecosystem, more than any technical argument.

The third front, the one about content

A different match has been running in Brussels for four years, over whether messages can be analysed before anyone receives them. Expired on 3 April 2026, the temporary derogation to the ePrivacy regulation had allowed voluntary scanning of unencrypted communications: Parliament rejected its extension on 26 March by 311 votes against, 228 in favour and 92 abstentions. Restarting the mechanism through a written procedure on 2 July, the Council pushed it back, and on 9 July the parliamentary motion to reject that position gathered 314 votes, short of the absolute majority needed to block it.

Still in trilogue after five rounds without agreement sits the permanent text, renamed Chat Control by public debate. In its November 2025 position the Council dropped mandatory detection orders on encrypted communications, and the open points still concern automated scanning of private messages.

The common denominator

A competition authority forcing openness, a regulation forcing interoperability, a regulation debating scanning. Three legal instruments, three opposite outcomes, one contested quantity: the content of conversations and who may reach it.

Content, then, absorbs the whole visible conflict. The message you are about to receive crosses that battlefield protected by an encryption none of the three proceedings has dented, lands on your phone, and at that point something happens that none of the three matches addresses.

The message reaches your phone, and somebody else reads it

Decrypted on screen, the text becomes readable again. Whoever receives it can do as they please, and increasingly what they please is to ask an assistant to summarise it or reply on their behalf. That gesture moves the content off the device for a precise technical reason.

A previous-generation voice assistant ran almost everything locally. Setting an alarm or calling a contact means working on closed vocabularies and short strings, which a mobile processor handles without leaving the phone. Summarising a group thread with two hundred unread messages, reconstructing the sense of a text full of typos, drafting a reply: these operate at a different order of magnitude, and demand computing power the device does not have. A server is needed, and the text has to get there.

Intermediate perimeters soften the problem. Apple processes locally what it can and moves the rest to dedicated infrastructure. Meta announced Private Processing in April 2025, built on trusted execution environments, encrypted routing and anonymous requests, with content processed and then deleted without any link to the sender’s identity, and with the summary feature disabled in conversations protected by Advanced Chat Privacy. These remain architectural guarantees, verifiable by whoever designs the system and opaque to whoever sits inside it, and they cover the application’s integrated feature. Growing instead is the share of processing that runs through general-purpose assistants a user connects to their own accounts, where no such perimeter exists, and that is the configuration the role of language models as cognitive mediators is making ordinary.

Where end-to-end encryption breaks

Guarding the route is exactly what end-to-end encryption does, and acting on what follows is exactly what it cannot do. Meredith Whittaker, president of the Signal Foundation, brought the question to SXSW in March 2025 with the image of a brain in a jar: to book a concert, tell friends and add the appointment, an agent has to drive the browser and reach payment data, calendar and messaging, with permissions close to system administration and over content almost always in the clear. At the United Nations AI for Good summit she added the part concerning Signal: an application guarantees confidentiality at its own layer, and loses that capacity once an external process with higher permissions reads what the application has just decrypted.

From there opens a risk the encryption debate never had to face. An agent treats as data any instructions somebody hid inside an incoming message or a linked page, so prompt injection turns received content into an executed command, and the entry point is the inbox the user delegated.

Where an encrypted message ends up
LayerWho reaches the contentAvailable guarantee
TransportNobody beyond the two devicesEnd-to-end encryption
DeviceThe app and every process the user authorisedOperating system permissions
Built-in featureIsolated environment of the app providerDeclared architecture, not inspectable by the sender
External agentModel provider and every intermediary in the chainContract terms signed by the recipient alone
TrainingPotentially anyone querying the modelDefault settings of the service

Whoever chose the encrypted app is not the one deciding

Here the person who wrote the message returns. Choosing an encrypted application, she had decided something about her own privacy, relying on a guarantee the industry sold her as absolute, and that decision stops at the threshold of your device. Confidences, medical results, bank details and family matters travel to a company she never contracted with, through a choice she did not make and is almost never told about.

Less automatic than it looks, though, is the legal reading. Article 2(2)(c) of the GDPR excludes purely personal or household activity from the regulation’s scope, and the Court of Justice has read that derogation narrowly since the Ryneš judgment without emptying it. Whoever uses an assistant on their own private correspondence generally stays covered, and is not the party an authority would call to account.

The gap

Responsibility shifts to the model provider, which processes the personal data of a person it has no relationship with, on the instruction of a user holding no standing to consent on that person’s behalf. None of the legal bases listed in Article 6 covers that position.

Resembling a control the counterpart can exercise is only Advanced Chat Privacy, which disables artificial intelligence features inside a conversation and can be switched on by anyone taking part. It works by exclusion, applies to one application, and assumes a person knows it exists before writing something they would rather not hand to a machine.

From text to attributes

You read an email and after a few days you recall its general sense. An agent with persistent memory instead correlates this morning’s message with one written eight months ago, and keeps available for future querying what a human correspondent would have forgotten. On that basis come inferences no content declares: the tone of a reply, the hour it was written, a length that shortens, a typo rate that climbs under pressure. Features of the text, to a language model, from which to derive estimates about emotional state, health conditions, financial deadlines and political leanings, which is why digital twins built to model behaviour before it happens exist at all.

There remains the most discussed and most misunderstood scenario, where a third party’s words, having entered a training set, resurface in an answer given to a stranger. The European Data Protection Board addressed it in Opinion 28/2024 of 17 December 2024, holding that a model trained on personal data is not automatically anonymous and setting a high threshold: it must be shown that the likelihood of extracting such data, directly or through queries, is negligible for every single data subject, with documented controls against exfiltration, regurgitation and membership inference. In academic settings, extraction of portions of training data has succeeded on open, semi-open and closed models. Enterprise plans normally exclude reuse for training by default and consumer services almost always offer an opt-out, so the risk concentrates where nobody touches the settings.

There the do-it-yourself variant piles on, now trivial to assemble: a mailbox wired through an API to an automation platform, which queries a model provider, perhaps through a further intermediary handling orchestration. Each hop applies its own rules on retention, activity logs and reuse, with defaults that diverge substantially between professional and consumer tiers. One misconfiguration suffices for corporate correspondence to pass through parties nobody ever catalogued.

That message, whatever happens next, has stopped being a message. It has become a set of attributes: an intention, a date, a mood, a price sensitivity. Attributes of that kind have been, for at least a decade, the raw material of an industry that never needed to read a conversation to obtain them.

The debate is about reading. The chain that identifies people has never read anything

A man identified without anyone reading a line

In 2018 a company in Ashburn, Virginia bought location data from suppliers who had gathered it through smartphone applications. Among the billions of trajectories in its archives was one belonging to a priest. Filing its complaint against Gravy Analytics and its subsidiary Venntel in December 2024, the Federal Trade Commission does not give his name, and had no need to: it was enough to follow an identifier that appeared, evening after evening, in a dating app for men, then at a private residence, then at a parish. Enough to draw a virtual perimeter around those places, what the company internally called geofencing, and watch which device crossed both circles regularly enough.

He resigned, that priest, once his private life became public. Nobody along the chain that identified him knew his name, and nobody had ever opened one of his conversations. One company logged the event when he opened the app; technical infrastructure carried it to a remote server; a broker aggregated it with thousands of other events; a final company turned it into a segment ready for sale. Data crosses that chain the way a raw material crosses refineries and wholesalers before becoming the product somebody buys over a counter, never having seen the mine it came from.

Missing from all of this is the subject who watches. The power to identify that man sat in none of the companies involved, it sat in the sequence connecting them, and it materialised when somebody paid to query it.

Why an identifier alone says nothing

Take an isolated location signal and you hold almost no information, since a point on a map could be anyone at any moment of the day. Ferdinand de Saussure argued that a sign has no value in itself and acquires meaning only through its difference from the other signs in the system it belongs to. The same holds for a mobile advertising identifier: alone it identifies nobody, and once the same code appears beside a church at eight in the evening and beside a dating profile at eleven it starts to mean something, through the position it occupies inside a web of relations. Looking at one element at a time, as many privacy notices and much of the encryption debate do, amounts to reading a single letter of a word and concluding it says nothing.

The auction that lasts a tenth of a second

Those codes circulate because a market makes them circulate. Every time an advert appears on a site or an app, dozens of companies bid in real time for that space, in a process known as real-time bidding. Each bidder receives a request carrying information about the device about to see the advert, often including location and advertising identifier. Losing bidders are supposed to discard that data.

According to the FTC complaint against Mobilewalla, a company based in Georgia, between January 2018 and June 2020 it kept the data even when its bid was rejected, accumulating more than five hundred million advertising identifiers paired with precise locations. No system was breached: it was enough to stop deleting what the system sent anyway.

The scale of real-time bidding
FigureWhat it measuresSource
178 trnRTB data broadcasts per year across the US and EuropeICCL, 2022
747Times a day a person’s activity and location are exposed in the USICCL, 2022
376Times a day for a person in EuropeICCL, 2022
4,698Companies authorised by Google to receive RTB data on US usersICCL, 2022
500 mnAdvertising identifiers paired with precise locations held by MobilewallaFTC, 2024

Arriving in December 2024, the explicit ban on that practice also tells its converse: until then, harvesting data from lost auctions was not in itself unlawful. The first figure in the table explains why the question exceeds any commercial perimeter, since infrastructure capable of broadcasting information 178 trillion times a year reaches parties under no technical obligation to delete what they receive. Among the recipients of European data, the ICCL has documented, are companies based in Russia and China, and the flow carries information traceable to political leaders, judges and military personnel.

From database to graph

Seventeen billion signals a day from roughly a billion devices: that is how Gravy Analytics and Venntel described their collection. These are not seventeen billion people watched individually, they are points that become interesting once they repeat. A coordinate visited every Tuesday at the same hour resembles a habit, and a habit observed long enough becomes a saleable inference: a list of people who frequent a certain kind of place, offered as a product to other clients.

Identity resolution is what they call the next step. Companies such as LiveRamp merge emails, phone numbers, cookies, mobile device identifiers and smart TV identifiers into a single persistent key, able to represent both a person and the entire household they belong to. Structural anthropology, studying kinship systems, had shown that an individual’s identity inside a community is defined by the position they occupy in a web of recognised relations: whose child, which line of descent. The identity graph operates in a structurally equivalent way, with technical data replacing genealogy, and delivers commercially the breakdown of the individual into samples and databanks that Gilles Deleuze described in 1990 when writing about societies of control.

That stitching can carry near-total certainty, where a direct match exists such as the same email address used on two services. Or it stays an estimate, built by observing that a given device, a given IP address and a given hour recur together often enough to suggest, without proof, the same person. The old database reasoned in rows: a name, a city, a purchase. The graph replacing it reasons in relations, and that shift hides the hardest part of the phenomenon to explain.

The unified profile and the clean rooms

Once identity is settled, where to keep it remains. Customer Data Platforms, such as the one Adobe sells to enterprises, promise to unify into a single profile the data arriving from the website, the app, the physical store and customer service, so that the same client does not read as five different people depending on the channel.

Artificial intelligence does not replace this architecture, it lets it interpret what previously escaped it. A traditional system searched a text for keywords. A language model reads a message announcing a departure for Milan on Friday and voicing concern about the cost of the trip, and pulls out an intention, a date, a price sensitivity and an emotional register, turning a hastily typed sentence into attributes ready for a profile. This is the same operation that closed the previous chapter, differing only in provenance: there the attributes were born inside the conversation, here they are bought outside it. When two companies would rather not swap archives they turn to a data clean room, an environment that lets them compare their respective audiences without showing each other raw data, since a count, a match and a probability returned at the end of the computation suffice for a commercially decisive answer.

The phone and the browser as collection points

The device in your pocket gathers continuously: location, connections, open applications, timings, sometimes camera and microphone when authorised. The browser adds IP address, language, screen resolution, cookies and session identifiers, and Google’s technical documentation lists which of these an analytics tag collects automatically on every visit. In recent years a growing share of that traffic has stopped travelling straight to dozens of external destinations, passing first through a server controlled by whoever runs the site, in an architecture called server-side tagging.

That same infrastructure allows the user’s real IP address to be replaced with the server’s own before forwarding it to an external vendor. According to the same documentation it can equally be configured to do the opposite, preserving the person’s real identification while hiding from her the list of who will receive it. The code does not decide which way the scale tips. Whoever implements it does, through a choice the site’s visitor never sees, whatever the cookie banner says.

Holding all this construction up is a legal premise: that the data being processed is not personal data. Whoever controls that premise controls whether the whole architecture falls inside or outside the rules.

What counts as personal data, and who decides

In 2013 a group of researchers led by Yves-Alexandre de Montjoye published a study in Scientific Reports covering fifteen months of mobility data for one and a half million people. At the hourly and spatial resolution of mobile network antennas, four spatio-temporal points suffice to uniquely identify 95 per cent of individuals, even inside a dataset declared anonymous, and two points alone characterise more than half. Even coarsened data offers very little real protection, because uniqueness decays with resolution along a very slow power law.

Declaring that location is handled in pseudonymised form therefore describes a thinner barrier than the term suggests. It stopped being an academic matter on 19 November 2025, when the European Commission presented the Digital Omnibus package proposing a relative reading of what counts as personal data: information would be personal for a given party only where that party can reasonably identify the person with the means available to it. The package also introduces an explicit legitimate interest for training and operating artificial intelligence systems, and on that point digital rights organisations have documented the correspondence between the Commission’s text and requests the large platforms had made in preceding months. Defending the reform are the unpredictability of applying the current framework and the weight that uncertainty places on smaller operators.

Unresolved tension

The proposal hands each operator the assessment of whether the data it handles is identifying. The de Montjoye study shows four coordinates suffice to reconstruct an identity, and Opinion 28/2024 demands proof that extraction from a model is negligible for every data subject. The three criteria cannot hold together for the same data.

When the proof of consent becomes the data

A precedent already exists on this ground, concerning the strings the advertising industry uses to demonstrate that users consented to tracking. Those strings are themselves personal data, the Belgian data protection authority held, fining IAB Europe 250,000 euros; the Court of Justice of the European Union confirmed that reading on 7 March 2024. Brussels’ Market Court took it up on 14 May 2025, restating the personal nature of the TC String and IAB Europe’s joint controllership for its processing, while excluding joint controllership for the downstream advertising processing carried out by individual operators. On 7 January 2026 the same court annulled the parts of the Belgian decision imposing changes to the framework beyond that perimeter, sending the file back to the authority.

That path intertwines with the American action without anyone having planned it. The Irish Council for Civil Liberties had published its report on the scale of real-time bidding in May 2022, evidence the FTC later used in the Mobilewalla case. Two jurisdictions that never worked together, two legal languages, an Irish association and an American federal agency meeting only on the paper of a case file: the same technical infrastructure produced, almost in parallel, a European action on the consent mechanism and an American action on the collection mechanism.

The limit set at Karlsruhe

A constitutional court has named the mechanism precisely. On 16 February 2023 the Bundesverfassungsgericht ruled unconstitutional the Hesse and Hamburg provisions on automated data analysis for crime prevention, in proceedings 1 BvR 1547/19 and 1 BvR 2634/20. When already-held records are processed with an automated analysis application, the interference reaches the informational self-determination of everyone whose data is used in that procedure, victims and witnesses included, because the processing generates new knowledge about those people. The provisions struck down permitted automated processing of unlimited records by legally unlimited methods, whereas proportionality requires at minimum a concretised danger.

HessenDATA is the name of the platform used by the Hesse police, and it is Palantir’s Gotham product, from a company that has meanwhile put itself forward to solve Europe’s technological dependence problem.

Two sellers, one buyer

Positions like the ones described so far are not won on the market alone. They are also obtained by having them written into a law, and the message-scanning file offers the best documented case because the documents came out. Follow the Money, netzpolitik.org, BalkanInsight and Zeit reconstructed, through freedom of information requests, the network that accompanied the Commission’s proposal. At its centre sits Thorn, founded by the actor Ashton Kutcher, registered in the EU transparency register as a charity and introduced at a meeting with Commission officials as a non-profit startup. Thorn sells Safer, detection software whose customers include the US Department of Homeland Security.

The reconstruction documents at least a dozen meetings with European officials over three years, a letter from commissioner Ylva Johansson thanking for the close cooperation shortly before the proposal was published, and an appointment with Kutcher confirmed thirty-seven minutes after the request. Around it moves a funded ecosystem, including the WeProtect platform on whose board a Commission official sat alongside Thorn’s chief executive.

The money around the rule
FigureDestinationReconstruction
$24 mnOak Foundation grants since 2019 to organisations including Thorn and ECPATBalkanInsight
€600kThorn payments to the lobbying firm FGS Global in 2022netzpolitik.org
$4 mnSafer software licences purchased by the US Department of Homeland SecurityZeit Online
$4.6 bnPalantir 2025 revenue, up 56 per centCompany filings
$27 bnEuropean financial institutions’ holdings in PalantirEU Perspectives

None of this proves child abuse is a pretext. The phenomenon is real, real victims have been identified with the help of detection tools, and organisations working on it have their own reasons to back a law. The objection concerns sequence: whoever would supply the technology helped shape the demand that technology answers. Before the LIBE committee, Johansson rejected every criticism, maintaining that no error had been made, and an independent assessment never followed. The permanent text also provides for a European centre receiving the reports, defended with the argument that a public body offers stronger guarantees than the voluntary reporting private companies handle today, and destined either way to become a stable node crossed by a permanent flow.

The square is open to everyone. The ground has an owner

Sovereignty sold as the alternative

Speaking the language of sovereignty is the proposal formed on the opposite front. In April 2026 Palantir published a twenty-two point manifesto drawn from The Technological Republic, the book by its chief executive Alex Karp, and in July a white paper titled Institutional Sovereignty in the Age of AI. The argument is blunt: an organisation entrusting critical decisions to external systems without retaining control over information, decision logic and verifiability of results loses strategic autonomy, and whoever uses third-party models converts its competitive advantages into training data for somebody else’s laboratory.

That thesis captures a real problem. European technological dependence exists, choosing to regulate rather than build carried a cost, and Karp adds that surrendering technological superiority would amount to handing it to others. The paradox sits in the remedy, since sovereignty is offered by a US company founded in 2003 with seed capital from In-Q-Tel, the CIA’s venture arm, while France, Germany and Italy invoke digital sovereignty and renew contracts with that same company. Mediated by construction, the sovereignty on sale leaves the client sovereign to the extent the supplier certifies it, and whoever defines the categories through which an organisation reads itself holds a deeper form of access than whoever merely processes text. The charge levelled at general-purpose laboratories, that they look inside other people’s data, identifies a real risk and leaves in shadow the position of whoever makes it.

Where the asymmetry turns into a figure

Finally the message we started from returns, in the form of a price. On 17 January 2025 the Federal Trade Commission published preliminary findings from an inquiry opened six months earlier into eight intermediaries, six of which supplied the material the study rests on: Mastercard, Accenture, McKinsey and the pricing software vendors PROS, Bloomreach and Revionics. Staff wrote that minimal behaviours such as cursor movement on a page or the type of product left in an abandoned cart can be tracked and used to calibrate the price shown to that specific person. Passed on a three-to-two vote along political lines, the publication never reached a final report after the change of administration.

On 10 November 2025 New York’s first-in-the-nation disclosure law took effect: where a price is set by an algorithm using the consumer’s personal data, the company must say so next to the price, with penalties up to a thousand dollars per violation. A First Amendment challenge was rejected, the court finding the compelled communication purely factual. On 27 January 2026 California’s attorney general opened an investigative sweep into companies in retail, food and hospitality, challenging surveillance pricing on the ground of the purpose limitation principle set out in the California Consumer Privacy Act.

The Californian argument matches what Helen Nissenbaum formalised as contextual integrity: information gathered in one context carries that context’s norms with it, and moving it elsewhere is a violation even when nobody publishes it. Applied to the chain travelled here, the principle locates the point where asymmetry becomes measurable in currency. Data gathered while we buy a pair of shoes should not determine what a flight costs us, and a friend’s confidences should not feed the commercial profile of whoever received them.

The square and the tower

Rereading the route from the start, a recurring figure appears. Whoever runs the application decides who enters. Whoever supplies the model decides how the text is interpreted. Whoever owns the graph decides which fragments belong to the same person. Whoever writes the definition decides whether those fragments are personal data. None of these parties produces the information it profits from, and each occupies a compulsory passage.

Niall Ferguson read modern history as an alternation between horizontal networks and vertical hierarchies, dismantling the idea that a network is emancipatory by nature. Contested by parts of the historical profession for the breadth of its analogies, that thesis stays useful for one narrow reason: square and tower have stopped being alternatives, because the square stands on ground the tower owns. Shoshana Zuboff described behavioural surplus as the residue interaction produces and the company appropriates without payment. Nick Srnicek added the economics, showing how an intermediary’s value grows with the number of transactions crossing it, which explains why these positions tend to concentrate in few hands.

Contemporary surveillance does not watch people. It occupies the positions people must pass through.

Michel Foucault described the panopticon as a device that disciplines through the permanent possibility of being watched, even when nobody is watching. The architecture reconstructed in these pages moves that device from an eye that might settle on us at any instant to a calculation already performed elsewhere, before we noticed, which has decided what we will see, at what price, and with what probability somebody will consider it worthwhile to take an interest in us.

A distinction stays useful. Some data we declare voluntarily, like an address typed into a form. Other data is observed, like time spent on a page. Other data still is inferred, conclusions a model produces about us that we never communicated, confirmed or got to see. Operating almost entirely on the first category, and partly on the second, are the proceedings contending for access to European conversations, while the third grows fastest of all and is now generated inside private conversations too, from words written by people who chose nothing.

Every position crossed here is defended in its own vocabulary. User security for Meta, market contestability for the Commission, child protection for the organisations backing scanning, strategic autonomy for Palantir, experience personalisation for the brokers. Some of these arguments hold, and all of them ask for the same thing, which is how the weld between technological concentration and political power came about: a stable seat inside the flow, from which to exercise a capacity that people at the far end can neither verify nor revoke.

Sanctions have hit single links, and for the pieces removed the chain changed supplier. An effective counter-power would have to act on positions of transit rather than on individual processing operations, which means confronting a question none of the fronts opened in 2026 has yet put on the table: who answers for knowledge produced by a relation between data that nobody, taken singly, could have produced. Karlsruhe gave a partial answer for the police of two German Länder, and remains the only place where somebody measured that cost instead of assessing the offer. Anyone who has followed the route from the advertising identifier to the substantive end of anonymity online knows the breaking point was never technical.

Follow the algorithm · The tower, the square and the data chain
{{TESTO_CTA}} ↗ Opens in another page
Sources

Post scriptum

A year after declaring it processed seventeen billion signals a day from a billion devices, Gravy Analytics disclosed that it had been breached. On 4 January 2025 an attacker reached its Amazon cloud environment through a stolen key. The security researcher who analysed the first sample of the stolen files found more than thirty million location points, some corresponding to areas around the Vatican, the Kremlin and the White House, with data coming from thousands of different applications, dating and messaging apps included.

The company that had built its business on knowing where anyone is could not stop somebody else from knowing where its data was. In that case third-party access was not negotiated in Brussels, and nobody had to ask permission to read anything.

Watch on YouTube ↗

Similar Posts