Nothing to Hide?
The Tyranny of Transparency, and the Power to Disappear
Every few months, usually in response to some real and serious social problem, public debate seems to rediscover the same temptation: perhaps the difficulty is that we just don’t know enough.
If the state had better information, perhaps welfare could be distributed more fairly. If platforms knew more about their users, perhaps children could be better protected online. If employers, landlords, regulators, journalists and voters could verify more claims more quickly, perhaps fraud, abuse, corruption and dishonesty would become harder to hide. If identity were easier to prove, perhaps access to services would be smoother, public administration would become less wasteful, and the dishonest minority who exploit gaps in the system would find those gaps closing around them.
It’s not hard to see why this story appeals. Some of the things said in defence of greater transparency and stronger identity systems are not merely plausible, but true. Fraud does exist. Children are harmed online. Public trust is damaged when powerful people lie without consequence. The internet has created whole shadow economies of impersonation, manipulation, harassment and scam artistry. The state already holds huge quantities of information about us, often badly joined up, badly secured, badly explained and badly used. Against that background, the promise of a cleaner, safer, more accountable digital order has obvious moral force.
That’s why the weaker civil-liberties argument is not enough. It’s easy to oppose surveillance by saying it won’t work, or that it will be abused, or that the claimed benefits will turn out to be exaggerated.
Often that’s true. Governments overpromise. Technology vendors overpromise more. Databases rot. Errors proliferate. Outsourced systems find bold new ways to be expensive and useless at the same time, which is admittedly a sort of technical achievement. But the more interesting question begins when we grant the premise.
Imagine, then, that the government legislates to abolish privacy as a social institution. Not merely to create a new ID card, or to require age checks for certain websites, or to join up public records more efficiently, but to create the logical endpoint of total transparency: a free-to-use, publicly accessible database containing all information about everything and everyone.
And suppose, for the sake of argument, that it works.
Social welfare improves enormously. Benefits are distributed more fairly because need is visible and fraud is harder to conceal. Journalistic and political integrity improve because public claims can be checked instantly against public facts. Crime rates fall. Dangerous people are easier to identify. Corrupt officials are easier to expose. Hidden conflicts of interest become public knowledge. The vulnerable are easier to find and support. The dishonest are easier to catch. The evasive are easier to pin down. The whole system becomes cleaner, safer, more efficient and more truthful.
The question is whether such a society would be better.
My answer is no. Or, more precisely, it might be better at some things, while being worse at the thing that makes political and social life worth having in the first place: the ability of a human being to exist as something more than a public file.
The problem with total transparency is not only that it might fail. The problem is that, even when it succeeds, it succeeds by destroying the private sphere. It gives us safety by making everyone searchable. It gives us integrity by making everyone permanently auditable. It gives us efficiency by making everyone administratively legible. It doesn’t merely reveal facts. It changes the conditions under which people live, think, experiment, associate, dissent, mature, recover and become themselves.
That is why the usual framing of privacy as a trade-off between security and secrecy is too thin. The real question is not whether we have something to hide. The real question is whether we’re still allowed to have a door.
The seduction of transparency
There’s a reason transparency has become one of the great moral words of modern politics. It sounds clean. It sounds democratic. It suggests sunlight, accountability, open records, honest administration and the end of cosy deals done behind oak doors by people with hereditary furniture. In that sense, transparency is not the enemy. Much of modern democratic life depends on it.
We should know who funds political parties. We should know what ministers have declared as interests. We should know how public money is spent. We should know whether a company dumping waste into a river has also been lobbying the regulator meant to stop it doing precisely that. A great deal of corruption survives because relevant information is hidden, scattered, inaccessible, expensive to obtain, or technically public but practically impossible to find without a law degree, three free afternoons and the personality of a terrier.
So the argument against total transparency cannot be an argument for total opacity. That would be absurd. Secrecy can protect the powerful as easily as the vulnerable; indeed, it usually protects them better, because the powerful can afford lawyers, shell companies, non-disclosure agreements, reputation management consultants and the sort of filing practices that make accountability feel like archaeology.
The question, then, is not whether transparency is good. The question is where transparency belongs, who it is for, what it is meant to expose, and what kinds of life it makes possible or impossible.
That distinction is crucial because transparency does not mean the same thing when applied upwards as when applied downwards. Transparency directed at powerful institutions can be a democratic tool. Transparency directed at ordinary individuals can become a disciplinary one. There is a difference between making the Home Office explain its decision-making and making every citizen’s medical history, romantic life, religious doubts, income, debts, mistakes, complaints, searches, friendships and political affiliations visible to anyone with an internet connection and a slow afternoon.
A society in which the powerful are accountable to the public is not the same as a society in which every person is accountable to everyone else at all times. The first can be democratic. The second is not democracy at all. It’s exposure.
The crowd is not a court
The internet has already given us a partial preview of what happens when private information becomes easy to find, easy to copy, easy to detach from context and easy to weaponise.
Some of this has been genuinely emancipatory. People once silenced by institutions can now speak around them. Abuse once concealed within families, workplaces, churches, schools, parties, clubs and industries can now be documented, shared and believed. The old gatekeepers were not neutral guardians of truth; they were often bouncers for reputation, class, money and institutional convenience. Anyone defending privacy has to take this seriously, because privacy has also been used as a polite name for burying harm.
But there’s a difference between enabling victims to speak and turning public accusation into public punishment without procedure. Social media does not need to wait for evidence, relevance, proportionality, context, right of reply, appeal, limitation periods, or any of the other boring procedural devices by which civilised societies try to distinguish judgement from appetite. It moves quickly, often thrillingly so. A name appears. A screenshot circulates. A thread begins. Someone adds a second-hand story, then a third-hand interpretation of the second-hand story, then someone with a podcast voice and a ring light announces that the silence from the accused is itself revealing. By lunchtime, the crowd has become detective, prosecutor, jury, judge and public executioner, although naturally it still has strong feelings about institutional overreach.
There are cases where public anger exposes what formal systems refused to see. That’s the strongest version of the defence, and it should not be dismissed. Courts fail. Police fail. HR departments fail with the dead-eyed fluency of institutions that have discovered the passive voice. But the failure of formal process doesn’t mean the crowd is a better process. It may be faster, louder and more emotionally satisfying, but speed, volume and satisfaction are not substitutes for justice.
The danger here is sometimes described as the tyranny of the majority, but even that phrase may be too organised. A majority at least implies a polity, a defined body, a decision rule, a mandate. The online crowd has none of that. It does not need to explain who belongs to it, what authority it claims, what standard of proof it applies, what punishment would be proportionate, when punishment should end, or what it would take to be forgiven. Its power comes from aggregation rather than legitimacy. Enough people looking at you can become a form of government, even if none of them individually thinks they’re governing.
Total transparency would make this dynamic permanent. It would not merely let the public judge wrongdoing. It would supply the public with an infinite archive from which wrongdoing, or something close enough to wrongdoing for present purposes, could always be assembled.
That is not safety. It is exposure to unlimited retrospective prosecution by people who don’t have to tell you what law they’re applying.
The state is not a saint
The opposing danger comes from the state, and here the usual libertarian warnings are often stated too crudely but not entirely wrongly.
There’s an old line attributed to Cardinal Richelieu: “If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him.” It survives because it names something unpleasantly durable about power. Give an institution enough information about a person, enough time to search through it, and enough motive to harm them, and innocence becomes beside the point. The question is no longer whether someone has done anything seriously wrong. The question is whether something can be found, isolated, reclassified, exaggerated, misread, or placed before the wrong audience.
The problem is not that every government is tyrannical. Most aren’t, at least not most of the time. The problem is that states are continuous in ways citizens are not. Administrations change. Ministers change. Laws change. Political moods change. Databases remain. Data collected for one purpose can be reused for another. Powers created under one moral emergency can be inherited by people with different enemies. A system built to find benefit fraud can be used to find dissidents. A system built to verify age can become a system for routine identity checking. A system built to protect the vulnerable can become a system for classifying the inconvenient.
This is why good intentions are not enough. The question is not whether the present minister sounds reasonable in a consultation document. The question is what structure is being built, what it permits, what it normalises, what safeguards exist beyond ministerial reassurance, and what a future government could do with the same machinery under different political conditions.
A benevolent database is still a database. A humane surveillance system is still a surveillance system. A well-administered architecture of total visibility is still an architecture of total visibility. Its moral character cannot be judged only by the intentions of the people who first switch it on.
There are, of course, practical objections too. Public records contain errors. People share names. Addresses go out of date. Relationships are complicated. Data taken from one context is often misleading in another. But, again, the thought experiment asks us to go further. Suppose the system is accurate. Suppose it catches the right people. Suppose it works exactly as advertised.
Even then, the citizen has been converted into a permanently inspectable object.
That conversion is not a side effect. It is the point.
Privacy is not secrecy
The laziest argument against privacy is that only people with something to hide need it. This is rhetorically effective because it makes privacy sound guilty before the argument has even begun. It quietly replaces the right to a private sphere with the right to conceal evidence, and then invites us to be suspicious of anyone who objects.
But privacy is not the same thing as secrecy.
Secrecy is about the content of what’s hidden. Privacy is about the existence of a sphere in which hiding is possible. That distinction, made powerfully by Emilio Mordini in his work on biometrics and the private sphere, changes the whole argument. The point is not that everyone has a scandal in the cupboard. The point is that a human life requires cupboards.
This may sound melodramatic until one thinks about the ordinary architecture of social life. We already live through forms of selective disclosure. We don’t present ourselves to our parents exactly as we do to our friends, or our colleagues, our partners, our doctors, or at the pub, at the polling station, in the group chat, the confessional, the therapist’s office, the classroom, the union meeting, the job interview, or the moment when we idly search for something odd on the internet and hope, for a moment, that no one is watching. We present as different people when given different audiences or contexts.
This is not hypocrisy. It is personhood.
The same fact can mean different things in different contexts because the relationship, purpose and audience are different. A medical diagnosis belongs in a medical context. A political opinion may belong in a meeting, a notebook, a ballot box, a conversation, an essay, or nowhere at all. A sexual preference may belong between consenting adults and no one else. A debt may be relevant to a lender but not to a neighbour. A past mistake may be relevant to safeguarding in one setting and wholly irrelevant in another. To collapse all of those contexts into one public database is not to reveal the truth of a person. It is to destroy the conditions under which truth can be interpreted properly.
This is where Helen Nissenbaum’s idea of contextual integrity is useful. Privacy is not simply violated when information becomes known; it’s violated when information moves in ways that break the norms of the context in which it was disclosed, produced, or held. The fact that a GP knows something doesn’t mean an employer should know it. The fact that a tax authority knows something doesn’t mean a journalist should know it. The fact that a friend knows something doesn’t mean a stranger should be able to search it.
The transparent society pretends that information is morally neutral once it’s accurate. It isn’t. Information has context, and when context is stripped away, accuracy can become a form of falsehood.
The administrative person
Total transparency would also change the kind of person the system expects us to be.
A private person is unfinished. They can think things they don’t yet believe, try on opinions they later reject, make mistakes without those mistakes becoming permanent public property, recover from humiliation, change affiliations, leave groups, enter relationships, exit relationships, experiment with identity, abandon foolishness, learn, contradict themselves, apologise, mature and quietly become someone else.
An administratively legible person is different. They are a record. They are a profile. They are a searchable sequence of attributes, transactions, affiliations, associations, risks, flags, scores, statements and deviations. They may still have an inner life, but the public system has less reason to care about it, because the file is easier to process than the person.
This is one reason the nothing-to-hide argument is so inadequate. It imagines privacy as a shield for incriminating content, when privacy is also the condition under which non-incriminating life can remain human. Most of what we wish to keep private is not criminal. Much of it is not even shameful. It is private because it’s fragile, unfinished, intimate, experimental, context-dependent, or simply nobody else’s business unless we choose to make it so.
The right to privacy protects the awkward draft of the self.
A society without that right doesn’t merely expose wrongdoing. It changes incentives. People become more cautious, more performative, more risk-averse, more conformist. The issue is not that everyone would become obedient overnight, because human beings are stranger and more stubborn than that. The issue is that everyone would learn to live before an imagined tribunal. Every search, joke, friendship, message, purchase, diagnosis, meeting, donation, doubt and desire would carry the question: how will this look when retrieved later?
That question is not morally neutral. It colonises the mind. It turns life into reputation management.
And although people sometimes say that the innocent have nothing to fear, innocence has never protected people equally. Those with conventional lives, secure jobs, respectable accents, supportive families, boring hobbies and the good sense to have been born into socially approved categories will always experience transparency differently from those whose lives are messier, poorer, queerer, more marginal, more stigmatised, more politically exposed, or simply less legible to the people doing the judging. Total transparency doesn’t flatten power. It gives power more material to work with.
The policy temptation
None of this means every digital identity proposal is tyranny, or that every form of age assurance is the first brick in the tower of Foucault’s panopticon. That would be too easy, and too silly. States need to know some things. Institutions need ways of verifying identity. Children do need protection online. Welfare systems do need to reduce fraud. Public services can be improved when records are accurate, portable and sensibly joined up. There are privacy-preserving technical designs that may answer some real problems better than the current mess of passwords, photocopied documents, insecure uploads and proving one’s existence to five different agencies in five different ways.
But this is precisely why the conceptual argument is important. The danger often doesn’t arrive as a villain stroking a cat and announcing the end of liberty. It arrives as an interface improvement, a safeguarding measure, fraud prevention, convenience, verification, service integration, child protection, risk management, public confidence and administrative efficiency. Sometimes these are genuine goods. Sometimes they’re even urgent goods. But none of them removes the need to ask what kind of citizen is being designed into the system.
The live debate about digital ID and online regulation is not identical to the thought experiment above. It would be unfair to pretend that a phone-based identity credential, or a requirement for age checks on ‘high-risk’ platforms, is the same thing as a universal public database. The serious argument is not that we’re already living in the hypothetical. It is that the hypothetical reveals the direction of travel we should be wary of: a society in which access to ordinary life increasingly depends on being identifiable, verifiable, classifiable and traceable.
That may be acceptable in some contexts. It may be necessary in others. But it should never be treated as cost-free simply because the interface is neat and the stated aim is benevolent.
The key questions are not only technical. They’re constitutional, moral and social. Who holds the data? Who can see it? Who can combine it? Who can compel it? Who audits the system? Who can refuse? What happens to people without smartphones, documents, stable addresses, conventional family structures, or trust in the institutions demanding proof? What information is disclosed to the service being accessed? Can identity be verified without identity being exposed? Can age be proved without a permanent record of the attempt? Can the state design systems that know only what they need to know, rather than everything they can know?
These questions are often treated as implementation details. They aren’t. They are the substance of liberty under digital conditions.
The right to close a door
The private sphere is not a sanctuary for wickedness. Or, at least, it is not only that, and no serious defence of privacy should pretend otherwise. Bad things happen behind closed doors. Secrecy protects abusers, fraudsters, hypocrites and cowards. Privacy can be invoked cynically by people who don’t want accountability, and any argument for privacy must face that fact squarely.
But a right can be abused without becoming worthless. Speech can be used to lie. Association can be used to conspire. Due process can be used by the guilty. Political freedom can be used by fools. The answer is not to abolish the right, but to understand why the right exists and where its limits should fall.
Privacy exists because a human being is not public property.
That is the point I keep returning to. We can concede almost every practical benefit claimed for transparency and still reject the transparent society, because the deepest case against it is not practical but civic. Total transparency would not merely help institutions know more about us. It would change our relation to institutions, to one another, and to ourselves. It would make life permanently inspectable. It would make context fragile. It would make error indelible. It would make identity less something lived and more something retrieved.
The point of privacy is not that every room contains a scandal. Most don’t. Some contain grief. Some contain illness. Some contain fantasy, prayer, boredom, sex, resentment, doubt, stupidity, recovery, unfinished politics, bad poems, worse search histories, and the small, undignified machinery by which people remain people. Some contain nothing very interesting at all.
That doesn’t weaken the case for privacy. It is the case for privacy.
A person should not need to prove that the room contains something important before being allowed to close the door. The door is the point. The power to close it is part of what separates a citizen from an object of administration, a neighbour from a suspect, a person from a profile.
A safer society may require some information to be shared. A fairer society may require some secrecy to be pierced. A more accountable society may require some doors, especially the doors of the powerful, to be opened more often and more forcefully than they are now. But a society with no doors at all would not be an honest society. It would be a society in which honesty had been confused with exposure, and exposure had been confused with justice.
The right to privacy is the right to remain partly unknown.
It is the right to be more than the sum of one’s records.
It is the right, sometimes, to disappear.

