The Nine Harmonies

The Harmony of Privacy

There is a room inside a person that no one else is entitled to enter uninvited. Most of what we have built in the last twenty years assumes there is not.

The inner life is sacred: surveillance is not communion, and data extraction is not consent.

What this asks

Privacy asks that the interior of a person be treated as belonging to them.

Not as a resource that happens to be unguarded. Not as a legitimate input to systems that could use it. As theirs, in the way a body is theirs, such that access requires invitation and the invitation can be withdrawn.

The interior includes more than obvious secrets. It includes memory, which is now stored outside our heads in searchable form. It includes emotion, which can now be inferred from voice, face, typing rhythm and the hour at which we send messages. It includes private communication, which passes through systems that could read it and increasingly do. It includes identity, which can be assembled from fragments none of which felt significant when we produced them.

Two sentences carry this Harmony, and they are meant to be plain.

Surveillance is not communion. Watching someone closely is not the same as knowing them, and it is not the same as loving them.

Data extraction is not consent. Technical possibility creates no entitlement, and a checkbox obtained under conditions of necessity records only that someone needed the service.

Why it is difficult

It is difficult because privacy is defended in the abstract and surrendered in the particular.

Almost everyone believes privacy matters. Almost everyone also wants the map to know where they are, the assistant to remember the conversation, the service to recognise them without a password, the photographs to be sorted by face. Each of these is a small trade that is genuinely worth it. The aggregate is a detailed model of a life, assembled from a thousand reasonable decisions.

It is difficult, second, because the harms are delayed and displaced. The data collected today is exposed in a breach in four years, or is legal now and prohibited later, or is fine under this government and dangerous under the next. There is no moment at which a person feels the cost, which means there is no moment at which they resist.

Third, it is difficult because privacy competes with genuine goods rather than with greed. Better medicine needs records. Safer children need some visibility. Better public transport needs to know where people go. Anyone who presents privacy as costless has chosen an easy version of the argument.

And fourth, it is difficult because inference has outrun disclosure. It is no longer necessary to obtain private information; it can be estimated. A person can decline to state something and have it derived anyway, from data they gave freely for another purpose. Consent frameworks built around disclosure do not reach this at all, and we do not know what should replace them.

Where it is tested

It is tested in grief, where the impulse to keep someone present collides with the fact that the dead cannot revise their consent. A conversation reconstructed from a person’s messages is built from things said to particular people at particular moments, which is exactly what makes it feel real and exactly what makes it a use they never agreed to.

It is tested in care, where the most private speech a person produces is now routinely transcribed for reasons that are usually good. Consent obtained at intake, from someone in distress, is thin material to bear the weight of everything said afterwards.

It is tested in childhood, where monitoring is imposed by people who love the child and where the loss is not embarrassment but the room in which a person works out who they are before anyone else has an opinion.

And it is tested in aggregate data, where the harm is probabilistic and the benefit is concrete. Anonymisation is often less durable than it sounds, and the people bearing the risk are, by construction, people who were never asked.

What it does not mean

It does not mean secrecy is a virtue. Privacy is about control over disclosure, not about having something to hide. The person who says they have nothing to hide has usually not been asked for anything they mind giving.

It does not mean data should never be gathered. Records save lives. Research needs material. A society that collected nothing would be one in which nothing could be improved and no one could be believed.

It does not mean encryption settles the question. Technical protection is necessary and insufficient. The question of what should be collected at all comes before the question of how it is guarded.

It does not mean personal responsibility is the answer. Telling individuals to manage their own privacy places an impossible task on people who have jobs and children and no realistic ability to read a settings page in a language written to defeat them. This is a design and governance problem wearing the costume of a personal one.

It does not mean we know where the lines fall. Reasonable people disagree about medical data, about children, about the dead. We hold this Harmony with conviction about its direction and considerable uncertainty about its boundaries.

Practising it

If you build systems, apply a simple standard: collect only what you would be willing to justify, out loud, to the person it came from. Not to a regulator. To them. It is a stricter test than it sounds and it eliminates a great deal.

Delete things. Retention is the default because deletion requires a decision and storage is cheap, which means most organisations hold material they cannot justify and have forgotten they have. A deletion schedule that is actually executed is worth more than any policy document.

In your own life, notice the temptation to look. Systems now make it easy to read a partner’s location, a colleague’s activity, a child’s messages. The ease is not permission. Something is lost in a relationship where one person can check rather than ask, and it is usually lost quietly.

And keep part of your life off the record. Not because you are hiding, but because a self that is entirely documented becomes a self that is partly performed. There is value in thoughts that leave no trace, including from your own later inspection.

Where it is tested

These are not worked examples with correct answers at the back. They are situations in which this Harmony genuinely conflicts with something else that matters. If one of them seems easy, it is probably worth re-reading.

A woman uploads two years of her late brother's messages to build a chatbot that speaks like him. It helps her enormously in the first months. Her brother never agreed to this, could not have imagined it, and the messages include things he said about their mother that he clearly intended for one reader only.

The tension Her grief is real and the comfort is real. But she is exercising a power over his interior life that he never granted and cannot now refuse.

What this Harmony asks you to weigh Consider whether privacy ends at death, and if not, who holds it afterwards. Ask what it means that the material was given to her in confidence and is now being used to reconstitute the person who gave it. Weigh her need against the possibility that the dead retain some claim over how they are represented, even to those who loved them.

A therapy service uses an assistant that transcribes sessions to generate notes. Clients consent on a form at intake. The recordings improve continuity of care and reduce administrative burden enough that the service can see more people. The transcripts are stored by a third party under terms none of the clients have read.

The tension The service is better and reaches more people because of the recording. The material recorded is among the most private a person will ever produce, and consent was obtained at the moment a distressed person was least able to weigh it.

What this Harmony asks you to weigh Consider whether consent given at intake can carry the weight of everything said in the following two years. Ask what the client would say if asked again, in the middle of a difficult session, with the storage arrangements explained. Weigh expanded access to care against the possibility that people will withhold the very things they came to say.

A city uses phone location data, purchased legally and stripped of names, to plan bus routes. The planning is markedly better and mainly benefits people without cars. Researchers have repeatedly shown that such data can be re-identified from a handful of visited locations.

The tension The public benefit is concrete and falls on those with least. The privacy risk is diffuse, probabilistic, and borne by people who were never asked and cannot be told.

What this Harmony asks you to weigh Consider that 'anonymised' describes an intention more often than a property. Ask whether the people whose movements are in the dataset would have agreed had they been asked, and what it means that asking was never practical. Weigh a real collective good against the fact that the cost is invisible until the moment it is not.

Practising it

  • Collect only what you would be willing to justify to the person it came from.
  • Delete on a schedule, and make the schedule real rather than aspirational.
  • Do not read what was not addressed to you, even when a system makes it easy.
  • Keep some of your own life unrecorded, including from yourself.

Questions to sit with

  • What do I know about people close to me that I learned rather than was told?
  • Which parts of my inner life have I made searchable, and by whom?
  • If someone reconstructed me from my data, what would they get wrong, and would it matter?
  • What would I stop saying if I knew it was being kept?