If you have said “I have nothing to hide,” you are probably right. You are not running a crime ring out of your garage. Your search history is boring. If a police officer went through your phone tonight, the worst they would find is a half-written text you never sent and a lot of receipts.
A lot of privacy writing skips past this part, or treats the “nothing to hide” line as proof that you have not thought hard enough. That is a bad way to convince anyone of anything, and it is not what this post is going to do. The concern is real: plenty of privacy talk online is dialed up to a level that does not match how most people actually live.
So here is the honest question underneath it. If you genuinely are not hiding anything, what is privacy even for? Why should you care who has your data, if none of it is incriminating?
The short version: the argument rests on a mix-up about what privacy is, and that mix-up is worth walking through slowly.
What the argument gets right, and where it slips
“I have nothing to hide” is the most common response people give when privacy comes up, and as a statement about crime it usually holds. If the only question were “would this get me arrested,” most people could hand over everything and sleep fine.
Here is where it slips. The argument treats privacy and secrecy as the same thing. Secrecy is about wrongdoing, or at least about information you would be embarrassed to have surface. So if you picture privacy as secrecy, then “I have nothing to hide” really does sound like a full answer. You have addressed the whole issue.
But privacy is a much larger and more ordinary thing than secrecy, and you rely on it constantly without noticing. Once you separate the two, the “nothing to hide” line stops being an answer and turns back into the question it always was.
Privacy is control over context
The doctor test
Think about what you tell a doctor. Symptoms, habits, family history, things you would not bring up at dinner. Everyone else in your life gets a smaller version of that, and nobody calls it dishonest. You are matching what you say to who you are saying it to, and why.
That instinct is the whole concept. You already run something like a privacy policy in your head, dozens of times a day, and you adjust it by the room you are in. A privacy violation is your information walking out of the room you shared it in and turning up somewhere you never agreed to. The words are the same. The room changed, and the room was most of the point.
Secrecy is the smaller idea
Secrecy means information nobody has. There is not much of that in your life, and most of it is dull. Privacy is the bigger, more ordinary thing sitting around it: you deciding who gets a piece of information, in what setting, for what reason. Your doctor can know your medical history without your manager knowing it, or a life insurance underwriter, or whoever buys the database in four years. You would happily explain that line out loud, which is a decent sign it is not hiding.
You can want that kind of control while having nothing secret at all. For almost everyone, that is the normal state.
You already expect this everywhere
None of this is theoretical. You draw these lines all the time, and none of it involves anything you would be ashamed of.
You probably would not want coworkers knowing your exact salary. You might not want anyone watching what you search at 1 a.m. after a bad test result. A couple who is not ready to announce a pregnancy is not committing fraud by keeping quiet. Neither is someone quietly going through a breakup, or looking up divorce lawyers, or reading about a religion they were raised in and are starting to leave.
The physical versions are so normal they are invisible. You close the bathroom door. You lower your voice when the call gets personal. You seal the envelope instead of taping a postcard to the mailbox. The secret ballot exists because a vote you can be pressured over is not really a free vote, and a whole system of government is built on that one small curtain.
In every one of these cases you are setting the boundary yourself, instead of leaving it to someone else. That is the whole of what privacy is.
Small facts add up to big ones
Here is the part that makes “none of my data is sensitive” fall apart.
Take any single thing a company knows about you. You bought a book. You filled a prescription. You drove past a certain building on a Tuesday. On its own, each fact is nothing. String enough of them together and they start to describe things you never told anyone.
Buy a book about a serious illness one week and a hair-loss product the next, on the same card, and a system does not need your diagnosis. It can guess it, and act on the guess. Retailers have been quietly scoring shoppers for things like pregnancy from ordinary purchase patterns since at least the early 2010s, in some cases before the person has told their own family.
And “anonymous” does less than it sounds. One well-known study found that four rough time-and-place points, the kind your phone gives off on any normal day, were enough to pick one person out of an anonymized dataset of more than a million.
There is an industry of companies whose entire business is buying these scraps, stitching them into a profile, and selling it on to advertisers, insurers, landlords, background-check services, and sometimes police. You never signed up with any of them. None of this turns on a single embarrassing fact. The catch is that you cannot argue with a conclusion you never saw being drawn.
You can’t know who holds it later
“I have nothing to hide” is a statement about right now. Your data does not stay in right now. It sits in storage, and storage outlasts the situation you were in when you handed it over.
The company you trusted gets acquired, and your history transfers to the buyer as an asset. It goes on the balance sheet next to the office furniture. A company folds and its customer database gets sold to pay creditors. A service gets breached, and once private data is public it does not go back to being private. There is no recall.
Then there is time itself. Something that is fine to have known about you today can read very differently in ten years, to a future employer, an insurer pricing your policy, or a government with priorities nobody has campaigned on yet. None of this predicts a specific disaster. The plainer point: you are agreeing to terms on behalf of a future you cannot see, and nobody asks you again later.
Trusting a company with your data today means trusting every future owner of that company, and every future owner of the data after that.
The other side knows far more than you do
The exchange is lopsided in a way that is easy to miss.
A data broker can hold hundreds of fields about you: where you live, what you earn, your rough health picture, the major events in your life. You cannot name three of those companies, cannot see your file, and in most places cannot make them delete it. They can act on what they hold. You cannot even check it for errors.
There is also a quieter cost. After it became widely known that online activity was being logged and kept, measured traffic to sensitive and controversial reference articles dropped and stayed lower. It happens even when you have done nothing wrong, because the point of thinking something through is doing it without an audience. Take the audience for granted and you censor yourself before you have finished the thought.
The usual mix-ups
A few things trip people up here. Secrecy and privacy get used as the same word, though secrecy is the rare case and privacy is the one you lean on every day. Wanting privacy gets read as a sign you have something to conceal, though the same instinct shows up in anyone who has ever closed a door. And people treat it as all or nothing, a straight choice between a normal life and a cabin with no mailing address. It works more like a dial you already adjust all day long, and the only real question is who gets to set it: you, or someone you cannot see.
So what do you do with this
Not much, at first. You do not need to torch your accounts this weekend.
The useful next step is to get specific about who you actually want to keep your information away from, and how much hassle that is worth to you. Keeping it away from targeted advertising, a nosy acquaintance, an abusive ex, or a government agency are four different jobs with four different answers. Working out which ones actually apply to you is what makes every later decision easy.
If you want one concrete thing to do while you think about it, set up a password manager and let it generate every password. It is the closest thing to a universal recommendation there is, and it pays off whichever way that question lands for you.
Privacy is just the ordinary work of deciding who knows what about you, and when. You already do that everywhere else in your life. Your data is the one place you have quietly let someone else take the wheel.
1 thought on “What’s the point of privacy? I’ve got nothing to hide!”