Security cameras watching over a public space.

What Surveillance Means to Me

Niclas Hedam

PhD, Computer Science

· 13 min read · 5 sources

  • I am not against all surveillance. A camera that records an assault is a witness, and taking that away would help no one. What I object to is the step from recording an event to identifying, tracking, and cataloguing the people caught in it.
  • The line I care about is not surveillance versus none, but its properties: whether it has boundaries, whether a human reviews it or a machine decides alone, whether the data expires or accumulates, and whether a warrant guards access. The other test is who pays the cost and who gets the benefit.
  • Mass surveillance is a spectrum, not a switch. One end is impunity; the other is an Orwellian society where behaviour becomes performance. The right place sits between them and keeps moving, so the boundaries have to be drawn again each time the technology does.

My posts may make it sound as though I think all surveillance is wrong. I write about governments watching us, companies tracking us, and data being turned into a weapon, so it would be fair to read me that way. I am not, though. If I were against all of it, there are parts of my professional life I would struggle to explain.

What I am against is the way some modern surveillance systems are built and used.

Why some Surveillance Makes Sense

Take the CCTV cameras on public transport. If a passenger is assaulted, the cameras record it, the police can work out who was responsible, and the victim has something to point to. Someone can be held to account.

I have no objection to that. The alternative is worse: an assault with no record of it, a victim with no way to prove who attacked them, and an investigation that has to start from nothing. Here the camera is a witness. It documents something that happened in a public space, and the same holds for a theft or a hit-and-run. The camera provides evidence, and that seems reasonable to me.

In everyday discussion, “surveillance” gets used loosely for any kind of monitoring or data collection. I think it is worth separating two very different things: passive recording, like a security camera capturing footage of a public space, and active tracking or profiling, like a facial recognition system that identifies and catalogues individuals. Recording can be a tool for accountability and safety. Identifying and cataloguing raises harder questions.

The Issue with Automation and Algorithms

A camera that records an event and a camera that recognises who is in front of it are not the same kind of machine, even if they look identical on the wall. The Electronic Frontier Foundation recently set out the legal case against Ring, Amazon’s doorbell service, over a face recognition feature it plans to add. A camera like that does more than capture what happened at your door. It puts a name to each face and builds a searchable record of who called at which address.

Amazon’s Ring rolls out controversial, AI-powered facial-recognition feature to video doorbells — Coverage of the “Familiar Faces” rollout, which builds a named catalogue of everyone a Ring camera recognises at the door.

The Legal Case Against Ring’s Face Recognition Feature — EFF’s analysis of why automated facial identification at residential doorbells crosses from safety and evidence-gathering into mass surveillance infrastructure.

That is a different object from a CCTV camera that records a crime, or a doorbell that simply lets you see who is standing outside. Once you add automatic identification and cross-referencing, the thing on the wall stops being a camera in the ordinary sense and becomes infrastructure for tracking people across time and place.

The question is not whether recognising and cataloguing faces is useful today. In some narrow, well-defined settings it plainly is. The question is what the same system does tomorrow, in a year, in five years. What happens when it is quietly extended to a new purpose, or the context around it shifts? What happens when the data is reached by people who were never meant to have it? What happens when whoever runs the system draws the line between acceptable and unacceptable somewhere quite different from where you or I would draw it? The worry is not really the use in front of us. It is everything the same infrastructure makes easy later.

The Role of Retention

Denmark has an interesting rule when it comes to CCTV footage. Any footage must be deleted within 30 days unless there is an active investigation. It sounds like a technical detail, but I think it matters.

Optagelser og overvågning — Under Danish law, surveillance footage must be deleted within 30 days. Retention beyond that requires an active police investigation that specifically needs the footage. The law also prohibits private cameras from recording directly into public spaces (e.g. the street or side-walk) to prevent the cameras from being used for mass surveillance. The default is deletion and not accumulation.

Keep the footage forever and the system quietly changes into something else. It stops being a way to prevent or solve crimes and becomes an archive you can interrogate after the fact. Someone can ask, “Where was this person on these dates?” and get a full answer. The camera is no longer a witness to particular events; it is a permanent record of everything that passed in front of it. A deletion rule pushes against that. When the default is to erase, the system is not built to remember everyone indefinitely, and it stays closer to what it was meant to be: a way to hold people to account when something goes wrong, rather than a way to track everyone on the chance it might matter.

Ring’s planned facial recognition makes this worse because it is centralised. Match faces to addresses over time and you can draw a fairly detailed map of where someone goes and who they see. An ordinary CCTV setup does not do this: a handful of cameras keep their recordings for a while on a local server or in the owner’s own cloud, and that is the end of it. Ring already runs a network of cameras across many homes. Add recognition on top and a single database can be asked, all at once, who was where and with whom.

Data without Names

The same logic runs through data collection more broadly. Truly anonymous data and data about you and me by name are different things, even when they start from the same sensor. A city planner who counts how many people pass through a train station at each hour has something useful for managing the crowds. A record that says I passed through that station at that hour is something else. That is no longer surveillance of a place. It is tracking of a person.

Aggregate data of that kind seem fine to me. Knowing how a station fills up, how traffic moves, where the infrastructure strains: all of that is worth having. The trouble starts when the data stays personal, or could be made personal again with very little effort.

Once the data is personal, another line has to be drawn around it. Danish ISPs were at one point ordered to log all their customers’ network activity. That might help a future criminal investigation, but the whole question is who can reach those logs, and on what terms. Under Danish law you needed a warrant to pull the detailed records of a named individual, and rightly so. It would have been a completely different arrangement if the logs sat open to anyone with administrative access, or were mined for profiling with nobody watching. In the first case the data is guarded by a court and used to investigate a crime that has already happened. In the second it is just a standing tool for control and profit, with no real check on it.

Logningsbekendtgørelsen — The Danish executive order requiring telecommunications providers to log customer traffic data, with release to police conditioned on a court order under the Administration of Justice Act. The law was later found to be in violation of the European Charter of Fundamental Rights, and the Danish government repealed it in 2022.

Lektor: Lov om telelogning er en krænkelse af grundlæggende rettigheder — An Associate Professor at the University of Copenhagen argues that the Danish law requiring ISPs to log user activity is a violation of fundamental rights.

Who the System Serves

What matters most is what becomes of the data the surveillance produces. A camera that catches an assault serves the victim. A traffic count serves the public that has to move through the city. In both cases the benefit is clear, and it lands on an identifiable person or group.

Other systems serve someone else entirely. A facial recognition system that follows my movements serves whoever wants to know where I go. A log of my browsing history serves advertisers. The benefit is still real, but it accrues to them, and the cost falls on me.

There is a third category, and it is the awkward one. Here the system does not serve me directly, but it does serve some public good. Chat Control is the obvious example: a proposed system that scans everyone’s digital communications to catch child exploitation. You can make a genuine case that it serves the public, but it works only by reading through everyone’s private messages. The people it protects and the people it monitors are not the same people. When the group being protected and the group being watched come apart like that, “it helps good people” is not enough of an argument. You are asking most of the population to give up privacy to shield a smaller group. That can be worth doing, but it is never a clean or automatic yes. It needs explicit consent, hard limits, and real oversight, not the assumption that a good intention settles the matter.

The same question sits under all three cases: who pays the cost, and who gets the benefit? When it is the same person or group, the justification is easy. When they come apart, when I carry the surveillance cost and someone else pockets the benefit, that is exactly where you need firm boundaries: limits on what can be collected, how long it is kept, who can reach it, and what it can be used for.

And once the infrastructure exists, it rarely stays put. A camera installed for one reason attracts other reasons. Data gathered to solve crimes draws interest from people who would like to solve quite different problems with it. Whoever holds it, a government or a company, now holds a version of the story of where you go, who you see, and how you behave. You agreed to carry a cost for one purpose. You did not necessarily agree to carry it for the next three. The system drifts, and the line between acceptable and unacceptable slowly loses its edge.

Mass Surveillance: A Spectrum, Rather than Binary

It helps me to think of mass surveillance as a spectrum rather than a simple on-or-off switch.

At one end is a society with no surveillance at all, sometimes called privacy absolutism. No cameras, no records, no mechanism of accountability of any kind. In practice this shades into anarchy, because crime becomes very hard to investigate or prosecute. With no witness nearby, anyone can do more or less anything, since there is nothing left afterwards to show they did it. A total absence of monitoring does not produce freedom. It produces impunity, and impunity mostly favours whoever already holds power.

At the other end is an Orwellian society, where every movement is tracked, every message logged, every association noted and cross-referenced. The point is not just that crime gets harder. It is that people stop behaving freely at all. When you are always watched, behaviour turns into performance. You self-censor, keep away from anything that might look bad, and drift towards whatever the system seems to reward. Freedom does not disappear because anyone banned it. It disappears because it cannot survive being watched every minute.

The term “Orwellian” comes from the English author George Orwell and his 1949 novel Nineteen Eighty-Four. In the novel, a totalitarian state called Oceania monitors its citizens through telescreens, which are two-way screens installed in every home and public space and deploys a vast surveillance apparatus to enforce political conformity. The ruling Party’s figurehead, Big Brother, watches everyone at all times. Citizens who express dissent, even privately, are disappeared.

Today, “Orwellian” describes any system of pervasive surveillance, thought control, or manipulation of truth that resembles the world Orwell depicted. In essence, a society where observation is total, privacy is impossible, and behaviour is shaped by the knowledge that every action is being watched.

The right place is somewhere between the two, and finding it is genuinely hard. The problem is not only technical or legal but philosophical, and reasonable people disagree, in good faith, about where the line belongs. The answer can fairly change with the setting, too: a hospital, a city square, a private home, a political meeting. What counts as proportionate in one of these can be plainly invasive in another. That is a large part of what makes the whole question so difficult.

What makes it harder still is that neither the systems nor the people running them stay put. What looks like an acceptable use today can quietly become the machinery for an abuse tomorrow. So wherever you decide the line belongs, the more useful question is how well that line would hold as everything around it keeps changing.

What I Am Actually Hoping For

I used to argue that real privacy meant being invisible. I no longer think that is realistic in 2026, and I am not sure it is even what I want. I do want cameras in shared spaces that help solve crimes and let me feel safe, and I want people held to account when they cause harm. I want a site like this one, where I can write down what I think and hand it to whoever cares to read it. I do not want to vanish. I want to be able to share things about myself when it serves some purpose of my own, and to stay in charge of the story of who I am and what I do.

What I want to avoid is the comprehensive kind of tracking, and the slow drift towards the Orwellian end of the scale. Systems that can join up where I go, what I read, and who I meet, and pull all of it together into a profile that can later be turned against me. I would rather have data collection that is tied to a specific, stated purpose and stops there.

The distinction I keep reaching for comes down to a handful of concrete questions. Does the surveillance have boundaries, or none? Does a person review it, or does a machine decide on its own? Does the data expire, or does it pile up? Does a warrant guard access, or can anyone with authority over the system simply help themselves?

I do not think that line is arbitrary, and I do not think it contradicts itself. The boundaries are real. A camera that records an assault is not the same thing as a system that catalogues everyone who walks past a building. A record that is looked at once and then deleted is not a permanent archive. Access that needs a warrant is not the same as access anyone on the admin team can grant themselves. Treat these as interchangeable and you smudge the one distinction that actually matters.

That is the conversation worth having. Not whether surveillance is good or bad in the abstract, but where the lines fall, and why. And those questions never settle for good. The technology keeps moving, and each time it does, the boundaries have to be drawn again.

The views and perspectives expressed here are the author's own and do not represent any employer or affiliated organisation. The writing draws on public sources and the author's own experience, never on confidential information. Artificial intelligence is used on some posts to identify sources, draft structure, and assist with quality assurance; the final article is always the author's own work. The AI assists, but never authors.

Niclas Hedam

PhD, Computer Science

Niclas Hedam holds a PhD in Computer Science from the IT University of Copenhagen. He is passionate about educating others on the importance of safeguarding personal information online.

A phone with a bunch of notifications for social media apps.

The Retention Economy: Kept at All Costs

· 19 min read · 11 sources

A recommendation feed is not trying to entertain you. It is trying to keep you watching, and it drifts towards whatever version of you is easiest to hold on to.