Privacy and Sovereignty
Privacy is sovereignty applied to citizens.
In July 2021, Morocco’s intelligence services were reading the private communications of the President of France through Pegasus spyware. France’s own intelligence agencies did not detect the intrusion. If a foreign state can read the head of government of a nuclear power, no European citizen’s data is safe.
Three digital models exist. American treats data as commodity. Chinese treats data as control. European treats data as belonging to the person, alone among the three with that commitment in constitutional law. The technology to enforce the commitment exists: fully homomorphic encryption, zero-knowledge proofs, secure enclaves. The institutional verification mechanism, a Register operated by CWI, Aarhus, INRIA and ANSSI, does not yet exist. Europe wrote the commitment. The architecture is the next move.
Technology as Surveillance
The American model answers the question of what technology is for with a business architecture: extraction.
In July 2024, journalists at netzpolitik.org and Bayerischer Rundfunk registered on a Berlin data marketplace and requested a free sample.
A Florida-based broker sent them 3.6 billion location records from eleven million German devices, collected over two months, precise to the metre.[1]
From that free sample, they reconstructed the daily movements of a member of President Macron’s security detail, tracking him to the Élysée Palace, to La Lanterne, the presidential hunting lodge in Versailles, and to Villacoublay military airfield.
They identified a BND officer’s commute to the intelligence facility at Bad Aibling. They counted 9,600 location pings from 543 devices inside NATO headquarters.
The data came from weather apps, games, and prayer apps.
No exploit was required. No government licensed the collection.
The surveillance infrastructure that Pegasus requires a nation-state to deploy, the advertising industry provides for free.
The American digital economy was designed to eliminate privacy.
The business model that produced the world’s most valuable companies is data extraction.
Google’s revenue – $307 billion in 2023 – comes from knowing what people search for, where they go, what they buy, and who they talk to.[2]
Meta’s $135 billion comes from mapping the social, emotional, and political relationships of three billion people.[3]
Amazon’s $575 billion comes from knowing what the world consumes, when it consumes it, and what it will consume next.[4]
The model is simple: collect everything, monetise what you can, store the rest.
The user is the product. The surveillance is the business.
The constitutional foundation predates the internet.
In 1979, the US Supreme Court ruled in Smith v. Maryland that persons have no legitimate expectation of privacy in information voluntarily disclosed to third parties.
The case involved a pen register on a robbery suspect’s phone line. The doctrine was written before the internet existed.
It now governs the digital lives of billions. Every email in Gmail, every document in OneDrive, every database in AWS is, in the American legal imagination, data the user has voluntarily surrendered.[5]
The state surveillance layer sits on top of the commercial one.
FISA Section 702 grants American intelligence agencies blanket surveillance authority over non-US persons whose data is held by American companies.
The CLOUD Act, enacted in 2018, allows the US government to compel any American-headquartered company to produce data stored anywhere in the world.
The data does not need to be on American soil. The data subject does not need to be American. The host country does not need to be notified.[6]
In 2024, Russia’s GRU exploited a vulnerability in Microsoft Outlook to compromise the communications of Chancellor Olaf Scholz and multiple members of the German Social Democratic Party.
The attack exploited a known flaw in software that runs on the majority of European government systems.
Germany’s own cybersecurity agency, the BSI, acknowledged the breach months after foreign intelligence services had flagged it.
The infrastructure that carried the Chancellor’s communications was American. The vulnerability was American. The detection came from outside Germany.
The software was the problem, and no configuration could change it.[7]
The American model is the deliberate product of specific legal choices, reinforced by institutional architecture, compiled into software that runs on infrastructure the world depends on.
When a European uses American technology, they operate within a constitutional order that treats their data as accessible by design. The surveillance is the system working as intended.
Technology as Control
China built the alternative. It is worse.
The People’s Bank of China’s digital yuan deployed 260 million wallets by 2022.
The system is centralised, closed-source, with what Beijing calls “managed anonymity”: the PBOC controls all vendor access and selectively releases transaction data.[8]
The technical design enables real-time surveillance, account freezing, and travel restrictions tied to payment history. In 2024, citizens in Suzhou discovered their digital yuan wallets had been programmed with expiry dates.
Spend it by this date or lose it.
The government can programme your money. It can make your money expire. It can restrict what you buy, where you buy it, and when.[9]
In January 2026, the PBOC announced the digital yuan would pay interest on holdings.[10] This is a behavioural incentive: users are rewarded for holding money digitally, where it can be monitored, rather than as cash. The form is a feature. The function is control.
The surveillance infrastructure extends beyond finance.
Facial recognition cameras in every major city, linked to a social credit system that rewards compliance and punishes dissent.
A journalist who writes the wrong story loses the ability to buy a train ticket. A lawyer who takes the wrong case finds their children cannot attend university.
The monitoring is total. The consequences are automated.
And it is being exported.
Huawei’s Safe City platform has been deployed in over eighty countries.
Hikvision’s facial recognition cameras have been installed across Africa, Latin America, and Southeast Asia. The digital yuan’s architecture is being studied by central banks in countries that lack the institutional capacity to resist Beijing’s technical assistance.
The Global South is being offered turnkey authoritarianism by a country that has perfected it at home and packaged it for export.[11]
The Chinese model proves that sovereignty alone is not sufficient. China has sovereign digital infrastructure.
It is the most effective system of population control since the invention of the filing cabinet. Sovereignty without values is a cage.
The Specification No One Else Wrote
European law answered a question that no other legal order has addressed: what is technology for?
America’s answer was a business model: collect everything, monetise what you can. China answered with a governance model: monitor everything, automate compliance. Europe wrote a constitutional principle into binding law: technology is for people.
Article 1 of the EU Charter of Fundamental Rights: human dignity is inviolable.
Article 7: the right to respect for private life.
Article 8: the right to protection of personal data, subject to purpose limitation, consent, and independent oversight.
These are constitutional guarantees, binding every institution of the European Union and every member state when implementing Union law.
The origin is specific.
In the Netherlands, a meticulous civil registry recorded every citizen’s religion. When German forces occupied the country in 1940, they seized the records intact.
Seventy-three per cent of Dutch Jews were deported and murdered – the highest rate in Western Europe – because the data existed, was structured, and was accessible.[12]
IBM’s punch card tabulation accelerated the identification.
In East Germany, the Stasi maintained 111 kilometres of files on its own citizens.
When the archives opened in 1991, marriages dissolved and families shattered as people discovered who had been reporting on them for decades.
The constitutions written after liberation – the German Basic Law, the European Convention on Human Rights, and ultimately the EU Charter – encoded privacy and data protection as safeguards against repetition.[13]
The guarantee was written in the specific knowledge of what happens when data is collected without constraint on power.
GDPR was designed to prevent the apparatus of surveillance from being rebuilt, not to regulate corporate data collection, though it does that too.
That is why the right to erasure, the right to access, and the right to object exist. They are instruments of individual agency against structural power.
They are the constitutional expression of a specific historical determination: never again.
No other legal order contains this architecture.
The United States has no federal privacy law.[14] India’s law exempts the government from most of its own provisions. Brazil’s mirrors GDPR in structure but lacks the institutions to enforce it. Japan and South Korea protect data competently.
Neither connects that protection to a constitutional claim about what a person is. Only European law connects privacy to personhood, personhood to dignity, and dignity to an inviolable constitutional guarantee.
This is a European obligation, and one becoming strategically valuable as the world wakes up to needing what European law demands.
The Three Convergences
Three changes converged: power became unpredictable, authoritarian technology went into export, and AI changed what data could be used for. All three made European constitutional privacy more important than at any point since it was written.
Europe has known about American surveillance for decades. The ECHELON revelations of the 1990s. The Snowden disclosures of 2013. Angela Merkel’s personal phone, tapped by the NSA for years.
None of it triggered a fundamental reassessment. Because the unspoken deal held: America watches, but America is our ally.
The surveillance was the price of the relationship. Nobody said it out loud. Everybody paid it.
That deal is now broken.
A sitting American president has threatened to withdraw from NATO. Paper 0 documented what followed: American sanctions targeting the International Criminal Court, Microsoft cancelling the ICC prosecutor’s email, a French judge unable to buy bread because the payment infrastructure runs through New York.
The infrastructure obeyed Washington. It will again.
In January 2025, the Trump administration fired three of five members of the Privacy and Civil Liberties Oversight Board, the body that oversees the EU-US Data Privacy Framework.[15]
The oversight mechanism that made the adequacy decision legally defensible ceased to function. The legal basis for every transatlantic data transfer is now hollow.
The surveillance infrastructure that was built under the assumption of benign power is now operating under the reality of capricious power. The surveillance itself is unchanged. The assumption that it was safe has collapsed.
It is about the eighty-plus countries now purchasing surveillance infrastructure from states that have perfected it at home. Huawei’s Safe City. Hikvision’s cameras. The digital yuan’s programmable money architecture.
NSO Group’s Pegasus, sold with Israeli government approval to Saudi Arabia, the UAE, Morocco, Hungary, Poland, Spain, and others.[16]
The tools that compromise phones, steal elections, and silence journalists are for sale to any government that wants them.
Europe’s citizens have been on the receiving end. The infrastructure that should protect them does not exist.
When your data was sold to advertisers, the cost was annoyance. When your data trains systems that decide your creditworthiness, your insurance, your parole, the cost is your life.
The Netherlands proved the cost in 2020.
The Dutch Tax Authority’s SyRI algorithm – the System Risk Indication – used bulk citizen data to predict welfare fraud.
It flagged 26,000 families. Disproportionately, those families held dual nationality.
Parents were ordered to repay tens of thousands of euros in childcare benefits they had legitimately received. Families lost their homes. Marriages collapsed under the financial pressure.
In February 2020, The Hague District Court ruled SyRI violated Article 8 of the European Convention on Human Rights.[17]
The system had been trained on data collected under the assumption of a social contract. It was deployed as a weapon against the people that contract was supposed to protect.
The harvest-now-decrypt-later problem documented in Paper 5 now has a companion: harvest-now-train-forever. Every dataset collected today will be used by AI systems whose capabilities cannot be predicted. The value of privacy is compounding.
These three convergences are why European constitutional privacy is no longer an abstract legal principle. It is an urgent strategic necessity. The world needs infrastructure where surveillance is architecturally impossible. Europe is the only place that has written this into law.
The Capture Risk
The absence of European assessment creates a vacuum. That vacuum is being filled by institutions that define privacy to suit their own interests.
The precedent is documented.
In 2004, the NSA paid RSA Security ten million dollars to embed a deliberately backdoored random number generator, Dual_EC_DRBG, in a widely deployed encryption product.[18]
Paper 5 documents the precedent.
Europe’s post-quantum cryptographic migration will rely on algorithms selected by the same institution. The definition of “secure” will be written by a standards body with a documented history of compromising its own standards on behalf of American intelligence.
Crypto AG proves the risk predates the digital age.
For forty-eight years – from 1970 to 2018 – the CIA and West German intelligence secretly owned Crypto AG, a Swiss encryption company. Over 120 governments purchased its equipment, believing they were buying Swiss neutrality and Swiss privacy.
They were buying American surveillance.[19] Every “encrypted” communication was readable by Langley.
The operation, codenamed Rubicon, was one of the most successful intelligence operations in history.
It succeeded because nobody checked the mathematics. Nobody verified the encryption. Nobody assessed the product independently.
The register exists so that Crypto AG can never happen again in Europe.
NIST sets cryptographic standards adopted globally.
When NIST defines what counts as privacy-preserving, and American cloud providers certify against NIST standards, and European procurement accepts those certifications, the American definition of privacy becomes the operating definition.
Even when it is weaker than what European constitutional law demands.
Paper 2 asks who controls each layer of the infrastructure stack. The question is different: whether the mathematics underneath those layers is trustworthy. Both questions must be answered independently. A European company can control every layer of its stack and still deploy cryptography that has been compromised at the mathematical level.
The pattern extends to institutions that were supposed to provide alternatives.
Paper 3 documents how Gaia-X ended with AWS, Microsoft, and Google on its board.
The Data Privacy Framework rests on an adequacy decision whose oversight mechanism the current American administration has gutted.
Helen Dixon, former head of the Irish Data Protection Commission – the regulator responsible for supervising Meta, Google, Apple, and Microsoft in Europe – joined Meta’s law firm after leaving office.[20]
The revolving door does not require conspiracy. It only requires incentives.
Privacy is being redefined downward. The label stays. The substance empties out. And Europe has no independent mechanism to verify what “private” actually means in practice.
What Happens When You Do Not Build
The law exists. The infrastructure does not. And in the gap between the two, European citizens are unprotected.
In Greece, the story is worse.
Thanasis Koukakis, a financial journalist investigating corruption at Piraeus Bank, was targeted by his own government.
The national intelligence service placed a legal wiretap on his phone. When Koukakis filed a complaint with the Greek communications authority to identify the wiretap, the intelligence service terminated it the same day, to avoid disclosure.
Predator spyware, manufactured by Intellexa, then took over. Intellexa was founded by Tal Dilian, a former Israeli military intelligence commander who deliberately relocated his operation to European soil – Cyprus, then Greece, then Ireland – specifically to avoid Israeli export controls.
Israeli surveillance expertise, restructured as a European company, sold to European governments, deployed against European citizens.
In February 2026, a Greek court convicted Dilian and three other Intellexa executives. Each received an eight-year sentence, suspended pending appeals.[21]
The first criminal conviction of spyware company executives in history.
Koukakis’s sources fled. His stories died.
The journalism that was supposed to hold a bank accountable was killed by surveillance.
And the technology that did it was operating freely in Europe because no European authority had the mandate, the funding, or the framework to assess it.
In 2019, Israel’s NSO Group sold Pegasus spyware to the Polish government.
In the autumn of that year, with elections approaching, the ruling Law and Justice party deployed it against Krzysztof Brejza, the opposition Civic Platform’s campaign chief.
His phone was compromised. His private messages were extracted.
Polish state television broadcast the stolen communications in the weeks before the vote.
Brejza was never charged with a crime. Poland’s Senate later determined the 2019 election was unfair because of the surveillance.[22]
Israeli tools, purchased by a European government, hacked a phone and stole an election.
No European institution had assessed the spyware. No European body had certified the devices the targets used. No European framework detected the intrusion.
The targeting is systematic.
Morocco targeted the President of France. Saudi Arabia surveilled the associates of Jamal Khashoggi in a chain that led to his murder in Istanbul.[23] Russia’s GRU hacked the German SPD and Chancellor Scholz through a Microsoft Outlook vulnerability in 2024. China’s APT31 targeted European parliamentarians who advocated for Uyghur rights.[24]
In every case, the tools were either Israeli spyware or exploits in American software. In every case, no European assessment had been conducted. In every case, the word “private” on the victim’s phone meant nothing, because nobody had verified that it was true.
The Register
One central recommendation: Europe needs a sovereign register of verified privacy-preserving technologies, centrally funded and independently assessed.
The logic follows directly from the evidence. Pegasus works because nobody assessed the devices European citizens use. Predator operated in Europe because no European authority had the mandate to evaluate it. Crypto AG survived for half a century because nobody independently verified the cryptography.
Any technology that claims to be private – including the homomorphic encryption, zero-knowledge proofs, and secure enclaves discussed below – could be compromised today and no European institution would know.
The register would assess mathematical privacy claims. Does this encryption implementation match its specification? Does this zero-knowledge proof hold under adversarial conditions? Is this homomorphic encryption scheme sound, or does it leak information through side channels? The register checks the mathematics.
The register would be operated by European cryptographic institutions with the mathematical capacity to conduct the assessment.
CWI Amsterdam, home to some of Europe’s strongest cryptographic research, has pioneered work in multiparty computation and provable security. The Aarhus University cryptography group, led by Ivan Damgård and his colleagues, co-invented foundational constructions used in SHA-256 and is among the world’s leading centres for multiparty computation. INRIA, France’s national research institute, maintains deep expertise in formal verification of cryptographic protocols. ANSSI, France’s national cybersecurity agency, maintains Common Criteria evaluation centres and has assessed cryptographic products for government use for decades.
These institutions have the capacity.
They lack the mandate, the funding, and the legal authority to assess the full European market.
Europe’s fragmentation is, for once, an advantage.
Twenty-seven member states means twenty-seven independent verification paths. If France’s ANSSI, Germany’s BSI, and the Netherlands’ CWI all independently verify an algorithm, that is stronger than one NIST process controlled by one institution with a documented history of compromise.
A single standards body is a single point of capture.
Distributed verification across sovereign institutions is resilient by design. This is the same principle that the website Trustless Sovereignty vision document applies to architecture: trustlessness as a security property.
Assessment must be centrally funded.
If the companies being assessed pay for their own certification, the incentive structure is captured from day one.
The register must operate like a European medicines agency for digital privacy: independent, publicly funded, with the authority to approve or reject, and with assessments that carry legal weight in procurement decisions.
No pharmaceutical product can be sold in Europe without EMA approval.
Privacy-preserving technology – on which democratic governance, journalistic integrity, and legal privilege depend – currently requires no European assessment whatsoever. The President of France’s phone was compromised by a product no European institution had evaluated. That is the gap the register fills.
The register would also address the standards capture problem.
When NIST selects post-quantum cryptographic algorithms, European institutions need the independent capacity to verify those selections. When a technology claims zero-knowledge properties, European mathematicians – not American standards bodies, not Israeli defence contractors – need to confirm the proof.
Sovereignty over the definition of privacy is as important as sovereignty over infrastructure. You cannot build a private system on someone else’s definition of private.
The Proof That It Is Buildable
The technology to build a provably different system exists. It is operational.
Fully homomorphic encryption is in production.
Zama, a French company headquartered in Paris, raised one hundred and fifty million dollars to reach a billion-dollar valuation building this technology, and in December 2025 launched on mainnet with live confidential transfers.
The mathematics works as advertised: computation on encrypted data without decrypting it.
A hospital can run diagnostics on patient records without ever seeing them in plaintext. An intelligence agency can search a database without learning its contents.
The data stays private because the mathematics makes it impossible to do otherwise. The code runs in production today.
Zero-knowledge proofs allow one party to prove a statement is true without revealing why it is true. You can prove you are over eighteen without revealing your date of birth. You can prove a transaction is valid without revealing the amount. You can prove compliance without exposing the underlying data. The privacy is the system.
Secure enclaves allow computation in hardware-protected environments that even the operator of the infrastructure cannot access. Data is processed inside a locked box whose contents cannot be read by anyone: not the cloud provider, not the government, not an employee with administrative access.
These three technologies – FHE, ZK proofs, and secure enclaves – represent the most fundamental shift in the architecture of digital privacy since public-key cryptography. Together, they make it possible to build infrastructure where surveillance is prevented by mathematics. Laws can be changed. Proofs cannot.
Europe has commercial proof that values-driven technology creates viable businesses.
Proton – founded by three scientists who met at CERN, the same institution that gave the world the Web – provides encrypted email, storage, VPN, and calendar services to over 100 million users.[25]
The company is profitable.
It is headquartered in Switzerland, structured as a non-profit foundation so that its mission cannot be captured by shareholders.
It was built on a single thesis: European privacy values are a competitive advantage. One hundred million users agreed.
The GDPR itself has demonstrated the market power of European values.
Apple’s App Tracking Transparency – prompted by the regulatory culture GDPR created – wiped ten billion dollars off Meta’s annual revenue.[26]
A European legal principle reshaped the global advertising industry. When Europe enforces its values, the world adjusts. Europe has not yet understood that this means the values have market power.
The digital euro’s design encodes the thesis into payment infrastructure: offline anonymity for small transactions, privacy enforced by cryptography rather than contract.
Paper 14 examines the digital euro in detail. The design choice itself is evidence that European constitutional values can be built into operational systems, not merely written into law.
What Follows
Three models of digital civilisation are available. Only one encodes human dignity.
The American model harvests. The Chinese model controls.
European law demands something different: that technology serves people, that privacy is a right rooted in dignity, and that no entity – state, corporate, or hybrid – may exercise unchecked power over the data that defines a person’s life.
The technology to build this exists.
Homomorphic encryption, zero-knowledge proofs, and secure enclaves make it possible to construct digital infrastructure where surveillance is mathematically impossible.
The commercial proof exists. Proton built a billion-dollar company on European privacy values.
The legal framework exists. No other jurisdiction has Europe’s constitutional architecture.
What does not exist is the infrastructure.
Europe wrote the specification and then bought American systems that violate it every day. It created the world’s strongest privacy law and then stored sixty-seven million medical records on a platform whose own legal director admits he cannot protect them from American government access.
The register – a centrally funded, independently assessed framework for verifying that privacy-preserving technology does what it claims – is the minimum institutional requirement.
Without it, Europe cannot distinguish genuine privacy from marketing. Without it, “sovereign” cloud remains a label on American infrastructure. Without it, the definition of privacy will be written in Washington and adopted in Brussels by default.
Sovereignty without dignity is tyranny.
A sovereign cloud that surveils its citizens is someone else’s model with a European flag.
An AI system that profiles citizens for behavioural modification is authoritarianism compiled into code that happens to run on European servers.
Privacy is the constraint on power that makes sovereignty worth having. European law demands it, European history requires it, and the world is beginning to need what Europe has already written.
Privacy and dignity are not domain-specific concerns.
They are the constraint on power that makes every other right operational. Without architectural enforcement, payments become surveillance, identity becomes tracking, healthcare becomes social control, communications become evidence, and law becomes performance.
These rights underpin every domain in which European constitutional commitment runs ahead of European infrastructure. The principle is general. The architecture is specific to each domain.
Europe is the only civilisation that has answered the question “what is technology for?” in constitutional law. The answer is human dignity. The question now is whether Europe will build the infrastructure to make that answer real, or continue buying someone else’s.
[1] Netzpolitik.org and Bayerischer Rundfunk, “Databroker Files” (July 2024–), in partnership with Le Monde, L’Echo, and BNR Nieuwsradio. The investigation obtained 3.6 billion location records from Datastream Group (Florida) via the Datarade marketplace (Berlin) as a free preview sample. The Macron security detail tracking was published December 2025. Original reporting primarily in German with English-language coverage available at netzpolitik.org/databroker-files/.
[2] Citizen Lab, University of Toronto, “Pegasus Project: Massive Data Leak Reveals Israeli NSO Group’s Spyware Used to Target Activists, Journalists, and Political Leaders Globally,” July 2021. Amnesty International Security Lab independently verified the forensic methodology.
[3] Meta Platforms Inc., Annual Report 2023. Advertising comprised over 97 per cent of total revenue.
[4] Amazon.com Inc., Annual Report 2023. Total net sales of $574.8 billion.
[5] Smith v. Maryland, 442 U.S. 735 (1979). The Supreme Court held that individuals have no reasonable expectation of privacy in information voluntarily disclosed to third parties.
[6] Clarifying Lawful Overseas Use of Data (CLOUD) Act, H.R. 4943, enacted 23 March 2018, amending the Stored Communications Act (18 U.S.C. §2713). FISA Section 702, 50 U.S.C. §1881a, reauthorised April 2024.
[7] German Federal Government, attribution statement on APT28 (GRU Unit 26165) exploitation of Microsoft Outlook vulnerability CVE-2023-23397, May 2024. The vulnerability allowed credential theft via specially crafted calendar invitations.
[8] People’s Bank of China, Digital Yuan (e-CNY) Research and Development Progress Report, published July 2021, updated October 2022. 260 million individual wallets reported by end of 2022.
[9] Reports from Suzhou pilot programme participants, 2024. Digital yuan wallets issued with expiry dates requiring funds to be spent within designated periods.
[10] People’s Bank of China announcement, January 2026. Interest payments on digital yuan holdings designed to incentivise adoption of the central bank digital currency.
[11] Huawei Safe City platform deployments documented across more than eighty countries. Hikvision surveillance camera installations reported across Africa, Latin America, and Southeast Asia. See Feldstein, Steven, “The Global Expansion of AI Surveillance,” Carnegie Endowment for International Peace, 2019.
[12] Croes, Marnix, “The Holocaust in the Netherlands and the Rate of Jewish Survival,” Holocaust and Genocide Studies, 2006. The municipal population registers (Bevolkingsregister) recorded religious affiliation. See also Black, Edwin, IBM and the Holocaust, Crown Publishers, 2001.
[13] Grundgesetz (German Basic Law), Article 1 (human dignity) and Article 2 (right to free development of personality, interpreted to include informational self-determination). European Convention on Human Rights, Article 8 (right to respect for private and family life). EU Charter of Fundamental Rights, Articles 7 and 8.
[14] As of April 2026, the United States has no comprehensive federal data privacy statute equivalent to GDPR. Sector-specific laws include HIPAA (health), COPPA (children), and GLBA (financial services). State-level legislation includes the California Consumer Privacy Act (CCPA/CPRA).
[15] The Privacy and Civil Liberties Oversight Board (PCLOB) lost its quorum in January 2025 following the removal of three members. The PCLOB’s oversight role was a key element of the EU-US Data Privacy Framework adequacy decision (Commission Implementing Decision of 10 July 2023).
[16] Citizen Lab, University of Toronto, multiple investigations 2018-2024. NSO Group’s Pegasus spyware exports require approval from the Israeli Ministry of Defence under Israel’s Defence Export Control Law.
[17] Rechtbank Den Haag, Case C/09/550982 / HA ZA 18-388 (NJCM et al. v. The State of the Netherlands), 5 February 2020. The court found the System Risk Indication (SyRI) legislation insufficiently transparent and disproportionate under Article 8 ECHR.
[18] Reuters, “Exclusive: Secret contract tied NSA and security industry pioneer,” 20 December 2013. The NSA paid RSA Security $10 million to set Dual_EC_DRBG as the default in RSA’s BSAFE cryptographic toolkit.
[19] Washington Post and ZDF, “The intelligence coup of the century,” 11 February 2020. Operation Rubicon (previously Thesaurus): the CIA and BND secretly owned Crypto AG from 1970, with the CIA assuming sole ownership from 1993 until the company’s dissolution in 2018.
[20] Helen Dixon served as Data Protection Commissioner of Ireland from 2014 to 2024. She subsequently joined William Fry, a law firm that has represented Meta Platforms Ireland in data protection proceedings.
[21] Athens Criminal Court, conviction of Tal Dilian and three co-defendants, February 2026, for surveillance of journalist Thanasis Koukakis using Predator spyware manufactured by Intellexa. The first criminal conviction of spyware executives for targeting a journalist.
[22] Senate of the Republic of Poland, report of the extraordinary committee investigating the use of Pegasus spyware, 2022. The committee concluded that the surveillance of opposition figures undermined the fairness of the 2019 parliamentary elections.
[23] Citizen Lab, University of Toronto, investigation into NSO Group’s Pegasus spyware targeting associates of Jamal Khashoggi. Khashoggi was murdered at the Saudi consulate in Istanbul on 2 October 2018.
[24] US Department of Justice, indictment of seven Chinese nationals associated with APT31, March 2024. European targets included members of the Inter-Parliamentary Alliance on China (IPAC) and parliamentarians who had advocated for Uyghur human rights.
[25] Proton AG, founded 2014 by Andy Yen, Jason Stockman, and Wei Sun, who met at CERN. Headquartered in Geneva, structured as a Swiss non-profit foundation. Over 100 million user accounts reported by 2024.
[26] Meta Platforms Inc., Q4 2021 earnings call. CFO David Wehner estimated Apple’s App Tracking Transparency changes would reduce 2022 revenue by approximately $10 billion. ATT was introduced in iOS 14.5, April 2021.
Sign the Manifesto. The eight demands that follow from the case made in this paper and the twenty-seven others. Sign →