Module 04 / 14 · Phase 2 — Architecture: law, technology, and the human cost
4. Privacy-enhancing technology and its human limits
This week in the arc
Coming from
Week 3 killed the social fix: “I agree” doesn’t protect you. So people reach for the technical fix instead.
Going to
Week 5 — data brokers: the first look at the machinery as an industry, not a choice you made. The first step toward the structural question this week opens.
Core
Last week we buried consent — the idea that agreeing protects you. When people accept that, they reach for the next hope almost immediately: the technology will protect me. The data is anonymized. There’s encryption. There are privacy tools. This week we test that hope.
Here’s the honest version, because the crude version (“anonymization is a scam”) isn’t true and won’t survive a smart room: these tools work exactly as designed. Anonymization really does strip your name. Encryption really does protect data in transit. The problem is that the protection they deliver is not the protection you think you’re getting. Strip the names off a dataset and you are still in it — because you can be picked out from the pattern of everything else. That’s re-identification, and it has been demonstrated, repeatedly, for over two decades.
So we’ll watch “anonymized equals safe” — maybe the most common false comfort in this entire field — come apart on real cases. But the deeper work of the night comes after. Because if you step back, something connects every failure we’ve seen: consent, anonymization, privacy tools — every fix has been something you do alone. And every one has failed. The question that opens the rest of this course is whether that’s a coincidence, or whether privacy was never something a single person could secure in the first place.
Cases — tagged by category, name the kind before you react
A state released “anonymized” hospital records for research — names and addresses removed. A researcher re-identified the state governor’s own records by cross-referencing them with public voter rolls, using nothing but ZIP code, birth date, and sex. That same trio uniquely identifies the large majority of Americans. The names were gone. The people weren’t.
A streaming company released 100 million “anonymized” movie ratings for a public contest. Researchers re-identified specific users by matching the ratings against public reviews elsewhere — potentially exposing sensitive facts a person never disclosed. The dataset was scrubbed of identity. Identity came back anyway.
Reading
Discussion
- Before tonight: did you believe 'anonymized' data was safe? What did you think it meant?
- The tools did exactly what they promised. So where, precisely, did the protection fail — the technology, or what we expected of it?
- Every solution we've studied — reading the agreement, anonymizing, protecting yourself — is something an individual does. What if that's the pattern that matters?