WHY PRIVACY MATTERS
You do not need to believe in a malicious government to care about surveillance.
Assume the agency is honest. Assume the employee follows policy. Assume the technology is accurate. There are still questions about scale, permanence, security, sharing, consent, and what power should exist in the first place.
The question is not only whether you have something to hide. It is whether someone else should have something to search.
THE FIRST DISTINCTION
Privacy is not the same thing as secrecy.
Most private things are not crimes. Medical appointments are not crimes. Political organizing is not a crime. Religious attendance is not a crime. Visiting a friend, driving to a protest, meeting a journalist, going to therapy, changing jobs, attending a support group, or spending the night somewhere other than home are all ordinary parts of life.
The privacy question is not whether those acts must be hidden from everyone. It is whether they should become easily searchable, reconstructable, shareable, or permanently attributable through government or commercial systems.
A society can reject criminal conduct while still deciding that lawful life should not automatically produce a searchable behavioral record.
TRUST IS NOT THE WHOLE THREAT MODEL
Good people can operate vulnerable systems.
Privacy debates often get reduced to motive: Do you think the government is trying to hurt you? That is only one possible failure mode.
A sensitive system can expose people through credential theft, phishing, software vulnerabilities, supply-chain compromise, misconfiguration, ransomware, contractor failures, lost devices, insecure integrations, overbroad permissions, or ordinary human mistakes. None of those require a malicious public employee.
Biometric systems make this especially important. A password can be changed. A cryptographic key can be rotated. A face is not a replaceable credential. That does not mean a stolen facial image automatically defeats every biometric system; it means the underlying identifier is persistent, so exposure can create unusually durable risk.
Data minimization is therefore a security control as much as a privacy principle: information that was never collected cannot later leak from that collection.
SCALE CHANGES THE QUESTION
Being visible is not the same as being searchable.
People have always been observable in public. A police officer can see a car. A witness can recognize a face. A camera can record a street. None of those facts, standing alone, are new.
What changes is the ability to index those observations, search them later, connect them across locations, share them between agencies, or combine them with other databases. A task that once required many people and many hours can become a query.
That difference matters because practical anonymity can disappear long before formal secrecy does. A stranger on a sidewalk may see your face without knowing your name. A large biometric or vehicle-tracking system can turn the same observation into an identity or a movement history.
DATA FUSION
The most revealing system may be the connection between systems.
A license-plate reader knows something about a vehicle. A facial-recognition system knows something about an identity. A camera knows something about a place and time. A phone record knows something about a device. A dispatch system knows something about an incident. A commercial database may add addresses, vehicles, associates, or historical records.
Each dataset can look limited in isolation. Combined, they can reveal patterns that no single sensor could produce.
The relevant record therefore includes integrations, sharing rules, exports, APIs, vendor relationships, and secondary dissemination—not only the camera itself.
FUNCTION CREEP
Systems outlive the emergency used to justify them.
A capability may be introduced for a narrow and compelling reason: stolen cars, violent crime, identity fraud, missing persons, or a specific security threat. The original purpose can be legitimate.
The harder question comes later. Once the infrastructure exists, adding a new user, integration, query type, retention period, or purpose can be much easier than building the system from scratch. What began as an exceptional tool can become ordinary infrastructure.
This does not mean expansion is inevitable or always improper. It means expansion should be visible, justified, and independently reviewable rather than treated as a technical detail.
POLICY CHANGES
You are not only trusting today's rules.
A database may be created under one administration, one police chief, one vendor contract, or one interpretation of the law and remain available under the next. Access policies can change. Laws can change. Agency missions can change. Vendors can be acquired. New integrations can appear.
That is why privacy protections should not depend entirely on the belief that the people currently in charge are reasonable. Durable limits matter precisely because institutions persist longer than individual decision-makers.
COMMERCIAL INCENTIVES
Surveillance can also be a market.
Private companies can create genuinely useful tools for government. The problem is not that a vendor earns money.
The concern is that a commercial system introduces incentives that are different from public necessity. More customers, more cameras, more searchable data, more integrations, more features, and longer subscriptions can all be good for the vendor even when the public-interest case for each expansion is weak.
Procurement is part of surveillance policy. Contracts, renewals, grants, data-sharing terms, technical capabilities, retention options, and exit conditions define what public agencies are buying with public money.
LEGITIMATE USES EXIST
Acknowledging benefits makes the privacy argument stronger, not weaker.
A facial-recognition search may help identify the unknown suspect in a murder. An ALPR may help recover a stolen car or find a vehicle connected to an abduction. A camera can document an event more accurately than memory. Data sharing can help one jurisdiction obtain evidence held by another.
Those are not imaginary benefits and NoRec does not need to pretend otherwise.
The disagreement is about proportionality: what population-scale infrastructure should exist to obtain those benefits, how narrowly searches should be authorized, how long innocent people's records should remain, and whether less intrusive alternatives could accomplish the same goal.
THE "NOTHING TO HIDE" TEST
Try applying it to every other kind of information.
Most people who say they have nothing to hide still close the bathroom door. They use passwords. They do not publish their entire bank history. They choose who sees their private messages. They may be perfectly willing to tell one person something they do not want broadcast to everyone.
That is not hypocrisy. Privacy is contextual. Information can be harmless in one context and invasive in another.
The same principle applies to government data. A photograph may be appropriate for issuing an ID. A location may be appropriate for responding to a 911 call. A plate number may be visible on a public road. None of those facts automatically settle every later use of that information.
THE BREACH QUESTION
What happens when the system fails?
The cost of a breach depends partly on how much information existed to steal. A narrowly scoped system with short retention and limited exports creates a different risk than a large historical database with many users and integrations.
Security controls matter. So do architectural choices made before the breach: whether raw data was retained, whether derived biometric templates existed, whether exports were allowed, whether credentials were shared, whether access was logged, and whether old records were ever deleted.
NoRec's position is not that every database will be breached. It is that breach risk belongs in the policy analysis before a sensitive database is created or expanded.
FAP · FREQUENTLY ARGUED POINTS
The arguments people actually make.
FAP What if the agency is trustworthy? Competing considerations
Then evaluate the system on security, scope, oversight, and permanence instead of bad intent. A trustworthy agency can still inherit a vulnerable vendor, an overbroad retention policy, weak credentials, or a future rule change.
FAP Should privacy ever outweigh solving a serious crime? Competing considerations
Sometimes a narrowly targeted search for a grave offense can be justified. The privacy question is not whether investigators should be prevented from using every powerful tool. It is what predicate should be required, what database may be searched, what happens to non-matches, and whether the exceptional case becomes routine practice.
FAP If it's happening in public, isn't it fair game? Competing considerations
Public observation is real, but automation changes scale. Seeing one person once is different from being able to search millions of observations and reconstruct where a person or vehicle has appeared. The policy question is whether technological capability should erase practical anonymity by default.
FAP Would warrants fix the problem? Competing considerations
Warrants can be an important safeguard because they impose a legal predicate and independent review. They do not, by themselves, resolve retention, vendor security, data-sharing, database composition, or what happens to records belonging to people who were never the target of a warrant.
FAP If the technology becomes perfectly accurate, is there still a privacy issue? Competing considerations
Yes, but it is a different issue. Perfect accuracy would remove the false-match objection. It would not answer whether everyone should be identifiable everywhere, whether every appearance should be searchable later, or whether a government should maintain the infrastructure required to do that.
FAP Isn't deletion enough? Competing considerations
Deletion is one of the most useful privacy controls when it is real, timely, and verifiable. The remaining questions are how long data exists before deletion, whether backups or exports persist, whether another recipient kept a copy, and whether deletion rules can be changed later.
NOREC'S POSITION
Use the least surveillance necessary for a demonstrated need.
NoRec.US is not asking readers to assume the worst about every institution. It is asking institutions to justify powerful systems before those systems become ordinary.
Collect less. Retain less. Share less. Require a real purpose. Log access. Audit it. Publish the rules. Make expansion visible. Delete data when the purpose is over. And where a capability is not necessary or proportionate, do not build it merely because technology makes it possible.