|
recaplica
Mass Surveillance: What It Is and How It Clashes With Human Rights |
| © 2026 Recaplica · recaplica.com — All rights reserved |
Mass Surveillance: What It Is and How It Clashes With Human RightsWhat to print Page numbers appear when printing with default margins. SlidesChoose a cut Flash10 slidesThe essential thread, to present in classFull14 slidesEvery chapter and the deeper detailBoth come with speaker notes. In 30 seconds quick readMass surveillance means monitoring an entire population, or a large part of it, with no specific suspect in mind: it does not target individuals, it collects data on everyone. Governments use it through bulk interception of communications, facial recognition on public streets and spyware such as Pegasus, while private companies gather and resell personal data on a similar scale. The European Court of Human Rights does not ban the practice outright, but it demands strict safeguards against abuse, and the GDPR requires companies to collect only the data they actually need. Where those limits are missing, mass surveillance collides with privacy, freedom of expression and, for anyone monitored without knowing it, the presumption of innocence. Key Points
Key figures
Deep DiveMass surveillance is not a recent invention or a purely military phenomenon: it is a way of collecting data that has settled into city streets, phone networks and the smartphones of billions of people. According to Privacy International, what defines it is not the technology used, but the fact that it reaches an indefinite or large number of people instead of limiting itself to those reasonably suspected of a crime. It is the difference between a targeted investigation, which follows a specific suspect, and a system that watches everyone to find someone. The techniques that fall under this definition are varied. There is bulk interception of communications and access to the data telecom operators store on their users; there is mass hacking; there is indiscriminate facial recognition, installed in public spaces without passersby knowing; there is tracking phones at protests through devices such as IMSI catchers. The New York Police Department, for instance, uses facial recognition software, automatic license plate readers and vans fitted with X-ray scanners to identify possible threats. On the commercial side, the company Clearview AI has built a facial recognition database also used in partnership with Ukraine, while Pegasus spyware allows deep intrusion into people’s phones.
On the government side, mass surveillance collides directly with the European Convention on Human Rights. The European Court of Human Rights, in the Grand Chamber judgment Big Brother Watch and Others v. the United Kingdom of 25 May 2021, clarified a central point: a bulk interception regime is not in itself incompatible with the Convention, but to be lawful it must have detailed, effective safeguards of necessity and proportionality. In the case at hand, the United Kingdom’s bulk interception regime (Section 8(4) of RIPA) and its regime for acquiring communications data (Chapter II of RIPA) were both found wanting on exactly that point, breaching Article 8 of the Convention, the article that protects private life. The Court also found a breach of Article 10, on freedom of expression, because neither regime offered sufficient safeguards to protect journalists’ confidential communications: protecting journalistic sources, the Court wrote, is one of the cornerstones of press freedom. Five judges, in separate opinions, criticised the ruling for not going far enough, arguing that judicial authorisation should be mandatory for bulk interception. An earlier Grand Chamber case shows how little proof the Court can require to find a violation. In Roman Zakharov v. Russia, decided on 4 December 2015, the Court examined a system that legally required Russian mobile network operators to install equipment allowing law enforcement to intercept communications. It ruled that the mere existence of that legislation, lacking adequate safeguards against arbitrariness, already amounted to an interference with Article 8: there was no need to prove that a specific person had actually been intercepted. Among the factors in the Court’s reasoning was that a secret surveillance system set up to protect national security risks undermining, rather than defending, the very democracy it is meant to protect, if left without controls. On the side of individual rights, the Pegasus spyware case shows that mass surveillance is not only a problem for distant authoritarian governments. In July 2021, responding to revelations from what became known as the Pegasus Project, then UN High Commissioner for Human Rights Michelle Bachelet called the widespread use of the spyware “extremely alarming,” noting that programs such as Pegasus and one developed by Candiru enable extremely deep intrusions into people’s devices, reaching insights into nearly every aspect of their lives. According to the OHCHR, the use of surveillance software has been linked to arrests, intimidation and even killings of journalists and human rights defenders, and several parts of the UN human rights system have flagged the risk of authorities using tools built for public safety to hack the phones of people doing legitimate journalism, monitoring human rights or expressing political dissent. Mass surveillance is not only about collecting data: in some cases it turns into a direct break in communication. According to the Internet Shutdowns in 2025 report from the #KeepItOn coalition, led by Access Now, at least 313 internet shutdowns were implemented across 52 countries in 2025, the highest number recorded since 2016. In Eastern Europe and Central Asia alone, the network was cut 29 times across 7 countries. The report describes a trend that is rising, not falling, with an impact that reaches from work and school to medical care and banking. Shutdowns often accompany protests or elections, at the same moment a government also steps up data monitoring: two different tools aimed at the same goal, controlling what happens to a population. On the commercial side, the main regulatory barrier in Europe is the General Data Protection Regulation (GDPR), in force since 25 May 2018. Article 5 of the regulation requires personal data to be processed lawfully, fairly and transparently, collected only for specified and explicit purposes, and, above all, limited to what is necessary for those purposes: the principle of data minimisation, which runs directly against a form of surveillance built to leave no one out, regardless of individual suspicion. The regulation also imposes an accountability principle: whoever processes the data must be able to demonstrate that they follow these rules. That the GDPR is more than a paperwork exercise is shown by the penalty decided by the European Data Protection Board (EDPB) and made enforceable by the Irish Data Protection Commission: €1.2 billion against Meta Platforms Ireland, in 2023, for transferring EU users’ data to the United States on the basis of contractual clauses the Court of Justice of the European Union had found insufficient. EDPB chair Andrea Jelinek called Meta’s infringement “very serious,” since it involved transfers that were systematic, repetitive and continuous; it is the highest GDPR fine issued up to that point, surpassing the previous record of €746 million against Amazon, issued by Luxembourg’s data protection authority (CNPD) in 2021. What emerges from these cases isn’t a technical problem to leave to lawyers and engineers. It touches the freedom of movement of anyone who knows they could be caught on camera in any public square, the freedom of speech of anyone whose journalistic sources risk being exposed, and the presumption of innocence of anyone who ends up in a database built to catch a few suspects and instead includes everyone. Understanding how the internet and communication networks work helps clarify where this data actually travels; telling verified information apart from disinformation, as with fake news, helps weigh the alarms (and the reassurances) that circulate around these issues with more care. The EU’s newer rules on artificial intelligence, the AI Act, also reach some of the technologies used for surveillance, such as real-time facial recognition in public spaces. And the procedural safeguards the European Court of Human Rights demands from surveillance regimes, such as independent oversight and limits on state power, are the same questions the Italian Constitution addresses when it defines the boundaries of state action toward citizens. Slide deckSlides ready to download and make your own in PowerPoint or Google Slides, with speaker notes. Pick the Flash cut or the Full one. ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Common myths
Mind mapDrag the background to move around and the nodes to reposition them; use − and + to collapse and expand branches.
Quiz: test yourselfAnswer the questions to check what you have learned: you get instant feedback and a short explanation. Grade 0/10 0/5
FlashcardsTap the card to flip it and check whether you remember the answer, then move to the next one. 1 / 8 Explain it in your own wordsThe ultimate test: if you can explain it in simple words, you've truly understood it. Write your explanation, then compare it with the Recap. Your explanation is saved only on this device.
Frequently asked questionsWhat is mass surveillance?It is the indiscriminate monitoring of a population, or a large part of it, collecting data on an indefinite or large number of people instead of limiting itself to someone suspected of a specific crime. It can be run by governments, through interception, facial recognition and spyware, or by private companies that collect and resell data. Is mass surveillance legal?It depends on the safeguards attached to it. The European Court of Human Rights does not ban it outright, but requires detailed, effective rules against abuse, proportionality and independent oversight; without those safeguards, as in the United Kingdom's case in 2021, a surveillance regime breaches the Convention. What is Pegasus spyware?A surveillance program that enables deep intrusion into people's devices, reaching information on nearly every aspect of their lives. According to the UN Human Rights Office, the 2021 revelations showed it used against journalists, human rights defenders, politicians and opposition figures. How does the GDPR protect against corporate surveillance?It requires anyone processing personal data to collect only what is necessary for a stated purpose, to handle it lawfully and transparently, and to be accountable for those choices. Companies that break these rules risk severe penalties, such as the €1.2 billion fine imposed on Meta in 2023. What are internet shutdowns and how do they relate to mass surveillance?They are direct government-imposed interruptions of internet access, often during protests or elections: according to Access Now, at least 313 were recorded in 52 countries in 2025. They frequently accompany data surveillance, since cutting the network and monitoring it are two different ways of controlling what happens to a population. Every Recap goes through an independent review before publication. |












