Skip to content
recaplica

    One moment: security check

    Cloudflare wants to make sure you're not a robot. Tick the box below and your search will continue on its own.

    IT
    recaplica Mass Surveillance: What It Is and How It Clashes With Human Rights
    © 2026 Recaplica · recaplica.com — All rights reserved
    Home › Civics

    Mass Surveillance: What It Is and How It Clashes With Human Rights

    By Recaplica Newsroom · Updated on September 19, 2026

    What to print

    Page numbers appear when printing with default margins.

    Slides

    Choose a cut

    Flash10 slidesThe essential thread, to present in classFull14 slidesEvery chapter and the deeper detail

    Both come with speaker notes.

    Telegram channel
    recaplica Clear in 30 seconds, yours in 10 minutes.
    In 30 seconds Key points Figures Deep dive Slides Myths Mind map Quiz Flashcards FAQ

    In 30 seconds quick read

    Mass surveillance means monitoring an entire population, or a large part of it, with no specific suspect in mind: it does not target individuals, it collects data on everyone. Governments use it through bulk interception of communications, facial recognition on public streets and spyware such as Pegasus, while private companies gather and resell personal data on a similar scale. The European Court of Human Rights does not ban the practice outright, but it demands strict safeguards against abuse, and the GDPR requires companies to collect only the data they actually need. Where those limits are missing, mass surveillance collides with privacy, freedom of expression and, for anyone monitored without knowing it, the presumption of innocence.

    Key Points

    • Mass surveillance collects data on entire populations rather than individual suspects: that is what separates it from a targeted investigation.
    • It covers very different techniques, from bulk interception of communications to indiscriminate facial recognition and spyware such as Pegasus.
    • It isn't only a government tool: private companies also gather and process data at scale, which is why the GDPR reaches corporate surveillance too.
    • The European Court of Human Rights allows bulk interception regimes only with independent, proportionate safeguards; without them, they breach Article 8 of the Convention.
    • In Roman Zakharov v. Russia, the Court ruled that a law lacking adequate oversight is enough to establish a violation, even without proof that a specific interception took place.
    • Internet shutdowns are a form of mass control that often runs alongside data surveillance: at least 313 were recorded across 52 countries in 2025.

    Key figures

    • 313 shutdowns At least 313 internet shutdowns imposed across 52 countries in 2025, the highest number recorded since 2016. Source: Access Now, KeepItOn report 2025
    • €1.2 billion GDPR fine imposed on Meta Platforms Ireland in 2023 over EU-US data transfers found to lack adequate safeguards, the largest GDPR penalty issued up to that point. Source: EDPB and Irish Data Protection Commission, 2023

    Deep Dive

    Mass surveillance is not a recent invention or a purely military phenomenon: it is a way of collecting data that has settled into city streets, phone networks and the smartphones of billions of people. According to Privacy International, what defines it is not the technology used, but the fact that it reaches an indefinite or large number of people instead of limiting itself to those reasonably suspected of a crime. It is the difference between a targeted investigation, which follows a specific suspect, and a system that watches everyone to find someone.

    The techniques that fall under this definition are varied. There is bulk interception of communications and access to the data telecom operators store on their users; there is mass hacking; there is indiscriminate facial recognition, installed in public spaces without passersby knowing; there is tracking phones at protests through devices such as IMSI catchers. The New York Police Department, for instance, uses facial recognition software, automatic license plate readers and vans fitted with X-ray scanners to identify possible threats. On the commercial side, the company Clearview AI has built a facial recognition database also used in partnership with Ukraine, while Pegasus spyware allows deep intrusion into people’s phones.

    Real-world example: a facial recognition camera installed in a public square doesn’t just record whoever is committing a crime. It records everyone who crosses that square, every day, for years. The same principle makes a deepfake or a disinformation campaign hard to contain once it spreads: it’s the scale of the system, not the intent behind any single case, that creates the risk.

    On the government side, mass surveillance collides directly with the European Convention on Human Rights. The European Court of Human Rights, in the Grand Chamber judgment Big Brother Watch and Others v. the United Kingdom of 25 May 2021, clarified a central point: a bulk interception regime is not in itself incompatible with the Convention, but to be lawful it must have detailed, effective safeguards of necessity and proportionality. In the case at hand, the United Kingdom’s bulk interception regime (Section 8(4) of RIPA) and its regime for acquiring communications data (Chapter II of RIPA) were both found wanting on exactly that point, breaching Article 8 of the Convention, the article that protects private life. The Court also found a breach of Article 10, on freedom of expression, because neither regime offered sufficient safeguards to protect journalists’ confidential communications: protecting journalistic sources, the Court wrote, is one of the cornerstones of press freedom. Five judges, in separate opinions, criticised the ruling for not going far enough, arguing that judicial authorisation should be mandatory for bulk interception.

    An earlier Grand Chamber case shows how little proof the Court can require to find a violation. In Roman Zakharov v. Russia, decided on 4 December 2015, the Court examined a system that legally required Russian mobile network operators to install equipment allowing law enforcement to intercept communications. It ruled that the mere existence of that legislation, lacking adequate safeguards against arbitrariness, already amounted to an interference with Article 8: there was no need to prove that a specific person had actually been intercepted. Among the factors in the Court’s reasoning was that a secret surveillance system set up to protect national security risks undermining, rather than defending, the very democracy it is meant to protect, if left without controls.

    On the side of individual rights, the Pegasus spyware case shows that mass surveillance is not only a problem for distant authoritarian governments. In July 2021, responding to revelations from what became known as the Pegasus Project, then UN High Commissioner for Human Rights Michelle Bachelet called the widespread use of the spyware “extremely alarming,” noting that programs such as Pegasus and one developed by Candiru enable extremely deep intrusions into people’s devices, reaching insights into nearly every aspect of their lives. According to the OHCHR, the use of surveillance software has been linked to arrests, intimidation and even killings of journalists and human rights defenders, and several parts of the UN human rights system have flagged the risk of authorities using tools built for public safety to hack the phones of people doing legitimate journalism, monitoring human rights or expressing political dissent.

    Mass surveillance is not only about collecting data: in some cases it turns into a direct break in communication. According to the Internet Shutdowns in 2025 report from the #KeepItOn coalition, led by Access Now, at least 313 internet shutdowns were implemented across 52 countries in 2025, the highest number recorded since 2016. In Eastern Europe and Central Asia alone, the network was cut 29 times across 7 countries. The report describes a trend that is rising, not falling, with an impact that reaches from work and school to medical care and banking. Shutdowns often accompany protests or elections, at the same moment a government also steps up data monitoring: two different tools aimed at the same goal, controlling what happens to a population.

    On the commercial side, the main regulatory barrier in Europe is the General Data Protection Regulation (GDPR), in force since 25 May 2018. Article 5 of the regulation requires personal data to be processed lawfully, fairly and transparently, collected only for specified and explicit purposes, and, above all, limited to what is necessary for those purposes: the principle of data minimisation, which runs directly against a form of surveillance built to leave no one out, regardless of individual suspicion. The regulation also imposes an accountability principle: whoever processes the data must be able to demonstrate that they follow these rules. That the GDPR is more than a paperwork exercise is shown by the penalty decided by the European Data Protection Board (EDPB) and made enforceable by the Irish Data Protection Commission: €1.2 billion against Meta Platforms Ireland, in 2023, for transferring EU users’ data to the United States on the basis of contractual clauses the Court of Justice of the European Union had found insufficient. EDPB chair Andrea Jelinek called Meta’s infringement “very serious,” since it involved transfers that were systematic, repetitive and continuous; it is the highest GDPR fine issued up to that point, surpassing the previous record of €746 million against Amazon, issued by Luxembourg’s data protection authority (CNPD) in 2021.

    What emerges from these cases isn’t a technical problem to leave to lawyers and engineers. It touches the freedom of movement of anyone who knows they could be caught on camera in any public square, the freedom of speech of anyone whose journalistic sources risk being exposed, and the presumption of innocence of anyone who ends up in a database built to catch a few suspects and instead includes everyone. Understanding how the internet and communication networks work helps clarify where this data actually travels; telling verified information apart from disinformation, as with fake news, helps weigh the alarms (and the reassurances) that circulate around these issues with more care. The EU’s newer rules on artificial intelligence, the AI Act, also reach some of the technologies used for surveillance, such as real-time facial recognition in public spaces. And the procedural safeguards the European Court of Human Rights demands from surveillance regimes, such as independent oversight and limits on state power, are the same questions the Italian Constitution addresses when it defines the boundaries of state action toward citizens.

    Slide deck

    Slides ready to download and make your own in PowerPoint or Google Slides, with speaker notes. Pick the Flash cut or the Full one.

    Slide 1 of the presentation on Mass Surveillance: Mass SurveillanceSlide 2 of the presentation on Mass Surveillance: What is mass surveillance?Slide 3 of the presentation on Mass Surveillance: Coming upSlide 4 of the presentation on Mass Surveillance: Chapter 01: What it isSlide 5 of the presentation on Mass Surveillance: Interception · Facial recognition · SpywareSlide 6 of the presentation on Mass Surveillance: Chapter 02: The techniquesSlide 7 of the presentation on Mass Surveillance: Who uses it: NYPD, Clearview AI, PegasusSlide 8 of the presentation on Mass Surveillance: If you haven't done anything wrong, you have nothing to worry aboutSlide 9 of the presentation on Mass Surveillance: Chapter 03: The rights at stakeSlide 10 of the presentation on Mass Surveillance: What the European Court of Human Rights saysSlide 11 of the presentation on Mass Surveillance: Chapter 04: The European rulesSlide 12 of the presentation on Mass Surveillance: Two numbersSlide 13 of the presentation on Mass Surveillance: What separates mass surveillance from a targeted investigation of a single suspect?Slide 14 of the presentation on Mass Surveillance: Learn more
    Flash10 slidesThe essential thread, to present in classFull14 slidesEvery chapter and the deeper detail

    Common myths

    • ✗ Myth Mass surveillance is always illegal in Europe.

      ✓ Reality The European Court of Human Rights does not ban bulk interception regimes outright. In Big Brother Watch and Others v. the United Kingdom, decided in 2021, it allowed them on condition that detailed, effective safeguards of proportionality and independent oversight exist. Strip away those safeguards, and the same technique becomes unlawful.

    • ✗ Myth If you haven't done anything wrong, you have nothing to worry about.

      ✓ Reality In Roman Zakharov v. Russia, decided in 2015, the Court held that the mere existence of a surveillance law lacking adequate safeguards is enough to breach Article 8, even when nobody proves that a given person was ever intercepted: the risk falls on anyone covered by the system, not only on those with something to hide.

    • ✗ Myth Spyware like Pegasus is only used against criminals and terrorists.

      ✓ Reality According to the UN Human Rights Office, the 2021 revelations of the Pegasus Project showed it used against journalists, human rights defenders, politicians and opposition figures as well, not only against suspects in serious crimes.

    Mind map

    Drag the background to move around and the nodes to reposition them; use − and + to collapse and expand branches.

    Customize
    Mind map: Mass Surveillance: What It Is and How It Clashes With Human Rights
    • Mass surveillance
      • What it is
        • Definition Indiscriminate data collection on a population, with no specific suspect
        • Government surveillance Interception, facial recognition, spyware
        • Corporate surveillance Private companies collecting and reselling data
      • Techniques
        • Interception of communications
        • Indiscriminate facial recognition
        • Spyware
        • Internet shutdowns
      • Rights at stake
        • Privacy Article 8 of the European Convention on Human Rights
        • Freedom of expression Protection of journalistic sources
        • Presumption of innocence Monitoring without individual suspicion
      • Legal framework
        • European Court of Human Rights
          • Big Brother Watch v. UK, 2021
          • Roman Zakharov v. Russia, 2015
        • GDPR
          • Data minimisation
          • Fine against Meta, 2023

    Quiz: test yourself

    Answer the questions to check what you have learned: you get instant feedback and a short explanation.

    Grade 0/10 0/5
    1 According to Privacy International's definition, what distinguishes mass surveillance from targeted surveillance?

    Mass surveillance collects data on an indefinite or large number of people instead of limiting itself to those reasonably suspected of a crime: that is the distinguishing criterion, not the technology used or how secret it is.

    2 In Big Brother Watch and Others v. the United Kingdom (2021), the European Court of Human Rights ruled that bulk interception regimes...

    The Court accepted that a bulk interception regime is not in itself incompatible with the Convention, but to be lawful it must have detailed, effective safeguards of necessity and proportionality; in the UK's case, those safeguards were found lacking.

    3 What did the European Court of Human Rights rule in Roman Zakharov v. Russia (2015)?

    The Court found that the mere existence of the contested legislation, lacking effective remedies against arbitrariness, already amounted to an interference with the right to private life, without any need to prove that an interception had actually happened.

    4 True or false: the GDPR applies only to government surveillance, not to surveillance by private companies.

    False: the GDPR governs the processing of personal data by anyone who collects it, including private companies. That is exactly why it led to a €1.2 billion fine against Meta Platforms Ireland in 2023.

    5 According to the Access Now / #KeepItOn report, what happened with internet shutdowns in 2025?

    The report counts at least 313 shutdowns in 52 countries in 2025, the highest number since 2016; Eastern Europe and Central Asia, with 29 shutdowns in 7 countries, is only one of the regions involved, not the only one.

    Answers: 1-B · 2-B · 3-B · 4-B · 5-B

    Flashcards

    Tap the card to flip it and check whether you remember the answer, then move to the next one.

    1 / 8

    Explain it in your own words

    The ultimate test: if you can explain it in simple words, you've truly understood it. Write your explanation, then compare it with the Recap.

    Your explanation is saved only on this device.

    Mass surveillance means monitoring an entire population, or a large part of it, with no specific suspect in mind: it does not target individuals, it collects data on everyone. Governments use it through bulk interception of communications, facial recognition on public streets and spyware such as Pegasus, while private companies gather and resell personal data on a similar scale. The European Court of Human Rights does not ban the practice outright, but it demands strict safeguards against abuse, and the GDPR requires companies to collect only the data they actually need. Where those limits are missing, mass surveillance collides with privacy, freedom of expression and, for anyone monitored without knowing it, the presumption of innocence.

    Frequently asked questions

    What is mass surveillance?

    It is the indiscriminate monitoring of a population, or a large part of it, collecting data on an indefinite or large number of people instead of limiting itself to someone suspected of a specific crime. It can be run by governments, through interception, facial recognition and spyware, or by private companies that collect and resell data.

    Is mass surveillance legal?

    It depends on the safeguards attached to it. The European Court of Human Rights does not ban it outright, but requires detailed, effective rules against abuse, proportionality and independent oversight; without those safeguards, as in the United Kingdom's case in 2021, a surveillance regime breaches the Convention.

    What is Pegasus spyware?

    A surveillance program that enables deep intrusion into people's devices, reaching information on nearly every aspect of their lives. According to the UN Human Rights Office, the 2021 revelations showed it used against journalists, human rights defenders, politicians and opposition figures.

    How does the GDPR protect against corporate surveillance?

    It requires anyone processing personal data to collect only what is necessary for a stated purpose, to handle it lawfully and transparently, and to be accountable for those choices. Companies that break these rules risk severe penalties, such as the €1.2 billion fine imposed on Meta in 2023.

    What are internet shutdowns and how do they relate to mass surveillance?

    They are direct government-imposed interruptions of internet access, often during protests or elections: according to Access Now, at least 313 were recorded in 52 countries in 2025. They frequently accompany data surveillance, since cutting the network and monitoring it are two different ways of controlling what happens to a population.

    Sources

    • Privacy International — Mass Surveillance
    • European Court of Human Rights — Big Brother Watch and Others v. the United Kingdom (Grand Chamber)
    • European Court of Human Rights — Roman Zakharov v. Russia (Grand Chamber)
    • OHCHR — Statement by High Commissioner Bachelet on Pegasus spyware
    • Access Now — #KeepItOn, Internet Shutdowns in 2025
    • GDPR — Regulation (EU) 2016/679, Article 5
    • EDPB — Binding decision and fine against Meta Platforms Ireland
    • CNPD (Luxembourg) — GDPR fine against Amazon Europe Core, €746 million (2021)

    Every Recap goes through an independent review before publication.

    Every evening, the day's new Recaps on our Telegram channel. Join the channel →

    Keep learning

    • Civics Credible Sources for Research: the CRAAP Test, Step by Step Not every source that turns up in a search engine belongs in a research paper, a school assignment or a thesis. The CRAAP test breaks the question into five checks, currency, relevance, authority, accuracy and purpose, that a student can run on any source before citing it. It also helps separate a primary source, the original document, from a secondary one that comments on it, and clarifies that Google Scholar applies no peer-review filter to the results it returns. Curated databases such as Scopus and Web of Science, by contrast, flag peer review at the journal level. With these tools a student can judge a source on its merits instead of trusting whatever ranks first. Read the Recap →
    • Civics SPID Digital Signature: Italy's Advanced Electronic Signature, Explained Since 2020, Italian law has allowed a real 'signature with SPID': a button on a public body's or company's website that lets someone sign a document with the same legal weight as a handwritten signature, without needing a separate qualified digital signature. In practice, though, this free and direct service is offered almost only to public bodies and partner companies, not to a private citizen who wants to sign a contract on their own. What providers like InfoCert and Poste sell to the public as 'digital signature with SPID' is usually something else entirely: SPID used just to verify identity, then a separate qualified digital signature, often paid. Knowing the difference keeps people from paying for a product they assume is the free one the guidelines describe. Read the Recap →
    • Civics Media Literacy: What It Is and How to Judge a Source's Credibility Media literacy is the set of skills that lets people read, judge, and use articles, websites, and encyclopedia entries with a critical eye. The University of Chicago Library lists five practical criteria for judging a source: currency, relevance, authority, accuracy, and purpose. FactCheck.org published an eight-step method for spotting fabricated news in 2016, later translated and distributed worldwide by IFLA. Wikipedia works the same way, with reliability resting on the quality of the sources cited in its footnotes. Read the Recap →

    recaplica

    Clear in 30 seconds, yours in 10 minutes.

    Recaps Mind maps Request a Recap Telegram channel Mind map maker Our method About Privacy & cookies Legal notes & terms of use

    © 2026 Recaplica · A project by Curi S.r.l. — VAT IT05472000750

    Statistics, only if you say so

    To learn which Recaps help most we would use Google Analytics, with aggregate, anonymous data. It starts only with your OK, and you can change your mind anytime. Privacy policy