The Digital Whale

Privacy and security

What people know about online privacy

Public privacy knowledge is low and measured concern is high, but the gap between the two is smaller than the "privacy paradox" story suggests.

Public understanding of online privacy is thin, stated concern is high, and the technical picture has not moved in the public's favour. The strongest population evidence is a set of Pew Research Center surveys from 2023: a minority of US adults can answer simple factual questions about privacy and security, most agree to policies they have not read, and 81% say they worry that companies will use collected data in ways they would not be comfortable with, with 71% concerned about government use, up from 64% in 2019 (Pew Research Center, 2023). The much-repeated claim that concern and behaviour are unrelated does not survive careful longitudinal testing — the relationship is real, just small. Third-party tracking remains near-universal, and Google's plan to remove third-party cookies from Chrome was abandoned in 2024. For a concrete commercial example of the monitoring category discussed here, see this page.

Most people fail a five-question privacy quiz

Pew asked a probability panel of US adults five factual questions about privacy and cybersecurity in May 2023. It is a crude instrument — five items cannot capture what someone understands about data flows — but it is the only recent measure of its kind on a properly sampled population. Knowledge of how account security actually works is patchy in the same way.

2023

Only 21% of US adults correctly answered at least four of five basic privacy and cybersecurity knowledge questions, and 24% got no more than one right.

Direction: Decrease. Strength of evidence: Strong.

Pew Research Center, "How Americans' online privacy choices relate to their knowledge, tech confidence and data concerns", 20235,101 US adults, probability panel, fielded 15-21 May 2023

Caveat US-only, and a five-item quiz is a crude proxy for real-world privacy literacy.

The consent model assumes people read what they agree to. They report that they do not, and they also report that the documents would not help if they did.

2023

56% of US adults say they always, almost always or often click "agree" to privacy policies without reading them, and 61% say privacy policies fail to explain how companies use data.

Direction: Increase. Strength of evidence: Strong.

Pew Research Center, "How Americans feel about and manage data privacy: Key findings", 20235,101 US adults, probability panel

Caveat Self-reported behaviour, which typically understates non-reading, with no observational validation.

The arithmetic behind this has been laid out once, badly and famously. McDonald and Cranor's 2008 paper The Cost of Reading Privacy Policies estimated roughly ten minutes per policy across documents averaging about 2,500 words, and converted the national time cost into a figure in the hundreds of billions of dollars a year. Treat that dollar total as illustrative only: it dates from 2008, it models browsing rather than observing it, and the authors' own conference and journal versions differ by more than $100 billion. The same weakness runs through much of what circulates as privacy fact, which is why checking a source before repeating it matters more here than in most subjects.

The privacy paradox is weaker than its reputation

The standard claim is that people say they care about privacy and then behave as though they do not. A three-wave German panel study tested this properly, separating differences between people from changes within the same person over time.

2021

Privacy concern and self-disclosure are modestly but genuinely aligned, at beta = -.09 between persons and beta = -.10 within persons.

Direction: Decrease. Strength of evidence: Mixed.

Dienlin, Masur & Trepte, New Media & Society, 20211,403 German respondents, three survey waves, 2014-2015

Caveat Mean respondent age 54, social media disclosure only, small effects and no lagged effects over six months.

An effect that size means concern nudges behaviour rather than governing it. There is no paradox, only a weak relationship described as a contradiction because people expected it to be strong.

Whatever readers absorbed from four years of adtech coverage, the measured web has not changed much.

2025

75% of desktop and 74% of mobile home pages carry at least one third-party tracker, with Google-owned trackers on 61% of sites and Facebook on 22%.

Direction: Increase. Strength of evidence: Strong.

HTTP Archive, Web Almanac 2025, Privacy chapter, 2025Crawl of desktop and mobile home pages, WhoTracks.Me taxonomy

Caveat Crawler measurement from a US vantage point on home pages only, so it undercounts EU-specific behaviour and deeper-page tracking.

The primary record on cookies is clear and comes from the interested party itself. In July 2024 Google abandoned third-party cookie deprecation in Chrome, saying it would offer users "a new experience in Chrome that lets people make an informed choice" instead; that prompt was later dropped too. On 17 October 2025 Google announced it was retiring the core Privacy Sandbox technologies, including Topics, Protected Audience and Attribution Reporting, without publishing sunset dates (Google, 2025). Third-party cookies remain the Chrome default, which shapes what a personal data trail contains.

European fines are large, American ones are not

Enforcement totals are worth citing carefully, because no regulator publishes an authoritative aggregate.

2026

2,685 GDPR fines totalling roughly EUR 6.11 billion had been recorded, an average of EUR 2.28 million per fine, with Spain issuing the most at 1,048.

Direction: Increase. Strength of evidence: Mixed.

CMS, GDPR Enforcement Tracker Report 2025/2026, 2026Public sources compiled to 1 March 2026

Caveat Compiled by a commercial law firm, counting fines issued rather than collected, and other trackers report materially different totals.

The largest single GDPR penalty is the EUR 1.2 billion fine adopted against Meta Platforms Ireland on 12 May 2023 for unlawful EU-US transfers under Article 46(1) (Irish Data Protection Commission, 2023). It was appealed, and headline GDPR fines are often reduced or annulled, so "largest fine" is not "largest amount paid". The American comparison is stark.

2025

The largest CCPA enforcement action to date is a $1.55 million settlement with Healthline Media, announced 1 July 2025, over failures to honour opt-outs and the sharing of health-inferring article titles.

Direction: Increase. Strength of evidence: Strong.

California Attorney General, press release, 2025Single enforcement settlement

Caveat US privacy penalties run two to three orders of magnitude below EU maxima, so this is not evidence of deterrent-level enforcement.

The short version

  • Only about a fifth of US adults could answer four of five basic privacy and security questions in Pew's 2023 probability survey.
  • A majority of US adults report agreeing to privacy policies without reading them, and a similar majority say the policies would not explain the data use anyway (Pew Research Center, 2023).
  • The privacy paradox is overstated: a three-wave German panel found concern and disclosure genuinely aligned, at beta around -.10 (Dienlin and colleagues, 2021).
  • Three-quarters of home pages carried a third-party tracker in the 2025 Web Almanac crawl, and third-party cookies remain Chrome's default after Google reversed course.
  • The evidence has hard limits: no regulator publishes fines collected, no survey has updated public attitudes since 2023, and the use of privacy rights and opt-out signals is not measured at all.