After spending years working with technology and later building my own online publications, I have watched the internet change from a place we visited into something that follows us everywhere.
It sits in our pockets, our homes, our cars and increasingly on our bodies. It knows where we go, what we search for, what we buy, what we read, how long we look at something and what time we normally go to sleep.
The deeper issue is that most of us never consciously agreed to create such a detailed record of our lives simply by using the services modern life now expects us to use.
Every website visit, mobile app, rewards card, online purchase, streaming service and social media account adds another piece to a profile being built about us.
That profile may be scattered across hundreds of companies, advertising platforms and data brokers we have never heard of and may never knowingly interact with.
We are reaching a point where the only certain way to protect our privacy would be to stop using the internet altogether.
That would mean giving up online banking, digital government services, email, social media, cloud storage, navigation apps, streaming platforms, online shopping and much of the technology now woven into ordinary life.
For most people, disconnecting completely is no longer a realistic choice.
How Your Data Can Be Collected Without You Realising
Data collection often happens quietly in the background while people browse websites, use mobile applications, make purchases or move through public spaces. These methods can reveal far more than the information people knowingly provide.
-
Tracking cookies
Cookies can record website visits, viewed products, searches and interactions, sometimes allowing activity to be followed across multiple websites.
-
Invisible tracking pixels
A tiny invisible image embedded in a website, advertisement or email can report when content was viewed, which device was used and the user’s approximate location.
-
Browser fingerprinting
Websites can combine details such as screen size, browser version, language, fonts and operating system to recognise a device without relying on cookies.
-
Mobile application trackers
Applications may contain third-party software that quietly sends device information, usage activity and advertising data to analytics or marketing companies.
-
Real-time advertising auctions
When an advertisement is loaded, information about the device, location and content being viewed may be distributed through an automated advertising marketplace.
-
Device advertising identifiers
Phones and tablets contain advertising identifiers that can connect activity across different applications and help advertisers build behavioural profiles.
-
Location tracking
Applications and services can estimate or record location through GPS, IP addresses, mobile towers, Wi-Fi networks and nearby Bluetooth devices.
-
Email tracking
Marketing emails can report when a message was opened, how often it was viewed, which links were selected and the type of device used.
-
Social media buttons
Embedded like, share and follow buttons may send information to social platforms even when the visitor does not click them.
-
Social account logins
Using a social media or search account to sign into another service can connect activity across separate websites and applications.
-
Contact list uploads
When someone allows an application to access their contacts, information about people who never joined the service may also be collected.
-
Loyalty and rewards programs
Rewards cards can connect purchases, store visits, spending habits and promotional responses to a named customer profile.
-
Payment and transaction records
Card payments and digital purchases can reveal shopping habits, regular locations, subscriptions and changes in financial behaviour.
-
Online competitions and quizzes
Competitions, surveys and personality quizzes can collect names, contact details, interests and personal preferences for later marketing or profiling.
-
Data brokers
Data brokers can purchase, license and combine information from numerous online and offline sources to create detailed commercial profiles.
-
Public information and web scraping
Information from websites, public profiles, business records, directories and published documents can be automatically collected and added to databases.
-
Photographs and image metadata
Images can contain hidden metadata such as location, time, device model and camera settings, while facial recognition may identify people appearing in them.
-
Smart televisions and connected devices
Smart TVs, speakers, watches, doorbells and household devices may collect viewing activity, voice requests, location signals and patterns of daily use.
-
Cross-device tracking
Companies can use account details, network information and behavioural patterns to associate a phone, computer, tablet and television with the same person or household.
-
Inferred personal information
Companies can analyse existing data to predict income, interests, health concerns, political views, family status or the likelihood of making a purchase.
The most revealing information is often created through combination and inference. A single data point may appear harmless, but connecting location, purchases, browsing activity and device identifiers can produce a detailed picture of a person’s identity, habits and private life.
Australians know they are losing control
The latest figures confirm that this unease is now widespread.
The Office of the Australian Information Commissioner surveyed 1,504 Australian adults in March 2026 and found that 93% considered protecting their personal information important.
Another 87% said they were more concerned about privacy than they had been five years earlier.
Most tellingly, 78% felt they had very little or no real control over how their personal information was collected and used. Only 22% believed they had at least some meaningful control.
The same 2026 Australian Community Attitudes to Privacy Survey found that 68 per cent rarely or never felt that requests for consent represented a genuine choice.
More than half said they shared personal information because refusing could mean missing out on essential services or opportunities.
That is not meaningful consent. It is the digital price of admission.
When someone needs to accept a privacy policy to apply for a rental property, communicate with their child’s school, access government services or manage a bank account, the choice is largely theoretical.
The option may exist on paper, but the practical alternative is exclusion.
Our lives are recorded in ways we rarely see
Some information is provided deliberately. We type our names into forms, upload photographs, enter addresses, provide phone numbers and create profiles.
A much larger stream of data is collected in the background.
Websites can record an IP address, approximate location, device type, browser, operating system, screen size, language settings, referral source, pages visited, links clicked and the time spent viewing each page.
Cookies and advertising identifiers can help connect those actions across different sessions, websites and apps. Mobile applications may contain software development kits supplied by advertising, analytics or location-data companies.
The components can transmit device identifiers, app activity and location information to third parties while the user believes they are dealing only with the app visible on the screen.
Tracking pixels embedded in websites, advertisements and emails can report when content is opened or viewed. An email that appears to contain only text may quietly tell the sender when it was opened, which device was used and the approximate location of the recipient.
The advertising system adds another layer.
When a website or app offers an advertising space through an automated auction, information associated with that opportunity can be distributed through the advertising technology chain in milliseconds.
That information may include an advertising identifier, device information, location signals and details about the content being viewed.
In one case, the United States Federal Trade Commission alleged that data broker Mobilewalla collected information from real-time advertising auctions even when it did not win the right to display an advertisement.
The company allegedly accumulated more than 500 million unique advertising identifiers linked with precise location information between 2018 and 2020.
The FTC said the data included visits to health clinics, places of worship and pregnancy centres, while many of the people being tracked had no knowledge that Mobilewalla possessed their information.
That example exposes how far removed data collection can be from anything resembling an informed agreement.
The online and offline worlds are being joined together
Online tracking is only one part of the system.
Supermarket loyalty programs record what we buy, how often we shop, which stores we visit and which promotions influence our spending.
Payment providers see transaction histories. Telecommunications companies hold location and communications metadata.
Property platforms record searches, enquiries and estimated housing interests. Navigation services know our routes, destinations and routines.
Competitions, surveys, quote requests and free product trials can also become sources of marketing data. A person may enter a competition once and unknowingly create a trail that follows them for years.
The Australian Competition and Consumer Commission documented one case involving a woman who received marketing from a business she had never dealt with.
After six months of enquiries, she discovered that two unfamiliar data firms held her name, date of birth, home address, telephone number, email addresses and two pages of modelled information about her finances, employment, family and living arrangements.
The apparent source was an online competition she had entered in 2019. Somewhere in the terms and conditions was consent allowing her information to be used for direct marketing.
This is how privacy disappears in practice. A single form can become the starting point for years of collection, enrichment, profiling and redistribution.
What data brokers know about Australians
Data brokers generally operate outside the direct relationship between a consumer and the service they are using. They acquire information from companies, public sources, surveys, transactions, online activity and other data suppliers before combining it into larger commercial profiles.
The ACCC’s report into Australian data products and services showed the scale of those holdings.
In information examined for the report, illion said one of its consumer marketing products contained 5.6 million telephone numbers, 11 million email addresses and more than 100 attributes that could be appended to consumer records.
Experian claimed to hold more than 15 million email addresses, eight million mobile numbers and 10 million residential addresses in Australia.
Its ConsumerView product was described as containing information on more than 18 million Australian consumers, equivalent to 73% of the adult population at the time, with household-level information covering income, assets, education and household composition.
The purpose is to transform isolated fragments into commercially useful identities.
A supermarket purchase can be combined with a location, household estimate and browsing pattern. An email address can connect an online account with an offline customer record.
An advertising identifier can link app activity to repeated visits to physical locations.
Statistical models can infer interests, financial circumstances, family status, health concerns, political leanings or the likelihood that someone will buy, borrow, move house or respond to a particular message.
The profiles are then used for targeted advertising, customer segmentation, identity verification, fraud prevention, property analysis, risk assessment and campaign measurement.
Some of those uses provide legitimate benefits, particularly where data helps prevent fraud or confirm an identity.
The danger lies in the absence of visibility. A person may never know which broker has created a profile, which information it contains, whether it is accurate, who purchased access to it or what decisions were influenced by it.
In the OAIC’s 2026 survey, only 4% of Australians considered data brokers trustworthy. AI companies also received 4%, while trust in social media companies fell to just 3 per cent. At the same time, 96 per cent considered the sale or trading of personal information unfair or unreasonable.
The public has delivered a clear verdict, yet the machinery continues to operate.
Fine print has become a shield
Privacy policies were supposed to explain how information would be handled. Many have become lengthy legal documents designed to authorise as much data use as possible while transferring responsibility to the person clicking “accept”.
The ACCC found that long, complex and ambiguous privacy policies made it difficult for consumers to understand or control what happened to their information.
Third parties were often described using broad terms such as “partners”, “suppliers” or “affiliates”, leaving consumers with no practical way to identify the companies receiving their data.
The 2026 OAIC research found that 69 per cent of Australians often accepted privacy policies without reading them. I do not see that as evidence that people do not care. It shows that the system asks something unreasonable of them.
Nobody can realistically stop during every online interaction to interpret pages of legal language, investigate every named partner and trace every possible secondary use. Even if they could, refusing often means losing access to the service.
Whether this complexity is described as legal protection, poor design or deliberate obscurity, its effect is the same. Companies can claim that users consented while users remain largely unaware of what they supposedly accepted.
Consent buried deep inside a document that almost nobody can understand is closer to legal cover than genuine permission.
The danger continues after the data is collected
Every new database creates another target for criminals, hostile governments, dishonest insiders and opportunistic scammers.
The OAIC received 1,205 data breach notifications during 2025, the highest annual number recorded since Australia’s mandatory reporting scheme began in 2018. The total was 8% higher than in 2024, with 716 notifications attributed to malicious or criminal activity.
A privacy policy can’t protect information after it has been stolen. Changing a password will not change a date of birth, home address, medical history or biometric identifier.
We are continually told to protect ourselves with stronger passwords, multi-factor authentication, privacy settings, encrypted messaging, tracking protection and virtual private networks.
The measures can reduce exposure, and I use many of them myself, but personal security habits cannot solve an industrial system built around mass collection.
We can close the curtains in our own homes, but that offers little protection when hundreds of organisations already hold copies of the floor plan.
Ways to Protect Your Online Privacy
Complete online anonymity is difficult to achieve, but these practical steps can reduce tracking, limit unnecessary data collection and make personal information harder to exploit.
-
Share less personal information
Provide only the information genuinely required to access a product or service.
-
Create a separate online persona
Use an alias for forums, newsletters and non-official accounts, keeping it separate from your legal identity. Never use it for fraud, impersonation or regulated services.
-
Use unique passwords
Create a different password for every account and store them in a trusted password manager.
-
Enable multi-factor authentication
Add an authenticator application or security key to important accounts wherever possible.
-
Review social media settings
Limit who can see your posts, personal details, location, photographs and friends list.
-
Disable unnecessary location tracking
Allow location access only while an application is actively being used and genuinely needs it.
-
Restrict application permissions
Remove unnecessary access to your contacts, camera, microphone, photographs and local files.
-
Reject non-essential cookies
Decline advertising and tracking cookies when websites provide a genuine choice.
-
Use a privacy-focused browser
Choose a browser with built-in tracker protection and consider adding a reputable content blocker.
-
Disable personalised advertising
Turn off advertising personalisation and regularly reset the advertising identifier on your devices.
-
Avoid social account logins
Create a separate login instead of using Facebook, Google or another social account across unrelated services.
-
Use email aliases
Create separate addresses for shopping, newsletters and account registrations to protect your primary email address.
-
Use encrypted messaging
Choose services offering end-to-end encryption when discussing private or sensitive matters.
-
Keep software updated
Install security updates for operating systems, browsers, applications, routers and connected devices.
-
Delete unused accounts
Close old accounts and remove applications that continue collecting information without providing value.
-
Request data deletion
Ask companies and data brokers to delete information they no longer need to hold about you.
-
Avoid intrusive competitions and surveys
Do not exchange personal information for prizes, discounts or offers without checking how the data will be used.
-
Remain alert to phishing
Check addresses, links and requests before entering passwords, payment details or identity information.
-
Use a reputable VPN on public Wi-Fi
A VPN can protect traffic on an untrusted network, but it does not make a person completely anonymous online.
-
Monitor known data breaches
Check whether your email addresses have appeared in reported breaches and change affected passwords immediately.
No single privacy setting provides complete protection. The strongest approach combines data minimisation, secure accounts, careful browsing habits and fewer connections between your real identity and everyday online activity.
Privacy should not require disappearing from society
The greatest failure of the modern internet is that privacy has been framed as an individual responsibility.
People are expected to find hidden settings, reject cookies, read legal documents, delete old accounts, contact unknown data brokers and continually monitor breaches.
Meanwhile, the organisations collecting the information possess the technology, legal teams and commercial incentives to keep expanding their databases.
Privacy cannot survive if the burden remains entirely on the person being watched.
Organisations should have to collect only what is necessary, explain every significant use in plain language, obtain genuine opt-in consent for secondary purposes and delete information when it is no longer required.
People should be able to discover who holds their data, correct it, stop it from being sold and have it permanently erased without navigating a maze of forms.
The internet has become too important to abandon, but that importance cannot be used as an excuse to strip away the private parts of our lives.
I don’t want to disconnect from the world. Most of us do not. We want to communicate, work, publish, learn, shop and participate without leaving an endlessly expanding commercial record behind us.
The fact that complete disconnection is beginning to look like the only reliable privacy setting should concern everyone Once privacy is gone, we may discover that convenience was a very small reward for everything we gave away.

