The L-space shelf¶
L-space connects all libraries. The shelves here are a selection of places worth returning to: organisations doing sustained work on digital rights and privacy, guides that are actively maintained, journalists and researchers who track the same ground.
Digital rights and policy¶
The Electronic Frontier Foundation publishes analysis, legal commentary, and practical guides on digital rights, surveillance, and the law as it applies to privacy. Their work covers both the technical and the legal dimensions, and their Deeplinks blog is worth following for developments in privacy tools and the law around them. The address is eff.org.
European Digital Rights, known as EDRi, is a network of civil society organisations across Europe working on digital rights, privacy, and online freedoms. Their collective monitoring of EU legislative developments, from the AI Act to chat control proposals, makes them a good single source for tracking how European privacy and surveillance law is changing. The address is edri.org.
noyb, which stands for None Of Your Business, is the organisation founded by Max Schrems to bring strategic litigation under GDPR. Schrems’ earlier litigation produced the Schrems II decision that invalidated the EU-US Privacy Shield, and noyb’s complaints have driven some of the most significant enforcement actions in European data protection law since. Their published case summaries are a useful reference on data-broker practices and the right to erasure. The address is noyb.eu.
La Quadrature du Net is a French digital rights organisation with particularly strong coverage of mass surveillance legislation, data retention, and state-level threats. Their analysis of French and European surveillance law is detailed and consistently well-sourced. The address is laquadrature.net.
Access Now works on digital security and rights specifically for people at elevated risk: activists, journalists, and human rights defenders. Their Digital Security Helpline provides direct support, and their publications track policy developments across many jurisdictions. Their work speaks directly to higher-risk, targeted situations rather than ambient collection. The address is accessnow.org.
Article 19 focuses on freedom of expression and information as human rights, with particular attention to surveillance and censorship. Their legal and policy analysis is useful context on state-level threats and censorship circumvention. The address is article19.org.
The Electronic Privacy Information Center, known as EPIC, is a US-based research and advocacy organisation focused on privacy law and emerging technology. Their publications track regulatory developments and enforcement on the US side, which is where many of the data brokers live. The address is epic.org.
Practical guides¶
Privacy Guides at privacyguides.org maintains a carefully curated set of tool recommendations across all major categories: operating systems, browsers, messaging, email, VPNs, password managers, and more. The recommendations are community-maintained and updated regularly as tools change and new ones emerge, which makes it a reliable first check on whether a specific privacy tool is still a current recommendation.
Surveillance Self-Defense, published by the EFF at ssd.eff.org, approaches privacy through a threat modelling lens. The guides are organised by context and risk level rather than by tool category, which aligns closely with a threat-modelling approach. The section on threat modelling is a good companion read.
Security in a Box, from Front Line Defenders at securityinabox.org, is written specifically for civil society organisations and people working in environments with significant adversarial risk. The tool guides are practical and kept current. The framing is pitched at organisations rather than households, but the underlying principles are the same, and the guides are a useful reference for the more technical material.
Investigative and journalistic sources¶
Forbidden Stories is a Paris-based consortium of investigative journalists whose model is to continue reporting stories that have been suppressed or whose authors have been silenced. They coordinated the Pegasus Project, which exposed the use of NSO Group’s spyware against journalists, lawyers, and politicians across multiple countries, and Story Killers, which investigated the disinformation-for-hire industry. Their investigations are a primary source of evidence for some of the more serious claims about commercial spyware. The address is forbiddenstories.org.
The Markup at themarkup.org, publishing under the nonprofit newsroom CalMatters since 2024, does data journalism on how technology actually behaves: how tracking works in practice, how algorithms affect real people, how platforms use the data they collect. Their investigations are well-sourced and typically include the technical detail needed to understand what they are describing. They are useful for validating claims about how tracking and data collection actually work, as distinct from how companies describe them in their privacy policies.
The Citizen Lab at the University of Toronto at citizenlab.ca produces research on state-sponsored surveillance, spyware, and network interference. Their work is technically detailed and peer-reviewed, and it regularly surfaces new information about the tools and methods used by state-sponsored adversaries. Their publications are the place to check what those adversaries can actually do this year, as distinct from what they could do when a page was written.
Bruce Schneier’s Schneier on Security at schneier.com combines technical analysis with policy commentary and has maintained a high signal-to-noise ratio over many years. It is useful for tracking security developments and for understanding how specific incidents fit into broader patterns.
Krebs on Security at krebsonsecurity.com covers breaches, fraud, and criminal activity in the digital space with considerable technical depth. It is particularly useful for the pages covering data breaches, identity theft, and the practical consequences of poor credential hygiene.
Technical standards and open research¶
The Open Observatory of Network Interference, known as OONI, measures internet censorship and network interference around the world. Their data and reports are publicly available at ooni.org and are relevant to censorship, circumvention tools, and surveillance infrastructure at the national level. Their explorer tool allows you to look up conditions in specific countries, which is useful for grounding abstract threat descriptions in measured evidence.
ENISA, the European Union Agency for Cybersecurity, publishes threat landscape reports, guidelines, and technical recommendations at enisa.europa.eu. Their annual threat landscape report is a useful check on whether a threat description still reflects the current state of play.
Exodus Privacy is a French project that analyses the tracker libraries embedded in Android applications and publishes the results in a searchable database at exodus-privacy.eu.org. Their reports show which third-party trackers each app includes, what permissions it requests, and what network connections it makes. This connects directly to stalkerware and surveillance: the same tracking infrastructure used by advertising networks appears in apps marketed as parental controls or productivity tools.
AlgorithmWatch is a Berlin-based research and advocacy organisation that investigates automated decision-making and algorithmic profiling as they affect people in practice. Their reports cover how profiling is used in employment, credit, public services, and law enforcement, grounding inference and algorithmic profiling in documented examples from European contexts. The address is algorithmwatch.org.
The Tor Project’s blog at blog.torproject.org covers developments in anonymity and censorship circumvention from the people who maintain one of the primary tools for it. It is relevant for the circumvention material and for understanding how the threat landscape affecting anonymity tools is changing, including adversarial attempts to de-anonymise Tor users.
The W3C Privacy Working Group at w3.org standardises privacy mechanisms for the web platform and tracks how privacy is being designed into, or out of, it. Their work is relevant to browser-level tracking and to understanding what protections browsers can and cannot provide structurally, as distinct from what extensions and configuration choices can achieve on top of them.
The thinking behind the approach taken here is documented at The Foundations.
Last reviewed: 2026-07-08.