Impacts¶
Surveillance does not need to act to be effective. The awareness of its possibility changes behaviour. The awareness of its certainty changes more. The consequences of the same surveillance infrastructure are materially different depending on who a person is and what they do.
Individuals¶
The primary and most direct impact on ordinary citizens is the chilling effect: the modification of behaviour driven by the belief that communications may be monitored, associations recorded, and political or social activity logged and retained.
Research consistently shows that mass surveillance awareness reduces engagement with politically sensitive content, reduces willingness to communicate about controversial subjects, and increases self-censorship among groups most likely to be targeted. These effects do not require any individual to have been specifically surveilled. The structural awareness of capability is sufficient.
Two harms sit beneath it.
Collection at population scale, analysed automatically, produces false positives as a matter of arithmetic. Someone who matches a pattern associated with a risk category can be flagged, watchlisted, held longer at a border, or refused a service, having done nothing that would justify any of it. The algorithm does not know the difference. It knows correlations. And challenging the result requires knowing one is on a list, which is the thing least likely to be disclosed.
Anonymity in public life is the other. Movement through public space, attendance at a meeting, presence at a protest, activity in nominally private digital contexts: all of it is increasingly observable and increasingly kept. Anonymity in civic life has historically protected dissent, minority views, and anyone a change of government could reclassify, and it is structurally eroding. What turns an observed trace back into a named person is a separate step, and the deanonymisation model covers it.
NGOs and civil society¶
Organisations working on human rights, refugee support, environmental protection, political advocacy, or any activity that involves documenting or challenging government behaviour draw the attention of domestic agencies, foreign services, and the commercial layer at once, which is a threat profile few of them are resourced for.
The sharpest exposure is not the organisation’s own. Case management data, contact lists, and secure communications carry the identities of refugees, whistleblowers, human rights defenders in conflict zones, and people fleeing persecution, any of whom face direct personal risk if named. Watching the organisation reaches all of them at once.
Inside, the chill lands on the work. Legal teams, advocacy teams, and strategy documents become surveillance assets the moment a group is of interest to a domestic agency, a foreign government, or a donor state’s service. Knowing that internal communications may be read changes what gets discussed, and how frankly.
Then there is what the intelligence enables. Internal disagreements, financial pressure, a sensitive case: each can be turned into a public attack, a regulatory investigation, or a quiet word with a funder. It is a disinformation campaign with state resources behind it and no fingerprints on it.
Companies¶
Industrial espionage is the most direct impact on commercial organisations, and it is not limited to adversarial states. Allied intelligence agencies have documented records of collecting economic intelligence on EU companies and making it available to domestic competitors. The Snowden disclosures included specific examples. The competitive intelligence collected includes R&D data, trade negotiation positions, merger and acquisition planning, and pricing strategies.
Compliance is the second lever, and the quieter one. A regulator or a police force can use what it already requires as leverage for what it would otherwise have to ask for. A business that depends on its operating licence, its tax treatment, or its standing in a jurisdiction can find itself under informal pressure to cooperate with requests that fall short of the legal threshold. The pressure need never be explicit. It rarely leaves a written record.
The third is simply where the data sits. European business runs on non-EU cloud, software, and hardware, so commercially sensitive material routinely transits or rests in jurisdictions whose law reaches it. That is not a risk in the hypothetical sense. For a large European enterprise it is a standing condition of operating at all.
Research institutions¶
Universities, research institutes, and think tanks hold intellectual property, pre-publication research, and communications with international collaborators that are attractive to state intelligence collection for economic and political reasons.
Cross-border collaboration creates structural exposure: research conducted jointly with institutions in other jurisdictions involves data flows that may be subject to collection under any of those jurisdictions’ legal regimes. A collaborative research project involving institutions in three countries is potentially subject to the intelligence laws of all three.
The academic community’s tradition of open communication and international collaboration is a professional norm that creates an attack surface. Secure communication practices that would be routine in a high-risk civil society organisation are rarely standard in research settings.
Nations and EU¶
The EU faces a structural problem that GDPR and data protection law were not designed to solve: asymmetric intelligence capability between member states, and collective dependency on infrastructure that is jurisdictionally outside the Union.
Take the asymmetry first. Some member states sit deep inside the Fourteen Eyes arrangement and others sit outside it, so the intelligence one government holds is not the intelligence its neighbour holds. The imbalance does not stop at the border; it runs through the EU institutions those governments share.
The dependency is the other half. European citizens’ data is processed by US-headquartered platforms, stored on US cloud, and carried over networks built partly from equipment whose makers have contested relationships with foreign governments. Three iterations of the transatlantic transfer framework have failed to reconcile US national security law with EU data protection rights, which suggests the problem is not one a fourth draft reaches. It is a question of sovereignty wearing a technical costume.
Put together, they erode the thing underneath: the Union’s ability to govern its own digital environment, protect the data of the people in it, and keep its democratic processes intact. That ability currently rests on infrastructure it does not control, legal frameworks other jurisdictions decline to respect, and sharing arrangements that are neither symmetrical nor visible.
Cross-layer: trust erosion¶
Across all of these layers, the deepest impact is on trust: in institutions, in systems, and between people.
When legal structures designed to protect privacy contain exemptions large enough to drive a signals intelligence agency through, when commercial platforms are required to cooperate with surveillance requests and prohibited from disclosing them, when the data generated by ordinary life is available for purchase by any actor with a budget and an interest, the reasonable response is uncertainty about what is private.
That uncertainty is not neutral in its effects. It falls most heavily on those who most need privacy: political dissidents, journalists, human rights workers, minorities under political pressure, and anyone whose legitimate activity might, under some future government’s definition, become a threat.
The system does not need to punish often. It needs to be perceived as capable of it. That perception is, at this point, well-founded.
Last reviewed: 2026-07-17.