When Tools Designed to Protect You Feel Like Another Form of Control
In 2023, the Irish Data Protection Commission fined Meta €1.2 billion for transferring European user data to US servers — the largest GDPR fine in history at that point. The public reaction was telling: a brief flurry of headlines, some outrage on social media (posted, ironically, on Meta platforms), and then silence. Most users kept scrolling. This gap between knowing something is happening to your data and actually doing anything about it is precisely where psychology and technology collide. Privacy-enhancing technologies — the suite of tools designed to technically protect personal information — exist in exactly this uncomfortable space. They work, mostly. And yet most people don’t use them.
This isn’t laziness or ignorance. It’s something more interesting, and more worth examining.
What Privacy-Enhancing Technologies Actually Are
Privacy enhancing technologies, or PETs, is an umbrella term for any tool, protocol, or design mechanism that reduces the collection, exposure, or misuse of personal data. That’s a wide net. It includes the obvious — VPNs, end-to-end encrypted messaging apps like Signal, browser extensions that block trackers — but also less visible technical mechanisms like differential privacy (used by Apple and Google to analyze aggregate user data without identifying individuals), homomorphic encryption (which allows computation on encrypted data without ever decrypting it), and zero-knowledge proofs, which let you prove you know something without revealing what that thing actually is.
The concept has been formalized in EU policy through the principle of privacy by design, embedded in GDPR Article 25. The idea is straightforward: data protection shouldn’t be an afterthought added to a product; it should be engineered into its architecture from the start. In practice, compliance has been uneven at best.
The Three Categories That Matter Psychologically
- Anonymization and pseudonymization tools — These reduce the identifiability of data. Tor, for instance, routes your internet traffic through multiple servers so no single node knows both who you are and what you’re accessing. VPNs offer a simpler (if less robust) version of this principle.
- Consent and transparency tools — Cookie managers, privacy dashboards, data deletion request services. These don’t protect data technically so much as they empower the user to make and enforce choices. They’re only as effective as the user’s ability to understand what they’re consenting to — which is where things get complicated.
- Cryptographic protections — End-to-end encryption, secure key management, zero-knowledge authentication. These are the most technically robust but also the most cognitively opaque to the average user. You can’t see encryption working, which is psychologically significant.
The technical literature on PETs is extensive. The psychological literature on why people don’t use them is, frankly, more revealing.
The Privacy Paradox Runs Deeper Than We Thought
Most people reading this will have heard of the privacy paradox — the well-documented phenomenon where individuals express high concern about their personal data while simultaneously engaging in behaviors that expose it. Research by Barth and de Jong (2017) confirmed this across multiple studies: privacy concern and privacy behavior are surprisingly weakly correlated. Knowing the risk and changing behavior are different cognitive processes, governed by different psychological systems.
What makes the PET adoption question particularly interesting is that it strips away the passive dimension of the paradox. Using a privacy-enhancing technology requires an active choice. It means installing something, learning something, accepting some friction. And friction is the enemy of protective behavior, not because people are foolish, but because of well-documented cognitive patterns.
Present bias is relevant here: the immediate inconvenience of switching to a more privacy-respecting tool feels more costly than the abstract, future risk of data exposure. Optimism bias does similar damage — most people systematically underestimate their own probability of being targeted by a data breach or stalkerware. And then there’s cognitive overload. The average privacy policy requires a reading level equivalent to a Harvard Law Review article and takes approximately 18 minutes to read. Multiplied across every service a person uses, it would take hundreds of hours per year. Westin’s privacy typology is relevant here: privacy pragmatists — the largest group — perform cost-benefit calculations, and when the costs of engagement are this high, inaction becomes the rational default.
The Trust Equation
There’s another psychological variable that rarely gets sufficient attention: trust, and specifically the strange trust dynamics around PETs themselves. When a user downloads a VPN, they are not eliminating a surveillance relationship — they’re transferring it. Instead of their ISP knowing their browsing habits, their VPN provider does. Several major VPN services have, at various points, been caught logging user data despite claiming not to. This isn’t a niche concern; it’s structurally inherent to the model. Petronio’s communication privacy management theory is useful here. Her framework suggests people manage privacy through a complex system of mental boundaries and rules about who may access what information under which contexts. Being asked to trust an invisible third party with everything violates those intuitive boundary rules, even when the tool is technically sound. The discomfort is real and rational.
Surveillance Awareness Changes More Than Your Behavior
Here’s where it gets genuinely uncomfortable. The psychological effects of surveillance don’t require actual surveillance — they require only the reasonable belief that surveillance might be occurring. This is the panopticon effect, Foucault’s famous extrapolation of Bentham’s prison design: when people believe they are being watched, they begin to self-police. In digital environments, this produces measurable chilling effects on information seeking. A 2016 study by Alex Marthews and Catherine Tucker found that Google searches for sensitive topics — medical symptoms, legal questions, political dissent — declined measurably in the period following the Snowden revelations. People didn’t stop having these concerns. They stopped typing them.
Privacy-enhancing technologies can, in theory, restore a sense of psychological safety that makes genuine intellectual exploration possible again. Tor’s most significant user base has historically included not criminals (the common misconception) but journalists, dissidents, domestic abuse survivors, and LGBTQ+ individuals in hostile environments. These aren’t edge cases. They’re people whose relationship with surveillance carries real stakes. For them, PETs aren’t privacy paranoia — they’re contextual integrity, in Helen Nissenbaum’s framing, being restored. Information flowing in ways appropriate to its context rather than leaking promiscuously across it.
For the rest of us with lower stakes, the psychological argument for PETs is less about physical safety and more about something Altman’s privacy regulation theory identifies as fundamental: the capacity to control access to oneself. Altman argued that privacy isn’t about secrecy per se — it’s about maintaining the ability to regulate the boundary between self and environment. When that capacity is undermined, people experience stress, a reduced sense of autonomy, and what he called privacy overload. The constant low-level awareness that your data is being harvested, traded, and processed may contribute more to ambient digital anxiety than we currently recognize.
A Practical Self-Assessment: Where Do You Actually Stand?
Rather than issuing a list of apps to install, the more useful exercise is to first understand your own privacy profile. This brief checklist isn’t about judgment — it’s about honest accounting.
- What’s your Westin type? Are you a privacy fundamentalist (distrust most data collection), a pragmatist (weigh costs and benefits), or largely unconcerned? Your honest answer shapes which PETs will realistically become part of your behavior.
- Map your highest-exposure contexts. Where is the data that matters most to you being created? Work communications? Health apps? Location data from your phone? Start with those.
- Audit your messaging apps. If a significant portion of your personal conversations happen on Facebook Messenger, Instagram DMs, or standard SMS, they are not end-to-end encrypted by default in ways that protect against platform access. Signal or iMessage (between Apple devices) offer stronger protection.
- Check your browser environment. Install Privacy Badger or uBlock Origin. Run your browser through a tool like coveryourtracks.eff.org to see how uniquely identifiable your device fingerprint is. The result is often surprising.
- Evaluate your VPN reasoning, not just your VPN choice. Why do you want a VPN, specifically? If it’s for privacy from your ISP, ensure the VPN provider has had an independent security audit and has a verified no-logs policy. If it’s for security on public Wi-Fi, the threat model is different and the solutions are more straightforward.
- Notice your consent behavior. Next time you encounter a cookie consent banner, pause for three seconds before clicking. What is the default option? Who designed that default and why? Dark patterns in consent interfaces are, by Solove’s taxonomy, a form of privacy violation even when technically legal.
- Assess your data breach exposure. Visit haveibeenpwned.com and enter your email addresses. If you find breach exposure (most people do), consider whether you’ve changed the relevant passwords and whether you’re using a password manager.
This isn’t about achieving perfect digital privacy — that’s neither realistic nor necessarily desirable. It’s about narrowing the gap between your stated values and your actual practice. Even small reductions in that gap produce what psychologists call cognitive consonance: alignment between beliefs and actions that reduces the low-grade discomfort of knowing you’re not doing what you think you should be doing.
The Technology Alone Won’t Fix the Psychology
Here’s the uncomfortable conclusion: privacy-enhancing technologies are necessary but not sufficient. The most sophisticated encryption in the world is undermined if you share your location with seventeen apps, post daily to an algorithm-optimized feed, and use a single password across accounts. PETs exist at the technical layer. The privacy problem also exists at the behavioral, social, and structural layers — and those require different interventions.
At the structural level, privacy by design means the engineering defaults should protect users rather than exploit them. At the behavioral level, it means friction needs to be redistributed — right now, protecting your privacy requires significant effort while exposing it requires none. This asymmetry is not accidental; it is designed, and recognizing it as a design choice rather than a natural state is psychologically significant. It shifts the locus of responsibility from the individual to the system, which is more accurate and more motivating.
Contextual integrity, again, offers a useful frame. Most people don’t want to be invisible online. They want their information to flow appropriately — shared with their doctor but not their employer, shared with their partner but not with a data broker in Delaware, shared in a moment of vulnerability and not archived forever. PETs, at their best, help restore that contextual control. But they work best when paired with an honest understanding of your own psychology: your biases, your threat model, your actual values versus your reactive ones.
The Snowden revelations didn’t make most people adopt encryption. Meta’s billion-euro fine didn’t make most people leave Instagram. But both events shifted something in the cultural understanding of what’s happening in the background of digital life. Perhaps the most important function of privacy-enhancing technologies is not technical but psychological: they make visible a choice that platforms work hard to make invisible. Whether you make that choice differently afterward is, as always, up to you.
Questions Worth Sitting With
- When you share something online, do you ever think about who else might access it — not in the future, but right now, in the same moment?
- Which of your digital behaviors would change if you knew with certainty that they were being watched, recorded, and analyzed by someone whose interests differ from yours?
- Is your current level of digital privacy exposure a conscious choice, or the result of never making a choice at all?
- What would it actually feel like to have meaningful control over your own information? When was the last time you did?



