Forouzan Marzbani
PhD Student in Political sociology, Razi University
Introduction
The contemporary era rests upon a fundamental paradox: digital technologies have simultaneously created the most powerful instruments of individual empowerment and the most pervasive mechanisms of state surveillance in human history. While citizens enjoy unprecedented access to information, global communication, and platforms for expressing their views, governments have also acquired immense technological capacities to collect, store, and process the vast volumes of data generated by digital activity. This simultaneity has transformed the classic tension between “national security” and “the right to privacy” from an abstract legal debate into a technical and everyday reality. In other words, this is not simply a matter of balancing two competing interests; rather, it involves a fundamental reconfiguration of the architecture of power and control. The question is not which of these two concepts—security or privacy—is more important. Both are public goods and indispensable to the survival of a democratic and functional society. National security provides the conditions necessary for the continued existence of society, while privacy constitutes the cornerstone of individual autonomy, freedom of thought, and human dignity.
The present challenge lies in the narrow boundary between these two domains—a boundary that was historically defined and protected through legal and judicial safeguards, such as the requirement to obtain a judicial warrant before conducting wiretapping. Yet the paradigm of digital surveillance, which is based on mass data collection, pattern-based processing, and predictive analysis, has rendered these traditional safeguards increasingly ineffective. Rather than producing a new equilibrium, this institutional inadequacy has resulted in the asymmetrical erosion of the right to privacy in favour of an indefinite expansion of security powers. Against this background, this analytical note argues that recalibrating the relationship between security and privacy can no longer be achieved through conventional oversight mechanisms. Instead, it requires a redefinition of the foundational principles of “necessity” and “proportionality” in the age of big data, together with the establishment of new mechanisms for technical and pattern-based oversight of data-collection processes.
The Changing Nature of Threats: From “Defence” to “Prediction”
The paradigmatic shift towards pervasive digital surveillance has neither been accidental nor merely the result of technological progress. Rather, it has emerged as a direct response to the changing nature of threats in the twenty-first century. The traditional model of national security was essentially reactive and state-centric. Threats, such as hostile armies, were identifiable, visible, and predominantly physical. Legal frameworks governing surveillance were therefore designed accordingly: monitoring a particular suspect—for example, by intercepting telephone communications—required judicial authorisation based on reasonable grounds for suspicion. This was a defensive logic that became operative only after a threat had been identified or a crime had occurred. With the emergence of new forms of threat, particularly networked and transnational terrorism, this model gradually lost its effectiveness. Contemporary threats are decentralised, concealed, ideologically driven, and devoid of a clearly defined state structure (Sageman, 2008).
In response to such threats, the logic of security shifted from reaction to prevention and subsequently from prevention to prediction. Governments could no longer afford to wait for an attack to occur; they sought instead to identify threats before they had fully materialised. This transition to a paradigm of pre-emptive security had direct implications for the collection of data (Aradau & van Munster, 2007). Within this new paradigm, data ceased to function merely as an investigative instrument used to prove that a crime had already occurred. It became instead a raw material used to predict future criminality. It is at this point that the logic of big data enters the picture. Unlike traditional statistical analysis, which relies on sampling, the philosophy of big data is premised on the collection of all available data (Mayer-Schönberger & Cukier, 2013).
Security institutions argue that identifying suspicious behavioural patterns and detecting previously unknown threats requires them to avoid determining in advance which data are relevant and which are not. Consequently, rather than searching for a single needle—a known suspect—in a haystack, they now collect the entire haystack—the communications data of the whole population—and subsequently employ artificial-intelligence algorithms to identify patterns and possible needles within it (Schneier, 2015).
This logic of “collect everything” stands in direct contradiction to the foundational principles of privacy and data-protection law, particularly the principle of data minimisation enshrined in many data-protection regimes, including the General Data Protection Regulation (GDPR). The principle of data minimisation requires that personal data be collected for a “specified, explicit and legitimate” purpose and that their processing not extend beyond that purpose. The logic of pre-emptive security, however, defines its objective as the discovery of unspecified future patterns—an objective that is inherently open-ended and indeterminate. Surveillance is thereby transformed from a targeted and exceptional measure based on suspicion into a mass, permanent, and default practice based on the analysis of potentiality. In doing so, it fundamentally dismantles the boundaries that had previously governed the permissible scope of state monitoring.
Privacy as the Cornerstone of Individual Autonomy
In debates concerning the balance between security and surveillance, privacy is frequently mischaracterised as a “right to conceal” or treated as synonymous with secrecy. This reductionist understanding provides fertile ground for the familiar fallacy that “if you have done nothing wrong, you have nothing to hide.” Such an argument fundamentally misunderstands the social and psychological functions of privacy. Privacy is not primarily a means of concealing wrongdoing; it is an essential precondition for individual autonomy and the formation of personal identity.
As Daniel J. Solove correctly observes, the harms generated by surveillance are not confined to the disclosure of embarrassing information. They also include the aggregation and processing of personal information and the individual’s loss of control over the ways in which personal data are used (Solove, 2008). The most significant, yet often least visible, harm caused by mass digital surveillance is the phenomenon commonly described in legal scholarship as the “chilling effect.” This is not a direct harm, such as arrest or punishment. Rather, it is an indirect and anticipatory form of harm imposed upon citizens’ behaviour. When individuals—whether journalists, academics, civil-society activists, or ordinary citizens—know, or even merely suspect, that their communications, internet searches, and online activities are being continuously monitored, they begin to censor themselves (Penney, 2016). They refrain from researching sensitive subjects, discussing unconventional ideas, or challenging prevailing norms, regardless of whether such activities are entirely lawful.
This self-censorship extends far beyond individual discomfort and has profoundly damaging systemic consequences for society. Innovation, intellectual creativity, and scientific advancement require a secure space for experimentation, intellectual trial and error, and risk-taking—a space in which individuals do not fear judgment or the permanent recording of their undeveloped or provisional thoughts. Similarly, a healthy democracy requires citizens who can freely seek information, form their own opinions, and participate in public debate without fear of being labelled or categorised. By creating a transparent and continuously observable public sphere, pervasive surveillance eliminates this essential space for intellectual and civic breathing.
Moreover, the normalisation of mass state surveillance is reinforced by the phenomenon of surveillance capitalism, as described by Shoshana Zuboff (Zuboff, 2019). In this model, the collection and analysis of citizens’ behavioural data by major technology companies for the purpose of predicting and shaping consumer behaviour have become routine and socially accepted practices. This cultural acceptance of surveillance by private corporations significantly weakens public resistance to surveillance conducted by the state. Privacy, therefore, is not merely an individual preference. It is a public good that underpins social trust, freedom of expression, and democratic vitality. Its erosion, even when justified in the name of security, entails long-term costs that are frequently overlooked in short-term security calculations.
Dissecting the Boundary: The Erosion of Traditional Frameworks
The central point of tension between national security and privacy lies in the oversight mechanisms designed to protect the boundary separating these two domains. The classic legal instrument employed for this purpose has been the judicial warrant based on reasonable grounds. This mechanism was founded upon a straightforward principle: before intruding into an individual’s private sphere, the state had to persuade an independent authority—a judge—that sufficient evidence existed to indicate that a particular person had committed, or intended to commit, a criminal offence. This mechanism rendered surveillance targeted, exceptional, and subject to independent oversight.
The age of digital surveillance has rendered this logic ineffective in three fundamental respects. First, as discussed in the preceding section, the pre-emptive paradigm based on big data is not inherently targeted; it is based on mass collection. Under this model, data are collected before any suspicion exists, so that suspicion can subsequently be generated from the data. In such circumstances, the concept of “reasonable grounds” in relation to a specific individual becomes virtually meaningless, because the object of surveillance is the entire population—or a substantial proportion of it. Judicial bodies cannot meaningfully supervise an authorisation that permits the government to search the entire haystack in the hope that it may eventually locate a needle (Schneier, 2015).
Second, technological developments have undermined the traditional distinction between content and metadata, a distinction that historically formed the backbone of communications-interception law. In the past, the law afforded strong protection to the content of a telephone conversation—what was actually said—while treating metadata, such as the identities of the caller and recipient and the time and duration of the call, as comparatively less sensitive. In the digital age, however, metadata—including location information, web-search patterns, and social-network connections—can, when aggregated and analysed over time, produce a far more precise and revealing portrait of an individual’s life, beliefs, and relationships than the content of several isolated communications (Mayer-Schönberger & Cukier, 2013). Nevertheless, these highly sensitive forms of data often remain subject to a legal vacuum or to substantially weaker protective standards than those governing communications content.
Third, and perhaps most dangerously, digital surveillance is accompanied by the phenomenon of mission creep. This term refers to the process through which tools, technologies, or databases originally created and justified for a highly specific and exceptional security purpose—such as counterterrorism—are gradually repurposed for other objectives, including the investigation of minor offences, immigration enforcement, or even administrative disciplinary control (Lyon, 2018). The normalisation of exceptional surveillance permanently shifts the boundaries of acceptable state conduct. A measure regarded yesterday as an emergency and extraordinary intervention becomes today a routine instrument in the ordinary policing toolkit, and returning it to its former exceptional status becomes almost impossible.
In this process, legal frameworks originally intended to manage exceptional measures become effectively disarmed in the face of a new general rule. The narrow boundary between security and privacy retreats in favour of surveillance, not as the result of a transparent and deliberate decision, but through gradual, technical, and institutional erosion.
Conclusion
The preceding analysis demonstrates that the narrow boundary between national security and privacy in the digital age is not a fixed line but a field of continuous erosion. Traditional legal and judicial frameworks designed to preserve this boundary have largely lost their effectiveness when confronted with the contemporary architecture of surveillance based on mass data collection and pre-emptive analysis. The classical metaphor of balance, in which security and privacy are imagined as two weights placed on opposite sides of a scale, is no longer capable of accurately describing or regulating present realities. Within the big-data paradigm, the security side of the scale is structurally weighted from the outset, while the harms inflicted upon privacy are gradual, systemic, and frequently invisible, as exemplified by the chilling effect.
Continued reliance on analogue remedies—such as traditional judicial supervision of individual warrants—to address a digital problem—namely, algorithmic mass surveillance—will merely perpetuate the asymmetrical erosion of privacy. A sustainable solution lies not in seeking a new point of equilibrium, but in redesigning the architecture of surveillance itself. Such a redesign requires two fundamental conceptual transitions.
The first is a transition from the idea of security versus privacy to the idea of security through privacy. Contrary to widespread assumptions, technologies such as strong encryption are not enemies of national security. They constitute the foundation of the security of critical infrastructure, economic systems, and citizens’ communications against a wide spectrum of threats, whether state-sponsored or non-state in nature.
The second and more important transition concerns the redefinition of the principles of “necessity” and “proportionality” for the age of algorithms. Necessity can no longer be interpreted merely as the usefulness of mass data collection. Instead, it must be understood as requiring the complete absence of any less intrusive alternative. Likewise, oversight institutions can no longer confine their role to authorising the initial collection of data. They must be equipped with technical and algorithmic oversight capabilities that enable them to scrutinise how collected data are processed.
Because a substantial proportion of contemporary surveillance occurs inside the black boxes of artificial-intelligence algorithms, ensuring the transparency and accountability of these systems lies at the heart of the challenge ahead. Ultimately, the boundary between security and privacy in the digital age is not merely a legal boundary to be protected by judges. It is also a technical boundary that must be designed and embedded within the code and architecture of information systems.
References
- Aradau, C., & van Munster, R. (2007). Governing terrorism through risk: The precarious security of emergency politics. Review of International Studies, 33(2), 175-194. From: https://doi.org/10.1177/1354066107074290
- Lyon, D. (2018). The culture of surveillance: Watching as a way of life. Cambridge: Polity Press. From: https://www.politybooks.com/bookdetail/?isbn=9780745671727
- Mayer-Schönberger, V., & Cukier, K. (2013). Big data: A revolution that will transform how we live, work, and think. New York: Houghton Mifflin Harcourt. From: https://www.hmhbooks.com
- Penney, J. W. (2016). Chilling effects: Online surveillance and gasoline on the fire of self-censorship. Berkeley Technology Law Journal, 31(1), 115-176. From: https://lawcat.berkeley.edu/record/1127413/files/fulltext.pdf
- Sageman, M. (2008). Leaderless jihad: Terror networks in the twenty-first century. Philadelphia: University of Pennsylvania Press. From: https://www.pennpress.org/9780812240658/leaderless-jihad/
- Schneier, B. (2015). Data and Goliath: The hidden battles to collect your data and control your world. New York: W. W. Norton & Company. From: https://wwnorton.com/books/9780393352148
- Solove, D. J. (2008). Understanding privacy. Cambridge, MA: Harvard University Press. From: https://www.hup.harvard.edu/books/9780674027725
- Zuboff, S. (2019). The age of surveillance capitalism: The fight for a human future at the new frontier of power. New York: PublicAffairs. From: https://www.publicaffairsbooks.com/titles/shoshana-zuboff/the-age-of-surveillance-capitalism/9781478947271/






