Saying You’re Afraid Is Not Being Protected

Is the privacy paradox a myth? On the fissure between what we declare and the architecture we live in


Abstract

People say they place a high value on privacy, yet in their behaviour they hand over their personal data for small rewards, sometimes for nothing at all. This mismatch is known as the “privacy paradox.” Two opposing camps have formed in the literature: on one side, those who argue that behaviour reveals the true preference, that privacy is therefore of little value, and that regulation should be loosened; on the other, those who argue that behaviour is distorted by cognitive biases, manipulation and ignorance, and that the distortion must therefore be corrected. Daniel Solove (2021) takes a third and radical position: the paradox is a myth, because behaviour is a risk decision in a particular context while an attitude is a general value judgment; the two are different things, and their divergence is not a contradiction.

This essay begins where Solove is right, but does not stop where he stops. First we bring into focus a distinction the literature has largely overlooked: privacy and security are not the same thing. Privacy is the question of who sees information, and in what context; security is the question of whether information is protected against unauthorised seizure. The privacy-paradox literature frames the phenomenon mainly along the privacy axis. Yet a particular type of case, the user who voices security concerns at high volume but keeps a sensitive document in a large commercial cloud and conducts communication through a platform that, even when the content is encrypted, commercially processes the whole map of the relationship, speaks the language of security and does not fit neatly into Solove’s frame of “contextual rational risk.” Here the contradiction is not between attitude and behaviour; the contradiction is between the declared threat model and the actual threat architecture. Moreover, the person conflates two axes: they mistake a large brand’s security reputation for a privacy guarantee. In the end, the discourse “security is everything to me” turns into a performative ritual and takes the place of the actual experience of being protected: the person feels protected because they have declared it. We feed this reading with Acquisti and colleagues’ (2015) findings on the control paradox and on malleability, and try to show that the behaviour is not a character flaw but a predictable output of normal cognition inside a broken information architecture.


1. Introduction: the one who says and the one who does

Picture a common scene. A person places a high value on privacy: they say their data must be protected, they explain that there is no trust without security, they stress that the digital world must be approached with caution. Notice that the language they use is, from start to finish, a language of security: secret, protection, password, the danger of a breach. Then the same person uploads a sensitive document containing identity details and a signature to an ordinary commercial cloud storage account. They conduct their everyday correspondence through a large platform that, even when the content is encrypted, records who they talk to, when, and how often, and ties this map of relationships to the advertising economy. From an alternative that collects far less of their data, they keep their distance, saying “I don’t know it” or “it can’t be trusted.”

The scene looks inconsistent. The first reaction is easy and is voiced often: “This person doesn’t know what they’re saying; what they say contradicts what they do.” This essay begins with that first reaction, but treats it as a question rather than a conclusion. Because this scene is not the exception, it is the rule. Millions of people, millions of times, behave in exactly this way. When a phenomenon is this widespread, explaining it as a personal flaw is scientifically weak. What is common points to a structure that needs explaining.

Our question is this: why does a person fail to protect the very thing they say they care about? And, more sharply: why, without protecting it, do they feel protected? This second question is where the essay’s real contribution is born.


2. The privacy paradox: definition and a preliminary distinction

The phenomenon has been observed for close to half a century. In one of the earliest experiments, people interacting with an anthropomorphic shopping bot shared, in flat contradiction of the privacy concern they had declared, “enough information for a fairly revealing profile of themselves to be built up in a single shopping session” (Spiekermann et al., 2001, as cited in Solove, 2021). In the years that followed, dozens of studies repeated the same pattern: people give their date of birth and monthly income for a one-euro discount; they sell their browsing history for eight dollars; and although a free email service scans the content, they will not pay more than fifteen dollars a year for an alternative that does not (Solove, 2021).

Privacy and security: two separate axes

Before going further, we must separate two concepts that are often used interchangeably but are in fact distinct, because the case at the heart of this essay sits precisely on that distinction.

Security is the protection of information against unauthorised access, seizure and corruption. The classic framework of information security gathers this under three headings: confidentiality (only the authorised may reach the information), integrity (the information cannot be altered without permission) and availability (the information is at hand when needed). The question of security is: Can an attacker steal, intercept or corrupt this data? Its breach is concrete: account takeover, leak, password cracking, a man-in-the-middle attack.

Privacy is a different question: Who sees this data, in what context, and for what purpose? Privacy is breached when information is torn from its own context and poured into another. A piece of data may be technically flawless in its protection, unreachable by any attacker; but if the company providing the service scans it, profiles it, opens it to third parties, or hands it to the state on a legal request, then security is high and privacy is low.

The two axes vary independently of each other. A large commercial cloud service may be extremely secure against attackers (strong infrastructure, encrypted storage, two-step verification) yet weak on privacy, because the owner of the service reaches the data. A messaging app may raise security by encrypting content end to end, yet still be weak on privacy if it collects and commercially processes who talks to whom, when and how often (that is, the metadata). By contrast, an app that both encrypts content end to end and minimises metadata collection raises both axes at once. This simple-looking distinction is the key that will unlock the heart of the case in Section 6.

Here we must also flag a trap of terminology: the sub-heading of security called “confidentiality” (the prevention of unauthorised access) and the everyday sense of privacy as “keeping something secret” go by the same word yet are different things. Solove’s warning, which we will see below, that “privacy is not secrecy” is aimed precisely at this confusion. This interweaving of concepts is not merely a linguistic problem; as we will see shortly, it is also the source of the real confusion in people’s heads.

The large body of the privacy-paradox literature builds the phenomenon along the privacy axis: to whom are people opening their data, are they willing to be profiled for advertising, are they sharing selectively. The case of this essay, by contrast, places at its centre a user who speaks in the language of security. The tension between the two is the original vein of this work.

Two camps

The answers given to the mismatch in the privacy paradox gather into two camps.

First camp: the behaviour-valuation argument. Behaviour is a more reliable measure than declaration. In the language of economics, attitudes are counted as “stated preference” and behaviour as “revealed preference”; the revealed preference is the true one. Since people trade their data away cheaply, they must place little value on privacy. Conclusion: privacy regulation overvalues privacy and should be rolled back (authors such as Cooper, Ben-Shahar, Goldman; as cited in Solove, 2021).

Second camp: the behaviour-distortion argument. Behaviour does not reflect the true preference, because it is distorted. Cognitive biases, framing effects, manipulative interface design (dark patterns), ignorance and inertia warp people’s choices. Conclusion: regulation should reduce these distorting effects, so that people can make choices in line with their true preferences.

What is interesting is this: most of those who defend the second camp are the authors of the very studies that revealed the paradox. They are researchers who grew uneasy with their own findings, called them “troubling” and “disturbing,” and tried to explain the behaviour (Solove, 2021). It is precisely here that the three legs of this essay’s conceptual spine are set: first the strongest form of the second camp (Acquisti), then the position that rejects both camps (Solove), and finally the fissure that neither of them sees.


3. The first explanation: “behaviour tells the truth,” and why it falls short

The behaviour-valuation argument is intuitively appealing: look not at what a person says but at what they do. But it carries a logical error, and Solove shows this error most clearly. From the fact that a person gives a particular store, at a particular moment, a particular piece of data for one dollar, it does not follow that this person “values privacy at one dollar.” All that follows is that, in that specific transaction, they judged the risk to be low. The argument leaps from a narrow observation to a broad generalisation. To see why the leap is invalid, we first need to understand how volatile behaviour is; and this takes us to the second camp.


4. The second explanation: behaviour is distorted, Acquisti’s three themes

Acquisti, Brandimarte and Loewenstein (2015), in their comprehensive review in Science, organise privacy behaviour around three interconnected themes. These three themes explain the paradox without belittling it as “irrationality.”

Uncertainty. The person is uncertain on two levels: about both the consequences of their sharing and their own preferences. In the authors’ striking phrase, when it comes to the consequences of privacy and their own feelings, people are often “at sea” and search for cues to guide their behaviour (Acquisti et al., 2015). Information is asymmetric: when data is collected, by whom, and to what end is mostly invisible. Moreover, the person does not even know their own preference; privacy is no exception to the rule that “people have poorly defined preferences about how much they like a good, a service, or other people.”

Context dependence. The same person may be indifferent to privacy in one situation and excessively anxious in another. Because a person mired in uncertainty clings to cues, behaviour too shifts with context. Westin’s famous typology of the “privacy fundamentalist, pragmatist, and unconcerned” is not a set of fixed personality types; in the authors’ words, “we are all privacy pragmatists, fundamentalists, or unconcerned, depending on time and place” (Acquisti et al., 2015).

Malleability. Here is the most critical theme for our essay. While the person is unaware of the factors that shape their own concern, the institutions whose welfare depends on others’ disclosure of information are experts in those factors. Default settings, interface design, the sense of control: these can activate or suppress privacy concern. A sentence the authors set down at the very start is the seed of our thesis: on social media, “providing more control can create an illusion of security and encourage more sharing” (Acquisti et al., 2015).

These three themes spill into concrete and unsettling findings:

Hold on to this last finding. In the laboratory it is proof that a person places the real threat in the wrong place, and it opens directly onto the essay’s fissure.

Do Acquisti’s three themes represent the whole field? The most orderly answer to this question comes from reviews that systematically scan the heading “privacy paradox.” Gerber, Gerber and Volkamer (2018), in a review in which they sifted 181 relevant studies and examined thirty-eight quantitatively, divide the approaches the literature has produced to explain the paradox into eight families: the cost-benefit calculation (privacy calculus), bounded rationality and decision biases (the core of Acquisti’s themes), lack of personal experience and technical knowledge, social influence, the risk-trust balance, the quantum decision model, the illusion of control, and finally the claim that the paradox may be a “methodological artefact.” This inventory sets Acquisti’s conceptual frame within a broader map: uncertainty, context dependence and malleability are patterns the field rediscovers again and again under different names.

The review’s most striking side is its empirical weighing. When the effect sizes of dozens of studies are laid side by side, the strongest and most stable predictor turns out to be the cost-benefit calculation: the concrete gain people expect from sharing is the variable that best predicts both the intention to share and actual sharing (Gerber et al., 2018). By contrast, the evidence for models that explain the paradox by “cognitive bias” alone is weaker than expected; and demographic factors are almost negligible. This result carries two implications for our essay. First, to read behaviour as an “irrational heap of biases” is a more assertive reading than the data support; a person largely makes, however flawed, a calculation of benefit. Second, and more important, this finding opens the door of the next section: if behaviour is essentially a benefit-risk decision embedded in context, then comparing it to a general “value” judgment and declaring a “contradiction” may be a comparison wrongly set up from the start.

The mechanics of manipulation: five biases and dark patterns

Acquisti’s “malleability” theme opens a door but stays abstract: which biases, which design? Ari Ezra Waldman (2020) takes the same phenomenon up at exactly this concrete level. He argues that the rational-actor model, the assumption that a person, once informed, will make the disclosure decision best suited to their own interest, collapses not only in practice but in principle, because widespread cognitive barriers distort the disclosure decision. Waldman lists the five most common.

Anchoring. Disproportionate attachment, at the moment of decision, to the first piece of information seen. In an experiment Waldman reports, participants who were first shown increasingly revealing selfies subsequently disclosed more about themselves; the images they saw anchored their sense of “what is appropriate to share” (Chang et al., 2016, as cited in Waldman, 2020).

Framing. The good or bad presentation of the same option changes the decision. Technology companies frame data collection in steering language: “if you don’t allow cookies, functionality will be reduced,” or “turning on data collection brings new conveniences” (Waldman, 2020). The positive side is foregrounded, the cost made invisible.

Hyperbolic discounting. Overstating the immediate consequence and understating the future one. The benefit of disclosure (convenience, access, social interaction) comes at once, while its risk is often felt much later; this is why a person is more inclined to share now. In one study, users agreed to give up more personal information for a slightly cheaper cinema ticket, even when a privacy-friendly option was available at the same price (Jentzsch et al., 2012, as cited in Waldman, 2020).

Overchoice. Too many choices paralyse a person. In privacy the problem is not the existence of options but the number of choices a person is forced to make; mobile apps sometimes ask for more than two hundred permissions (Hartzog, 2018; Olmstead & Atkinson, 2015, as cited in Waldman, 2020).

Metacognition. A person sometimes reads the difficulty of a decision as a signal of “importance,” sometimes of “impossibility.” When protecting privacy looks hard, many people take this as a sign of impossibility, give up nihilistically, and leave the decision to the default (Mourey, 2019, as cited in Waldman, 2020). This gives a cognitive ground to Solove’s “resignation,” which we will see shortly.

These biases do not operate on their own; design turns them into weapons. Waldman calls the design tricks that steer a user toward actions they would not otherwise take “dark patterns,” and reports the field’s established definition: dark patterns are “interface design choices that benefit an online service by coercing, steering, or deceiving users into making decisions that, if fully informed and capable of selecting alternatives, they might not make” (Mathur et al., 2019, as cited in Waldman, 2020). Waldman likens the power of design to a magician’s sleight of hand: the magician “gives people the illusion of free choice while architecting the menu so that no matter what they choose, he wins” (Harris, 2016, as cited in Waldman, 2020).

The conclusion Waldman reaches coincides exactly with the spine of this essay. For him, the supposed paradox “does not reflect users’ disinterest in privacy; rather, it reflects users responding in predictable ways to the ways in which platforms leverage design to take advantage of our cognitive limitations” (Waldman, 2020). The rational-actor regime, on this reading, is not accidentally but by design “set up to fail” (Richards & Hartzog, 2019, as cited in Waldman, 2020).


5. The third explanation: there is no paradox, Solove

Solove (2021) takes a position that transcends both camps: the paradox is not a paradox, because there are not two things that need to match. What is interesting is that this intuition is not alone. The eighth explanation of the systematic review we mentioned in Section 4 also suggests that at least part of the paradox may be a “methodological artefact”: attitude is often measured on a continuous scale (how much do you care?), behaviour on a binary criterion (did you keep this profile public?); to measure two different things with different instruments and then be surprised that they do not match may be to mistake measurement error for a phenomenon (Dienlin & Trepte, 2015, as cited in Gerber et al., 2018). Gerber and colleagues leave this possibility as a cautious hypothesis; Solove carries the same intuition to its extreme at the conceptual and legal level.

Risk is not value. The behaviour in paradox studies is not about the value of privacy; it is about risk in a particular context. Risk is the potential for harm; value is the general importance attributed to a thing. When a person gives the title of their book away for a one-dollar discount, the only thing that follows is: “In this moment, to this store, for this data, they judged the risk low enough to accept the one-dollar reward.” Solove shows this with a “short quiz” and says the correct answer is “none of them.”

Valuing your own privacy is different from valuing privacy. A person may not choose privacy for themselves and yet still find privacy valuable. Solove’s analogy is clear: a person may value the right to vote in general while not voting themselves; not voting does not mean they do not value the right to vote.

Privacy is not secrecy. To share data is not to give up all privacy. People do not want to hide their information from everyone; they want to share selectively and to make sure it is not used harmfully. In the Information Age, sharing no data at all is possible only by “living in a cabin in the woods”; sharing does not mean not valuing privacy. (This third distinction is Solove’s counterpart to the terminological trap we opened in Section 2: privacy is not “keeping everything secret.”)

Self-management does not scale. Here is Solove’s political blow. Current regulation tries to protect privacy through “privacy self-management”: read the policies, opt out, change the settings. But this project is enormous, complex and endless. Reading all the relevant privacy notices would take a person roughly 201 hours a year (McDonald & Cranor, 2008, as cited in Solove, 2021). With thousands of institutions, opting out thousands of times is like “emptying the ocean with a cup.” Even a fully rational person cannot manage it.

Resignation is rational. In the face of this impossibility, resignation is a rational response. Solove admits that even he, as a privacy expert, has given up. The control offered is an illusion, “busy work”; people are given more buttons, switches and checkboxes, but these are not real protection. And a vicious circle runs: the person voices their concern, they are given self-management, they fail at the impossible project, they grow frustrated and resign, but the concern persists; the cycle repeats. The blame is placed on the individual, and the individual even blames themselves.

The solution: regulate the architecture. Privacy regulation, then, must give up making the individual a manager and instead regulate the architecture that structures how information is used, stored and transferred. Privacy is not a good bought and sold in the market but a constitutive element of a free society; in Tufekci’s (2018) words, “[d]ata privacy is more like air quality or safe drinking water, a public good that cannot be effectively regulated by trusting in the wisdom of millions of individual choices.”

What is remarkable is this: Acquisti and Solove meet here. Acquisti too concludes that “policy approaches that rely exclusively on informing or empowering the individual are unlikely to provide adequate protection; transparency and control, when used alone, are radically insufficient and may even backfire” (Acquisti et al., 2015). Two sources, by different roads, arrive at the same door: do not blame the individual, regulate the architecture.


6. The fissure: between declaration and architecture

Up to here the literature has given us solid ground. Now we begin where it ends.

Return to the scene in the Introduction. The user who voices security concerns yet puts their sensitive document in a general cloud, conducts communication through a large platform that commercially processes its metadata, and says “I don’t know it” to an alternative that collects less data. Solove’s frame explains part of this scene: “security matters” (a general attitude) and “the document is in the cloud” (a contextual risk decision) are different axes, so it is a mistake to look for a contradiction between them. True. But Solove’s frame cannot explain the heart of the scene. Because the critical point here is not the “general attitude versus specific risk” distinction. The critical point is this: the person, while speaking the language of security, gives away the very thing they want to protect, precisely on the privacy axis. In Solove’s model behaviour is a contextual but sound risk assessment. Here, by contrast, the risk assessment itself has strayed off its axis: the person fixes on the security threat and never sees the privacy threat.

What explains this straying is not Solove but Acquisti. The lens that sees it best is the privacy-versus-security distinction we set up in Section 2. The user in the case speaks the language of security, but conflates two separate things.

First, axis conflation. When the person chooses a large commercial cloud or a large messaging platform, they in fact make an intuitive security judgment: “This company is huge, its infrastructure is solid, its service is encrypted, it protects me from an attacker.” This judgment, on the security axis alone, is largely correct; the content may indeed be protected against unauthorised access. The error lies in mistaking this security assurance for a privacy assurance. Because that giant company itself reaches the data, or its metadata; the “third party” they fear is already inside. Because the person sees the brand’s security reputation, they never see the privacy risk. They take two axes for one; being right on one leads them to be blind on the other. The terminological trap of Section 2 takes on flesh and bone here: what they think is “secure” really is secure, but it is not “private”; and the person never feels the difference.

This does not make the person irrational; a point must be stated plainly here, because it may seem to conflict with the empirical finding of Section 4. As Gerber and colleagues showed, a person largely makes a benefit-risk calculation. Axis conflation does not abolish this calculation; it feeds a wrong risk input into it. Because the person takes the privacy risk to be near zero, even a well-functioning calculation arrives at the wrong result. The error is not in the reasoning itself but in the risk map that enters the reasoning. This is why the same behaviour can be both rational (consistent with the given map) and wrong (the map does not reflect reality); the two do not conflict. Gerber’s finding that “the strongest predictor is the cost-benefit calculation” and our claim that “the person is mistaken” are reconciled precisely on this distinction: the error is not in the calculation but in the data given to it.

This distinction has a concrete counterpart. A common messaging app secures content by encrypting it end to end, while collecting the metadata that shows who connected with whom, when and how often, and tying this to the advertising economy; the content is protected, the map of relationships is not. To the same service there is an alternative that also encrypts content end to end but minimises metadata collection. Both apps are strong on the security axis; where they diverge is the privacy axis. The person often chooses the more familiar, larger, more heavily advertised one as “secure” and never notices the point where the two axes diverge. Familiarity is not a privacy guarantee; but it feels like one.

Second, the wrong threat map. When a person calls a service “untrustworthy” or another “trustworthy,” they run a threat model; but this model is often built not from the real data architecture but from the comfort of familiarity, the size of the brand, and hearsay signals. The familiar and the large are taken to be safe; the little-known, untrustworthy. Yet how well a service protects your data is determined not by how familiar it is but by who sees the data and what they do with it. This is the exact everyday counterpart of the “How Bad R U” experiment in Section 4: a person misreads the security signal and confuses its source (familiarity, visual professionalism) with real protection. It is the direct result of the themes of uncertainty (a person does not know their own risk, they are “at sea”) and malleability (wrong cues turn concern in the wrong direction).

These two errors do not arise on their own in the individual’s head; they are produced by design. Axis conflation has a footing in the literature: Waldman (2020) shows that trust is itself the target of design and a tool of manipulation. In his account, “websites cue trust through professional design while hiding their invasive data collection practices in inscrutable privacy policies” (Waldman, 2020). That is, a person’s reading of the large, professional brand as a sign of trust is not individual naivety but an effect design aims to produce. Axis conflation is the crystallised form, on the privacy-versus-security axis, of what Waldman calls “the manipulation of trust”: the person mistakes the sense of security radiated by a professional interface for a privacy assurance about who reaches the data.

From here we propose the first half of the thesis:

The contradiction is not between attitude and behaviour (Solove is right); the contradiction is between the declared threat model and the actual threat architecture. A person declares a threat map, but this map does not overlap with the geography of the real data flow. Moreover, one root of the map’s distortion is the inability to separate privacy from security: the person takes the correct decision made on the security axis to hold on the privacy axis too. They position their defence not against the real threat but against an imaginary one; and so they are left defenceless precisely where they think they are protected.

The second half of the thesis is deeper and carries the truly original vein. The person in the case has not merely drawn a wrong map; by declaring that map out loud, they produce a function for themselves. The sentence “security is everything to me” is not a description but an act. As the person says it, saying it gives them the feeling of protection. In place of an actual act of protection (choosing a service that collects no metadata, keeping the data secure), a discourse of protection takes over. We name this as follows:

Discourse taking the place of experience (performative declaration). The person declares that they are protected, and the declaration takes the place of the actual experience of being protected. Because they have declared it, they feel protected. This feeling is a layer above Acquisti’s control paradox: there the control given to the person lowered the defence; here the discourse the person produces lowers the defence. In both, the mechanism is the same: the feeling of security takes the place of security itself and, paradoxically, reduces protection.

The difference between Solove’s “resignation” and this “false comfort” is important. Solove’s resigned person is passive: they sense they cannot be protected, they give up, but they know it. The person here, by contrast, believes they are protected: they do not sense that they cannot be protected; on the contrary, their own declaration has given them this belief. Resignation is helplessness with open eyes; false comfort is an openness veiled by the feeling of protection. The difference between the two is not a crime but a difference of cognitive state; and this difference will explain, in Section 8, why the solution cannot be “more declaration.”

An honest limit must be set here. “Performative declaration” is not a directly measured finding but a proposal derived by analogy from the experimentally proven mechanism of the control paradox. That the sense of control lowers the defence has been measured (Brandimarte et al., 2013); whether the act of declaring likewise produces a “feeling of protection” and lowers the defence has not yet been tested, and is a hypothesis open to testing. This is the essay’s most fragile and at the same time most testable claim; we mark it not as a proven fact but as what it is, a proposal.


7. Not a pathology: the cognitive naturalness of a widespread phenomenon

Now we can return to that first reaction in the Introduction: “This person doesn’t know what they’re saying; they’re inconsistent.”

This judgment is wrong, and why it is wrong is now clear. The behaviour in the case is not an inconsistency or a flaw but a predictable output of normal human cognition. Uncertainty is universal (Acquisti): a person often knows neither their own risk nor their own preference. Context dependence is universal: the same person is cautious in one place, open in another. Misreading a cue has been produced again and again in the laboratory: people may take the safe for dangerous and the dangerous for safe. And to conflate privacy with security a person need not even be careless; the two concepts are genuinely interwoven in language and experience, and go by the same words. Self-management genuinely does not scale (Solove); resignation genuinely is rational. If a behaviour is repeated in millions of people and its mechanism can be explained cognitively, then to count it a personal weakness is both scientifically mistaken and methodologically unproductive. To place the blame on the individual is the last link in the vicious circle Solove exposed: first the person is given an impossible task, then, because they fail it, it is said “so they don’t care.”

But does the phenomenon play out entirely outside the person? No; but the meaning of this is not a crime but a mechanism. The real determinant is the architecture that constantly pushes the person to give the wrong signal, to trust the large brand they know, to lower their defence with the sense of control. Default settings, dark patterns, the false assurance produced by the “we have a policy” badge, the way large brands foreground their security reputations (robustness, encryption, certificates) while making the privacy cost (their own access to the data or its metadata) invisible: these are all effects produced by design. Even axis conflation does not arise on its own, it is fed. The individual plays on a stage set up for them; the relief given by performative declaration is a part of this stage too, because the architecture can offer the person not the reality of protection but only its feeling, through instruments (more buttons, more policy text, more “control”).

Thus the naive judgment of the Introduction is turned on its head. What needs explaining is not why the person behaves “erratically”; what needs explaining is how a well-functioning cognition goes predictably wrong inside a badly built information architecture. This is not a pathology but a result of ordinary cognition shaped by design. And this is why the centre of gravity of responsibility shifts from the individual to the architecture; the policy proposal of the next section is born directly from here.


8. Conclusion

The privacy paradox, in its classic sense, really is a myth. Solove is right: attitude and behaviour are different things, and their divergence is not a contradiction. Moreover, this false paradox is often used as a weapon to undermine privacy regulation. But the refutation of the myth does not mean that nothing is left to explain. Beneath the false paradox lies a real fissure: the fissure between the threat model a person declares and the actual threat architecture they live in. Two things open this fissure. One is the confusion of privacy with security: the person takes the correct decision made on one axis (security) to hold on the other (privacy) too, and so gives away information precisely where they trust. The other is the way the discourse of protection takes the place of the experience of protection: declaring takes the place of protecting.

This diagnosis has two consequences. At the policy level, the direction pointed to by both Acquisti and Solove is right: to “empower” the individual more, to give them more buttons and policy text, does not work and even backfires by feeding false comfort. The burden of protection must be lifted from the individual’s back and loaded onto the architecture of the data economy. Waldman (2020) proposes a concrete legal mechanism in this direction: companies that collect data should be counted, like the responsibility a lawyer, a physician or a financial adviser carries toward us, as “information fiduciaries” of our data, entering into duties of care, confidentiality and loyalty. The duty of loyalty forbids the company from profiting by using us to our own harm; within this frame, forcing disclosure through dark patterns is legally barred. Thus three sources (Acquisti, Solove, Waldman) arrive by different roads at the same door: the burden is lifted from the individual and loaded onto the architecture that holds the data and the company that builds it.

But something remains to be said at the individual level too, and this is where the literature falls silent: the antidote to false comfort is not more declaration but the seeing of two things. First, “secure” and “private” are not the same thing; the protection of data from an attacker does not mean its protection from the company that holds it. Second, there is a distance between “I say I care” and “I am protected.” Seeing these two distinctions does not close the distance on its own; but it at least makes it visible. And to make it visible is the first step not of blaming the individual but of correcting the architecture: when a person can tell apart what is protected from what is not, they can begin to direct the right question to the right place, that is, to the architecture that builds the service.

Saying you’re afraid is not being protected. Seeing the difference between the two is this essay’s single, and hard enough, proposal.


References

(APA 7. Primary sources that were read are given with full bibliographic detail; secondary sources are shown with the abbreviation “as cited in,” because their full texts were not directly accessed in this work. Direct quotations were taken from the raw text of the primary sources and confirmed by comparison.)

Conceptual and factual ground (not citation, but framing)

Version 1.1 · Revised: 21 July 2026 · The Tufekci quotation restored to the source wording, reference linked to the correct publication

Permanent archival record, all versions: 10.17613/n24yh-r4d79 · Knowledge Commons