Privacy is not just an abstract legal concept – it shows up in the most ordinary moments of daily life. From scrolling through social media to visiting a doctor, from working remotely to bumping into a celebrity at a restaurant, our personal boundaries are constantly tested. The real challenge lies not in defining privacy in theory, but in navigating the messy, context-dependent situations where it actually matters. Let’s break down five common scenarios that raise serious privacy questions and explore what they reveal about autonomy, trust, and consent in modern life.
Table of Contents
- Social media and third-party data sharing
- The Cambridge Analytica scandal
- Does sharing with a platform mean consenting to share with everyone?
- Personal journals and unauthorized access
- Autonomy and the right to control personal information
- The damage to trust
- Celebrities and public spaces
- Consent and reasonable expectations
- The paparazzi problem
- Workplace monitoring and employee privacy
- The scale of the problem
- Legal frameworks and ethical limits
- Medical confidentiality
- The ethical roots of medical confidentiality
- HIPAA and legal protections
- When confidentiality can be breached
- What these situations have in common
Social media and third-party data sharing
Every time you sign up for a social media platform, you hand over personal details – your name, email, location, interests, and more. But the data collection doesn’t stop there. Platforms track your likes, clicks, browsing patterns, and even your contacts to build detailed profiles about you. Much of this data is then shared with third parties, including advertisers, analytics firms, and sometimes government agencies, often without meaningful user awareness or consent.
The IEEE Digital Privacy initiative notes that users frequently agree to data-sharing terms buried in lengthy service agreements without understanding how their information will be used. The result is a vast, opaque system where personal data circulates far beyond the platform you originally trusted.
The Cambridge Analytica scandal
The most striking example remains the Cambridge Analytica scandal. A third-party app on Facebook collected personal data from users who took a personality quiz – but it also harvested information from all of their Facebook friends, ultimately affecting around 87 million users. This data was then transferred to Cambridge Analytica, a political consulting firm, which used it to target voters in elections. The users whose data was collected never consented to this use, and Facebook itself failed to enforce its own data policies.
The fallout was enormous. Facebook was fined $5 billion by the U.S. Federal Trade Commission for privacy violations. In 2022, it agreed to a $725 million settlement to resolve class action claims of improper data sharing. These cases made one thing clear: when platforms allow third parties to access user data without proper safeguards, the resulting harm is not hypothetical – it is real, measurable, and deeply personal.
Does sharing with a platform mean consenting to share with everyone?
Philosopher Helen Nissenbaum’s concept of contextual integrity is helpful here. According to this framework, privacy is violated when information flows outside the norms of the context in which it was originally shared. You might share your birthday with Facebook to receive birthday wishes from friends. That does not mean you consented to having it sold to an advertising network. The context of the original sharing matters, and when that context is broken, privacy is violated – regardless of what the terms of service technically say.
Even people who avoid social media entirely are not immune. The Electronic Privacy Information Center (EPIC) highlights that social media companies collect information about non-users through contact uploads, tracking pixels on other websites, and data-sharing partnerships. The reach of platform surveillance extends well beyond those who actively sign up.
Personal journals and unauthorized access
A personal journal is one of the most private forms of expression. It is a space where people record unfiltered thoughts, emotions, fears, and desires – things they may never share with anyone. Reading someone’s journal without their permission is a straightforward violation of their privacy, but the ethical reasons behind this go deeper than simple etiquette.
Autonomy and the right to control personal information
At its core, unauthorized access to a journal violates personal autonomy – the individual’s right to decide what information about themselves is shared and with whom. This principle is central to nearly every philosophical account of privacy, from John Stuart Mill’s emphasis on individual liberty to contemporary accounts by scholars like Moskop et al., who describe confidentiality as essential for preserving trust in interpersonal relationships.
A journal is not intended for public consumption. The writer exercises deliberate control over the boundary between their inner world and the outer one. When someone reads a journal without permission, they override this boundary. They access thoughts the writer may not have chosen to share – or may have expressed in a way they would never use in conversation. The reader gains an unfair, non-consensual insight into another person’s mind.
The damage to trust
Beyond the privacy violation itself, unauthorized journal reading damages trust. If someone discovers their journal has been read, the relationship with the person who read it is fundamentally altered. The sense of safety that made honest self-expression possible is now gone. This is why reading a partner’s, child’s, or friend’s journal – even with good intentions – is ethically problematic. The motivation (curiosity, concern, suspicion) does not override the person’s right to control their own private reflections.
This scenario also highlights an important distinction: privacy is not the same as secrecy. Keeping a journal is not about hiding wrongdoing. It is about maintaining a space for honest self-reflection. Violating that space treats the journal-keeper as someone who must be monitored, rather than as an autonomous person deserving of respect.
Celebrities and public spaces
Do celebrities have a right to privacy? The answer depends heavily on context. Photographing a celebrity at a public event – a film premiere, a press conference, a music festival – is generally considered acceptable. These are events where the individual expects and accepts public attention. But what about photographing a celebrity at a restaurant with their family? That situation is very different.
Consent and reasonable expectations
The key ethical concept here is reasonable expectation of privacy. At a public event, a celebrity is performing a public role. At a restaurant, they are a private person having a meal. Privacy law in several jurisdictions reflects this distinction. In France, for example, publishing photos of individuals without their consent is restricted, especially in private settings. In the United States, courts have generally allowed photography in public spaces, but California enacted anti-paparazzi legislation after the death of Princess Diana, criminalizing physical interference or trespassing by photographers to capture images of persons with a reasonable expectation of privacy.
The ethical difference between these two scenarios is not just about legality – it is about the purpose and impact of the photograph. A photo at a premiere serves a legitimate public interest in entertainment news. A photo of a celebrity eating dinner with their children serves no public interest; it satisfies curiosity at the expense of someone’s personal life.
The paparazzi problem
Paparazzi culture raises difficult ethical questions. Some argue that celebrities implicitly accept public scrutiny as part of their careers. But as journalism ethics scholars have noted, factors such as the newsworthiness of the information, the level of intrusion, and the public interest in disclosure must all be weighed when assessing whether a specific photograph or story is justified. Being famous does not mean forfeiting all personal boundaries. The right to privacy is a human right, not one that disappears with fame.
Aggressive paparazzi behaviour – stalking, trespassing, reckless driving – has caused documented psychological and even physical harm. Constant surveillance can lead to anxiety, paranoia, and depression among public figures. The ethical conclusion is clear: context matters. A public event is fair game; a private dinner is not.
Workplace monitoring and employee privacy
The rapid shift to remote work has brought workplace surveillance to a new level. Employers now use software that tracks keystrokes, monitors screen activity, records webcam footage, logs application usage, and in some cases, even tracks eye movements to determine whether an employee is paying attention during video calls.
The scale of the problem
According to a 2023 survey by ResumeBuilder.com, around 96% of companies with primarily remote workers use some form of employee monitoring software. Data from the American Psychological Association shows that 51% of employees who are electronically monitored feel micromanaged, and monitored employees are more likely to report negative impacts on their mental health. These are not minor side effects – they point to a fundamental tension between productivity tracking and human dignity.
Eye-movement tracking is a particularly intrusive example. Monitoring where someone looks on their screen, how long they focus on a task, or whether they glance away during a meeting treats the employee not as a trusted professional but as a subject of surveillance. It collapses the boundary between professional performance and personal bodily autonomy.
Legal frameworks and ethical limits
In the United States, the Electronic Communications Privacy Act (ECPA) of 1986 provides the federal baseline for workplace monitoring. It broadly prohibits interception of electronic communications but includes a “business purpose exception” that gives employers wide latitude when using company-owned devices and networks. Many states have begun enacting their own, stricter requirements. In the European Union, the General Data Protection Regulation (GDPR) requires that any monitoring be necessary, proportionate, and transparently communicated to workers.
The ethical standard, however, goes beyond legal compliance. Effective monitoring should be transparent (employees know what is being tracked and why), proportionate (limited to what is genuinely necessary for business purposes), and respectful (avoiding collection of personal or off-duty information). A 2023 report from the White House Office of Science and Technology found that surveillance tools can be inaccurate measures of productivity, encourage performative busyness over meaningful work, and erode trust between employees and management.
Medical confidentiality
The relationship between a doctor and patient depends on trust. Patients share their most sensitive information – symptoms, mental health struggles, sexual history, substance use – because they trust that this information will remain confidential. When a doctor or any healthcare worker shares patient information without consent, they do not just break a rule. They undermine the entire foundation of medical care.
The ethical roots of medical confidentiality
The duty of medical confidentiality is one of the oldest principles in healthcare ethics. The World Medical Association’s Declaration of Geneva includes a pledge to respect patient secrets even after the patient has died. This commitment exists because patients who fear their information might be disclosed are less likely to seek treatment or to be honest with their doctors. Medical confidentiality is not just about protecting individual rights – it is about ensuring that the healthcare system functions effectively for everyone.
HIPAA and legal protections
In the United States, the Health Insurance Portability and Accountability Act (HIPAA) provides the legal framework for protecting patient information. HIPAA’s Privacy Rule applies to virtually every department in a medical facility. Only the minimum necessary health information should be disclosed during any healthcare interaction, and sharing information with anyone not actively involved in a patient’s treatment requires explicit consent.
The consequences of violating HIPAA are severe. Civil penalties can reach up to $1.5 million per year for ongoing violations. Criminal penalties include fines up to $250,000 and imprisonment. Real-world examples illustrate the gravity of these breaches: hospital staff revealing a patient’s HIV test results in a waiting room, a surgeon illegally accessing celebrity medical records, and medical assistants gossiping about patients’ test results to personal acquaintances. In one documented case from NORCAL Group, a medical assistant disclosed that a patient had been tested for a sexually transmitted disease, leading to damaging rumors and significant emotional distress for the patient.
When confidentiality can be breached
Medical confidentiality is not absolute. There are legally and ethically recognised exceptions. Doctors are required to report certain infectious diseases to public health authorities. They must report suspected child abuse or elder abuse. In some jurisdictions, physicians have a duty to warn identifiable third parties who may be at risk of harm from a patient. These exceptions exist because confidentiality, while important, sometimes conflicts with the equally important obligation to prevent serious harm to others.
The key point is that any breach of confidentiality must be justified by a specific, compelling reason. A doctor sharing patient details out of casual conversation, curiosity, or carelessness has no such justification. The ethical breach in such cases is profound because it violates the patient’s autonomy, damages trust in the healthcare system, and can cause real-world harm – from discrimination and social stigma to emotional suffering and loss of employment.
What these situations have in common
Each of these scenarios – data sharing, journal reading, celebrity photography, workplace monitoring, and medical confidentiality – illustrates the same core principle: privacy is about control over personal information. It is not about having something to hide. It is about the right to decide who knows what about you and under what circumstances.
Context matters enormously. Information shared willingly in one context (with a doctor, on a social media profile, at a public event) does not automatically become available for use in every other context. When that contextual boundary is broken – by a third-party data broker, a snooping colleague, an aggressive photographer, an employer’s surveillance tool, or a careless healthcare worker – privacy is violated, regardless of whether the information itself seems “harmless.”
These everyday privacy dilemmas also reveal how power imbalances shape privacy violations. Social media users have far less power than the platforms that collect their data. Employees have less power than employers who monitor them. Patients are vulnerable in relation to their doctors. Recognising these imbalances is essential for building ethical frameworks that protect privacy not just in principle, but in practice.
What do you think? Should the right to privacy depend on the context in which information is shared, or should there be universal rules that protect personal data regardless of the situation? And in an age of constant digital surveillance, is true privacy even possible anymore?
References
- https://digitalprivacy.ieee.org/publications/topics/privacy-risks-and-social-media/
- https://en.wikipedia.org/wiki/Privacy_concerns_with_social_networking_services
- https://www.ama-assn.org/practice-management/hipaa/hipaa-violations-enforcement
- https://epic.org/issues/consumer-privacy/social-media-privacy/
- https://pmc.ncbi.nlm.nih.gov/articles/PMC7132445/
- https://en.wikipedia.org/wiki/Celebrity_privacy
- https://fiveable.me/law-and-ethics-of-journalism/unit-3/celebrity-privacy-paparazzi/study-guide/pHu7ZnGdwrvqjzGd
- https://www.businessnewsdaily.com/6685-employee-monitoring-privacy.html
- https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html
- https://www.techtarget.com/searchcio/feature/What-CIOs-must-know-about-bossware-strategy
- https://www.ncbi.nlm.nih.gov/books/NBK519540/
- https://www.norcal-group.com/library/patient-confidentiality-understanding-the-medical-ethics-issues
Leave a Reply