The back door surveillance state
A deep dive on the history of the links between surveillance capitalism and the surveillance state.
Introduction
Both Big Tech and government security services operate large scale surveillance. How do they relate to one another? In the West we say "Aren't we lucky we don't live in a surveillance state like China!" but haven't we just privatised the surveillance?
Since 2018 we're in a weird limbo where on the one hand the GDPR law exists, giving Europeans digital privacy rights, and on the other hand security services operate a dragnet surveillance machine. In the US no such federal-level privacy law exists, but a few states have privacy laws. We've always found it a bit suss that governments have failed to regulate Big Tech, despite obvious privacy violations, during the same period we have seen the rise of 'Predictive Policing'. The most obvious feature of that is the spread of facial recognition technology, but we will look deeper than that, into the everyday harvesting of information from every citizen with an internet connection. I saw a comment on Mastodon recently that said:
"Big tech's primary business model has been to allow the government to buy technically private surveillance data and therefore skirt laws against spying on citizens"
We certainly don't want our national security services to be 'blind', but we also don't want widespread surveillance of citizens. Privacy is a human right after all, and no one acts naturally when they feel like they're being watched. This article explores the history of the relationship between government and private surveillance, from spies in the second world war to the every day assault on privacy we are living with today.
We hope that rather than just waving our arms around and saying "we're being surveilled!", if we lay out the evolution of state surveillance you'll see that the trend points towards a 'back door' surveillance state. This is defined as surveillance by the state but 'by the back door' i.e. the information is not gathered via democratically accountable government channels, but instead via privately-owned channels such as social media or the data free-for-all that is the targeted ads industry and data brokers.
Contents - click to expand
How we got here - jump to section
Surveillance advertising is still just surveillance - jump to section
Recent developments (since 2024) - jump to section
Conclusion - jump to section
How we got here
Pre-9/11
The dominant world power since the second world war has been the USA, and they have a close security relationship with the UK, Australia, New Zealand and Canada via the 'Five Eyes coalition'. This Science Focus article provides a succinct history of US miliary surveillance since then (link added by us for added context from another source):
During the early years of the Cold War in the 1950s, Washington carried out 170 clandestine operations in 48 nations. Over the next 50 years, the CIA would covertly manipulate 80 elections worldwide and, when such efforts failed, promote many of the military coups that roiled more than 30 nations between 1958 and 1975. Under a secret treaty signed in 1946, the National Security Agency (NSA) and its British counterpart GCHQ built a worldwide signals surveillance through the Five Eyes coalition of the US, the UK, Australia, New Zealand and Canada, with its Echelon surveillance programme, established in the 1960s.
A key point to note throughout this whole article is that it's not just authoritarian states that use intelligence to interfere in other countries' affairs. It's also the UK, the US, the EU - all governments do it. What's changed over time is the nature of the intelligence they use.
Evolution of Echelon
For a bit of fun you can 'see' Echelon in (fictionalised) action in the 2025 film Heads of State. If that's to be believed, Echelon is a massive 'all seeing eye' dragnet of surveillance that allows the US security services to track anyone, anywhere. That element is most likely over-dramatised (it's a film after all) but as we'll see, it's not that far off the truth.
However it was not a one way street. In 1978 the FISA act was passed in the US to clarify the boundaries between domestic and foreign surveillance, and what the government could and could not do without legal justification. Privacy for citizens was stengthened.
9/11 onwards
However, 9/11 (2001) appears to have changed everything. In 1998 the Childrens Online Privacy Protection Act (COPPA) was passed, strengthening privacy online for children. A more comprehensive federal privacy law, for all age groups, was being debated in 1999. This law would have been the Online Privacy Protection Act (OPPA), but was abandoned in the wake of 9/11 in favour of the Patriot Act.
The Patriot Act paved the way for the US government to surveil anything, domestic or foreign, in a comprehensive "collect it all, just in case" manner. This, of course, was all in the name of the 'War on Terror'.
Snowden
Then in 2013 an NSA contractor called Edward Snowden leaked a large amount of top-secret documents that revealed the true extent of the US government's surveillance of its own population, and the extent of surveillance generally by the 5 Eyes nations, as well as the data sharing agreements between them. Since Snowden there is also reference to a wider sharing coalition called the Fourteen Eyes, which includes Denmark, France, the Netherlands, Norway, Belgium, Germany, Italy, Spain, and Sweden.
Cambridge Analytica
In 2016 a British data analytics firm called Cambridge Analytica used Facebook to help the Brexit and Trump campaigns. (If you don't know much about this topic then we advise you to pause now and read those Wikipedia articles, as this scandal was a HUGE inflection point). This proved that widespread harvesting of citizen behavioural data can easily be misused. In these cases it was used to sway the voting of individuals in elections by bombarding 'swing' voters with tailored messages and videos to influence their vote.
This scandal broke in 2018 via reporting by Carole Cadwalladr in the UK's Guardian / Observer newspapers. We all owe her a debt of gratitude for that work, as the truth was well hidden. She now co-runs The Nerve, by the way. Where I (Patrick) heard about it, however, was the 2019 documentary The Great Hack on Netflix. It was a huge eye-opener, and it's a straight line from there to us founding the Rebel Tech Alliance in early 2025. We'd already stopped using Google Search, due to it recording a creepy profile of all your searches forever, but we deleted all our Facebook data and never used it again after watching The Great Hack.
Russian interference
The Mueller Report established that Russia engaged in a military organised information warfare campaign to influence the 2016 Trump 1.0 election result. This is relevant here because of the way in which it was done. Russia took advantage of the centralised trove of citizen behavioural data that Facebook had amassed, and the micro-targeting that their advertising model allows. Like the Cambridge Analytica scandal it showed how this system could be misused.
For an excellent dramatisation of how Russia managed to infiltrate the top levels of British Politics in the lead up to that time listen to the podcast 'Sergei and the Westminster Spy Ring'. It is co-presented by Carol Cadwalladr and Peter Dukes (founder of Byline Times) and takes place between 2011 and 2018.
Chinese cyber warfare
China used to engage in old-school cyber warfare such as hacking into high security networks, but they took notice after seeing the Russians weaponise social media.
Since 2017 Operation Spamoflage has been operating as the world's largest known cross-platform disinformation network, and the Instagram "Charm Offensive" (2018–2019), involved State-linked accounts, and amount to a coordinated campaign to reshape China's global image. Not quite at the level of Russia's military-grade efforts, but a similar direction of travel.
The Covid 19 pandemic
The relationship between governments and Big Tech corporations became very interesting during the Covid 19 pandemic in three areas: contact tracing, protestor profiling and misinformation censorship.
The developing of contact tracing apps was particularly revealing. Big Tech flexed its power and told governments how it was going to be, making things difficult for any that resisted. The UK was one country that tried to bypass Google and Apple's controls and build its own sovereign solution. They failed. Big Tech's approach was framed as a decentralised approach, because then no single government would get hold of a honeypot of all their citizens' tracking data. And citizens of authoritarian countries no doubt applauded this. Or indeed any country, as citizens of Singapore will tell you. But as always with Big Tech, they boast about our security but never tell us who will save us from them. Giving all your data to a Big Tech platform is about as centralised as it gets, and on a global scale.
Counter Disinformation Unit / NSOIT / NPoCC
Monitoring social media to surveil people that the government considers 'trouble makers' is not news any more, for example as this article outlines (US police specific), but its more recent prevalence has its roots in the Covid pandemic.
Big Brother Watch revealed in 2023 that the UK government had been running a social media monitoring unit called the Counter Disinformation Unit during the pandemic. Its purpose was to crack down on Covid-related misinformation. The unit was later renamed the National Security Online Information Team (NSOIT), but the Big Brother Watch campaign dubbed it the Ministry of Truth.
The National Police Coordination Centre (NPoCC) - which in 2025 did actually set up a social media monitoring unit - ran Operation Talla during the pandemic. Its stated purpose was to 'safeguard the public's health' by ensuring consistent and lawful enforcement of public health legislation and lockdown rules.
Given the rampant level of mis- and dis-information during the pandemic, it could be considered a positive that some level of filtering and coordination was attempted by the government - but the point here is that well-meaning measures during a crisis often scope-creep later, sliding towards more heavy-handed surveillance powers. The Big Brother Watch campaign found significant scope creep, veering into surveillance of anyone critical of the government. This statement from EthicalApproach.co.uk argues that the surveillance was intended from the start (but we'll add the disclaimer that they seem like an organisation with fairly extreme views, so do your own research).
The idea of state censorship by proxy (via private tech corporations) was very contentious during Covid. Facebook was pressured into imposing various efforts against mis-informaton about vaccines. If you're an anti-vaxer you'll think that was outrageous, or indeed if you're Mark Zuckerberg himself (as this article makes clear). Tech companies appear to flow with the times, as their more recent lurch to the right under the Trump 2.0 regime shows.
2024 onwards
The big political change in 2024 was Trump 2.0. As of the time of writing (June 2026) it is crystal clear that the data privacy problems with the RTB system, coupled with the build up of government and Big Tech surveillance detailed above, were a time bomb waiting to go off. All it took was a regime willing to fully tap into it and that ocean of citizen data could be used to bypass and drown democracy. Couple that with a complete bending of the knee by Big Tech firms to get favourable regulation and the outlook isn't good.
Before we go on, however, lets back up for a second and review.
🎓 Surveillance advertising is still just surveillance

We've been warning since we set up RTA in early 2025 that the targeted ads business model is a threat to democracy. The main article linked above from Cory Doctorow gives a whistlestop tour of private corporation surveillance (invented by Google, perfected by Facebook) and mentions the relationship with government security services:
"Why did Google decide to start spying on us? For the same reason your dog licks its balls: because they could". ... [meaning that they were not regulated, or if they were, the regulations were not enforced] ... "Why did policymakers fail us? It's not much of a mystery, I'm afraid. Policymakers failed us because cops and spies hate privacy laws and lobby like hell against them. Cops and spies love commercial surveillance, because the private sector's massive surveillance dossiers are an off-the-books trove of warrantless surveillance data that the government can't legally collect."
This statement comes right out and highlights the inherent tension between Big Tech surveillance and government security services. We could have just started the article with that, but wanted to show the history so you can see that the problem hasn't come out of nowhere.
OSINT
OSINT (Open Source Intelligence) is the collection and analysis of information that is publically available. Why mention this? We were assisted in researching this article by someone who used to be an OSINT contractor for the US army many years ago. They explained to us how it used to be a fairly innocuous activity but has morphed into a dodgy surveillance grey area involving advertising data and data brokers.
ADINT
To back up this point there's such a thing as ADINT (Advertising Intelligence) - it has a name now. Various intelligence, surveillance, and data analytics companies purchase third-party advertising and mobile app data to provide geolocation and human intelligence (HUMINT) services to government agencies, law enforcement, and private clients.
The ecosystem typically involves a chain of data brokers, who harvest precise location and behavioural data from mobile apps (via SDKs), web trackers that follow users across the internet and ad networks, advertisers (the RTB system), and data brokers, and then sell it to intelligence firms or directly to government agencies. Or to whoever asks for it, as this article about the data broker Babel Street shows (spoiler: the location data of people using abortion clinics was sold to law enforcement).
This New Republic report is revealing in that it shows that the scale of ADINT purchases by the US Department of Defence (now renamed the Department of War) was so high that when they reduced it in 2023 it led to staff cuts at Israeli spyware firm DSO Group. It also gives a small window into the US-Israeli surveillance link, and gives you a sense of the nefarious nature of ADINT by labelling the companies involved as "cyber-offensive companies", a polite way of saying spyware.
The data broker industry

👆🏼 This is a 2021 report on the scale and scope of the data broker industry. Here's a quote:
"Location firm 'Near' describes itself as “The World’s Largest Dataset of People’s Behavior in the Real-World,” with data representing “1.6B people across 44 countries.” Mobilewalla boasts “40+ Countries, 1.9Billion+ Devices, 50B Mobile Signals Daily, 5+ Years of Data.” X-Mode’s website claims its data covers “25%+ of the Adult U.S. population monthly.”"
They gather at conferences and openly brag about the scope of the data they've harvested via ADINT. Examples of such brokers are Babel, Penlink, Intelos/Adhoc, Rayzone Group, Bsightful, Wave Guard Technologies, Venntel.
In terms of misuse of this data, they reference a report by Vice that showed that apps were selling Muslim prayer app location data to the military. Such apps are paid by data brokers to host some code in their app, and this automates the 'phone home' functionality, sending location data of individuals to be stored and sold by the data broker.
This was all confirmed in an EFF report in 2022:
"Many of the mobile apps on our cell phones track our movements with great precision and frequency. Data brokers harvest our location data from the app developers, and then sell it to these agencies. Once in government hands, the data is used by the military to spy on people overseas, by ICE to monitor people in and around the U.S., and by criminal investigators like the FBI and Secret Service."
Data brokers in the US get away with this due to a precedent called the 'third party doctrine'. This states that if you voluntarily give your data to a third party you have no reasonable expectation of privacy. In the EU there is the GDPR regulations so we actually do have a reasonable expectation of privacy. However the GDPR is not well enforced (this is mostly Ireland's fault) and there is a ridiculous 'legitimate interest' loophole in the consent banners. It's a loophole because, according to the UK's Information Commissioner's Office, it is "more flexible and, in principle, may apply to any use of personal information for any reasonable purpose". RTA has examined what data is harvested via this loophole and it includes location data accurate to within 500m.
And while we're in learning mode, this April 2026 documentary, Dangerous Apps, is amazing. It shows how location data is now traded by data brokers at the individual level - and sold to anyone. We strongly recommend you watch it. It's up to date and very well made. It'll make you want to check the location permissions in your apps, as we encourage you to do in the first few steps of our Big Tech Walkout programme.
Recent developments
Since 2024 the trend towards governments exploiting citizen data mined from the RTB system and social media has accelerated. What follows are mainly UK and USA examples, so first here are some from other territories for balance:
China taps into RTB data to stalk Australian officials
The ICCL revealed in late 2024 that RTB ad tech data is being used by China (and anyone else who wants to tap into it) to track the location of Australian government officials (and from other nations). That should worry you.
Turkey cracks down

The Guardian reported in March 2025 that following prior crackdowns on journalists, the Turkish government arrested more than 1100 people to contain protests against the government. 37 of these were detained for sharing provocative material on social media. The government requested X to block thousands of accounts. X complied with many while also making noise about protecting free speech. The point is that social media data is actively monitored and abused by governments.
Russia kettles all citizens into social media comms that it can monitor
Following reports in 2025 that the Russian government would ban WhatsApp and replace it with their own app, MAX, Human Rights Watch reported in February 2026 that Russia has stepped up its crackdown on anti-government dissent. The number of political prisoners shot up, and minority groups were persecuted. All from monitored location data and social media posts.
Egypt monitor social media to make mass arrests
Between 2024 and 2025 Egypt authorities detained around 6000 people on 'special terrorist' charges. This followed a crackdown on social media, targeting influencers. Despite a presidential pardon in 2023, these people are still being harassed and sentenced.
Moroccan spyware scope-creep
This 2026 Guardian article about a Moroccan intelligence service whistleblower reveals the pattern shown in this article: if spyware is made available to governments, there will be scope creep. It's just too tempting. The article covers the use of Pegasus (an Israeli spyware) to spy on journalists and human rights defenders going back to 2017, and the scope spilled beyond Morocco's borders into Spain (and the Spanish government). Of note is that Spanish authorities later gave a prestigious award to the minister caught in this spy scandal, echoing the next story here about the EU tolerating the use of spyware "because they rather like it". All governments are at it - if it's there they'll use it. It doesn't matter if it's Russia, China, the UK, the US or Spain...
EU minister is hacked and the EC does nothing

The crux of this story is that after the hack was discovered (it was Pegasus again) the European Commission did nothing. Why? Because "national governments quietly keep the door open because they rather like having these tools themselves". A clear example of the back door surveillance state.
You can 'Stop Feeding The Beast' if you take part in The Big Tech Walkout free online course. Step-by-step we help you reduce your data footprint and move to non-Big Tech alternatives.
Start now, it's fun and easy:
US and UK - abuses of citizen data and social media
"Yes, but in the West we're not authoritarian so that's not going to happen to us" you say? Sorry but it's heading that way. The beast is hungry, and if the data is there, then even progressive governments get a taste for it.
2024
The US police have a history of using social media to surveil protesters. This report is from 2024 but documents activity going back further:

Not to be outdone, the UK has stepped up this practice too. Privacy International (a UK org) flags the increasing monitoring of social media by governments (2024):

2025
The predictions in that article came true. Mainstream media reported in 2025 that the UK has set up a special police division to monitor social media:

2026

In January 2026 Le Monde reported that security services get location data that is supposed to just be used for advertising i.e. from the RTB system. And it all has links to Israeli-based data brokers. We've been warning about the RTB system and data brokers since we founded RTA!
This practice is becoming commonplace now in the US, as this April 2026 Mother Jones interview with the author of Your Data Will Be Used Against You shows. He mentions Fusion Centres in the US where data is gathered for federal level surveillance, and is not subject to the 4th amendment.
"We should begin with the assumption that our data will be misused"
Looking further afield, to commercial spyware, this April 2026 deep dive by the Citizen Lab reveals a spyware tool that uses mobile app and advertising data (RTB) location data to profile hundreds of millions of people. The software is called Webloc, and is sold by Penlink as an add-on to the social media and web surveillance tool, Tangles. It is all powered by AI of course.
Predictive Policing in 2026
In May 2026 The Gist published this great article outlining what policing looks like in the 'age of total surveillance'. The crumpled detective Columbo, finding clues with his famous "there's just one more thing", is contrasted with todays world where everything is surveilled so the clues are already there - police just need to surface them from vast databases. The author questions what this will do do society.
In June 2026 Wired ran a story about the predictive policing techniques now used by British police. They reveal various 'risk scoring models' (algorithms that look at databases of citizen data) and show how they've been used since 2014. In many cases they've had to be abandoned because they are so unreliable. Despite this, the appetite for AI predictive policing is undiminished, and the police force studied in the article (Avon and Somerset) is reviewing around 100 AI projects as of January 2026.
The pace seems to be accelerating. In June 2026, Channel 4 news reported that UK police in London are quickly rolling out more facial recognition, drones and AI.
"But critics, and some within policing itself, say it’s being rolled out faster than the law can keep up"
That sounds an awful lot like how Big Tech operates: roll out its products faster than laws and regulations can keep up. Hmmm.... it's almost like Big Tech have got their teeth into UK government departments 🤔 And in the middle of the AI hype bubble... 🤔
Amongst all these tech products the police are coveting is a rushed new contract with US death tech firm Palantir. Thankfully the London Mayor blocked it and the Met Police have just been forced to hold a new procurement process.
Facial recognition technology is famous for producing a large number of false positives and embedding bias, as explained in this Big Brother Watch youtube video. If police want to create an accountability sink with these technologies then we have a rocky road ahead of us.
Flock - US cops love it

This really puts the 'creep' in scope creep. Not only do police in the US love Flock's nationwide system of automated licence-plate reading (ALPR) cameras, but recently some of them have started to abuse it to stalk people. This is another example of surveillance tool scope creep: if the capability is there, someone is going to misuse it eventually.
Think the stalking thing is 'just a few bad apples'? This July 2026 report shows that US police are now using Flock to track people, not cars. So a technology that was invented to automatically recognise number plates is being used to recognise people. Scope creep.
Social media bans = ID verification = "your papers, please!"
Under the guise of protecting children the UK government has announced in June 2026 that it intends to enact a blanket ban on social media. Everyone knows there are problems with social media but a ban is the wrong approach, as we detail in this blog post. There are so many arguments against it that the only explanation for the government pushing so hard for it (as they did with Digital ID) is for more control and surveillance.
Mullvad (who make the Mullvad VPN and the Mullvad browser) did a great job in this article of summarising the scope creep sequence we'll see if age gating is introduced.
Conclusion
The direction of travel is clear: the nature of government intelligence gathering has changed, and the AI hype is accelerating that change. Governments are increasingly using citizen behavioural data, either directly in-house from social media and the RTB (targeted ads) data system, or they buy it from data brokers. They are turning to data analytics firms to make sense of it for them. Heavy lobbying means that the firm chosen is often Palantir, despite their ties to the US and Israeli governments. Big Data meets Big Policing. And this all started when Google invented the RTB system back in the early 2000s, creating an always-on firehose of unsecured citizen data.
From that point on, first Big Tech perfected the dark arts of data harvesting analysis and prediction, then governments began to adopt the same approach. Intelligence work and policing moved from 'look for clues after signs of a crime' to 'surveil everything just in case, and if there's a crime we'll look in the mega database'. Cops in TV shows like The Wire having to ask permission for a wire tap looks quaint these days. If the database was always right, then it would not be so bad, but surveillance tech is rife with bias and false positives.
A consistent theme in this article has been 'scope creep'. It is sadly a facet of human nature that those in power will not resist the temptation to use surveillance powers if they are permitted to do so. One of the big challenges of our time is to stand up to power and say "No, it's not ok to surveil us like this". We at RTA believe that such dragnet surveillance is incompatible with democracy. In our workshops we ask the trick question "Do you trust your next government?". Hopefully this article has shown you how surveillance technologies gradually get misused over time, even by benign governments, and all it takes is a power grab to shift the equation. Citizens of the US are waking up to this now, and the UK (where we're based) is next.
If you take part in The Big Tech Walkout then you'll be doing your bit to STOP FEEDING THE BEAST. Start the online course now, it's fun and easy, and can be done at your own pace:
Rebel Tech Alliance is a non-profit dedicated to getting as many people off big tech products as possible. Why? Because that reduces the surveillance economy, and reducing that is good for individuals, society and democracy itself.






