The Structural Impossibility of Privacy Care

According to a 2023 Pew Research Center survey, 81% of American adults said they were concerned about how companies use their data, and 71% said they were concerned about how the government uses their data. At the same time, 61% expressed skepticism that anything they do makes much difference. In June 2025, when the Trump administration gave Immigration and Customs Enforcement access to a massive database of Medicaid recipients, privacy advocates sounded the alarm. Most people likely shrugged and moved on with their day. Why?

The Gap Between Concern and Action Is Not New

Pew Research Center survey data from 2023 shows that 81% of American adults said they were concerned about how companies use their data, and 71% said they were concerned about how the government uses their data. Yet 61% expressed skepticism that anything they do makes much difference. A 2026 survey of 1,000 Americans found 92% are worried about their data being collected online, yet many take no action. 41% of people never read the privacy policies of websites or apps before using them.

Privacy researchers have documented this gap for years. The term privacy paradox was mainly established by Norberg et al. (2007), who asked students about their willingness to disclose specific pieces of information and then, weeks later, asked them to provide the same kind of information to a market researcher. Individuals would actually disclose a significantly greater amount of personal information than their stated intentions indicate.

The pattern has been reproduced across contexts. Research shows that people’s use of computers and mobile phones is often characterized by a privacy paradox: their self-reported concerns about their online privacy appear to be in contradiction with their often careless online behaviors. But the term “paradox” assumes the problem is cognitive dissonance. No comprehensive explanation has been found so far and user privacy remains a rather complex phenomenon that cannot entirely be explained yet.

Resignation, Not Indifference

The most significant shift in privacy research over the last decade has been the recognition that the gap is not about indifference. It is about structural incapacity masked as choice.

Privacy cynicism describes a state in which individuals feel uncertain, mistrustful, powerless and resigned when it comes to digital privacy. Cynical users may still care deeply about privacy, but they no longer believe their actions can meaningfully change outcomes. Researchers have used several terms to describe this: privacy apathy, privacy cynicism, surveillance realism, privacy fatigue, digital resignation, and privacy helplessness.

Digital resignation can constitute a purposeful form of inaction in the face of corporate activities that encourage a sense of individual futility. Frequent data breaches may make people feel as though they have no control over personal information, and ultimately drive them into a state of resignation about online privacy. The increasing complexity of the measures needed to protect one’s personal data online aggravates the feelings of resignation and lack of control, leading to a sense of fatigue.

Privacy fatigue is a state attained when a user’s level of privacy fatigue (as a function of increased cynicism and exhaustion) reaches a point where privacy-protective behavior is ignored and self-disclosure is increased despite pertinent privacy risks. A 2017 study found that privacy fatigue has a stronger impact on privacy behavior than privacy concerns do, although the latter is widely regarded as the dominant factor in explaining online privacy behavior.

Consent Mechanisms Are Designed to Fail

The architectural problem becomes visible when you examine the mechanisms designed to offer control. Privacy laws across jurisdictions emphasize consent. The assumption is that users can opt out if they choose to. But the design of consent mechanisms ensures that most people will not.

Privacy laws predominantly take a consent-based approach that encourages you to give up your personal information even when it’s not necessary. These laws put the onus on individuals to protect their privacy, rather than simply barring companies from collecting certain kinds of information from their customers. Managing your personal data in today’s world is time-consuming. It’s too much for even a very efficient and diligent person to read and decipher the legalese of all the terms and conditions they sign off on.

Even though the GDPR includes rules like needing clear consent and allowing people to access, correct, move, and delete their data, people’s behaviors often make these rules less effective. Problems like too much information leading to quick, uninformed consent, people choosing convenience over privacy, and feasible default settings that favor less privacy weaken GDPR’s impact.

A November 2024 study analyzing 6,286 websites across 24 industries found that GDPR negatively affected online usage per website on average; specifically, weekly visits decreased by 4.88% in the first 3 months and 10.02% after 18 months post-enactment. This is often cited as evidence that GDPR worked. But the same study found the largest 10% of websites pre-GDPR suffered less, suggesting that the GDPR has increased market concentration. Regulation imposed compliance costs that small sites could not absorb. Users did not distribute their attention to more privacy-respecting alternatives. They consolidated on platforms large enough to navigate the rules.

The Evidence Does Not Support the “Nothing to Hide” Narrative

A common explanation for inaction is that people genuinely believe they have nothing to hide. Survey data contradicts this.

One in five (20%) agree that people only worry about personal data online if they have something to hide. That suggests privacy isn’t only a technical or political issue, it’s also a cultural one, where concern can be judged as suspicious rather than sensible. The majority reject the premise. 46% of consumers feel they cannot effectively protect their personal information. 86% say privacy matters, and they want greater control over their information.

Recent surveys show that about 75% of consumers will not purchase from companies they do not trust with their personal data, while roughly 48% have stopped buying from a business specifically because of privacy concerns. Additionally, a majority of users, around 63%, believe that most companies are not transparent about how they use personal information. Among US consumers, 69% have abandoned a transaction due to concerns about how their data was used by a brand, per June 2025 data from Liquid Web.

Privacy concern is not abstract. It affects purchasing behavior. Cisco research finds that 95% of consumers refuse to buy if they think a company fails to protect information. Another 99% say external privacy certifications matter when choosing a vendor. The population does care. But care does not translate to control when the environment is designed to prevent it.

What Email Architecture Tells Us About Structural Failure

Email is a useful lens for examining how architectural decisions determine outcomes at the population level. The email infrastructure used by billions of people was not designed with confidentiality as a principle. Messages travel in plaintext by default. Metadata is logged extensively. Centralized providers aggregate correspondence for hundreds of millions of users, creating single points of legal compulsion and surveillance.

End-to-end encryption tools exist. PGP has been available for decades. Yet adoption remains marginal. This is not because users are indifferent. It is because PGP requires both parties to generate keys, exchange public keys, manage private keys securely, and use compatible software. The friction is high enough that most people cannot integrate it into their workflow, even when they understand the threat model.

The architecture of popular email services moves in the opposite direction. Gmail, Outlook, and others offer convenience, search, integration, and accessibility across devices. The cost is that the provider holds decryption keys and can read every message. Users are aware of this trade-off. But the alternative is not “use PGP.” The alternative is “lose access to the communication infrastructure your employer, your bank, your family, and every service you use expects you to be reachable on.”

Services that attempt to reduce friction while preserving confidentiality operate in a different design space. Open-source post-quantum cryptographic tooling – such as PQCServer, released under AGPL-3.0 – illustrates this principle in practice. These are architectural responses to the problem that consent mechanisms cannot solve: the fact that most users cannot opt out of infrastructures they depend on.

But even services with better architectural properties face the structural problem that most users will not migrate unless the migration imposes no cost. Network effects, vendor lock-in, and the distribution of knowledge mean that privacy-preserving tools remain niche unless they become the default.

Trajectory, Not Alarm

The trajectory is not toward individual enlightenment. The trajectory is toward recognition that privacy protection is not a task individuals can successfully perform through better decision-making. Privacy concerns seem to be highly situation-dependent and can be described as a fluent concept that changes over time. But the fundamental asymmetry remains constant: individuals face thousands of decisions per week about data disclosure, each embedded in interfaces designed to nudge them toward sharing, while the entities collecting data operate at scale with legal, technical, and financial resources that no individual can match.

The question is not why people do not care. It’s not that people don’t care. The question is why we continue to frame the problem as individual apathy when the evidence points to structural design. Consent-based regulatory models assume that informed users can protect themselves. The assumption does not survive contact with the data. Privacy fatigue is not a cognitive failure. It is a rational response to an environment engineered to be unmanageable.