Computer Literacy · Foundations
Privacy
On this page 9 sections
In 30 seconds
Online privacy is about who can see, collect, and use information about you. Every account you open, Cookie A small piece of information a website saves in your browser so it can recognize your device on later visits and track activity over time. Full entry → a site sets, app you install, and place you carry your phone can add to a profile. Many "free" services are paid for with that data, and data brokers aggregate and sell it. You cannot make yourself invisible, but reviewing settings, limiting permissions, and thinking before you share meaningfully reduce your exposure.
Why this matters
Almost everything you do online leaves data behind, and that data is valuable enough to power much of the modern internet economy. Understanding how collection actually works lets you make deliberate choices instead of accepting every default. It helps you weigh convenience and personalization against exposure, spot when a "free" service is really trading on your information, and use the controls that laws like the GDPR and state privacy statutes increasingly require companies to offer. This is a practical literacy: not paranoia, but the ability to decide what you share, with whom, and why, across a lifetime of accounts, apps, and devices.
The college version
Personal data and why it matters
Privacy, in the digital sense, is about control over information that relates to you: who can collect it, see it, combine it, and use it. The core unit is Personal data Any information relating to an identified or identifiable person, from names and ID numbers to email addresses, IP addresses, location traces, and device identifiers. Full entry →. Under the EU's data-protection framework, personal data is any information relating to an identified or identifiable person, and it is broader than most people expect: not just your name, address, and government ID numbers, but also email addresses, IP addresses, cookie identifiers, a phone's Advertising identifier A unique code on a phone or tablet that advertisers use to recognize the device and link its activity across apps. Full entry →, location traces, and photos. A closely related U.S. term is Personally identifiable information (PII) Data that can single out a specific individual, either by itself or when combined with other available information. Full entry →, meaning data that can single out a specific individual on its own or when combined with other data. The 'when combined' part is what makes privacy hard. Individual scraps look harmless, but modern systems link them. Your device, your logins, and your habits act like a fingerprint, so pieces that each reveal little can be assembled into a detailed picture of who you are, where you go, what you buy, and what you believe. That is why personal data matters: it is not only sensitive on its own but powerful in aggregate, and aggregation is exactly what the data industry is built to do. This lesson is about how that collection works and how to reason about it; the reputational side of what you post is covered in 'Digital Footprints.'
How your data gets collected
Collection happens through several channels at once. The most obvious is information you hand over directly: the accounts you create and the forms you fill in with your name, email, birthday, or payment details. Less visible is automatic tracking. When you visit a site, it may store a cookie, a small piece of information saved in your browser that lets the site recognize your device on later visits. Sites and advertisers also use pixels and third-party trackers embedded across many sites, and Device fingerprinting Identifying a user from the unique combination of their browser and device settings, which can track them even without a stored cookie. Full entry →, which identifies you from your browser's unique configuration even without a cookie. On phones, apps can track you using a unique advertising identifier, and companies can link your activity across devices, tying your laptop to your phone. Apps also request permissions. Granting an app access to your contacts, camera, microphone, or precise location gives it a data stream that may have little to do with the app's core function, so permissions deserve scrutiny. Location is a category of its own: a phone that reports where it is, minute by minute, reveals home, work, routines, and visits that are among the most revealing data a person produces. Browsers offer their own privacy features and controls, which the 'Browsers' lesson covers in detail; here the point is simply that collection is continuous, layered, and mostly invisible unless you look for it.
The data economy and data brokers
None of this collection is an accident; it funds a large part of the internet. Many services that cost nothing to use are not charities. They are paid for with data, most often by using what they learn about you to target advertising or to build analytics that are themselves valuable. A useful habit is to ask, when something is free, how the provider actually makes money, because the answer is frequently 'from information about its users.' Sitting behind the visible services is an industry most people never interact with directly: data brokers. In a 2014 study of nine brokers, the U.S. Federal Trade Commission found that data brokers collect and store billions of data elements covering nearly every American consumer, drawn from both online and offline sources, largely without those consumers' knowledge. The sources ranged from purchases and social-media activity to warranty registrations, magazine subscriptions, and religious or political affiliations. Brokers combine these into profiles and sell them for marketing, fraud prevention, and other purposes. The FTC's central criticism was a fundamental lack of transparency: as one FTC official put it, brokers often know as much about us as our family and friends, yet many consumers are unaware the industry even exists. Understanding data brokers reframes privacy. The question is not only 'what does this one app see?' but 'where does my data flow after it is collected, and who can buy it later?'
Trade-offs and practical protection
Privacy is best understood as a series of trade-offs rather than a switch you flip. Sharing data buys real benefits: a maps app that knows your location gives directions, a store that remembers your history speeds checkout, and personalization can genuinely be useful. The cost is exposure, and reasonable people draw the line in different places. What good practice offers is not invisibility but deliberate choices that lower your exposure without giving up everything you value. Several steps are broadly effective. Review the privacy settings on your accounts, browser, and phone, and prefer more private defaults where they exist. Limit app permissions to what an app actually needs, and be especially cautious with location, microphone, and contacts. Use privacy-respecting tools and browser controls, and clear cookies or reset advertising identifiers when you want to reduce tracking. Think before you share: information you never provide cannot be leaked, sold, or misused later. Two neighboring topics carry their own weight and are only referenced here: keeping accounts themselves secure is the job of 'Password Security' and 'Multi-Factor Authentication,' not of privacy settings. The honest framing is that no single tool or setting makes you 'private' or 'safe.' These steps stack up to meaningfully less exposure, which is the realistic goal.
Privacy laws exist (and what that does and doesn't mean)
You are not the only party with responsibilities here; laws increasingly govern how organizations handle personal data. The best-known is the European Union's General Data Protection Regulation (GDPR), which has applied since 25 May 2018 and gives individuals rights such as access to their data, correction, erasure, and objection, while requiring organizations to justify and disclose their processing. In the United States there is no single federal equivalent, but state laws have emerged. California's Consumer Privacy Act (CCPA), later strengthened by the California Privacy Rights Act, gives California residents rights to know what personal information a business collects, to delete it, to correct it, and to opt out of its sale or sharing, along with protection from discrimination for exercising those rights. These laws are why you now see cookie notices, privacy dashboards, and 'do not sell my personal information' links. Two cautions matter for a learner. First, this is educational background, not legal advice; whether a specific law applies to a specific situation is a legal question. Second, the existence of laws does not make you compliant or safe, and no product can promise that it does. Laws set obligations for organizations and give you tools; using those tools well is still up to you.

Eli explains
The same idea, in plain words
Explain it like I’m 10
Think of everything you do online as leaving little footprints: an account here, a search there, an app that knows where you are. On their own the footprints seem tiny, but companies are very good at collecting them and gluing them together into a map of you. Some companies you have never heard of, called data brokers, buy and sell those maps. This is how a lot of 'free' apps make money: you are not paying with cash, you are paying with information about yourself. You cannot make the footprints disappear completely, but you can leave fewer of them by checking your settings, saying no to apps that ask for more than they need, and thinking for a second before you type something in.
Picture it like this
Your data is like footprints in wet sand at the beach. One footprint tells almost nothing. But if someone photographs every footprint all day, they learn where you swam, who you sat with, and when you went home. Data brokers are like people who collect those photos from many beaches and sell the whole album.
Where the picture stops working
Footprints in sand wash away with the tide, but collected data usually does not: once a company or broker stores it, deleting one app or clearing your browser will not pull it back. The analogy also makes tracking sound like one watcher, when in reality dozens of different companies are collecting pieces at the same time and combining them behind the scenes.
Worked example
Imagine installing a free flashlight app on your phone. On first launch it asks for permission to access your precise location, your contacts, and your camera. A flashlight needs the camera's flash, so the camera request is plausible, but location and contacts have nothing to do with turning on a light. That mismatch is the signal. If you grant location, the app can collect where you are over time and may pass that stream to advertisers or brokers using your device's advertising identifier. The privacy-aware move is to deny location and contacts, granting only what the function requires, or to choose a different app. Notice the reasoning: you did not need to know the company's business model to protect yourself. You compared what the app does with what it asked for, limited the permissions to the gap, and thereby cut off a collection channel before it opened. That is the everyday form privacy protection usually takes.
Key takeaway
Online privacy is control over personal data that is collected continuously, through accounts and forms, cookies and trackers, app permissions, and location, and then aggregated and often sold in a data economy powered by data brokers. You cannot become invisible, but reviewing settings, limiting permissions, using privacy tools, and thinking before sharing meaningfully lower your exposure; privacy laws like the GDPR and California's set obligations for organizations without making any single step a guarantee.
Quick check
3 questions here, of 5 in this lesson’s practice set. Answers stay hidden until you check.
A website stores a cookie in your browser. What is a cookie's basic function?
A popular social app costs nothing to download or use. Based on the data economy described in the lesson, how is it most likely funded?
Study tools & related lessonsYou’ll learn to · Common mistakes · Easily confused · Key vocabulary · Related
You’ll learn to
- Define personal data and personally identifiable information (PII) and explain why they matter.
- Describe the main ways data is collected: accounts and forms, cookies and trackers, apps and permissions, and location.
- Explain the data economy, including how many free services are funded and what data brokers do.
- Analyze the trade-offs between convenience or personalization and exposure of personal information.
- Apply practical protective steps and recognize that privacy laws exist without treating any single step as a guarantee.
Common mistakes
Believing a service is truly free just because you pay no money for it.
Many free services are funded by collecting and monetizing your data, typically through targeted advertising. If you cannot see how a product makes money, the answer is often 'from information about its users.'
Assuming individual pieces of data are harmless, so sharing them does not matter.
Privacy risk comes largely from aggregation. Scraps that each reveal little can be linked into a detailed profile, which is exactly what trackers and data brokers are built to do.
Granting every app permission it requests without thinking.
Grant only the access an app actually needs for its function. Location, microphone, and contacts deserve extra scrutiny, and a mismatch between an app's purpose and its requests is a warning sign.
Thinking one privacy tool or setting makes you anonymous, safe, or legally compliant.
No single tool guarantees privacy. Protective steps reduce exposure but do not erase it, and the existence of privacy laws does not by itself make you or a service safe or compliant.
Assuming deleting an app or clearing cookies removes data already collected about you.
Data already gathered by companies and brokers can persist and be sold after you stop using a service. Reducing future collection is realistic; retroactively erasing everything usually is not.
Easily confused
Data you provide directly vs. Data collected automatically
You knowingly enter the first through accounts and forms. The second, cookies, trackers, fingerprinting, advertising identifiers, and location, is gathered in the background, often without your awareness, which is why it is easy to underestimate.
Personal data / PII vs. Anonymized data
Personal data can be linked to a specific person. Data that is genuinely and irreversibly anonymized cannot, and so falls outside most privacy rules, though weak 'anonymization' can sometimes be re-linked.
A website or app that collects data vs. A data broker
The first collects data through a service you chose to use. A broker you never interact with aggregates data from many such sources into profiles and sells access, which is why data can flow far beyond where you first entered it.
Key vocabulary
- Personal data
- Any information relating to an identified or identifiable person, from names and ID numbers to email addresses, IP addresses, location traces, and device identifiers.
- Personally identifiable information (PII)
- Data that can single out a specific individual, either by itself or when combined with other available information.
- Cookie
- A small piece of information a website saves in your browser so it can recognize your device on later visits and track activity over time.
- Tracker
- A cookie, pixel, or script placed on many sites so a company can follow a user's activity across the web, often for advertising.
- Device fingerprinting
- Identifying a user from the unique combination of their browser and device settings, which can track them even without a stored cookie.
- Advertising identifier
- A unique code on a phone or tablet that advertisers use to recognize the device and link its activity across apps.
- App permission
- Access an app requests to a device capability or data store, such as location, camera, microphone, or contacts, which the user can grant or deny.
- Data broker
- A company that collects personal information from many online and offline sources, combines it into profiles, and sells access to others.
- Data economy
- The system in which personal data is collected, combined, and monetized, and in which many free services are paid for by using or selling user data.
Sources & references
- How Websites and Apps Collect and Use Your Information — U.S. Federal Trade Commission — Consumer Advice
- Data Brokers: A Call for Transparency and Accountability (FTC Report, May 2014) — U.S. Federal Trade Commission
- Data protection explained — European Commission
- General data protection regulation (GDPR) — summary — EUR-Lex (Publications Office of the European Union)
- California Consumer Privacy Act (CCPA) — California Office of the Attorney General
EliExplains lessons are original prose written from the open, credible references above. See Copyright & Licensing.
Researched 2026-08-19
Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.

