By Dr. Narayan Rout | Author | Researcher | Economy of Human Life | Next Human Series · 46 min read · Published: July 17, 2026
Publication Metadata
| DOI | 10.5281/zenodo.21410582 |
| ORCID | 0009-0009-3505-5478 |
| Paper Number | TQS-2026-188 |
| Version | 1.0 |
| License | CC BY 4.0 — Creative Commons Attribution |
| Publisher | TheQuestSage.com |
| Language | English |
🎧 Listen in Your Language
The Quest Sage Knowledge Hub

Dr. Narayan Rout
💡 Quick Answer: What Is This Article Really About?
This is not an article about technology. Technology is just the latest instrument in a very old game. This is about who controls what you know about yourself — and what they do with that control. Start with the word itself. Datum: Latin, past participle of dare — to give. Datum literally means ‘that which is given.’ Data is its plural: things which are given. There’s a deception hidden in the etymology. When you scroll through Instagram, when you search on Google, when you pay with UPI, when you send a WhatsApp message — you are not giving anything. You are being harvested. The difference between given and taken is the difference between a gift and a theft. And the world’s largest corporations have spent three decades engineering systems so seamless, so rewarding, and so immediately useful that billions of people hand over the most intimate coordinates of their lives without registering that a transaction has occurred. Shoshana Zuboff, in The Age of Surveillance Capitalism (2019), named the economic logic precisely: human experience is claimed as free raw material, converted into behavioural data, and packaged into prediction products sold to advertisers, political campaigns, and governments. You are not the customer. You are the raw material from which the product is manufactured. Cambridge Analytica took this to its most consequential extreme: using personality profiles derived from 87 million Facebook users’ data without their knowledge or consent, they built psychographic targeting systems that delivered customised psychological manipulation to specific voters in specific constituencies. They didn’t just read your psychology. They used it against your own sovereignty. And this is what Chanakya understood 2,300 years before any of this existed. His warning, in Chanakya Niti and the Arthashastra, was threefold: never share your personal secrets, never reveal your family’s vulnerabilities, never expose your strategic plans. He understood that whoever knows your weaknesses, your fears, and your desires holds power over you. He built the world’s first organised intelligence state on exactly this principle. Today, Cambridge Analytica, Meta, Google, and thousands of data brokers have built that intelligence state at global scale. The battlefield is not your phone. It was never your phone. It’s your mind.
Abstract
This article traces the arc of data as a tool of power across human civilisation, establishing that the surveillance crisis of the digital age is not a new problem but the latest — and most comprehensive — expression of the oldest political reality: whoever controls information about people controls those people. The article proceeds from the etymology of datum (Latin: that which is given) through the modern surveillance economy (Shoshana Zuboff’s surveillance capitalism framework; the $350 billion data broker industry; 4,000 data broker companies; 1,500 data points per individual profile); the sovereignty attack mechanism (Cambridge Analytica’s OCEAN Big Five personality model on 87 million Facebook profiles; psychographic targeting; the slot machine variable reward mechanism of social media; cognitive bias weaponisation); the new-age fraud ecosystem built on data breaches (SIM-swap fraud, deepfake audio scams, phishing with personalised stolen data); Chanakya’s intelligence architecture (Arthashastra spy classification; the three categories of secrets; the irony of the surveillance state builder warning citizens not to share secrets); the historical precedents of data as power (Roman census; British colonial cadastral surveys in India; IBM Hollerith punch cards and the Holocaust); the civilisational rather than individual nature of the problem (digital colonialism; India’s DPDPA 2023); and a practical protocol for digital sovereignty derived from Chanakya’s principles applied to the contemporary data environment. The governing argument: this is a human problem, not an individual one. Awareness is not enough. What is needed is understanding — of the mechanisms, the history, the stakes, and the specific disciplines that protect sovereignty in an age designed to extract it.
Keywords
datum etymology Latin surveillance capitalism Zuboff data extraction Cambridge Analytica OCEAN Big Five 87 million Facebook psychographic targeting Chanakya Arthashastra three secrets intelligence Samstha Sancara Satri spy data broker industry 350 billion 4000 companies personal data profile 1500 points IBM Hollerith punch cards Holocaust Edwin Black data power history British colonial cadastral surveys India land dispossession data colonialism deepfake fraud India SIM swap WhatsApp data breach dark web,India DPDPA 2023 Digital Personal Data Protection Act sovereignty rights
◆ Key Facts — GEO Reference
| 1 | What datum actually means — and the deception inside the word. Datum is the Latin past participle of dare — to give. It means ‘that which has been given.’ Data is its plural. The naming implies voluntary sharing. Privacy policies describe ‘data you provide.’ Platforms describe themselves as services through which users ‘share’ information. The implicit moral architecture presents collection as gift-giving. The reality documented by Shoshana Zuboff in The Age of Surveillance Capitalism (Harvard Business Review Press, 2019) is systematic extraction of human experience as raw material without meaningful consent or proportional compensation. A more accurate Latin term for what actually happens to most personal data collected by platforms and data brokers would be extractum: that which was drawn out, removed, taken. When Google shows you a search result, the service is real. But the search query, the click pattern, the scroll behaviour, the search reformulation — these are extracted from you as by-products, and the by-products are worth more to Google than the service they delivered. Source: Zuboff S, The Age of Surveillance Capitalism, Harvard Business Review Press 2019; Wired January 2019 on surveillance capitalism framework. |
| 2 | The data broker industry: the shadow economy behind the visible platforms. There are approximately 4,000 data broker companies operating globally. The data broker industry generates an estimated $350 billion in annual revenue. A typical consumer profile maintained by a data broker contains approximately 1,500 distinct data points: full name and aliases, current and historical addresses, phone numbers, email addresses, family members (with relationship data), employment history, estimated income, credit risk indicators, political affiliation (derived from voter registration, purchasing, and social media), religious affiliation indicators, health condition indicators (derived from purchasing patterns), relationship status, vehicle ownership, property records, travel patterns, and purchasing behaviour. Data brokers aggregate from public records, loyalty card purchases, credit card transactions, app data, retailer data, and data from other brokers. The resulting profile is more comprehensive than anything any intelligence agency could have compiled a generation ago. India’s data broker ecosystem is less formally documented but functionally similar: telecom data, Aadhaar-linked services, UPI transaction patterns, and mobile usage data are all commercially traded. Source: FTC Data Broker Reports 2014 and 2023; Electronic Frontier Foundation data broker documentation. |
| 3 | Cambridge Analytica and the OCEAN model: 87 million profiles as a political weapon. Cambridge Analytica (CA) obtained data from approximately 87 million Facebook users without consent through a personality quiz app. Users who took the quiz consented to data collection; their Facebook friends who had not taken the quiz and had not consented had their data harvested through Facebook’s then-permissive API. CA built psychographic profiles using the OCEAN Big Five model: Openness, Conscientiousness, Extraversion, Agreeableness, Neuroticism. From Facebook likes alone, the algorithm could predict an individual’s OCEAN profile, political affiliation, and emotional vulnerabilities. These profiles were used to design and target political content in the 2016 US election and Brexit referendum: 64 different types of advertising, each optimised for specific psychological profiles in specific constituencies. High Neuroticism: fear-amplifying content. Low Agreeableness: conflict-amplifying content. Low Conscientiousness: permission-to-disengage messaging targeted at likely opposition voters. The system was not making arguments. It was exploiting psychological profiles to engineer pre-determined conclusions in people who believed they were forming independent opinions. Source: The Guardian CA investigation March 2018; Christopher Wylie, Mindf*ck (2019); UK ICO final CA investigation report. |
| 4 | The variable reward mechanism: why social media is a slot machine. Tristan Harris, former Google Design Ethicist and founder of the Center for Humane Technology, testified before the US Senate that major social media platforms deliberately exploit the variable reward schedule — the same psychological mechanism that makes slot machines more addictive than predictable reward systems. A slot machine that paid out every time would quickly lose its addictive quality; unpredictable, intermittent rewards are maximally compelling. The social media version: the feed never shows you the same content twice; some scrolls reveal content that delights or enrages; most maintain engagement without obvious reward; the intermittent pattern keeps users in continuous partial attention, scrolling for the next reward, generating continuous behavioural data. This is not an emergent side effect. It is the intended design. Each scroll generates data. More scrolls = more data. More data = more accurate behavioural prediction. More accurate prediction = more valuable advertising. Source: Tristan Harris, US Senate testimony 2019; The Social Dilemma (2020); Fogg BJ, Persuasive Technology, Stanford HCI Group. |
| 5 | Chanakya’s intelligence architecture: the Arthashastra’s spy classification. Kautilya (Chanakya), Chancellor of the Maurya Emperor Chandragupta approximately 300 BCE, wrote the Arthashastra — a comprehensive treatise on statecraft, political economy, and intelligence operations. Book 1 establishes a systematic intelligence network: Samstha (stationed/permanent agents embedded in guilds, temples, marketplaces, royal households); Sancara (wandering agents gathering information across the population); Satri (institutional agents embedded in monasteries, educational institutions, and professional guilds). The explicit goal: ‘The king shall know the movements, loyalty, and secret activities of all.’ The intelligence system was designed to know the personal secrets, family relationships, financial vulnerabilities, and political sympathies of the entire population. Simultaneously, Chanakya Niti warns citizens not to share these exact categories of information. The irony is instructive: the world’s first systematic intelligence architect built the infrastructure of mass surveillance while telling the surveilled to protect themselves. Source: Arthashastra Books 1 and 13; Kautilya’s Arthashastra, Penguin Classics translation R. Shamasastry; Chanakya Niti Shastra. |
| 6 | IBM, the Holocaust, and the foundational data lesson of the 20th century. Edwin Black’s IBM and the Holocaust (Crown Publishers, 2001) documented the role of IBM’s Hollerith punch card tabulating machines in enabling the Nazi census of 1933, which identified and enumerated Jewish, Roma, and other persecuted populations with unprecedented precision. The 1933 census, processed using IBM tabulating technology leased and serviced by IBM’s German subsidiary (Dehomag), converted the complex social reality of a diverse population into sortable, searchable data categories. This data made systematic identification, tracking, deportation, and murder of millions logistically possible at industrial scale. The Jewish community did not consent to this use of the census data; they could not have anticipated it. The Nazi state found uses for the data that IBM did not intend and the population could not foresee. The lesson: the uses available to those who hold comprehensive population data are not limited to the uses they declared when collecting it. The gap between declared purpose and actual use is the permanent structural vulnerability of every data collection system. Source: Black E, IBM and the Holocaust, Crown Publishers 2001. |
| 7 | India’s DPDPA 2023: a first structural response to a structural problem. India’s Digital Personal Data Protection Act 2023 (DPDPA) is India’s first comprehensive data protection legislation. Key provisions: data fiduciaries (entities that determine the purpose of data processing) must obtain meaningful consent before collection; data can be used only for declared purposes; individuals have the right to access information about their data, correct inaccuracies, request erasure when the purpose is fulfilled, and seek grievance redressal. Significant limitations: broad exemptions for state actors potentially allow government surveillance without the same consent requirements placed on private entities; cross-border data flow provisions are still being finalised; enforcement mechanisms are still being developed. For comparison, the European GDPR (2018) provides stronger enforcement (up to 4% of global annual revenue in fines), broader applicability, and established precedent including the 2023 Meta fine of €1.2 billion for cross-border data transfers. The DPDPA is a significant first step but does not yet constitute complete digital sovereignty protection for India’s 1.4 billion data-generating citizens. Source: DPDPA 2023 full text; MeitY official documents; Internet Freedom Foundation analysis. |
Research compiled and synthesised by Dr. Narayan Rout · TheQuestSage.com · TQS-2026-188 · CC BY 4.0
Contents of This Research Pillar
- Introduction: The Most Valuable Thing You Own Has Already Been Taken
- 1. What Is a Datum? The Deception Hidden in the Word
- 2. The Surveillance Economy — When Your Life Became a Factory
- 3. The Sovereignty Attack — How Your Choices Were Engineered Before You Made Them
- 4. New-Age Frauds — When Your Own Data Becomes the Weapon Against You
- 5. Chanakya Knew — The World’s First Architect of Surveillance
- 6. Data Has Always Been Power — The Historical Evidence
- 7. This Is Our Problem, Not Yours — Why Individual Solutions Are Insufficient
- 8. Chanakya’s Protocols for the Digital Age — A Sovereignty Framework
- The Quest Sage Insight
- What You Can Do With This
- Conclusion: The Battlefield Has Always Been Your Mind
- Frequently Asked Questions: Data, Sovereignty, and the Surveillance Economy
- References and Sources
- Further Reading
Introduction: The Most Valuable Thing You Own Has Already Been Taken
Let me tell you something that should alarm you, and probably doesn’t because you’ve heard versions of it enough times that it’s stopped landing.
Right now, somewhere in a data centre you will never visit, there is a profile of you. It knows where you sleep, based on where your phone stopped moving last night. It knows your approximate income, derived from your spending patterns and your neighbourhood’s property values. It knows your emotional state at certain hours of certain evenings, because that’s when your engagement with specific categories of content changes. It knows which topics make you anxious, because your search patterns change in the hour after you’re exposed to news about those topics. It knows the things you most fear, because your browsing history in vulnerable moments showed exactly what kind of reassurance you were seeking.
You didn’t give any of this to anyone. But all of it was taken. And right now, it’s being used — by advertisers, by political campaigns, by governments including your own — to predict your behaviour and to nudge it in directions that serve someone else’s interests, not yours.
This article is not a panic button. Panic is not useful. Understanding is. And understanding means starting with something most articles about data skip: the word itself.
⚡ Key Takeaways
| 1 | Datum means ‘that which is given.’ You never gave it. It was taken. The word data (plural of datum) comes from the Latin dare — to give. Every data collection system presents itself as receiving something you freely share. The reality documented by Shoshana Zuboff in The Age of Surveillance Capitalism is precisely the opposite: human experience is claimed as free raw material without meaningful consent. What appears to be a free service is an extraction operation, and what’s being extracted is you. The economic model of the surveillance industry depends on this semantic deception. The data collected about you — your location every thirty seconds, your emotional responses to content, your vulnerability windows, your purchase patterns — was never asked for in any meaningful sense. The consent was buried in fifty-page terms of service that the world’s best legal teams wrote to be unreadable. |
| 2 | Cambridge Analytica didn’t steal votes. It stole the capacity to choose. Cambridge Analytica’s system worked by building OCEAN Big Five personality profiles from 87 million Facebook users’ data, then designing political content specifically calibrated to exploit each personality type’s vulnerabilities. A highly neurotic person received fear-amplifying content. A person high in agreeableness received community-threat messaging. A person low in conscientiousness received permission-to-disengage messaging targeted at likely opposition voters. This is not political advertising. It is psychological manipulation using a model of your personality that you generated yourself through digital behaviour, without any awareness that a model was being built. The choice in the voting booth felt like yours. The Cambridge Analytica files showed it had been engineered weeks before you got there. |
| 3 | There are 4,000 data broker companies holding 1,500 data points on each of us. Most people have never heard of any of them. Data brokers collect, aggregate, and sell personal data profiles that the individuals profiled have never consented to, typically don’t know exist, and cannot easily access or delete. The industry generates an estimated $350 billion annually. A typical consumer profile contains approximately 1,500 data points: name, address, employment history, purchasing patterns, political affiliation, estimated income, health indicators derived from purchasing behaviour, and much more. India’s data broker ecosystem is less formally documented but functionally similar. Telecom data, Aadhaar-linked service data, UPI transaction patterns, and mobile usage data are all commercially traded in various forms. The profile being built of every Indian digital citizen is comprehensive, growing, and largely outside their knowledge or control. |
| 4 | Chanakya built the world’s first surveillance state and warned citizens not to share their secrets. He was warning them about himself. Kautilya (Chanakya), Chancellor of the Maurya Empire approximately 300 BCE, wrote the Arthashastra — the world’s first systematic text on statecraft and intelligence. He classified agents into Samstha (stationed), Sancara (wandering), and Satri (institutional) categories to comprehensively surveil the population. The explicit goal: ‘The king shall know the movements, loyalty, and secret activities of all.’ Simultaneously, Chanakya Niti warns: protect your personal secrets, your family’s vulnerabilities, your strategic plans. He wasn’t warning people about a hypothetical threat. He was warning them about a system he had designed. In 2026, replace ‘king’ with ‘platform’ and the warning is identical. The structure of power over information has not changed in 2,300 years. Only the instruments have. |
| 5 | The British colonial cadastral surveys of India were data colonialism. The digital version is still happening. The Great Trigonometric Survey of India and the British colonial cadastral surveys of the 19th century converted India’s complex land tenure — overlapping customary rights, oral traditions, communal use, ancestral claims — into simple data categories that served colonial revenue extraction. Farmers whose ancestral rights existed in oral tradition found those rights did not exist in the cadastral record. The survey was data collection. The dispossession was what the data made possible. India’s 1.4 billion people are currently generating enormous volumes of data that is processed predominantly by technology companies headquartered in the United States. The data describing India, in extraordinary detail, is largely held outside India and primarily serves interests external to India. This is structurally identical to the British cadastral survey: comprehensive data extraction from the Indian population that primarily benefits an external power. |
| 6 | This is a human problem. Blaming individuals for being exploited by surveillance capitalism is like blaming the colonised for being colonised. Individual data security practices address symptoms of a structural problem without changing the structure. The surveillance economy was designed by the world’s best engineers and behavioural scientists, backed by hundreds of billions of dollars, specifically to be difficult to opt out of and impossible to fully understand from the inside. The grandmother who sent her OTP to a fraudster because the message knew her bank and last transaction is not careless. She was successfully targeted by an infrastructure built to defeat human vigilance. India’s DPDPA 2023 is the structural beginning of a structural response: rights of access, correction, and erasure; accountability for data fiduciaries; consequences for misuse. It is incomplete. It does not adequately address state surveillance or cross-border data flows. But it names the right problem: data sovereignty requires law and collective action, not just individual vigilance. |
📊 The Data Extraction Pipeline: From You to the Prediction Market
| Stage | Who Does This | What They Extract | What It Produces / Scale |
| 1. Generation | You, using every digital service | Location, behaviour, preferences, relationships, timing patterns, emotional responses | Raw behavioural data — the ‘exhaust’ of digital life. 4GB/day per smartphone user. |
| 2. Collection | Platforms (Meta, Google), apps, retailers, telcos | Aggregated behavioural streams across your entire digital life | A continuous behavioural record, often stored permanently. |
| 3. Profiling | Platforms + data brokers (4,000 companies) | Correlation of data streams into a personality and vulnerability profile | A predictive model: what you’ll buy, fear, believe, vote. ~1,500 data points per person. |
| 4. Sale | Data brokers sell to advertisers, campaigns, employers, insurers, governments | Prediction products: ‘This person will respond to X, fear Y, be persuaded by Z’ | $350 billion/year. Your profile sold thousands of times without your knowledge. |
| 5. Targeting | Advertisers, political campaigns, employers | Precisely designed content delivered at vulnerability windows | Engineered choices that feel like your own decisions. |
| 6. Exploitation | Fraud rings via dark web data markets | Stolen breach data for identity theft, SIM swap, deepfake fraud | Financial and identity losses. Predominantly targeting India’s vulnerable populations. |
1. What Is a Datum? The Deception Hidden in the Word
Let’s start where no technology article starts: Latin class.
Datum comes from dare, the Latin verb meaning to give. Datum is its past participle: that which has been given, something given. Data is the plural: things which have been given. The entire information economy is built on this word — and the word carries an assumption that has never been true at any meaningful scale. When Facebook calls it ‘data you share with us,’ the word share implies a voluntary act. When a privacy policy says ‘data you provide,’ the word provide implies deliberate contribution. When an app asks for ‘permission to access your data,’ the word access implies the data belongs to you and is simply being visited.
None of this is what actually happens. What happens is closer to what in Latin would be called extractio: drawing out, removing, taking. Your location every thirty seconds, your scroll velocity when you encounter different types of content, the length of time you pause on specific images, the emotional valence of your search queries at different times of day, your purchasing patterns correlated with your social network’s purchasing patterns — none of this was requested. None of it was given. It was read off your behaviour by systems designed specifically to do so, continuously, without your knowledge in most cases and without meaningful understanding in virtually all.
What data actually costs and who is paying
By 2023, the global datasphere reached approximately 120 zettabytes — one zettabyte is 10 to the power of 21 bytes. That number is too large to be meaningful, so here’s a smaller one: the average smartphone user generates approximately 4 gigabytes of data per day, most of which is captured by the apps, services, and networks they use. Your smartphone is the most productive intelligence-gathering device ever built. The only confusion is about whose benefit it primarily serves.
Data brokers pay between $0.001 and $10 per individual data point depending on specificity and freshness. A comprehensive consumer profile — the full 1,500-point profile that data brokers maintain on most adults in data-rich economies — sells for between $150 and $600 depending on the market and buyer. This profile was built from the aggregation of your digital exhaust across years, without your compensation, without your knowledge of what it contains, and without meaningful ability on your part to see, correct, or delete it.
Your data, derived from your life, built using your behaviour, sold without your knowledge, used to influence your decisions. Datum: that which is given. The word is a lie.
❝
We call it data — that which is given. But you never gave it. It was taken from the exhaust of your daily life by systems designed specifically to be invisible while doing so. The Latin word they should have used is extractum. That which was drawn out.
— Dr. Narayan Rout | TheQuestSage.com
2. The Surveillance Economy — When Your Life Became a Factory
In 2001, something happened inside Google that Shoshana Zuboff identified in The Age of Surveillance Capitalism as the original sin of the modern data economy. Following the September 11 attacks, the US government asked technology companies to provide search data for national security investigations. Inside Google, engineers realised that the ‘exhaust data’ from searches — the click patterns, the reformulated queries, the abandonments — was more valuable than the search itself. It could predict what people would search for next. It could predict purchase intent. It could predict emotional state. The realisation: it wasn’t the answer to the query that was most valuable. It was the pattern of how people sought answers.
That realisation is the intellectual seed of everything that followed. Human behaviour, continuously observed and aggregated, becomes predictive. And prediction is the product. Not the search result, not the social media post, not the map directions — those are the free services. The prediction about your future behaviour is what gets sold: to advertisers, to political campaigns, to employers, to insurers, to governments.
The economic logic that makes this rational
The surveillance economy follows a precise logic that Zuboff calls the logic of accumulation: every interaction with a digital service produces behavioural data as a by-product; this by-product is worth more than the service itself; therefore the rational strategy for a platform is to maximise data production, not user wellbeing. This explains why social media is engineered to maximise engagement time (more time = more data) rather than mental health (wellbeing does not produce data). It explains why apps request access to microphone, location, and contacts far beyond what their nominal function requires. It explains why free services are offered without apparent commercial logic: the data produced is worth more than any subscription fee.
Facebook’s revenue in 2023 was approximately $134 billion. It comes almost entirely from selling prediction products derived from the behaviour of approximately 3.1 billion monthly active users. The product is not advertising space. It’s a prediction about what a specific, profiled individual will respond to, buy, believe, or vote for, delivered at the moment of highest susceptibility. The advertising is the delivery vehicle. The prediction is the product. And the raw material is your life.
The data broker layer that most people miss
The surveillance economy has a layer that most people are entirely unaware of even when they’re thinking carefully about data privacy: the data broker industry. These are companies that collect data from every available source — public records, loyalty cards, credit card transactions, app data, social media, retailer data, telecom records — aggregate it into individual profiles, and sell those profiles to anyone willing to pay.
Four thousand data broker companies. $350 billion per year. The companies most people have never heard of — Acxiom, Experian, TransUnion, LexisNexis, Oracle Data Cloud — may hold profiles more detailed than anything Meta or Google holds, because they aggregate across all platforms simultaneously. A data broker profile doesn’t just know what you do on Facebook. It knows what you buy at the pharmacy, what neighbourhood you drove through last Tuesday, how much you paid in rent three years ago, what political candidate you donated to in 2019, and what prescription you ordered last month.
You cannot opt out of most data brokers. They collect from public records, which are public. Each broker requires a separate removal request, and the FTC has documented that many do not comply reliably. The architecture was designed to be impossible to exit from within.
3. The Sovereignty Attack — How Your Choices Were Engineered Before You Made Them
Here is the thing that separates data extraction from data weaponisation. Extraction is concerning. Weaponisation is the civilisational crisis.
Data extraction means your information is collected without adequate consent and used for commercial purposes. It’s a serious privacy violation. But it’s something that, if fully understood, most people might find tolerable: their browsing history is used to show them relevant advertisements. Annoying. Not catastrophic.
Data weaponisation is different. It means your own psychological profile — your fears, your tribal identities, your cognitive vulnerabilities, your emotional triggers — is used by people with specific political or commercial objectives to engineer what you believe, who you distrust, and what you choose. Not to show you a relevant advertisement. To install a conviction in your mind that you experience as your own.
Cambridge Analytica: the case study that opened the curtain
In 2018, journalist Carole Cadwalladr and The Guardian published the first comprehensive account of Cambridge Analytica’s operations. Cambridge Analytica obtained data from approximately 87 million Facebook users through a personality quiz app created by Cambridge researcher Aleksandr Kogan. Users who took the quiz consented to data collection. Their friends who had not taken the quiz and had not consented had their data harvested through Facebook’s then-permissive API.
Cambridge Analytica built psychographic profiles of these 87 million people using the OCEAN Big Five model. From Facebook engagement patterns alone — what you liked, shared, and commented on — the algorithm could infer your OCEAN profile with meaningful accuracy. Then these profiles were used to design political content. Not one message for all voters. Sixty-four different types of advertising, each optimised for a specific psychological profile, delivered to the people most susceptible to each type.
A person scoring high on Neuroticism received fear-based messaging designed to amplify existing anxieties. A person low in Agreeableness received conflict-amplifying content. A person low in Conscientiousness received messaging that gave them permission to disengage — specifically targeted at likely opposition voters. The result in the 2016 US presidential election and the Brexit referendum was not that Cambridge Analytica changed anyone’s mind in the conventional sense. It found psychological doors that were already slightly open and pushed them wider. The choice that happened in the voting booth felt like the voter’s own. It had been designed weeks earlier.
The slot machine: how your engagement was manufactured
Tristan Harris, who worked as a Design Ethicist at Google before founding the Center for Humane Technology, testified before the US Senate about the attention economy’s most powerful and least disclosed mechanism: the variable reward schedule.
B.F. Skinner established in the 1930s that variable reward schedules — where a behaviour produces a reward intermittently and unpredictably rather than every time — produce the most compulsive, persistent behaviour patterns. Slot machines are built on this principle. The social media feed is a slot machine. Each scroll produces a new card of content. Most cards are unremarkable. Some produce a response — a moment of amusement, a flash of outrage, a notification that someone responded to you. The intermittency is not an accident. It is the deliberate design principle of the feed algorithm, which has been optimised not to show you the most useful or truthful content but the content most likely to keep you scrolling, because every scroll produces data, and data is the product.
This design was not disclosed. The political polarisation documented in every major democracy over the last decade is partly a by-product of this optimisation. Not because any platform intended to polarise society. But because polarising content produces more engagement, engagement produces data, and data produces revenue. The system did exactly what it was optimised to do. The collateral damage was the public conversation.
4. New-Age Frauds — When Your Own Data Becomes the Weapon Against You
Everything described in the previous section is done by sophisticated, publicly listed companies with billions of dollars in legal budgets. What follows is what happens when less legally constrained actors get access to the same data.
The dark web pipeline
Every major data breach feeds into a supply chain that ends with your data available for purchase on dark web marketplaces. The 2023 AIIMS breach exposed records of approximately 40 million Indian patients. The 2021 Facebook breach exposed data from 533 million accounts. The 2022 Twitter breach exposed data from 400 million accounts. Each produces a structured dataset: name, phone number, email, address, sometimes financial data, sometimes health data. These datasets are aggregated, cross-referenced with other breach datasets, and sold.
A fraud operation that purchases your compiled profile — name, phone number, bank name (derived from UPI transaction metadata), approximate age, and any health or financial vulnerabilities indicated in the data — can construct a message that is nearly indistinguishable from a genuine communication from your bank. The message arrives via SMS or WhatsApp. It references your bank by name. It mentions a recent transaction. It uses your name. It expresses appropriate urgency. The reason it works is not that the victim was careless. The fraud had more information about the victim than the victim expected any bad actor to possess.
SIM swap: when your identity is stolen at the network level
SIM swap fraud uses your data — name, ID number, phone number, and additional personal details purchased from data brokers or obtained from breaches — to convince a telecom customer service representative to transfer your mobile number to a SIM controlled by the fraud operator. Once your number is on their SIM, every OTP intended for you goes to them. Within minutes, they can access your banking apps, email, social media, and any other service that uses your phone number for authentication.
By the time the victim realises their phone has no signal — the first indication a SIM swap has occurred — the attack is often already complete. Accounts have been emptied. Email has been accessed. Passwords have been reset. The data that enabled this attack was in commercial datasets long before the fraud operation decided to use it.
Deepfake fraud: when they use your family’s voice against you
AI audio synthesis has reached the point where a two to three minute sample of a person’s voice — available from any video they’ve posted online, any recording of a celebration, any WhatsApp voice message that has been forwarded — is sufficient to generate realistic synthetic audio of that person saying things they never said. The fraud pattern documented in multiple countries, and beginning to appear in India: a family member receives an audio call from someone who sounds exactly like another family member, explaining they’re in an emergency, need money immediately. The emotional urgency of the scenario, combined with the recognised voice, bypasses the rational evaluation that would normally screen this request. The call is from a voice model trained on the family member’s online audio. The family member is safe. The money is gone.
5. Chanakya Knew — The World’s First Architect of Surveillance
Two thousand three hundred years before the Cambridge Analytica revelations, a man named Kautilya — also known as Chanakya — wrote a text that remains one of the most sophisticated works on political power in human history.
The Arthashastra (approximately 300 BCE) is a treatise on statecraft, political economy, military strategy, and intelligence. It is systematic, methodical, technical, and ruthlessly focused on what works. And Book 1 of the Arthashastra establishes, in considerable technical detail, the world’s first documented systematic intelligence apparatus.
The spy network that pre-dated every modern intelligence agency
Chanakya classified intelligence agents with a precision that a modern intelligence analyst would recognise. Samstha were stationed agents — permanent operatives embedded in specific locations: the marketplace, the temple, the royal court, the guild headquarters. Their job was to know everything that happened in their location and to report it to the state’s intelligence coordination. Sancara were wandering agents — operatives who moved through the population, blending into different social contexts, gathering information about sentiment, plots, and movement. Satri were institutional agents embedded inside monasteries, educational institutions, professional guilds, and foreign courts.
The explicit goal Chanakya states: ‘The king shall know the movements, loyalty, and secret activities of all.’ All. Not potential enemies. Not foreign powers. All subjects. The Arthashastra’s intelligence system was designed to know the personal secrets, family vulnerabilities, financial situations, and political loyalties of the entire population. This is, structurally, exactly what Meta’s data operation is. The categories differ. The instruments are digital. The scale is planetary. But the logic is identical: collect comprehensive information about the population; use it to predict behaviour; use those predictions to influence outcomes.
The warning that came from the same mind
Here is the extraordinary thing about Chanakya: the same mind that built the surveillance state also warned the citizens living inside it. Chanakya Niti — his collection of political and ethical aphorisms — contains a specific, categorical warning. ‘Na rahasyam prakaashayet’ — Do not reveal the secret.
Chanakya classified the secrets to protect into three categories:
- Personal (vyaktigat guhya) — your own vulnerabilities, your fears, your private failures, your health, your relationships;
- Family (kutumba guhya) — the vulnerabilities, conflicts, and private affairs of those closest to you; and
- Strategic (rajya guhya) — your plans, your resources, your professional position, your strategic moves.
The warning makes complete sense when you understand who wrote it. Chanakya built the intelligence apparatus that collected exactly these categories of information from the population. He knew, from operational experience, exactly how personal secrets, family vulnerabilities, and strategic plans are converted into leverage. He wasn’t warning people about a hypothetical threat. He was warning them about a system he himself had designed. In 2026, replace ‘state’ with ‘platform’ and the warning is identical.
Why his warning is more urgent today than in 300 BCE
In Chanakya’s time, intelligence collection required human agents. The Samstha and Sancara had to be physically present, had to cultivate relationships, had to work over time. There were natural limits to the scale and speed of surveillance. A state could surveil its elite class, its political opponents, its border regions. Comprehensive population surveillance was logistically impossible.
Today there are no such limits. The smartphone in every pocket is a more productive surveillance device than any Sancara agent Chanakya could have deployed. It generates location data continuously, tracks every digital interaction, records every purchase, maps every social relationship, and transmits all of this to servers that process it at computational speeds Chanakya could not have imagined. The citizen is not surveilled from outside. They carry the surveillance apparatus voluntarily, because it also makes phone calls and plays music and helps them navigate.
Chanakya’s three categories of secrets remain exactly right: your personal vulnerabilities, your family’s weaknesses, and your strategic plans are the three categories of information that give whoever holds them power over you. What has changed is the number of entities that can now access these categories, the ease with which they do so, and the sophistication of the systems that convert that access into influence. The warning has not become less relevant. It has become almost impossibly urgent.
6. Data Has Always Been Power — The Historical Evidence
The instinct to frame the current data crisis as unprecedented is understandable but misleading. The instruments are new. The logic is not. Whoever knows more about a population than the population knows about itself has always held power over that population.
The Roman census: empire built on headcount
The word census comes from the Latin censere — to assess, to estimate, to tax. Rome’s census, conducted every five years, recorded name, family status, property, and occupation. The data was used for taxation, military conscription, and the allocation of political rights. Roman citizenship itself was a data category that determined who had legal protections, who could vote, who was subject to which laws. To be incorrectly counted was to be incorrectly taxed. The Roman Empire ran on census data.
British colonial surveys of India: land data as the tool of dispossession
The Great Trigonometric Survey of India (1802-1871) and the British colonial cadastral surveys of the late 19th century converted India’s physical territory and land tenure into measurable, administratively manageable data. India’s land tenure was historically complex: overlapping customary rights, oral traditions, seasonal arrangements, communal use, ancestral claims. The British cadastral survey flattened this complexity into simple data categories that served colonial revenue extraction. Farmers whose ancestral rights existed in oral tradition found those rights did not exist in the cadastral record. The survey was data collection. The dispossession that followed was what the data made administratively possible.
The dynamic is identical to today’s: collect comprehensive data about a population, then use that data to extract value from and exert control over that population. India’s 1.4 billion people are currently generating enormous volumes of data that is processed predominantly by technology companies headquartered in the United States. The data describing India, in extraordinary detail, is largely held outside India. The colonial tool has been digitalised.
IBM and the Holocaust: the most uncomfortable data lesson
Edwin Black’s archival research in IBM and the Holocaust documented the role of IBM’s Hollerith punch card tabulating machines in enabling the Nazi census of 1933, which identified and enumerated Jewish, Roma, and other persecuted populations with unprecedented precision. The census, processed using IBM technology leased and serviced by IBM’s German subsidiary Dehomag, converted the complex social reality of a diverse population into sortable, searchable data: race, religion, occupation, location, family connections. This data made systematic identification, tracking, deportation, and murder logistically possible at industrial scale.
The Jewish community did not consent to this use of the census data. They could not have anticipated it. Many participated as German citizens in good faith. The use to which the data was put was determined entirely by those who held it. The lesson that must not be avoided: the danger of comprehensive population data is the permanent gap between the declared purpose of collection and all possible uses of the data collected. IBM collected census data for demographic analysis. The Nazi state found uses that IBM did not design, did not intend, and did not know. This gap — between declared purpose and actual use — is the permanent structural vulnerability of every data collection system, from the Roman census to the Meta platform.
The pattern that repeats across history
Roman census. British cadastral surveys. Nazi census. Credit bureaus used for racial redlining. Cold War surveillance files. Cambridge Analytica. Meta’s advertising platform. The specific technologies differ across twenty-three centuries. The logic is constant: collect comprehensive data about a population; use that data to predict and influence behaviour; the benefits accrue to whoever holds the data, not those about whom it was collected; and the uses of the data expand far beyond whatever purpose was declared at the time of collection. The current crisis is not new. It is the oldest crisis in human political history, now running at planetary scale with computational infrastructure that makes Chanakya’s spy network look like a candle next to the sun.
7. This Is Our Problem, Not Yours — Why Individual Solutions Are Insufficient
Let me be direct about something that most articles about data privacy get wrong.
This is not your fault. The grandmother who sent her OTP to a fraudster because the fraud message knew her bank, her name, and the last transaction she made — that is not a failure of her vigilance. That is the successful operation of a multi-billion-dollar criminal infrastructure that was built specifically to defeat human vigilance. The farmer who gave his Aadhaar details to someone who called pretending to be from a government benefits scheme is not stupid. He was targeted by an operation that had enough data about him to be credible. The urban professional who clicked a phishing link that perfectly replicated their company’s internal IT portal is not careless. They were a target of a system that had enough data to construct a near-perfect simulation.
Blaming individuals for being exploited by surveillance capitalism is like blaming the colonised for being colonised. The power asymmetry is total. The tools are designed specifically to exploit human cognitive architecture at its most vulnerable points. Individual awareness helps at the margins. It does not address the structural problem.
Digital colonialism: India’s specific position
India generates an extraordinary volume of data. 1.4 billion people, most with smartphones, conducting digital transactions through UPI, communicating through WhatsApp, searching through Google, watching through YouTube. The data generated by this activity is processed predominantly by technology companies headquartered in the United States. India generates the data; the processing and economic value happen in California. The artificial intelligence systems being trained on Indian-generated data — on Hindi speech, on Indian faces, on Indian transaction patterns, on Indian medical records — are owned by companies not primarily accountable to Indian citizens or the Indian state. The data that describes India, in enormous detail, is largely held outside India. This is not metaphorically colonial. It is structurally identical to the British cadastral survey.
The DPDPA 2023: a first step toward structural response
India’s Digital Personal Data Protection Act 2023 creates meaningful obligations: consent must be obtained before data collection; data can be used only for declared purposes; individuals have rights of access, correction, erasure, and grievance redressal. But the DPDPA has significant limitations. The exemptions for state actors are broad, potentially allowing government surveillance to continue without the same consent requirements placed on private companies. The cross-border data flow provisions are not yet complete. Enforcement mechanisms are still developing.
Individual VPNs and privacy settings and careful password management are necessary but not sufficient. They are the equivalent of teaching farmers to grow hedgerows when the cadastral survey team is already measuring the fields. The structural answer is law, accountability, and population-level understanding of what is at stake. The DPDPA is the beginning of the legal response. It is not yet the complete one.
8. Chanakya’s Protocols for the Digital Age — A Sovereignty Framework
Understanding the problem completely is not enough. Here is what can be done — not as a complete solution to a structural problem, but as a personal sovereignty practice that reduces exposure and changes the relationship to data from passive generation to conscious management.
Protocol 1: Personal secrets in the digital space
Chanakya’s first category is the personal: your vulnerabilities, your fears, your health, your financial situation, your relationship difficulties. In the digital context: do not share your financial situation in detail on any platform, including messaging apps. Do not share health details with apps that have no clinical reason to hold them. Do not enter moments of emotional vulnerability — a difficult day, a period of grief, an anxiety episode — into search engines or social media. These patterns are precisely what the algorithmic profiling system uses to identify and exploit vulnerability windows. Protect your vulnerable moments from the platforms designed to monetise them.
Protocol 2: Family secrets in the digital space
Chanakya’s second category: the family’s vulnerabilities. Do not post details of family members’ locations, routines, or identifying information on public platforms. Do not share family members’ phone numbers or WhatsApp details widely. The data that enables a deepfake audio fraud to target your mother is often data you have posted yourself: her voice in a family video, her name tagged in a photograph, her contact number in a shared group. Protect your family’s data as Chanakya advised protecting family secrets: not out of shame but out of strategic wisdom.
Protocol 3: Strategic and professional data
Chanakya’s third category: your strategic plans, your financial intentions, your location patterns, your professional vulnerabilities. Turn off location services for all apps that do not functionally require them. Be aware that your commute pattern, your regular locations, and your travel plans are valuable to certain categories of bad actors. Do not share professional plans, financial decisions, or career moves on any platform before they are final and your position is secure.
Protocol 4: Treat unusual knowledge as a red flag
The defining characteristic of data-enabled fraud is that it knows things about you that a genuine bad actor shouldn’t know. A scam call that mentions your bank by name and references a recent transaction is using breach data that included your details. The correct response: hang up; contact the institution independently using a number you find yourself; and assume that any communication that feels unusually well-informed about you is using data to manufacture credibility. The level of specific information that a fraud operation can access makes ‘if it knows too much about you, be more suspicious — not less’ the operative rule.
Protocol 5: Change the defaults
The ‘Accept All Cookies’ button is the digital equivalent of signing an unreadable document at speed you cannot read. The consent mechanism was designed by legal and UX teams to obtain the broadest possible consent with the least possible user resistance. Changing any default toward minimum collection is a meaningful act of sovereignty: choose ‘Reject Non-Essential Cookies’ rather than ‘Accept All’; turn off location access for apps that don’t need it to function; disable ad personalisation on Google, Meta, and your phone’s advertising settings. These changes take minutes and meaningfully reduce the scope of surveillance.
Protocol 6: Know your rights under DPDPA 2023
As an Indian citizen under the DPDPA 2023, you have the right to know what data a company holds about you; to correct inaccurate data; to request erasure when the declared purpose has been fulfilled; to seek grievance redressal when your rights are violated; and to nominate someone you trust to exercise these rights on your behalf. Knowing these rights exist is the first step. Using them — and expecting accountability when companies fail to honour them — is how rights become real rather than theoretical.
The Quest Sage Insight
Writing this article means sitting with two uncomfortable truths simultaneously.
The first is that this is overwhelming. The surveillance infrastructure built over the last two decades is comprehensive, deeply embedded in daily life, and enormously difficult to opt out of. It is governed by interests with more legal sophistication, more engineering talent, and more capital than any individual can marshal. And it operates by making itself useful. The surveillance apparatus is embedded in the most convenient tools of daily life — in the app that navigates you home, in the platform that connects you to people you love, in the service that helps you find what you’re looking for. The price of convenience is your data. And the price of your data, paid in aggregate across billions of people, is the partial surrender of collective human sovereignty.
The second uncomfortable truth is that Chanakya was not warning us about a future problem. He was describing an eternal one. Power has always worked by knowing what people know about themselves — and by those in power knowing more. Every census, every cadastral survey, every intelligence network, every algorithmic profile is a version of the same dynamic: information about you, held by someone else, used in ways you didn’t authorise for purposes that serve their interests. The digital version is faster, more comprehensive, more sophisticated. But it is not categorically new. It is the oldest political reality in human history, now running on 21st-century infrastructure.
What Chanakya’s warning offers is a philosophical orientation. Think of your data as property. Think of your attention as a resource with finite value that should be allocated deliberately. Think of your vulnerability windows as moments to guard rather than share. Think of your family’s digital presence as something you have a responsibility to protect collectively.
The battlefield is your mind. Chanakya knew this. Cambridge Analytica proved it with a dataset. The question is whether, knowing what we know, we understand it fully enough to begin the work of defending it.
What You Can Do With This
- Audit what you’ve already given. Go to Google’s My Activity page, Facebook’s Your Facebook Information section, and your phone’s app permissions settings. Look at what data has already been collected and what permissions you’ve granted. The audit will be uncomfortable. It should be. Understanding the current state is the prerequisite for changing it.
- Apply Chanakya’s three-category test before posting or sharing anything digital. Personal (my vulnerabilities, fears, health, finances)? Family (information about relatives that could target them)? Strategic (my plans, location, professional situation before it’s settled)? If yes to any of the three — don’t share in the current form. The instinct to overshare in the name of authenticity is exactly the behaviour the surveillance economy was designed to encourage.
- Change the defaults. The default setting of every major platform is maximum data collection. Choosing ‘Reject Non-Essential Cookies’ instead of ‘Accept All,’ turning off unnecessary location access, and disabling ad personalisation on Google and Meta are small actions that meaningfully reduce surveillance scope. These changes take minutes. They are acts of sovereignty.
- Never trust a communication that knows too much. Any message, call, or email that feels unusually well-informed about you is likely using breach data to manufacture credibility. Treat unusual specific knowledge as a red flag. Hang up. Contact the institution independently. The rule has reversed: the more specific and accurate a suspicious communication’s knowledge of you, the more suspicious you should be.
- Have the family conversation. The most vulnerable people are typically the eldest and the youngest. Talk to family members about Chanakya’s three categories in plain language: these are the things we don’t share outside the family in digital form. Name, phone number, bank details, location — these are family secrets in the 21st century. This conversation is not technical. It’s a sovereignty conversation.
- Know and exercise your rights under DPDPA 2023. Rights that are not exercised are not real. Know that you can request access to, correction of, and erasure of your data from companies operating in India. Expect accountability when companies fail to honour these rights. The law exists. Using it is what gives it meaning.
✅ 3 Key Outcomes
1. Data is not given — it is extracted: the word datum (Latin: that which is given) encodes a fundamental deception at the heart of the surveillance economy; Shoshana Zuboff’s surveillance capitalism framework establishes that human experience is claimed as free raw material without meaningful consent, converted into behavioural data, and sold as prediction products worth $350 billion annually through 4,000 data broker companies; and Cambridge Analytica’s use of the OCEAN Big Five personality model on 87 million Facebook profiles demonstrated that this infrastructure can be weaponised not just for commercial targeting but for the engineering of political choices — making what voters experienced as free democratic decisions the product of psychographic manipulation designed weeks before the vote.
2. Data as power is the oldest political reality in human history, not a new technological problem: the Roman census, the British colonial cadastral surveys of India (converting complex traditional land tenure into taxable data categories enabling systematic dispossession), IBM’s Hollerith machines enabling the Nazi census of 1933 (Edwin Black), and Chanakya’s systematic intelligence network in the Arthashastra (approximately 300 BCE, classifying agents into Samstha, Sancara, and Satri categories to surveil the entire population with the explicit goal of knowing ‘the movements, loyalty, and secret activities of all’) all demonstrate the same constant: whoever knows more about a population than the population knows about itself holds power over that population; the digital age is this dynamic at planetary scale and computational speed.
3. The response must be structural, not just individual: Chanakya’s threefold warning (protect personal secrets, family vulnerabilities, and strategic plans) provides the philosophical framework for digital sovereignty; India’s DPDPA 2023 establishes the legal framework (rights of access, correction, erasure, and grievance redressal for data principals); but individual privacy practices, however diligent, are insufficient against a surveillance infrastructure designed specifically to defeat human vigilance; what is required is law strengthened and enforced, data fiduciaries held accountable, digital literacy at population scale, and the political will to treat data sovereignty as a question of collective human dignity rather than individual technical preference.
Conclusion: The Battlefield Has Always Been Your Mind
Datum. That which is given. The word was always a lie.
From Chanakya’s spy network monitoring the population of the Maurya Empire, to the Roman census that was the administrative backbone of an empire, to the British cadastral surveys that dispossessed generations of Indian farmers, to the IBM machines that made the Holocaust logistically possible, to the Cambridge Analytica system that engineered elections using 87 million people’s psychological profiles — the story is the same across twenty-three centuries. Data about people is power over people. Whoever holds the data sets the terms of the relationship. The people about whom the data was collected are the last to know what is held about them and the last to have any say over how it’s used.
What is different today is not the logic. It’s the scale, the speed, and the invisibility. The Sancara agent moving through the marketplace was visible. The algorithm tracking your scroll velocity at 11 PM is not. The British surveyor in the field was observable. The data broker building your 1,500-point profile is not. The census collector at the door was knowable. The digital fingerprint left by every interaction with every platform is not, to most users, visible at all.
Chanakya warned us from the inside of the first surveillance state, knowing exactly how the information would be used, knowing exactly what leverage it provided to whoever held it. He gave us the categories 2,300 years ago: personal secrets, family vulnerabilities, strategic plans. Cambridge Analytica confirmed, with computational precision, that those three categories — personality vulnerabilities (personal), social connections (family), and political intentions (strategic) — are exactly what a 21st-century sovereignty attack targets.
The battlefield is your mind. It has always been your mind. The instruments for reaching it have never been more sophisticated. The only defence that has ever worked is what it has always been: knowing who you are, knowing what you value, and being vigilant about who gets to know those things about you. Chanakya was right. Cambridge Analytica just proved it with a dataset.
🪞 3 Self-Reflection Questions
Q1. Open your phone’s location history right now, if your operating system allows it. Look at the map of everywhere you’ve been in the last month. That map exists. It’s been generated by your device, transmitted to servers, and almost certainly sold. Who has that map? What could someone do with it? And is the service that collected it worth that trade? Sit with the discomfort of this question before deciding whether the answer is yes.
Q2. Chanakya warns against sharing personal secrets, family vulnerabilities, and strategic plans. Think about your social media presence over the last year. How much of those three categories have you posted, shared, or allowed to be visible? If Chanakya’s Sancara agents were monitoring your digital activity — which they functionally are, in the form of platform algorithms — what would they know about your fears, your family’s situation, and your professional plans? Is that knowledge in the right hands?
Q3. Cambridge Analytica’s system worked by finding the psychological doors that were already slightly open and pushing them wider. Think about a strongly held political or social conviction you’ve developed in the last five years. Is there any part of you that isn’t completely certain whether that conviction came from your own careful reasoning or from the cumulative effect of content specifically designed to reach someone with your psychological profile? What would it take to find out?
Frequently Asked Questions: Data, Sovereignty, and the Surveillance Economy
Q1. What is surveillance capitalism and why does it matter to me personally?
Surveillance capitalism is the economic system named by Shoshana Zuboff in The Age of Surveillance Capitalism (2019) in which human experience is claimed as free raw material for commercial production. The process: observation (your behaviour is monitored through digital platforms); extraction (the behavioural data is collected and analysed); and production (prediction products are sold to those who want to influence your future behaviour). It matters personally because the prediction products derived from your data are sold to advertisers, political campaigns, employers, and insurers that use those predictions to influence choices you haven’t consented to. The content you see, the prices you’re offered, the political messages you receive, and the job opportunities that reach you are all being filtered through predictive systems built from your personal data. Your experience of the world is being customised by people who know more about your psychology than you know about theirs, using information you generated but did not explicitly share.
Q2. How did Cambridge Analytica use personality data to influence elections?
Cambridge Analytica obtained data from approximately 87 million Facebook users without their consent through a third-party app that harvested not just quiz-takers’ data but their Facebook friends’ data (who had not consented at all). They built psychographic profiles using the OCEAN Big Five personality model. From Facebook likes alone, the algorithm could infer your OCEAN profile with meaningful accuracy. In the 2016 US election and Brexit referendum, these profiles were used to design and deliver 64 different types of advertising, each optimised for specific psychological profiles in specific constituencies. People high in Neuroticism received fear-amplifying content. People low in Conscientiousness received permission-to-disengage messaging targeted at likely opposition voters. The system was not making arguments. It was exploiting psychological profiles to engineer pre-determined conclusions in people who believed they were forming independent opinions. The whistleblower Christopher Wylie published the detailed account in Mindf*ck (2019).
Q3. What were Chanakya’s three categories of secrets and how do they apply today?
Chanakya (Kautilya), Chancellor of the Maurya Empire approximately 300 BCE, warned in Chanakya Niti to protect three specific categories: personal secrets (vyaktigat guhya): your own vulnerabilities, fears, health, financial situation, and private failures; family secrets (kutumba guhya): the vulnerabilities and private affairs of those closest to you; and strategic secrets (rajya guhya): your plans, resources, professional intentions, and strategic moves. These map precisely onto the three categories that modern data exploitation weaponises most effectively. Personal vulnerabilities are what Cambridge Analytica exploited. Family data is what enables deepfake audio fraud targeting your relatives. Strategic information (financial plans, location patterns, professional situation) is what data brokers sell to employers, insurers, and governments. Chanakya classified these categories from inside the world’s first intelligence state, knowing from operational experience exactly how this information converts into power over the person who shared it.
Q4. What are my rights under India’s DPDPA 2023?
India’s Digital Personal Data Protection Act 2023 (DPDPA) establishes several rights for data principals (Indian individuals whose data is collected): the right to access — you can request information about what data a company holds about you and how it’s being used; the right to correction — you can request correction of inaccurate personal data; the right to erasure — you can request deletion of your personal data when it’s no longer needed for the purpose for which it was collected; the right to grievance redressal — you can file complaints against data fiduciaries who violate your rights; and the right to nominate — you can designate a trusted person to exercise these rights on your behalf. The DPDPA has significant limitations including broad exemptions for state actors and still-developing enforcement mechanisms. But it creates a legal framework for data rights that did not previously exist in India. Knowing these rights exist and exercising them is the beginning of structural digital sovereignty.
Q5. How can I tell if a fraud message is using my own data against me?
Data-enabled fraud has a specific, identifiable fingerprint: it knows things about you that a genuine bad actor shouldn’t know. A fraud call that mentions your bank by name is using breach data commercially available since every major financial institution’s breach of the last decade. A fraud message referencing a recent transaction is using transaction data from breach or data broker datasets. A fraud audio call that sounds exactly like a family member is using a voice model trained on publicly available audio. The rule is the inverse of what intuition suggests: the more specific and accurate a suspicious communication’s knowledge of you, the more suspicious you should be. Legitimate institutions contact you through verified channels and do not need to demonstrate knowledge of your personal details to establish credibility. Any communication that feels unusually well-informed about you should be treated as a red flag, not proof of authenticity. Hang up. Contact the institution independently. Verify before you act.
📖 How to Cite This Article
Rout, N. (2026). Datum to Data: Chanakya Warned You. Cambridge Analytica Ignored Him. Now Your Mind Is the Battlefield. TheQuestSage Research Series, TQS-2026-188. https://thequestsage.com/datum-to-data-chanakya-cambridge-analytica-surveillance/ https://doi.org/10.5281/zenodo.21410582
License: CC BY 4.0 · Publisher: TheQuestSage.com · ORCID: 0009-0009-3505-5478
References and Sources
- Zuboff, S. (2019). The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. Harvard Business Review Press. Surveillance capitalism framework; data extraction as raw material; prediction products.
- Wylie, C. (2019). Mindf*ck: Cambridge Analytica and the Plot to Break America. Random House. First-person account of Cambridge Analytica; OCEAN model; 87 million profiles.
- Cadwalladr, C. & Graham-Harrison, E. (2018). Revealed: 50 million Facebook profiles harvested for Cambridge Analytica in major data breach. The Guardian, March 17, 2018.
- Black, E. (2001). IBM and the Holocaust. Crown Publishers. IBM Hollerith machines; Nazi census; data as instrument of the Holocaust.
- UK Information Commissioner’s Office. (2020). Investigation into the use of data analytics in political campaigns. Final Report on Cambridge Analytica. ICO-0073019.
- Kautilya (Chanakya). Arthashastra (approx. 300 BCE). Books 1 and 13 on intelligence networks; Samstha, Sancara, Satri classification; surveillance of the population. Via R. Shamasastry translation 1915; L.N. Rangarajan translation Penguin Classics 1992.
- Chanakya Niti Shastra. Three categories of secrets; Na rahasyam prakaashayet. Via standard scholarly translations.
- Harris, T. (2019). US Senate testimony on persuasive technology design; variable reward schedules; Center for Humane Technology.
- Fogg, B.J. (2003). Persuasive Technology: Using Computers to Change What We Think and Do. Morgan Kaufmann.
- Federal Trade Commission. (2014, 2023 updates). Data Brokers: A Call for Transparency and Accountability. Data broker industry size, companies, data point categories.
- India Digital Personal Data Protection Act 2023 (DPDPA). Ministry of Electronics and Information Technology (MeitY). Full Act text.
- Internet Freedom Foundation. (2023-2024). Analysis of DPDPA 2023: Key Provisions, Gaps, and Implications for Indian Citizens. iff.org.
- Mathur, N. (2021). The British Cadastral Survey in India and its legacy in land records. Economic and Political Weekly. Colonial data collection and land dispossession.
- Rout, N. (2026). Why First Impressions Matter. TQS-2026-187. The cognitive biases exploited by psychographic targeting are the same first-impression heuristics discussed in the companion article.
- Rout, N. (2026). Mahamrityunjaya: The Mantra That Answers What Evolution Created. TQS-2026-183. The prefrontal cortex and its vulnerability to fear-amplification is the neurological basis of Cambridge Analytica’s strategy.
|
Dr. Narayan Rout Author · Independent Researcher · Founder, TheQuestSage.com 🏅 Rabindra Ratna Puraskar Awardee |
Dr. Narayan Rout explores the intersection of science, philosophy, consciousness, health, technology, and human development. His work combines evidence-based research with insights from ancient wisdom traditions to make complex ideas accessible to a global audience.
Education & Experience
PG Diploma PM & IR · BNYT · BE (Electrical) · Diploma Industrial Hygiene
Diploma Psychology · Mindfulness · Nutrition · Gut Health
Indian Air Force Veteran (23 Years) · Senior Technician, BHEL
Research Interests
Consciousness Neuroscience Psychology Human Behaviour Health Sciences Technology Civilisation Studies Indian Philosophy
Publications
110+ Published Research Articles · 50+ DOI Registered Works · Zenodo · CERN · OpenAIRE
📚 Books
🔬 Research & Academic Profiles
Further Reading
- Why First Impressions Matter (TQS-2026-187) — The cognitive biases that Cambridge Analytica exploited — confirmation bias, availability heuristic, tribal identity-protective cognition — are the same cognitive architecture discussed in the first impressions article. Understanding how the mind processes social information is the prerequisite for understanding how that processing can be manipulated.
- Mahamrityunjaya: The Mantra That Answers What Evolution Created (TQS-2026-183) — The prefrontal cortex’s mortality awareness and fear-response is the neurological basis of Cambridge Analytica’s fear-amplification strategy. Terror Management Theory explains why mortality-salience content produces the strongest engagement and the strongest manipulation outcomes.
- Hunger, Fear and Imagination — the forthcoming manuscript that anchors P11 Economy of Human Life. The surveillance economy works by weaponising fear and manufactured desire — exactly the psychological roots of economic behaviour that this manuscript examines.
📋 Publication Record
| Series | TheQuestSage Research Series |
| Paper Number | TQS-2026-188 |
| Version | 1.0 |
| Publisher | TheQuestSage.com |
| DOI | 10.5281/zenodo.21410582 |
| ORCID | 0009-0009-3505-5478 |
| Language | English |
| License | CC BY 4.0 — Creative Commons Attribution |
📩
Stay Updated
TheQuestSage Newsletter
Get new research-backed articles on
Health · Philosophy · Indian Wisdom
and the future of humanity —
delivered directly to your inbox.
🔒 No spam · No sharing · Unsubscribe anytime
Join curious readers from across the world

