What does Big Tech do with my data and why should I be worried?
Summary
Everyday, we provide personal data to various companies and institutions, with Big Tech companies holding the lions share of data. This creates vast pools of identifying information which is stored worldwide.
Our data is largely used for advertising purposes, some benign and some less so. We hand over our data in exchange for convenient services provided by Big Tech companies. Reliance on these services creates an income stream for Big Tech companies.
We are living in an age where democracy is declining and AI becomes increasingly capable. The data held by Big Tech companies can be used against us either by bad actors or the companies themselves. We cannot always assume that our data is in safe hands.
There are several ways to mitigate personal risks to our data. The most effective solution is to change our mindset towards data privacy and to ask ourselves the difficult questions. Try to set some time aside to learn as much as we can from trusted sources, and then make hard changes to our lifestyle for our friends and family to follow.
Most importantly, sacrifice convenience for data privacy.
What is data privacy?
IBM describes data privacy as the principle that individuals should have control over their personal data.1 In practice, this means that everyone understands how their data is used, and provides explicit consent for their data to be used.
This is not to be confused with data security, which focuses on preventing theft and unauthorised access to your data by cyber criminals. We've all at some stage watched a corporate flavoured presentation warning us of the risks of phishing and key logging. Data privacy is different.
Imagine two scenarios. In scenario one, you are in a glass room. The room is bullet proof, the door is triple locked and there is CCTV watching from every angle. However, the room is completely transparent. You are safe, but everyone can see what you are doing. This is data security.
In scenario two, you are again in a glass room. However, this time there is no lock, no CCTV and the glass is not bulletproof. Instead, the glass is completely frosted. Outsiders can access the room, but they cannot see what you are doing. This is data privacy.
Most people know to keep their data secure. We install firewalls and anti virus software, we enforce PIN codes and passwords, and we don't click suspicious links from Nigerian princes.
So if we are aware that there are bad actors who wish to take our data to profit from, why do we willingly hand out our data to large organisations on a daily basis?
How is my data collected?
How our data is used really depends on what you consider data. The Australian Bureau of Statistics states that the definition of data are 'measurements or observations that are collected as a source of information'.2 Measurements are anything that can be quantified such as the number of steps walked, the speed at which you drive or the price of fruit. Observations are more abstract, such as the mood you are currently in, your taste in music or your political leanings.
There is an endless list of people and organisations that we knowingly or unknowingly share our data with, but never before has our data been collected on such a large scale fashion as with Big Tech companies, specifically Meta, Google, Apple, Amazon and Microsoft.
For example, Google collects the following data:3
- Terms you search for
- Videos you watch
- Views and interactions with content and ads
- Images, files, audio and video from you interactions
- Purchase activity
- People you communicate with
- Activity on third party sites and apps that use Google Services
- Chrome browsing history
- Call and message log information such as your phone number, receiver's number, forwarding numbers, send and recipient emails, time and date of calls/messages, duration of calls, routing information and volumes of calls/messages
- GPS and other sensor data from your device
- IP address
- Your searches on Google Maps and your labels like home or work
- Information about things near your device like WiFi access points, cell towers and Bluetooth connections
- Content you create, such as emails you write, photos and videos you save, documents and spreadsheet you create and comments you make on YouTube
And here is a list of the ways in which Google collects this data:3
- Google apps, sites and devices such as Search, YouTube and Google Home
- Platforms like Chrome browser and Android operating system
- Products that are integrated into third party apps and sites, like ads, analytics and embedded Google Maps
The above does not include the information that we willingly provide, such as name, payment information and address.
You will have noticed that I have highlighted a few of the terms above. Google Services includes ads and analytics that are embedded in websites and apps. This information is shared with Google irrespective of your browser or whether you are using incognito mode.4 Google analytics is estimated to be installed on 55.7% of all websites in existence.5
Sensor data includes the accelerometer and gyroscope on your phone to determine speed and direction, but can also be expanded to cover bio metric data collected through Pixel Watches and Fitbits, which is covered under a separate privacy policy.6
This is just one organisation. How much data do you imagine is collected when we factor in all the other corporate and government entities that we deal with on a daily basis? This is more information then I would ever share with a loved one, and it is being kept in vast pools around the world by individuals that we don't personally know.
"Google analytics is estimated to be installed on 55.7% of all websites in existence."
How is my data used?
This largely depends on the organisation and their business model. If you are receiving a service and not paying for it, then chances are you are paying with your data or your attention.
Google is an advertising company. In 2024, Google made $264,590 million in USD.7 To be clear, Google is not directly selling your data. Google is instead producing anonymised reports using your data to help advertisers show targeted ads.89 By providing services such as YouTube, Search, Maps and Gmail, Google is providing ad space for these businesses to target you whilst also collecting your usage data to personalise these same ads.
Also, Google does not use the data from your emails, documents, photos and other private files to train its Large Language Model (LLM), Gemini. However, Google does take publicly available information to use as training data for Gemini.10 This would include social media profiles, news articles, business information and any other data that you could easily find online.
Like Google, Apple also uses your data for targeted advertising. Apple is also not selling your data.11 Like Google, Apple has a broad range of products at its disposal to collect your data and show you targeted ads.
Meta is also an advertising company, making $200,966 million in USD in 2025.12 However, Meta makes use of social media platforms to collect data and this changes the way that it is used. Like Google and Apple, Meta's privacy policy indicates that our data is used for targeted advertising.13 However, unlike Google and Apple, you explicitly provide your thoughts and feelings to Meta in the form of social media posts, and these are not only being used to provide targeted advertising. Meta uses information that you share on Facebook, Instagram and WhatsApp to train AI, including your posts and photos.14
When writing the above paragraphs, I tried to stay true to what each company specifies in their privacy policy so as to avoid mixing opinion with stated fact. The overarching theme of each privacy policy is that our data is taken and used for targeted (or if you prefer, personalised) advertising. This may seem like a benign concept, after all the average person can't go outside without seeing some form of advertising billboard or banner. However, targeted advertising is customised for the individual and is updated in real time. This can make targeted advertising a lot more manipulative than street advertising.
In 2025, Meta whistle blower and former director of Global Public Policy for Facebook, Sarah Wynn-Williams (author of Careless People) told US senators on the subcommittee for crime and terrorism that "Facebook had targeted 13 to 17 year olds with ads when they were feeling down or depressed". Wynn-Williams continued: "Advertisers understand that when people don’t feel good about themselves, it’s often a good time to pitch a product — people are more likely to buy something."15
Due to how large and complex Big Tech companies are, we have to assume a degree of trust when using the many convenient and sometimes mandatory services that they provide. This creates a 'black box' between us providing our data and then receiving the service where it isn't clear how our data is processed. With billions of users having their data processed by machine algorithms, controlled by companies that rely on generating a profit, how can we be sure that what we are receiving is within our best interests?
"Meta uses information that you share on Facebook, Instagram and WhatsApp to train AI, including your posts and photos."
Why should I care?
There are many reasons why you should care about your online privacy, even if you have nothing to hide, for the same reason that we have curtains in our house. If someone were to remove your curtains, your behaviour would be fundamentally different than if you were hidden. It wouldn't be acceptable for passing strangers to watch us through our living room window, so then why do we allow numerous institutions to observe our internet browsing history, watching habits and conversations.
You might argue that these institutions need our data to provide us with services, and in some ways you are correct. However, where do you draw the line between convenience and necessity? Watching films would still be possible without recommendation algorithms, browsing the internet would still be possible without cookies and messaging your friends would still be possible without WhatsApp collecting your metadata.16
There is also the future to consider, because what is normal now might not be so down the track. For now, your data is largely used for commercial purposes, which doesn't seem too dangerous. However, this might not always be the case. Everything you provide online can be used to infer your identity, your political leanings and even your thoughts. We don't have to look far to find examples of civil liberties being abused.
With democracies declining globally17, this vast pool of data could be used to persecute you.
Speaking of inferring your identity, a February 2026 study performed by academics from ETH Zurich University and Anthropic was able to determine that Large Language Models (LLM) can infer who you are, where you live, what you do and your interests from only a handful of anonymous details.1819 Large language models such as Claude and ChatGPT are extremely skilled at identifying patterns and their capabilities continue to improve with each new iteration.
It's not difficult to imagine what could go wrong if this technology was used for nefarious intentions.
Algorithms can also do more than infer who you are, they can shape your thoughts. Susie Alegre, a leading human rights barrister, writes in her 2022 book Freedom to Think:
"While we may be happy to let people know that we liked a post about Salvador Dali and another about kittens, we may not be so comfortable with the fact that this information will be analysed to reveal psychological traits or fleeting states of mind that will, in turn, be used to manipulate our behaviour or to tell others how they should treat us."
Alegre continues:
"The interpretation of our online activity is not restricted to conscious and public expressions we make online. It is not only what we say we like through hitting the 'like' button that is recorded, but also what we look at but don't choose to like, how long we linger over particular content and the conversations we have around our mobile devices."20
Alegre was referring to the use of algorithms by Facebook to customise our social media feeds according to our mood or preferences on any given day, but this line of thinking could also be extended to targeted advertising or recommendation systems.
This all sounds rather alarming, and I think it's reasonable to be alarmed, but this doesn't mean that things have to get worse. Although, if the potential for the worst to happen exists, then why would you not take precautions. Returning to my house analogy, you wouldn't wait for your house to be burgled before installing locks, so why would you wait for your data to be misused before taking action?
What can I do?
There is plenty you can do, and a lot of these actions are at no (or little) financial cost to you. However, there will be a cost in terms of time, effort and willingness to change. Many of the services that we rely on for convenience are funded by our data, and so a commitment to data privacy will rely on letting go of convenience.
With that said, the first thing you can do is to change your attitude towards data privacy. This will probably be the hardest task to achieve, as it requires undoing years of habits and assumptions that free up our mental bandwidth. Personally, it took me over a year to go from having very little awareness to being able to write an article on the matter, so don't expect overnight progress. If you have made it this far into this article, then it seems like you have taken the first steps towards achieving this.
If you are dedicated to the idea of change, then I would recommend learning as much as you can about data privacy and how it impacts the individual apps and services that you use. Do not use AI to accelerate this. Search online and read long form articles, watch videos and listen to podcasts. Go online and discuss your questions with others. Just make sure that you verify the information you are consuming is from a reputable source. Don't take any information at face value, even from me.
If data privacy alone doesn't seem like enough to warrant the dedication, then consider that a data privacy approach to tech will also align well with your digital wellbeing. Big tech companies compete with each other for your attention so that as much data as possible can be extracted from your usage. To be intentional with your data, you need to reduce the amount of screen time you provide these services. In 2026, we now know the damage that can be done to our mental health from excessive screen time. So if you value the mental health gain from reduced screen time, then by that same approach you can also gain from pursuing increased data privacy.
Okay, so you now think you have a good understanding of how data privacy impacts you. Let's start with the easy wins. You have control over some of the more major data under your device settings. Review the permissions that you grant each application and ask yourself whether it makes sense to be providing that information. Does WhatsApp require your location to make calls? No. Does Facebook require access to your contact list for you to scroll? No. Does Google Chrome require use of your microphone to browse the internet? No.
Similarly, another easy win is to think twice before providing your data in the first place. Your data cannot be misused if it was never provided to begin with.
A more difficult adjustment to make will be to move away from big tech services to privacy respecting alternatives. Again, do your research, but there are many alternatives to major services that offer the same if not better quality of service than big tech variations. For instance, ditch Google Chrome for Brave Browser, Microsoft Office for LibreOffice or Gmail for Proton Mail. These three examples are all free and are open source. Open source means that the code is available publicly for everybody to review, so you know that claims of privacy can be substantiated.
Not all alternatives are free. As mentioned earlier, you need to consider a company's business model and how they fund their operations. Generally speaking, if you are receiving a service for free then you may be paying with your data. So if you want privacy from your services, then you may have to pay. Be sure to understand how a service is funded before committing your data.
Finally, if you want a culture of data privacy to continue into the future, then you need to spread the word. Talk about it with your friends and family. Post about it online. Question the views of others. Set an example to follow by making hard changes towards privacy over convenience. Important issues become difficult to ignore if the people around you share concerns. If everyone contributes, then over time data privacy becomes the norm rather than an afterthought.
Sources
Kosinski, M. Forrest, A. (ND) What is data privacy? ibm.com. https://www.ibm.com/think/topics/data-privacy↩
Australian Bureau of Statistics. (ND). Data. abs.gov.au. https://www.abs.gov.au/statistics/understanding-statistics/statistical-terms-and-concepts/data↩
Google. (2026, May 26). Privacy Policy. google.com. https://policies.google.com/privacy?hl=en-US#infocollect↩
Google. (2026, May 26). Privacy Policy. google.com. https://policies.google.com/privacy?hl=en-US#footnote-activity-on-third-party↩
Digital Applied Team. (2026, April 7). Google Analytics Statistics 2026: GA4 Adoption Data. digitalapplied.com. https://www.digitalapplied.com/blog/google-analytics-statistics-2026-ga4-adoption↩
Google. (2026, February 27). Fitbit Privacy Policy. https://support.google.com/product-documentation/answer/14815921#anchor1↩
Thuy, D. (2026, July 6). Annual revenue of Alphabet from 2017 to 2024, by segment. statista.com. https://www.statista.com/statistics/633651/alphabet-annual-global-revenue-by-segment/↩
Poole-Sidell, E. (2020, December 18). What Does Google Do With Your Data? avast.com. https://www.avast.com/c-how-google-uses-your-data↩
Google. (ND). How our business works. google.com. https://about.google/company-info/how-our-business-works/↩
Couts, A. (2025). How Google Makes Billions Off You. WIRED. https://www.youtube.com/watch?v=rtoRk6QS3i4↩
Apple. (2025, July 30). Apple Privacy Policy. apple.com. https://www.apple.com/legal/privacy/en-ww/↩
United States Securities and Exchange Commission. (2026, January 28). Form 10-K. sec.gov. https://www.sec.gov/ix?doc=/Archives/edgar/data/1326801/000162828026003942/meta-20251231.htm#fact-identifier-204↩
Facebook. (2025, December 16). What is the Privacy Policy and what does it cover? facebook.com. https://www.facebook.com/privacy/policy/↩
Facebook. (ND). How Meta uses information for generative AI models and features. facebook.com. https://www.facebook.com/privacy/genai↩
Perez, S. (2025, April 9). Meta whistleblower Sarah Wynn-Williams says company targeted ads at teens based on their ‘emotional state’. techcrunch.com. https://techcrunch.com/2025/04/09/meta-whistleblower-sarah-wynn-williams-says-company-targeted-ads-at-teens-based-on-their-emotional-state/↩
Dawson, S. (2025, October 31). WhatsApp Privacy Review. mozillafoundation.org. https://www.mozillafoundation.org/en/nothing-personal/whatsapp-privacy-review/↩
Gorokhovskaia, Y. Grothe, C. Slipowitz, A. (2026, March). The Growing Shadow of Autocracy. freedomhouse.org. https://freedomhouse.org/report/freedom-world/2026/growing-shadow-autocracy↩
Lerman, S. Paleka, D. (2026, February 25). Large-Scale Online Deanonymization with LLMs. lesswrong.com. https://www.lesswrong.com/posts/xwCWyy8RvAKsSoBRF/large-scale-online-deanonymization-with-llms↩
Lerman, S. Paleka, D. Swanson, J. Aerni, M. Carlini, N. Tramer, F. (2026, February 25). Large-Scale Online Deanonymization with LLMs. arxiv.org. https://arxiv.org/abs/2602.16800↩
Alegre, S. (2022). Facebook Knows You Better - Page 150. Freedom to Think.↩