Cyber Privacy: Who Has Your Data and Why You Should Care

BenBella Books · 2020 · 320 pages
ISBN: 9781948836951
Review Editor Lena Park

April Falcon Doss spent years as a senior intelligence lawyer at the National Security Agency before moving to private practice as a cybersecurity attorney. Cyber Privacy: Who Has Your Data and Why You Should Care, published by BenBella Books in October 2020, draws on that experience to produce something genuinely useful: a clear-eyed, comprehensive account of the data collection ecosystem aimed at readers who want to understand what is actually happening to their personal information, not just worry about it in the abstract.

The book’s central claim is straightforward: the amount of data being collected about ordinary people by both corporations and governments is far larger, more detailed, and more interconnected than most people understand, the uses to which that data is put are largely invisible to the people being monitored, and the legal frameworks ostensibly protecting privacy are decades out of date and full of gaps that have been deliberately maintained by the industries profiting from the collection. Doss makes this argument systematically and with specific evidence, drawing on her experience on both sides of the surveillance question: as someone who worked within government intelligence programs and as someone who now advises companies on how to navigate privacy law.

The book covers three main areas of data collection: commercial data collected by technology companies and data brokers, government surveillance authorized by law, and the intersection of the two, which turns out to be where the most significant privacy risks actually live. Each area gets a thorough treatment, with specific examples, legal citations, and explanations of how the technical and legal systems enable collection that most people would find surprising if they knew about it.

The Expert’s Lens

What distinguishes this book from the many other privacy guides published in the wake of the Cambridge Analytica scandal is Doss’s combination of legal and intelligence expertise. She understands both how the surveillance systems work technically and how they are authorized legally, which allows her to explain why the gaps in privacy protection exist: not as oversights but as deliberate choices made by legislators, regulators, and courts that benefited specific interests. The chapter on third-party doctrine, the legal principle that you lose privacy rights in information you share with a third party, is particularly valuable for explaining why the American legal system provides so little protection for data held by companies rather than by the government.

Doss is also able to describe how government data collection programs operate in ways that are more specific than most journalists can manage, because she has worked within those programs. She is careful about what she can and cannot say, and she does not claim insider knowledge she does not have, but her descriptions of how intelligence agencies think about data collection and data minimization are more concrete than most public writing on the subject. The chapter on how government agencies access commercial data, sometimes without a warrant by exploiting the same third-party doctrine loopholes that protect commercial collection, is one of the most illuminating in the book.

The treatment of data brokers is the section that will likely surprise general readers most. Doss explains in detail how companies that most people have never heard of, businesses that buy and aggregate data from dozens of sources, maintain detailed profiles on most American adults that include location history, purchase history, social connections, health and financial inferences, and behavioral predictions. These profiles are sold to advertisers, employers, landlords, insurers, and sometimes government agencies. The legal framework governing these companies is minimal. The data they hold can be used for decisions that significantly affect people’s lives, and the people being profiled have no effective right to see or correct the information about them.

Pacing

The book is methodical rather than propulsive. Doss builds her argument systematically, covering each sector of the data economy in sequence before addressing policy implications and individual responses. For readers who want comprehensive coverage, this structure is exactly right. For readers who already know some of this material and want to get to the parts they don’t know, the chapter structure is clear enough that you can navigate to the relevant sections without much difficulty.

The legal chapters are the densest, and readers without a law background may need to slow down for those sections. Doss explains the legal concepts clearly but does not oversimplify them, which means some passages require careful reading. The effort is rewarded: understanding why the law works the way it does is more useful than a simplified summary, because it explains the difference between what privacy law promises and what it actually delivers. The chapters on practical steps individuals can take are more accessible and arguably the most actionable part of the book, though Doss is appropriately honest that individual action can only accomplish so much against systems designed at the institutional level.

Deeper Thematic Exploration

The book’s deeper argument is about power: specifically, about the asymmetry between individuals and the institutions, both corporate and governmental, that collect data about them. Doss frames privacy not as a preference but as a structural condition that enables other rights: the ability to organize politically, to seek legal counsel, to maintain intimate relationships, to make mistakes without permanent record, and to exercise judgment without being predicted. She draws on work by legal scholars who argue that privacy is a prerequisite for autonomy rather than an optional amenity, and the book is persuasive about why that argument matters practically rather than just philosophically.

The book also makes a careful distinction between surveillance that serves public interests and surveillance that serves private or institutional interests at the expense of the surveilled. Doss does not argue that all data collection is illegitimate. She argues that legitimate collection requires meaningful consent, limits on use, and accountability mechanisms, and that the current system provides almost none of these things. The distinction matters because it allows her to propose specific reforms rather than a wholesale rejection of data collection, which is a more realistic political program than the alternatives.

The international comparisons are among the book’s most useful sections. Doss describes the European GDPR framework, the differences between American and European approaches to privacy as a legal right, and the ways that international data flows create conflicts between different legal regimes. For readers who want to understand why privacy advocates in the United States so often point to European law as a model, these sections provide the necessary context. The comparison is not simply flattering to Europe: Doss notes the limitations of the GDPR as well and the ways that its implementation has fallen short of its intent in some areas.

Style and Voice

Doss writes like a lawyer, which is both a strength and a limitation. She is precise, careful, and well-organized. She qualifies her claims accurately and cites her sources clearly. She does not sensationalize: the book is more alarming for being understated than it would be if Doss had written it as a thriller. The limitation of the legal style is that it sometimes sacrifices momentum for completeness: there are passages where the book covers ground thoroughly that could be covered more quickly without losing the essential point.

The voice is authoritative without being dry. Doss is clearly engaged by her subject and occasionally allows her frustration with the state of privacy law to come through in her prose, which makes the book more human than a purely neutral policy analysis would be. She is also honest about the limits of her knowledge and about the ways that the landscape has changed since publication in 2020: she writes in the introduction that specific details will date but that the fundamental structural problems she describes are unlikely to be solved quickly, and the subsequent years have largely confirmed that prediction.

Verdict

This is the best comprehensive overview of the data privacy landscape available for general readers who want substance rather than slogans. It will not teach you every technical detail of how tracking works, and it is not a hands-on guide to securing your devices. What it will do is give you a clear, accurate understanding of what data is being collected about you, by whom, under what legal authorities, and for what purposes, and what the realistic options for changing that situation are at both the individual and policy level. For anyone who has felt vaguely troubled by the state of digital privacy but has not known where to get a reliable account of what is actually happening, this is the book to read.

The book is particularly valuable for readers who occupy roles where they make decisions about data: managers, product developers, policymakers, lawyers, and journalists. For those readers, the legal and policy analysis is directly applicable to their work, and Doss’s combination of insider knowledge and analytical clarity is hard to find elsewhere. General readers who simply want to be better informed citizens about one of the defining policy questions of the current era will find it thorough and accessible, if sometimes sobering.

Frequently Asked Questions about Cyber Privacy by April Falcon Doss

What is Cyber Privacy: Who Has Your Data and Why You Should Care about?

The book is a comprehensive guide to the data collection ecosystem, covering what personal data is collected about ordinary people, who collects it, under what legal authorities, and for what purposes. Author April Falcon Doss, a former NSA intelligence lawyer turned privacy attorney, covers commercial data collection by technology companies and data brokers, government surveillance programs, and the intersection of the two. The book also covers the legal framework governing data collection, why that framework provides limited protection, and what realistic reforms might look like.

Is Cyber Privacy by April Falcon Doss technically difficult to read?

The book is written for a general audience and does not require technical expertise. Doss explains technical concepts clearly when they are necessary to understanding a legal or policy point, but the focus throughout is on the legal and institutional structures that enable data collection rather than on the engineering of surveillance systems. The legal sections require careful reading but are accessible to non-lawyers. Readers with a background in technology or law will move through some sections quickly, but no specialized knowledge is required to engage with the core argument.

What is the most surprising thing people learn from Cyber Privacy?

Most readers are surprised by the section on data brokers: companies that buy and aggregate data from dozens of sources to build detailed profiles on individuals, including location history, behavioral predictions, health and financial inferences, and social network mapping. These companies operate largely outside public awareness and with minimal legal oversight. Their profiles can be used to make decisions about employment, credit, insurance, and housing, and the individuals being profiled generally have no right to see or challenge the information about them.

How does the US compare to other countries on data privacy according to Cyber Privacy?

Doss describes the European GDPR as providing significantly stronger individual rights than American law: explicit consent requirements, rights to access and delete personal data, and meaningful enforcement mechanisms. She notes that the US approach treats privacy primarily as a commercial matter governed by sector-specific regulations (medical data under HIPAA, financial data under the Gramm-Leach-Bliley Act, etc.) rather than as a fundamental right. This creates large gaps where data not covered by a specific sector law has almost no legal protection. Doss is not simply flattering Europe: she notes limitations in GDPR implementation, but the structural comparison is unfavorable to American law.

What practical steps does Cyber Privacy recommend for protecting your data?

Doss discusses individual steps including using encrypted messaging apps, enabling privacy settings on devices and accounts, being cautious about permissions granted to apps, and opting out of data broker profiles where possible. She is honest that individual action has significant limits: many of the data collection systems she describes operate without individual awareness or meaningful consent, and opting out of one system does not protect against the dozens of others. Her primary argument is that structural reform at the legal and policy level is necessary for meaningful privacy protection, and that informed citizens pressing for that reform are more important than individual technical countermeasures.

Has anything changed since Cyber Privacy was published in 2020?

The specific details of some programs and companies Doss describes have evolved since 2020. The broader legal landscape has seen some state-level action, including the California Consumer Privacy Act and similar laws in other states, but the federal legal framework has not changed fundamentally. The structural problems Doss identifies, the gaps in legal protection, the dominance of third-party doctrine, and the absence of comprehensive federal privacy legislation, remain largely in place. The book’s analysis of why those problems exist and why they are difficult to solve remains accurate.

Is Cyber Privacy relevant for someone who works in technology or law?

Yes, particularly for technology professionals who build products that collect user data, lawyers who advise companies or individuals on privacy matters, and policymakers working on technology regulation. Doss’s legal analysis is more thorough than most popular treatments of the subject, and her insider knowledge of government intelligence programs adds a dimension that most privacy guides lack. The book is not a compliance manual and is not aimed at specialists, but it provides a foundation for understanding the full landscape that is more useful than reading only the technical or only the legal literature.

Should I read Cyber Privacy even if I think I have nothing to hide?

Yes. One of the book’s core arguments is that the “nothing to hide” framing misunderstands what privacy is for. Doss explains that privacy is not primarily about concealing wrongdoing: it is about maintaining the structural conditions that allow political organization, intimate relationships, experimentation, and autonomy. Data collection at scale enables targeting, manipulation, and control in ways that affect everyone, including people who behave entirely within the law. The book makes this argument specifically and with evidence rather than appealing to abstract principles, which makes it more persuasive than the usual responses to the nothing-to-hide argument.

Book Details

Title
Cyber Privacy: Who Has Your Data and Why You Should Care
Publisher
BenBella Books
Year Published
2020
Pages
320
ISBN
9781948836951
WritersReview Rating
4.0 / 5