“I have nothing to hide” — why privacy is about security, not secrets

Most people don't think about online privacy until something goes wrong. A friend gets a loan taken out in their name. A colleague's old photos end up somewhere they shouldn't be. That's the pattern: privacy feels like a problem for other people, right up until it's your problem. And by then, your options have narrowed. Your data is already out there, copied or sold more times than anyone can count.

“I have nothing to hide” — why privacy still matters

Why are people indifferent to their online privacy?

Most people don’t see online privacy as a big concern, for several reasons. Part of the problem is that it’s nearly invisible. If a stranger opened your mailbox and read your letters, you’d react immediately. But data collection leaves no visible trace. There’s no sound and no broken lock. It just quietly runs in the background of every site you visit and every app you open. And because nothing has visibly gone wrong, it doesn’t feel like anything happened at all.

But that invisibility has a cost. Research on privacy attitudes keeps finding the same pattern: people become concerned about their privacy only after something happens. They care when their data is already out of their hands, when it leaks or their bank account is breached. And by then, it’s already too late.

And then there’s the most comfortable belief of all: “I’m not interesting enough to target.” It assumes surveillance works like a detective — someone picking suspects and watching wrongdoers. Surveillance doesn’t work that way. Everyone’s data is collected automatically, in bulk, sorted by machines that don’t care how boring someone is. To them, everyone is just a data point, and all data points have value.

What is the “nothing to hide” argument?

When someone says “I have nothing to hide,” they usually mean that privacy is only for people with secrets. The argument “if you have nothing to hide, you have nothing to fear” is not a new idea. In fact, it is much older than the internet. A version of it appeared in a story by Henry James in 1888. In 1917, Upton Sinclair, a writer, noted that a government official used the exact phrase to brush off concerns about spying. Years later, the UK government even used it as an official slogan to get the public to accept CCTV cameras on city streets.

Today, this old excuse is used to wave away modern privacy problems. Online, we are tracked all the time — every click, search, and scroll adds to our digital footprint. Companies and other entities constantly monitor what we read, what websites we visit, and what we search for on the internet. And the “nothing to hide” argument is still used today to make this constant watching feel normal, tricking people into giving up their right to privacy.

Why is the “I have nothing to hide” position dangerous?

This argument doesn’t sound dangerous at first — it sounds reasonable. But “nothing to hide” treats privacy as a mask — as if you only need it when there’s wrongdoing underneath. 

But privacy isn’t secrecy. You close the bathroom door without doing anything shameful there. You don’t publish your salary or your medical records, not because they’re evidence of a crime, but because they’re yours. Controlling who sees what is a normal part of being a person, not an admission of guilt. 

Unfortunately, today you get less and less control over how your personal data is used. Even if you are careful and say, “I don’t share much,” your data is still exposed. Your personal details are leaked through hacks at companies, gathered by invisible data brokers, and even shared by friends who upload their contact lists to new apps. Your personal choices have a limited impact on how much of your life is actually out there.

To make matters worse, information that seems totally harmless today might not be harmless tomorrow. The problem is that data never expires, but your life circumstances do. Laws change, governments shift, and personal situations change. Information that is collected and stored about you right now could easily be taken out of context or used against you years down the line. Because you cannot predict the future, treating your data casually today creates risks for tomorrow.

When do people start caring about their online privacy?

Most people only start prioritizing their data privacy when they are personally affected — which is usually when it is already too late. Abstract warnings rarely inspire action, but a hacked account, identity theft, or realizing exactly what personal data is at risk makes the danger instantly real. Until that moment of shock, the majority of internet users remain dangerously passive.

This reactive mindset is clearly reflected in the National Privacy Test — a global survey that lets people around the world measure their cybersecurity and digital privacy awareness. It shows that while people know basic password rules and recognize malware, they ignore less visible threats. For example, the 2025 results revealed that only 15% of US participants understood what data their internet service providers collect. Because this tracking happens quietly in the background, it is easily ignored.

However, when these hidden threats are exposed, the reaction is dramatic. During our recent “Ask a Hacker” campaign, everyday people were shocked as ethical hackers easily uncovered their passwords, home addresses, and phone numbers using only public data. Our survey showed the same false sense of security. An alarming 73% of Americans mistakenly believe that simple antivirus software is enough to protect them against identity theft. It often takes seeing their own exposed data before people finally take action.

What personal information is usually at risk? 

When our online activity is exposed, the data at stake goes far beyond just browsing history.

Your personally identifiable information

When a data breach happens and personal data is leaked, it usually falls into three risk categories:

  • Contact details: email addresses and phone numbers. Hackers use these to launch convincing, targeted phishing scams.
  • Account credentials: usernames and passwords. Because people often reuse passwords, a minor breach on one site can give criminals the key to your most important accounts.
  • Sensitive identifiers: Social Security numbers, credit card details, and ID scans. This data can be sold on the dark web, allowing criminals to steal your identity, open fraudulent loans, or drain your finances.

Financial details

Financial gain motivates most cybercriminals, which makes your credit card numbers, bank details, and crypto wallets prime targets. Unlike other personal data, financial information can be monetized instantly. Criminals steal this data by running phishing scams, breaking into accounts using reused passwords, or buying leaked information on the dark web. Once they have access, they can immediately drain your accounts or take out fraudulent loans before you even realize a breach has occurred.

Physical safety and whereabouts

Perhaps the clearest proof that privacy isn’t just about faceless corporations or government surveillance is that the most dangerous threats often come from someone the victim already knows. In many real-world cases, privacy harms involve an ex-partner, an acquaintance, or even a stalker weaponizing everyday technology. This can look like tracking a person’s daily movements through shared location history, secretly installing stalkerware on their phone to read private messages, or maliciously exposing their physical address online. 

Reputation and the people around you

When personal details are exposed online, the resulting harm can go far beyond data theft. Victims face targeted doxxing, online harassment, and having their private information intentionally taken out of context to inflict maximum damage. This exposure rarely stays contained to the original victim. It quickly spreads to their family members, friends, and colleagues who never made any choice to be involved. Through shared association and public records, innocent bystanders end up collateral damage, facing harassment and privacy violations simply for being connected to the victim.

How to protect your online privacy

Even if you’ve always operated under the “nothing to hide, nothing to fear” mindset, it’s never too late to start being safer online. Here are a few online safety tips to protect your data:

  • Find out what is already exposed. Use breach-checking or dark web monitoring tools to see if your email, passwords, or personal details have leaked. For example, NordVPN’s free data leak checker lets you instantly see whether your email address has appeared in a known data breach. If an account is compromised, you can immediately change your password and lock hackers out.
  • Reduce what’s already out there. Be proactive in removing your information from the internet. Opt out of major data brokers that sell your location and phone number, request that search engines remove your personal details, and delete old accounts you no longer use. 
  • Cut off passive collection at the source. Limit what you share by revoking unnecessary app permissions. Use privacy-focused browsers or extensions that block third-party trackers and reduce browser fingerprinting.
  • Encrypt your connection with a VPN. Using a reliable VPN service hides your online traffic and IP address, preventing internet service providers, network snoops, and hackers from monitoring the websites you visit or intercepting your online traffic.
  • Secure your important accounts. Use a password manager to generate unique, complex passwords for every site. Pair those with multi-factor authentication (MFA), preferably via an authenticator app, to add a critical line of defense that stops unauthorized logins even if someone steals your password.

Online security starts with a click.

Stay safe with the world’s leading VPN