Why privacy matters even when you have nothing to hide: An interview with Thorin Klosowski

Online privacy is often sold as a personal choice — change your settings, reject cookies, and use stronger passwords. Those habits matter, but they can’t prevent every privacy risk. Governments are pushing for access to encrypted messages. Data brokers trade location history, purchase records, and health-related browsing data. AI tools are being integrated into chats, devices, and workplace apps, where they can process highly personal information. Your choices still count, but laws, business models, and product decisions also shape how much privacy you have.

An interview with Thorin Klosowski

Thorin Klosowski is a senior security and privacy activist at the Electronic Frontier Foundation (EFF) opens in a new tab, a nonprofit founded in 1990 to defend civil liberties online. EFF works on privacy, free expression, and innovation through litigation, policy work, public campaigns, and technology development. Thorin contributes to EFF’s Surveillance Self-Defense project and focuses on consumer privacy, encryption, and digital rights.

In this interview, Thorin explains why many of today’s digital rights debates look similar to the fights EFF took on in the 1990s — and why encryption, anonymity, and privacy protections still matter for everyone.

The same fight, but with more data at risk

The rights people fight for offline are the same ones EFF fights for online.

“A lot of the civil liberties and civil rights stuff that we might think of in the real world, we fight for those in the digital landscape. So that comes down to privacy, security, general civil rights, free speech — a lot of the same things [people have] thought about for the last many decades,” says Thorin.

The technology keeps changing, but the questions stay the same — who can read your messages, who can limit your speech, and who controls your data. EFF has worked on issues dealing with encryption, online speech, government overreach, and corporate control for years.

“When we look back at our history, a lot of the fights we were having in the ’90s are the same fights we’re having today. The language has changed, and what we are specifically talking about has changed,” says Thorin.

The tools have also changed, and far more personal data now moves through them. But Thorin says the core problems are familiar — governments still want access to encrypted communication, and companies still try to narrow what privacy protections mean.

“A lot of governments are currently trying to attack encryption. A lot of corporations are trying to whittle down or change what they are defining as encryption. Our privacy is suffering because of that,” says Thorin.

The pressure comes from more directions than it used to, and far more data is at stake. But Thorin sees the underlying conflict as unchanged. “I think technology has changed a lot. It’s accelerated. There is more personal data being shared more widely, but fundamentally, the fight is the same.”

Encryption isn’t only for high-risk users

Encryption protects data by making it unreadable to people who don’t have the right key. For many people, encryption is most important in the places they use every day —private messages, personal files, photos, notes, backups, and cloud storage.

Thorin says encryption has become harder to separate from daily life because so much personal data now syncs across apps and devices.

“[Encryption is] a way to help keep our conversations private. I think that’s more evident now than ever. A lot of what we store online is now defaulting to syncing to the cloud in some way,” says Thorin.

Many people still think of private data as files stored on their own devices. In reality, notes, journals, photos, and backups often move between apps, cloud services, and connected devices.

“A lot of the data we create and store — notes, journals, photos, all of that stuff we have always thought of as private — is now online. A lot of people don’t understand how that is working, how it’s being stored, or why.”

Because so much personal data is stored online, encryption matters in everyday life for everyone. “That shows how important encryption can be, because it’s information we have always thought of as private,” says Thorin.

The problem with “nothing to hide”

Privacy debates often get reduced to one tired argument: “If you have nothing to hide, you have nothing to worry about.” Thorin rejects this common cybersecurity myth because privacy risks change throughout a person’s life.

“I think people forget that everything we do online is tracked. Everyone is going to have different risk factors at some point in their life, depending on where they live, which countries they live in, and what governments might be leading those countries. Those risks are going to change over time.”

Data outlives the rules it was created under. A search or location record that raises no concerns today can put you at risk if laws change, a new government takes power, or the data ends up with someone you never shared it with.

“Our digital trail can be forever, or at least for a very long time. At some point, we will all have something that we want to keep private. We don’t want to share it through a data breach, with law enforcement or a government, or with a corporation that shares and uses that information against us in ways that are surprising or new.”

For Thorin, privacy is about control over information you don’t want exposed, misused, or kept forever. “I think ‘something to hide’ is not the right framing. It’s more that we all have something we want to keep private,” he says.

How commercial data can become government surveillance

Privacy debates usually treat government surveillance and corporate data collection as separate problems. Thorin says they overlap in ways many people don’t see

“The simplest example in the US is that the government can actually buy a lot of that information from the corporations that are collecting it. We are fighting against that.”

Data brokers collect, package, and sell personal information. When government agencies buy that data, surveillance can happen without a warrant, a subpoena, or a direct request to the company that first collected the data.

“It is a battle happening on a lot of different fronts. I don’t think people are really aware of it, because it happens in the background without a lot of obvious signals. It’s difficult to keep track of how many levels it’s happening at and what’s happening.”

The problem affects many people at once. Government agencies usually buy large data sets, which can expose patterns, communities, locations, habits, and relationships.

“It’s not like the government is going in and buying one person’s data. That’s not necessarily how it works. [The data gets collected] all at once. So it affects everybody in different ways and can change over time.”


Age verification is becoming a privacy fight

Alongside encryption, Thorin points to a second major fight — age verification.

“I think there are two big [issues] this year. The battle for encryption is happening on a worldwide scale right now. Tied into that is also the fight around age verification — or the fight against age verification — and keeping our personal identities ours and anonymous.”

Age verification systems usually require people to prove their age before they can access certain websites, services, or content. Depending on the system, that may mean uploading an ID, submitting a face scan, using a third-party verification service, or linking an account to another identity check. The process can create privacy risks because it may connect identity checks to everyday browsing and platform use.

The concern goes beyond one country or platform. When one government adopts a rule, global tech companies may apply the same standard everywhere because it’s easier than building different systems for each market.

“A lot of the way tech companies work is that if something happens in one country, they’re just going to implement it worldwide. It’s very, very rare that we don’t see that [happen].”

Thorin points to Apple withdrawing Advanced Data Protection in the UK as a rare example of a company confining an encryption decision to one market. In 2025, Apple stopped offering Advanced Data Protection in the UK after the Home Office reportedly sought access to encrypted iCloud data. Apple limited the change to the UK instead of weakening the feature globally.1,2

Thorin warns that age verification rules can spread quickly if governments and platforms treat them as the default. He expects them to follow the same pattern. “I think age verification is another one that’s piecemeal right now, but I think that’s a snowball rolling down a hill. It seems small now, and it’s only happening in singular states or certain countries, but it will happen everywhere if we don’t stop it now,” he says.

AI tools can make private data harder to control

Thorin believes that system-wide artificial intelligence (AI) tools like Siri or Gemini can create new risks because they may access content across apps or devices. If an AI assistant can read, process, summarize, or store sensitive information, people may share private content without realizing where that data goes.

“With AI specifically, we are really looking at and thinking through how those systems are interacting with encrypted content, especially encrypted chat apps.”

Tracking where data goes becomes harder when AI tools process data in the cloud instead of only on the user’s device. In those cases, private information may leave the device, and users may not know how it’s stored, reviewed, or used later.

“I think there’s a really high likelihood of people accidentally sharing information that they do not intend to. That’s been on our minds a lot. AI systems are often cloud-based and not on-device, so in most cases, what you do in them is going somewhere. Tracking that and understanding it is very, very difficult.”

No safe backdoor exists

Governments often argue that fighting crime requires access to encrypted messages. EFF believes that weakening encryption makes everyone less safe.

An encryption backdoor is a built-in way to bypass security. Once it has been created, anyone can look for it, including attackers and hostile governments.

“There are several things going on there, but the main thing is that there is no magical single backdoor that only good guys can access. There is always going to be someone out there looking for this information who is going to find a way to get it.”

Thorin also argues that law enforcement already has ways to access evidence through legal processes, including warrants and subpoenas.

“It’s useful to remember that law enforcement already has a lot of tools. They already have a lot of ways to access these sorts of things. With encrypted chat specifically, the device itself matters. We’ve seen it time and time again where law enforcement is able to access a device and get what they need off of it with valid warrants and subpoenas — the hurdles that they’re supposed to go through.”

Thorin thinks that weakening encryption would make more people’s data easier to access, whether or not they are suspected of a crime. “I think that this is clearly a way to grant access to more information on everyone, regardless of what they’re doing,” he says.

Practical privacy starts with the basics

For people who want to improve their privacy and security, Thorin recommends starting with tools that protect the accounts they use every day.

“I think it really depends on where you are starting from. To this day, a lot of it is still walking people through password managers, two-factor authentication, and all of that.”

Password managers help people create and store strong, unique passwords. Two-factor authentication adds a second login step, such as an app code or security key, so a stolen password is less useful to an attacker.

Thorin also recommends one quick phone step — delete or reset your advertising ID on an Android device or an iPhone. Advertisers use it to link your activity across apps, so resetting it breaks that trail.

How technology companies can help

Thorin says technology companies should listen to civil society groups before making product decisions that create privacy or security risks. 

“I think [companies should take] us seriously, meet with the people who are on the ground and dealing with [these issues] day to day, and actually take those risks into consideration when designing products.”

Support from individuals matters, too. “We are a member-supported nonprofit, which means that most of our donations — basically everything that we do — is because of people who donate money to us. That’s what keeps us running day to day,” Thorin says.


NORDVPN’S INITIATIVE

NordVPN offers eligible organizations free or discounted VPN subscriptions. Nonprofits, journalists, human rights advocates, and educators can apply to join the program to securely access information, protect communication, and work without fear of surveillance. Let NordVPN help your organization stay safer online and focused on its mission. Apply for the NordVPN Nonprofits program.

Getting involved starts with people

Thorin says people who want to support digital rights should start by meeting the people already doing the work.

“Go to the meetups that different nonprofits run. Go to conferences. Talk to people. Speaking for us, we love meeting our members. We love meeting people who are interested in what EFF does.”

Digital rights can seem technical or abstract, but Thorin describes the work as deeply human — meeting people, explaining the issues, learning from those conversations, and building support around shared concerns.


Shaping a better world one step at a time. Together.

Apply for the NordVPN Nonprofits program

Disclaimer: The trademarks referenced are for illustrative purposes only. NordVPN is not affiliated with, sponsored by, or endorsed by the owners of those trademarks.

References

1 Hall, R. (2025, February 21). Apple removes advanced data protection tool in face of UK government request. The Guardian. https://www.theguardian.com/technology/2025/feb/21/apple-removes-advanced-data-protection-tool-uk-government opens in a new tab 

2 Apple. (2025, September 22). Apple can no longer offer Advanced Data Protection in the United Kingdom to new users. Apple Support. https://support.apple.com/en-us/122234 opens in a new tab

Violeta Lyskoit | NordVPN

Violeta Lyskoit

Violeta is a copywriter who is keen on showing readers how to navigate the web safely, making sure their digital footprint stays private.