Owning Your Digital Life: The Great Hack
A reflection on the internet's promise, the price of "free," and what it means to be an informed digital citizen today.
1. The Digital Age: A World Built on Connection
When social media first entered our lives, it arrived with a promise that felt almost utopian. Facebook's stated mission was simple and appealing: to give people the power to build community and bring the world closer together. The pitch behind nearly every major platform that followed Instagram, YouTube, Twitter, WhatsApp echoed the same idea. Connect people. Break down borders. Democratize information. Give a voice to anyone with an internet connection.
For a while, this promise felt true. A student in Bhavnagar could watch a lecture from a university in London. A grandmother could video-call her grandchildren on another continent. A small business could reach customers it never could have found through a physical storefront. The internet did, genuinely, shrink the world.
But somewhere between "connecting people" and "keeping people connected," the incentives shifted. Platforms discovered that the longer people stayed, the more valuable they became not to themselves, but to advertisers. Attention became a currency. And to hold attention, platforms needed to know their users intimately: what they liked, feared, believed, and were likely to click next.
This is the quiet transformation at the heart of the digital age. The tools that were built to connect us also became instruments for observing us continuously, invisibly, and at a scale no previous technology allowed. Understanding this shift is the starting point for anyone who wants to use the internet as an informed citizen rather than as a passive subject of it.
2. Every Click Leaves a Trace
Most people are aware, in a vague sense, that "the internet knows things about them." Far fewer understand how much, or how continuously, this happens.
Every interaction online generates data, and that data generally falls into two categories.
Active data is what you deliberately provide: your name, birthday, location, the photos you upload, the posts you write, the products you search for. You choose to hand this over, usually in exchange for using a service.
Passive data is different. It is collected without a deliberate act of disclosure. It includes how long you linger on a video before scrolling past, which ads you hover over without clicking, what time of day you're most active, which contacts you interact with most, and even how quickly you type. None of this requires you to "tell" anyone anything — it is inferred simply from how you behave.
Individually, these data points seem trivial. But when combined often across dozens of apps and websites, stitched together by advertising networks and data brokers they form what researchers call a "digital footprint" so detailed that it can reveal patterns about a person's personality, political leanings, health concerns, and purchasing habits with striking precision.
This is why data has been called the most valuable resource of the 21st century. Unlike oil, it doesn't deplete when used. It multiplies. Every new interaction adds another data point, refining the profile a company holds of you, making future predictions about your behavior more accurate.
This is not inherently sinister. Data helps a streaming service recommend a show you'll likely enjoy, helps a bank detect a fraudulent transaction on your card within seconds, and helps a navigation app reroute you around traffic. The problem isn't that data is collected it's that most people don't know how much is collected, who has access to it, how long it's kept, and what it's used for beyond the service they signed up for.
Digital literacy begins with a simple mental shift: assume that every action you take online is being recorded by someone, somewhere, for some purpose and ask yourself whether you'd be comfortable if that purpose were made visible to you.
3. If the Service Is Free, What Are You Paying With?
There's an old saying in the tech world: if you're not paying for the product, you are the product. It's a slight oversimplification, but it captures something true.
Facebook, Instagram, YouTube, and Google Search cost nothing to use. Yet these are some of the most profitable companies in history. Their revenue comes overwhelmingly from advertising — and advertising is valuable in direct proportion to how well a platform can predict what you'll respond to.
This is the business model known as the "attention economy." Every design choice on a platform the infinite scroll, the autoplay function, the red notification badge, the algorithmically curated feed exists to hold your attention a few seconds longer, because those seconds are the product being sold to advertisers.
Personalization, in this context, isn't a courtesy. It's the engine of the business. The more accurately a platform can model your interests, insecurities, and impulses, the more precisely it can place advertising in front of you, and the more it can charge advertisers for that placement.
This doesn't make personalization inherently exploitative. A recommendation engine that helps you discover new music you love is providing real value. But it does mean that "free" is a misleading word. You are paying not with money, but with attention, behavioral data, and, in aggregate, a measure of your own predictability. Recognizing this trade-off doesn't require you to abandon these platforms. It simply requires honesty about the transaction taking place every time you open the app.
4. The Great Hack: Separating Facts from Myths
Few events crystallized public concern about data and power as sharply as the Cambridge Analytica scandal, documented in Netflix's 2019 film The Great Hack. But the story is often remembered in a simplified, sometimes inaccurate form. It's worth walking through what actually happened.
How the data was obtained. Cambridge Analytica did not "hack" Facebook in the technical sense of breaching its security systems. Instead, a researcher named Aleksandr Kogan built a personality quiz app called "thisisyourdigitallife" and distributed it through Facebook's platform. Around 270,000 people voluntarily installed the app and agreed to share their data for what was presented as academic research. But at the time, Facebook's developer platform also allowed apps to pull data from the friends of anyone who installed them — without those friends' direct consent. Because of this policy, data belonging to an estimated 87 million users was harvested, even though only a fraction of them had ever interacted with the app themselves.
Who was involved. The film centers on several real individuals whose roles are documented in journalism and legal proceedings. Christopher Wylie, a former Cambridge Analytica employee, became a whistleblower who first exposed the scale of the operation to journalists. Brittany Kaiser, a former business development director at the firm, later testified before the UK Parliament and became a vocal advocate for stronger data rights. David Carroll, an American professor, filed a legal case in the UK attempting to force Cambridge Analytica to disclose exactly what data it held on him — a case that became a landmark test of individual data rights, even though Carroll ultimately never received the full disclosure he sought before the company collapsed. Investigative journalist Carole Cadwalladr's reporting for The Observer and The Guardian was instrumental in breaking the story publicly.
What Cambridge Analytica claimed to do with the data. The firm marketed a psychographic profiling system, claiming it could build detailed personality models — reportedly referencing thousands of data points per individual — based partly on the OCEAN personality model (Openness, Conscientiousness, Extraversion, Agreeableness, Neuroticism), a framework with genuine roots in academic psychology. Using this profiling, the company claimed it could identify "persuadable" voters and target them with tailored political messaging across websites, articles, videos, and advertisements.
What is well-documented versus disputed. It is well established that the data harvesting occurred, that it violated Facebook's own platform policies, and that Cambridge Analytica marketed itself using these psychographic claims to political clients, including during the 2016 U.S. presidential election cycle under an operation often referred to in reporting as "Project Alamo." What remains genuinely disputed among researchers is how effective this targeting actually was. Cambridge Analytica's own claims about its predictive power were, according to multiple post-scandal analyses, likely exaggerated a hallmark of a company selling a service to political clients eager to believe in a silver bullet. Several academic reviews found no strong evidence that psychographic microtargeting swayed the 2016 election outcome in any decisive way, noting that far more established factors party identification, economic conditions, television advertising, and get-out-the-vote operations plausibly had greater influence.
This distinction matters. The Great Hack is a documentary, not a courtroom verdict. It combines verified reporting with interviews, editorial framing, and dramatic pacing designed to tell a compelling story. Its core facts about data harvesting are solid. Its implicit suggestion that this data single-handedly determined an election result is a claim the broader evidence does not clearly support. A responsible digital citizen should be able to hold both truths at once: the privacy violation was real and serious, and the narrative of an all-powerful data machine deciding elections is likely overstated.
5. Algorithms, Personalization, and Filtered Reality
Beyond the Cambridge Analytica story lies a subtler, more permanent feature of digital life: the recommendation algorithm.
Every major platform YouTube, Instagram, TikTok, Facebook, even news aggregators uses algorithms to decide what to show you next. These systems are trained on your past behavior: what you watched to the end, what you skipped, what you liked, what you lingered on. Their goal is to maximize engagement, which usually means maximizing the time you spend on the platform.
This creates what researchers describe as a "filter bubble" a personalized information environment shaped entirely around your existing preferences. If you engage more with a particular political viewpoint, the algorithm will likely show you more of it, because that's what keeps you watching. Over time, two people using the same platform can end up living in strikingly different informational worlds, each reinforced in their existing beliefs rather than challenged by opposing ones.
This phenomenon overlaps with, but is distinct from, "echo chambers," a term that describes the social effect of surrounding yourself with people who share your views, amplifying agreement and dampening dissent. Filter bubbles are algorithmic; echo chambers are social. In practice, they reinforce each other.
It would be an overstatement, however, to claim that everyone lives in a completely separate reality with no shared common ground. People still encounter information through family conversations, television, schools, workplaces, newspapers, and offline social interactions that algorithms don't control. The filter bubble effect is real and measurable, but it is not absolute or inescapable.
The practical takeaway isn't to distrust every recommendation you receive. It's to recognize that your feed is not a neutral window onto "what's happening in the world" it is a curated selection optimized for your attention, and occasionally, that curation can narrow rather than broaden your perspective. Deliberately seeking out sources and viewpoints your algorithm wouldn't naturally serve you is one of the simplest acts of resistance available to any digital citizen.
6. Can Data Really Predict Human Behavior?
A recurring claim in discussions about targeted advertising and political microtargeting is that companies can predict and by extension, manipulate human behavior with near-total accuracy. This claim deserves careful scrutiny.
It is true that machine learning models, trained on large datasets, can identify patterns in behavior that are genuinely useful for prediction: what products a person is likely to buy, what content they're likely to watch next, what time of day they're most likely to respond to a message. These predictions can be impressively accurate in aggregate across millions of users, small statistical edges translate into significant advertising revenue.
But predicting the behavior of a population is very different from precisely predicting or controlling the behavior of a specific individual. Human decision-making, especially in something as complex as political choice, is shaped by countless factors an algorithm cannot fully capture personal relationships, lived experience, economic circumstance, cultural identity, and plain unpredictability. Claims that a company possessed a formula to reliably "flip" individual voters based on personality profiling are not well supported by independent research, however persistently they circulate.
This distinction is important because overstating the predictive power of these systems can be almost as misleading as understating the privacy risks they pose. Data profiling is a real and serious concern because it enables scaled, targeted persuasion attempts and because it reveals how much intimate information can be inferred about a person without their explicit knowledge not because it grants companies mind-reading powers over individuals. A digital citizen who understands this nuance is better equipped to evaluate both corporate marketing claims and alarmist media coverage with equal skepticism.
7. Digital Rights Are Human Rights
If data has become this central to modern life, then the rules governing who controls it, who can access it, and who is accountable for its misuse become a matter of basic rights — not just legal fine print.
Several foundational ideas underpin this framing:
The right to know. Individuals should be able to find out what data an organization holds about them and how it is being used.
The right to correct and delete. If data about you is inaccurate, or you simply no longer wish for it to be held, you should have a mechanism to fix or remove it.
The right to portability. You should be able to take your data with you if you switch services, rather than being locked into a platform because leaving means losing your history.
The right to meaningful consent. Consent buried in a fifty-page terms-of-service document that no one reads is, in a practical sense, not meaningful consent at all.
These principles are no longer purely aspirational — they have been written into law in several major jurisdictions.
The General Data Protection Regulation (GDPR), enacted by the European Union in 2018, is widely regarded as the most comprehensive data privacy law in the world. It grants individuals rights to access, correct, delete, and transfer their personal data, and it requires companies to obtain clear consent before processing personal information, with significant financial penalties for violations.
The California Consumer Privacy Act (CCPA), also from 2018 with later amendments, gives California residents rights to know what personal information is collected about them, to request its deletion, and to opt out of the sale of their data to third parties.
India's Digital Personal Data Protection Act, 2023, establishes a legal framework specifically for digital personal data within India, outlining obligations for organizations that process such data and rights for individuals including consent requirements and grievance redress mechanisms reflecting the country's own growing regulatory attention to digital privacy as one of the world's largest internet populations.
These laws differ in scope, enforcement mechanisms, and cultural context, but they share a common thread: an acknowledgment that data about a person is not merely a corporate asset, but an extension of that person's autonomy, deserving of legal protection.
For an ordinary internet user, none of this is abstract. It is the legal basis for the ability to request what a company knows about you, to have your account data deleted if you close it, and to opt out of certain kinds of tracking. Knowing these rights exist and that they vary depending on where you live is itself a form of digital empowerment.
8. Becoming a Responsible Digital Citizen
Understanding the mechanics of data and power is only useful if it translates into everyday practice. Being an informed digital citizen doesn't require technical expertise or paranoia about technology. It requires a handful of consistent habits.
Practice basic fact-checking. Before sharing a claim, especially an emotionally charged one, take a moment to verify it through a reputable, independent source. Misinformation spreads faster than corrections, and being a careful sharer is itself a civic contribution.
Understand why you're seeing what you're seeing. When a recommendation feels unusually specific or a piece of content seems designed to provoke a strong reaction, ask what data or behavior might have triggered it. This awareness alone reduces susceptibility to manipulation.
Review app permissions regularly. Many apps request access to contacts, location, or microphone data far beyond what their core function requires. Periodically auditing and revoking unnecessary permissions is a simple, high-value habit.
Use available privacy settings. Most major platforms now offer some controls over ad personalization, data sharing with third parties, and visibility of your information. These settings are often buried, but they exist and are worth using.
Recognize persuasive design. Infinite scroll, autoplay, urgency-inducing notifications, and variable reward mechanisms (the same psychological principle behind slot machines) are deliberately engineered to hold attention. Recognizing these patterns doesn't mean rejecting the platforms that use them — it means using them with intention rather than being used by them.
Build basic AI and algorithmic literacy. As AI-driven recommendation, generation, and decision-making systems become more embedded in daily life, understanding roughly how they work that they optimize for specific goals, that they can reflect and amplify biases in their training data, and that their outputs are probabilistic rather than authoritative — is becoming as fundamental as reading literacy once was.
Share data thoughtfully. Before granting an app broad access to your information, ask a simple question: does this permission actually serve a function I want, or is it collecting more than the service needs? A flashlight app that requests access to your contacts is a signal worth noticing.
None of these habits are about withdrawing from digital life. They are about engaging with it deliberately, the way a financially literate person engages with money not avoiding transactions, but understanding the terms of every exchange.
9. Conclusion: Owning Your Digital Future
The internet remains one of the most powerful tools humanity has built. It has connected families across continents, given a voice to people who were once unheard, made the world's knowledge searchable in seconds, and created opportunities for learning, work, and creativity that didn't exist a generation ago. None of that promise has disappeared.
But alongside that promise runs a parallel reality: our data, generated continuously and often invisibly, has become one of the most valuable and consequential resources in the modern economy. It fuels advertising, shapes the content we see, and in cases like Cambridge Analytica can be marketed, sometimes with exaggerated claims, as a tool for political influence.
The lesson of The Great Hack is not that technology is a trap to be avoided. It is that power, wherever it accumulates in a government, a corporation, or an algorithm deserves scrutiny, transparency, and accountability. Digital rights are not a niche legal concern; they are an extension of the basic idea that people deserve some say over information that describes who they are.
Being a responsible digital citizen doesn't mean deleting your accounts or distrusting every platform you use. It means understanding the trade-offs at play, exercising the rights available to you, questioning the reality your feed presents as complete, and treating your own data with the same care you'd bring to any other valuable personal asset.
The internet was built to connect us. Whether it continues to serve that purpose rather than quietly reshaping us into more predictable, more manageable audiences depends, in no small part, on how aware its users choose to be.
References
Amer, Karim, and Jehane Noujaim, directors. The Great Hack. Netflix, 2019.
Cadwalladr, Carole, and Emma Graham-Harrison. "Revealed: 50 Million Facebook Profiles Harvested for Cambridge Analytica in Major Data Breach." The Guardian, 17 Mar. 2018, www.theguardian.com/news/2018/mar/17/cambridge-analytica-facebook-influence-us-election.
McCammon, Sarah. "Documentary: 'The Great Hack.'" Interview with Karim Amer and Jehane Noujaim. NPR, 28 July 2019, www.npr.org/2019/07/28/746089858/documentary-the-great-hack.
Pariser, Eli. The Filter Bubble: What the Internet Is Hiding from You. Penguin Press, 2011.
Tappin, Ben M., et al. "Quantifying the Potential Persuasive Returns to Political Microtargeting." Proceedings of the National Academy of Sciences, vol. 120, no. 25, 2023, e2216261120. PNAS, www.pnas.org/doi/10.1073/pnas.2216261120.


