2026 or 1984?
The Quiet Disappearance of Privacy
You walk into a railway station.
Before reaching the platform, a camera captures your face and software converts it into biometric data. Your phone can reveal where you have been. Your ticket records the journey you intend to make. Your bank knows what you bought on the way. The apps in your pocket learn what you read, what you watch, what worries you and what is likely to hold your attention.
You have not been accused of anything. You are simply living an ordinary life in Britain in 2026.
None of this arrived with a dramatic announcement that privacy had been abolished. There was no single vote to make every citizen permanently observable. Each development came separately, usually accompanied by a reasonable explanation: convenience, personalisation, fraud prevention, public safety or national security.
The explanations are not necessarily dishonest. These technologies can catch criminals, locate missing people, prevent fraud and make services work better.
But taken together, they represent a profound change in the relationship between the individual, the state and the companies through which modern life is conducted.
Privacy is not disappearing in one decisive act. It is being surrendered in fragments.
The generation that never had privacy
Perhaps the most unsettling development is not that surveillance is expanding. It is that we are becoming accustomed to it.
Thomas Bunting, an analyst at the innovation foundation Nesta, recently offered a stark assessment: “In 2026 online privacy is a luxury, not a right.” At 25, he does not feel that his generation ever possessed meaningful online privacy in the first place. Instead, it learned to manage settings, accept the bargain and treat personal data as the price of participating in digital life. BBC News
That may be the greater cultural shift. Something does not feel like a lost freedom if we have never experienced it.
We are presented with privacy policies that almost nobody can realistically digest, consent notices that interrupt whatever we are trying to do and controls scattered across dozens of accounts and devices. Eventually, consent becomes less a considered decision than a reflex: click “accept” and continue.
This is sometimes called the privacy paradox. People say privacy matters, but behave as though it does not. Yet that apparent contradiction may be misleading. If declining data collection means losing access to communication, work, banking, travel, shopping or social life, compliance is not necessarily indifference. It may simply reflect the absence of a practical alternative.
Nor is privacy distributed equally. Protecting it requires time, knowledge and often money: paid services, premium devices, secure software and the confidence to alter defaults. Privacy may remain available—but increasingly as a specialist product for those able to understand and afford it.
The danger is a generation trained not merely to tolerate surveillance, but to regard the desire to avoid it as eccentric.
From watching suspects to scanning everybody
British Transport Police began trialling live facial-recognition technology at major London railway stations in February 2026. Deployments have included London Bridge, Waterloo, Euston, King's Cross, St Pancras, Liverpool Street and Victoria. In August, the trial expanded onto the London Underground, beginning at Victoria.
The cameras do not wait until somebody behaves suspiciously. They scan faces within a designated area and compare them in real time with images on a police watchlist. An officer then reviews any possible match before deciding whether to intervene.
BTP says the deployments are temporary and intelligence-led, prominent signs are displayed, alternative routes are available, and biometric data relating to people who do not produce an alert is deleted immediately. The ordinary CCTV footage used alongside the system is retained for 31 days. The pilot is due to be evaluated after running until November 2026. British Transport Police
Those safeguards matter. So do the results.
According to a parliamentary answer covering deployments up to 4 August, no wanted person had been successfully matched to a watchlist, one person had been stopped following a false alert, and no arrest had resulted specifically from a facial-recognition match. BTP reported 13 arrests linked to the wider deployments, but not directly caused by the technology identifying somebody. UK Parliament
That does not prove the trial is worthless. It does, however, raise the question that should accompany every expansion of surveillance:
Is the intrusion proportionate to the result?
More fundamentally, it reverses a principle we have long taken for granted. Traditionally, surveillance followed suspicion. Increasingly, everybody is scanned first so that the system can decide who deserves attention.
The loss of location privacy
There was a time when knowing where somebody had been required observation, questioning or investigation.
Today, an ordinary journey can produce several separate records: mobile-network location data, GPS information gathered by apps, payment records, ticketing data, number-plate recognition and CCTV footage. Each record may be held by a different organisation for a different purpose. That is not the same as saying a single authority routinely combines everything into one complete map of our lives.
The concern is the cumulative capability.
The Information Commissioner's Office defines network location data as information showing where a user's device is or was located, potentially including latitude, longitude, direction of travel and the time the information was recorded. GPS data gathered independently by apps falls under a different technical category, but remains subject to data-protection law. ICO guidance
Our location can reveal far more than movement. It can disclose where we live, work and worship; which hospital or clinic we visit; which political meeting we attend; whom we spend time with; and when our home is likely to be empty.
Location privacy is therefore not merely about hiding where we are. It protects association, belief, health, family life and personal safety.
A society in which movement can routinely be reconstructed is different from one in which people can simply go somewhere without creating a permanent trail.
The loss of conversational anonymity
Conversation was once naturally temporary. Words spoken privately disappeared unless somebody remembered, repeated or deliberately recorded them.
Increasingly, conversation passes through an intermediary.
Messages travel through platforms. Meetings are transcribed. Voice assistants process requests. Customer calls are recorded and analysed. Artificial-intelligence services can retain prompts and responses according to the settings and terms governing the service. Even where the content of a message is encrypted, communications data may still reveal who contacted whom, when, for how long and sometimes from where.
This does not mean that the Government is listening to every conversation or that every provider is secretly preserving every word. It means that conversation is progressively losing its natural anonymity and impermanence.
We are creating records of thoughts that, in an earlier age, would have vanished into the air.
That changes behaviour. People speak differently when they believe their words may be stored, searched, misinterpreted or retrieved years later. A joke becomes data. A moment of anger becomes evidence of character. A tentative question becomes a declared interest. An opinion expressed while thinking aloud can be treated as a settled belief.
The danger is not only that somebody might read our conversations. It is that we begin editing ourselves before speaking.
That self-censorship is already visible in ordinary life. The BBC article recounts young people who avoid dancing in clubs because somebody may film the moment and use it to embarrass them later. The behaviour is harmless; the inhibiting force is the possibility of permanent, searchable exposure.
When people assume that everything may be recorded, they begin living for the imagined future audience. Surveillance no longer needs to issue an instruction. The possibility of being watched does the work.
Biometric and physical privacy
A password can be changed. A bank card can be replaced. Your face, fingerprints, voice and manner of walking are part of you.
That is what makes biometric surveillance fundamentally different from conventional identification. The ICO describes facial-recognition systems as creating biometric templates by measuring facial features. In most applications involving identification, this is not merely personal data but legally protected special-category data. ICO facial-recognition guidance
Supporters reasonably argue that live facial recognition can locate dangerous offenders faster than officers relying upon memory and chance. Opponents reasonably ask whether millions of innocent faces should be processed to find a small watchlist—and what happens if today's narrowly drawn list becomes broader tomorrow.
There are also unavoidable errors. The ICO acknowledges that biometric systems produce false positives and false negatives, and that uneven error rates can create discriminatory outcomes. It also warns that systematic monitoring of public spaces can discourage people from exercising freedom of expression or assembly. ICO biometric guidance
The immediate question may be whether the camera has correctly identified us.
The deeper question is whether we should have to be identified at all merely because we entered a public place.
Predictive privacy—and privacy of the mind
The next frontier is not simply recording what we have done. It is predicting what we may do next.
Every search, pause, click, purchase, journey and viewing choice can add to a profile. Algorithms can assess or predict our behaviour, interests, characteristics, reliability, economic situation, health, location and movements. They can infer what we fear, what persuades us, whether we may be financially vulnerable and which message is most likely to change our behaviour.
The ICO recognises profiling as automated processing that assesses or predicts people's behaviour, interests or characteristics. It also recognises that sensitive information—such as political opinions, religious beliefs or health information—may be inferred rather than explicitly supplied. ICO profiling guidance ICO special-category guidance
Nobody needs literally to read our minds. A sufficiently accurate model of what we are likely to think, want or do may be commercially or politically more useful.
This is the loss of predictive privacy: the loss of control not merely over facts about us, but over the conclusions that machines draw from them.
It can also become a form of mental intrusion. A system that learns what keeps us anxious or engaged can decide what to show us next. It does not simply observe our attention; it can influence it. The profile shapes the content, the content shapes the person, and the resulting behaviour improves the profile.
Consider the apparently harmless smart refrigerator. It may help a household reduce waste or remember what to buy. But the same record of dietary choices could also be used to infer health, habits and risk. If such information were ever shared with a health insurer, convenience could quietly become a factor in the price or availability of cover. That remains a hypothetical example, not an inevitable future—but the data and the incentive to use it can now exist in the same system.
Orwell imagined a state determined to control thought. Our version may be quieter and more complicated: states, platforms, advertisers and algorithms each possessing fragments of insight into our private lives, often acquired because we clicked “accept” to reach the next screen.
The decline of financial confidentiality
Our bank statements may be the most revealing diary we never intended to write.
They show where we eat, what we subscribe to, which charities we support, which doctors or pharmacies we use, where we travel and, increasingly, the smallest details of daily life.
The Public Authorities (Fraud, Error and Recovery) Act 2025 now provides a particularly important example of how financial confidentiality is changing.
Under the Eligibility Verification Measure, the Department for Work and Pensions can issue notices requiring banks and other financial institutions to examine accounts receiving Universal Credit, Pension Credit or Employment and Support Allowance—and linked personal current, savings and investment accounts—against specified eligibility indicators. Those indicators may relate to capital limits or possible periods spent overseas. Information on accounts meeting the criteria can then be returned to the DWP. DWP Code of Practice
It is important to describe this accurately.
The measure does not give DWP officials unrestricted live access to everybody's bank account. Eligibility Verification Notices cannot name individual claimants, cannot request transaction-level spending information and cannot establish guilt automatically. They require financial institutions to apply criteria across relevant accounts and return limited information on matches. If the information prompts a further inquiry, investigators may use separate powers to obtain detailed bank statements. DWP fraud strategy
There is an entirely legitimate public interest in preventing benefit fraud and correcting overpayments. Those receiving means-tested support must comply with the rules, and taxpayers are entitled to expect public money to be protected.
But the constitutional change still deserves attention. Banks are no longer simply holding and transferring customers' money. They can be legally required to run checks across classes of accounts to identify people whose financial circumstances may warrant examination—even where those people were not already the subject of an individual fraud suspicion.
Today the purpose is checking eligibility for specified benefits, with statutory limits and safeguards. The question for society is what principles will govern the infrastructure tomorrow.
Once a capability exists, the argument often moves from whether it should exist to the widening range of worthy purposes for which it could be used.
“If you have nothing to hide...”
The standard response to privacy concerns is familiar: if you have done nothing wrong, you have nothing to fear.
But privacy is not the concealment of wrongdoing.
We close bathroom doors without committing crimes. We draw curtains without plotting against the state. We expect medical consultations, family disagreements, political beliefs and personal finances to remain private because dignity requires spaces in which we are not continuously observed.
Privacy creates room to change our minds, make mistakes, explore ideas and live without performing for an unseen audience.
The presumption that only the dishonest need privacy is itself dangerous. It quietly changes privacy from an ordinary condition of freedom into a suspicious preference that must be explained.
Gold: private, but not invisible
This is where physical gold has a relevant—but often overstated—role.
Gold is not a magical route outside the law, and reputable dealers should never present it as one. The purchase of investment gold can involve identity checks, banking records and legally required customer and transaction records. HMRC rules require specified records for qualifying investment-gold transactions, and professional storage, insurance and eventual sale can create further documentation. Britannia Bullion complies with all applicable identification, anti-money-laundering and record-keeping obligations. HMRC investment-gold guidance
So the honest claim is not that gold is anonymous.
It is that gold is private in character after acquisition.
Physical gold held directly is an asset rather than an account. It has no password, subscription or digital profile. It does not record where its owner travels, analyse what they purchase, report a daily balance to an app or generate a stream of behavioural data simply by continuing to exist.
It does not need an issuer to honour a promise or a platform to recognise a login. When held directly, access does not depend upon a bank's opening hours, an application's availability or an institution maintaining an account in good standing.
That does not make it risk-free. Direct ownership creates responsibilities involving custody, security and insurance. Gold's value can fall as well as rise. If it is professionally vaulted, third-party custody and records remain involved. Legal authorities can act against assets where the law permits.
Nevertheless, in a world where an increasing share of wealth exists only as entries in permissioned databases, the ability to own something physical and finite has a privacy value distinct from its market price.
Gold cannot make its owner invisible.
It can preserve a small area of independent ownership.
2026 or 1984?
Britain in 2026 is not Orwell's 1984. We retain courts, elections, legal protections, public scrutiny and the ability to challenge government policy. Facial-recognition deployments are disclosed. Data-processing rules exist. Decisions can be reviewed. Safeguards are real and should not be dismissed simply because technology makes us uneasy.
But Orwell's warning was not valuable because every detail of his novel would arrive exactly as written.
It was valuable because it understood the relationship between observation and power.
A society changes when citizens assume they may be identified wherever they go, recorded whenever they speak, profiled before they act and financially examined by systems they cannot see.
The greatest danger may not be one enormous act of surveillance. It may be a thousand individually defensible intrusions that gradually make anonymity abnormal, confidentiality conditional and privacy an historical curiosity.
The question is not whether technology should ever be used to catch dangerous people or prevent fraud. Of course it should.
The question is whether necessity remains exceptional, whether safeguards keep pace with capability, and whether citizens retain meaningful spaces in which they are neither watched nor assessed.
Privacy is not secrecy.
Privacy is the right to have a life that is not permanently converted into data.
And as that right becomes harder to exercise, direct ownership—of our information, our choices and part of our wealth—may become more valuable than we yet appreciate.
About the author
Matthew Jones is Co-founder and Precious Metals Analyst at Britannia Bullion. This article represents his personal analysis and opinion. It is intended for general information and does not constitute personal financial advice or a recommendation to buy or sell any asset.
Investment in physical gold is unregulated in the UK and is not protected by the Financial Services Compensation Scheme or Financial Ombudsman Service. Its value can rise or fall, and ownership, custody, insurance and storage arrangements must be properly understood.