The two children leave for school and are picked up by the cameras at the gate. Their parents' wearables have been recording their bodies since before dawn. The doorbell films the street, the smart meter logs the kettle, the car reports where it is going, and by the evening the television may have scanned what is on screen tens of thousands of times.
None of this is unusual, and that is the point of a study published today by Web3 Foundation, which set out to answer a simple question about an ordinary weekday: if a family actually read the privacy documents attached to the services and systems around them, how long would it take?
For a modelled family in the United Kingdom, the answer is 83 hours. The relevant privacy policies, terms, notices and supporting documents run to 257 documents and 1,184,835 words, which at an average reading speed would occupy 10.4 eight-hour working days. William Shakespeare's complete works contain about 884,647 words. The family's small print is 34 per cent longer.
A modelled single working adult fares little better, with 224 documents, 1,055,153 words and 73.9 hours of reading, or 9.2 working days. Even a modelled 75-year-old retiree, who uses fewer digital services, is linked to 156 documents containing 645,118 words, a 45.2-hour read spread across 5.6 working days.
The study, Everyday Surveillance: What One Ordinary Day May Reveal About You, is released to mark UNESCO's 2026 International Day for Universal Access to Information, whose theme this year is "Upholding Information Integrity in the Digital Age: The role of access to Information in addressing Information Disorder". Researchers built six evidence-based model households, a working adult, a family with two children and an older adult living independently, in both the United Kingdom and the United States. They then did what consumers are told to do and read the privacy documents.
Across the six households they identified 1,195 relevant documents containing more than 5.38 million words. Analysing them produced a picture of routine digital life in which a household may be observed through phones, wearables, televisions, banks, cars, schools, utilities, cameras, health services and location systems, each potentially creating its own record, with many organisations' documents describing further potential uses of that information.
Gavin Wood, founder of Web3 Foundation, said: "We did what consumers are told to do: we read the privacy policies. For the modelled UK family, one ordinary day means more than ten working days of reading. What we found in that fine print was much bigger than a collection of individual privacy notices. It described how information about people's bodies, homes, money, movements, children and behaviour can be combined, inferred, shared, retained and, in some cases, used to train AI. Disclosure is not meaningful control if a person has no realistic chance of reading it."
The foundation is careful about what the study does and does not claim. It is not a national survey and does not describe the practices of every or any user. It examines documented capabilities and permissions across evidence-led model scenarios, under stated assumptions about product choice, settings, configurations and system operation. A company policy shows what an organisation says it may collect or process, not that every permitted action happens to every user every day. Numerical findings are presented as documented minimums, modelled estimates or reasonable ranges.
Within those limits, the volume of potential data is considerable. The study links the modelled UK family to 88 organisations, 25 of which have documents indicating that they may collect information relating to the children. The two adults' wearables may generate around 2,000 combined daily health readings. The children are modelled as being captured around 100 times by school cameras in a day, and the modelled school record produces 11,400 logged keystrokes over a school week, including keystrokes that the relevant monitoring system may retain where text is deleted or never sent. Across school CCTV, school-gate cameras, shops, streets, the family's own Ring doorbell and in-car filming, the family may be recorded an estimated 90 to 260 times in the modelled day.
The study links the modelled single working adult to 68 organisations, around 271 modelled processing events and 522 described information items. His wearable may generate more than 1,100 biometric and physiological readings. Around three hours of television is modelled as producing approximately 21,600 screen observations where Automatic Content Recognition, a feature that scans what is being shown on a television, is assumed to be enabled. Ordinary movement may add an estimated 60 to 190 camera captures across residential doorbells, tram CCTV, shops, the gym and the office.
Limited technology use does not necessarily mean limited data. In the modelled retiree's day, 49 organisations are involved. Five to six hours of television is modelled as producing around 40,000 automatic scans of what is being shown when Automatic Content Recognition is assumed to be enabled. Her routine can also include 16 to 45 quantified doorbell clips, 48 half-hour smart-meter intervals, NHS and pharmacy records, telecare data and number-plate records linked to regular journeys.
Bill Laboon, Vice President of Technical Operations at Web3 Foundation, said: "What is striking is how much data may be generated around completely ordinary digital activity. The report raises the question of whether we can build services differently, for example, by allowing people to prove what is needed without routinely disclosing the underlying information."
The documents themselves describe what may happen to that information once collected. Across the 143 organisations examined, the documents of 118, or 83 per cent, describe potential use of data for marketing or advertising. Those of 114 (80 per cent) describe potential combining of data across sources, 109 (76 per cent) describe potential inference or profiling, 102 (71 per cent) describe potential sharing with commercial partners as defined by the study, and 95 (66 per cent) state no fixed retention period. Separately, the documents of at least 35 organisations, 24 per cent, contain an affirmative statement that user data may be used to train or improve AI or machine-learning systems.
The trail extends well beyond names and email addresses. Fifty-five of the 143 organisations, 38 per cent, list particularly sensitive categories among the information they could collect, including health, biometrics, sexual orientation, political opinions, ethnicity or religion. Separate data points can then be linked or used to infer information about a person's body, home, finances, movements, relationships, children, beliefs, interests and likely future behaviour.
Much of this can happen when no screen is being actively used. Wearables may measure the body during sleep, smart meters may record household activity through the night, doorbells and cameras may remain active, connected devices may synchronise in the background and connected cars may transmit location and driving telemetry.
The White Paper sets the UK findings against a broad cross-sector data-protection framework comprising the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. It notes requirements including a lawful basis for processing, transparency, purpose limitation, data minimisation and storage limitation. That framework is broader than the US position modelled in the study, where federal sectoral rules operate alongside state-level protections. Yet in each of the three matched scenarios, the UK household was linked to more separately counted organisations than its matched US household. The figures are model-household figures rather than national statistics, but the study concludes that a broader privacy framework does not by itself mean that ordinary digital life generates little data.
In response, the White Paper proposes six design principles aimed at reducing disclosure. These include revealing only the information a service actually needs, for example age rather than date of birth; allowing people to hold reusable digital proofs rather than repeatedly copying identity documents; making permissions clear and easy to withdraw; and using selective disclosure so that a fact can be verified without handing over the full underlying dataset.
The researchers mapped a normal 24-hour weekday against the products, services and systems around each household and what those systems say they may collect, generate or infer, drawing on company policies, technical documentation, regulator records, academic research and published measurement studies. Reading time was calculated at 238 words per minute, the average silent reading rate for non-fiction identified in Brysbaert's 2019 meta-analysis. The Shakespeare figure comes from the Folger Shakespeare Library, citing Marvin Spevack's concordances. The documents were reviewed between August and September 2026, with the legal and regulatory position checked to 18 September 2026, and the methodology, assumptions and supporting data are published alongside the study so that the calculations, source choices and analytical approach can be scrutinised, challenged and rerun by others.
The study uses "surveillance" in a defined sense: the systematic generation, observation, recording or inference of information about a model person or household. It describes an information process rather than a legal conclusion or allegation of wrongdoing, and covers records created for safety, public services, administration, commerce and security as well as for advertising or behavioural monitoring.
Web3 Foundation supports a fairer internet built on systems that are more distributed and give people greater control over their data and identity, funding research and development of decentralised web software protocols. The White Paper and Technical Methodology are available at web3.foundation/insights.
Its closing observation is the one the modelled family lives out without noticing. A person may experience one journey to work, one television programme or one payment. The systems around them can experience the same activity as repeated measurements, identifiers, timestamps, images, location traces and behavioural signals.
Join the Discussion
Have something to say? Join the conversation!
Sign in to share your thoughts and engage with other readers.
Sign In Create AccountNo comments yet
Be the first to share your thoughts on this article!