Analysis
The Snowden disclosures and the ethics of building surveillance at scale
Edward Snowden's 2013 leaks forced engineers to confront how ordinary technical work can be repurposed for mass surveillance.
Dr. Marisol Vega FACS
Fellow and Technology Editor, American Computer Society
June 2013 · 7 min read

Starting 6 June 2013, The Guardian and The Washington Post published documents leaked by former NSA contractor Edward Snowden detailing the PRISM programme and bulk telephony metadata collection. The disclosures raised uncomfortable questions for the engineers who build the infrastructure such programmes depend on.
What was disclosed, and when
The Guardian's first report, published 6 June 2013, revealed a secret court order compelling Verizon to hand the National Security Agency daily records of millions of Americans' phone calls. A second report the following day described PRISM, a programme under which the NSA obtained data from major technology companies including Microsoft, Google, Yahoo, Facebook and Apple, according to leaked slides. The source, Booz Allen Hamilton contractor Edward Snowden, was named publicly on 9 June 2013 after identifying himself from Hong Kong.
Over the following months, further reporting detailed programmes for bulk internet metadata collection, efforts to weaken encryption standards, and surveillance of allied foreign leaders. The disclosures triggered congressional hearings, a legislative response in the 2015 USA FREEDOM Act, and a lasting shift in how technology companies discussed their relationships with government data requests.
“Systems for data collection and retention existed because engineers built them — often with limited visibility into how the results would be used.”
The engineers in the middle
What distinguished this episode from prior surveillance controversies was how squarely it implicated ordinary software engineering practice. Systems for data collection, retention, indexing and query existed because engineers built them, under classification regimes and legal authorities that limited what those engineers could know about downstream use. Reporting also drew attention to a parallel programme, referred to as Bullrun, aimed at undermining commercially deployed encryption — placing cryptographers and standards-body participants in a position where their technical contributions may have been quietly weakened without their knowledge.
The episode also renewed debate inside companies about data minimisation: architectures that retain more personal data than a product function requires create surveillance capability as an unintended by-product, whether or not that capability is ever exercised by a government request.
A professional, not just political, reckoning
The Society's interest here is deliberately narrower than the political debate over surveillance policy, on which reasonable people disagree. Its concern is with the standards of practice that determine whether an engineer can even recognise, let alone object to, a use of their work that conflicts with professional ethics — and what recourse exists when they do.
- Data architectures should be designed for minimisation and purpose limitation by default, not as an afterthought.
- Cryptographic standards work carries a public trust dimension inseparable from technical merit.
- Engineers need clear, protected channels to raise concerns about the use of systems they build, distinct from whistleblower routes reserved for extreme cases.
What the Society advises
The Society calls on employers to establish internal ethics review for systems with surveillance or mass-data-collection potential, comparable to review boards long used in other high-consequence fields. It urges members to treat data minimisation as a design default and to document, for their own protection and the public's, any objection raised about a system's intended use. A code of ethics is only meaningful if it is backed by real institutional protection for the engineers who invoke it.
Join the professional body behind this work
ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.
Become a memberMore from ACS Insights
Optimus: a humanoid robot from prototype to production line
Four years from an AI Day slide to a converted Fremont assembly line — and still no commercial sale.
AnalysisGrok, Colossus and the compute arms race
xAI built a 100,000-GPU cluster in 122 days, doubled it, and merged twice. The externalities arrived with the electricity.
ArticleA national consortium to build trust in AI
ACS joins federal partners, universities and industry to strengthen assurance practice for high-impact AI systems.