Articles & Research

Analysis

The Snowden disclosures and the ethics of building surveillance at scale

Edward Snowden's 2013 leaks forced engineers to confront how ordinary technical work can be repurposed for mass surveillance.

Dr. Marisol Vega FACS

Fellow and Technology Editor, American Computer Society

June 2013 · 7 min read

The United States Capitol dome at golden hour
The United States Capitol dome at golden hour

Starting 6 June 2013, The Guardian and The Washington Post published documents leaked by former NSA contractor Edward Snowden detailing the PRISM programme and bulk telephony metadata collection. The disclosures raised uncomfortable questions for the engineers who build the infrastructure such programmes depend on.

What was disclosed, and when

The Guardian's first report, published 6 June 2013, revealed a secret court order compelling Verizon to hand the National Security Agency daily records of millions of Americans' phone calls. A second report the following day described PRISM, a programme under which the NSA obtained data from major technology companies including Microsoft, Google, Yahoo, Facebook and Apple, according to leaked slides. The source, Booz Allen Hamilton contractor Edward Snowden, was named publicly on 9 June 2013 after identifying himself from Hong Kong.

Over the following months, further reporting detailed programmes for bulk internet metadata collection, efforts to weaken encryption standards, and surveillance of allied foreign leaders. The disclosures triggered congressional hearings, a legislative response in the 2015 USA FREEDOM Act, and a lasting shift in how technology companies discussed their relationships with government data requests.

“Systems for data collection and retention existed because engineers built them — often with limited visibility into how the results would be used.”

The engineers in the middle

What distinguished this episode from prior surveillance controversies was how squarely it implicated ordinary software engineering practice. Systems for data collection, retention, indexing and query existed because engineers built them, under classification regimes and legal authorities that limited what those engineers could know about downstream use. Reporting also drew attention to a parallel programme, referred to as Bullrun, aimed at undermining commercially deployed encryption — placing cryptographers and standards-body participants in a position where their technical contributions may have been quietly weakened without their knowledge.

The episode also renewed debate inside companies about data minimisation: architectures that retain more personal data than a product function requires create surveillance capability as an unintended by-product, whether or not that capability is ever exercised by a government request.

A professional, not just political, reckoning

The Society's interest here is deliberately narrower than the political debate over surveillance policy, on which reasonable people disagree. Its concern is with the standards of practice that determine whether an engineer can even recognise, let alone object to, a use of their work that conflicts with professional ethics — and what recourse exists when they do.

  • Data architectures should be designed for minimisation and purpose limitation by default, not as an afterthought.
  • Cryptographic standards work carries a public trust dimension inseparable from technical merit.
  • Engineers need clear, protected channels to raise concerns about the use of systems they build, distinct from whistleblower routes reserved for extreme cases.

What the Society advises

The Society calls on employers to establish internal ethics review for systems with surveillance or mass-data-collection potential, comparable to review boards long used in other high-consequence fields. It urges members to treat data minimisation as a design default and to document, for their own protection and the public's, any objection raised about a system's intended use. A code of ethics is only meaningful if it is backed by real institutional protection for the engineers who invoke it.

CybersecurityPublic policySoftware engineering

Join the professional body behind this work

ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.

Become a member