The Privacy Documents Attached to Just One Family’s Digital Day Can Take More Than 10 Workdays to Read – Longer Than the Complete Works of William Shakespeare

The Privacy Documents Attached to Just One Family’s Digital Day Can Take More Than 10 Workdays to Read – Longer Than the Complete Works of William Shakespeare

 

Zurich, Switzerland | Sept 28: A new Web3 Foundation study of six evidence-based model households in the United Kingdom and United States found that it may take up to 10 full working days to read the privacy policies, terms, notices and supporting documents linked to one ordinary modelled digital day.

Across the six scenarios, researchers identified 1,195 relevant documents containing more than 5.38 million words. Depending on the modelled household, simply reading the material linked to one ordinary day would require between 37 and 83 hours, or 4.6 to 10.4 full workdays.

The largest reading burden was found in the modelled UK family scenario, where 257 privacy policies, terms, notices and supporting documents contain 1,184,835 words. That is about 83 hours of reading – 10.4 eight-hour workdays – and 34% more than the 884,647 words contained in William Shakespeare’s complete works.

In the US scenarios, a similar family’s relevant privacy policies, terms and notices run to 233 documents and 1,118,224 words – 26% more than Shakespeare’s complete works – and require 78.3 hours, or 9.8 workdays, to read.

For the single modelled working adult, the relevant documents would take 73.9 hours, or 9.2 eight-hour workdays, to read in the UK scenario and 59.4 hours, or 7.4 workdays, in the US scenario. Even the older-adult models, which use fewer digital services, would require 45.2 hours of reading in the UK and 37.1 hours in the US, equivalent to 5.6 and 4.6 workdays respectively.

Released to mark UNESCO’s 2026 International Day for Universal Access to Information, the study, Everyday Surveillance: What One Ordinary Day May Reveal About You, modelledthe everyday products, services and systems surrounding six evidence-based model households in the United States and United Kingdom and then did what consumers are supposedto do: read the privacy documents.

Analysing those documents created a picture of routine digital life in which the same model household maybe observed through phones, wearables, televisions, banks, cars, schools, utilities, cameras, health services and location systems, with each system potentially creating its own record and many organisations’ privacy documents describing further uses of that information.

The study does not claim to be a national survey or to describe the practices of every or any user. It examines documented capabilities and permissions across evidence-led model scenarios and, where relevant, stated modelling assumptions about product choice, settings, configurations and system operation.

In each matched pair in these modelled scenarios, the UK household was linked to more separately counted organisations than its US counterpart, while the US scenarios showed greater involvement of some commercial location, insurance and data systems.

These are model-household findings, not national totals or statistics, but the comparison illustrates that different regulatory and institutional structures affect who may collect and reuse information, what rules apply and what rights people have once the data exists. In both sets of modelled scenarios, ordinary digital activity may still generate large volumes of information.

Gavin Wood, founder of Web3 Foundation, said: “We did what consumers are told to do: we read the privacy policies. In our modelled family scenarios in the US and UK, one ordinary day came with around ten workdays of reading. What we found in that small print was much bigger than a collection of individual privacy notices. It described how information about people’s bodies, homes, money, movements, children and behaviour can be combined, inferred, shared, retained and, in some cases, used to train AI. Disclosure is not meaningful control if a person has no realistic chance of reading it.”

Bill Laboon, Vice President of Technical Operations at Web3 Foundation, said: “What is striking is how much data may be generated around completely ordinary digital activity. The report raises the question of whether we can build services differently, for example, by allowing people to prove what is needed without routinely disclosing the underlying information.”

The comparison shows that high-volume data collection can arise across very different ages and levels of technology use. In both family models, adult wearables are modelled as generating around 2,000 daily readings: combined health readings in the UK scenario and heart-rate readings in the US scenario.

The modelled children may also generate records through school systems, cameras and location tools. In the UK family model, 11,400 keystrokes can be logged in a school week and the children can be captured around 100 times by school cameras in a day. In the US family model, school-device activity is modelled as potentially being monitored minute by minute and a family location-sharing service is modelled as making a child’s location available around the clock.

The two single-adult scenarios also show how quickly repeated observations can accumulate. In both models, around three hours of television is modelled as producing approximately 21,600 Automatic Content Recognition screen captures where ACR is assumed to be enabled. The UK single adult is linked to 68 organisations and around 271 modelled processing events. The US counterpart is linked to 62 organisations and around 219 modelled processing events.

Among the older-adult scenarios, the modelled UK retiree is linked to 49 organisations and five to six hours of television is modelled as producing around 40,000 scans of what is being watched where ACR is assumed to be enabled. The US retiree is linked to 44 organisations and around five hours of viewing is modelled as producing roughly 36,000 screen captures where ACR is assumed to be enabled. Their days also include smart-meter readings, cameras, health and pharmacy records, location sharing and license-plate records.

Across the 143 organisations examined, documents of 118 (83%) describepotential use of data for marketing or advertising; 114 (80%) describe potential combining data across sources; 109 (76%) describe potential inference or profiling; 102 (71%) describe potential sharing with commercial partners as defined by the study; and 95 (66%) state no fixed retention period. Separately, the documents of at least 35 organisations (24%) contain an affirmative statement that user data may be used to train or improve AI or machine-learning systems.

The data trail may extendfar beyond names and email addresses. Across the organisations reviewed, 55 of 143 (38%) list particularly sensitive categories among information they could collect, including health, biometrics, sexual orientation, political opinions, ethnicity or religion. Separate data points can then be linked or used to infer information about a person’s body, home, finances, movements, relationships, children, beliefs, interests and likely future behaviour.

Potential data collection or generation can also occur when no screen is being actively used. Wearables may measure the body during sleep, smart meters may record household activity through the night, doorbells and cameras may remain active, connected devices may synchronise in the background and connected cars may transmit location and driving telemetry.

The two countries also operate under markedly different privacy frameworks. The UK has one broad cross-sector data-protection framework, while the US relies on federal sectoral rules alongside a state-by-state patchwork.

The White Paper cautions that these figures are model-household findings rather than national totals or statistics. The matched scenarios are intended to illustrate how similar routines can interact with different legal, institutional and commercial environments.

It proposes six Web3 Foundation design principles intended to reduce disclosure. These include revealing only the information a service actually needs, such as age not date of birth, allowing people to hold reusable digital proofs rather than repeatedly copying identity documents, making permissions clear and easy to withdraw, and using selective disclosure so a fact can be verified without handing over the full underlying dataset.

Methodology at a glance

Web3 Foundation built six evidence-based model households: a working adult, a family with two children and an older adult living independently in both the UK and US. Researchers mapped a normal 24-hour weekday against the products, services and systems around each household and what those systems say they may collect, generate or infer, using company policies, technical documentation, regulator records, academic research and published measurement studies.

The study does not claim to be a national survey or to describe the practices of every or any user. It examines documented capabilities and permissions across evidence-led model scenarios under stated modelling assumptions about product choice, settings, configurations and system operation. Company policies show what an organization says it may collect or process, rather than proving that every permitted action happens to every or any user every day. Numerical findings are presented as documented minimums, modelled estimates or reasonable ranges.

The analysis reflects company terms, privacy notices and other relevant documents publicly available and reviewed between August and September 2026, with the legal and regulatory position checked 18 September 2026. The methodology, assumptions and supporting data are published as part of the study so the calculations, source choices and analytical approach can be scrutinized, challenged and rerunby others.

 

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *