The first time it happened, you might have thought it was a fluke. An ad popped up on Facebook for something you had recently been googling – maybe even on a different device. What a coincidence! Wow! Amazing!
Sheesh.
It’s ridiculous to consider how naive some of us (ahem) may have once been, when we now understand that we are constantly being monitored, tracked and targeted. Stalked is a word one online privacy expert uses; he prefers to call what is commonly called surveillance capitalism by a different term floating out there: the stalk market.
Driven by a flurry of alarming reports about surveillance pricing last spring, along with the troubling breach of the Alberta voters’ list, I set out on a layperson’s search to determine how – or if – a person who operates in the 2026 world can maintain a level of digital security. How do I book a flight, order takeout, buy a toaster without checking a box and accepting the requisite terms and conditions? What are those terms (which, let’s face it, almost nobody reads)? And what am I giving up by clicking?
We can feel ourselves being followed – or following. An app notifies you that your teenager just braked too hard while driving. A “relevant” ad pops up on a different platform than the one you were using to search for a similar product. That loyalty card you signed up for almost seems to intuit the rhythms of your cravings. Because it’s not just your loyalty that a retail conglomerate is after in exchange for discounts or points. It’s your information.
Everyone’s personal data is being extracted, and no one seems to care
We may think we’ve protected ourselves. It’s not like we’re posting sensitive information. But out there, somewhere, eerily bang-on data sketches are being drawn of our lives.
“It can feel deeply impactful or violating when you see a profile, even just the commercial marketing profile of you,” Ottawa-based privacy and security expert Mark Nunnikhoven told me recently. For instance: “‘Mark is middle-aged, has a family, and buys most of the household supplies. When prompted, he’s likely to add household essentials to smaller orders.’ And so on. All together, it’s a terrifyingly accurate picture of who I am.”
Creepy, right? Like somebody has been following you around and jotting down what they observe – which is, in fact, what’s happening, digitally. And then they’re using the information to sell you things – or worse.
“It’s surveillance by design,” another leading Canadian privacy expert, Colin Bennett, told me.
Last Sunday I clicked on a listing for an entryway console that seemingly randomly popped up on Facebook Marketplace. Was Facebook reading my mind? Because, in fact, someone had told me that week that my hallway table was too large for the space. Then on Monday a promotional e-mail arrived in my Gmail from a furniture store I didn’t think I subscribed to – offering up, of course, entryway tables.
Artificial intelligence has been added to the privacy (or lack thereof) mix, and the possibilities are next-level. AI makes it easier for things to look (or sound) real, and thus easier for us to be duped and robbed of our privacy or even our cash or identities.
And what do we do? Shrug our shoulders and carry on. Who has the time or knowledge to fight the Digital Man? Especially when it feels like the game is rigged.
“They know something about you and you do not know what that is,” says Prof. Bennett.
What I do know? We have a privacy problem. And we are being socially engineered, by forces outside our control.
How much do they know about us?
When Octavia Howell was 16, she googled her name. She got hits about Octavia the Younger, wife of the Roman general Mark Anthony, and a European car, the Skoda Octavia. There was nothing about herself. The same search in university did produce some of Ms. Howell’s academic work, along with the car and the Romans.
“Fast forward 20 years: If you google me now, I am coming up,” said Ms. Howell. “My voice is coming up.”
A search of Ms. Howell, who is head of security for Equifax Canada, quickly brings up interviews she’s given, her job history, photographs, videos, social-media posts by industry groups – all content that could be weaponized by nefarious actors. A recent Equifax Canada survey found that 83 per cent of Canadians are worried that technology can now be used to create fake legal documents – such as IDs, pay stubs, or insurance claims – that appear “convincingly real.”
So why do we do it? Why has clicking on a terms and conditions box, accepting a website’s cookies, posting our lives on social media, become so normalized? Especially when we know this information could be used to manipulate us, rob us, scam our loved ones? And make the tech oligarchs and data-mining operations we’ve never heard of rich off the backs of our privacy?
An Amazon delivery worker pulls a delivery cart full of packages in New York City.Brendan McDermid/Reuters
I asked Prof. Bennett – a professor emeritus at the University of Victoria who has authored studies and books on privacy and data protection – what the shadowy data overlords might know about me as an average Canadian.
“An enormous amount,” he answered, without hesitation. “The capture of the data happens surreptitiously and beneath the surface of our many, many transactions online.”
It can include data about where we live, who we associate with, whether we buy a lot of toilet paper – creating those eerily accurate profiles Mr. Nunnikhoven described.
In today’s economy, the capture of personal data has risen “exponentially” in importance, according to Prof. Bennett. “It’s the way that organizations, the big platforms, make wealth,” he told me. “They use personal data in order to fuel the advertising economy on the internet, which allows them to do what they do.”
An ironic example: In preparation for our interview, Mr. Nunnikhoven looked up the dictionary definition of “privacy,” he told me. “And when I went to the Cambridge Dictionary website, it popped up with a notification saying that Cambridge and its 679 partners” store and access digital data. To get to the definition, you have to click “I accept.”
Okay, my online activity is being tracked. But so what? I’ve got nothing to hide, right? I bet you’ve heard (or said) that before.
This, said Prof. Bennett, is a red herring. “Everybody’s got something to hide. Everybody deserves some privacy.”
What can they do with this information?
This trail of data bread crumbs we leave, often unknowingly, can be used in ways that would make the 2005 version of your head spin.
With surveillance pricing, sellers set different prices for the same goods or services for different people shopping at the same time. These price adjustments aren’t about the inventory (overstocked, end-of-season, the colour is unpopular) but about the shoppers – their habits, finances, likeliness to buy, based on data that has been collected.
We’re used to surge pricing with, say, airline fares – even if we don’t like it. But different prices for tangible goods? Paying a higher price because, say, you have wealthy Facebook friends? That seems to have been a bridge too far for public trust. Okay, we’ll tick the boxes; okay, we’ll give you our e-mail address; okay, we’ll sign up for the newsletter. But you’re going to use that information – to charge me more for something?
Davi Ottenheimer, a cybersecurity expert based in the U.S. and Germany, suggested an experiment: Go into incognito mode and get your price. Then go back to your regular search method. Different price? That’s when it hits you, he said. “They’re using my identity to price me up, and that takes like 30 seconds to just see if you’re being tracked and priced.”
Mr. Ottenheimer, founder of the security consultancy flyingpenguin, is the one who likes the term “stalk market.” Because while surveillance can be useful in certain contexts, stalking is an ethics violation.
Opinion: The privacy threat that AI poses isn’t what it learns. It’s what it figures out
Various factors can affect the price differences and it’s hard to know who is doing what, as the information is proprietary. But here’s one example – never proven, but the subject of much speculation: You are trying to order a ride, but your battery is low, which is detected on the other end, so there is knowledge of your urgency, even desperation. Up goes the price.
There’s even concern about brick-and-mortar stores getting into this game, by replacing price tags with electronic shelf labels that perhaps work with a store’s app.
You may hear some justify this as a positive practice: People of lesser means can pay less than the rich.
But that would suggest a benevolent marketplace. What we have here is a way for Big Tech/Big Data to help Big Retail squeeze as much as possible out of us by using data to determine how much we are willing to pay. Data provided by you and me. And disseminated by AI faster than you can read this sentence.
“Your privacy is what stands between you and this wave of people trying to take as much as possible from you,” said Mr. Ottenheimer.
We need regulation
Last April, Alberta’s official List of Electors – which contains personal information of 2.9 million Albertans – was posted online in a shocking data breach.
Here’s why it might not have been that shocking (but you should still be shocked): Most of what led to the leak was above-board. Registered political parties have legitimate access to the List of Electors, including the pro-independence Republican Party of Alberta, from which the leak was alleged to have originated, triggering investigations. However, the Centurion Project, the pro-independence advocacy group that Elections Alberta said posted the list, does not. Lists are distributed only to political parties and elected officials and must not be shared. Further, political parties, federally and in most provinces, are exempt from privacy laws. There is a campaign to change that, which the government – and the parties – are resisting “very strenuously,” Prof. Bennett said.
The Elections Alberta data breach raised concerns about privacy and safety.Ahmed Zakot/Reuters
In his recent testimony to the House and Senate on the issue of privacy protection for political parties, Prof. Bennett pointed to what he calls the total inadequacy of Bill C-25, the Strong and Free Elections Act. The new Bill-36, the Protecting Privacy and Consumer Data Act (PPCDA), also fails to cover political parties. That bill is a significant overhaul meant to modernize the outdated Personal Information Protection and Electronic Documents Act (PIPEDA) and touted as protection against surveillance pricing. (Manitoba, meanwhile, has introduced legislation to ban the practice, which it calls “personalized algorithmic pricing.”)
But the proposed system will see a new commission oversee the private sector, taking that responsibility away from the Office of the Privacy Commissioner. Prof. Bennett argues that under such a system, accountability for the privacy issue will be fragmented and made unnecessarily complicated. He is also concerned that there is no real international parallel on which Canada can model this system.
The bill has passed first reading and is heading to second reading in the fall.
Then there’s Bill C-22, which has passed third reading and is headed to the Senate. The Lawful Access Act would give police and CSIS access to more digital information more quickly and force tech companies to retain metadata for six months (reduced from one year, as originally proposed). Big Tech and civil liberties groups don’t like it. Cybersecurity experts warn against storing all that metadata.
Maybe we should be more up in arms about the fact they have all this information to begin with. As Mr. Ottenheimer put it: “You can’t leak what you can’t gather.”
Privacy out in the world
Digital surveillance has invaded our IRL world – for security, we’re told. Which is great. I’m all for criminals getting caught. But at what point does the surveillance itself become – or at least feel – criminal?
Or creepy.
“You are potentially being tracked constantly,” Levan Lobzhanidze, a data-protection lawyer with the European privacy NGO noyb (none of your business), told me.
There is the controversy over Flock cameras, which use AI to read licence plates – ostensibly to catch criminals. Beyond the mass, indiscriminate surveillance, there are fears information can get into the wrong hands – or be used for nefarious purposes, including by immigration authorities.

An automatic license plate reader camera monitors traffic in Silver Spring, Maryland.Chip Somodevilla/Getty Images
There’s also concern about secondary, money-making uses. In grocery stores, for instance, to track shopping habits. Are white middle-aged women more likely to buy lemons? On a mass scale, such observations can become sellable information.
There are privacy concerns related to Meta’s smart glasses, with cameras built into the Ray-Ban frames. Among other issues, the AI-equipped specs make it easy to surreptitiously record – or live-stream – unsuspecting passersby. Glasses are far less obvious than cellphones, which themselves have cut into our privacy in the world.
And our phones – are they listening to us? Beyond when we prompt them by conjuring Alexa or Siri? Is that how the internet knew about my hallway problem; was it listening to my conversation? There is no hard evidence proving this, I’m told. But what is happening might be scarier. “The algorithms have become so sophisticated that they practically don’t need to listen to you to actually understand your interests or which products to push to you,” Mr. Lobzhanidze said.
Another weird thing happened to me while writing this. I have no need for a new toaster. However, for this story, I typed the word “toaster” into a Word document, connected to an online server. Then, boom, two hours later, Facebook Marketplace served me up a listing for a Breville toaster oven.
Coincidence?
What can we do?
With each successive interview, I became more distressed. “We’re doomed!” I think I said to each person.
But here is some helpful info I gathered along the way regarding how we can protect ourselves.
Obviously be careful about sharing personal details online. But also practice good computer hygiene: clear your cache, clear your history, and use a search engine that doesn’t capture your search information (DuckDuckGo for instance). Use a VPN. Use ad blockers. If you have accounts for social-media platforms you don’t use, cancel them. If you don’t have to subscribe to buy something, don’t. Use encrypted messaging, such as Signal. Use two-factor authentication. Use a pass-key. Or at least alter your passwords. Mr. Ottenheimer suggested creating a new e-mail address – and thus a new online identity – for each store.
Sure, some of this may sound like a hassle. But as Ms. Howell put it to me: The things that make it easy for us also make it easier for bad actors to target us.
Opinion: Can Ottawa save you from the scourge of surveillance pricing?
Above all, regulation is key, even if tech will always be ahead of legislation. Laws should oblige organizations to treat personal data with care, to only collect it for reasonable purposes and to not disclose it without restrictions. Europe’s General Data Protection Regulation (GDPR) is a good model. Article 25 offers data protection “by design and by default.” The European Convention on Human Rights recognizes privacy as a fundamental right.
“The most important thing individuals can do to protect themselves is to understand which politicians are in favour or against their rights to privacy,” said Mr. Lobzhanidze, from Vienna. “And vote based on that.”
Reader, I am buying the entryway table. I need it. My current one is too large for the space; it’s a hazard! And the internet, somehow, knew this. It did its work to separate me from my cash, while at the same time making me feel good about the purchase. Another bullish day for the stalk market.
Editor’s note: A previous version of this article incorrectly stated that Prof. Colin Bennett gave testimony to the House and Senate regarding Bill C-36. He gave testimony on Bill C-25.

