Imagine you and your neighbour buy the same groceries, from the same supermarket, on the same day, but you pay more. The prices were adjusted based on what you could afford and what you are willing to pay, based on your data.This is surveillance pricing: a system where prices are determined based on the individual and their willingness to pay. This is not surge pricing, where supply and demand influence prices. This is price discrimination on an individual level. We have seen versions of this play out in physical supermarkets in the US and in online stores like Zepto in India.How the ‘nothing to hide’ argument failsDebates on privacy are often brushed off with the statement: “I don’t have anything to hide.” This implies that if one is not doing anything questionable as per societal norms, they need not worry. But privacy is not about “having something to hide.” It is about recognising that our lives contain aspects that we may not want others to know.You may not want your children to see your search history. You may not want your employer to know about your menstrual data. You may not want your parents to know about your financial commitments.When pricing is individualised through data, users are participating in a system that may extract greater value from them than from others. In such a setting, consent becomes difficult to meaningfully exercise. Users may click through permissions without understanding that their information can be used to determine prices, targeting and access.India’s privacy challenge: digitisation without digital literacyIn India, identity and digital services are interlinked. Our digital services heavily rely on sharing personal information that connects us to our banks, mobile numbers and other sensitive information, putting us at a higher risk of data misuse.The challenge before us is not only in having privacy-protecting laws or systems but in whether they can be implemented. In a recent visit to an institution, I was asked to share my Aadhaar. When I attempted to use the masked Aadhaar format, which replaces the first eight digits with “xxxx-xxxx” and shows only the last four digits needed for verification, the request was initially declined. I was allowed to proceed only after discussion and escalation.Also read: The Government’s Advice to Exercise ‘Normal Prudence’ With Aadhaar Is Confusing and DangerousMasked Aadhaar is recognised by UIDAI as valid. The point is that privacy safeguards depend on implementation. It is dependent on whether systems have privacy-respecting alternatives and whether staff are trained to use them correctly.This is how privacy battles become hierarchised. Those who know the rules can fight their way, while others, often the most marginalised, risk exposing themselves.What could go wrong?In the world of data-driven pricing and profiling, privacy becomes the ability to decide what you share and with whom. The same data that determines what you pay can also be used to determine what you are paid. This is called algorithmic wage discrimination.As legal scholar Veena Dubal explains, it is a practice in which individual workers are paid different wages, calculated using data, behaviour, demand and supply, for broadly similar work. The system has learned who is desperate, who is reliable, and who cannot afford to say no.In December 2014, an Uber driver raped a woman in Delhi. The company’s head of Asia Pacific at the time obtained the survivor’s confidential medical records and claimed her complaint was an attempt to destroy Uber’s name and business.Similarly, researchers from Cambridge University have found that period data is over 200 times more valuable than age or demographic data for targeted advertising, and can be used for stalking, insurance discrimination, employment decisions and even limiting access to abortion.Recently in the United States, Missouri’s health department tracked the menstrual cycles of patients to investigate “failed abortions”. They monitored medical ID numbers, gestational age and procedure dates. The Office of Refugee Resettlement tracked menstrual cycles of unaccompanied minors seeking asylum to prevent them from accessing abortions, even in case of rape.Also read: AI Companions Are Exploiting Human Intimacy and India Needs a LawThese cannot be dismissed as isolated incidents. They are the result of a system that treats personal data as a commodity that can be sold and bought without consent.Not paranoia, but threat analysisThe conversation around privacy is not intended to induce panic but to inform. However, the risks are different for each of us. It is important to do a threat analysis to help decide how and what precautions we should take. Threat analysis means identifying what you want to protect, from whom and why, and then taking precautions accordingly. This is important as risks are different for each of us based on profession, region, gender and other identities.Another healthy practice is to move towards free and open-source applications (FOSS). Such apps allow anyone to access the code of the application, much like you can see the ingredients before deciding if you want to consume any packaged food item you buy. FOSS is open for anyone to see, inspect and verify. That is the difference between blind trust and informed consent.To start, go to your phone settings and check what data each app has access to. Your Gmail account does not need your camera. Your photo app does not need your contacts. Your fitness tracker does not need your location when you are not using it. Turn off what is not essential.We do not have to disappear from the internet. We need to demand transparency, accountability and control over what we can do online and what can be done to our data. It means building digital literacy alongside digital access. It means teaching people not just how to use apps but how to assess risk, how to choose tools and how to protect themselves.Until then, the question is not “do you have something to hide?” The question is: “Do you have the right to control how your data is used, especially when it directly affects how you live?”