The Privacy Documents Attached To Just One Family’s Digital Day Would Take Almost 10 Workdays To Read – Longer Than The Complete Works Of William Shakespeare

Web3 Foundation researchers created six modeled households, read the privacy policies and terms linked to an ordinary modeled day – and found that they describe capabilities and permissions for potential data collection, profiling, sharing and retention across everyday digital activity
The modeled US family household is linked to 81 organizations across its day.
· Across the US models, the modeled devices and systems may generate thousands of body readings and, where ACR is enabled in the single-adult and retiree scenarios, tens of thousands of television screen captures.
· In the modelled US family, school-managed devices may generate minute-by-minute monitoring records, while a family location-sharing service is modelled as making a child’s location available around the clock.
· Out of the organizations in the study, the documents of 83% describe the ability to use personal data for marketing or advertising, 80% to combine it with other information, 71% to pass it to commercial partners, and at least 24% have documents stating that user data may be used to train or improve AI or machine-learning systems.
Zurich, Switzerland | 28 September 2026: A modeled US family would require almost 10 full workdays to read the privacy documents surrounding the digital services and systems used in just one ordinary modeled family day, a new study by Web3 Foundation has found.
For the modeled US family, the relevant privacy policies, terms and notices total 233 documents and 1,118,224 words. That is 78.3 hours of reading – 9.8 eight-hour workdays – and 26% more than the 884,647 words contained in William Shakespeare’s complete works.
A US single working adult scenario involves 188 relevant documents containing 848,062 words and 59.4 hours of reading. Even the modeled US retiree, who uses fewer digital services, is linked to documentation requiring more than 37 hours – 4.6 full workdays – to read.
Released to mark UNESCO’s 2026 International Day for Universal Access to Information, the study, Everyday Surveillance: What One Ordinary Day May Reveal About You, modeled the everyday products, services and systems surrounding six evidence-based model households in the United States and United Kingdom and then did what consumers ae supposed to do: read the privacy documents.
Across the six US and UK model households, researchers identified 1,195 relevant privacy policies, terms, notices and supporting documents containing more than 5.38 million words. Analyzing them created a picture of routine digital life in which a model household may be observed through phones, wearables, televisions, banks, cars, schools, utilities, cameras, health services and location systems, with those systems potentially creating separate records and many organizations’ documents describing further potential uses of that information.
The study does not claim to be a national survey or to describe the practices of every or any user. It examines documented capabilities and permissions across evidence-led model scenarios and, where relevant, states modelling assumptions about product choice, settings, configurations and system operation.
Gavin Wood, founder of Web3 Foundation, said: “We did what consumers are told to do: we read the privacy policies. For one ordinary US family day, that means nearly ten workdays of reading. What we found in that fine print was much bigger than a collection of individual privacy notices. It described how information about people’s bodies, homes, money, movements, children and behavior can be combined, inferred, shared, retained and, in some cases, used to train AI. Disclosure is not meaningful control if a person has no realistic chance of reading it.”
Bill Laboon, Vice President of Technical Operations at Web3 Foundation, said: “What is striking is how much data may be generated around completely ordinary digital activity. The report raises the question of whether we can build services differently, for example, by allowing people to prove what is needed without routinely disclosing the underlying information.”
The US family scenario was linked to 81 organizations during an ordinary weekday. The adults’ wearables are modeled as generating approximately 2,000 potential daily heart-rate readings. School-managed devices may generate minute-by-minute monitoring records, including which tabs are open and device location. The model estimates approximately 79 combined school-camera captures of the two children during the day, with the White Paper giving a narrative range of 40–120 depending on movement through the building. In the model a family location-sharing service is assumed to make a child’s location available 24 hours a day; and the model estimates that a family car may be recorded two to six times by roadside license-plate readers, in addition to the collection of vehicle location and driving data.
For a US single working adult, the study identified 62 organizations, around 219 modeled processing events and 485 described information items. In the model around three hours of television can generate approximately 21,600 screen observations where Automatic Content Recognition is assumed to be enabled, while a fitness wearable may produce roughly 1,000 heart-rate samples.
Routine movement during the day may add an estimated 20 to 80 private doorbell or yard-camera clips, overlapping location records from phones, maps and connected cars, and the scenario identifies 12 companies whose documents indicate that they may hold voice recordings. In the modeled scenario, one linked financial-data connection may make up to 24 months of transaction history available through a single action.
The modeled scenarios indicate that high volumes of potential data collection can also arise where technology use is relatively limited. In the modeled US retiree’s day, around five hours of television is modeled as producing roughly 36,000 automatic screen observations where Automatic Content Recognition is assumed to be enabled. The day also includes an estimated 25 to 65 camera captures, 24 to 96 smart-meter readings, commercial license-plate records, health and pharmacy information and the scenario also includes the documented potential for USPS Informed Delivery to provide scanned images of the address side of eligible incoming letter-sized mail.
Across the 143 organizations examined, documents of 118 (83%) describe potential use of data for marketing or advertising; 114 (80%) describe potential combining data across sources; 109 (76%) describe potential inference or profiling; 102 (71%) describe potential sharing with commercial partners as defined by the study; and 95 (66%) state no fixed retention period. Separately, the documents of at least 35 organizations (24%) contain an affirmative statement that user data may be used to train or improve AI or machine-learning systems.
The data trail may extend far beyond names and email addresses. Across the organizations reviewed, 55 of 143 (38%) list particularly sensitive categories among information they could collect, including health, biometrics, sexual orientation, political opinions, ethnicity or religion. Separate data points can then potentially be linked or used to infer information about a person’s body, home, finances, movements, relationships, children, beliefs, interests and likely future behavior.
Potential data collection or generation can also occur when no screen is being actively used. Wearables may measure the body during sleep, smart meters may record household activity through the night, doorbells and cameras may remain active, connected devices may synchronize in the background and connected cars may transmit location and driving telemetry. A person may experience one drive to work, one television program or one payment; the systems around them can experience the same activity as repeated measurements, identifiers, timestamps, images, location traces and behavioral signals.
The US model operates within a patchwork of federal sectoral and state protections. As of September 2026, the United States has no single comprehensive federal consumer privacy law. The legal protections for the same information can therefore depend on who holds it, which state a person lives in and how the data is being used.
Health data illustrates how the legal protection can differ. The White Paper notes that HIPAA protects health information when handled by covered healthcare organisations and certain companies working for them, but does not automatically cover every health detail stored in a consumer app or personal device. The legal protection applying to the same heart-rate reading or symptom can therefore differ depending on where it is held.
The White Paper proposes six design principles aimed at reducing disclosure. These include revealing only the information a service actually needs, for example age not date of birth, allowing people to hold reusable digital proofs rather than repeatedly copying identity documents, making permissions clear and easy to withdraw, and using selective disclosure so a fact can be verified without handing over the full underlying dataset.
Methodology at a glance
Web3 Foundation built six evidence-based model households: a working adult, a family with two children and an older adult living independently in both the UK and US. Researchers mapped a normal 24-hour weekday against the products, services and systems around each household and what those systems say they may collect, generate or infer, using company policies, technical documentation, regulator records, academic research and published measurement studies.
The study does not claim to be a national survey or to describe the practices of every or any user. It examines documented capabilities and permissions across evidence-led model scenarios under stated modelling assumptions about product choice, settings, configurations and system operation. Company policies show what an organization says it may collect or process, rather than proving that every permitted action happens to every or any user every day. Numerical findings are presented as documented minimums, modeled estimates or reasonable ranges.
. International Day for Universal Access to Information: The White Paper is being released on 28 September 2026, which coincides with UNESCO’s International Day for Universal Access to Information. The 2026 theme is “Upholding Information Integrity in the Digital Age: The role of access to Information in addressing Information Disorder”.
2. Shakespeare comparison: The Folger Shakespeare Library, citing Marvin Spevack’s concordances, states Shakespeare’s complete works at approximately 884,647 words. The largest US scenario contains 1,118,224 words of relevant privacy policies, terms, notices and supporting documents, approximately 26% more than Shakespeare’s complete works.
3. Reading-time calculation: The White Paper calculates reading time at 238 words per minute, using the average silent reading rate for nonfiction identified in Brysbaert’s 2019 meta-analysis. The largest US scenario requires 78.3 hours, or 9.8 eight-hour workdays, to read. The US single-adult scenario requires 59.4 hours (7.4 workdays) and the US retiree scenario 37.1 hours (4.6 workdays).
4. Use of the term “surveillance”: In the White Paper, ‘surveillance’ means the systematic generation, observation, recording or inference of information about a model person or model household. The term describes an information process, not a legal conclusion or allegation of wrongdoing. It includes records created for safety, public services, administration, commerce and security as well as advertising or behavioral monitoring.
5. Policy status: The analysis reflects company terms, privacy notices and other relevant documents publicly available and reviewed between August and September 2026, with the legal and regulatory position checked to 18 September 2026. The methodology, assumptions and supporting data are published as part of the study so the calculations, source choices and analytical approach can be scrutinized, challenged and rerun by others.
About Web3 Foundation
Web3 Foundation supports a fairer internet built on systems that are more distributed and give people greater control over their data and identity. It funds research and development of decentralized web software protocols and supports technologies designed to give users greater control over identity, data, digital assets and online interactions.

