Explain

The Archive Is Already Built

Multiple sources (7)
DeceitExplain

Evidence-first pattern recognition. Sourced to reputable reporting.

August 7, 2026

The Pattern

The dossiers exist. The names are in the database. The movement records are in the cloud. The intercepted communications are on a server in a building someone owns. The archive is already built. The question is not whether it was collected. The question is whether it remains cheap to read.

What deletion assumes

GDPR Article 17 gives you the right to erasure. You request deletion. The holder complies. The data is gone. The model is clean, simple, and built on assumptions that hold for a spreadsheet and fail for a surveillance archive.

Deletion assumes the data is locatable. A dossier of 100 names pulled from Canary Mission into a DHS “tiger team” database — Politico reported the testimony, NBC News confirmed it — is locatable. You can find it. You can request its deletion. The holder can refuse, and the refusal is the political fight. But the data is there to fight over.

Deletion assumes the data is still in a form that can be deleted. A movement-tracking system that logged license plates, locations, and timestamps for a year of protests produces a structured database. The database is deletable. The records are rows. The rows can be purged.

Deletion assumes the holder will comply. This is the assumption that breaks first. A government agency that built a deportation pipeline from a private doxxing database is not going to delete the database because a privacy law says it should. The agency will cite national security, law enforcement exceptions, ongoing investigations, data retention requirements. The deletion request becomes a legal fight that takes years and costs more than the surveillance did. The archive survives the request. The request is the theater. The archive is the reality.

What encryption does that deletion cannot

Encryption does not ask the holder to delete the archive. Encryption asks the holder to make the archive unreadable without a key. The archive still exists. It is just no longer cheap to read.

The distinction matters. The political fight over deletion is a fight over whether the archive should exist. The holder has every incentive to keep the archive — it was expensive to build, it is useful, and the people it tracks are not the people the holder answers to. The political fight over encryption is a fight over whether the archive should be accessible. The holder can keep the archive. The holder cannot keep reading it without producing the key.

This is the cost-imposition theory. You cannot force the holder to delete the data. You can force the holder to encrypt it, so that every access requires a deliberate, logged, accountable act of decryption. The cost is not the encryption. The cost is the friction. A database that can be queried in milliseconds is a database that can be abused in milliseconds. A database that requires key retrieval, decryption, and re-encryption for every access is a database that can only be abused slowly, deliberately, and with a trail.

The EFF’s position is that encryption is a human rights issue. Access Now frames it the same way. Both are correct. But the specific demand for retroactive encryption is narrower: encrypt the archives that were built in plaintext, because the plaintext is the vulnerability, and the vulnerability is the liability.

The plaintext was a choice

The pattern named plaintext liability shifts the burden. It is not the subject’s fault for having data that was exposed. It is the holder’s fault for storing it in a form that made exposure trivial.

Canary Mission built a database of names, photos, and locations. The database was stored in plaintext. When the database was used as a lead source for federal deportation proceedings, the transfer was frictionless — the data was readable, copyable, and portable because it was never encrypted. The plaintext was the choice. The choice made the pipeline possible.

Flock Safety built a network of automated license plate readers that log the movement of millions of drivers. The logs are stored in the cloud. The storage is designed for fast access by law enforcement partners. The fast access is the product. The fast access is also the vulnerability. A database of where every car in a city was at every hour is a database that can be subpoenaed, breached, or sold. The plaintext is what makes all three trivial.

The frame of plaintext liability asks: why was the data stored in a form that made exposure equivalent to publication? The holder chose the form. The holder benefited from the form — fast access, easy sharing, no key management. The subject bore the cost of the form — exposure, breach, deportation. The asymmetry is the pattern. The fix is not to ask the holder to apologize for the asymmetry. The fix is to make the asymmetry expensive to maintain.

Retroactive, not forward-only

Forward-only encryption protects new data. It does nothing for the archive that already exists. A surveillance system that begins encrypting tomorrow leaves a decade of plaintext records readable. The historical archive is the liability. The historical archive is also the asset — it is what the holder built the system to produce.

Retroactive encryption encrypts the existing store. The archive is not rebuilt. It is not purged. It is encrypted in place, so that the records that were once trivially readable now require a key the holder must deliberately produce. The archive still exists. It is just no longer free to read.

The technical details vary. Encryption at rest with key custody separated from data custody is stronger than encryption at rest with the holder keeping the keys. Trusted execution environments are stronger than software encryption. But the political demand is the same at every level: the archive that was built in plaintext must be made expensive to read. The expense is the protection.

Why the holder will resist

A holder that stored data in plaintext for convenience will resist retroactive encryption because encryption-at-rest breaks the fast access the plaintext enabled. The resistance is the tell. A holder that fights encryption of its existing archive is a holder that planned to keep reading it.

The resistance will come dressed in operational language. “Encryption at rest degrades query performance.” “Key management introduces single points of failure.” “Law enforcement partners require real-time access.” Each of these is a statement about the holder’s convenience, not about the subject’s safety. The translation is simple: the holder wants to keep reading the archive cheaply. The subject needs the archive to be expensive to read. The political fight is over the cost.

The holder will also cite law enforcement exceptions. A surveillance database that is encrypted at rest is still accessible to law enforcement — with a warrant, with a key, with a deliberate act. The encryption does not prevent access. It prevents casual, unlogged, unaccountable access. If the holder’s argument is that encryption prevents access, the argument is that the holder needs access without accountability. That is the argument to refuse.

What this establishes

The archive is already built. The lever is not delete. They will not delete it. The lever is cost. Encrypt the archive so the subpoena returns ciphertext. Encrypt the archive so the breach returns ciphertext. Encrypt the archive so the rogue employee, the partnering government, the future administration that inherits the database returns ciphertext unless they produce the key.

The theory is not erasure. The theory is expense. The archive survives. The access does not. The cost of decryption is the protection, and the protection is the right of the subject to have their data exist in a form that is not trivially weaponizable against them.

The question is not whether the archive should exist. It exists. The question is whether it should remain cheap to read. The answer is no.

Patterns in this piece

Sources

Related Essays

Editorial contextCorrectionsReport an error in this piece