Your Data Double
How a parallel digital identity is constructed from your behavior — device fingerprinting, browser cookies, location data, and the profile you never consented to.
Learning Objectives
- 1Explain how device fingerprinting, cookies, and location data combine to create behavioral profiles
- 2Distinguish between data you consciously share and data that is passively harvested
- 3Evaluate the accuracy and consequences of data doubles in everyday life
You Have a Twin You've Never Met
Right now, somewhere in a data center, there is a profile that describes you. It contains your approximate location history for the past several years, your spending patterns, your political leanings inferred from what you read, the hours you sleep inferred from when your phone goes dark, your relationship status inferred from who you text most, and hundreds of other data points assembled without you ever filling out a form.
This is your data double — a digital replica constructed entirely from behavioral traces you leave behind. Unlike a social media profile you control, your data double is built by third parties, maintained by companies you've never heard of, and sold to buyers you'll never meet.
Understanding how it's built is the first step to understanding why it matters.
How Device Fingerprinting Works
When you visit most websites, your browser sends information about itself automatically. This includes your browser type and version, your operating system, your screen resolution, the fonts installed on your device, your time zone, the plugins you have installed, and how your graphics card renders specific test images.
Individually, each of these facts is unremarkable. But combined, they create a signature that identifies your device with extraordinary precision. This technique is called device fingerprinting, and it works even when you're in incognito mode, even when you clear your cookies, and even when you use a VPN.
The Electronic Frontier Foundation's "Cover Your Tracks" tool demonstrates this vividly. When you run the test, it tells you whether your browser fingerprint is unique among all the browsers that have visited their site. Most people's fingerprints are unique. That uniqueness is the point — it allows companies to track you across websites without storing anything on your device.
Think About
Think about the last time you cleared your browser history or used incognito mode. What did you believe you were preventing? Based on what you now know about device fingerprinting, how accurate was that belief? What does it reveal about the gap between perceived privacy and actual privacy?
The Cookie Economy
Cookies are small text files that websites store in your browser. First-party cookies — set by the site you're actually visiting — are mostly benign. They remember your login, your shopping cart, your language preference.
Third-party cookies are different. They're set by advertisers and data brokers whose code appears invisibly on thousands of websites simultaneously. When the same tracker appears on a news site, a fashion retailer, a sports blog, and a health information site, that tracker sees every page you visit across all of them. It builds a log: you read about your local team's injury report (interest: sports), then researched flu symptoms (interest: health), then looked at hiking boots (interest: outdoor recreation, likely male 18-35).
This data is combined into a profile, assigned to a unique ID tied to your device, and sold in real-time ad auctions that conclude in about 100 milliseconds — before the page you're visiting has even finished loading.
❓Concept Check
Why are third-party cookies more privacy-invasive than first-party cookies?
▸
Concept Check
Why are third-party cookies more privacy-invasive than first-party cookies?
Third-party cookies are set by advertisers and tracking companies whose code appears across thousands of unrelated websites simultaneously. Unlike first-party cookies that only track your activity on one site, third-party cookies track your behavior across the entire web — assembling a comprehensive profile of your interests, habits, and activities that no single website could build alone. This cross-site tracking is the foundation of behavioral advertising.
Location Data: The Most Revealing Signal
Your phone's GPS is the most intimate data source in the surveillance ecosystem. Location data tells stories that no self-reported form ever could.
Consider what location history reveals: visiting a specific hospital oncology ward on repeated Tuesdays suggests a cancer patient or caregiver. Visits to a planned parenthood clinic can be inferred to relate to reproductive health services. Regular appearances at a specific place of worship reveal religious affiliation. Late-night visits to an unfamiliar address might suggest a relationship. Frequent presence at union halls or political campaign offices reveals organizing activity.
All of this is legal. Apps collect GPS data, often with buried consent buried in terms of service, and sell it to location data aggregators who sell it to data brokers who sell it to employers, insurers, law enforcement agencies, and political campaigns.
The app on your phone asking for "location access to improve your experience" is not lying. It is also not telling you the full story.
Think About
Open your phone's location settings and look at which apps have 'Always On' location access. For each one, ask: does this app need to know where I am at 3am? What might it infer from my location history that I would not want strangers to know? What did you find?
Your Profile Is Not Really You — But It Treats You Like It Is
The data double is built on inference, not certainty. Algorithms make probabilistic guesses: if you searched for "fertility clinics" you're probably trying to conceive; if you visit financial planning websites you're probably approaching retirement age; if you follow certain accounts you're probably conservative or liberal.
These guesses are often wrong. And yet they have real consequences. The profile may cause you to see higher prices for flights or insurance. It may determine whether you're shown job ads. It may flag you for fraud detection systems. Your data double makes decisions about you without your knowledge or appeal.
This is what privacy scholars call the problem of the profile — the data double can harm the real person even when the data is imperfect, because the systems acting on it treat the inferences as facts.
❓Concept Check
What is meant by the 'problem of the profile' and why does the imperfection of data doubles make them more concerning, not less?
▸
Concept Check
What is meant by the 'problem of the profile' and why does the imperfection of data doubles make them more concerning, not less?
The problem of the profile refers to the paradox that inaccurate data profiles can harm people just as much as accurate ones — because automated systems treat probabilistic inferences as established facts. If a credit algorithm incorrectly infers someone is a financial risk based on where they live or what websites they visit, that person faces real consequences like loan denial or higher rates, with no mechanism to challenge the underlying inference. Imperfection compounds the harm because the subject has no way to correct a record they can't even see.
Assignment
Your Data Double Audit
-
Go to panopticlick.eff.org or coveryourtracks.eff.org and run a browser fingerprint test. Record what it says about the uniqueness of your fingerprint.
-
Open your phone settings and navigate to the location permissions section. List every app with "always on" or "while using" location access. For each one, write one sentence explaining what the app might infer from your location history that goes beyond its stated purpose.
-
Visit optout.aboutads.info and note how many companies have a profile on you eligible for opt-out. Write 2-3 sentences reflecting on what this number suggests about the scale of the data broker ecosystem.
Write a 300-word reflection: Who is your data double, and how does it differ from how you understand yourself?

