a/internet· 27 September 2026 · 6 min read

What if you could see every time an official looked at your records?

In Estonia you can. Citizens log in to the state portal and see which agency looked at their data and why. A police officer who looked up his future wife, and a medic who looked up a neighbour's ambulance call, both paid fines. Australia holds just as much about its people, and shows them almost none of who reads it.

This is a thought experiment with a working example. It asks what changes when the people being watched can watch back.

The idea

Governments see a lot of us. Tax, health, benefits, address, family, fines. The usual rule runs one way: officials can look at your file, and you can't see when they do.

Flip it. Every time a public servant opens your record, the system writes a line: who, when, and for what reason. You can read those lines whenever you like. If one looks wrong, you ask for an explanation, and someone must give one.

Nothing gets locked. Officials still do their jobs. The only change is that looking leaves a trace the person looked at can see. Rules on paper say "don't browse people's files". A log the person can read makes the rule real.

A country that built it

Estonia runs almost its whole state online. Three pieces make it work.

  • The ID card. Since January 2002 every Estonian carries a mandatory ID card with a chip. It proves who you are online and gives a legally binding digital signature. By September 2021 people had used it to sign more than 1.39 billion documents (Wikipedia, 2026a).
  • X-Road. Instead of one giant database, each agency keeps its own records and they talk to each other over a shared exchange layer, piloted in 1998 and launched in 2001 (Wikipedia, 2026b). Every request that crosses it is signed, encrypted and logged. It handles about 2.2 billion transactions a year (e-Estonia, n.d.-a).
  • Ask once. Citizens give the state a piece of information once, and agencies reuse it rather than asking again (e-Estonia, n.d.-b).

Because every request is already logged, showing it to the person it's about is a small step. Estonia took it. Since 2017 the Data Tracker (Andmejälgija) on the state portal eesti.ee lets people "keep an eye on who is accessing their data, and for what reasons" (e-Estonia, 2019). It started with the population register, the Health Insurance Fund, the Unemployment Insurance Fund and the Social Insurance Board, and the state's information agency built it to connect to any public system that holds personal data (Information System Authority, n.d.). In health, "every patient has the right to see who, when, and why someone has accessed their medical records" (Holm, 2025).

The scale shows why a person can't check this any other way. In one month of 2019 the population register alone answered about 7.3 million queries (e-Estonia, 2019).

Who it caught

Two cases get told again and again in Estonia. A police officer checked the record of the woman he was about to marry. A medic looked up why an ambulance had been called to an address, because a nosy neighbour asked. Both "quickly admitted their wrongdoing, were judged to have shown remorse and have paid a fine" (Numa, 2020). Neither case involved a hacker or a leak. Both were ordinary people with ordinary access, doing what curious people do when nobody can see.

The point isn't punishment. Two fines won't scare anyone. The point is that every official knows the person on the other end can read the log. As one Estonian put it: "If we see any access to our data that we don't understand, we can demand an explanation" (Rang, 2025).

Why Estonia, of all places?

Estonia spent about 51 years under Soviet occupation, from 1940 until it declared independence again on 20 August 1991. It won that back without a war. In the Singing Revolution, crowds sang together at the Tallinn song festival grounds, and on 23 August 1989 about two million people joined hands in a chain from Tallinn to Vilnius (Wikipedia, 2026c).

A people who lived half a century under a state that kept secret files on them came out and built a state that shows you your own file. They didn't choose fewer records. They chose records that point both ways.

They also started from almost nothing. At independence, fewer than half of Estonians had a phone line. With few resources, the leaders chose cheap, open systems, and by 1997 the Tiger Leap programme had connected 97% of the country's schools to the internet (Wikipedia, 2026d).

Then came the test. From 27 April 2007, after a row with Russia over moving a Soviet war memorial, waves of cyberattacks hit the websites of Estonia's parliament, banks, ministries and newspapers (Wikipedia, 2026e). Estonia didn't retreat offline. It hardened its systems, and in 2008 NATO opened its cyber defence centre in Tallinn. When a flaw turned up in 750,000 ID cards in 2017, the state suspended the affected certificates and had people renew them (Wikipedia, 2026a). Trust there isn't blind. It's kept up by fixing things in the open.

Australia: plenty of data, little view

Australians sign in to myGov to reach Centrelink, Medicare, the Tax Office, the NDIS, My Aged Care and more through one account (Wikipedia, 2026f). The data is joined up. What you can't do is open a single page and see which officials, across all those agencies, have looked at your file and why.

Australia has already seen what happens when automated government runs out of sight of the people it acts on. From July 2016 to May 2020, Robodebt matched Centrelink records against averaged Tax Office income and issued debts automatically. About 470,000 debts were wrongly issued. The Federal Court found the averaging unlawful in 2019, and the government settled a class action for $1.872 billion (Wikipedia, 2026g). The Royal Commission reported on 7 July 2023. It called the scheme a "crude and cruel mechanism" that "made many people feel like criminals", and made 57 recommendations (Wikipedia, 2026h).

People on Robodebt couldn't see how the machine reached its number, and had to prove years-old income through an online system many of them couldn't navigate. That's the gap a two-way log closes. When you can see what the system did with your data, a wrong number gets caught by the person it's wrong about, early, instead of by a Royal Commission years later.

What we can do

None of this needs new technology. Government systems already log who opens what, for security audits. The step is showing those logs to the person they're about.

  • Ask for your own log. Any Australian government agency must give you the personal information it holds about you, free, within 30 days (OAIC, n.d.). Ask, too, for its record of who accessed it.
  • Back the rule, not a product. Any power an agency has to look at you should come with your power to see that it looked. Watching, made visible, keeps everyone honest.
  • Keep people in the loop on automation. Every automated decision should show the data it used and name a person who can explain it.

Estonia shows the hopeful part: a small country, rebuilt from almost nothing, made officials visible to the people they serve, and kept its digital state running through cyberattacks and a broken ID chip. The public servant who knows you can see the log looks only when there's a reason. That's not surveillance of officials. It's good manners, written into code.

Sources

  1. e-Estonia. (n.d.-a). X-Road. e-estonia.com
  2. e-Estonia. (n.d.-b). e-Governance. e-estonia.com
  3. e-Estonia. (2019, September 18). Data Tracker: a tool to build citizen trust. e-estonia.com
  4. Holm, P. (2025, September 17). Digital health: a democratic right to control our own data. e-Estonia. e-estonia.com
  5. Information System Authority. (n.d.). Data Tracker. Republic of Estonia. ria.ee
  6. Numa, A. (2020, August 19). I spy with my little eye… privacy! e-Estonia. e-estonia.com
  7. Office of the Australian Information Commissioner. (n.d.). Access your personal information. oaic.gov.au
  8. Rang, A. (2025, October 16). A digital ID can be the best protection against a surveillance state. e-Estonia. e-estonia.com
  9. Wikipedia. (2026a). Estonian identity card. wikipedia.org
  10. Wikipedia. (2026b). X-Road. wikipedia.org
  11. Wikipedia. (2026c). Singing Revolution. wikipedia.org
  12. Wikipedia. (2026d). e-Estonia. wikipedia.org
  13. Wikipedia. (2026e). 2007 cyberattacks on Estonia. wikipedia.org
  14. Wikipedia. (2026f). myGov (Australia). wikipedia.org
  15. Wikipedia. (2026g). Robodebt scheme. wikipedia.org
  16. Wikipedia. (2026h). Royal Commission into the Robodebt Scheme. wikipedia.org

Keep reading