Studio Matrx Monthly · Volume 1 · Issue 4 · September 2026
Amogh N P
 In loving memory of Amogh N P — Architect · Designer · Visionary 
Privacy, Surveillance & EquityLesson 8.3
Urban Digital Twins/Module 8 · People, Governance & Ethics

Lesson 8.3 · People, Governance & Ethics

Privacy, Surveillance & Equity

A living model of a city, fed by cameras, sensors and movement data, is by its nature a system that watches - so privacy, consent, algorithmic bias, the invisible informal city and the digital divide are not footnotes to the twin but the gravest questions it raises

12 min Interactive lessonFree · open lessonByAmogh N P· Architect & interior designer
The hook

A twin that can show you the city as it really is, right now, must be watching the city - so the real question is not whether it watches, but who it watches, who decides, and who it never sees at all

Everything that makes an urban digital twin powerful - that it is live, that it reflects the real city as it actually is, that it knows where the traffic is jamming and which blocks are crowded and how people move - depends on watching. A twin is fed by cameras, by sensors, by mobility traces, by occupancy counts, by the digital exhaust of a connected city. You cannot have a living mirror of a place without, in some measure, surveilling it. That is not an abuse of the technology; it is the technology. Which is exactly why privacy, surveillance and equity are not ethical add-ons to be bolted on at the end. They are the core of what a twin is.

This lesson confronts the gravest concerns in this course without flinching. A poorly governed twin can become an instrument of mass surveillance, watching people who never consented in a way no one could have watched them before. Its models can carry bias that quietly disadvantages the already-disadvantaged. Its data can render the informal city - the street vendors, the unregistered settlements, the gig workers who are so much of an Indian city - invisible, and what a twin cannot see, a city can forget. And access to the twin itself can follow the digital divide, so that it serves the connected and comfortable while watching, or ignoring, everyone else. We will not defer these concerns to a footnote. We will defer only the binding legal specifics - how data may lawfully be handled - to the governing law, including India's Digital Personal Data Protection Act, and to counsel.

A living mirror must watch to live. Who it watches, who it serves, and who it never sees - that is the whole ethics of the twin.

The twin as a surveillance system

Begin with the hardest truth stated plainly: an urban digital twin fed by real-time data is, structurally, a surveillance system, whatever its intentions. To show movement it must track movement; to show occupancy it must count people; to reflect the live street it may ingest camera feeds, vehicle positions, phone-derived mobility, transit taps and more. Individually these feel mundane. Integrated into one living model, they become something qualitatively new: a single, continuously updated, spatial picture of who is where, when, and doing what, at a scale and granularity no human watcher could ever achieve. Mass surveillance has historically been limited by the cost of watching; a twin can dissolve that limit.

The danger is not only deliberate abuse - though that is real, and a twin built by a state or a vendor without strong limits can be turned to tracking protesters, minorities, or ordinary people going about their lives. The subtler danger is function creep: a twin built for traffic management or energy optimisation, with its watching infrastructure already in place, is a short political or administrative step away from watching for other purposes. The sensors are installed; the integration exists; the temptation to repurpose is constant. This is why privacy cannot be a setting toggled at the end. It has to be designed into the architecture from the start - what is collected, at what resolution, how long it is kept, whether it is aggregated or individual, who can query it and for what.

The discipline that answers this is privacy by design: minimise what you collect to what the purpose genuinely needs; prefer aggregate and anonymised data over individual-level data wherever the purpose allows; limit retention; constrain access by role and purpose; and build in audit so misuse can be detected. A twin does not need to know who you are to manage traffic - it needs to know how many vehicles, not which driver. Much of the privacy risk in twins comes from collecting and keeping individual-level data that the actual purpose never required, simply because it was available. The honest designer's instinct is the opposite of the data-hoarder's: collect the least that serves the purpose, keep it the shortest time, and treat every camera and sensor as a civil-liberties decision, not just a technical one. How data may lawfully be collected and handled is set by the governing law - defer those specifics to the law and counsel - but the design instinct to minimise and protect is yours to hold.

A twin is only as complete as its dataSeen: the formal citymetered, addressed, sensored -> crisp dataMissed: the informal citystreet vendors?informal settlement?thin or absent data -> faint or invisible
Zoom
Who the twin sees, and who it misses. The formal city - metered, addressed, sensored - shows up in sharp detail. The informal city - street vendors, unregistered settlements, gig workers - is thin or absent in the data, so a twin built on official data can render it invisible.

To show movement, it tracks movement. A twin watches by design. Minimise, aggregate, limit, audit - or it becomes a panopticon.

Privacy, consent and the limits of anonymisation

Privacy in a city twin is genuinely hard, and it is worth being honest about why rather than offering false comfort. The first difficulty is consent. The classic model of privacy - you are asked, you agree - largely breaks down in public urban space. You cannot meaningfully ask every pedestrian on a street for consent to be counted by a sensor, and people cannot opt out of walking through their own city. This does not make consent irrelevant, but it means a twin cannot lean on individual consent the way an app can; it must rely far more on strict purpose limitation, strong governance, legal authority and public accountability for what is collected and why. The question shifts from did this person agree to is this collection lawful, necessary, proportionate and accountable.

The second difficulty is that anonymisation is weaker than it sounds. It is tempting to believe that stripping names makes data safe, but location and movement data are notoriously re-identifiable: a handful of time-stamped locations can single out an individual, because the pattern of where you go - home at night, work by day, the same clinic every week - is itself an identifier. Aggregated data helps, but aggregation done carelessly can still leak individuals, especially in sparsely populated areas or for unusual patterns. This is not a reason for despair, but it is a reason for humility: a designer should never assume that because data has been anonymised it is therefore harmless, and should treat movement and location data as inherently sensitive even when names have been removed.

The third difficulty is the chilling effect and the shift in the citizen-state relationship. A city where people know, or suspect, that their movements feed a model watched by authorities is a different kind of city - one where people may alter their behaviour, avoid assembly, or feel permanently observed, even if no specific harm ever befalls them. Privacy is not only about preventing concrete harms; it is about preserving the freedom and dignity of not being watched, which is part of what makes a public space genuinely public. A twin that erodes this quietly, in the name of efficiency, changes the character of the city even when it is never misused. The governing data-protection law - in India, the Digital Personal Data Protection Act, 2023, and the wider regime - sets the binding rules for lawful handling, and those specifics belong to the law and to counsel; but the designer carries the prior duty to treat the people in the model as people with a right to privacy, not as data points to be maximised.

Who gains, who bears the cost, who can even reach it?Benefitservices, investment,flood protectionBurdensurveillance, displacement,being unseenDigital divide gates who can access the twin at all
Zoom
The equity question has two edges. A twin can direct benefit (services, investment, protection) toward some and concentrate burden (surveillance, displacement, neglect) on others. The digital divide decides who can even access the model. Asking who benefits and who bears the cost is the work.

Bias, the invisible informal city, and the digital divide

Surveillance is the danger of being seen too much. Equity raises the opposite and equally serious danger: being seen too little, or seen wrongly. A twin is built on data and models, and both encode choices that can entrench injustice. Algorithmic bias enters when the data a twin learns from, or the models it runs, reflect existing inequalities - so a twin optimising traffic flow might systematically favour car-owning commuters over pedestrians and cyclists; one optimising investment or property value might steer resources toward already-wealthy districts; one trained on historical patterns might bake in historical discrimination. The model looks objective - it is just maths on data - and that apparent neutrality is precisely what makes its bias dangerous, because it launders contested political choices into the authority of a dashboard.

The sharpest equity problem, especially in India, is the invisible informal city. A twin can only model what its data captures, and enormous parts of a city generate little formal data: informal settlements without addresses or meters, street vendors with no registered premises, the cash economy, daily-wage and gig workers whose lives leave few official traces. These are often the most vulnerable residents and the largest share of an Indian city's population - yet a twin built on formal, official data can render them statistically invisible. And what the model cannot see, decision-makers can forget: resources, protections and plans flow toward what is measured, so invisibility in the twin can translate into neglect in the real city. A twin can thus quietly encode a city for its formal, measured, well-sensored minority while erasing the informal majority - a profound equity failure that no amount of technical sophistication fixes, because it is a failure of what was counted, not how well it was computed.

The digital divide adds a third edge. Even where a twin is used for public benefit or participation, access to it - and to the connectivity, devices and literacy needed to engage with it - is unevenly distributed. A twin that serves citizens through a portal or an app serves those who can reach it, which in India and elsewhere skews toward the urban, connected, literate and comfortable. So the twin can concentrate benefit on the already-advantaged while the disadvantaged bear its burdens (surveillance, displacement from projects the model justifies, neglect from being unseen) without its benefits. The equity question is therefore double: who does the twin watch, and who does it serve? A just twin is one whose benefits and burdens are fairly distributed, which actively works to see the informal city rather than erase it, and whose models are audited for bias rather than trusted because they look like objective computation. None of this is automatic; all of it has to be chosen.

A twin is only as complete as its dataSeen: the formal citymetered, addressed, sensored -> crisp dataMissed: the informal citystreet vendors?informal settlement?thin or absent data -> faint or invisible
Zoom
Who the twin sees, and who it misses. The formal city - metered, addressed, sensored - shows up in sharp detail. The informal city - street vendors, unregistered settlements, gig workers - is thin or absent in the data, so a twin built on official data can render it invisible.

Seen too much = surveillance. Seen too little = erased. A dashboard that looks objective can launder injustice into maths.

Toward a just twin - and the Indian stakes

None of this counsels abandoning the idea - a well-governed twin can genuinely help a city, including its most vulnerable, by making flooding, heat, pollution and service gaps visible and actionable. The point is that justice in a twin is a set of deliberate commitments, not a default. Several are worth holding. Data minimisation and privacy by design: collect the least that serves the purpose, prefer aggregate over individual data, limit retention, constrain access, and audit use. Purpose limitation against function creep: bind the twin's watching to its stated purpose and require explicit, accountable authorisation to extend it - the traffic twin must not quietly become a tracking system. Active inclusion of the informal city: treat the gaps in the data as a known bias to be corrected through fieldwork, community mapping and participatory data, not as an acceptable blind spot, so the unmeasured are not erased. Bias auditing: test whose interests the twin's models actually serve, and surface the value choices hidden inside apparently neutral optimisation. Equitable access and benefit: ensure the twin's benefits reach those who bear its burdens, and do not let the digital divide turn it into a tool for the comfortable.

Crucially, these are partly technical but mostly governance and accountability commitments - which is why this lesson sits between data governance (8.2) and the question of control (8.4). Privacy, anti-surveillance safeguards, bias auditing and inclusion all require someone accountable to citizens to decide, to be transparent, and to be answerable - they cannot be guaranteed by a vendor optimising a platform. A twin's ethics live in its governance, not its graphics.

The Indian context sharpens every edge of this. India's cities are substantially informal, so the invisible-city problem is not a marginal concern but central: a twin that cannot see the informal economy cannot fairly serve an Indian city. The digital divide, though narrowing, remains vast across income, gender, language and region. Surveillance concerns are serious where watching infrastructure is deployed at scale under smart-city programmes. And the legal framework - centred on the Digital Personal Data Protection Act, 2023 - is still maturing, shaping what lawful handling of personal data requires. The honest, rigorous position for a designer is to hold privacy, anti-surveillance discipline and equity as first-order design responsibilities; to actively design against invisibility and bias rather than assume the data is fair; to treat every sensor and camera as a civil-liberties choice; and to defer the binding legal specifics of lawful data handling to the governing law, the regulators and legal counsel - while never using that deferral as an excuse to stop caring. The law sets the floor; the designer's conscience and the public's rights set the standard.

Verify-this: privacy and lawful handling defer to the law; the duty to care does not

Digital Personal Data Protection Act, 2023 (India) & applicable data-protection law

Lawful collection, handling and rights over personal data

The binding rules for lawful handling of personal data are set by the governing law. Defer the legal specifics to the law, the regulators and legal counsel; treat the law as the floor, not the ceiling.

Privacy by design & data minimisation

Building privacy into the twin's architecture

Collect the least the purpose needs, prefer aggregate over individual data, limit retention and access, audit use. A design discipline, not a legal mandate - but the practical core of a non-surveilling twin.

Purpose limitation against function creep

Stopping a traffic twin becoming a tracking system

Watching should be bound to its stated purpose, with explicit accountable authorisation required to extend it. Governance principle; the specifics of lawful purpose rest with the law and the accountable authority.

Equity, bias auditing & inclusion of the informal city

Who the twin serves and who it erases

Gaps in the data (informal settlements, vendors, gig workers) are a known bias to correct, not an acceptable blind spot; models should be audited for whose interests they serve. Illustrative best practice, context-dependent.

Hands-on workshop

Workshop - a privacy, surveillance and equity audit of a twin

The skill this lesson builds is seeing the watching, the bias and the invisibility that the graphics hide. In this workshop you audit a real or proposed twin for its surveillance risk, its bias, the city it cannot see, and who it actually serves.

A twin or sensing deployment you can read about, this lesson, and the two figures. No software - this is ethical and equity reasoning, not modelling.

Given & goal
Goal: a clear-eyed audit of a twin's privacy, surveillance and equity risks
Inputs: a real or proposed city twin / smart-city sensing deployment you can read about + this lesson + the two figures
Time: ~50 minutes
  1. 1Map the watching: list what the twin senses (cameras, mobility, occupancy, transit, phones) and at what granularity. For each, ask: is this individual or aggregate, how long is it kept, who can query it, and could it be re-identified?
  2. 2Test for function creep: what is the stated purpose, and what else could this watching infrastructure be used for? Is there an accountable limit stopping the traffic twin becoming a tracking system?
  3. 3Hunt the bias: what does the twin optimise for, and whose interests does that quietly favour (car-owners vs pedestrians, wealthy vs poor districts)? Where might the model launder a political choice as neutral maths?
  4. 4Find the invisible city: who and what generates little data here (informal settlements, vendors, cash economy, gig workers)? What would the twin fail to see, and what neglect could that invisibility cause?
  5. 5Weigh benefit vs burden: who gains from this twin and who bears its costs (surveillance, displacement, being unseen)? Does the digital divide gate who can access it? Write a one-paragraph verdict and the single change that would make it more just - as reasoning, with lawful-handling specifics left to the law and counsel.

You’ll walk away with
A one-page audit: the watching map, function-creep risk, the bias, the invisible city, and the benefit-vs-burden verdict with one decisive equity fix. Keep it - it feeds directly into the question of who controls the twin.

The worked example

Three altitudes on the same idea

Read the band that fits you — or all three.

For the architect / urban designerDesigning in the city's living model and its data context

When your project contributes to or draws on a city twin, you are handling data about people and places, and the equity and privacy stakes are part of your professional responsibility. Practise data minimisation: design sensing into schemes to collect the least that serves the purpose, prefer aggregate over individual data, and treat every camera or sensor you specify as a civil-liberties decision, not just a building-services one. Be alert to the invisible informal city - when you model a site in the twin, ask who and what is not in the data (the vendors on that footpath, the settlement behind that wall) and resist letting the model erase them from your reasoning. Watch for bias in optimisation that quietly favours the car, the wealthy block, the measured over the unmeasured. Defer the binding lawful-data-handling decisions to the governing law (including India's DPDP Act) and counsel; own the instinct to design for the people in the model, not to surveil them.

For the interior designerHow building data and the wider twin connect to interiors

Sensing occupied space is where privacy gets most intimate - and building twins increasingly watch how people use rooms. Occupancy, movement, presence and environmental sensors in workplaces, homes and public interiors can feed comfort, energy and operations, but they also watch people in spaces where they reasonably expect privacy. Apply privacy by design rigorously: collect the least the purpose needs, prefer counts over identities, prefer aggregate over individual tracking, be transparent with occupants about what is sensed and why, and limit retention and access. Remember that data from an occupied interior can flow upward into building and city twins, so the governance you set at room scale matters beyond the room. Coordinate the binding data-protection and lawful-handling decisions with the engineers, owners and legal counsel; your domain is a humane interior that serves its occupants rather than surveilling them.

For the studentHow a city becomes a living, data-connected model

Understand that a live city twin is, by its nature, a watching system - then learn to ask the three equity-and-privacy questions: who does it watch, who does it serve, and who does it not see at all? Grasp privacy by design and data minimisation (collect the least the purpose needs), the weakness of anonymisation for movement data, and function creep (a traffic twin is a short step from a tracking system). Understand algorithmic bias - how an apparently objective model launders contested choices - and, most importantly for India, the invisible informal city: a twin built on formal data can erase the street vendors, informal settlements and gig workers who are much of the city, and what the model cannot see, a city can forget. Add the digital divide, which decides who can even access the twin. You are not expected to write the privacy law; you are expected to use the twin's outputs critically and always ask who it serves and who it harms.

Misconception check

Privacy and surveillance worries about city twins are overblown: as long as the data is anonymised, nobody is really being watched, and the model is just neutral maths on data, so it cannot be biased or unfair. The ethical concerns are edge cases, not central to how a twin works.

Every part of that is mistaken, and the mistakes are exactly the ones that let harm happen. First, a live twin is structurally a surveillance system - to show movement it must track movement, to show occupancy it must count people - so watching is not an edge case but the core of how it works; the real questions are who it watches, who decides, and whether watching is minimised, purpose-limited and audited against function creep. Second, anonymisation is far weaker than it sounds: location and movement data are notoriously re-identifiable, because the pattern of where you go is itself an identifier, so stripping names does not make movement data safe, and it should be treated as inherently sensitive. Consent, the usual safeguard, largely breaks down in public space - you cannot ask every pedestrian - so protection must come from purpose limitation, strong governance, legal authority and accountability, not from a consent checkbox. Third, a model is not neutral maths: the data it learns from and the objectives it optimises encode value choices, so a twin can carry algorithmic bias that favours car-owners over pedestrians or wealthy districts over poor ones, and its apparent objectivity is what makes the bias dangerous, because it launders political choices into the authority of a dashboard. Worst of all is invisibility: a twin built on formal data can render the informal city - street vendors, unregistered settlements, gig workers, much of an Indian city - statistically invisible, and what the model cannot see, decision-makers can forget. Privacy, bias, invisibility and the digital divide are first-order design and governance questions, not footnotes. The binding legal specifics of lawful handling defer to the governing law (including India's DPDP Act) and counsel - but the duty to care does not.
Try it

Do it yourself

No tools needed - reason it through.

  1. 1Why is a live urban digital twin, by its nature, a surveillance system - and what is 'function creep'?
  2. 2Why does individual consent largely break down in public space, and what must protect privacy instead?
  3. 3Why is anonymisation weaker than it sounds for movement and location data?
  4. 4What is the 'invisible informal city' problem, and why is it especially serious in India?
  5. 5Explain the double equity question: who does the twin watch, and who does it serve?
Take this with you

The one line to carry out

A live twin is structurally a watching system, so privacy, anti-surveillance discipline, bias auditing and the inclusion of the invisible informal city are first-order design and governance responsibilities - the twin can surveil people it never asked, erase the informal majority it cannot measure, and serve only those on the right side of the digital divide, unless justice is deliberately designed and governed in.
Take it further
References & further reading

Peer-reviewed journals & authoritative standards

  1. 01SurveillanceWikipedia - Surveillance, 2026.
  2. 02Information privacyWikipedia - Information privacy, 2026.
  3. 03Algorithmic biasWikipedia - Algorithmic bias, 2026.
  4. 04Digital Personal Data Protection Act, 2023Wikipedia - Digital Personal Data Protection Act, 2023, 2026.
  5. 05Digital divideWikipedia - Digital divide, 2026.
Related lessons
Recap
Everything that makes a twin powerful - that it is live and reflects the real city - depends on watching, so a twin fed by real-time data is structurally a surveillance system, and privacy, surveillance and equity are its core questions, not add-ons. Integrated sensing creates a continuously updated picture of who is where and when at a scale no human watcher could achieve, with function creep a constant danger as a traffic twin's infrastructure is repurposed; the defence is privacy by design and data minimisation - collect the least the purpose needs, prefer aggregate over individual data, limit retention and access, and audit use. Privacy is genuinely hard: consent breaks down in public space so protection must come from purpose limitation, governance, legal authority and accountability; anonymisation is weak because movement data is re-identifiable; and surveillance changes the character of public space through the chilling effect, harming dignity even when never misused. Equity raises the opposite danger - being seen too little or wrongly: algorithmic bias launders contested choices into an apparently neutral dashboard; the invisible informal city (street vendors, unregistered settlements, gig workers, much of an Indian city) can be rendered statistically invisible so that decision-makers forget it; and the digital divide gates who can access the twin at all, concentrating benefit on the advantaged while the disadvantaged bear the burdens. A just twin requires deliberate commitments - minimisation, purpose limitation, active inclusion of the informal city, bias auditing, equitable access - which are mostly governance and accountability, not graphics. In India the informality, the divide, scaled surveillance infrastructure and the maturing DPDP Act sharpen every edge. The binding legal specifics of lawful handling defer to the governing law and counsel; the duty to care does not.
Carry forward →

Privacy, anti-surveillance safeguards and equity all come back to one question: who gets to decide? Who builds, owns, operates and decides with the twin determines whose privacy is protected, whose city is seen, and whose interests the model encodes. Next we ask, directly, who controls the twin.

A

The author

Amogh N P

Architect, interior designer, and creative polymath. Studio Matrx began in his notebooks — his vision of design made honest, useful, and open to everyone. Its Academy is written and taught in his memory, and free, forever.

More about Amogh →