# You Didn't Agree to the App. You Were Just Standing Next to Someone Who Did.

2026-09-11 · Sherrerd Hall · Princeton University, Princeton, New Jersey · Event

A Princeton seminar on "the bystander privacy problem" points to a growing weakness in the way technology treats consent: one person can choose the device while everyone nearby becomes part of the data.

A Princeton seminar on "the bystander privacy problem" points to a growing weakness in the way technology treats consent: one person can choose the device while everyone nearby becomes part of the data.

---

Privacy has a second person now

Privacy has traditionally been presented as a transaction between a person and a system. You install the app. You create the account. You click the box. You decide whether the camera gets access to your photos, whether the microphone can listen, whether the car can upload diagnostic information or whether a device can learn from what it sees around you. That model has always been imperfect, but it at least has a recognizable main character: the user.

The problem is that many newer technologies do not observe only the person who bought them. They observe environments. A camera mounted beside a front door can record a delivery driver, a neighbor and a child walking a dog. A parked car can keep exterior cameras ready to record activity around it. Smart glasses can photograph or record people from the wearer's point of view. A headset can signal to the room that its cameras are being used. In every case, the owner made a technology choice and someone else became part of what the technology could see, hear or store.

That second person is the bystander, and privacy scholar Helen Nissenbaum is bringing the problem to Princeton on September 15.

The Center for Information Technology Policy will host Nissenbaum, the Andrew H. and Ann R. Tisch Professor of Information Science at Cornell Tech and Cornell's Bowers College of Computing and Information Science, for a seminar titled "The Bystander Privacy Problem." Princeton's description starts with Meta Ray-Ban smart glasses, which it says have drawn public ire over bystander privacy, but the larger issue is not one particular pair of glasses. It is the privacy framework underneath an entire class of products.

The seminar is an advance, not a verdict. Nissenbaum's full argument has not yet been delivered publicly. But Princeton's event description makes the direction unusually clear: she plans to examine what she calls a conceptual failure in privacy thinking and to offer contextual integrity as an alternative. More provocatively, the description says she will argue that treating bystanders as a special privacy category may actually reinforce assumptions that should be questioned more broadly.

The notice is not the permission

The easiest way to see the problem is to look at the signals technology companies already build for people who did not buy the device.

Meta says its AI glasses activate capture LEDs when a wearer takes photos, records video for a gallery or livestreams, and says users should ask permission from people around them before capturing. The company also says the glasses prevent photo or video capture if the external capture light is covered. Apple uses the outward-facing EyeSight display on Vision Pro to tell people nearby when the device is taking a spatial photo, recording spatial video, capturing the wearer's view or sharing that view. Tesla says Sentry Mode can display a message indicating that cameras may be recording when the system detects a possible threat around a parked vehicle.

Those are meaningful design choices. They acknowledge that the person outside the account matters but a signal and a choice are different things.

A recording light can tell you that something is happening without giving you any practical ability to stop it. A message on a parked car can provide notice after you are already standing in the field of view. Asking a wearer to seek permission is a social rule placed on the customer, not a permission mechanism controlled by the people being recorded. The bystander is recognized, but the bystander is still not the person operating the system.

Ring's privacy tools illustrate the same imbalance from another direction. Ring allows the camera owner to create privacy zones that block parts of the field of view from live and recorded video, and the company recommends using those tools to respect people nearby. That can be valuable. It also means the protection depends on the person who owns the camera choosing the right boundary for somebody else.

This is where the familiar language of "consent" begins to strain. It works most cleanly when the person affected by the technology is also the person at the controls. Once sensors observe a shared environment, privacy can no longer be reduced to whether the account holder clicked yes.

The bystander exposes the old bargain

Nissenbaum's work has long challenged the idea that privacy is simply control over personal information. Her theory of contextual integrity instead asks whether information flows are appropriate to the context in which they occur: who the information is about, who is sending it, who receives it, what kind of information it is and under what conditions it moves.

Seeing someone standing on a sidewalk is ordinary. A neighbor remembering that you walked past at 7:15 is ordinary. A doorbell camera saving the event to a cloud account is a different information flow. A pair of glasses recognizing that there is a person in front of the wearer is one thing; creating a shareable recording of that person is another. A parked car detecting movement for security is not socially identical to a human sitting inside and watching the same street for hours.

There is no realistic terms-of-service screen for entering a friend's kitchen, walking through a parking lot, sitting beside someone wearing camera-equipped glasses or approaching a connected front door. The environment can contain multiple privately owned systems, each operating under a separate account and separate policy, while the person moving through that environment has no corresponding dashboard showing which systems can observe them.

The practical absurdity is useful because it reveals the structural flaw. Privacy cannot depend entirely on each observed person individually negotiating with every sensor that happens to be nearby.

Convenience can be purchased by one person and paid for by another

The appeal of these devices is not mysterious. Doorbell cameras can help homeowners see who is at the door. Vehicle security systems can document theft or vandalism. Smart glasses can capture hands-free photos, assist with navigation and accessibility, and make computing less dependent on holding a phone. Wearable displays can make digital information feel integrated with the physical world.

This is not a story in which a useless technology invades privacy for no reason. It is a story about benefits and burdens landing on different people.

The buyer receives the convenience. The bystander may supply some of the raw material that makes the convenience possible: an image, a voice, a face in the background, a license plate, a location, a movement through space or simply evidence that they were present at a particular moment.

That does not automatically make every capture harmful or every device illegitimate. It does mean the ethical accounting changes when the person receiving the benefit is not the only person being observed.

Modern consumer technology increasingly turns private purchasing decisions into environmental conditions. Someone else buys the camera, and the sidewalk changes. Someone else buys the glasses, and a conversation now takes place in front of a wearable sensor. Someone else enables a vehicle security mode, and the space around the car becomes part of a security perimeter.

We are accustomed to asking whether a user has accepted the trade. The bystander problem asks whether that was ever the only trade that mattered.

Maybe "bystander" is the warning label on a bigger problem

There is a temptation to solve this by creating a special category called bystander privacy: stronger recording lights, better signage, more obvious camera indicators, narrower fields of view, privacy zones, automatic blurring or new rules for people who happen to be nearby.

Some of those interventions may be useful. But Princeton's description of Nissenbaum's upcoming talk points toward a more disruptive possibility. If bystanders seem uniquely hard to protect, perhaps that is because the prevailing framework is too dependent on individual control in the first place.

The bystander is simply the person who makes the weakness impossible to ignore.

A user can at least be shown a policy, however unreadable it may be. A bystander often cannot. A user can sometimes adjust a setting. A bystander usually cannot. A user can stop using a product. A bystander may have no meaningful way to stop other people from bringing the product into shared space.

Once that becomes common, "you agreed" loses much of its explanatory power. The person affected may not have agreed, may not have been asked, and may not even know which device created the data.

Contextual integrity offers a different question: not merely whether information was technically observable or whether someone clicked a permission box, but whether moving that information from this person, in this place, through this device, to this recipient is appropriate for the situation.

That is a harder standard because it cannot be satisfied by a universal banner. It forces designers, companies, regulators and users to think about relationships and settings, not just accounts.

It also fits the way people actually experience privacy. Most people do not object to being seen by everyone at all times. They object when information crosses a boundary they believed was meaningful: a conversation becomes a recording; a visit becomes a searchable history; a face in the background becomes data available to a system; an ordinary passage through public space becomes persistent evidence of where someone was and when.

You were not the customer, but you were still part of the system

The most important thing about the bystander privacy problem may be that it changes who counts as a participant in technology.

For years, the consumer-technology story has treated the purchaser as the center of the system. Product design begins with the user. Privacy controls belong to the user. Settings belong to the user. Terms are presented to the user. The company-customer relationship is the formal relationship that receives the most attention.

Sensors make that boundary porous.

The people around a device can become subjects of the system without becoming customers of it. They can appear in the camera's field of view, enter the microphone's range or move through a space being analyzed without ever opening an account. Their role is real even when the interface has no button for them.

That is why the Princeton seminar matters beyond Princeton and beyond smart glasses. It is attached to a question that will become more common as cameras, microphones and AI systems move off screens and into ordinary environments: what happens to consent when technology no longer waits for each person to become a user before it can observe them?

The answer probably cannot be another box to click. The bystander did not install the app. The bystander did not buy the glasses. The bystander did not enable the camera.

The bystander was simply there, and increasingly, being there is enough to become part of the system.

EVENT INFORMATION

EventHelen Nissenbaum - The Bystander Privacy ProblemWhenTuesday, September 15, 2026, 12:15-1:15 p.m.WhereSherrerd Hall 306, Princeton UniversityAccessRestricted to Princeton University; Princeton says the talk will not be livestreamed or recorded.

This article is an advance based on publicly available event materials and product/privacy documentation. Nissenbaum's Sept. 15 seminar had not yet occurred at publication time.

SOURCE NOTES

• Princeton University Center for Information Technology Policy / Computer Science - "CITP Seminar - The Bystander Privacy Problem," Sept. 15, 2026. • Princeton School of Public and International Affairs - "The Bystander Privacy Problem" event listing. • Helen Nissenbaum - "Privacy as Contextual Integrity," Washington Law Review. • Cornell Tech - "Nissenbaum Receives NSF Award for Work on Automated Privacy Management Systems," Oct. 11, 2018. • Meta - Responsible Innovation in AI Glasses & Quest. • Ring - Privacy and privacy-zone guidance. • Tesla - Model S Owner's Manual, Sentry Mode. • Apple Support - "What EyeSight shows on Apple Vision Pro," updated Apr. 13, 2026.

---

ProbleMattic is written and maintained by Matthew Kulcsar, a software engineer, project manager, technologist, platform builder, emergency-services-trained helper, grandfather, and lifelong collector of broken systems, odd behaviors, and useful nonsense.
