DATAGOV Blog

Here you can find works in progress, exploratory notes, and thoughts on current affairs in data infrastructures.

Compliance by Design: Reflections from the Surveillance Studies Network Conference 2026

29 July 2026 · Mattéo Bard · #DATAGOV #SSN2026 #PlanetarySurveillance #Interoperability #Biometrics #DataGovernance #GovernancebyDataInfrastructure

From 9 to 12 June, the Université Catholique de Lille hosted the 11th biennial Surveillance Studies Network conference under the theme "Planetary Surveillance." Under said theme, presenters went beyond one context or technology, and instead exploring the many facets of surveillance, covering cases like border regimes in the EU, policing infrastructures around the globe, OSINT use in the day to day, geospatial data use in agricultural development, and interoperability architectures.

Introducing Compliance by Design

I went to Lille to present early theoretical ideas from initial literature reviews on EU biometric interoperability. More especially, DG HOME's interoperability initiative, which connects previously separate EU security databases, (Like the Visa Information System [responsible for tracking visa applications], the Schengen Information System [responsible for tracking police warrants], and more) through a supra-layer that allows data to be copied and cross-referenced between the security databases (See Bellanova et al., 2022 for a more detailed explanation). My core argument is that existing scholarly literature explains how expansions of security systems affect civil liberties, sovereignty distribution at a multinational scale, and reshape fundamental rights; but sparsely analyses how and why expansions in security apparatuses occur at the implementer level. DATAGOV is centered around understanding how governance by data infrastructures happens and understanding how their builders create these infrastructures is key to seeing their impact.

As such, I introduce compliance by design, a rather young concept that I would like to develop more through field research. The concept is meant to run directly counter the GDPR principles of ‘privacy by design’, where novel technologies should build data protection into the system from the outset, arguing that when security experts adopt technical systems, they start from legal constraints and engineer around them.

Compliance by design is a result of a growing innovation logic within the field, where development is seen as inevitable and necessary and thus must be ‘kept up with,’ treating law as a limiter. The interoperability case illustrates this perfectly. Officially, it is "not one database," all the databases remain legally distinct, which is precisely what keeps the interoperability system compliant as it does not repurpose data. However, it functionally behaves as one. That gap between legal form and functional reality is where compliance by design lives.

Conference Highlights

Beyond my presentation, here are some highlights of the sessions I attended. "At the Border" featured research framing eu-LISA and EU border control as experimental infrastructures, a laboratory in which surveillance technologies are trialed on populations with the least power to refuse them. "Migration & Refuge" extended these questions beyond Europe and analyzed biometric interoperability through the eyes of refugee-led organizations in Kenya. A second thread concerned the political economy of surveillance. The "War & Conflict" session examined the commodification of surveillance at arms fairs and how moral distancing is built into data-based conflict early warning systems, while “Intelligence Power” panel framed Big Tech as an intelligence power in its own right. Both illustrating how the private sector plays an important role not only selling technologies but also designing the technologies that are used to govern our society. Therefore, private sector ideas like innovating and efficiency become ingrained, at a data infrastructural level, within the security apparatus.

The final highlight is the doctoral colloquium, which addressed the softer skills research actually runs on: how to write when the writing will not come, how to navigate publishing and grants, how to make your work visible, and how to think about careers inside and beyond academia. What made it invaluable was less the answers than the honesty. Hearing established scholars talk openly about writer's block, rejection, and the slow work of getting recognition is a reminder that these are structural features of academic life. This groundedness illustrates a broader welcoming and warm atmosphere in conference, one where mutual knowledge sharing and positive reinforcement is valued.

What Lille Leaves Behind

I went to Lille to present my early ideas as part of DATAGOV, a project that investigates how governance by data infrastructures shapes our society at a larger scale. I introduced the concept of compliance by design, which is the idea that security experts start from legal constraints and engineer around them, treating law as a limiter rather than a foundation.

SSN provided support for my initial ideas. First, by illustrating how borders work as testing grounds, where data infrastructures are trialed on the populations least able to refuse them, from Schengen to refugee organizations in Kenya. Second, the private sector doesn't just sell surveillance but designs it, embedding logics of innovation and efficiency into the security apparatus itself. Both are compliance by design at scale.

The doctoral colloquium demonstrated the hard side to research, like writer's block, rejection, and lack of visibility. The presenters depicted these issues as structural rather than personal failings and approached it with significant empathy, a wider theme to how SSN was. It is clearly a community united by a common goal to limit surveillance creep and hold political actors accountable. Therefore, aiding and helping one another becomes natural. It was a lovely thing to be part of.