The government is preparing a plan that threatens to tear apart the already fragile boundary between public health and civil liberties, pushing the country towards a permanent surveillance infrastructure disguised as pandemic preparedness. At the heart of the new strategy lies a contact tracing system built not on voluntary participation or decentralised technology, but on location data harvested directly from the world’s largest tech companies. The proposed system, scheduled for deployment by the end of the decade, represents a fundamental shift in how the state would monitor its citizens during health emergencies.
The UK Health Security Agency has been tasked with developing a real-time population movement monitoring capability, one that stands ready to be activated the moment a new threat emerges. The underlying assumption driving this project is that future epidemics are not a matter of if, but when. In response, the government is constructing a technological apparatus that would use location data analysis and artificial intelligence to instantly detect disease clusters and alert individuals who may have crossed paths with an infected person. While the strategy explicitly states that data would be sourced from major technology firms, it conveniently leaves out any mention of which companies would be involved or what the terms of such partnerships would look like. Even more concerning is the complete absence of any answer regarding what happens to location histories once a health crisis is declared over.
The government is building a location surveillance system in partnership with companies whose entire business model depends on hoovering up as much personal data as humanly possible.
This is not a new idea suddenly materialising out of a policy vacuum. During the COVID-19 pandemic, British authorities had already dipped their toes into mobile data tracking to analyse public behaviour. Researchers linked to the University of Oxford conducted studies involving thousands of individuals whose movements were monitored without their knowledge. Those analyses covered everything from post-vaccination mobility patterns to visits to public spaces and daily routines. The details of these operations only emerged later, sparking widespread condemnation. Big Brother Watch warned at the time that such practices risked eroding public trust and normalising mass surveillance under the guise of emergency measures.
A spokesperson for Big Brother Watch made clear that no one showing up for a vaccination would reasonably expect to be tracked and monitored by their own government. They described it as deeply disturbing and warned it could cause immense damage to public confidence in medical confidentiality. Drawing a direct line between the infrastructure of Covid passports and the surveillance of citizens during vaccination appointments, they argued that the government was systematically turning the UK into a panopticon state under the cover of a pandemic. They stressed that this should have served as a warning sign for everyone.
The government continues to insist that the data it uses is anonymised and fully compliant with privacy regulations. But this is a hollow reassurance. Even aggregated location information is often granular enough to reconstruct a person’s daily life, revealing where they live, where they work, and the rhythms of their routines. Privacy experts have repeatedly pointed out that when combined with other datasets, mobile mast data can produce an extraordinarily detailed portrait of individual behaviour. The new system would not only entrench these capabilities but elevate them to a permanent feature of the state’s technological infrastructure.
Britain has already attempted to build a centralised contact tracing system once before. The initial version of the NHSX app was plagued by resistance from privacy advocates and technical failures. Apple and Google effectively blocked its functionality due to its centralised architecture, forcing a humiliating retreat. The project was eventually abandoned in favour of a less invasive, decentralised model. Now, the new strategy signals a return to the centralised approach, only this time with even deeper involvement from private technology firms.
The timeline for implementation is set for 2030. By then, the government aims to have built the full technological stack, secured the necessary legal frameworks, and formalised partnerships with the private sector. But the road to that date is fraught with unanswered questions about consent, oversight, and the long-term consequences of normalising location surveillance as a routine tool of governance. What happens when a system designed for health emergencies outlasts the emergencies themselves? History has shown that powers justified by temporary crises have a tendency to become permanent. And in this case, the stakes are nothing less than whether the UK will drift into a future where the state tracks where you go, who you meet, and how you move – not because it suspects you of anything, but simply because it can.