The second story beneath the screen

It is 6.42 in the morning. A reporter leaves the bus two streets before a meeting, records a few establishing shots, checks a message from a confidential source and opens a map because the entrance is through a courtyard. Afterwards, she photographs a document, edits a thirty-second trailer, sends it to the newsroom and orders a car. One device does everything.

On the screen, a story about abuse in a local institution is taking shape. Beneath the screen, another story is being written: location, time, contacts, device identifiers, files, cloud copies, applications and the regularity of the route.

The scene is hypothetical; its architecture is ordinary. In the visible version, the smartphone is a reporter’s Swiss Army knife. In the invisible version, it is a meticulous secretary who does not always work only for us. This is not the cinematic claim that a phone is secretly listening to every word. It is the more prosaic fact that digital services produce and process traces, and that traces assembled together can reveal more than one message.

MoJo training asks whether the battery is charged, the lens clean and the microphone alive. One less photogenic question now belongs on the list: what will this device record about the story before the story is published?

Two productions in one pocket

Oscar Westlund describes the smartphone as a tool that combines searching, source contact, recording and publication, radically increasing what journalists can do in the field (2013, pp. 16–17). In one study he cites, ‘journalists accepted being located when on duty’ (Westlund, 2013, p. 17). The sentence sounds almost administrative: the desk sees who is nearest a fire and dispatches them quickly. Yet location is both coordination and surveillance. The same capability may assist, discipline or expose.

A smartphone therefore produces two kinds of material. The first is intentional: video, sound, text and photographs. The second emerges from using the infrastructure. It includes data about data and behaviour: when a file was created, where a device connected, which accounts participated in its movement, what permissions applications held and who gained access. One item may be banal. A series becomes a pattern.

José van Dijck uses datafication for the transformation of aspects of life into processable data, and dataveillance for surveillance based on systematic data collection (2014). The change of perspective matters. We need not imagine an individual in a dark room following a dot on a map. An infrastructure can generate traces automatically and make them available to organisations with different interests, safeguards and business models.

This is the hidden bargain behind convenience. A feature solves a real reporting problem while creating information about how the problem was solved. The newsroom sees a finished clip. The surrounding ecosystem may see a journey, a social graph, a recurring place and the hour at which an account becomes active.

The reporter as a data object

Salzmann et al. (2021) show how a mobile journalist can become a traceable data object. A smartphone is not a neutral box containing applications; it operates inside an ecosystem designed partly to collect, combine and monetise behavioural data. Journalists face a distinctive risk because traces may reveal not only their own habits, but also their sources and the direction of an investigation.

The mosaic effect is crucial. A source’s name may appear nowhere. Repeated visits to a small institution, the time of contact, a cluster of numbers and the type of document can nevertheless narrow the field. Anonymising one file does not remove context from the entire environment. It resembles painting over a house number in a photograph that still displays the street name, a distinctive mural and a bus-stop sign.

A Polish guide produced by NASK notes that news organisations hold contact details, correspondence, investigative material and other assets attractive to attackers, while smaller outlets may be particularly exposed because they have fewer resources (Adamczyk et al., 2025). It recommends separating professional and private spheres and using protected communication channels. This is not a taste for paranoia. It is the digital equivalent of locking the newsroom door – except that there are more doors, and some of them come with terms longer than a weekend.

The mosaic is not produced by one villainous application. It can emerge across operating systems, cloud storage, transport apps, payment records, photographs, calendars, mobile networks and editorial platforms. No single provider needs the whole story for the whole story to become reconstructable. Security therefore cannot be reduced to choosing a fashionable encrypted messenger and congratulating ourselves.

The source pays for somebody else’s convenience

Cybersecurity discussions often cast the reporter as the owner of the phone and potential victim. Journalism ethics must turn the camera around. The highest cost may be carried by somebody who did not choose the device,

application or cloud policy. A whistle-blower agreed to trust a journalist. That is not automatic consent to a chain of technological intermediaries.

Research on mass surveillance and confidential sources suggests that awareness of monitoring can change journalists’ communication practices and discourage contact (Waters, 2018). Harm can arise without a proven breach. If a potential source believes that speaking will leave too many traces, they may remain silent. This is the chilling effect in its cleanest form: democracy loses information before anybody has the chance to record it.

Imagine an employee in a small public office, one of three people with access to a particular set of documents. After publication, managers may not need the content of an encrypted conversation. Time, place and the relevant circle of staff may be enough. Her job, family safety or professional standing may be at stake. The reporter risks losing a source. Society receives a message addressed to the next possible whistle-blower: better not speak.

Source protection is not a courtesy. It is a condition of press freedom. A promise of confidentiality includes reasonably foreseeable routes to identification, not simply omitting a name from the article. It also includes the humility to admit what a newsroom cannot guarantee. ‘Completely anonymous’ is not an ethical promise when the system beneath it has never been mapped.

A freelancer cannot be an entire security department

The tempting response is that journalists should be careful. Of course they should. But the phrase often moves responsibility from an organisation to the person with the least power. A freelancer must buy the device, find the story, film, edit, publish, run social channels, submit an invoice, read service policies, model threats and remember where the microphone adaptor went. At some point, multitasking stops being innovation and becomes an elegant name for institutional loneliness.

Research into the information security cultures of journalism shows that protective practices depend not only on individual knowledge, but also on norms, resources, technical relationships and organisational support (Crete- Nishihata et al., 2020). Individual data minimisation and tool choice matter, but

have limits; a newsroom needs a security culture, training and procedures that bring journalists, legal advisers and technical specialists into the same process (Salzmann et al., 2021).

Responsible innovation asks more than whether a phone can publish faster. It asks whose interests were considered, which effects were anticipated and who has authority to stop the workflow. A phone may be cheap to buy and expensive in consequences. The invoice does not always arrive at the newsroom.

Human-centred responsibility therefore has two levels. The reporter makes careful operational choices. The organisation supplies tools, expertise, time and an escalation route. If an editor insists on speed while refusing the resources needed for safety, the risk is an editorial decision, not a personal failure by the person holding the device.

The Minimum Trace Protocol

No set of settings fits every story. A stadium reporter, a corruption investigator and a journalist under state repression inhabit different threat environments. The MINIMUM TRACE PROTOCOL is not a shopping list of magical applications. It is a structured conversation before, during and after a story.

1. Name the people and assets. List what requires protection: a source’s identity, conversation, meeting place, unpublished document, journey, raw recording or newsroom account. For each item, record who would be harmed by disclosure and how severely. ‘Sensitive’ is too vague; protection begins with particulars.

2. Define a realistic threat. Who might want the data, and what legal, organisational or technical powers do they possess? Not every football interview needs the highest controls. A story about a powerful institution, violence, organised crime or repression requires specialist advice. Do not improvise a threat model on publication day.

3. Collect less. Remove unnecessary applications and permissions; limit automatic backups and retention ‘just in case’. Every additional copy and recipient increases exposure. Minimisation is not the careless

deletion of evidence. It is a deliberate decision about what must exist, where and for how long.

4. Separate roles. Keep work and private accounts, profiles and – where risk justifies it – devices apart. Separation makes automatic linking harder and limits the impact of one compromised account. It must be genuine: a second phone synchronised to the same personal cloud is a second screen, not a second security zone.

5. Design contact with the source. Agree a channel, contact rules, copies, deletion periods and a plan for unexpected silence. Use methods proportionate to the threat and supported by the newsroom. Do not promise perfect anonymity when you cannot define the boundaries. An honest risk conversation respects the source’s autonomy more than heroic reassurance without foundations.

6. Review location and metadata. Before a meeting, decide whether location services are needed and what traces transport, payment, photography and synchronisation may create. After recording, inspect the information attached to the file before it reaches an editor or audience. Removing a visible map pin is not enough; consider the whole flow.

7. Map the material’s route. Draw a simple chain: device → application → cloud or server → edit → publication → archive. Beside each arrow, name the owner, access rules and retention period. This is a data-flow dossier. If nobody knows where a file lands after ‘send’, the newsroom has hope, not a process.

8. Prepare for an incident. A reporter must know whom to contact if a phone disappears, an account behaves strangely or a source reports danger. The procedure should cover preservation of evidence, containment, legal advice and communication with the source. The first response cannot be a message in the general chat asking whether anybody is ‘good at cyber’.

9. Give risk an owner. Every high-risk story needs a named person with authority to allocate resources, delay work and stop publication. That owner cannot automatically be the reporter merely because the phone is in their hand. A management choice about production speed is also a safety choice.

The protocol passes only when the source understands the material limits of protection, the reporter can explain the data route, and somebody with institutional authority has accepted the residual risk. A ticked form without those three conditions is stationery performing security theatre.

A one-page field audit

Turn the protocol into a short pre-departure card. Record the topic and date; exposed people; critical data; risk level; approved devices and channels; settings to inspect; storage location; people with access; retention date; risk owner; emergency contact; and the source’s informed agreement after discussing the limits of confidentiality.

After publication, reopen the card. Which traces remain? What must be securely archived for evidence or accountability? What should be removed under the retention policy? Did any tool create an unexpected copy? Has the risk to the source changed because the story prompted attention?

This audit is not bureaucracy for its own sake. It is like a memory card for the camera: mainly annoying when it is missing. Documentation also allows a newsroom to learn from incidents without hunting for a culprit. If the same weakness appears in several stories, the organisation can see that its infrastructure needs repair, not another email telling staff to be vigilant.

For a genuinely urgent event, the audit can be abbreviated, but never simply imagined. A two-minute verbal check with a named editor is better than nine boxes completed retrospectively. Afterwards, the record should be reconstructed while memories are fresh.

The limits of minimisation

Leaving no trace at all is usually impossible. Tools change and documentation may be incomplete. Restricting one category of data can obstruct reporting or create false confidence. Encryption protects content under defined conditions; it does not automatically secure an endpoint, every copy, user behaviour or the fact that contact occurred.

Security can also conflict with documentation and accountability. Evidence must not be deleted reflexively. Retention should account for public interest, legal duties and the safety of the people involved. High-risk decisions need competent advice, not a universal list copied from the internet.

The protocol does not transfer responsibility to the source. Asking why a whistle-blower used an ordinary phone resembles asking a victim of theft why they had a pocket. Reporter and source can agree a safer method, but the newsroom remains responsible for its own systems and promises.

Nor may ‘security’ become a reason to deny vulnerable people a voice. Some sources possess only a basic device, use shared internet access or cannot install a recommended application. A human-centred newsroom adapts the method, explains the trade-off and looks for proportionate safeguards. It does not reserve source protection for the technically fluent.

No tool can remove all risk. The ethical goal is informed, proportionate reduction with responsibility attached. Residual uncertainty should be visible to the decision-makers; it should not be silently exported to the source.

The most important shot may be invisible

MoJo rightly promises lightness. A reporter no longer needs a transmission van, five cases and a crew resembling a small orchestra. Light equipment does not mean light responsibility. The more functions concentrated in one object, the more ethical questions are concentrated with them.

Before filming, journalists check the frame: what entered on the left, what grows out of the interviewee’s head, whether the operator appears in a reflection. Datafied reporting requires a second frame – the map of traces, recipients and dependencies invisible on screen.

A good mobile journalist can tell the world a story with one phone. A responsible newsroom makes sure the phone does not tell the world the story of the source. Technology serves human freedom when it expands the ability to bear witness without quietly turning witnesses, journalists and informants into raw material for somebody else’s system.

References

  1. Westlund, O. (2013). Mobile news: A review and model of journalism in an age of mobile media. Digital Journalism, 1(1), 6–26. https://doi.org/10.1080/21670811.2012.740273
  2. Waters, S. (2018). The effects of mass surveillance on journalists’ relations with confidential sources: A constant comparative study. Digital Journalism, 6(10), 1294–1313. https://doi.org/10.1080/21670811.2017.1365616
  3. Salzmann, A., Guribye, F., & Gynnild, A. (2021). Mobile journalists as traceable data objects: Surveillance capitalism and responsible innovation in mobile journalism. Media and Communication, 9(2), 130–139. https://doi.org/10.17645/mac.v9i2.3804