Published by
1 link
Graph · Publication
01 · In focus
The structured facts the source records about Invisible Infrastructures: Surveillance Architecture, the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.
publication
↑1 declared connection
02 · Connections
Split by direction. Direct links are the ones Invisible Infrastructures: Surveillance Architecture’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity.
1 link
Links named in this entity's structured fields.
1 link
03 · Background
Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.
Invisible Infrastructures: Surveillance Architecture is a data investigation published on 9 March 2015 by SHARE Lab — the research and data investigation unit of the SHARE Foundation led by Vladan Joler — documenting how Serbia's four largest telecommunications providers (Telekom, Telenor, VIP, and a fourth operator) allow state bodies systematic access to subscriber metadata. The investigation draws on approximately 2,000 pages of documents and reports obtained through Freedom of Information Act requests submitted in April 2014 to Serbia's Commissioner for Information of Public Importance and Personal Data Protection, and is grounded in the Commissioner's own 2012 inspection reports on how telecoms were implementing the Law on Personal Data Protection in relation to police, civil intelligence, and military intelligence agencies.
The investigation is built from primary administrative documents rather than from whistleblower testimony or secondary reporting. SHARE Lab submitted FOIA requests in April 2014 to Serbia's data protection Commissioner, obtaining the underlying inspection files that the Commissioner's office had gathered from the four carriers during a 2012 enforcement review. The resulting approximately 2,000 pages documented the specific metadata fields each carrier retained, the technical architectures enabling state access, and the legal bases claimed for each mechanism. This document-first approach — treating the regulator's own inspection record as the primary source — gives the investigation unusual evidentiary density for the civil-society research genre.
The investigation identifies four distinct mechanisms by which state bodies access subscriber metadata across Serbia's four largest telecoms:
Request-response. Standard submissions by state bodies via email, fax, or telephone, to which the carrier responds by producing the requested records. The investigation treats this as the legally grounded baseline mechanism.
Independent access portals. Online portals through which police and intelligence agencies query carrier databases directly — without routing individual requests through the carrier — enabling direct lookups without court orders.
Automated daily metadata transfer. One carrier delivers a full daily metadata extract from its Mobile Switching Centre directly to the Security Intelligence Agency (BIA) on an automated, standing basis — without a per-request trigger.
Direct infrastructure access. At least one carrier has granted BIA a direct connection into its network infrastructure, enabling interception capabilities below the request-response level.
The investigation explicitly flags the final two mechanisms as having no legal grounds in Serbian electronic communications legislation, characterising them as active threats to user privacy in conflict with existing law. The metadata retained across carriers includes caller and called numbers, IMEI, base station details, call timestamps and durations, data volumes, service types, and identifiers for both parties — data sufficient for real-time physical tracking through base station triangulation and, in some documented cases, via custom mobile tracking devices issued by carriers to state organs.
Surveillance Architecture is the seventh and final entry in the Invisible Infrastructures seven-part series published by SHARE Lab in February and March 2015, which also includes investigations into autonomous systems, Serbia's internet map, internet packet routing, mobile app permissions, online trackers, and data flow architectures. The series as a whole represents SHARE Lab's foundational research output — an effort to render the invisible technical and legal infrastructure of digital life legible to civil society, journalists, and policymakers. Surveillance Architecture is the entry that garnered the most sustained attention because of its documentary grounding: where the series' other entries work from publicly available technical knowledge, this one is built on state administrative records obtained through formal legal process. Vladan Joler was recognised by the Mozilla Foundation in 2016 as one of 50 people who made the internet a better place, with SHARE Lab's data investigation work — including this series — as the cited basis.
Invisible Infrastructures: Surveillance Architecture is the corpus's first civil-society publication from the Balkan region, closing the geographic gap left by prior Publications entries concentrated in the United States, United Kingdom, and Western Europe. It represents a publication-shape distinct from the legal-advocacy reports (A Hazard to Human Rights, Losing Humanity), the academic-framework texts (Anatomy of an AI System), and the mapping surveys (Automating Society Report 2020): a forensic document investigation turning an administrative inspection record into a public accountability artefact. The finding that two of Serbia's four major telecoms were providing BIA with legally unauthorised automated data access — documented through the regulator's own files — is the kind of primary-source disclosure that grounds subsequent campaign and litigation work by organizations like SHARE Foundation and its partners. It is also an early instance of the methodology that SHARE Lab would extend across its subsequent investigations into Facebook's data architecture and Amazon's digital labour supply chain: using FOIA, data mapping, and network visualisation to make extractive infrastructure visible to those it operates on.
04 · Sources
3 sources listed from the pinned corpus. Links are shown only when the source URL is a valid HTTP(S) address.
SHARE Lab primary source for the investigation — publication date March 9, 2015 (updated April 6, 2016); primary source for the FOIA methodology (approximately 2,000 pages of documents obtained from April 2014 requests to Serbia's Commissioner for Information of Public Importance and Personal Data Protection); names Telekom, Telenor, and VIP as three of the four carriers examined; identifies four surveillance access mechanisms and explicitly flags the automated BIA data delivery and direct database access as lacking legal grounds; CC BY-NC-SA licence
SHARE Lab biography of Vladan Joler — primary source for his role co-founding and leading SHARE Lab as a research and data investigation unit of SHARE Foundation; confirms he directed the Invisible Infrastructures series and the surveillance architecture investigation specifically; notes his co-founding of SHARE Foundation in 2012 and directorship through 2017; Mozilla Foundation named Joler among 50 people who made the internet a better place in 2016 in part for this work
SHARE Lab publications index — confirms Invisible Infrastructures as a seven-part series published February–March 2015 (Understanding Autonomous Systems; Internet Map of Serbia; The Exciting Life of Internet Packet; Mobile Permissions; Online Trackers; Data Flow; Surveillance Architecture); Surveillance Architecture (March 9, 2015) is the final and most cited entry; CC BY-NC-SA licence across the series
Source: entities/publications/pub-share-lab-invisible-infrastructures.md — movement-graph pin 5d136ad.