What You Read Is Nobody's Business: Libraries, Media Centres and the Memory of Your Loans

Back to the blog
7 October 202612 min read

Introduction: the file nobody thinks to ask for

We worry about our bank statements, our medical records, the cameras in our building. Almost nobody thinks about their library card.

And yet, take five years of borrowing history and you get a portrait of unsettling precision. Divorcing Without Going Broke, borrowed in March. Three books on alcoholism in April. A guide to childhood autism in September, the year your son started primary school. An employment law manual on dismissal, two months before you left the company. An essay on religious conversion. A book on perinatal bereavement. An Arabic course book. A graphic novel you didn't dare buy in a bookshop for fear of running into a colleague at the till.

A borrowing history doesn't say what you are. It says what you were trying to understand — and that is far more intimate. Librarians have known this for a long time: the confidentiality of loans is one of the ethical pillars of the profession, written into the Charte des bibliothèques of the Conseil supérieur des bibliothèques as well as the code of ethics of the Association des bibliothécaires de France (ABF).

Hand holding a US passport above bank cards, a smartphone and a boarding pass

But between the principle and the technical reality lies a world of difference. Integrated library management systems (ILS) keep far more than necessary by default. Digital lending platforms are private services with their own policies. The media centre's free wifi is a collection point. And self-service loan kiosks replace the discreet librarian with a very talkative database.

This guide takes stock of what is actually recorded when you read, sets out what the GDPR requires regarding retention periods, and then offers concrete steps for carrying on reading everything — including whatever makes you uncomfortable — without building up a file.


Part 1 — The inventory: what a library card records

The registration record

Signing up at a municipal or inter-municipal library generally requires:

  • full civil status details (surname, first names, date of birth);
  • postal address, with proof of residence;
  • telephone number and email address;
  • sometimes occupation or socio-professional category, "for statistics";
  • for minors, the identity of the legal guardian and their authorisation;
  • for reduced rates, supporting documents (student, jobseeker, income support recipient, family means-tested rate).

That last point deserves attention: a social tariff is a marker of financial circumstances recorded in your reader file. It circulates between town hall departments when registration is tied to a single municipal services portal (school canteen, after-school care, swimming pool, music school, library).

The transaction history

Every loan, return, renewal and reservation creates a line in the ILS: reader ID, copy ID, timestamp, branch where the loan took place. Technically, that line only needs to exist for the duration of the loan, plus a reasonable period to handle overdues and disputes.

In practice, three situations coexist:

ConfigurationWhat is keptRisk
Anonymisation on return (good practice)Aggregated statistics with no link to the readerMinimal
History kept "for the reader's convenience"A named list of everything you have readHigh
History enabled as an optionNothing by default, everything if you tick the boxUp to you

Many library networks now offer a personal account displaying "my past reading", complete with recommendations. It's pleasant. It is also a file of your reading, hosted in software your local authority does not always control, backed up, replicated, and which often outlives your membership.

Fines, unpaid charges and incidents

Overdues, lost items and named reminder notices make up a parallel history. In some local authorities, unpaid charges are passed on to the debt recovery department, or even to the public treasury, which takes the information outside the library's perimeter. A book lost in 2019 may therefore have left an accounting trace mentioning its title.

CCTV and access control

Large media centres are fitted with cameras (foyers, self-service loan machines, work areas) and sometimes with RFID anti-theft gates that record passages. In university libraries you can add student cards that track entries and exits, group study room bookings and printer usage.


Part 2 — The blind spots: digital, wifi and third-party platforms

Digital lending is anything but anonymous

Borrowing a paper book means an object changing hands. Borrowing an e-book means a file locked by a digital rights management system (DRM) that often requires an account with a third party.

In concrete terms, library digital lending (PNB in France) and the cultural streaming platforms partnered with media centres involve several players: the library, the aggregator, the publisher, the DRM provider, sometimes the maker of your e-reader. Each of them can know part of the equation.

What may be recorded on the platform side:

  • the title borrowed and the date;
  • the device and reading software used;
  • the IP address used for downloading;
  • in some reading apps, your reading progress: pages viewed, time spent, highlighted passages, the point at which you gave up.

This is the most frequently overlooked point. A paper book doesn't know you dropped it on page 40. An e-book does — and it can tell.

Practical rule: paper is the most confidential format in existence. It connects to nothing, doesn't update itself, and reports to no one. For sensitive subjects, it's the right choice.

If you read a lot digitally, go for an e-reader capable of displaying locally loaded files, and switch off its synchronisation when it isn't needed. An e-ink reader used offline, fed with your own files, tells nobody anything. A clip-on reading light, incidentally, makes paper just as comfortable as the backlit screen you were trying to avoid.

Two blue Ukrainian biometric passports and a red card lying on a white surface

The media centre's wifi

A library's public wifi is an internet access service. As such, the operator — here the local authority or its contractor — is subject to obligations to retain connection data. Depending on the set-up, add to that:

  • a captive portal asking for an email address, a phone number (with an SMS code) or your library card credentials;
  • logs linking your MAC address to the times you were present;
  • sometimes footfall counting by detecting the wifi signals of phones, even when they aren't connected.

In other words: a search session from a public workstation or the media centre's wifi can link your identity as a reader to your online activity. Remember to switch off wifi and Bluetooth when you're not using them, and to enable MAC address randomisation, available on recent mobile operating systems.

Open-access computers

Public computers are generally reset after each session, but not always. Check three things before you leave: that you have genuinely logged out, that history and downloads have been cleared, and that no USB stick has been left in the tower. For documents you carry around, a hardware-encrypted USB stick stops an oversight from becoming a leak.


Part 3 — What the law says

The GDPR requires minimisation, not convenience

A public library processes your data as part of a public interest mission. It must comply with the principles of the GDPR and of the French Data Protection Act of 6 January 1978:

  • minimisation: collect only what is necessary for the loan. An occupation "for statistics" is not necessary if aggregated data will do;
  • storage limitation: a named borrowing history is not meant to be kept indefinitely. The CNIL, in its recommendations on local authority cultural services, calls for transactions to be anonymised promptly once the item has been returned;
  • information: at registration you must be told who the data controller is, what data is collected, for how long, and how to exercise your rights;
  • rights of access, rectification, erasure and objection: you can request a copy of your reader file and the deletion of your history.

Every local authority appoints a data protection officer (DPO), whose contact details are usually given on the town hall or library network website. That is the person to write to.

Confidentiality of reading and outside requests

French librarians have long defended the principle that a user's loans must not be disclosed to anyone — not to family, not to an employer, not to an inquisitive elected official. In professional practice, only a properly issued judicial order can compel the disclosure of information — and even then, there has to be something to disclose.

Hence the obvious conclusion that is nonetheless rarely drawn: the best protection against a data request is the absence of data. A library that anonymises its transactions on return has nothing to hand over, to anyone, ever.

The case of minors

Parental access to a child's reading history is a delicate matter. For a young reader, parental oversight is legitimate and practical. For a 16-year-old borrowing a book on sexual orientation, eating disorders or contraception, a history visible from the parent account can be a deterrent — and that is a genuine public health issue. Several networks now offer independent individual cards from secondary school age, precisely for this reason. It's worth asking for one.


Part 4 — Ten concrete steps

  1. Ask for your history to be switched off. At registration or by email to the DPO: "I would like my borrowing history not to be retained once the items have been returned." The request is simple to process, often at reader-account level.

  2. Read the privacy notice. It almost always exists, at the bottom of the library rules or the registration form. It states the actual retention periods.

  3. Limit what you give at registration. Occupation, income, a second phone number: ask whether the field is mandatory. If it determines neither the rate nor the loan, it generally isn't.

  4. Keep your channels separate. If you make heavy use of the network's online services (reservations, notifications, newsletters), a dedicated email address for cultural pursuits keeps your reading from being linked to your professional identity.

  5. Prefer paper for sensitive subjects. Health, family law, religion, sexuality, addiction, legal proceedings: a physical book doesn't measure your reading. A discreet bookmark also saves you from leaving a till receipt with your name on it between the pages, which happens more often than you'd think.

  6. Use inter-library loans sparingly. An ILL request creates a trace in two institutions, with the title in plain text and your name, and it often travels by email.

  7. Do your sensitive searches elsewhere. Querying the catalogue while logged into your reader account ties the search to your file. Many catalogues can be consulted without logging in: use them that way, then go and find the item on the shelf.

  8. On public wifi, reduce your footprint. A private browsing session, updates disabled, and wifi switched off as you leave. On public computers, no important personal accounts.

  9. Buy what you don't want to borrow. A second-hand book paid for in cash remains the most discreet reading there is. A bookshelf at home costs less than the peace of mind it brings.

  10. Exercise your rights once, just to see. An access request sent to the network's DPO will tell you exactly what is being kept about you. It's free, the response deadline is one month, and the result is often enlightening.

Red Portuguese European Union passport with a citizen card tucked between the pages


Part 5 — Template letter to the DPO

Subject: exercise of my rights — reader file no. [card number]

Dear Sir or Madam,

Pursuant to Articles 15, 17 and 21 of Regulation (EU) 2016/679, I hereby request:

  1. a copy of the personal data held about me as a user of the public library network, including the history of my loan transactions, my reservations, my fines and the data generated by my use of the wifi and the computer workstations;
  2. the retention periods applied to each of these categories;
  3. the erasure of the named history of my past loans, all the items concerned having been returned;
  4. the recording of my objection to any future retention of my borrowing history, as well as to any use of my data for personalised recommendation purposes or for communications unrelated to the management of my membership.

I would be grateful if you could confirm that these requests have been taken into account within the one-month period provided for in Article 12.

[Surname, first name, address, date, signature]

If you receive no reply, an online complaint to the CNIL is possible — and it will be dealt with.


Conclusion: reading is an act that must remain free

Freedom to read only counts if it is without consequence. The day you hesitate to borrow a book because it will be recorded somewhere next to your name, you are no longer reading entirely freely: you censor yourself, quietly, and nobody notices — which is precisely what makes the phenomenon dangerous.

French libraries are, on the whole, on the right side of this battle. Many already anonymise their transactions, refuse to disclose histories and defend confidentiality as a professional value. But the digitisation of services has brought in third parties, platforms, captive portals and "personal spaces" whose logic is the opposite: accumulate in order to personalise.

The same reasoning applies, incidentally, to all your communication channels. You don't protect your reading by hiding, but by not producing the data in the first place: asking a question without opening an account, reporting information without giving your number, writing without leaving a name. That's the logic of the anonymous message, and it is exactly the logic of the good old bookshelf, where nobody notes down who stops in front of it.

Ask for your history to be switched off. Put the question to your town's DPO. And carry on borrowing whatever you like.

#Vie privée#Confidentialité#Anonymat#RGPD#CNIL#Cas d'usage

On the same topic

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme