https://www.theguardian.com/world/2013/aug/01/new-york-polic...
https://www.theguardian.com/world/2013/aug/01/new-york-polic...
So I guess don't do that if you work for someone who's going to send the police to your house over it after they fire you? Not sure there's really a larger point to be made here about watchlists, surveillance, or indeed anything, considering the only element of that story which couldn't happen in 1930 is the part about Google.
Client certs are a different thing entirely, and unrelated to this discussion.
One supposes there might be some banks or B2B sites that might use client certs, but they're such a minority that no one ever heard of them.
Separate from that, client certificates are certainly common, being used for authentication, in the US Federal Government, which issues tens of millions of certificates for this purpose as well as smartcards, since George W. Bush banned passwords with HSPD-12.