Protecting your personal data

    Data protection is usually presented as a legal subject, but in daily life it comes down to three practical questions: who holds information about you, what can you make them delete, and how much new data are you handing over by default?

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    The data you generate without noticing

    Every account, loyalty card, app permission and advertising identifier contributes to a profile that is bought, merged and resold. Location history, purchase records and browsing behaviour are the three most commercially valuable streams, and all three are collected passively.

    Data brokers combine these sources with public records to build profiles far more detailed than any single company holds. That aggregation is what makes breaches harmful: an individually trivial leak becomes useful when matched with five others.

    • Account details and purchase history held by retailers
    • Location data from apps with background permission
    • Advertising identifiers linking activity across apps
    • Public records and social profiles merged by data brokers

    The rights you can actually use

    In the European Union and the United Kingdom, the GDPR gives you the right to access a copy of your data, correct it, have it deleted in many circumstances, object to profiling and receive it in a portable format. Brazil's LGPD and several US state laws grant broadly comparable rights.

    Exercising them is usually a matter of emailing the company's privacy contact with a clear request. Organisations generally have one month to respond in the EU and UK, and refusing without valid grounds is itself a breach you can report to the supervisory authority.

    • Access: request a copy of everything held about you
    • Rectification: correct inaccurate records
    • Erasure: require deletion where no lawful basis remains
    • Objection: stop profiling and direct marketing
    • Portability: receive your data in a reusable format

    Reducing what you share from now on

    The highest-value changes take under an hour. Turn off ad personalisation and reset the advertising identifier on your phone, set location permission to 'while using' for everything except navigation, and remove apps you have not opened in six months along with the permissions they retain.

    Use a separate email address for shopping and newsletters so that marketing breaches do not expose the address tied to your bank and identity documents. Decline optional loyalty-programme data sharing, and give date of birth or phone number only when a service genuinely requires it.

    Browser and device settings that matter

    Choose a browser with tracking protection enabled by default, add a reputable content blocker and reject non-essential cookies rather than closing the banner. Blocking third-party cookies removes a large share of cross-site tracking at no practical cost.

    On the device itself, enable full-disk encryption, set a lock screen with a strong code, and review which apps hold contacts, microphone, camera and photo-library access. Photo-library access in particular is requested far more often than it is needed.

    When your data is breached

    Assume any breached password is public and change it everywhere it was reused. Watch specifically for targeted phishing afterwards, because attackers use leaked order details and account references to make follow-up messages convincing.

    Where financial or identity documents were exposed, consider credit monitoring or a credit freeze where your country offers one, and keep the breach notification: it is useful evidence if fraud occurs later.

    Families and children

    Children accumulate data footprints before they can consent to them. School platforms, games and connected toys collect substantial information, and default settings are rarely the most protective.

    Review privacy settings on the services children use, disable public profiles and voice-chat with strangers where possible, and explain in plain terms why an address, school name or live location should never go into a game or social app.

    Frequently asked questions

    Can I really make a company delete my data?

    Often yes, but not always. Organisations may keep data required by law, such as accounting records, or needed for an ongoing contract. They must tell you what they are keeping and why.

    Is a VPN a privacy solution?

    It hides your IP address from websites and your browsing from the network you are on. It does nothing about the data you give to accounts you log into, which is where most profiling happens.

    Do cookie banners actually matter?

    Yes. Rejecting non-essential cookies genuinely reduces tracking on compliant sites. Closing the banner without choosing is often treated as no consent, but explicit rejection is safer.

    How do I remove myself from data-broker sites?

    Each broker has an opt-out process, and several paid services automate submissions. Expect to repeat the process, because profiles are frequently rebuilt from new source data.

    Which single change helps most?

    Reducing the number of accounts and apps that hold your data at all. Deleting unused accounts removes both current exposure and future breach risk.