The data you generate without noticing
Every account, loyalty card, app permission and advertising identifier contributes to a profile that is bought, merged and resold. Location history, purchase records and browsing behaviour are the three most commercially valuable streams, and all three are collected passively.
Data brokers combine these sources with public records to build profiles far more detailed than any single company holds. That aggregation is what makes breaches harmful: an individually trivial leak becomes useful when matched with five others.
- Account details and purchase history held by retailers
- Location data from apps with background permission
- Advertising identifiers linking activity across apps
- Public records and social profiles merged by data brokers
The rights you can actually use
In the European Union and the United Kingdom, the GDPR gives you the right to access a copy of your data, correct it, have it deleted in many circumstances, object to profiling and receive it in a portable format. Brazil's LGPD and several US state laws grant broadly comparable rights.
Exercising them is usually a matter of emailing the company's privacy contact with a clear request. Organisations generally have one month to respond in the EU and UK, and refusing without valid grounds is itself a breach you can report to the supervisory authority.
- Access: request a copy of everything held about you
- Rectification: correct inaccurate records
- Erasure: require deletion where no lawful basis remains
- Objection: stop profiling and direct marketing
- Portability: receive your data in a reusable format
Reducing what you share from now on
The highest-value changes take under an hour. Turn off ad personalisation and reset the advertising identifier on your phone, set location permission to 'while using' for everything except navigation, and remove apps you have not opened in six months along with the permissions they retain.
Use a separate email address for shopping and newsletters so that marketing breaches do not expose the address tied to your bank and identity documents. Decline optional loyalty-programme data sharing, and give date of birth or phone number only when a service genuinely requires it.
Browser and device settings that matter
Choose a browser with tracking protection enabled by default, add a reputable content blocker and reject non-essential cookies rather than closing the banner. Blocking third-party cookies removes a large share of cross-site tracking at no practical cost.
On the device itself, enable full-disk encryption, set a lock screen with a strong code, and review which apps hold contacts, microphone, camera and photo-library access. Photo-library access in particular is requested far more often than it is needed.
When your data is breached
Assume any breached password is public and change it everywhere it was reused. Watch specifically for targeted phishing afterwards, because attackers use leaked order details and account references to make follow-up messages convincing.
Where financial or identity documents were exposed, consider credit monitoring or a credit freeze where your country offers one, and keep the breach notification: it is useful evidence if fraud occurs later.
Families and children
Children accumulate data footprints before they can consent to them. School platforms, games and connected toys collect substantial information, and default settings are rarely the most protective.
Review privacy settings on the services children use, disable public profiles and voice-chat with strangers where possible, and explain in plain terms why an address, school name or live location should never go into a game or social app.
