Added on: 19/08/2024
Have you ever wondered why your inbox is filled with junk, promotions or subscriptions that seem to be coming out of nowhere?
I have.
That was until a few years ago when I was introduced to the Data Protection industry, and discovered some interesting things, including that many companies sell and share our personal data.
Most of the time, this happens behind closed doors, as you don’t know if and when it takes place.
But there are other times when it’s pretty clear.
And that’s how I found that my data was sold at least 3 times.
First time happened about 4 years ago.
One day, out of nowhere, I got a welcome email from a local flower shop in California.
How the hell did these guys got my info, since they only sell within that state?
Luckily, I knew what I had to do.
I immediately sent them a Data Request, and asked what data they had about me, where they got it from and what they’re doing with it.
Initially, they were reluctant to disclose this information, but I don’t back down easily, and I pushed them even more.
They finally told me that they bought my data (fortunately it was only my email address) from 2 US based data brokers.
Second time it happened was about 2-3 years ago. I was working on startup, and was quite active on HARO and on the lookout for opportunities to take part in articles or interviews.
At some point, I found an ad from a publication, sent them an email, completed a form, and waited.
Lo and behold, 2 days later I get a welcome email from Harvard Business Review, and no response from that publication.
I start looking through my emails, maybe I missed something and I actually subscribed to HBR.
Nothing.
So I sent them a Data Request through the platform I was working on at that time.
Again, they were reluctant to answer my request and disclose any info, but I REALLY don’t back down easily and submitted a complaint to the ICO (they handle anything data protection related in the UK).
HBR operates pretty much anywhere across the globe, including UK, and they can’t afford a bad data protection PR or fine.
They finally got back to me almost a month later with some BS answer: they know that I subscribed to their newsletter some many years ago, and didn’t kept records around that time.
Did I really subscribed and forgot about it, or did they bought my data and tried to cover their sh*t?
Who can say…
Now for the final time I got my data sold, I had quite the surprise. It was in the middle of the pandemic. I was in Romania, and my wife and I were travelling back and forth between the UK and Romania.
Back then, you couldn’t enter the UK without a negative test, quarantine or vaccine (remember those good times?).
So we got vaccinated, and found out about a government incentive where they offered some cash for being vaccinated.
Free money!
I applied, they sent the money a week or 2 later, and about a month later it started.
I started getting loads of promotions and marketing emails from a bunch of Romanian companies (bear in mind that I used my email only in UK).
Yeah…even the government is out to sell you.
Good times we live in.
Since you got to the end, have a look below at the template I personally use to send Deletion Requests, so you can start removing your data from companies you don’t use, and avoid having your data sold. Learn from my mistakes.
Data Deletion Request Template:
“Dear Data Protection Officer,
I am writing to you to request the deletion of my personal information from your database, under the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).
I include the information below in order to confirm my identity: Full name: Email:
lease confirm once all my information has been removed from your systems.
If you are not the person responsible for handling these requests, please pass this email to your relevant department.”
If you want a simpler way to manage your subscriptions, your data, and your requests (both Data Requests and Deletion Requests), I invite you to join Sentrya (sentrya.net) - get 45% off Pro Plan.
I hope this articles sheds some light on how companies might handle your data, and gives you the push you needed to start improving your privacy and security.
Until next time.
Read more
Your iPhone Data May Have Been Leaked in China:–Here is What It Means and How to Protect Yourself
Did you know that your iPhone data may have just been exposed? According to Cybernews, up to <b>62 million iPhone users’</b> personal information has been leaked from an iOS app in China. This includes details like your <em>name, ID number, gender, date of birth, phone number, province, and city</em> – basically, enough data for scammers to wreak havoc.<br/><br/>If you’re like most people, this probably feels like a punch to the gut. After all, you trust your iPhone and Apple to keep your data safe. Unfortunately, even the best technology can’t always protect you when shady apps or data brokers get involved.<br/><br/><br/><h2 class= "text-heading">Here’s What Was Leaked</h2><br/>Hackers managed to grab personal info that could let them impersonate you online or even in the real world. This data is fresh – as recent as February 2025 – so it’s especially worrying.<br/><br/><br/><h2 class= "text-heading"> Why Should You Care?</h2><br/>Think about all the ways your personal data is linked to your life:<br/>- <u>Identity theft</u> – Scammers could open bank accounts or credit lines in your name.<br/>- <u>Phishing attacks</u> – You might get emails or texts that look real but are traps.<br/>- <u>Financial fraud</u> – They could trick you into sending them money or personal info.<br/>- <u>Location-based scams</u> – Because they know where you live, they might tailor attacks just for you.<br/><br/><br/><h2 class= "text-heading">How to Protect Yourself</h2><br/>The best thing you can do <u>right now</u> is to start cleaning up your personal data footprint. Removing your info from data brokers and shady sites is crucial.<br/><br/>That’s where services like <a href= "https://sentrya.net" class= "content-link">Sentrya</a> come in. Sentrya helps you <em>find and delete your personal data</em> from data broker websites and search engines. It’s like taking your info back into your own hands – because the less data out there, the harder it is for criminals to target you.<br/><br/>Sentrya works by continuously scanning for your info and removing it from places where it shouldn’t be. It’s a smart move to help protect your privacy, especially after a major leak like this.<br/><br/><br/>If you’re an iPhone user – or just care about your privacy – don’t wait. This breach is a wake-up call that your personal data can be out there in ways you never imagined. <b>Act now</b> to lock down your information and stop hackers in their tracks.
Read more
Morocco CNSS Data Breach: A Wake Up Call for Consumer Data Protection
In April 2025, Morocco experienced a significant cybersecurity incident when the National Social Security Fund (Caisse Nationale de Sécurité Sociale – CNSS) was compromised. The breach resulted in the unauthorised release of sensitive data pertaining to millions of Moroccan workers and hundreds of thousands of businesses. The fallout from this breach has raised serious concerns about consumer privacy and the adequacy of data protection measures.<br/><br/><br/><h2 class= "text-heading">The CNSS Breach: What Happened?</h2><br/>On April 8, 2025, a hacker group identifying itself as JabaRoot DZ claimed responsibility for the cyberattack on CNSS. The group leaked over 50,000 official documents, including personal identification numbers, salary declarations, employment contracts, and correspondence involving foreign diplomatic entities. The leaked data was disseminated through various channels, including encrypted messaging platforms and public file-sharing websites.<br/><br/>Cybersecurity analysts suggest that the attackers may have exploited vulnerabilities in outdated file storage protocols or gained access through compromised administrator accounts. The breach potentially began weeks or months before the data was released, allowing the attackers ample time to exfiltrate information undetected.<br/><br/><br/><h2 class= "text-heading">Implications for Consumer Privacy</h2><br/>The CNSS breach has exposed nearly 2 million employees and approximately 470,000 companies to potential risks, including identity theft, financial fraud, and targeted phishing attacks. The leaked information encompasses a wide range of personal and financial data, making it a valuable resource for malicious actors.<br/><br/>This incident underscores the vulnerabilities inherent in centralised data repositories and the critical need for robust cybersecurity measures to protect consumer information. It also highlights the importance of transparency and prompt communication from institutions in the event of data breaches.<br/><br/><br/><h2 class= "text-heading">Sentrya: Empowering Consumers to Protect Their Data</h2><br/>In the wake of such breaches, you must take proactive steps to safeguard your personal information. <a href= "https://sentrya.net" class= "content-link">Sentrya</a> offers a comprehensive solution designed specifically for individual users. Sentrya provides tools to remove personal data from the web and data brokers, and to clear inboxes of scams and phishing emails. By leveraging Sentrya’s services, you can regain control over your digital footprint and enhance your privacy.<br/><br/><br/>The CNSS data breach serves as a stark reminder of the growing threats to consumer privacy in the digital age. While institutions must bolster their cybersecurity frameworks, individuals also have a role to play in protecting their personal information. Utilising services like Sentrya can be an effective strategy for consumers to mitigate risks and maintain their privacy in an increasingly interconnected world.
Read more
Trump Administration Reverses Data Privacy Protections Exposing Americans to Increased Risks
In a significant policy reversal, the Trump administration has dismantled a Biden-era initiative aimed at limiting the sale of Americans’ personal data by data brokers. This move raises substantial concerns about consumer privacy and national security.<br/><br/><br/><h2 class= "text-heading">Background: The Biden-Era Initiative</h2><br/>Under President Biden, the Consumer Financial Protection Bureau (CFPB) proposed regulations to subject data brokers to oversight akin to credit bureaus. The goal was to protect consumers from the unregulated sale of sensitive personal information, which could be exploited for identity theft, scams, and even national security threats.<br/><br/><br/><h2 class= "text-heading">The Reversal and Its Implications</h2><br/>On May 14, 2025, the CFPB announced the withdrawal of the proposed regulations, stating that they no longer align with the bureau’s policy objectives. Consumer advocacy groups, such as Consumer Reports, have expressed alarm, warning that this decision leaves consumers vulnerable to scams and identity theft.<br/><br/>The rollback also includes the withdrawal of proposals related to digital payment technologies and the prohibition of certain terms in consumer finance products.<br/><br/><br/><h2 class= "text-heading">Risks to Consumer Privacy</h2><br/>The unregulated sale of personal data poses several risks:<br/>• <u>Identity Theft</u>: Personal information can be used to impersonate individuals, leading to financial loss and reputational damage.<br/>• <u>Scams and Phishing</u>: Data brokers can sell information to malicious actors who craft targeted scams and phishing emails.<br/>• <u>National Security Threats</u>: Sensitive data about government officials and military personnel can be exploited by foreign adversaries for espionage.<br/><br/><br/><h2 class= "text-heading">Sentrya: A Consumer-Focused Solution</h2><br/>In light of these developments, consumers seeking to protect their personal information can turn to services like <a href= "https://sentrya.net" class= "content-link">Sentrya</a>. Sentrya offers tools to remove personal data from the web and data brokers, and to clear inboxes of scams and phishing emails. Designed specifically for individual consumers, Sentrya empowers users to take control of their digital privacy.<br/><br/><br/>The Trump administration’s decision to scrap proposed data privacy regulations underscores the importance of individual action in safeguarding personal information. While federal protections may be in flux, consumers can proactively protect themselves using services like <a href= "https://sentrya.net" class= "content-link">Sentrya</a> to mitigate the risks associated with data exposure.
Read more
Your Airline Might Be Sharing Your Data with ICE: Here is What You Need to Know
Have you ever booked a flight thinking it was just between you, your airline, and your destination? You might want to think again. Recent reporting from Jacobin has exposed a chilling truth: airlines and travel companies are quietly sharing your personal travel data with U.S. Immigration and Customs Enforcement (ICE). And it’s happening without your consent, knowledge, or any real way to opt out.<br/><br/>Let’s break down what’s going on—and what it means for you.<br/><br/><br/><h2 class= "text-heading">Your Data Is Being Sold—Not Just Shared</h2><br/>You probably don’t know what the Airlines Reporting Corporation (ARC) is. That’s by design. ARC is a behind-the-scenes player that processes flight bookings between travel agencies (think Expedia, Priceline, or even a local agency) and over 200 airlines. That includes the biggest names: Delta, American, United, JetBlue, and more.<br/><br/>When you book a ticket, your itinerary, payment information, and travel history don’t just stay with the airline. They flow into ARC’s massive system. And from there? That data is being sold directly to ICE, as part of something called the “Travel Intelligence Program.”<br/><br/>Yes, sold.<br/><br/>This isn’t a targeted subpoena for a specific criminal investigation. This is bulk data sharing—ICE getting access to your travel habits, international flights, layovers, and even payment methods, all neatly packaged. Whether you’re a citizen, a visa holder, or just someone trying to visit family, that data can land in a government file, without your knowledge.<br/><br/><br/><h2 class= "text-heading">Why This Should Deeply Worry You</h2><br/>This isn’t just about immigration enforcement. This is about your right to privacy—and how it’s being traded away.<br/><br/>1. <em>You never consented to this.</em><br/>When you hit “purchase” on that ticket, did you get a notice saying your personal information might be sold to a federal law enforcement agency? Of course not.<br/><br/>2. <em>You have no control over where your data goes.</em><br/>Even if you use third-party travel sites, ARC is the middleman. And ARC is owned by the very airlines you’re booking with—so they’re profiting off your data in multiple ways.<br/><br/>3. <em>You could be flagged for future surveillance without doing anything wrong.</em><br/>Maybe you fly often to a country ICE is scrutinising. Maybe you paid for a ticket for someone else. Maybe you booked with cash. These perfectly legal activities can appear suspicious when viewed out of context by an algorithm or agency.<br/><br/><br/><h2 class= "text-heading">Real People, Real Risks</h2><br/>Imagine you’re visiting family abroad and come back to find you’ve been flagged for extra screening—no explanation, just delays and discomfort. Or ICE shows up at someone’s door based on flight data you unknowingly shared when you booked a ticket for them. These aren’t hypotheticals. This data is being used for real enforcement actions, with real consequences.<br/><br/>And no, there’s no easy opt-out.<br/><br/><br/><h2 class= "text-heading">What You Can Do to Protect Yourself</h2><br/>Unfortunately, you can’t completely stop airlines from selling your data—at least, not yet. But you can take steps to limit your exposure:<br/>• <u>Avoid big-name platforms</u> when booking, or research which agencies work with ARC. Smaller, privacy-conscious travel services may reduce how much data is shared.<br/>• <u>Pressure airlines and lawmakers</u> to stop this. If enough consumers speak up, companies and legislators will take notice.<br/><br/><br/><h2 class= "text-heading">This Isn’t Just a Policy Issue—It’s Personal</h2><br/>You deserve to travel without fear that your movements are being logged, sold, and scrutinised by law enforcement. This isn’t about politics. It’s about privacy, consent, and basic digital rights.<br/><br/>Next time you book a flight, take a moment to think about where your data is going—and who might be watching.
Read more
I'd like to set analytics cookies that help me make improvements by measuring how you use the site.