Tag: Privacy
-

The Data Your Browser Leaks Before You Click Anything
Before any JavaScript runs, before any consent banner, your browser is already giving the server enough information to identify you across visits. The cookie debate is over. The fingerprint debate is just starting.
-

The Data Classification Debate Nobody Wins
A field guide to data classification in 2026, with why the debate goes nowhere, what the practical minimum looks like, and the part about the schema the team is going to keep maintaining.
-

AI Models and Data Leakage in 2026
Every model that trains on your data remembers more of it than the provider’s privacy page suggests. The leakage problem is not the model’s fault. It sits in the prompts people send, the data they upload, the sessions they never close, the retention the vendor keeps for abuse monitoring.
-

Privacy on Public WiFi in 2026
Public WiFi in 2026 sits as the WiFi the typical knowledge worker uses in the coffee shop, the airport, the hotel, the conference, the home of the friend. The privacy of the public WiFi in 2026 amounts to the privacy of a network the user does not control, the user does not trust, the user…
-

GDPR Enforcement 2026: The Fines, the Decisions, the Patterns
GDPR enforcement in 2026 is no longer the warning shot phase. The fines are landing, the precedent is being set, and the gap between the regulator’s interpretation of the regulation and the typical enterprise’s implementation of it is being measured in millions of euros per incident.
-

The Data Classification Problem Nobody Wants to Solve
Data classification in 2026 stands as the security work that everyone agrees needs to happen and that nobody wants to do. The work takes months, the work costs money, the work produces a taxonomy nobody uses, and the work does not get done. The 2026 state of the data classification problem amounts to a state…
-

The Privacy Impact Assessment You Are Skipping
The privacy impact assessment sits as the document that has become the regulatory requirement the enterprise knows about and skips. The PIA the team writes for the regulator gets the PIA the regulator accepts, and the PIA the regulator accepts does not reflect the actual data flow.
-

Regulatory Enforcement: Q1 2026 in Numbers
The regulators moved from guidance to enforcement in 2025. Q1 2026 was the first full quarter of the new normal. Here is what the numbers actually look like, and what they tell you about what is coming.
-

Session Token Theft Has Replaced Password Theft (And You Are Not Ready)
Infostealer logs have made session token theft the dominant credential attack. The password is no longer the thing the attacker wants. The session is. Here is what to do about it.
-

What Actual Data Minimization Looks Like
Data minimization has been a GDPR requirement since 2018. Most organisations have done almost nothing about it. Here is what it actually looks like when you do.