A data breach (or data leak) happens when personal information held by an organisation — name, email, phone number, address, bank details, government ID numbers — ends up in the hands of people who were never supposed to see it. The essential point to understand: it is almost never you who gets hacked. It is the companies you entrusted your data to. Protecting yourself from breaches is therefore not about securing your computer — it is about deciding who holds what about you, and making sure that whatever leaks anyway is useless.

Understand where data breaches come from


Recent European figures give a sense of the scale. In France alone — one of the most closely documented markets — nearly the entire population has been affected by at least one major breach in just a few years:

43 million
France Travail (March 2024) — everyone registered with the employment agency since 2004, social security numbers exposed. €5M fine from the CNIL, France's data protection authority.
33 million
Healthcare payment providers Viamedis & Almerys (February 2024) — roughly one French resident in two, national ID numbers exposed.
19.2 million
Free, a major telecom operator (October 2024) — including 5.1 million bank account numbers (IBAN). Record €42M CNIL fine in May 2026.
402,000
Belambra holiday resorts (May 2026) — including nearly 360,000 records linked to minors, through an IDOR vulnerability.

The causes repeat themselves: intrusion through a poorly secured access point (VPN, a subcontractor's account), targeted phishing against employees, application vulnerabilities — or simply databases resold by data brokers that are themselves hit by breaches. To understand how these brokers accumulate profiles on you in the first place, see how data brokers get rich off your back.

💡 The guiding principle: every company that holds your data is a potential leak. You don't control their security — but you do control how many companies hold your data, and what they hold.

Pillar 1 — Reduce your exposure surface


This is the most powerful and the most neglected lever: data minimization. Data that nobody holds cannot leak. Three concrete work streams:

Give less, from the start

Every time you create an account, fill in only the required fields. Date of birth, phone number, postal address: if the service doesn't need them to function, don't provide them. For one-off online purchases, prefer guest checkout over creating a permanent account.

Close dormant accounts

Old e-commerce accounts, forums and abandoned apps are time bombs: their databases age, their security does too, and your data has sometimes been sitting there for ten years. Go through your password manager or your inbox (search for "welcome", "confirm your registration") and delete what no longer serves you. Our guide on removing your personal data from the internet details the method.

Exercise your right to erasure (GDPR article 17)

Closing an account is not always enough: many companies keep your data after the account is gone. Article 17 of the GDPR lets you demand actual deletion — from online merchants, but above all from data brokers, the companies that compile and resell complete profiles of you without you ever having heard of them. Two approaches:

✏️ Manual method

Identify each company holding your data, find its DPO's contact details, send a motivated erasure request, follow up if there is no answer within 30 days. Effective but time-consuming — and it has to be repeated, because profiles rebuild themselves. See our data broker opt-out guide.

⚡ Automated method

Sheeldy sends and tracks the erasure requests for you, with the data brokers and merchants active in Europe, with automatic follow-ups and a transparent dashboard — for €2.50/month (or €20/year), in full GDPR compliance.

🎯 Direct effect on breaches: the fewer companies hold your data, the fewer breaches can concern you. This is a structural protection, not a band-aid — it acts before the incident, not after.

Pillar 2 — Make stolen data useless


Even with a reduced exposure surface, some breaches will reach you. The second pillar is making sure a stolen piece of data gives access to nothing else. That is the whole point of credential stuffing: attackers automatically test a stolen email + password pair on hundreds of other sites. If you reuse passwords, a single breach compromises your entire digital life.

The details of these three tools — password manager, aliases, 2FA — and how to set them up step by step are covered in our dedicated guide: how to limit personal data leaks.

Pillar 3 — Monitor your addresses and accounts


Between the moment a breach happens and the moment the company discloses it, weeks — sometimes months — go by. Active monitoring shortens that window, and every day gained limits the damage.

Check whether your addresses have already leaked

Services like Have I Been Pwned compare your email address against publicly known breaches. Enter your main addresses and note the breaches listed: each one tells you which types of data were exposed. Keep the nuance in mind though: a negative result proves nothing — breaches sold privately on the dark web only appear in these tools once they become public.

Turn on automatic alerts

Browsers (Chrome, Firefox, Safari) and password managers now flag compromised credentials. Enable these alerts and treat them like fire alarms: you don't ignore them, you act within the hour.

⚠️ Beware of fake alerts: scammers send fake "your data has leaked, click here to check" emails. Never click a verification link received by email — type the address of the verification service into your browser yourself.

Pillar 4 — React fast when a breach hits you


When the alert lands — an email from the company, a browser notification, a press article — the order of actions matters more than their exhaustiveness:

Your rights against companies that let your data leak


The GDPR does not just regulate data collection: it imposes precise obligations in case of a breach, and gives you concrete leverage.

The company must notify its supervisory authority within 72 hours of becoming aware of the breach (article 33) and inform you directly when the breach creates a high risk for your rights (article 34). You can then exercise your right of access (article 15) to find out exactly which of your data was concerned, your right to erasure (article 17), and lodge a complaint with your data protection authority — the ICO in the UK, the CNIL in France, and their counterparts across Europe — if the company doesn't respond within a month. Sanctions have become dissuasive — €42M for Free in May 2026, €5M for France Travail in January 2026 — and compensation for damages remains possible before the courts (article 82).

The best breach is the one that contains nothing about you

Sheeldy reduces your exposure surface at the source: automatic erasure requests to data brokers and online merchants, follow-ups, and continuous monitoring — GDPR-compliant, hosted in Switzerland.

Erase my data — €2.50/month

Frequently asked questions

Can data breaches be prevented entirely?
No. When a company holding your data gets hacked, there is nothing you can do about the hack itself. What you can do is reduce the number of companies that hold your data (GDPR article 17 erasure, closing dormant accounts) and make stolen data useless (unique passwords, two-factor authentication, email aliases). It is the combination of both that actually protects you.
How do I know if my data has already been leaked?
Enter your email address on a verification service like Have I Been Pwned: it compares it against publicly known breaches. Be careful: a negative result does not prove the absence of a leak — unpublished breaches and data sold privately do not appear there. Also enable the compromised-credential alerts of your browser and your password manager.
What are the concrete risks after a data breach?
Four main risks: targeted phishing (scammers know your name, your email, sometimes your provider or your bank, which makes their messages very credible), credential stuffing (automatically testing your stolen password on dozens of other sites), payment fraud if your bank details leaked, and identity theft if official documents or government ID numbers are exposed.
Does deleting my data from data brokers protect me from breaches?
Yes, mechanically: a company that no longer holds your data can no longer leak it. Data brokers aggregate very complete profiles (identity, contact details, consumer habits) and are themselves regularly hit by breaches. Exercising your right to erasure with them — manually or through an automated service like Sheeldy — durably reduces your exposure surface.
What should I do immediately after a breach alert?
In order: change the password of the affected account and of every account that shared the same password, enable two-factor authentication, be wary of emails and text messages mentioning the breach (phishing campaigns follow within days), monitor your bank accounts if payment data is involved, then request the erasure of your data from the company at fault.