A data breach (or data leak) happens when personal information held by an organisation — name, email, phone number, address, bank details, government ID numbers — ends up in the hands of people who were never supposed to see it. The essential point to understand: it is almost never you who gets hacked. It is the companies you entrusted your data to. Protecting yourself from breaches is therefore not about securing your computer — it is about deciding who holds what about you, and making sure that whatever leaks anyway is useless.
Understand where data breaches come from
Recent European figures give a sense of the scale. In France alone — one of the most closely documented markets — nearly the entire population has been affected by at least one major breach in just a few years:
The causes repeat themselves: intrusion through a poorly secured access point (VPN, a subcontractor's account), targeted phishing against employees, application vulnerabilities — or simply databases resold by data brokers that are themselves hit by breaches. To understand how these brokers accumulate profiles on you in the first place, see how data brokers get rich off your back.
Pillar 1 — Reduce your exposure surface
This is the most powerful and the most neglected lever: data minimization. Data that nobody holds cannot leak. Three concrete work streams:
Give less, from the start
Every time you create an account, fill in only the required fields. Date of birth, phone number, postal address: if the service doesn't need them to function, don't provide them. For one-off online purchases, prefer guest checkout over creating a permanent account.
Close dormant accounts
Old e-commerce accounts, forums and abandoned apps are time bombs: their databases age, their security does too, and your data has sometimes been sitting there for ten years. Go through your password manager or your inbox (search for "welcome", "confirm your registration") and delete what no longer serves you. Our guide on removing your personal data from the internet details the method.
Exercise your right to erasure (GDPR article 17)
Closing an account is not always enough: many companies keep your data after the account is gone. Article 17 of the GDPR lets you demand actual deletion — from online merchants, but above all from data brokers, the companies that compile and resell complete profiles of you without you ever having heard of them. Two approaches:
✏️ Manual method
Identify each company holding your data, find its DPO's contact details, send a motivated erasure request, follow up if there is no answer within 30 days. Effective but time-consuming — and it has to be repeated, because profiles rebuild themselves. See our data broker opt-out guide.
⚡ Automated method
Sheeldy sends and tracks the erasure requests for you, with the data brokers and merchants active in Europe, with automatic follow-ups and a transparent dashboard — for €2.50/month (or €20/year), in full GDPR compliance.
Pillar 2 — Make stolen data useless
Even with a reduced exposure surface, some breaches will reach you. The second pillar is making sure a stolen piece of data gives access to nothing else. That is the whole point of credential stuffing: attackers automatically test a stolen email + password pair on hundreds of other sites. If you reuse passwords, a single breach compromises your entire digital life.
- One unique password per site, generated and remembered by a password manager. It is the number-one recommendation of every national cybersecurity agency — and it neutralises credential stuffing on its own.
- Two-factor authentication (2FA) on all sensitive accounts: primary email, banking, taxes, social networks. A stolen password is then no longer enough to get in.
- Email aliases for secondary sign-ups: if the alias leaks, you know exactly where the leak came from and you disable it — your main address stays clean.
- Virtual payment cards (offered by most banks) for online purchases: a compromised number gets deactivated in one click, without touching your real card.
The details of these three tools — password manager, aliases, 2FA — and how to set them up step by step are covered in our dedicated guide: how to limit personal data leaks.
Pillar 3 — Monitor your addresses and accounts
Between the moment a breach happens and the moment the company discloses it, weeks — sometimes months — go by. Active monitoring shortens that window, and every day gained limits the damage.
Check whether your addresses have already leaked
Services like Have I Been Pwned compare your email address against publicly known breaches. Enter your main addresses and note the breaches listed: each one tells you which types of data were exposed. Keep the nuance in mind though: a negative result proves nothing — breaches sold privately on the dark web only appear in these tools once they become public.
Turn on automatic alerts
Browsers (Chrome, Firefox, Safari) and password managers now flag compromised credentials. Enable these alerts and treat them like fire alarms: you don't ignore them, you act within the hour.
Pillar 4 — React fast when a breach hits you
When the alert lands — an email from the company, a browser notification, a press article — the order of actions matters more than their exhaustiveness:
- Change the password of the affected account — and of every account that shared the same password, starting with your primary email.
- Enable 2FA on the affected account if it isn't already.
- Anticipate phishing: in the days following a breach, phishing campaigns exploit the stolen data to impersonate the breached company, your bank or a public service. Maximum suspicion towards any message mentioning the breach.
- Watch your bank accounts if bank details or payment data are involved, and report any unknown transaction to your bank immediately.
- Request the erasure of your data from the company at fault (GDPR article 17): it has demonstrated it cannot protect your data — it has no business keeping it.
Your rights against companies that let your data leak
The GDPR does not just regulate data collection: it imposes precise obligations in case of a breach, and gives you concrete leverage.
The company must notify its supervisory authority within 72 hours of becoming aware of the breach (article 33) and inform you directly when the breach creates a high risk for your rights (article 34). You can then exercise your right of access (article 15) to find out exactly which of your data was concerned, your right to erasure (article 17), and lodge a complaint with your data protection authority — the ICO in the UK, the CNIL in France, and their counterparts across Europe — if the company doesn't respond within a month. Sanctions have become dissuasive — €42M for Free in May 2026, €5M for France Travail in January 2026 — and compensation for damages remains possible before the courts (article 82).
Frequently asked questions
Can data breaches be prevented entirely?
How do I know if my data has already been leaked?
What are the concrete risks after a data breach?
Does deleting my data from data brokers protect me from breaches?
What should I do immediately after a breach alert?
In conclusion
Protecting yourself from data breaches is not about building a fortress — it is about reducing what there is to steal. Give out less information, close dormant accounts, get what data brokers and merchants already hold erased; lock down the rest with unique passwords and two-factor authentication; monitor your addresses; and when a breach reaches you anyway, act within the hour. Each of these pillars reduces the risk — together, they change the game. Sheeldy automates the first and most structural one: the fewer companies hold your data, the fewer breaches can reach you.