Why Your Data Is Your Security
“I have nothing to hide.” That’s exactly what everyone in these stories thought — before everything changed.
Before we begin
Eric Schmidt — former CEO of Google — said it outright: “We know where you are. We know where you’ve been. We can more or less know what you’re thinking about.”
That’s not a threat. It’s a description of what’s already working. Right now. In Tallinn, Riga, Warsaw, Berlin, Moscow.
Data about you exists. It’s collected. It’s stored. And it’s used — by people you’ve never met, for purposes no one ever warned you about.
Here are thirteen stories. Real ones. Close to you.
- CASE 1 — ESTONIA. A LEAK AND SOMEONE ELSE’S LOAN.
A resident of Tallinn discovered that a consumer loan had been taken out in his name at a microfinance company. He hadn’t taken it. His passport data had leaked through one of the online services he used. Fraudsters used the data for verification — name, date of birth, ID code. That was enough. For three months he tried to prove the loan wasn’t his. His credit history was ruined. Collectors called his workplace.
Check right now: enter your email at haveibeenpwned.com — find out if there’s been a leak with your data. It’s free and takes 30 seconds.
- CASE 2 — LATVIA. GEOLOCATION AS EVIDENCE.
In Riga, a man was called in for questioning in connection with an incident in an area where he had allegedly been. Police obtained geolocation data from the telecom operator. His phone really had been in that area — he simply drove through that neighborhood on his way to work every day. Weeks of explanations. Stress. Lost time. His phone silently recorded every route. He never thought about it. The operator stored the data. The police requested it — the operator handed it over. All perfectly legal. All without his knowledge.
What to do: turn off constant geolocation on your phone. Settings → Location → Only while using the app. Not always.
- CASE 3 — LITHUANIA. AN EMPLOYER AND SOCIAL MEDIA.
A young professional from Vilnius went through three rounds of interviews at a major company. Got a verbal offer. A week later — rejection, no explanation. He later learned through acquaintances that the company’s security team had been monitoring his social media pages. They found comments from three years earlier where he had criticized one of the company’s shareholders. The comments were public. A reputation-monitoring algorithm found them automatically. He had long since forgotten those comments. The algorithm hadn’t.
What to do: go into your social media privacy settings right now. Old posts — restrict visibility or delete them. Something written three years ago continues to exist and can work against you.
- CASE 4 — FINLAND. MEDICAL DATA AND BLACKMAIL.
In 2020–2021, the Finnish psychotherapy network Vastaamo was hacked. Session records for tens of thousands of patients leaked — the most personal conversations with their therapists. Hackers contacted patients directly and demanded ransom, threatening to publish the recordings. People who had sought help from a professional became victims of blackmail. Several people took their own lives after this incident. This isn’t an abstract story. This is Finland. This is the EU. This is the GDPR. And it happened anyway.
What to do: never store medical data in unencrypted apps. If you use health apps, check where the data is stored and who it’s shared with.
- CASE 5 — POLAND. POLITICAL ACTIVITY AND ITS CONSEQUENCES.
In 2021, Polish authorities used the Pegasus spyware to surveil opposition politicians, lawyers, and journalists. This was confirmed by Citizen Lab. Pegasus installs on a phone without the owner’s knowledge. It gains access to everything — calls, messages, camera, microphone, geolocation. Victims didn’t find out right away — and not all of them found out at all. Poland is an EU member. Pegasus is a tool sold to governments. Your phone is a target.
What to do: reboot your phone regularly — Pegasus doesn’t survive a reboot on most devices. Update iOS and Android immediately — Pegasus exploits vulnerabilities that updates patch.
- CASE 6 — GERMANY. A SMART TV AND YOUR INTIMATE LIFE.
Germany’s data protection regulator (BSI) documented cases where smart TVs collected data on the content being watched and transmitted it to manufacturers and advertising networks. Including adult content. Including viewing times — late at night, on specific days. This data was used for ad targeting. The algorithm knew more about people’s habits than they were willing to admit publicly. Samsung was fined for collecting data without proper notice.
What to do: go into your smart TV’s settings. Find the “ACR” (Automatic Content Recognition) section, or “advertising” — turn it off. Connect your TV to a guest Wi-Fi network, separate from your computer and phone.
- CASE 7 — RUSSIA. CAMERAS AND IDENTIFICATION.
In Moscow, a facial recognition system covers more than 100,000 cameras. In 2021–2022, it was used to identify protest participants. People who were simply standing nearby — not participating, just walking past — received summonses. The algorithm doesn’t understand context. It sees a face in a specific place at a specific time. That’s enough. The system continues to operate. Its database of faces is fed from social media, from documents, from any public source.
What to do: if you’re an EU resident and your data is on Russian services — VKontakte, Mail.ru — you have the right to demand its deletion. Article 17 GDPR applies. They’re obligated to respond.
- CASE 8 — CZECHIA. DIVORCE AND THE CLOUD.
A woman from Prague was going through a divorce. Her husband presented printouts of her private correspondence from a cloud storage account in court — he knew the password to a shared account they had set up years earlier and forgotten about. The correspondence contained personal conversations with friends. Context was stripped away. The court used fragments to characterize her personality. She hadn’t thought about that account in years. The data existed. And it was used against her.
What to do: right now, check every account that other people might have access to. Change your passwords. Check active sessions in Google, Apple, Dropbox — remove other people’s devices from the list.
- CASE 9 — NETHERLANDS. AN ALGORITHM AND CHILD BENEFITS.
In 2019–2021, a scandal broke in the Netherlands — an algorithm used by the tax authority (Belastingdienst) automatically flagged families as fraudulently claiming child benefits. The algorithm’s criteria included ethnic origin and dual citizenship. More than 26,000 families lost their benefits. They were forced to repay money they didn’t have. Families fell apart. People lost their homes. The algorithm had been running for years. No one checked it. This is what’s called an automated decision — exactly what Article 22 GDPR regulates. The Dutch government resigned over this scandal.
What to do: if you’ve been denied a service, a benefit, or a loan — and the decision seems unfair — you have the right to know whether it was made by an algorithm. Article 22 GDPR gives you the right to an explanation and to have the decision reviewed by a human being.
- CASE 10 — ESTONIA. A DEEPFAKE AND FRAUD.
In 2023, cases of fraud using synthesized voices were recorded in Estonia. Scammers called elderly people using the voice of a “grandson” or “daughter,” asking them to urgently transfer money — an accident, detained at the border, needs help right now. The voice was synthesized from social media videos. A few minutes of recording was enough. People transferred the money because they heard a familiar voice.
What to do: agree on a codeword with your family. A word only you know. If someone calls asking for money — ask for the codeword. A synthesized voice won’t know it.
- CASE 11 — AUSTRIA. AN APP AND INSURANCE.
An Austrian insurance company offered customers a discount in exchange for installing an app that tracked their driving style. Speed, braking, trip times. Customers agreed — the discount seemed like a good deal. A year later, the company used the collected data to revise rates upward — for those whose driving style the algorithm rated as risky. Those who drove at night, braked often, or sped — paid more. Consent had been given. Everything legal. But no one explained that the data would be used against the customers.
What to do: read the terms before installing any insurance or banking app. If a discount is offered in exchange for your data, that discount may cost more than it seems.
- CASE 12 — UKRAINE/RUSSIA. DATA AND WAR.
After the war began in 2022, Ukrainian authorities discovered that Russian security services had used data from VKontakte and other Russian services to compile lists of people — by political views, religious affiliation, profession.
These lists were used in occupied territories.
People who had spent years publicly posting on social media never thought it would one day become a threat to their lives.
What to do: if you have accounts on Russian services — VKontakte, Mail.ru, Odnoklassniki — and you’re an EU resident, submit a data deletion request under Article 17 GDPR. Russia doesn’t have “adequate country” status — storing your data there is already a violation.
- CASE 13 — EVERYWHERE. PRICE DISCRIMINATION, EVERY DAY.
You’re searching for a flight, Tallinn to Berlin. You check a few times. The price goes up. You open it in incognito mode — the price is lower. You open it on a different device — a different price again. This isn’t chance. The algorithm sees that you’re interested. It sees your device, your neighborhood, your search history. And it names the price it calculates you’re willing to pay. Studies by European regulators have confirmed that price discrimination is practiced on hundreds of major sites. Booking, airlines, online stores.
What to do: always search for flights and hotels in incognito mode. Compare prices across different devices. Use a VPN to change your location. Your data literally costs you money — reduce how much of it you give up, and pay less.
What all these stories have in common
Not one of these people thought their data would be used against them. The resident of Tallinn was just using online services. The man in Riga was just driving to work. The professional from Vilnius just wrote some comments three years ago. Vastaamo’s patients just sought help. Data isn’t collected because you did something wrong. It’s always being collected. And it gets used whenever it’s advantageous to someone else. “I have nothing to hide” isn’t an argument. All of these people had nothing to hide too — until the moment their data became a weapon against them.
Three steps you can take today
- First — right now: Go to haveibeenpwned.com. Enter your email. Find out if your data was in any leaks. 30 seconds.
- Second — today: Check active sessions in Google and Apple. Remove unfamiliar devices. Change passwords on accounts you haven’t updated in a long time.
- Third — this week: Send an Article 15 GDPR request to one company you trust the least. Simply write: “Please provide all personal data you process about me.” They’re required to respond within 30 days. Free of charge.
Privacy isn’t paranoia. It’s what separates you from the next story on this list.