Data Privacy Strategy
No one is perfect. Just do what you feel is appropriate for you.
Five main identifiers used to define you
- Email address
- Phone number
- Debit card
- Browser
- Your device (smartphone, laptop)
Main Strategies
1. Reduce data collection at the source
- Use a privacy-respecting browser
- Brave, Firefox with strict tracking protection on,
- Install tracker/ad blockers (uBlock Origin) — blocks pixels, most ad-tech, and many fingerprinting scripts
- Disable third-party cookies; regularly clear cookies/local storage
- Turn off ad personalization in Google, Meta, Apple account settings
- Deny app permissions by default (location, contacts, mic) and grant only when actively needed, not "always"
- Audit your smartphone privacy settings
- Use email image-blocking or a client that proxies images (Apple Mail Privacy Protection, Gmail's proxy) to defeat pixel tracking
- Opt out of data collection settings buried in smart TVs, IoT devices, and car infotainment systems (these are major, under-discussed collectors)
- Choose "dumb" devices over "smart" ones. No one needs a refrigerator that connects to the Internet.
2. Break linkability (stop data brokers from "identity stitching")
- Use unique email aliases per service (SimpleLogin, Firefox Relay, Apple Hide My Email) so a breach or resale doesn't tie back to one address (see Email Privacy)
- Use a password manager with unique logins - Reused credentials are a linkage vector
- Pay with virtual/masked card numbers (Privacy.com, bank-issued virtual cards) to avoid one card number tying purchases together
- Use a VPN to decouple browsing from your home IP (note: shifts trust to the VPN provider — worth a nuance point in the workshop)
- Avoid "Sign in with Google/Facebook" - it links account activity across unrelated services
- Use separate browser profiles or containers (Firefox Multi-Account Containers) to compartmentalize shopping vs. social vs. banking
3. Remove/limit existing exposure
- Submit opt-out/deletion requests to data brokers (or use a service like Optery, DeleteMe, or Consumer Reports' Permission Slip that automates this. California residents, use DROP service to automate this.
- Exercise legal rights where available: GDPR "right to erasure" (EU), CCPA "right to delete" (California)
- Freeze credit reports at all three bureaus to blunt identity-theft use of leaked data
- Google yourself periodically and request removal of sensitive results (Google has a form for this)
- Check "Have I Been Pwned" and rotate passwords/security questions on flagged accounts
4. Reduce the "surface area" you expose
- Minimize what you share on social media (birthdate, location tags, employer): these feed both direct profiling and social-engineering/security-question guessing
- Use Virtual phone numbers (Google Voice, MySudo) for signups that demand a number
- Decline loyalty programs/surveys that trade discounts for detailed personal data, or use a minimal/generic identity for them
- Review and prune app permissions and connected third-party apps (OAuth grants) periodically — these often persist long after you stop using a service - see
5. Behavioral/operational habits
- Read privacy policies for data sharing/selling clauses specifically (skip to that section rather than the whole doc). See Mozilla's Nothing Personal for product reviews that focus on respect for privacy
- Use "does this need to know that?" as a gut check before filling out forms
- Segment your identity: a "public" persona for social/professional life vs. a more guarded one for everything else
Check out orgs like...
- Electronic Frontier Foundation
- Privacy Rights Clearinghouse
- World Privacy Forum
- The Center for Democracy and Technology
- Nothing Personal and ToSDR are both sites designed to rate/review common products based on how they handle their customers' privacy