SimplComIA

Data breach: what to do, and in what order

Your personal data has leaked? The actions to take in order of urgency: passwords, bank, phone, phishing, erasure requests.

Once a database has been stolen, nobody can recover the copies in circulation. The goal is therefore to make that data useless and to limit abuse. Here are the steps, from most to least urgent.

1. Your password leaked: change it now

Change it on the site concerned and on every site where you used the same one. Turn on two-factor authentication for your email first: it is what lets anyone reset all your other accounts. Details in compromised password: how to react.

2. Bank details leaked: alert your bank

Card number: have it blocked. IBAN: watch your direct debits. See IBAN or bank card in a breach.

3. Expect phishing attempts

Scammers use stolen data to make their messages convincing: they know your name, the site you were a customer of, sometimes your address. Learn to recognise them.

4. Your phone number leaked

Be wary of texts and calls claiming to be your bank or a delivery company, and protect your line against hijacking. See phone number in a breach.

5. Ask for your data to be erased

The GDPR lets you require the company concerned to delete the data it still holds about you, especially if you no longer use the service. It has one month to reply. See GDPR erasure request.

6. No reply: complain to the data protection authority

If the company does not reply or refuses without a valid reason, you can lodge a complaint with a data protection authority.