Data breach: what to do, and in what order
Your personal data has leaked? The actions to take in order of urgency: passwords, bank, phone, phishing, erasure requests.
Once a database has been stolen, nobody can recover the copies in circulation. The goal is therefore to make that data useless and to limit abuse. Here are the steps, from most to least urgent.
1. Your password leaked: change it now
Change it on the site concerned and on every site where you used the same one. Turn on two-factor authentication for your email first: it is what lets anyone reset all your other accounts. Details in compromised password: how to react.
2. Bank details leaked: alert your bank
Card number: have it blocked. IBAN: watch your direct debits. See IBAN or bank card in a breach.
3. Expect phishing attempts
Scammers use stolen data to make their messages convincing: they know your name, the site you were a customer of, sometimes your address. Learn to recognise them.
4. Your phone number leaked
Be wary of texts and calls claiming to be your bank or a delivery company, and protect your line against hijacking. See phone number in a breach.
5. Ask for your data to be erased
The GDPR lets you require the company concerned to delete the data it still holds about you, especially if you no longer use the service. It has one month to reply. See GDPR erasure request.
6. No reply: complain to the data protection authority
If the company does not reply or refuses without a valid reason, you can lodge a complaint with a data protection authority.