Technicien Informatique ParisRepair · IT Support · Web — Paris 16e
Blog

How to Protect Your Personal Data Online

How to Protect Your Personal Data Online

The most common image of online protection is a VPN icon lighting up on a phone. In practice, that one habit accounts for a small slice of what actually keeps your personal data safe. What exposes most individuals in Paris is almost never the Wi-Fi at the café where you work for an afternoon — it's a password reused across a dozen sites, an old forgotten account that leaked without your knowledge, or public information stitched together by a data broker you've never heard of. This guide ranks what actually helps by effort versus benefit, without the usual VPN marketing pitch.

Hand holding a smartphone showing an active VPN app, with a checked VPN toggle at the bottom of the screen
Illustration: a lit-up VPN icon feels reassuring, but it only covers a small part of your personal data protection.

The real risk: data brokers, breaches and oversharing

Companies whose business is collecting and reselling personal information — reverse phone-lookup sites, "people search" directories, advertising data brokers — combine name, address, phone number and buying habits from public records. Most people discover these exist the day they search their own name and land on a profile they never created.

Data breaches often trace back to services you used once and forgot — a forum, a delivery app you tried years ago — and the password that leaked there is probably still reused elsewhere: a minor leak on a forgotten site turns into full access to an email or bank account. Voluntary oversharing matters too: holiday dates shared ahead of time, a child's school named in a photo caption, a home address visible on a parcel in a story. None of that is a hack, but it's often what makes a targeted scam believable.

Public Wi-Fi deserves to be downgraded on the worry list: by 2026, almost every site encrypts the connection by default, and someone snooping on a café's network can no longer read your email the way they could a decade ago. Far from the top threat VPN advertising makes it out to be.

What actually helps, ranked by effort and benefit

1. Unique passwords, through a password manager

The best effort-to-benefit trade on the list, by far. A password manager (Bitwarden is free, 1Password and Dashlane are paid) generates and remembers a different password for every site. Setup takes about an hour; after that, it fills credentials in on its own. A leak on a forgotten site no longer unlocks anything else.

Open laptop showing a social media login page, with a potted plant and a phone resting beside it on a white desk
Illustration: every account created online is one more database that could end up in a future leak.

2. Two-factor authentication, on email first

Your primary email acts as the reset key for almost everything else. Turning on two-factor authentication there first, ideally with an authenticator app rather than SMS, blocks most fraudulent sign-ins even if the password has already leaked. Only then move on to your bank account and main social network.

3. Checking your breach exposure

Have I Been Pwned lets you type in an email address and see, in about thirty seconds, which known breaches it has appeared in. Free, no installation, and it turns a vague worry into a concrete picture. Checking every six months is plenty.

4. Reviewing app permissions on your phone

In iOS or Android privacy settings, plenty of apps have "always" location, microphone or contacts access that isn't actually needed. Switching to "while using the app" and removing unneeded access takes about ten minutes and noticeably cuts background data collection.

5. Browser hygiene and tracker blocking

Safari and Firefox block a good share of trackers by default; Chrome does less, and an extension like uBlock Origin closes the gap. Clearing cookies regularly and removing unused extensions limits day-to-day ad profiling.

6. Thinking before you post

The least technical step, and the most overlooked. Location metadata in photos, a holiday date shared in advance, a front door with the street number visible — added together, they map out someone's daily life fairly precisely. Posting after you're back rather than in real time meaningfully lowers that risk.

The France-specific part: GDPR erasure, CNIL complaints, France Connect

The GDPR includes a right to erasure (Article 17): the right to ask a company to delete the personal data it holds on you, with a few legal exceptions (accounting obligations, an ongoing dispute). In practice, a written email to the relevant department or its data protection officer, citing Article 17 and specifying the data, is enough. The organisation has one month to respond.

If there's no response within that month, or an unjustified refusal, a free complaint can be filed online with the CNIL, France's data protection authority, at cnil.fr. It's not symbolic — the CNIL can sanction an organisation that ignores these requests, and simply mentioning that possibility in the initial email often speeds up the response on its own.

France Connect centralises access to impots.gouv.fr, Ameli, the CAF and other public services behind a single login. A weak or reused password on that one account doesn't just risk that service; it potentially exposes everything routed through it. A client near the 14th once spotted, in his impots.gouv.fr login history, a sign-in at a time he hadn't touched his computer — a password recycled from an old forum was the likely cause. Checking that history once or twice a year, and keeping the France Connect source password unique, protects everything that depends on it in one move.

What's not worth your time

Private browsing only stops history and cookies from being saved on the device you're using. It hides nothing from your internet provider, from an employer on a company-managed network, or from the sites themselves, which still identify you through your account or through device fingerprinting that doesn't rely on cookies. Useful for keeping a search out of a shared history, not for privacy in any broader sense.

A consumer VPN deserves the same honest treatment. It encrypts the connection and hides your real IP from sites you visit while not logged in — useful on a Wi-Fi network you don't trust, or for geo-restricted content while travelling. It is not a general anonymity tool: the moment you sign in with Gmail, Facebook or Amazon, those services identify you perfectly, VPN on or off. It doesn't stop data brokers either, and doesn't replace unique passwords. Don't confuse it with the business VPN used to connect to a company network for remote work — a different use case, covered in my article on setting up a VPN for remote work: there, the goal is access to internal company resources, not an individual's privacy.

A hand on a laptop trackpad in a café, with a connected VPN app shown on screen and a coffee sitting on the table
Illustration: a VPN protects the local connection on a café's Wi-Fi, not your entire digital identity.

The 30-minute weekend routine

One weekend morning covers the essentials, in this order:

  • 5 min — turn on two-factor authentication on your primary email, using an authenticator app.
  • 5 min — check your email address on Have I Been Pwned and note which services are affected.
  • 10 min — install a password manager and change the three or four most-reused passwords (email, bank, main social account).
  • 5 min — review location and microphone permissions across the apps on your phone.
  • 3 min — check the login history on impots.gouv.fr or Ameli if you use France Connect.
  • 2 min — send a GDPR erasure request to one data broker or forgotten service, just to build the habit.

My free security checklist, on the free tools page, walks through these same steps if you'd rather tick boxes than follow an article top to bottom.

Paris pricing

Most of this is a solo job, but if the starting point is already messy — dozens of accounts to migrate, a password manager switch, or simply no time to spare — I can handle it remotely or during a home IT visit in Paris. Setting up a password manager with two-factor authentication on the main accounts usually runs €69 to €99 depending on the number of accounts. For a broader pass covering phone and computer app permissions too, a standard IT troubleshooting visit covers it in an hour or two.

Frequently asked questions

Is antivirus software enough to protect my personal data?
No. Antivirus software protects against malware installed on a device, but it does nothing to stop a leaked password being reused elsewhere, a data broker reselling your information, or what you post yourself. The two protections are complementary, not interchangeable.

Do I need a VPN to protect my personal data?
A consumer VPN encrypts your connection and hides your IP address from sites you're not logged into, which is useful on public Wi-Fi or an untrusted network. It does not make you anonymous on sites where you're signed in with your own account, and it does not replace unique passwords or two-factor authentication.

How do I exercise my GDPR right to erasure?
Contact the organisation's data protection team or data protection officer in writing, citing Article 17 of the GDPR and specifying which data should be deleted. The organisation has one month to respond. If there's no response, or an unjustified refusal, a free complaint can be filed online with the CNIL, France's data protection authority, at cnil.fr.

What should I do if my account has already been hacked?
The preventive steps in this article won't undo an active breach. If an account is compromised right now, the priority is changing the password from a clean device and revoking active sessions: the full process is covered in my article on a hacked account, what to do in the first hour.

Need help securing your accounts?

Get it sorted with a technician in Paris

Password manager setup, two-factor authentication, breach checks and app-permission reviews: I can help by phone, WhatsApp, remote support, or on-site in Paris.

More articles

Back to the blog listing

See the latest published guides and blog posts.