What Data Privacy Day is about
Every January 28, Data Privacy Day (known in Europe as Data Protection Day) asks a simple question: do you actually know where your personal information lives, and who can reach it? The date marks the 1981 opening for signature of Convention 108, the first binding international treaty on protecting personal data. What started as a European observance is now marked across North America too, led by nonprofits, schools, companies, and government agencies.
The goal is not to scare you offline. It is to turn a vague, low-grade worry into a short list of concrete actions. Most privacy leaks do not come from Hollywood-style hacking; they come from reused passwords, oversharing apps, and forgotten accounts. Those are all fixable in an afternoon.
Privacy is not about having something to hide. It is about getting to decide what you share, with whom, and when.
A quick history
The idea of protecting personal data predates the modern internet. As governments and banks began storing records on early computers in the 1970s, people realized that centralized data could be misused as easily as it could be helpful. Convention 108 set out principles that still sound current: collect only what you need, keep it accurate, secure it, and let people see and correct their own records.
Decades later those principles echo through laws like Europe’s GDPR and various U.S. state privacy acts. Data Privacy Day exists to remind the rest of us, the everyday account-holders, that we have a role too. The strongest regulation in the world still cannot force you to turn on two-factor authentication.
How to make the most of January 28
Treat today as a recurring maintenance day, the way you might change smoke-detector batteries. You do not need to do everything; pick two or three high-impact moves and actually finish them.
Start with your email account, because it is the master key to almost everything else. Give it a long, unique password and a second login factor. Then open your phone’s privacy settings and prune app permissions you never think about. If you have twenty minutes more, set up a password manager and let it flag the reused passwords you have been meaning to fix.
For the ambitious, freeze your credit with the three bureaus and file a few data-broker opt-outs under your own name. Parents and teachers can make it a conversation instead of a chore, walking kids through what a strong passphrase looks like and why “check the sender before you click” matters.
Finally, write next year’s date, January 28, on your calendar with a two-line checklist. Privacy is not a one-time project; it is a habit you renew. A single focused hour today buys you a much quieter, safer digital life for the twelve months ahead, and that is a genuinely good trade.
How to celebrate
- 1Turn on real two-factor auth
Switch your most important accounts (email, bank, primary password manager) to two-factor authentication, and prefer an authenticator app or a hardware key over text-message codes. SMS codes can be intercepted through SIM-swap attacks, so app-based or physical keys are meaningfully safer. Start with your email, since whoever controls it can reset everything else.
- 2Audit your app permissions
Open the privacy settings on your phone and scroll through which apps have location, microphone, camera, and contacts access. Revoke anything that does not obviously need it, and set location to While Using rather than Always. On both iOS and Android you can also see which apps recently used those sensors, which often surprises people.
- 3Start using a password manager
Pick a reputable password manager and let it generate long, unique passwords so a breach at one site cannot unlock the rest. Import your existing logins, then work through its security report to replace reused or weak passwords a few at a time. You only have to remember one strong master passphrase after that.
- 4Freeze your credit and cut brokers
Place a free credit freeze with the three major bureaus so no one can open accounts in your name; you can thaw it in minutes when you actually need credit. Then search your own name plus your town and file opt-out requests with the data-broker sites that list you. Set a calendar reminder to repeat this yearly, since listings creep back.