Richard Ford | Group CTO | Integrity360 | mail me |
International Data Privacy Day on 28 January usually brings a wave of advice about passwords and privacy settings. Most of us tune it out. Instead, we fall back on a comfortable but dangerous cop-out.
We say, “I am boring. I have nothing to hide”. This reflex often defines how people approach Data Privacy Day each year. This apathy creates our greatest vulnerability.
Most of us would feel deeply uncomfortable if our medical records, therapy notes, or credit scores were shared with colleagues or posted on a street WhatsApp group. That natural recoil proves we all have information we want to keep private. The problem is not that we do not care. The problem is that we do not see where the data goes.
The invisible supply chain of personal data
When you start receiving spam SMSes or scam calls, it is easy to assume a hacker stole your number. In reality, someone likely sold it.
Data has a supply chain, much like retail goods. You may give your details to a legitimate gym app or an online clothing store. You trust them. However, that app often relies on third-party aggregators and marketing partners. Your data travels to those parties. They may combine it with other information, such as location history or spending habits. They then sell refined lists to marketing firms.
You signed up with a brand you know. But behind the scenes, there is an entire ecosystem of vendors you have never heard of. Privacy is not just about what you share. It is about who your vendors share it with. This reality often goes unnoticed on Data Privacy Day.
The high cost of “free” rewards
In South Africa, loyalty programmes function almost like a second currency. People swipe for points, miles and cash-back without hesitation. However, the exchange rate can be high. When you swipe for a free coffee, you often trade deep behavioural data. You tell a system what you buy, when you buy it, which branch you visit and how price-sensitive you are.
This behaviour creates a detailed digital twin of your life. Advertisers value this profile highly. While this can improve service, consumers must check the fine print. Look for vague phrases in Terms and Conditions, such as “sharing for business purposes” or “with select partners”. These phrases often allow data to leave the organisation you trust. This risk deserves more attention during Data Privacy Day discussions.
When you click ‘I Agree’ on a major software ecosystem prompt or a comprehensive loyalty programme, you are not just skipping a flyer. You are skipping the entire script of Macbeth, which runs to about 17,000 words.
If you signed up for just three major apps or services this year without reading the T&Cs, you likely skipped the equivalent of George Orwell’s Animal Farm, which is around 30,000 words. You would not sign a mortgage without reading it. Yet we sign away our digital rights in novels we never read.
The SME blind spot – shadow IT
This risk moves from personal irritation to professional liability for business owners. In the pursuit of efficiency, employees often register for free online tools. These include PDF converters, AI text generators, and project management apps. They usually use their work email addresses. This practice is known as Shadow IT.
If you are a business owner and your employees use cheap, unvetted software to run payroll or process client documents, you expose your organisation. When an employee clicks ‘I Agree’ on a free tool, they may grant that vendor rights to uploaded data. You are outsourcing security to a company you have never vetted.
Business owners do not need legal training. However, they must treat software procurement with the same seriousness as hiring a physical security guard. If software is free, business data is often the payment. This is a core message that Data Privacy Day aims to highlight for organisations.
Taking back control
One of the most dangerous permissions people grant is the “Sign in with…” button. It offers convenience. However, if a third-party app suffers a breach, attackers could gain access to your primary email or cloud accounts.
As a rule of thumb, if an app asks for permissions that do not match its function, delete it. A torch app does not need your contacts list. You do not need to disconnect entirely to stay safe. Instead, focus on reducing your risk surface. Review app permissions regularly. At a minimum, read the “Third Party” clause in contracts. These steps matter far more than most people realise on Data Privacy Day.
Being mindful of data privacy simply means vetting the company you keep. Even if you think you have nothing to hide, you certainly have something worth protecting.

























