Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Protection - Data Privacy Day 2025: Protecting Sensitive Information Has Never Been More Critical 
Data Protection Articles Data Loss Prevention Industry Insights Security

Data Privacy Day 2025: Protecting Sensitive Information Has Never Been More Critical 

Kirsten DoyleBy Kirsten DoyleJanuary 28, 2025Updated:January 28, 20256 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Data Privacy Day
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Every year, 28 January marks Data Privacy Day, a global event dedicated to championing the importance of data protection and privacy in our increasingly digital, connected world.  

Established by the Council of Europe in 2006, this day commemorates the anniversary of Convention 108, the first binding international treaty on data protection.  

The purpose of the Convention was: “To secure in the territory of each Party for every individual, whatever his nationality or residence, respect for his rights and fundamental freedoms, and in particular his right to privacy, with regard to automatic processing of personal data relating to him.” 

Over the years, it has become a day about raising awareness about protecting personal data, particularly as technology continues to change the way information flows across borders. 

Cybersecurity experts share their thoughts on how to protect sensitive data and strengthen privacy in a time of soaring digital threats and growing regulatory scrutiny. 

Effective Data Management 

For Carl D’Halluin,  CTO of Datadobi, the number one data privacy best practice is ensuring the right data is in the right place at the right time. “Throughout its lifecycle, data should be protected and only accessible as needed. While this is easier said than done, it’s imperative to implement the right strategies and technologies. Data is an organization’s most valuable asset and its greatest potential risk.” 

D’Halluin says balancing these aspects is crucial. “Effective data management optimizes business intelligence, enables smarter decision-making, and provides a competitive edge. It also ensures compliance with internal governance, legal mandates, external regulations, and financial goals.” 

Outpacing the Development of Frameworks 

Tech advancements and the AI boom, in particular, are changing the data privacy game, says Ravi Bindra, CISO at SoftwareOne. “AI has fast become a firm fixture at such a pace that merely offering AI solutions as a business is no longer a differentiator; however, using the technology responsibly certainly can be. With new regulations set to come into force, particularly the EU’s Digital Operational Resilience Act (DORA), not to mention growing public awareness of how much personal data they entrust to businesses, there’s a world of new compliance and moral obligations that all must strive to meet in equal measure.” 

Bindra believes that the main challenge is that the speed of technology evolution is outpacing the development and implementation of data governance frameworks and security protocols for businesses to roll out.  As such, a priority focus for Data Privacy Day must be on ways to balance AI investment with secure integration.  “Ensuring that security protocols are baked into all processes to provide employees with clear direction on accepted AI use. This should be met with increased AI training for staff, so employees understand their key role in keeping organizational data secure.”  

Taking it a step further, Binddra says hybrid cloud models can be set up to keep secondary and tertiary backups in other locations, keeping data isolated from threats within internal networks.  “With so much at stake, from reputational damage to customer and financial loss, protecting sensitive data through AI and cloud investment should be business critical in 2025.”   

Reinforce Potential Weak Spots

“As AI advances, protecting sensitive data is an increasingly complex task,” comments Steve Bradford, Senior Vice President EMEA at SailPoint. “Security risks associated with an explosion in machine identities are growing ever more prevalent, with 7 in 10 companies now managing more machine identities, such as software bots and robotic process automation, than human identities. Combine this with rising numbers of non-employees, such as freelancers and contractors, and the scope for identity related infiltration widens.”  
 

Bradford says with no proper oversight as to who can access what, when, why and for how long, it makes it close to impossible to secure a business and its wider supply chain. “This challenge will only grow more complex as the volume, variety and velocity of identities continues to increase: this Data Privacy Day should prompt organizations to take action and reinforce potential weak spots that could be seen as easy access points for cybercriminals.” 

Be Mindful of Information  

“This is a great time for developers and product leads to remember that ‘if you don’t collect it, it can’t find its way into a breach,’ and be mindful of how much information is captured and stored that may be a liability to the business rather than an asset,” says Evan Dornbush, a former NSA cybersecurity expert.  

Dornbush says for end users, in the past few months, clear-text SMS messages and call data records, some dating back as far as seven years, have been disclosed in telecom hacks. “Encrypted options for video, voice, and text exist and are now being promoted by professionals and government groups alike.” 

Understand How Data is Collected, Processed

“So much of our personal information is constantly being collected, shared, and analyzed across websites, apps, devices, and services,” says Miia Hytonen, Privacy Risk and Compliance Manager at Laserfiche. “It’s more important than ever to understand how data is collected and processed, especially with the AI boom dramatically changing technology and how we do things at work and personally this year.”  

Hytonen adds that individuals and entities can limit what data they allow to be collected and processed by updating privacy and security settings on mobile apps and IoT devices and browsing online according to their preferences. This will help individuals protect their personal data and better protect organizational data, too, including, of course, customer data.  

It is extremely important that we all mobilize the significant privacy tools available to us in our online toolkits—through web browsers, applications, software, etc. For 2025, understanding privacy awareness is vital to understanding how information may be used in the event of data breaches and, again, with the rapid deployment and use of AI tools, Hytonen explains. 

Security and Privacy Go Hand in Hand

“Data Privacy Week is a good opportunity to reflect on how security and privacy go hand-in-hand,” says  Jawahar Sivasankaran, President at Cyware. “Threat intelligence is a critical part of protecting sensitive data – it helps us identify and respond to risks before they turn into tangible threats. A strong security posture is essential for safeguarding privacy, and this week underscores the need to integrate both into your strategy. Protecting data is about more than compliance; it’s about being proactive in identifying and mitigating risks to keep both privacy and security intact.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}