Time to Assess Your Digital Privacy
Cyberattacks do not only target states and businesses — they can also have direct consequences for individuals. Vast amounts of personal data are stored by employers, public agencies, and private companies. Vulnerabilities in their systems can put our privacy at risk.
March 19, 2025 | SOCIETY
Image by AI/S&P
Threat of Cyberattacks
We are living in uncertain times, and cyberattacks are our greatest fear, as emerged on NRK Debatten (Norwegian news program) yesterday. Preparedness is a word we hear increasingly often, but not often in relation to the internet. Although the fear itself was mentioned in the debate, preparedness in that context was not discussed.
When it comes to cyberattacks, we may primarily think of attacks against the state and businesses, but they can also affect us personally. A vast amount of information about us is stored by employers, public agencies, and private companies. These entities can be subjected to cyberattacks that put our personal privacy at risk.
Furthermore, we must be aware that social media are also vulnerable and pose a risk. Many of us have large amounts of data stored with various companies — something we will return to further below.
Digital Security
As for Norwegian authorities, there is reason to question how secure our personal information is. In March last year, the Norwegian Data Protection Authority issued a fine of NOK 20 million to NAV (the Norwegian Labour and Welfare Administration) for breaches of privacy legislation. NAV appealed, and in December the Personvernnemnda (the Norwegian Privacy Appeals Board) decided that NAV would not have to pay the fine, as they considered the breach not to be intentional.
On NRK Nyhetsmorgen (Norwegian news program) in December 2023, it also emerged that NAV uses American cloud services. Furthermore, Fagforbundet (Norway’s largest trade union) writes that these providers do not necessarily comply with General Data Protection Regulation, the European data protection rules.
In the private sector, the use of foreign IT services is widespread. Both public and private entities are exposed to, and are subjected to, cyberattacks. This means that our personal privacy is at risk.
Social Media
Social media are also vulnerable to cyberattacks. Just a week ago, the social media platform X was subjected to a major cyberattack. This makes it important to consider which social media platforms we use and what information we provide to them. Social media store large amounts of information about you. Every single activity you have performed on your account is stored. This includes, among other things, where you have logged in, your IP address, your hardware identity, your personal data, every post and comment you have ever made, all messages you have sent and received, all “likes” you have given, all people you have been in contact with, the groups you follow, what you view, who your friends are, and much more.
Companies stores information about you
Email services, web browsers, search engines, and online service providers also store large amounts of information about you. Some companies own browsers, search engines, email services, and multiple social media platforms. It is important to be aware that information is shared across these platforms. Furthermore, it is difficult to maintain an overview of what information they sell to other companies — which they do.
How to Prepare
Think in terms of online security and preparedness. Start early — a power outage may prevent you from doing so.
Consider where you have accounts. This applies to both public and private entities, social media, and all other services mentioned above, as well as those I may have forgotten. What service do they provide? Do you need it? Who owns it? Where is it based? Is it secure?
Use privacy settings on hardware, operating systems, internet services, browsers, search engines, websites, applications, accounts, and memberships, etc.
Use a unique and secure password for each account, and change them regularly. Use two-factor authentication. Log out after use. Do not store passwords in your browser.
Review your information — should you delete anything? Deleting information can be an extensive process; see the point below.
If you decide to delete an account entirely, you cannot assume that simply deleting the account is sufficient. All information and data should be deleted before the account is deleted. Once this is done, you can ask the company to disclose what information they hold about you, and then submit a request for all information to be deleted. Once this has been confirmed, you can delete the account.
SOURCES
NRK (Norwegian Broadcasting Corporation)
The Debate on Emergency PreparednessDatatilsynet (Norwegian Data Protection Authority)
Decision on NAV privacyPersonvernemda (Privacy Appeals Board)
Decision on NAV privacyNRK (Norwegian Broadcasting Corporation)
NAV’s use of American cloud servicesFagforbundet (Norwegian Union of Municipal and General Employees)
NAV and privacyIntersoft Consulting
European data protection rules GDPR
Content on Society and Politics is based on reliable sources and actual events, providing a news-oriented perspective intented for further debate. To access the article’s author and the related debate, membership on Hudd is required.