A Data Protection Officer’s First Privacy Lessons

Here are three formative privacy experiences that happened years before I knew what a Data Protection Officer (DPO) was — a forum, a hacked MySpace account, and a television show about people pretending to be someone else.

@kierinsightarchives on Unsplash

Forums

In the early to mid 2000's, I discovered online chats and forums for the first time. I was quickly sold to the idea of sharing ideas and thoughts online, with the added bonus of creating your own profile with varying levels of creativity and even learning HTML. I loved being part of a (Harry Potter) community with like-minded people, which enhanced my first experience in the digital realm.

This was also the time when I learnt that the internet was a big place and not everyone was there to talk about books. My parents' lecture on online safety, sharing personal information and general 'internet smarts' came very early on in my life.

This was the first time that it dawned on me that people could pretend to be someone else (which we'll come back to), have bad intentions and can use the information I give them for something I didn't intend or expect.

Being on a forum was the first time I accidentally put into practice the data minimisation principle, thinking about how much data I actually need to share about myself to make the most of the discussions online.

MySpace

What I'd learnt about sharing details about yourself online clashed horribly with the hype and appeal of MySpace. By the time it got popular, I'd already moved countries as a moody teenager, was homesick and craved the connection I didn't have with friends anymore (or with anyone).

I tentatively created a profile for myself and, once again, entered a similar online community with friends and where people liked the same music as me. It felt good until my account got hacked.

I didn't know what exactly "being hacked" meant but I knew it was bad.

I felt guilty because I felt like I'd betrayed myself and let someone get into my account, seeing limited but definitely identifying information about me.

Who hacked my account? Why and how; what information did they access? We will never know. I deleted MySpace and that was it because that was only viable response at the time – no remedy, process or anyone to ask what had happened.

The uncertainty about the scope of the breach is what stays with people whose information has been unlawfully accessed. Once it’s out, you can’t get it back regardless of how little data did come out. It’s still about you and can still be used. Or not – either way, you don’t know. And that’s the unsettling part.

Catfishing

Years later, I watched Catfish — the 2010 documentary, then the MTV series it spawned — and recognised something I'd already half-learnt as a teenager on a forum. I knew people pretend to be other people online, but what the show made concrete was the method.

A stranger doesn't need much. They gather the details you've left in different places and assemble them into a picture of you. They take your photographs and use them to build someone else. Someone who now has a relationship with a person you have never met.

They do this repeatedly, keeping folders of the material, because there is no cost or repercussions to doing it again. Some people have no regrets doing it either despite it having profound effect on people’s lives.

People are still writing to the hosts to ask whether the person they love is real. From everything I have seen, they rarely are.

From Idealism to Pragmatism

Another confession is that time and practice have changed me from a privacy idealist when I was a law student to a much more balanced and commercially-aware DPO who knows it's not all or nothing with privacy (and data protection).

Back at university, I thought data collection was rarely okay, pretending, for example, that I didn't appreciate it when Netflix was suggesting content I'd like. This is not the case anymore. While I remain a privacy advocate, experience and real life have thought me a lot about balance, compliance and risk management. Data protection compliance is always a work in progress and rarely 100% at all times.

Finally, I do as I say... but not with cookies. I don't individually reject them all if they are more than 10 lines of text, toggles or the banner lists 100+ partners. This needs an overhaul from above.

Previous
Previous

Shortlisted Author/Creator of the Year at the PICCASO Awards 2026

Next
Next

Good Faith and Respect for the GDPR are not a Lawful Basis