SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Story image

KnowBe4 shares data protection tips for 2025 privacy focus

Today

KnowBe4 is marking Data Privacy Day by providing practical recommendations to assist individuals and organisations in taking charge of their data security.

Data Privacy Day, celebrated annually, underscores the importance of protecting and managing online privacy. This initiative started in the United States in 2008, extending from Data Protection Day in Europe, and is spearheaded by the National Cybersecurity Alliance (NCSA) in North America.

In 2025, the event's theme, 'Take Control of Your Data,' aims to inspire individuals to regain their digital autonomy through straightforward, actionable steps for informed privacy decisions, while urging organisations to respect and prioritise users' data privacy.

With the increasing prevalence of social media platforms, AI chatbots, and connected devices, there is an expanded digital footprint that heightens the risk of misuse of personal information. These developments can potentially lead to identity theft, financial fraud, and psychological damage.

Recognising the collective responsibility of data protection, KnowBe4 provides ten recommendations for individuals and organisations for 2025.

Tips for individuals:

  • Vet your apps and tools: Before using new apps, check their data usage policies, control options, and origin to ensure they are trustworthy.
  • Optimise IoT device privacy: Adjust settings in your IoT device apps to enhance privacy, such as disabling voice recordings, limiting data storage, or controlling ad preferences.
  • Educate your family: Discuss online safety with family members, especially children, covering topics like avoiding sharing personal information, recognising suspicious links, and managing location sharing.
  • Set up a reputable password manager: Use it for critical accounts and generate strong, unique passwords.
  • Enable multi-factor authentication (MFA): Activate MFA, preferably with a FIDO token, for critical accounts as an added layer of protection.

Tips for organisations:

  • Minimise data collection: Only collect and store data that is essential for business operations. Eliminate unnecessary personal or payment information.
  • Communicate transparency in privacy policies: Clearly explain what data is collected, how it is used, and with whom it is shared.
  • Train employees: Educate all employees on data protection regulations, while training them to recognise the latest social engineering attacks and other security risks.
  • Encrypt personal data: Protect personal data—at rest and in transit—from unauthorised access or exposure.
  • Vet vendors and partners: As a 'responsible party', your organisation is responsible and accountable for protecting the data of its subject – even if the processing is outsourced to third parties. Ensure that any external parties handling your organisation's data maintain a high standard of privacy and protection.

"The new year brings a wave of challenges, especially with the rapid advancements and creation of AI-driven technologies," said Lecio DePaula, Vice President of Data Protection for KnowBe4.

He continued, "For AI to function effectively, it relies on vast amounts of data being collected and utilised, which raises important questions about privacy, transparency, and ethics. It is up to every organisation to take responsibility, not just in regards to how data is handled, but in fostering a culture of accountability. We have an obligation to build and maintain trust as we navigate our digital landscape."

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X