As Data Privacy Day on January 28 casts a spotlight on how enterprises use personal information, security and customer engagement leaders are warning that the biggest privacy risks are shifting from external hacks to the misuse of trusted access and the growing role of AI.
Also known as Data Protection Day, the annual reminder was established by the Council of Europe to encourage “all of us… to safeguard our personal data and uphold our right to privacy.”
Chris Harris, EMEA Technical Director, Data and Application Security at Thales, argues that many customers still don’t feel they have meaningful visibility or choice over how their personal data is used. “Data privacy still feels like a black box,” Harris said.
“Our research shows that a third of consumers don’t understand how their data is managed and only share personal information because they see no other option. That’s not informed consent, it’s quiet coercion.”
Harris added that privacy frustration is already translating into lost business, warning against organizations leaning on lengthy terms and conditions that leave customers in the dark and suspicious about entrusting their information.
“It’s no surprise that 82 percent of people have abandoned a brand over concerns about data use.”
“Trust won’t be rebuilt through longer privacy policies. It will come from making data use visible, understandable and meaningful – clearly highlighting what data is collected, why it’s needed, how long it’s kept and who or what is accessing it,” Harris said.
Building Trust Through Careful Data Handling
Separate research from Zoho suggests 46 percent of organizations in the UK see privacy as important, but just 36 percent say their business complies with all regulations and industry guidelines. Meanwhile, only 43 percent report conducting regular training, and 45 percent have clear and transparent data privacy policies, down from 50 percent in the Zoho Digital Health Study 2025.
Sachin Agrawal, Managing Director at Zoho UK, said the stakes have moved beyond regulatory box-ticking.
“Data privacy is no longer just a compliance requirement, but rather a requirement of building trust with customers. As organisations become increasingly reliant on data and emerging technologies, protecting personal information must be embedded into every aspect of their operations.”
Trust can be won—or lost—at the point of interaction. For customer-facing brands, privacy concerns may surface in the most everyday moments: a text message, a verification code, an unexpected phone call.
"Customers want clarity and control over their information, and agents should only access the minimum data required not only reduce exposure but also deliver more accurate, meaningful results.”
Privacy breakdowns often stem from human and process failures rather than technical shortcomings, Agrawal added.
“When privacy is treated as a core value rather than an afterthought, companies not only reduce risk, but also strengthen customer confidence and loyalty."
Organizations that prioritise transparency around how they handle data will be better placed to deliver better customer experience, Agrawal added.
Corey Nachreiner, CSO at WatchGuard Technologies, said: “Data privacy risk today isn’t primarily caused by attackers breaking through a firewall; it’s driven by identity compromise and the misuse of trusted access.”
Criminals are increasingly using “social engineering and AI-enabled deception to steal credentials, impersonate legitimate users, and quietly exfiltrate data,” often starting with “something as simple as a deceptive link or download,” Nachreiner said.
Privacy Best Practices That Build Trust
Enterprises need to adapt to the changing threat landscape by moving beyond fragmented security controls and adopting integrated protections that reduce exposure across the data lifecycle.
“This shift is why protecting data now requires a simpler, more unified approach that combines identity, endpoint, and identity protections. When those layers operate in silos, gaps emerge that attackers are quick to exploit.”
Simple measures such as verifying download sources, using multi-factor authentication and maintaining strong credential hygiene can interrupt attackers even when they gain access to credentials, preventing data breaches, regulatory exposure, or long-term reputational damage, Nachreiner said.
Genetec, which provides enterprise physical security software, shared best practices to help organizations protect sensitive data while maintaining effective security operations. Mathieu Chevalier, Principal Security Architect at the company, said:




