Opens in a new tab
vmblog logo 2024 wht (updated)

Data Privacy Day 2026: Industry Experts Weigh In on AI Governance, Zero Trust, and the Evolving Threat Landscape

Share: 

David Marshall | Published: January 27, 2026
data privacy day 2026

As Data Privacy Day 2026 arrives on January 28th, the conversation around data protection has never been more critical-or more complex. The past year has seen seismic shifts in how organizations handle personal information, driven by the rapid proliferation of artificial intelligence, increasingly sophisticated cyber threats, and a patchwork of evolving global regulations. From the EU’s AI Act taking effect to state-level privacy laws reshaping the American data landscape, businesses find themselves navigating a regulatory environment that demands both technical excellence and ethical accountability.

The stakes have escalated beyond mere compliance. High-profile data breaches, AI-driven privacy concerns, and growing consumer awareness have transformed data privacy from a back-office IT function into a boardroom imperative. Organizations are grappling with fundamental questions: How do we balance innovation with protection? What does responsible AI deployment actually look like in practice? And how can security teams stay ahead of threat actors who are themselves leveraging AI to exploit vulnerabilities?

To mark Data Privacy Day 2026, VMblog reached out to leading voices across cybersecurity, compliance, and technology to share their perspectives on the current state of data privacy and what organizations should prioritize in the year ahead. The insights that follow offer a comprehensive look at the challenges, opportunities, and strategies that will define data protection in 2026 and beyond.

++

Anthony Cusimano, solutions director, Object First

From grain to gold to bitcoin, currency has taken a variety of shapes throughout history. Today, data is our currency. Your personal information is bought, sold, and exposed via real-time bidding (RTB) more times than you’d like to know in a single day.  

AI has paved the slippery slope to exploitation with deepfakes, phishing campaigns, data poisoning, AI agents, and the list goes on. It’s no exaggeration to say that your data faces more threats today than at any other point in history, driven by AI-powered exploits and cyberattacks. 

That’s why it’s so important to have proper controls in place to protect your data.  

Start by reviewing your privacy settings, using strong authentication, and partnering with trusted organizations that prioritize security and recovery. Although we can hope organizations champion transparency and accountability, individuals also need to take proactive steps to protect their digital footprint.

++ 

Sam Peters, Chief Product Officer at IO (formerly ISMS.online)

Privacy in the US is being shaped more by enforcement than by a single federal law. As state-level privacy regulations continue to expand, organizations are forced to manage overlapping — and sometimes conflicting — requirements across jurisdictions. This fragmentation makes operational consistency the biggest challenge, as teams struggle to maintain a unified approach to data handling, consumer rights, and vendor oversight while controlling cost and risk.

In the absence of a nationwide privacy framework, market pressure is filling the gap. Supplier and customer expectations, enforced through contracts and procurement requirements, are increasingly driving privacy maturity across supply chains. At the same time, privacy risk is moving upstream into product and technology decisions, with issues like automated decision-making, data sharing, and profiling now evaluated earlier in development, particularly in regulated and high-growth sectors. Enforcement risk is also rising, as state attorneys general signal a greater willingness to investigate complaints, raising the bar for defensible governance and audit-ready processes.

To navigate this complexity, many organizations are turning to standards as a practical unifier. Frameworks such as ISO 27701 help establish consistent privacy controls across states while supporting international data transfers and partner trust. As privacy, security, and AI governance continue to converge, organizations that align these programs are better positioned to scale compliance and adapt to regulatory change without repeated rework. 

++

Sundaram Lakshmanan, VP of Development at Fortra

1. AI represents a generational leap in technology, and with it come new challenges that society will only fully understand over time. Privacy is one of the biggest concerns, and not all AI providers handle it in the same way. As laws evolve to catch up, users can protect themselves by avoiding the sharing of sensitive personal information such as identity details, financial or health documents, or family photos when seeking advice from AI tools. Digital images often contain hidden data like location and timestamps, and being aware of this is an important part of staying in control of your privacy.

2. The always on digital world has blurred the boundaries between personal life and work. People often use their personal devices for work tasks and their work devices for personal ones without a second thought. A simple way to protect both privacy and corporate data is to use separate browser profiles, or even different browsers, depending on the situation. This small habit helps maintain personal privacy while keeping organizational information secure.

3. Most people don’t realize how much information apps and websites collect beyond what they type into forms. Modern web tools track a wide range of online activity including uploaded photos, interactions, chats, hashtags, and mentions, which can all create a much larger data trail than users expect. To protect your privacy, people can adopt simple habits like using separate browser profiles, different browsers for different tasks, or distinct email addresses. These small steps help limit how much of your personal information gets aggregated.

++

Kevin Surace, Chair, Token

Over the last year, one thing has become painfully clear. Identity is now the attack surface. Groups like Scattered Spider and APT28 are not breaking systems anymore. They are logging in. After hundreds of public breaches, millions of stolen identities, and the repeated collapse of MFA apps and push approvals, we have to accept a hard truth. Knowledge and possession can both be stolen or relayed. Identity cannot.

That is why biometric identity is no longer optional. It must be hardware based, domain bound, and require physical proximity. If the system cannot verify who you are, where you are, and exactly which service is requesting access, it is already compromised. AI has made phishing instant and perfect. Training and awareness cannot keep up. Only absolute identity can. Anything short of biometric, cryptographically bound identity is no longer security. It is theater.

++

Richard Copeland, CEO, Leaseweb USA

In 2026, data privacy stops being an abstract compliance challenge and becomes a direct function of architectural decisions. Trusted Execution Environment technologies are finally viable at scale, and that changes how organizations think about where their most sensitive workloads live. When you can lock down data at the hardware and memory level, you’re no longer beholden to a single cloud provider for safety. You gain the freedom to run distributed, high-value workloads across multiple clouds, edge locations, and on-prem environments without sacrificing confidentiality or control. It’s a fundamentally different approach to privacy – one built on verifiable isolation rather than trust in the provider’s perimeter.

At the same time, AI’s shift from simple automation to agentic workflows is exposing the weaknesses of large, multi-tenant hyperscale environments. As AI continues to become more and more critical, the less tolerant organizations are of unpredictable billing, noisy-neighbor issues, opaque GPU allocation, or cascading failures triggered by one overloaded service. Likewise, attackers are evolving too, using AI to exploit precisely those blind spots. That’s why we’re seeing momentum toward regional and bare-metal infrastructure where the environment is cleaner, the performance is transparent, and the blast radius is smaller. For enterprises that care about privacy and operational resilience, 2026 is the year infrastructure strategy becomes inseparable from data protection and privacy strategy.

++

Jonathan Edwards, Managing Director at KeyData Cyber

Most organizations already understand the basics of data privacy and protection, and there is no shortage of guidance on how to do it “right.” Companies talk about knowing where their data lives, classifying sensitive information, encrypting it, limiting access, and aligning to frameworks and regulations. Identity and access controls, vendor risk reviews, privacy-by-design, and assume-breach thinking have become table stakes. These practices matter, and they should not be dismissed. They reduce risk, satisfy regulators, and create a baseline of trust. But they also represent a world where data is relatively static, users are mostly human, and boundaries are still somewhat defined. That world is already fading.

What is coming next challenges many of the assumptions those traditional models were built on. Data is now feeding AI systems that learn, infer, and remember in ways we do not fully control. Non-human identities, APIs, and autonomous agents are rapidly outnumbering employees. Data is no longer just stored in a region; it is processed, transformed, and recombined across borders in real time. At the same time, regulators are shifting their focus from whether controls exist to whether organizations can prove intent, governance, and restraint. The uncomfortable reality is that even companies doing “everything right” by today’s standards may still find themselves exposed tomorrow, not because they were careless, but because their models assumed stability in a world that is accelerating.

This is where privacy strategy has to become more philosophical, not just technical. Forward-thinking organizations are beginning to treat data less like an unlimited resource and more like a financial asset with real downside risk. They are experimenting with just-in-time data access instead of permanent permissions, running data misuse fire drills alongside breach simulations, and deliberately limiting how long data can exist at all, even in backups. Some are shifting analytics and AI development to synthetic or privacy-preserving data by default, not as a compliance exercise, but as a way to reduce existential risk. The most advanced conversations are no longer about how to protect data forever, but about when data should no longer exist, who should never have access in the first place, and how much risk the business is consciously willing to carry. In the next phase of data privacy, restraint may become the most powerful control of all.

++ 

Vijay Pawar, SVP of Product, Quokka

Mobile devices have become one of the most sensitive — and least governed — data environments in modern organizations. Smartphones routinely store authentication credentials, personal communications, financial information, and direct access to corporate systems. When a mobile device or app is compromised, attackers can quietly collect and exfiltrate sensitive data at scale, often without the user’s awareness. From a privacy perspective, this creates significant risk, particularly as organizations face increasing scrutiny around how personal and regulated data is accessed, processed, and protected.

Best practices now require a layered security approach that treats mobile apps as first-class data processors. While device management and network controls remain important, they are no longer sufficient on their own. Attackers are increasingly embedding AI capabilities directly into mobile applications to identify valuable data, adapt behavior to avoid detection, and operate in ways that appear legitimate to users and app marketplaces. This raises serious concerns for consent, transparency, and data minimization.

Looking ahead, organizations should expect mobile threats to become more adaptive, autonomous, and difficult to audit using traditional methods. To meet both security and privacy obligations, companies need deeper visibility into the mobile applications accessing their data, including insight into app behavior, permissions, third-party SDKs, and embedded AI functionality. Proactive analysis and continuous monitoring will be critical for maintaining compliance, protecting user trust, and ensuring sensitive data is not misused as mobile ecosystems continue to evolve.

++

Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer at AvePoint

Building on the shared responsibility mindset that’s been widely highlighted for Cybersecurity Awareness Month, Data Privacy Week draws attention to individual data ownership and designing privacy into the way we work and the systems we rely on. Personal data ownership and agency is critical both in and outside of the workplace, which is data directly tied to an identity of an individual (whether it be surrounding their being, health, finances, or person). From the CEO down to every single employee in the company, organizations must make sure that they prioritize data protection, privacy and security by design (and by default) – leading with privacy awareness when building their security practices. This ensures a sustainable future, and one that respects rights of individuals as well as protects the greater good. In practice, this means designing privacy into all workflows across the organization by default, directly into daily systems and teams so that protecting information becomes a shared responsibility rather than an afterthought. Organizations should treat employees’ personal data with the same care as their own, ensuring it is never used or collected without explicit permission. However, there is no such thing as privacy without a strong data and AI governance foundation. Security teams must become privacy-aware and proactive, by using AI defensively to predict breaches before they occur rather than just reacting to them.

++

Avi Hein, Senior Product Marketing Manager, Checkmarx

Software development has always involved tradeoffs. But AI has created a new one: speed for privacy.

Here’s what keeps me up at night: Developers feed code into AI tools, AI feeds code back into applications, and somewhere in between, sensitive data can slip through cracks no one’s watching. Both directions create privacy risks.

When developers use AI assistants, they’re often pasting proprietary code, internal APIs, and even credentials into prompts. That data goes somewhere. When AI generates code based on its training data, who knows what sensitive information from other companies might end up in your application? 

A recent Checkmarx survey found that one in three developers admits over 60% of their code is AI-generated. So are the developers in your company, whether you like it or not.

What do we do about this?

First, secrets detection needs to catch things earlier. API keys, credentials, server locations can’t be allowed to reach repos. If they do, they leak everywhere. Finding them before code gets committed is basic data hygiene, but it matters more than ever when AI tools are in the mix.

Second, we need to know what AI components are in our applications. LLM models, AI agents, third-party AI services all need to be inventoried just like any other dependency. If you don’t know what AI is running in your apps, you can’t assess the data privacy risks.

This isn’t just about new tools. It’s about having a mature approach – measured by maturity models built for application security – that keeps up with how development works now. Compliance can’t be a checkbox, rather it must be a checkup that verifies applications truly protect data, not just pass an audit. 

++

Gary Orenstein, Chief Customer Officer, Bitwarden

What do you need in 2026 to keep your personal information private? First, users need to stay aware of when, where and how their personal information is being used.

When signing up for new accounts, consider using unique credentials, including potentially a unique username, and of course a strong and unique password. Password managers such as Bitwarden make this easy and provide ways to manage this information seamlessly.

Integrating additional tools like privacy-centric browsers, email alias providers, and VPNs can further enhance users’ privacy, creating a comprehensive defense against the misuse of sensitive information and breaches. 

The 6th annual Bitwarden Data Privacy Week Survey highlights the top privacy-centric apps recommended by the company’s global community. Respondents indicate a strong preference for tools such as Brave, Firefox, Signal, SimpleLogin, and DuckDuckGo for daily browsing, messaging, email aliases, and search engine use to strengthen data privacy and protect personally identifiable information (PII).

++

Bill Bruno, CEO, Celebrus

World Privacy Day is a reminder that most privacy failures don’t come from bad intent, but from lost visibility. Many organizations no longer have a clear understanding of what data is being collected, where it flows, or which systems actually need it. A practical first step is creating an audit trail of every tag, script, and SDK running across digital channels, documenting exactly what data is captured and where it’s sent. Equally important is enforcing a formal review and approval process for any digital change that involves data collection. Without governance at the point of change, even strong privacy programs slowly erode as new tools and integrations are added.

The next step is harder but essential: stop defaulting to full data sharing with third parties. In most cases, only a small portion of the data being transmitted is required for the intended use case, yet organizations continue to send entire payloads out of convenience. This expands privacy risk, increases breach impact, and complicates compliance. More mature programs now focus on data minimization at the source – questioning every field, event, and outbound flow – and sharing only what’s truly required. Privacy resilience is built through engineering discipline, not just policy.

++ 

Andrius Ulenskas, Technical Director at Hyve Managed Hosting

Data Privacy Day is a timely reminder that privacy is more than just a necessary compliance check; it’s a foundation of trust in today’s digital age. As cyber threats intensify and regulatory pressures increase, businesses must look beyond surface-level protections and take a more deliberate approach to how and where their data is stored.

Data sovereignty is now a central part of any effective privacy strategy. Understanding which laws apply to your data and controlling its geographic footprint are essential in a world of accelerating AI adoption, cloud expansion, and an increasingly complex regulatory landscape. It’s more critical than ever that data is both secure and stored within trusted legal frameworks.

This shift requires more than just technical controls and safeguards alone. It calls for clear governance, transparent vendor relationships, and a proactive approach to adapting infrastructure to meet the growing demands of privacy, resilience, and compliance.

++ 

Jimmy Astle, Director, Machine Learning at Red Canary

Agentic AI is moving out of the lab and into real-world corporate systems – used for scanning documents, augmenting workflows, and taking actions once reserved for humans. That shift has significant ramifications for data privacy, especially if AI tools are deployed without clear governance, strong access controls, and careful oversight.

The risk stems from the increasing volumes of information that organiations need to grant their agents access to for them to act autonomously. That data is often sensitive or personal, relating to employees and customers – who expect the business to keep it secure. This is why guardrails around data access must come first in any AI initiative.

Data privacy in the agentic era starts with treating AI like any other user that accesses corporate systems – it must be secured at the identity layer. Organizations should keep their access privileges tight, maintain clear visibility into which data AI agents can retrieve and act on, and control which users are able to prompt them. From there, employees need clear usage policies and security teams should regularly review how their AI systems behave in practice. Privacy checks should also be built directly into user workflows from day one to ensure consistent and widespread compliance. With robust data privacy controls, AI will remain a force for efficiency and insight, rather than a source of unintentional exposure.

++

Matthew Stern, Chief Security Officer at Hypori

Individuals deserve control over their personal data, and organizations have a responsibility to respect that privacy while safeguarding their own information. Our mobile lives generate an enormous amount of data, often collected long before we realize it. Every app we open on every device we carry creates a continuous stream of information about who we are, how we behave, and how we work. Real privacy begins when we acknowledge that we cannot fully secure our devices and instead invest in systems that ensure sensitive data never touches the endpoint. 

For enterprises, that starts with recognizing that personal devices have become the primary gateway to corporate systems. When employees use their phones for work, corporate data ends up on an exposed attack surface that basic mobile defenses cannot defend. Once a device is compromised, anything stored on it is within reach. More device management, more authentication, and more monitoring don’t create zero trust. If corporate data lives on the device, the enterprise is already exposed. 

The most reliable way to take control of your data is by removing corporate apps and information from the physical device entirely. When enterprise data never resides on the phone, a compromised device can’t escalate into an organization-wide incident. Data Privacy Week is a strong reminder for companies to adopt this approach so they can protect corporate information while allowing employees to maintain privacy over their personal lives.

++

Jack Bicer, Director of Vulnerability Research, Action1

In today’s digital world, protecting your privacy doesn’t require being a tech expert, it starts with small, everyday habits. One of the simplest steps is sharing less information than you think you need to. If a form field is optional, leave it blank; the less data you give out, the less there is to be leaked, sold, or misused later. Your email address is especially important, as it’s often used to link data about you across multiple sites. Using temporary email addresses for one-time sign-ups, or email aliases for regular accounts can reduce how easily your activity is tracked and limit the fall-out from data breaches. 

And while strong passwords still matter, they’re no longer enough on their own – enabling multi-factor authentication adds a critical layer of protection if credentials are ever compromised. Data privacy is really about control, and my adopting a few practical habits like these, people can significantly reduce their risk and take back ownership of their digital identity.

++

Marinela Profi, Global AI & Generative AI Market Strategy Lead, SAS

As industries from financial services to retail and banking race to deploy AI-powered chatbots and enterprise copilots, challenges of privacy, transparency and trust are emerging just as quickly. These systems can inadvertently leak sensitive data, infer information that was never explicitly shared, or blur the line between acceptable use of private and public data. 

While organizations have historically relied on tools like synthetic data to address traditional privacy concerns, AI introduces a new challenge: how models retain, infer and expose information during everyday interactions, including emotional and contextual cues. As AI increasingly drives decision-making and content creation, users want to understand how models are trained, how outputs are generated and who ultimately owns the data – and even the “memories” created along the way. 

This moment signals an urgent need for a more modern, rights-based privacy architecture – one that enables transparency, governance and human oversight into AI workflows to prevent unintended data exposure, inference risks and erosion of user trust.

++

Joe Kaufmann, Global Head of Privacy & DPO at Jumio

As with every Data Privacy Day before it, we have seen a material increase to the amount of our lives spent online. The influx and entrenchment of AI has forcibly evolved the field of data protection and introduced more complex implications. Yet, the basic human right to privacy remains at the core. As lawmakers continue to address online security concerns with identity and age verification measures, we must acknowledge the symbiotic relationship between privacy and safety. The balanced harmony between the two interests is best described as user trust, and it should remain a priority for every organization.    

New laws are placing organizations into unfamiliar positions of being responsible for processing sensitive personal data. Mishandling of this information risks undermining user trust and indirectly fueling the very fraud that organizations are trying to prevent. Jumio research reveals that 93% of consumers trust themselves more than companies or governments to protect their data from AI-powered fraud. Aligning enterprise practices to data minimization and strict enforcement of limited retention periods is a foundational necessity for improving this noted lack of user trust.  

As the pressure for security and automation builds, we should not abandon our consideration of the individual’s rights. We can take this Data Privacy Day as a time to recalibrate our navigation toward an approach that reinforces user trust holistically with security, privacy and transparency for all.

++

Shiva Pillay, SVP and GM Americas, Veeam Software

Data Privacy Day 2026 is a powerful reminder that taking control of your data is more than a security imperative, it’s a business accelerator. When organizations build trust in their data and embrace safe AI, they unlock new levels of agility, customer confidence, and competitive edge. Trusted data fuels smarter decisions, resilient operations, and innovation that drives real business outcomes. The companies who get this right won’t just keep pace – they’ll lead the way.

++

Ken Braatz, CTO of SupportNinja

The safest data is the data you never store. AI doesn’t need Social Security numbers or credit card details to be effective – in fact, holding onto that kind of personal data just makes you a target. The real opportunity is using clean, connected, non-sensitive data to deliver better customer experiences without putting people at risk.

++

Adenike Cosgrove, CMO at Mimecast

The definition of data privacy is fundamentally shifting – and meeting regulatory requirements isn’t enough anymore. From AI-driven threats to the explosion of collaboration tools, there are more places where sensitive data can be accessed, shared, or exposed than ever before.

But here’s the often-overlooked reality: privacy compliance is fundamentally a search and governance problem. Organizations can’t protect, minimize, or produce what they can’t find. With data subject access requests surging, often driven by workplace disputes, and regulators scrutinizing response times, companies need universal visibility across their data ecosystem.

At the same time, data minimization is becoming non-negotiable. Many organizations are still struggling to manage their pre-AI data footprint, let alone stay compliant with GDPR and emerging frameworks. Setting up defensible retention policies isn’t just about compliance – it’s about reducing risk and exposure.

Data Privacy Day is a reminder to shift from reactive compliance to proactive governance. That means reassessing retention policies, ensuring you can respond to access and erasure requests efficiently, and treating privacy not as a burden, but as good business.

++

Jack Berkowitz, Chief Data Officer, Securiti AI

Data Privacy Day serves as a reminder that privacy is not a one-time task and that it carries new weight in today’s AI era. 

In 2026, the main data security pressure point is GenAI and AI agents that pull data from a number of sources: SaaS tools, cloud systems, on-premises environments, and shared workflows. The biggest risk is not just feeding AI bad data. It’s not knowing what sensitive data is used to train AI, who is allowed to see it, and where that data is sent or queried. When teams can’t trace data lineage or enforce permissions, they don’t just increase breach exposure, they also increase the odds of AI making decisions on stale, sensitive, and inaccurate data.

The fix starts with visibility because you can’t govern what you can’t trace. Organizations need to inventory and classify sensitive data (including shadow data), continuously map how it moves through AI pipelines, and enforce context-aware access controls at the point of use before data flows into AI models. 

++

Frederic Rivain, CTO, Dashlane

Data Privacy Day is a reminder that strong privacy foundations are no longer reserved for niche security products. Zero-knowledge architecture, long seen as complex or impractical at scale, is now accessible to many organizations thanks to advances like confidential computing. This shift makes privacy by design achievable across a much wider range of applications, reducing systemic exposure and reinforcing user trust.

At its core, zero-knowledge ensures that only end users can access their sensitive data, even in the event of a system compromise. This approach limits blast radius by design, lowers liability for businesses, and aligns security incentives with customer expectations. Privacy stops being a promise and becomes by design.

This foundation will matter even more as AI agents progressively enter the workplace. These systems increasingly access internal tools, process sensitive data, and act autonomously across multiple services. As AI agents become embedded in business workflows, data privacy will be tested at an entirely new scale. Organizations that invest today in zero-knowledge and privacy-first architectures will be far better positioned to adopt AI safely tomorrow. 

++

Andrew Becherer, CISO at Sublime Security

Data Privacy Day is an important reminder that attackers are constantly evolving their tactics and techniques, and can now leverage AI to bypass much of the effort attacks used to require. 

We’ve seen this in our own research, as attackers can now pull from LinkedIn profiles and company pages, use AI to process its data instantly, and create believable personas, backstories, and email threads for phishing attacks. Attackers can also analyze social media accounts to determine the typical grammar and spelling of a colleague or executive they’d like to impersonate and create legitimate-looking phishing emails that mimics their personal capitalization and punctuation habits.

Security teams must be mindful of this reality when securing their data. Phishing and email based security attacks are still the most effective way for a threat actor to gain entry into an organization. It is imperative to safeguard your most valuable information as attackers become increasingly sophisticated.

++

Przemyslaw Grandos, Head of IT & Compliance, Catalogic Software 

After two decades in banking across InfoSec and AML, I’ve learned a simple rule: if you can’t evidence it, you don’t really have it. Privacy programs fail when they’re built on policies instead of controls and when -who has access to what data- lives in tribal knowledge. 

In 2026, the winning approach is simple: strong identity controls, least privilege, encryption by default, and audit trails that actually stand up to scrutiny. But there’s a piece many teams miss: resilience is part of privacy. 

When ransomware hits, the pressure to “just restore something fast” leads to shortcuts, unsafe reintroductions of malware, and bad decisions about paying. Treat backup and recovery as privacy controls: immutable copies, separation of duties, tight admin access, and routine restore tests. Regulators care about outcomes. Customers care about trust. Both care whether you can contain damage and recover cleanly. 

++

Gal Naor, CEO, StorONE

Data Privacy Day is a reminder that privacy is not a feature added after the fact. It is a foundational design decision that must be embedded into the core of every data platform.

For years, organizations focused primarily on preventing breaches. Today, that approach is no longer sufficient. Data now spans on-prem environments, cloud and hybrid deployments, backups, archives, and AI pipelines. In many cases, privacy risk does not stem from external attackers, but from loss of control and unclear security policies across these environments.

A privacy-by-design approach starts at the architectural level, where data protection and data security are integrated rather than treated as separate layers. Organizations need the ability to enforce encryption policies that align with operational requirements, whether encrypting data at the software layer, at the drive level using self-encrypting drives, or both. Just as importantly, encryption must be flexible enough to apply globally or selectively, ensuring strong protection without limiting how data is used.

When organizations know exactly where their data resides, how it is protected, and who can access it, privacy becomes enforceable rather than aspirational. Combined with intelligent data placement strategies and reduced data duplication, this approach limits exposure and reduces the blast radius when incidents occur.

On Data Privacy Day, the message is clear. True data privacy is achieved through architecture, control, and resilience, not promises. 

++

Chris Hauk, Consumer Privacy Champion at Pixel Privacy

As we reach another Data Privacy Day, it seems that every day we hear about a new data breach or a group of hackers threatening to expose data harvested in a previous data breach. This reminds us that organizations need to do a better job of securing their systems, while also educating their employees about how to protect themselves, their employers, and their customers from having their information exposed in a data breach. All the security measures in the world won’t protect against employees or executives being fooled into turning over sensitive information, such as access to systems or accounts.

Also, it seems as if users these days want to be free to share as much information as they’d like via social networks and other types of online activity. At the same time, they want those same networks to protect their personal information, even though they are responsible for sharing sensitive information online. Those same users want new government regulations to protect their online activities. This is the wrong approach. 

While social networks should help protect their users, those same users need to take responsibility for protecting their information while online. Users expect the government to protect them online by putting rules and regulations in place. Users need to keep in mind that the government is not their friend. By putting new regulations in place, governments do not provide additional protection, but instead merely restrict their citizens’ access to online content. Case in point, the UK’s proposed 16-and-under restrictions on Social networks. While on the face this sounds like a valid bit of law, it will instead drive children to the darker corners of the web, exposing them to dangers that they otherwise would never be exposed to.

While some may complain that it’s just too difficult to protect their accounts with secure and unique passwords, that excuse doesn’t hold up today. There are several password managers available for free or a low price, and many operating systems, like iOS and macOS, that have password managers built-in.

++

Martin Jartelius, AI Product Director at Outpost24

Data privacy and the risks to it have increased substantially over the past year or two. Organizations’ readiness to detect, respond to, or recover from ransomware attacks that rely solely on encryption has improved. As a result, attackers have adapted through two shifts. First, they have moved toward smaller, less prepared targets with a higher propensity to pay to protect their businesses. Second, they have shifted away from encryption-based ransom and toward extortion through data leakage. This evolution also means attackers no longer need deep access to internal networks. An exposed business intelligence system, CRM, or other database, potentially even one hosted by a SaaS provider, is sufficient. In many cases, a single leaked credential is all that is required. 

++

Dr. Sean Kelly, Chief Medical Officer and SVP of Customer Strategy, Imprivata

Few industries demand higher standards for data privacy than healthcare, where protecting sensitive patient health information is fundamental to building patient trust and ensuring continuous care delivery. As one of the most targeted industries for cyberattacks, the stakes are even higher, yet hospitals’ security practices lag behind. Outdated access management strategies like passwords are no longer enough to protect patient privacy and secure healthcare data. Our research shows that 60% of health systems still rely heavily on passwords for user authentication, with more than 40% linking them directly to increased risk of breach.  

Without modern access controls that reliably verify user identity and limit access to the right people at the right time, patient privacy remains at risk. The challenge is strengthening protections without disrupting clinical workflows, since friction often leads to workarounds that can undermine security. Equally important is the ability to detect and respond to identity-based threats in real time, before compromised access escalates into a broader breach of sensitive healthcare data.  This Data Privacy Week should serve as a wake-up call for healthcare organizations: password-heavy workflows are not only increasing risk but also fueling frustration and burnout. Shifting to identity-centric access models helps strike the right balance, reducing friction without introducing new vulnerabilities. By moving toward a passwordless future, healthcare leaders can lower risk, simplify workflows, and lay a stronger foundation for what comes next. 

++

Patrick Harding, Chief Product Architect, Ping Identity 

This week offers an opportunity to pause and assess the rapidly evolving landscape of digital trust, as privacy really boils down to choice and trust around how personal data is being used. Data privacy is no longer a passing concern for consumers – it has become a defining factor in how they judge brands, with three-quarters now more worried about the safety of their personal data than they were five years ago, and a mere 14% trusting major organizations to handle identity data responsibly.  

Whether it’s social engineering, state sponsored impersonation or account takeover risks, AI will continue to test what we know to be true. As threats advance and AI agents increasingly act on behalf of humans, only the continuously verified should be trusted as authentic. 

For businesses, the path forward is clear: trust must be earned through transparency, verification, and restraint in how personal data is collected and used. The businesses that adopt a “verify everything” approach that puts privacy at the center and builds confidence across every identity, every interaction, and every decision, will have the competitive edge. 

++

Kev Breen, Senior Director of Threat Research, Immersive

Data privacy remains one of the most significant business risks organizations face, as attackers increasingly focus on stealing large volumes of sensitive data with minimal effort. Once exposed, that data is routinely reused for phishing and social engineering, creating lasting consequences for customers and organizations alike. 

These incidents show that technology alone is not enough. Social engineering continues to grow more sophisticated, making people a primary attack vector even in environments with strong technical controls. In 2025, rapid adoption of generative AI further expanded risk, as organizations rushed to deploy tools that give employees and systems direct access to internal data. Architectures such as RAG-enabled chat interfaces were often implemented without sufficient safeguards, leading to accidental exposure through prompt injection and misuse. 

At the same time, long-standing weaknesses in data access controls continue to surface in other parts of the attack surface. A recent example was the suggestion that Instagram had suffered a major data breach. In reality, reports pointed to abuse of legitimate API access, where large volumes of improperly constrained data were scraped and later sold. While technically different from a breach, the outcome was the same: sensitive information at scale ended up in criminal hands. 

As Data Privacy Week 2026 reminds us, protecting data isn’t just about keeping bad actors out. It’s about battle-testing teams so they can recognize exposure risks early, respond effectively under pressure, limit damage, and recover quickly when a cyber crisis inevitably occurs. 

++

Greg Wetmore, Vice President of Product Development at Entrust

Data security has evolved from isolated checkpoints, like passwords or MFA, into an interconnected, agile identity ecosystem. Having more digital presence does not automatically mean more risk; smart digital identity design can actually make you safer. 

Real identity resilience comes from synergy across layers of biometric, behavior, historical, and device data. Instead of relying on a single moment of verification, modern security systems build trust over time, creating a baseline for future activity and adapting as the context changes and as threats evolve. The future of digital trust depends on a multi-layered approach to protecting identities that replaces rigid perimeter-based checkpoints with adaptive, intelligence-driven systems that put the control back in the hands of everyday individuals. 

++ 

Doug Kersten, CISO, Appfire  

As AI becomes more embedded in everyday tools and business operations, data privacy risks are driven less by the technology itself and more by a lack of clarity and accountability. The biggest challenges come from weak visibility into where data lives, disconnected systems, and poor communication about who owns and protects sensitive information. 

Data Privacy Week is a timely reminder that taking control of your data starts with understanding your digital environment and making intentional choices about access, tools, and information sharing or in other words, security and privacy-by-design. Security and privacy can no longer be treated as a purely technical problem – it must be embedded into daily operations and everyday behavior. 

By bringing discipline to the basics and fostering a culture of awareness and responsibility, organizations can reinforce trust, protect sensitive data, and ensure the people that data represents remain secure. 

++ 

Fernando Martinez Sidera, Lead Threat Researcher, LevelBlue

AI is reshaping how we work, create, and make decisions, but most organizations have no visibility into how, where, or why it’s being used, leading to a surge in shadow AI. Blind trust in AI outputs, poor cybersecurity training, and a lack of clear governance are allowing sensitive data, intellectual property, and even decision-making processes to slip beyond organizational control. This unmanaged AI adoption introduces a range of risks, spanning data leakage, data theft, legal and regulatory liabilities, and more. Ignoring Shadow AI won’t make it go away. Organizations must confront it head on by enhancing visibility, control, and accountability of their AI usage. 

++ 

Martin Raison, Co-founder & CTO, Nabla 

Data Privacy Week is an important reminder for leaders that as AI becomes more embedded in enterprise workflows and decision-making, governance plays just as pivotal a role as accelerating technical capabilities. In healthcare, AI is a huge asset – it can analyze patient data, including medical history, scans, and lab results, to identify the root causes of health conditions. However, in a field where data privacy is so top of mind, these capabilities require strong guardrails and human oversight to be deployed safely. Often, we see companies rush to accelerate AI capabilities and deploy agents without extending data access policies or understanding how they act on behalf of users. This amplifies risk and erodes trust. The most successful AI strategies will treat privacy and security as foundational principles rather than afterthoughts. 

++ 

Melissa Bischoping, Head of Security Research, Tanium 

As AI agents and workflows become an undeniable part of the modern enterprise, data privacy expands into a complex ecosystem that many organizations are scrambling to understand and govern. The spirit of innovation that fuels technologists drives them to want to build, adopt, and integrate agentic AI, but fear of the unknown can bring pause. While AI has given us unprecedented ability to execute sophisticated workflows at speed and scale, we also understand that – if ungoverned and unchecked – it can introduce unprecedented risk and loss of data at that same scale.   

To lead responsibly as an AI-forward technologist, build on a strong foundation of data governance and visibility first. Understanding the scope and permissions of agents, the data resident on systems interacting with other AI tools and infrastructure and having safeguards where there is always a human-in-the-loop to validate actions will reduce the risk of unexpected data loss through misconfiguration. Data privacy in the era of AI requires a clear, accurate, real-time answer to the questions, “What AI agents exist in my environment? What data/systems can they access? Under what permissions can they access systems? And do I have governance and controls to ensure autonomous workflows and agentic actions can be traced and audited with confidence?”

Agentic AI is transformational for every organization, but its transformation must be responsibly built on foundations of visibility, governance, and human oversight to protect privacy and resilience. 

++ 

Bobby Ford, Chief Strategy & Experience Officer, Doppel

As technology advances, so do the attackers using it. We’re seeing identity-based threats evolve faster than ever, with adversaries learning to exploit the trust people place in AI platforms. These platforms provide a rich source of intelligence for those looking to impersonate, manipulate, or deceive. The challenge isn’t that people are unaware, it’s that the positive impact of their use seems to outweigh the negative consequences of their misuse. Our responsibility now is to close that gap; to build awareness, resilience, and safeguards that evolve as fast as the threats themselves. 

++ 

Corey Nachreiner, Chief Security Officer at WatchGuard 

Data privacy risk today isn’t primarily caused by attackers breaking through a firewall, it’s driven by identity compromise and the misuse of trusted access. We’re seeing threat actors rely more heavily on social engineering and AI-enabled deception to steal credentials, impersonate legitimate users, and quietly exfiltrate data. In many cases, these attacks start with something as simple as a deceptive link or download, underscoring the importance of user awareness alongside technical controls.   

This shift is why protecting data now requires a simpler, more unified approach that combines identity, endpoint, and identity protections. When those layers operate in silos, gaps emerge that attackers are quick to exploit. Simple measures like verifying download sources, using multi-factor authentication, and maintaining strong credential hygiene can stop attackers even when credentials are targeted. With these practices, organizations can interrupt attacks much earlier, before credential theft turns into a data breach, regulatory exposure, or long-term reputational damage.

++ 

David Lee, Field CTO, Saviynt

AI doesn’t create new security problems; it exposes the ones we already ignored. Most organizations don’t lose data because encryption failed-they lose it because access wasn’t properly governed. Identity is the control plane for data access, whether that access comes from a person, an application, or an AI agent. If you can’t answer who has access, why they have it, and whether they still need it, you don’t have a data protection strategy; you have hope.

++ 

Ravi Soin, CIO/CISO at Smartsheet

As we mark Data Privacy Week 2026, we must recognize that privacy isn’t something we can check off our list once a year. It’s a fundamental right that requires our constant attention and action. We need to go beyond awareness campaigns and make privacy a core part of everything we do-how we design products and systems, how we manage security and risk, how we choose and oversee vendors, and how we lead our teams and shape our culture. 

We must hold vendors accountable for how they secure our data, especially as AI adoption accelerates. Vendors should be transparent about how customer data is accessed, protected, and retained, because customer data belongs to customers. Period. Organizations should have clear control over if and how their data is used to train or improve AI, and vendors should clearly disclose those practices. Prioritizing data privacy pays dividends: it helps reduce exposure to security threats and data leakage as AI scales, and it reinforces confidence in the organization, strengthening customer trust.

++ 

Mark Wojtasiak, SVP of Product Research and Strategy, Vectra AI

Taking control of data in the AI enterprise isn’t about writing better policies-it’s about building resilience into how systems behave. As data moves continuously across identities, clouds, SaaS, and automated workloads, privacy failures don’t start with a single breach. They happen when organizations can’t see or respond fast enough as behavior changes. 

Privacy by design only works when teams can detect abnormal access early, contain misuse quickly, and limit blast radius when controls inevitably fail. That requires continuous visibility into identity and network behavior-not assumptions based on static rules or one-time reviews. 

In resilient organizations, privacy isn’t something you hope holds-it’s something you can measure and prove under pressure. The ability to detect, contain, and recover from misuse is what ultimately determines whether personal data stays protected in an AI-driven world.

++

Ifrah Arif, Product Manager at PureVPN

“Notification storms” typically arise when someone’s using incompatible, non-integrated password managers, VPNs, dark web monitors, trackers, ad blockers and other security tools from differing vendors. The storm arises when tools roll out uncoordinated alerts and notifications to get the user’s attention. One tool mistakes another tool’s attempt to do its job as a threat, and sends users alerts. The “alert fatigue” it creates can prompt the user to close their VPN or password manager, exposing them to data theft and fraud.

The recent study The Cost of Fragmentation: Measuring Time, Spend and Risk in Personal Cybersecurity Tool Stacks, found that 44% of users receive overlapping alerts, and 38% of those receiving overlapping alerts say they ignore them.

That’s why it’s important to use an integrated suite of security tools – a single unified platform. That way, instead of juggling multiple apps competing for your attention and overriding one another, you get a single, intelligent alert stream and a single place to act on it.

++

Greg Clark, Director, Product Management and Strategy OT Enterprise Cybersecurity at OpenText

Industry research continues to show that data privacy teams and budgets are shrinking while AI is being used more than ever to access and act on sensitive data. As organizations mark this year’s Data Privacy Day, the gaps between data use and risk readiness are becoming harder to ignore.

For privacy and security teams, the challenge in 2026 is to do more with less – by rethinking data management through a risk-first lens. Teams are consolidating tools and clarifying ownership, focusing on what matters most. With better visibility into where sensitive data lives, how it is used and who or what can access it – including AI and non-human actors, organizations can reduce complexity and maintain control as data volumes grow and budgets remain constrained.

At the organizational level, adopting a privacy-first approach to data management is no longer optional. Building privacy into data practices from the start helps reduce the risk of breaches, regulatory exposure and operational disruption. Just as importantly, it enables secure collaboration and analytics-allowing teams to share, analyze, and extract value from data with confidence, rather than locking it down or slowing the business.

Employees play another critical role in effective data management. This year’s Data Privacy Day theme, Taking Control of Your Data, is a reminder that everyday actions matter. Staying alert to evolving phishing tactics, understanding insider risk and reinforcing the fundamentals of data hygiene are increasingly important as AI continues to become a greater part of everyday work.

Taking control of your data doesn’t mean slowing innovation. With strong data governance and privacy practices in place, organizations can safely collaborate, adopt AI-driven analytics, and scale data use, even with leaner privacy teams, while maintaining trust with customers, regulators and partners.

++

Kristel Kruustuk, Founder, Testlio

Adopt a “double verification” mindset for everything AI tells you

We’ve entered an era where verifying AI-generated outputs is table stakes now. I’ve reached a point where I fact-check nearly everything AI tells me: the sources, the quotes, the statistics. When I ask any AI chatbot like ChatGPT or Perplexity to give me sources, I’m checking if those sources are actually real. When I ask for quotes, I’m Googling to confirm they exist. Sometimes they don’t.

This matters for personal safety because AI models are also known to be a people-pleaser. That means if you feed them incorrect assumptions or leading questions, they’ll reinforce misinformation rather than correct it. Double verification protects you from acting on fabricated information, whether that’s a fake statistic you’re about to share at work or a “source” that doesn’t exist.

Rule: if it affects money, reputation, health, or security, verify with a second, primary source. 

++

Marc Rubbinaccio, VP of Information Security, Secureframe

On Identity as the New Attack Surface:

Attackers have figured out that compromising identity is easier than directly hacking the software itself. Stolen credentials, hijacked sessions, and abused API tokens are becoming a reliable way to gain access to systems and exfiltrate data. For companies built on cloud infrastructure and third-party integrations, a single compromised service account or API key can give attackers direct access to sensitive data as if they were to compromise a user account.

The mindset organizations need to have in 2026 is treating every login, token, and OAuth grant as a potential attack vector. Short-lived credentials, least-privilege access, and continuous monitoring are required controls when protecting customer data when managing a modern application.

++

Ionut Mihai Chelalau, FIRST Transportation & Mobility SIG Chair and Cybersecurity Consultant at Diconium

On the Privacy Trade-Off

Privacy, as most people understand it, cannot truly exist in today’s connected ecosystem. Every time you use an AI assistant, some of your data will ‘leak’ into training datasets, and despite claims of anonymization, device fingerprints and usage patterns leave identifiable traces. The uncomfortable truth is that customers worldwide are willingly trading privacy for convenience, and unless strong regulations force the issue, manufacturers won’t voluntarily cut into profit margins to protect data they can monetize.

++

Yoram Novick, CEO, Zadara

The importance of data privacy and security can’t be overemphasized in today’s hyper-digital and increasingly fragmented world. With the vast increase in AI workloads, the question is no longer whether organizations should focus more on data privacy, but where and under whose control that data resides. Data sovereignty, digital sovereignty, and the rise of sovereign cloud and sovereign AI cloud platforms are becoming central to national resilience, enterprise risk management, and regulatory compliance.

As AI adoption accelerates, particularly for sensitive workloads such as healthcare, finance, defense, and government services, traditional public cloud models reveal growing limitations. Sovereign AI and sovereign AI cloud architectures address these gaps by ensuring that data, models, and operations remain under local jurisdiction, aligned with national regulations, and insulated from foreign access or extraterritorial control. This approach is becoming essential for organizations seeking to deploy AI responsibly while maintaining trust, compliance, and operational continuity.

Zero-trust architectures and intelligent security controls remain foundational to modern data protection. Identity-aware systems, multi-factor authentication, and continuous verification significantly reduce attack surfaces and help defend against threats such as credential theft and lateral movement. When combined with sovereign cloud and AI-ready infrastructure, these measures provide stronger protection than legacy perimeter-based approaches.

AI itself introduces both powerful opportunities and new risks in the context of data privacy and security. While AI-driven tools can enhance threat detection and operational efficiency, poorly governed AI systems can amplify vulnerabilities and compliance risks. Human oversight, transparent governance, and adherence to proven security principles remain essential. Importantly, deploying AI within sovereign AI cloud environments can materially reduce exposure to public cloud security incidents and regulatory uncertainty.

Data Privacy Day is a timely reminder that in an era defined by AI acceleration and geopolitical uncertainty, organizations must proactively embrace sovereign cloud and sovereign AI strategies to protect sensitive data, maintain digital autonomy, and build long-term trust in an increasingly interconnected world.

++

Jadee Hanson, CISO at Vanta

Businesses are rushing to adopt agentic AI, exposing a large gap between deployment and control. While AI agents can increase efficiency by acting and making decisions, without proper oversight shadow agents pose a serious threat to data privacy.

According to Vanta’s recent State of Trust report, 65% believe that their current use of agentic AI outpaces their understanding of it. The lack of understanding means sensitive data can be leaked. It’s critical for businesses to demonstrate transparent practices, enforce clear rules, and deliver auditable outcomes.

++

Thomas Fikentscher, Area Vice President ANZ, CyberArk

As AI systems move from analysis to autonomous decision-making, Data Privacy Day is no longer just about how data is collected or stored — it’s about accountability. Organizations are deploying AI into high-impact environments faster than governance frameworks can keep up, raising hard questions around liability, data quality and oversight when AI-driven systems produce unintended consequences. While the scale of what AI can enable is compelling, there is a growing responsibility gap as AI decisions increasingly affect people, outcomes and trust.

For organizations, the priority must be securing AI at the point where privacy risk is highest: the AI agent itself. These agents operate with speed, scale and access that often exceed human users, making them a new class of highly privileged identity. Treating AI agents as trusted software rather than privileged identities is a very risky endeavor. In a hybrid world of human and machine collaboration, agentic AI security becomes a core privacy control — requiring least-privilege access, continuous monitoring and clear human accountability. With regulation still evolving, organizations must take the lead to protect privacy in the AI era.

++

Cabul Mehta, Industry Principal, Healthcare & Life Sciences at Presidio

Without tech modernization and strong AI governance, healthcare organizations are on a dangerous path and risk widening an already growing trust and security gap. Data privacy is a top concern for patients when asked about their healthcare providers adopting AI tools. According to a recent survey Presidio conducted of 1,000 U.S. consumers, only 32% said they are very confident that their provider protects their personal info from cyber threats, and nearly 1 in 4 are uncomfortable with AI in any role. This problem is becoming impossible to ignore as clinician burnout pushes some frontline workers toward unsanctioned shadow AI workarounds – right when patients are already questioning whether their data is safe.

++

Chris Mierzwa, Sr. Director – Global Resilience Programs, at Commvault

As organizations continue to grapple with their AI use, shadow AI is the top data privacy challenge that they are facing. With new and exciting generative AI offerings coming to market every single day, employees are unintentionally skirting around corporate policies to try these new tools and potentially sharing sensitive information. As a result, this is unfortunately creating a massive data blind spot for CISOs.

In order to combat these data privacy issues, security leaders should compile a list of sanctioned AI tools that employees can use and explore. As a part of this, CISOs can also establish private AI workspaces that don’t get used externally to train larger models but allow employees to experiment with guardrails.

In addition, executive hesitancy to begin allocating Enterprise-Safe licenses of major LLMs will continue to accelerate this problem. Allocating budget for this new frontier is a must to encourage innovation through AI while implicitly maintaining security and governance.

++

Philip Dutton, CEO and cofounder at Solidatus

The real privacy challenge is not just where data is stored, but what data you hold, where it came from and where it goes. Without data lineage, organisations cannot reliably honour access requests, guarantee the right to erasure, or prove that personal data has only been used for its agreed purpose. You cannot take control of your data if you cannot see it.

Data Privacy Week is about giving people confidence in how their data is handled. For organisations, taking control means being able to explain, protect and, when needed, remove personal data across the business.

++

Carlo Finotti, SVP Service Delivery at DataStrike

As AI accelerates attack sophistication, the weakest link is no longer infrastructure, its trust. AI generated impersonation, deepfake voice attacks, and contextual phishing are making it harder for employees to distinguish real interactions from malicious ones. Organizations that fail to invest in training and behavioral security will see data breaches that start with people, not just systems.

Strong data protection in the age of AI requires multiple layers of defense combined with clear AI governance. That means controlling what data AI systems can access, how outputs are monitored, and where information is allowed to flow. Without guardrails, AI becomes an unintentional data exfiltration tool rather than a productivity engine.

As tools like ChatGPT, Copilot, Gemini, Claude, and Llama become part of everyday workforce, organizations need clean, practical controls around how AI is used. That starts with limiting what data these systems can access and being clear about where outputs can go. Without basic guardrails (controls, tools, and policies), AI can easily expose sensitive information. With the right controls in place, it becomes a secure tool for productivity rather than a risk to companies core data assets.

The real challenge with AI and data privacy is not speed. It is clarity. Organizations need a clear understanding of their data and the risks tied to it. AI only amplifies the level of access it is given. Without strong data classification, access controls, and governance, AI accelerates exposure rather than value. Enterprises that manage data intentionally across its full lifecycle can adopt AI with confidence. They can do so while protecting intellectual property, regulated information, and customer trust.

++

TJ Carsten, senior consultant at Optiv

In 2025, we saw multiple high-profile data breaches tied to consumer applications, underscoring that personal data is only as secure as the platforms we trust with it. Data Privacy Day is an important reminder for individuals to reassess how and where they share their information. Here are five golden rules they should prioritize:

1. Assume Anything Shared Could Become Public – Treat all data as potentially exposable. No matter how private a platform claims to be, anything you share today could become public tomorrow.
2. Limit the Personal Data You Share – If an app or service doesn’t truly require certain information, don’t provide it. Data that isn’t collected can’t be breached.
3. Choose Trusted Apps Over Trending Ones – Trending isn’t the same as trusted. Share your data only with organizations that have demonstrated a consistent commitment to protecting user information.
4. Review the Privacy Notice – While often overlooked, this document defines what data is being collected, how it is used, and who it is being shared with. Understanding this is essential to informed consent.
5. Clean Up Your Digital Footprint Regularly – Remove unused apps and delete dormant accounts to reduce unnecessary data exposure and long-term risk.

++

Jack Cherkas, Global CISO at Syntax

Many organizations run into trouble when they treat privacy and security as separate disciplines. In reality, they’re inseparable. You can’t credibly protect personal data without securing it, and you can’t secure it properly without understanding the privacy obligations that come with it. Data Privacy Day is a timely opportunity to reflect on the gap between privacy commitments and the controls operating day to day.

Security fundamentals (e.g., IAM, threat detection, incident response, disciplined data hygiene) remain the foundation of credible privacy protection. And they are even more critical in 2026 as Generative AI accelerates, turning data into the fuel that powers new capabilities as well as new risks. The organizations that will succeed won’t simply “comply”; they’ll treat privacy as an active practice, pairing innovation with responsibility and grounding every AI ambition in strong data stewardship and mature security controls. Strong privacy AND strong security, together, are what will carry organizations through the next wave of technological change.

++

Christopher Zangrilli, VP of Technology Strategy at Vertex Inc.

Data Privacy Day highlights the growing urgency around protecting sensitive information, and for security leaders, it’s also an opportunity to address an often-overlooked foundation: data integrity. In today’s highly interconnected environments, privacy risk doesn’t come only from external threats. It increasingly emerges when inaccurate, inconsistent, or poorly governed data moves at speed across systems, partners, and jurisdictions. In the finance and tax functions specifically, with real-time reporting, e-invoicing, and AI-driven automation becoming standard, companies must embed validation, transparency, and auditable controls directly into data flows to reduce exposure and maintain trust. Getting privacy right doesn’t mean slowing innovation; it means establishing the guardrails that allow organizations to scale securely and confidently.

++

Chris Millington, Global Solutions Lead of Data and Cyber Resilience at Hitachi Vantara

Businesses can’t single in on one solution for cyber resilience:

Cyber resilience maturity is still extremely low. Many businesses are pinning their future hopes on solution-in-a-box products to stay safe and remain operational. What they need are targeted resilience strategies. Attacks vary, so there’s no single way to fix this.

Businesses need a multi-pronged approach that includes reliable and secure data infrastructure, efficient and dependable backup, anomaly detection and malware scanning, and the ability to recover within minutes. We haven’t seen enough of that in the last 12-18 months.

++

Justin Endres, Head of Data Security at Seclore

Every January 28, Data Privacy Day reminds us how quickly the meaning of privacy is changing. What once centered on basic data protection now confronts far more complex risks: autonomous AI systems, synthetic media, and a world where privacy is inseparable from trust in identity and reputation.

Last year, I wrote about the rise of Agentic AI. Since then, deepfakes and synthetic content have exploded, moving from novelty to weapon. In 2025, fabricated audio, images, and video scaled into the millions, fueling fraud and impersonation at unprecedented levels. Privacy risk is no longer just about data exposure, but about identity integrity.

Privacy is not a checkbox. It is the foundation of digital trust in an era where sensitive data must remain protected, governed, and provably controlled wherever it is accessed … by people or by AI.

++

David Redekop, Founder and CEO, ADAMnetworks

It is right and appropriate for privacy dialogue to be driven by a consumer demand. If we don’t demand privacy, we won’t get it.

Privacy may be the most valuable asset we have, yet modern connectivity has normalized giving it away. We’ve been told that we’ll be on the winning end of the exchange, but on many levels, we are falling short. When people say “I have nothing to hide”, they may be saying “I don’t know what to do about it so I’m not even going to think about it”, and that is a dangerous position to take.

One of the most important ways people can take control is to first be aware of the digital breadcrumbs we leave behind in our online activity. Once we are aware, we intuitively start resisting the privacy leaks that happen with something as simple as launching a free app or visiting a typical website.

While tools exist to limit the exfiltration from our devices, the consumer has no control over what companies do when we willingly give them necessary information. This is where public policy has an important protective role to play.

++

Todd Thorsen, CISO at CrashPlan

Data Privacy Day is a reminder that privacy isn’t just a policy—it’s an outcome of disciplined security and resilient data practices. Preventing unauthorized access is foundational and starts with knowing where PII resides in your environment, limiting access, defining ‘need to know”, and taking an assumed breach approach to protecting it. At a minimum, implement strong identity and access controls, employ continuous monitoring, and leverage immutable backups to ensure security, availability and recoverability when things go wrong. In 2026, true data privacy depends on security and resilience practices to protect trust when—not if—systems are compromised.

++

Nick Burling, Chief Product Officer at Nasuni

Data privacy and data resilience are no longer secondary considerations but have become foundational to how modern organizations operate. As unstructured data continues to grow rapidly across the enterprise, with roughly 80 percent of enterprise data being unstructured, it has become an increasingly attractive target for attackers. As a result, data resilience is rising to the top of boardroom and executive agendas— yet, many organizations continue to struggle due to data silos, which complicates data management and increases exposure to new attack vectors. Achieving resilience at scale is extremely difficult without the right foundation and requires that resilience be designed into the core of infrastructure rather than added after the fact.

The rapid adoption of AI further heightens the urgency. While AI can significantly improve productivity and decision-making, it also introduces new risks related to data quality, access, and misuse, including data poisoning, AI-driven ransomware, and deepfake fraud. Secure-by-design principles are essential to data privacy and resilience, and begin with unified, well-governed data foundations that reduce risk and enable rapid recovery.

On this Data Privacy Day, organizations should take a closer look at their data strategies to ensure they can keep pace with increasingly complex data environments and AI-driven threats. Those that prioritize resilient architectures, proactive governance, and cross-functional accountability will be better positioned to protect sensitive data, meet regulatory expectations, and responsibly harness the potential of AI in the year ahead.

++

Raghu Malpani, Chief Technology Officer at UiPath

As AI agents gain real autonomy—accessing data, making decisions, and executing actions—their security stakes skyrocket. Addressing this challenge is now a top enterprise priority. From governance-as-code and human-in-the-loop workflows to real-time observability, organizations are wiring in control systems to ensure agents adhere to enterprise data policies, privacy requirements, and usage limits wherever they operate.

Data Privacy Day reminds us of the importance of adopting embedded governance across AI agent lifecycles and aligning automation, security, and data teams around shared frameworks that keep agents compliant, explainable, and secure as they scale.

++

Brett Tarr, Head of Privacy & AI Governance at OneTrust

Data Privacy Day is a reminder that privacy isn’t just about compliance; it’s about trust, accountability, and how organizations earn the right to use data responsibly. As we look forward in 2026, we are seeing some shifting tides in the world of Privacy and AI governance, both domestically and across the globe. Increasingly, the scales are shifting towards economic competitiveness across regions.

Within the US, additional states continue to deliver comprehensive privacy policies, but at the federal level there is a shift in focus towards pre-empting disparate state AI regulations to pursue competitive advantages for US AI leadership.

In Europe, the European Data Protection Board has recommended streamlining and simplifying the EU’s complex digital laws (including GDPR, AI Act, Data Act, ePrivacy Directive) by reducing overlapping rules, harmonizing definitions, and cutting administrative burdens for businesses. The underlying goal is to boost EU competitiveness and innovation by making digital compliance easier and cheaper.

For privacy leaders, this means the potential for less complexity in managing compliance. We will always anchor our strategy to regulation (both current and horizon scanning) and principles of good data governance, but we identify trends and that helps us build our tactical plans/workflows accordingly. Europe’s move to consolidate and simplify compliance doesn’t change how we approach privacy, but it does reduce the number of steps and channels we need to execute across.

From an AI perspective, changes in regulation don’t mitigate the underlying need for AI governance, it just shifts how and why we deliver governance controls. Customers expect businesses to take care of their data and statistics show that customers flee brands that are careless with the data they are entrusted with. Even if the regulatory environment shifts to fewer controls, market conditions demand that companies pick up the slack if regulations recede, and responsibility for AI governance simply shifts from compliance requirement to a business imperative.

++

Cynthia Overby, Director of Strategic Security Solutions, Rocket Software

Data Privacy Day is a timely reminder that privacy must be built into enterprise strategy, not added after the fact—especially as AI moves from experimentation to full-scale production. However, AI outcomes are only as reliable as the data they consume, and inaccurate or poorly governed data undermines both model performance and privacy protections.

That’s why data governance is becoming a board-level priority. Enterprises need clear accountability for how sensitive data is managed across operational systems, analytics, and AI pipelines, while also addressing growing data sovereignty requirements through flexible hybrid architectures. This includes tackling long-standing challenges like excessive access to sensitive data on the mainframe, which remains a major and often overlooked privacy risk. Without the resources to properly manage external security managers, organizations expose critical data to unnecessary risk.

At the same time, AI-driven threats are accelerating. Protecting privacy now depends on strong identity controls, Zero Trust principles, and security models that can respond at machine speed. Organizations that embed privacy, clean data practices, and access discipline into their data, AI, and security foundations will be best positioned to innovate with confidence.

++

By Sergio Gago, Chief Technology Officer at Cloudera

AI is increasingly embedded in everyday operations, which means enterprises are feeding more data into models than ever before. Large language models (LLMs) are now the norm in customer support, analytics, developer productivity, and knowledge management. AI agents also add valuable contributions, such as retrieving information, reasoning over it, and then taking the necessary next step. To mitigate the risk of using sensitive data to train AI models, enterprises have been using synthetic data, which is considered the best way to protect customer privacy. 

However, synthetic data is unfortunately not the silver bullet for data protection. Poorly generated synthetic datasets can still leak sensitive information. If they preserve rare combinations or inadvertently frame a data point too closely to the original, the risk of personal information being used for AI training increases. Synthetic data can also fail in the opposite direction. If it is “too clean” or generic, it won’t accurately reflect the data used to train models, and these solutions will struggle in real-world deployments. 

A more realistic framing is that synthetic data serves as a risk-reduction tool. When it’s handled with structure and discipline, it can reduce the exposure to personal data and enable model development to move forward. For synthetic data to mitigate privacy risk, it must be treated as an engineering discipline with guardrails, rather than a last-minute workaround.

++

Emilio Escobar, Chief Information Security Officer at Datadog

Data Privacy Day is a vital reminder to evangelize and adopt cybersecurity best practices. Every identity—human or machine—is a potential entry point to critical data, and protecting this data only becomes harder as companies grow and adopt new technologies. Datadog’s 2025 State of Cloud Security report found that there is still a lot of work to be done in adopting well-established best practices as simple as removing long-lived credentials. Because long-lived credentials never expire and frequently get leaked in source code, container images, build logs and applications artifacts, they are a common gateway to data theft. In 2025, 59% of AWS IAM users, 55% of Google Cloud service accounts and 40% of Microsoft Entra ID applications had an access key older than one year. Organizations should take the opportunity on Data Privacy Day to remove long-lived credentials, and adopt strong access controls and continuous verification features. Best practices like these are how we can continue making privacy a continuous outcome, not just a one-day commitment.

++

Dan Balaceanu, Chief Product Officer and Co-Founder at DRUID AI

Data privacy is the first thing to consider when building an IT system—especially an AI solution. It is not a naïve architectural choice. In today’s world, IT solutions are composed of multiple services, often distributed, integrating LLM providers, vision providers, line-of-business applications, and automations. Ensuring data privacy in such complex ecosystems requires expertise.

As a solution provider, Druid takes full responsibility for keeping data private by hosting the required technologies within its own environment and validating that all connected technologies comply with data privacy regulations.

++

Jared Atkinson, CTO, SpecterOps

Data Privacy Day is a reminder that protecting sensitive data starts with protecting identity. In modern environments, identity has become the control plane for access to systems, applications, and data, which attackers know. Identity sprawl and the rise of agentic AI have made it increasingly difficult to understand who or what has access to sensitive information. When identities are compromised, data privacy controls quickly break down, regardless of how well the data itself is secured.

This is why Attack Path Management is essential to effective identity security and data privacy. Traditional controls like MFA and access reviews don’t show how attackers move through identity infrastructure by chaining misconfigurations, excessive privileges, and trusted relationships. Safeguarding sensitive data in an AI-driven world requires continuous visibility into identity attack paths and the ability to eliminate them before privacy is put at risk.

++

Brent Torre, GM of Backup Continuity and SaaS Protection at Kaseya

Data privacy cannot exist without cyber resilience. As organizations face an evolving threat landscape and increasingly complex compliance requirements, the ability to recover quickly has become inseparable from privacy protection. With multiple new state privacy laws taking effect throughout 2025 – including stricter frameworks in Maryland, Minnesota, and New Jersey – and states embedding security requirements directly into privacy laws, organizations face mounting pressure to demonstrate both data protection and operational resilience.

Vendors need to help technicians navigate these challenges with a resilience-first approach. Regulations like HIPAA, PCI DSS, CMMC, and CJIS require robust data retention policies, encryption, access controls, and disaster recovery capabilities. A unified BCDR platform needs to address these requirements with hardened appliances, immutable cloud storage using write-once, read-many formats, and FIPS validated encryption. This Data Privacy Day, assess both your privacy policies and resilience posture: Can you recover within hours? Are your backups tested and immutable? With compliance frameworks evolving rapidly, cyber resilience isn’t just good practice – it’s a regulatory imperative.

++

Monica Landen, CISO at Diligent

Data Privacy Week comes at a moment when the gap between AI adoption and AI governance has never been wider. Business leaders are doubling down on AI investments, yet many organizations are racing to implement AI tools without putting the right data governance frameworks in place.

In some instances, companies have deployed generative AI solutions only to discover too late that they have inadvertently exposed sensitive customer data or violated compliance requirements. The aftermath isn’t pretty, leading to reputational damage, regulatory penalties, and considerable loss of revenue.

So how do companies actually protect their data when AI enters the picture? Recent research shows that 97% of organizations that experienced an AI-related security incident lacked proper AI access controls – a striking and preventable gap. This isn’t just a technology problem. It’s a governance failure. While 22% of boards have adopted formal AI governance, ethics or risk policies, another 31% have only discussed it without putting policies in place. The potential for AI-related data privacy incidents is no longer just a theoretical concern; it has become a critical governance challenge that many organizations are struggling to overcome.

++

Nico Dupont, Founder and CEO, Cyborg

The rapid adoption of AI without true consideration for data privacy and security is a huge cause for concern. While an AI-literate organization understands that AI adoption is as much a data security challenge as a technology one, those further behind the curve may not understand that sensitive information is required to make AI useful and effective in driving business value.

As organizations centralize data to power AI, they are creating valuable knowledge bases that become prime targets for attackers. This growing threat calls for a shift in security architecture away from insecure vector databases – embedding data encryption directly into the AI stack to keep information usable and secure for those who have the keys, while simultaneously meaningless in the hands of the adversary.

++

Nimrod Partush, VP of AI & Innovation at CYE

The distinction between data privacy and data security is crucial, particularly when discussing AI training data. Privacy, in this context, is about preventing the LLM from accidentally revealing private data it encountered during training—like suggesting a user’s API key. Risk becomes concrete the moment a system is connected to something personal, like an email inbox for a recent example. Tools that summarize messages or draft replies often read content a human never opens. If malicious input makes it past spam filters and enters that workflow, the model can be steered in ways the user never intended. This has been tested in real systems.

That said, the industry is moving quickly to connect AI to inboxes for productivity, while security remains secondary. Once a model has access to personal data, the stakes shift. An attacker does not need deep access or technical exploits. Influence alone can be enough. Training models on sensitive information or allowing them to retain private data introduces long term risk that cannot be reversed later. Privacy and transparency shape whether AI remains useful or quietly creates exposure.

When discussing the path forward, the current landscape of AI regulation is fascinating. The self-regulation strategies adopted by major AI companies, like forming internal safety committees, have effectively slowed the pace of external government-mandated laws. While acts like the EU AI Act are important for basic transparency, a gap remains: there is no specific regulation ensuring new models are consistently safe and private before deployment.

We cannot solely rely on the companies to police themselves, especially as business interests evolve.

++

Sonu Shankar, President and COO at Phosphorus Cybersecurity

Everyone is fixated on LLM security and prompt injection, yet the physical backbone of AI remains dangerously overlooked. Compromise a single chiller or PDU (devices often secured no better than an office printer with default passwords), and you can physically cripple an entire data center: GPUs overheat, systems cascade-fail, training halts, and cloud services vanish. Trillion-dollar AI empires are being built on sand. Until we secure the diverse, invisible device foundation facilitating it all, every privacy promise and uptime guarantee is hollow. A forgotten default password isn’t just a vulnerability; it’s a loaded weapon aimed at modern computing’s heart.

The Human Element: Trust, Consent, and Behavior – Why human access, browser habits, and psychological manipulation are the primary drivers of data exposure.

++

Aviad Hasnis, CTO of Cynet

The human layer is no longer the weakest link, it’s the most manipulated one.

This past year, we saw campaigns like ClickFix use AI to generate hyper-realistic CAPTCHA and consent prompts that look and feel legitimate, but quietly push users into approving actions they don’t fully understand or intend. There’s no malware pop-up. No obvious red flag. Just interfaces designed to exploit trust.

What’s unsettling is when this works, nothing is technically broken. Systems behave exactly as designed. Yet, sensitive data can still be exposed because trust is being abused rather than bypassed. Attackers no longer need to break in, they simply blend in.

The takeaway for Data Privacy Day is that consent without context is no longer meaningful consent. As AI erases the visual and behavioral cues people are trained to rely on, privacy protection can’t depend on perfect user judgment. It has to be engineered into systems through architectural controls that limit third-party blast radius, enforce least privilege by default, and revoke trust quickly without disrupting the business.

++

Cody Pierce, Co-Founder and CEO, Neon Cyber

Data privacy breaks down through people, not systems. Attackers do not need to breach infrastructure when they can exploit trust and access a single individual’s browser session. With cloud and SaaS centralizing data, one compromised token can expose entire datasets in minutes. From a privacy standpoint, that makes human access the most critical control plane.

What leaders still underestimate is visibility. Security teams make risk decisions without understanding the context behind how data moves, where it goes, and why. That gap is widening as employees copy and paste sensitive information into third-party tools and AI platforms with little awareness of downstream use. Data Privacy Day is a reminder that privacy is not just a policy problem. It is a visibility and decision-speed problem, and without context, organizations cannot protect what matters most.

++

Jon France, CISO, ISC2

While public awareness campaigns about privacy are valuable, data privacy focus should be a continuous, year-round commitment. There needs to be a clear understanding of where data is located, managed and accessed to avoid getting into the wrong hands. Strong information governance, clear access controls and the practice of data minimization (i.e., only information needed for a given purpose should be collected, stored and processed) are paramount for rigorous information privacy.

People remain a critical part of this equation. Appropriate security controls can help enforce policy and reduce complexity, but they do not replace the need for professionals who understand privacy obligations and the intent behind them. When the right skills are in place, this approach can deliver meaningful insight while still respecting information privacy and compliance requirements.

++

Christie Terrill, CISO at Bishop Fox

Privacy expectations and realities have shifted. Historically, personal information was something consumers could often control or avoid sharing by using non-identifying usernames and strong passwords. Today, pervasive data collection, biometric authentication, and stronger identity requirements, like MFA and passkeys, mean people frequently have to disclose or generate more sensitive identifiers just to participate in digital services.

At the same time, definitions of what qualifies as personal data continue to expand, alongside a growing patchwork of U.S. state and international privacy regulations. That combination makes protecting personal data far more complex than policies alone acknowledge. Many organizations are collecting and storing data in architectures that were never designed for strict minimization, purpose limitation, or timely deletion at scale.

Businesses don’t have a magic “delete” button. Removing all instances of a specific data type or a single individual’s data requires intentional design, deep visibility into data flows, and ongoing testing. Without that foundation, even well-intended privacy commitments can quietly break down in practice.

I’m also skeptical that consent, as it exists today, functions as a meaningful control. Most users aren’t reading privacy disclosures and then deciding not to use a service they already intend to sign up for. Consent fatigue and disclosure overload weaken the idea that user choice alone can meaningfully protect privacy.

In short, personal data is becoming more exposed and more widely shared as a prerequisite for participating in a technology-driven society. Privacy regulations set important goals, but without systems that are architected, tested, and validated to enforce them under real-world conditions, it’s difficult for organizations to meet the full intent behind those laws.

++

T. Frank Downs, Senior Director of Proactive Services, BlueVoyant

Globally, the current state of online privacy of individuals is wildly inconsistent and, in many cases, deeply concerning. For example, the EU, which observes GDPR as key legislation, provides its citizens a gold standard level of privacy in comparison to other Western countries by taking a citizen first perspective to data sovereignty. As a result, individuals have meaningful control over their personal information, including access to strong mechanisms for permanent data deletion that organizations are obligated to provide in a clear and accessible manner.

Comparatively, outside of California, the United States makes miniscule effort to protect the data of its citizens. Companies are largely free to collect, exploit, and monetize user information within the bounds of laughably weak regulatory requirements, and at times push even beyond them. This disturbing reality is reinforced by the disingenuous lip service that is provided by companies when compromises such as the 2017 Equifax hack occur.

Despite compromising the personal data of over 100 million US citizens, Equifax’s offers to provide “free” identity monitoring services came with the small print requirement that users agree not to sue the company for its failure to protect their data in the first place.

This despairing dichotomy between EU and U.S. privacy protections highlights the global fragmentation of individual privacy rights and reveals how certain countries prioritize corporate interests over the fundamental rights of their citizens.

++

David Sequino, Founder and CEO of Integrity Security Services (ISS):

Data privacy is no longer a policy issue. It is a trust problem rooted in technology. As AI, connected devices, and autonomous systems expand across critical environments, privacy failures increasingly stem from compromised device identities, unmanaged cryptographic assets, and unverified software supply chains.

If a device cannot authenticate its firmware, protect its keys, or prove software integrity, the data it produces cannot be trusted. Privacy controls applied after the fact cannot fix a lack of trust at the source. True privacy must be built in, starting with cryptographic identity at manufacturing and enforced throughout the entire lifecycle.

In the agentic era, AI systems and automated machines must be treated as managed identities, with actions that are verifiable and auditable. Without continuous visibility into keys, certificates, and secrets, privacy promises will fail, especially as quantum risk accelerates. Trust will define who can truly protect data privacy.

++

Wayne Gipson COO at ISSE Services

As a company that works in the Defense Industrial Base, we approach data privacy as a fundamental obligation to the nation and to the individuals whose data we are entrusted to protect. The user data we handle—whether related to employees, partners, or government stakeholders—exists because people and the public sector have placed their confidence in us to act as careful stewards.

From a taxpayer’s point of view, any failure to protect user data would feel like a violation of that trust, raising concerns not only about personal privacy but also about whether public funds are being responsibly managed. Taxpayers would reasonably expect that organizations, performing work funded by their dollars, apply the highest standards to safeguard sensitive information, rather than exposing it to misuse or unnecessary risk. Protecting data, therefore, is not simply a compliance exercise for us; it is a reflection of our commitment to respect individual privacy, maintain public confidence, and ensure that taxpayer-supported systems are worthy of the trust placed in them.

++

Bob Bobel, Founder & CEO of Cayosoft

With Data Privacy Week upon us, it’s important to remember that data privacy today depends less on where data is stored and more on the identity infrastructure that controls access to it. As organizations add cloud services, automation, and machine identities, access quietly expands in ways that are easy to justify but hard to fully see. When identity isn’t treated as critical infrastructure – visible, governed, designed for change, and routinely maintained – privacy risk becomes embedded in everyday operations rather than appearing as a single failure.

In modern hybrid and cloud environments, identity effectively acts as the control plane for privacy. Every application, service account, and automated workflow depends on access decisions that determine which data can be read, modified, or shared. Those decisions accumulate incrementally through ordinary operational changes such as new integrations, temporary exceptions and inherited permissions, making it possible to satisfy compliance checklists while still lacking a defensible understanding of who truly has access to sensitive data and why.

Organizations with mature identity practices approach access as a continuously operating system rather than a periodic audit exercise. By maintaining ongoing visibility into permissions and reassessing access as roles, workloads, and systems evolve, they reduce the gap between documented policy and lived reality. That discipline doesn’t prevent change, but it ensures privacy controls remain aligned with how the environment actually functions, helping organizations manage risk proactively as technical complexity continues to grow.

++

Michelle Finneran Dennedy, Chief Experience Officer and Advisor at Lokker

Privacy in 2026 demands we move beyond policy and into operational reality. While we’ve spent years crafting beautiful policies and consent banners, the data tells a stark truth: 92.7% of websites still load third-party trackers before users give consent, and 80% of consent managers remain fundamentally ineffective or poorly implemented.

The shift is profound. Privacy can no longer exist as a purely legal or advisory function. Forward-thinking organizations are restructuring privacy under operational leadership, creating direct workflows with engineering and analytics teams that enable real-time risk detection, remediation, and strategic planning. 2026 should bring the curtain down hard on compliance theater. Users, regulators, and demanding class action legal sharks require demonstrable leadership, repeatable assessments, and preserved evidence of control.

What excites me most is that privacy, marcom, legal, and business teams have access to workable tools that enable technical fluency in SDK behavior, web tracking, and third-party code characteristics. Facts and data flows—not policies alone—determine successful outcomes. Organizations that adopt KPI-driven reporting, continuous monitoring, and cross-functional collaboration will transform privacy from a cost center to a competitive advantage. The path forward requires visibility first, then action. Companies that can prove how data is actually processed in practice, not just described on paper, will build lasting user trust and thrive in an environment where transparency drives growth.

++

Todd Moore, VP of Data Security Products, Thales

Data Privacy Day is a good moment for all of us to step back and consider how much data is being collected and shared through everyday technologies like wearable devices. As these tools become more popular and deliver real benefits, they generate highly sensitive health, location, and behavioral data that often flows through mobile apps, enterprise systems, and cloud platforms, making it essential to understand where that data goes, who it’s shared with, whether it’s encrypted, and how it’s protected at every step. Companies collecting this data must be good stewards of data privacy, and individuals should take time to understand how their information is being used and safeguarded throughout its entire lifecycle.

++

Stephen Manley, Chief Technology Officer at Druva

Your greatest privacy threats are your well-intentioned co-workers. They’re using AI to do their job, but it exposes your organization’s weak data governance. Privacy through obscurity once kept us safe, but AI agents are shining a light on sprawled data, and what users can see is terrifying.

For decades, companies focused on securing sensitive data from external threats, but blocking external access does not resolve unclear data ownership, overly broad access, and poor access tracing. Before AI, a person might misuse data one record at a time. AI can access millions of records in seconds, and if permissions are broad or auditing is weak, there is no way to stop it.

Teams want to move fast, but the data environment is not ready. The only viable path forward is modernizing governance for an AI era: reduce access by default, make data use traceable end-to-end, and monitor how agents interact with sensitive data. You need a centralized policy and tools to govern all your data—from endpoint to data center to cloud. Otherwise, your co-workers will continue to be the biggest unintentional threat to your privacy.

++

Jennifer Davide, Senior Director of Privacy and Product Counsel at Alteryx

As we arrive at Privacy Day 2026, privacy is no longer a parallel concern to artificial intelligence; it has become AI regulation’s central organizing principle.

In 2025 alone, eight comprehensive state privacy laws took effect in the United States, alongside eight new international regimes, including India’s Digital Personal Data Protection framework and Mexico’s federal data protection law. Though not AI-specific, these laws increasingly function as de facto constraints on AI development, governing how training data is sourced, how automated decisions are disclosed, and how individuals can access, delete, or object to data use. As AI systems scale, lawmakers are reinforcing baseline privacy rights as a necessary counterweight.

At the same time, AI-specific legislation is beginning to embed privacy protections directly. Internationally, only two AI laws meaningfully entered into force in 2025—the phased EU AI Act and Italy’s national AI law—yet both incorporate data governance, human oversight, transparency, and alignment with existing data protection regimes. In the United States, California enacted six AI-related bills addressing privacy-adjacent risks, including AI disclosures in healthcare, companion chatbot safety, protections against AI-generated deepfakes, and age-appropriate design requirements for children. Even when framed as consumer protection or safety measures, the core concern is personal data misuse and loss of individual agency.

The regulatory pipeline matters as much as what is already in force. Colorado’s AI law will take effect next, EU member states are advancing national AI implementation legislation, and Mexico, Brazil, and Canada all have active AI bills pending. Together, these developments show a trend: regulators are responding to expanding AI capabilities not by halting innovation, but by insisting that AI systems be built, deployed, and governed to preserve transparency, user choice, and control over personal data.

In 2026, privacy professionals must deepen AI literacy to meet heightened accountability to employees, customers, and users.

++

Dr. Srinivas Mukkamala, CEO at Securin

AI doesn’t leak data by accident; it leaks data through exposure. Every training pipeline that ingests sensitive records, every embedding that preserves latent meaning, every API that over-trusts prompts and every autonomous agent that chains actions together expands the AI attack surface. Adversaries don’t need a single catastrophic flaw. They exploit weakness chaining — a permissive data source, an overexposed model interface, a misconfigured access control — and suddenly sensitive data can be inferred, exfiltrated or reconstructed without tripping traditional controls.

On Data Privacy Day, the message is straightforward. If you don’t understand your AI attack surface — and how CVEs, CWEs, misconfigurations and design assumptions combine across it — you don’t control your data. Privacy survives only when AI systems are defended the way attackers see them: end to end, continuously validated and tested against real exploit paths rather than theoretical assurances.

++

Bruce Kornfeld, Chief Product Officer, StorMagic

Data Privacy Day is a reminder that protecting sensitive information requires consistent discipline, not just policies. This discipline starts with infrastructure choices. As organizations continue to evaluate cloud-first strategies, many are also reassessing where their most critical data should live. For workloads that demand predictable performance, strong governance and clear ownership, on-site infrastructure continues to play an essential role in a sound privacy strategy.

Keeping data on-prem, closer to where data is being generated and managed, gives organizations greater visibility and control over how information is stored, accessed and protected. This is especially relevant as regulations evolve and as more data is generated at distributed and edge locations. When data stays closer to where it is created and used, IT teams can more consistently enforce security standards, reduce exposure and respond quickly when issues arise.

Long-term data protection comes down to stability and accountability. Infrastructure decisions should support privacy by design and reduce operational risk across all environments, helping organizations protect sensitive information and maintain trust as their IT environments continue to change.

++

Cyrus Robinson, VP of Security Operations, C3 Integrated Solutions

In highly regulated sectors like the defense industrial base, data privacy issues usually arise when organizations lose track of where sensitive data resides, how it moves, and who has access to it. In our incident response and security operations work, problems rarely come from a single breakdown. More often, they stem from familiar gaps such as misclassified data, overly broad access, or environments where visibility hasn’t kept pace with cloud adoption and third party integrations.

Data Privacy Week highlights that protecting sensitive information requires consistent, day to day operational discipline. Attackers are increasingly leaning on MFA bypass techniques, credential theft, and zero-day vulnerabilities in edge systems to get to the data organizations assume is protected.

The teams that are most effective treat privacy as an ongoing, ever-evolving set of operational responsibilities. They build alignment around how data is handled, which controls, monitoring, and response approaches fit their environment, and how to maintain a unified picture across security and compliance teams. When everyone operates from a shared understanding, organizations are far better positioned to reduce exposure and act decisively when an incident occurs.

++

Yair Cohen, Co-Founder and VP Product, Sentra

Data Privacy Day is a good reminder that finding sensitive data is only the first step. In modern environments, data is constantly moving across cloud platforms, SaaS applications and AI workflows. Privacy breaks down not because organizations don’t care, but because access decisions are often disconnected from how data is actually being used.

What matters now is governing access in real time. Organizations need to understand who or what can touch sensitive data, whether that access is still appropriate, and how it changes as systems evolve and data moves. As AI and automation become part of everyday operations, privacy cannot be enforced once a year during an audit. It has to be maintained continuously.

The organizations that succeed will treat data privacy as an ongoing responsibility, built into how data is accessed and used and whether the security posture of that data is continually maintained, not as a compliance checkbox that gets revisited after something goes wrong.

++

Milan Chutake, Vice President (VP) of Engineering, Protegrity

In an AI-driven world, data privacy must be addressed before data ever touches a model, not after something goes wrong. Once sensitive data enters an AI pipeline or an external LLM, it becomes extremely difficult to reverse that exposure. The biggest challenge I see today is that many organizations are moving faster than their governance models can support, and data privacy is becoming a real nightmare because there is no centralized policy consistently controlling how data is discovered, shared and used across systems.

AI can help automate discovery across databases and unstructured data, but it cannot replace human oversight, and nobody should blindly trust AI with sensitive data. Privacy requires more than discovery: it requires clear policies, continuous logging and visibility into how data flows across every step of an AI workflow. Without centralized control and proof of how data is accessed and used, enterprises risk losing control of their most sensitive information at the exact moment they are trying to scale AI the fastest.

++

John Searby, Chief Strategy Officer of HUMAN Security

The rise of AI-driven systems has unlocked immense innovation but also exposed critical vulnerabilities. Scraping, the raw material of the AI economy, powers agentic systems and automated decision-making while threatening intellectual property, licensed content, and creative rights. As businesses grapple with data leakage, unauthorized reuse, and IP exposure, the challenge lies in balancing the benefits of agentic systems with the governance of the scraped inputs that fuel them. This challenge is no longer theoretical— with agentic traffic surging 6,900% in 2025, this underscores how quickly machine-driven interactions are becoming a leading online source.

These pressures are especially pronounced in agentic commerce, and industries like retail, e-commerce and finance. According to HUMAN’s 2025 Quadrillion Report, retail and e-commerce faced nearly three-quarters of all scraping attacks, with some businesses seeing months where 95% of their traffic was automated. Mastercard’s latest move to help write the rules for agentic commerce further signals that AI-driven shopping is rapidly moving from concept to reality. This surge in machine-driven activity foreshadows the scale at which AI agents will operate by 2026. To stay competitive, businesses must not only protect their data but also prepare for a future dominated by AI agents, where innovation and governance must go hand in hand.

++

Spencer Kimball, CEO & co-founder of Cockroach Labs

Data sovereignty doesn’t fail because people ignore policy. It fails because systems weren’t designed to enforce boundaries when things go wrong. In steady state, almost anything looks compliant. Under failure—regions go dark, providers misbehave, failovers trigger—that’s when data crosses borders unintentionally and risk compounds fast.

The real signal from regulations like GDPR isn’t about paperwork or checklists. It’s a warning that architecture matters more than intent. As data protection laws proliferate and geopolitics continue to shift, sovereignty has to be a property of the system itself. The future belongs to architectures that can localize data by default, preserve guarantees under stress, and adapt as rules inevitably change.

++

Michael Gray, CTO of Thrive

Data Privacy Day is a reminder that trust is now one of the most valuable assets organizations have, and one of the easiest to lose. As businesses rely more heavily on data and AI to drive decisions and automation, privacy can no longer be treated as a compliance exercise alone.

Strong data protection starts with understanding what data you collect, why you need it, and how it is governed throughout its lifecycle. In 2026, poor data hygiene does not just create privacy risk, it undermines the reliability of AI systems built on that data. Regulatory scrutiny will continue to increase, but the greater risk for organizations is reputational damage when customers lose confidence in how their information is handled.

Companies that prioritize transparency, accountability, and restraint in their data practices will be better positioned to build lasting trust in a data-driven world.

++

Danny Manimbo, Managing Principal and ISO & AI Practice Leader at Schellman

Data Privacy Day is a reminder that many of the risks organizations face with AI and data are not new. What has changed is scale. As AI and automated systems become more deeply embedded in business operations, long-standing gaps in data governance, ownership, and oversight become harder to contain and easier to expose.

AI amplifies these existing privacy risks. When data governance is weak, those gaps surface faster and with greater impact — through biased outcomes, unreliable outputs, and limited visibility into how decisions are made. This is why privacy and AI risk cannot be managed as ad hoc compliance exercises. They must be treated as material risk domains, governed through structured, repeatable processes aligned to recognized management system frameworks such as ISO 27701 for privacy information management and ISO 42001 for AI management.

Used together, these frameworks reinforce disciplined governance by requiring organizations to assess risk upfront and continuously through privacy and AI impact assessments. These assessments help organizations understand how personal data is used, how automated decisions may affect individuals, and where controls, human oversight, and accountability are needed across the AI lifecycle. Building trust requires more than strong policies — it requires evidence that risks are identified, mitigated, and monitored as systems scale.

##