With 2026’s Data Privacy Day marking the 45th anniversary of the first legally binding international data privacy treaty (though the actual Data Privacy day in only 20 years old), the debate over who should protect personal information – and how – has hardened into a practical, day-to-day problem for organisations and the public alike.
Taking a moment to reflect for this year’s iteration of Data Privacy Day and its hard not to feel a bit of unease as we take in a data landscape reshaped by rapid AI adoption, chronic resourcing shortfalls in privacy teams, and a string of high-profile incidents and regulatory moves that make privacy risks feel immediate and tangible in the last year more than arguably ever before.
To understand just how these pressures are playing out in practice, let’s take a look at some research and data from the past year – as well as a couple of big news stories from the world of data protection and privacy to better understand the lay of the land.
What does the research and data tell us about privacy & data protection in last 12 months?
Across Europe, privacy functions are straining under rising workloads.
Recent research found in ISACA’s State of Privacy report paints a stark picture: almost four in ten legal privacy teams and more than half of technical privacy teams report being understaffed, while 44% say they are underfunded.
As those teams scramble to keep pace, more than a quarter (26%) of privacy professionals told ISACA they believe their organisation is likely to suffer a material privacy breach in 2026.
The human cost is already visible – two-thirds of those surveyed say the job is more stressful than it was five years ago – and the capacity shortfall is having measurable operational effects: only 64% of European firms have a formal incident response plan in place, leaving a significant minority ill prepared for serious incidents.
At the same time, commercial pressures and AI imperatives that will wait for no one are forcing companies to expand privacy programmes quickly.
Cisco’s 2026 Data and Privacy Benchmark Study finds that AI is the primary catalyst pushing 90% of firms to grow their privacy and governance functions, with 93% planning further investment. Cisco’s respondents argue that robust privacy frameworks unlock AI agility and customer trust: 96% say strong privacy controls support AI innovation, and 95% say privacy is essential to build customer confidence in AI systems.
Yet the same study flags a governance gap – three in four organisations report having an AI governance body, but only 12% judge those structures to be mature.
Those structural tensions – between the need to move fast on AI and the reality of under-resourced privacy teams – are not hypothetical or embedded within the nebulous world of business operations at large scale. No, they show up in product launches and public incidents that cut close to everyday users.
For example, OpenAI’s roll-out of ChatGPT Health in the US, for instance, commits the company to handling sensitive medical documents and data from health and fitness apps to provide personalised guidance. OpenAI says health data will be stored separately and not used to train the core model, and that it will be encrypted “by default at rest and in transit.” But the plan to deploy a health feature first in the US – where legal protections for medical data are narrower than in the UK and EU – and the broad appetite for health advice from chatbots have prompted fresh questions about when and how such services should be allowed to process clinical information.
On the flip side, when you take into account the millions of low‑income Americans that have lost or been put at risk of losing Medicaid coverage in recent years, following post-COVID policy changes and tightened eligibility and increased administrative hurdles via the Trump administration, it’s hard to state a cogent case against something like ChatGPT Health.
Elsewhere – and far more ethically clear-cut – apparent design choices have exposed private interactions in alarming ways. In August 2025, more than 370,000 conversations with xAI’s Grok chatbot were found indexed by search engines after users shared conversation links – a by-product of a “share” feature that made chats discoverable.
The published conversations included benign content but also sensitive material, from medical information to internal business notes, and in some reported cases instructions for wrongdoing.
Those incidents have coincided with intensified regulatory focus on the frontiers of privacy. The UK Information Commissioner’s Office published new guidance for manufacturers and developers of smart products, urging privacy-first design across the Internet of Things.
The ICO’s draft guidance stresses meaningful consent, transparent privacy information, and tools that let people exercise their data rights – in recognition that smart devices increasingly collect special category information such as health, biometric and location data.
The regulator’s intervention follows consumer research by Which? (brilliantly titled Why is my air fryer spying on me?) suggesting many IoT devices ask for permissions beyond what is functionally necessary, and it signals growing willingness by authorities to set expectations for privacy by design.
Tech Experts Weigh In
Against this backdrop, industry voices are urging both practical measures and broader cultural change.
Michael Field, managing director of Workflo Solutions, stresses individual steps people can take: “Smart technology continues to evolve at an incredible pace, so we’re encouraging people to be smart about protecting their data. We want to educate and empower individuals to make informed decisions about what data they share and who they share it with.” His advice – review privacy settings, use secure networks, enable multi-factor authentication and think carefully about social media disclosures – echoes the defensive checklist many now expect users to follow.
But experts emphasise that responsibility cannot rest with consumers alone. “Most privacy violations today don’t involve hackers. They happen quietly inside organisations’ own systems,” warns Chris Harris, EMEA Technical Director for Data and Application Security at Thales. He points to threats such as internal misuse, over-collection of data, and automated access through APIs and bots.
“As AI and automation become core to business operations, machines are now consuming sensitive data at scale in ways traditional privacy frameworks were never designed to handle,” Harris adds.
Security practitioners are also calling for better visibility into machine behaviour. Bernard Montel, EMEA Field CTO at Tenable, notes that “cyber criminals are weaponising AI to automate attacks and accelerate data theft…security visibility is shifting from human access to machine-driven behaviour.” That shift changes defenders’ priorities: detection and governance must extend beyond people to account for the actions of services, agents and integrations operating on behalf of users.
For many organisations, the answer lies in embedding privacy into everyday operations rather than treating it as a paperwork exercise. “This year’s Data Privacy Day theme, ‘You have the power to take charge of your data,’ is ultimately about accountability,” says Sam Peters, Chief Product Officer at IO. “Customers, partners and regulators now expect organisations to demonstrate how privacy is embedded into day-to-day operations. Policies alone are no longer enough.” Standards-based approaches, he argues, help firms move from intent to execution — formalising data mapping, privacy-by-design and rights management in ways that are auditable and repeatable.
Trust – and how to earn it – remains the throughline. “Data privacy is no longer a passing concern for consumers – it has become a defining factor in how they judge brands,” Patrick Harding, Chief Product Architect at Ping Identity, observes.
“For businesses, trust must be earned through transparency, verification, and restraint in how personal data is collected and used.” In customer experience, the tension between useful memory and intrusive retention is acute.
Recommended reading
- Report: Cyber Breaches Are Tanking Share Prices
- How Prepared Are You For The Inevitable Data Breach?
- AI Is Driving Data Breaches, IBM Finds
Shana Simmons, Chief Legal Officer at Zendesk, describes the promise and hazard of “memory-rich AI”: “Persistent memory builds customer loyalty…by embedding privacy by design at the architectural level, we can transition from a reactive posture to a proactive era of ethical data stewardship.”
If there is a unifying lesson as Data Privacy Day arrives, it is that the technical, organisational and regulatory pieces must move together. Companies are investing more in privacy – but seemingly only through the lens of AI demands for better data (that can be captured within the confines of the law), but investment alone will not address this while teams are understaffed and governance remains immature.
Beyond this, product features that surface private data – intentionally or accidentally – show how brittle privacy can be when design and oversight are weak and there isn’t a whole lot motivation for big companies to not just roll out features and track back later if there’s a privacy/data protection failure point.
For regulators, the message is that clearer expectations are needed for everything from smart devices to AI-driven services.
Happy Data Privacy Day!





