Breach Notifications Are Gaslighting You: The Real Reason Your Data Keeps Leaking

You know the feeling. The email arrives — “We’re writing to inform you of a data breach…” Your heart sinks, but only for a second. Because you’ve been here before. You scroll, skim, sigh, and move on. Because what else can you do? That’s the problem.

We’ve been trained to accept this as normal. Another breach, another notification, another reminder that your personal data is not really in your control. It’s a weary inevitability — the digital equivalent of death and taxes. But here’s the uncomfortable truth: Data breaches are not accidents. They are the inevitable result of a business model that treats your personal information as a byproduct to be hoarded, not a liability to be minimized.

Look at the latest victim: Framework, the laptop maker that prides itself on modularity and repairability, just told “all customers” about a breach. Not some random forum, not a sketchy app — a company that’s supposed to be the “ethical” hardware brand. If they can’t protect your data, who can? The answer: nobody. Because the entire industry is built on collecting data they don’t need and keeping it around forever.

Think about it. Why does a laptop maker need your home address, your phone number, your order history? They need to ship you a product. That’s it. But they hold onto everything — just in case. Just in case they want to market to you. Just in case they want to sell your data to a partner. Just in case someone asks for it.

And when the breach happens — and it will happen — they send you a generic email telling you to “take precautions.” Change your password. Enable two-factor authentication. Monitor your credit. Use a credit freeze. In other words: Stop asking me to fix your mistakes. Start by not making them in the first place.

This is the gaslighting at the heart of modern data breaches. The notification is a ritual designed to offload responsibility onto you. It’s not an apology; it’s a deflection. “We’re sorry, but also, you should have known better.” The onus is on you to protect yourself from a system that refuses to protect you.

What would actually work? Data minimization. The principle that you only collect and retain the data you genuinely need, and delete the rest. If Framework didn’t have your phone number, it couldn’t leak your phone number. If they deleted your order history after the warranty expired, they couldn’t expose it. It’s that simple — and that radical.

But companies won’t do it because data is valuable. Not to you — to them. It’s the fuel for their targeted ads, their “personalized experiences,” their algorithmic voodoo. They’d rather risk a breach than sacrifice a single data point. And they’ve convinced regulators and consumers that the answer is “better cybersecurity” rather than “less data.”

So what do you do? You could follow the advice in every breach notification: use aliases, isolate spam, use a separate email for every service. But that’s just band-aids on a bullet wound. The real fix is to stop accepting the narrative. The only truly reliable mitigation is systemic data minimization — not customer-side workarounds.

Demand better. Ask every company you do business with: What data do you hold on me? Why do you need it? How long will you keep it? Deletion is a right in many jurisdictions — use it. And when you’re asked to “upgrade your account” or “complete your profile,” say no. Every bit of data you refuse to give is a bit they can’t leak.

We’re tired of being the victims and the fallback plan. It’s time to turn the tables. The next time you get a breach notification, don’t just sigh and move on. Forward it to the company’s CEO. Ask them why they needed your data in the first place. Ask them what they’re doing to minimize what they collect. And if they don’t have a good answer — take your business elsewhere. Because the only way to stop the endless cycle of breaches is to make hoarding data more expensive than protecting it. And that starts with us, refusing to play their game.

FAQ

Q: Isn't it my responsibility to protect my own data by using strong passwords and monitoring accounts?

A: No. That's exactly the deflection companies use. Your password habits don't matter when a company's server is exposed. The only way to be truly protected is to not give them data they don't need. You can't secure data that doesn't exist.

Q: What practical action can I take beyond changing passwords?

A: Exercise your data deletion rights. Send requests to companies to delete your data after you stop using their service. Decline optional data collection. Use privacy-focused services that collect less. And when you get a breach notification, respond publicly — ask the company why they needed your data in the first place.

Q: Isn't data minimization unrealistic in a modern digital economy?

A: It's not unrealistic — it's just inconvenient for companies. GDPR and CCPA already require data minimization in principle. The technology exists. The problem is that businesses are addicted to data as a revenue stream. If consumers demand it, regulation will force it. The alternative is an endless cycle of breaches and victim-blaming.

📎 Source: View Source