Please please please take your cyber security seriously even if you don’t consider yourself a high risk person. Here are a few easy things to start with. 1/n

Switch from WhatsApp to Signal and enable disappearing messages. Most of us cannot stop using WhatsApp entirely but at least turn off back ups to Google Drive or iCloud. 2/n
Do not have private conversations using the messaging service on any social media platform like Facebook, Instagram or Twitter. 3/n
Switch from Gmail to ProtonMail or any other secure email service provider. 4/n

https://t.co/lQfyjLnu4B
Switch from Google Docs to CryptPad or RiseUp Pad. 5/n

https://t.co/c4WJr8ilRs

https://t.co/DSbnZkAUAM
Get yourself a trustworthy VPN. 6/n

https://t.co/TjgylNbjKn
Want to share documents securely? Use Onion Share. 7/n

https://t.co/HKbPZyD6kj
Stop using weak ass passwords and get yourself a password manager which will generate and remember secure passwords for you. 8/n

https://t.co/gL55SsqNec

https://t.co/zJQvYv3XId
There is a lot that can't be covered in a Twitter thread and you should always do your own research. Here are some guides by actual technical experts unlike this thread written by a well-intentioned lawyer. 9/n

https://t.co/TXiOwURsA3
https://t.co/ntvh1Sgq7p

You May Also Like

Recently, the @CNIL issued a decision regarding the GDPR compliance of an unknown French adtech company named "Vectaury". It may seem like small fry, but the decision has potential wide-ranging impacts for Google, the IAB framework, and today's adtech. It's thread time! 👇

It's all in French, but if you're up for it you can read:
• Their blog post (lacks the most interesting details):
https://t.co/PHkDcOT1hy
• Their high-level legal decision: https://t.co/hwpiEvjodt
• The full notification: https://t.co/QQB7rfynha

I've read it so you needn't!

Vectaury was collecting geolocation data in order to create profiles (eg. people who often go to this or that type of shop) so as to power ad targeting. They operate through embedded SDKs and ad bidding, making them invisible to users.

The @CNIL notes that profiling based off of geolocation presents particular risks since it reveals people's movements and habits. As risky, the processing requires consent — this will be the heart of their assessment.

Interesting point: they justify the decision in part because of how many people COULD be targeted in this way (rather than how many have — though they note that too). Because it's on a phone, and many have phones, it is considered large-scale processing no matter what.