Normalisation
“This happens everywhere these days.”
Data leaks follow one another so quickly that warnings can lose their effect. News about yet another hack or data breach no longer feels unusual. Many people simply shrug.
When it published its 2022 data breach report, the Dutch Data Protection Authority already warned that everyone should assume their personal data has been leaked or still will be (NOS, in Dutch).
“This happens everywhere these days.”
“My data is out there anyway.”
“What can I still do myself?”
“Another data breach email.”
I use the term datalekmoe for this.
Datalekmoe (also: datalekmoeheid, in English breach fatigue) is the feeling that data leaks happen so often that acting no longer seems to make any difference.
In August 2026 I wrote a column about this on Cyberschaamte.nl and on LinkedIn (both in Dutch).
But precisely because data leaks keep becoming more common, we must stop familiarity from tipping into resignation.
As a society we need to stay alert about preventing data leaks and at the same time learn to live with today’s reality.
“Data leaks are the emissions of our digital society.”
The more data we collect, share and process, the greater the chance that some of it is exposed somewhere. That does not make data leaks normal or acceptable. It does mean we have to learn to live in a world where personal data may already be known to others.
We therefore must not only try to prevent data leaks.
We also have to become datalekfit.
Your data may have been leaked. Your ability to act does not have to be.
That your data may be known is not something you can undo. How you respond to it is something you can influence.
This frame of thinking is what we call assume exposure here: reckon with the possibility that information about you is already available to criminals.
That someone knows your address, date of birth, phone number or customer number does not prove that person is trustworthy.
That information may come from an earlier data leak.
Personal data is therefore less and less suitable as proof that someone really is who they say they are.
Do you feel haste, pressure or fear? Then stop. Trust your gut feeling.
Break off the contact and get in touch again yourself, using a phone number, app or website that you look up yourself.
Do not let someone else decide through which channel you should verify.
Do you have doubts, or did something go wrong? Share it.
Shame can make people wait before asking questions or reporting something. Discussing and reporting early gives you and others more room to act.
In cybersecurity, organisations have worked for years with the principle assume breach: assume that an attacker may already be inside and design your security around that.
Especially within customer service, helpdesk, identification and verification processes, a different starting point also applies:
assume exposure.
Assume that certain details about your customers may already have been exposed.
Name, address, date of birth, email address, phone number or customer number are therefore less and less suitable for establishing that someone really is the customer.
The question then becomes not only:
“How do we protect personal data?”
but also:
“How do we act safely when personal data may already be known to people with bad intent?”
Would you like to put this topic on the agenda within your organisation or at an event?
Keynote · 45 to 90 min
Awareness month, annual conference, customer service and service desk teams or board meeting
What happens when data breaches become so common that people stop acting? On normalisation, resignation and four reflexes that work even when your data is already out there. For organisations, including assume exposure in identification and verification processes.
Less resignation, more capacity to act and safer verification when data is already known to criminals.
Part of Cyberschaamte.nl · Last updated: