Chapter 3

Digital security for the family

3. Protecting your family’s online data

If the previous chapter was about the "keys" to our home, this chapter is about the walls and windows. In the digital world, our family’s data—our photos, our location, our children’s identities, and our private habits—is the most valuable asset we own. In 2026, we are no longer just fighting against "viruses"; we are navigating a landscape where information is a currency. Every time we click "Accept" on a website's cookie banner, a terms-of-service update, or an app permission pop-up or share a family moment, we are making a choice about how much of our private world we want to expose to the outside. Also casually clicking through unexpected pages or intrusive pop-ups just to make them disappear is a major privacy and security slip. In many cases, these notices concern cookies and other tracking technologies that can collect information about how your family uses websites and online services. While some cookies are necessary for websites to function properly, others may be used for analytics, advertising, or behavioural profiling. Understanding how these technologies work and how to manage them is an important part of protecting your family’s digital privacy.

Protecting your family’s online data is not about hiding from the internet; it is about controlled transparency. At its core, privacy is no longer just about keeping secrets; it is about establishing digital boundaries and exercising your fundamental right to govern your own identity. To protect this right from being corporate property, modern legal frameworks like the General Data Protection Regulation (GDPR) were established as a powerful digital armour for citizens. The GDPR fundamentally changes the rules of the game by legally declaring that your data belongs entirely to you, forcing companies to grant you transparency and the explicit right to view, limit, or completely erase your personal information from their databases. In the modern digital and marketing ecosystem, "controlled transparency" means having the ultimate agency over what, when, and how your information is communicated. By actively exercising these GDPR privacy rights, you maintain the authority to decide exactly what third-party platforms can harvest from your household. However, big tech frequently challenges this through tactical "forced consent"—such as when platforms like Instagram or other major social networks block your access completely unless you click "Accept" to their extensive tracking terms. Navigating this reality requires us to be the "Digital Guardians" of our children’s privacy. As we move forward, we must stay informed about new protective technologies and regulations designed to keep families safe. By shifting our perspective from seeing data as "abstract information" to seeing it as our family’s "digital DNA," we can ensure that our online presence remains a source of joy rather than a source of risk.

3.1 Personal Data: What it is, How it is Collected and Why it Matters

Think of personal data as your family’s Digital DNA: fragments of information that, when combined, create a detailed map of your family’s daily life. It includes for example legal name, phone number, birthdate, home addresses, parents’ names, and also, a child’s school schedule, shopping preferences, location history, photos and device identifiers — and it can be gathered not only in large breaches but quietly by apps, websites, smart toys and social platforms used every day by families.
One of the most common ways personal data is collected today is through website cookies. When visiting a website, one of the first things families often see is a cookie banner asking them to "Accept All", "Reject All", or "Manage Preferences". Although many people click the quickest option simply to access the page, these choices can have important privacy implications. Cookies are small text files stored on a device that allow websites to remember actions, preferences, and information about a user's visit. Some cookies are strictly necessary for a website to function correctly, such as remembering language preferences, keeping a user logged in, or storing items in an online shopping cart. Other cookies may be used for analytics, advertising, personalisation, or behavioural profiling, allowing companies to better understand browsing habits and online interests. For this reason, families should develop the habit of reviewing cookie choices before proceeding. Whenever possible, select "Manage Preferences", "Customize", or "Learn More" and enable only the cookies that are necessary for the service being used (if required since generally are already activated by default). So if you are not interested in any optional cookie, better simply deny them all. For example, if you are visiting an online newspaper, checking school information, or browsing a public website, you can often access the content while declining many optional tracking features. In these situations, the website generally only needs the cookies required to display the page correctly and remember basic settings, such as your language preferences. Advertising, marketing, and profiling cookies are often not essential for the service itself and can frequently be declined without affecting the core functionality of the site. However, families will sometimes encounter websites or platforms that make this choice more difficult. Some services limit certain features, repeatedly ask for consent, or even block access unless tracking cookies are accepted. This practice is often referred to as "forced consent" because users are pressured into sharing more data than they might otherwise choose. When this happens, it is important to understand that accepting cookies is not a security requirement but a privacy choice. If the service is essential—such as a school platform, government portal, banking service, or other trusted resource—you may decide to proceed while limiting data sharing wherever possible through the available privacy settings. If the service is not essential, consider whether the convenience offered is worth the additional collection of personal information. In fact, most parents mistakenly believe personal data is limited to sensitive records like credit card numbers, but the digital ecosystem silently harvests invisible elements like tracking cookies that shadow your family's browsing habits across different websites to build behavioural profiles, your device's unique IP address and metadata—the hidden tracking information embedded inside every smartphone photo that reveals the exact GPS coordinates and time the picture was taken.

This data is valuable because of its predictive power. Social media platforms like Instagram, TikTok, and YouTube have turned this into a hyper-sophisticated science by tracking "dwell time", the exact millisecond a child pauses while scrolling through their feed because a specific post or video catches their eye or sparks their curiosity. The algorithm interprets this brief, silent hesitation as an unspoken sign of interest, using it to construct psychological profiles that exploit emotional vulnerabilities and trap young users in addictive feedback loops.

While social networks leverage this data for engagement, a child's digital footprint can also attract far more dangerous actors. For a criminal, knowing a child’s birthdate and middle name can be the first step toward identity theft. The primary reason perpetrators target minors, is because children represent a financial "clean slate" in fact they have entirely pristine records that are completely unmonitored by parents, banks, or credit bureaus precisely because as minors they cannot open bank accounts. To exploit this, criminals use a highly strategic method known as "Synthetic Identity Theft”: they take the child's legitimate core identifiers—such as their birthdate and government identification numbers—and blend them with a completely fabricated name or a different address to create a hybrid, "ghost" identity, automatically forcing the system to generate a brand-new credit file under that hybrid persona at the criminal's first fraudulent application. The criminal then carefully nurtures this fake profile over several years creating an unmonitored baseline of fraudulent activity that often can go undetected for over a decade.

Moreover, for a scammer, knowing that you just booked a flight or your regular habits is the perfect “hook” for a fraudulent message. When a phishing text arrives pretending to be a courier or an airline support agent at the exact moment the family is actually expecting that specific service, it is no longer a random coincidence, but a highly calculated manipulation designed to lower a parent's guard. Crucially, these highly targeted messages rarely require your personal account to be compromised; cybercriminals frequently exploit vulnerabilities or steal credentials directly within major third-party platforms, like Booking.com. This allows them to do far more than just harvest your reservation details; they can actually hijack the official communication channel and chat with you directly inside the platform's legitimate interface, making the fraudulent message appear entirely authentic because it comes from the hotel's verified account. If an urgent notification inside your app demands immediate credit card verification for an upcoming stay, parents should never click the provided links. The safest defence is to step completely away from the interface and independently call the hotel directly or contact the platform’s verified, official support line to confirm the request. For companies, the same information allows targeted advertising, behavioural profiling and personalised offers that can follow a child as they grow. This continuous tracking feeds a multi-billion-dollar shadow economy run by data brokers, who buy and aggregate data from free mobile games, school platforms, and online quizzes to build extensive digital dossiers on entire households. Your data is the currency that pays for many “free” services — but the cost of giving too much away can be high. When an app costs nothing to download, your children are not the customers; they are the product, and these digital choices can follow them well into adulthood. Recognising that your family’s information is a high‑value asset is the first step toward building a safer digital environment.

💡 Why is it important to understand data value?

Informed consent is the practical core of data value: when an app or website is “free,” you are usually paying with data. True consent means understanding what is collected, why it is needed, who will see it, how long it will be stored, and whether it is shared with third parties. With that awareness, parents can choose to share only the minimal data necessary and refuse requests that are not justified by the service.

Signs that you are managing your data value correctly?

  • choosing the “minimal data” option (provide an email instead of a phone number when possible)
  • routinely checking app permissions (camera, microphone, location, contacts) and removing anything unnecessary
  • hesitating before filling forms or surveys that ask for more information than seems relevant
  • treating your financial details as high-value data during online shopping by using temporary virtual cards, refusing to save payment information permanently inside retail databases, and shielding your purchase history
  • teaching children not to post location, school, or full birthdates in public places.
  • resisting the urge to blindly click "Accept All" on website banners, taking a brief moment to choose "Manage Preferences" or "Reject All" to block unnecessary tracking and marketing cookies

When assessing an app, check both the store’s privacy label and the developer’s reputation and reviews; store labels are helpful but not always complete.

👨‍👩‍👧 Example from everyday life

The Smith family wanted to download a simple "Flashlight" app on their son's tablet. The app requested access to their contacts, location, and microphone. Instead of clicking "Allow," they realized that a flashlight doesn't need to know who their friends are or where they live. They recognized the app was just a "data harvester" and chose a different one that requested zero permissions. They protected their data value by simply saying "No" to an unnecessary request.

However, the Smiths also encountered a much harder challenge when setting up their daughter’s mandatory school communication platform and her social media accounts. In those cases, there was no alternative app to choose; they faced a strict take-it-or-leave-it wall where clicking "Accept" to aggressive data terms was the only way to access the service. Instead of feeling completely powerless under this forced consent, the family applied the principle of controlled transparency. Since they couldn't say "No" to the initial download, they immediately went into the app’s internal privacy settings after installation, manually turning off precise location tracking, revoking ad-personalization permissions, and using a dedicated, secondary email address —a separate account kept isolated from important matters like online banking, work, or official communications, and/or used only for casual app registrations and online profiles—­ to isolate their household's primary digital identity.

📝 Activity: The "Invisible Audit"

Take 5 minutes to look at the "Free" apps on your phone. Pick one and look it up in the App Store or Play Store under "Data Privacy." Notice how much data it collects (Location, Contacts, Browsing History).

Ask yourself: "Is the service this app provides worth the amount of data I am giving it?"

If the answer is no, delete the app. This is the simplest way to immediately increase your family’s digital security

Attention: Your Child’s "Data Cleanliness"

Children are prime targets for identity theft because their credit records are clean and often unmonitored for years. Avoid publishing full birthdates or national ID numbers online when not strictly required for an official process. Where local law allows, consider placing protections (fraud alerts or credit freezes) on a child’s record and keep their personal identifiers as private as you would keep a physical valuable.

3.2 Phishing and Social Engineering: how hackers "trick" families

In the world of cybersecurity, the weakest link is rarely the software; it is the human element.

Both phishing and social engineering are techniques that rely on tricking people rather than breaking into systems.

Social engineering is the art of manipulating people into giving confidential information. While a hacker might spend weeks trying to break a password, a social engineer can achieve the same result in seconds – it can happen on the phone, in person, or inside games or social media apps – by simply asking the right question and the right time and creating a sense of urgency so that you act without thinking. This often takes the form of Phishing: fraudulent emails, text messages (Smishing), or phone calls (Vishing) designed to look real and from a trusted source – such as your bank, your child’s school or even a popular site like Netflix or Amazon. This constant financial targeting is exactly why modern families must change how they pay online. When scammers trick you into entering card details on a fake website, a traditional credit card leaves your entire bank account exposed. This is where secure tools like PayPal, prepaid cards, and virtual cards act as a financial shield. PayPal acts as a trusted middleman, ensuring the merchant—and any hacker watching them—never sees your actual bank details. For direct purchases, virtual cards generated inside your banking app offer the ultimate protection: they create a temporary, digital-only card number for a specific amount or a single transaction. Once used, that number expires automatically. This means that even if a highly sophisticated phishing attack manages to lower your guard and trick you into typing those card details, the cybercriminal walks away with a dead, useless number, completely neutralizing the financial trap before it can hurt your family. However, even if your financial shields successfully block the threat and prevent money from being stolen, it is absolutely vital never to let these attempts slide. Families must always report the incident to their bank, block the credit cart and file a formal report with local cybercrime authorities and block whoever contacted you; sharing these digital footprints is the only way law enforcement can track down scammers, shut down malicious servers, and protect the wider community.

In 2026, these attacks have become incredibly sophisticated. Scammers no longer rely on poorly written emails with obvious spelling mistakes; using advanced generative AI tools, cybercriminals can now instantly generate flawless highly persuasive messages and they often use familiar logos, names or specific language to appear trustworthy while the sender is pretending to be someone else.

They use the personal data we discussed to create "spear-phishing" attacks—highly targeted messages that include your real name, your recent purchases, or mentions of events happening in your local community.

For a parent, the danger is doubled: you aren't just protecting your own data, but also teaching your children not to fall for the digital "stranger danger" that often arrives disguised as a friendly notification or a gift card offer.

💡 Why is it important to recognize manipulation?

The primary reason is "Emotional Defence." Phishing and social engineering works by triggering an emotional response—usually curiosity or fear (e.g., "Your account will be deleted!") or greed (e.g., "You’ve won a €500 voucher!").

For families this is especially risky because:

  • children often respond to messages from “friends” or gifts in games
  • parents may act quickly when a message appears to come from a school, bank or the family calendar

By understanding these psychological triggers, and realizing that a threat that begins on the internet can crawl directly into your physical reality where scammers pick up enough digital crumbs to map your daily routine, meaning a virtual compromise can escalate until you literally find the threat right outside your house or at your very doorstep, you can train your brain to pause when a message feels too urgent or too good to be true. This "digital intuition" is your family’s best shield against scams that no antivirus can stop.

Signs of a Phishing attempt

You can spot a "trick" by looking for a few red flags: an unusual sender address (e.g., support@net-flix.security.com or even a completely generic public domain not associated with the platform like netflix@gmail.com instead of netflix.com), a generic greeting like "Dear Customer," or a link that doesn't match the destination when you hover over it. Most importantly, any message that asks you to "verify" your password or provide a one-time code via a link is almost certainly a scam. Legitimate companies will never ask for your credentials in this way.

👨‍👩‍👧 Example from everyday life

A parent receives a text that looks like it’s from the school: “Immediate: view your child’s report here [link].” The message looks urgent and uses the school’s logo. Instead of clicking, the parent opens the school’s official website directly (not the link), finds no such notice, and calls the school office to confirm. The school confirms it didn’t send any message.

📝 Activity: The "Spot the Fake" Game

Next time you receive a marketing email or a notification from a service you use, sit down with your children and play detective.

  1. Look at the sender's email address. Is it completely accurate?
  2. If there is a link do not click on it, do the same for email attachments.
  3. Check the tone. Is it trying to make you feel panicked or rushed?

Teaching your kids to be "sceptical by default" is the most valuable digital life skill you can give them.

Attention: The "Go to the Source" Rule

If you receive an alarming message from a bank, a school, or a government agency, never use the links or phone numbers provided in that message. Always open a new browser tab and go directly to the official website you know, or use the official app. If the problem is real, you will see a notification there. If it’s not, you’ve just avoided a trap.

3.3 Public Wi-Fi risks and the use of VPNs

When we are away from home—at a cafe, an airport, or a hotel—we often look for a public Wi-Fi network and we reach for our phones as soon as we see that familiar symbol appears: “Available Wi‑Fi networks” because the promise of a free connection is hard to resist. For parents, it can feel like a small relief: let the children watch a video, play a game, or check homework without using up mobile data. However, from a security perspective, a public Wi-Fi network is like a room with glass walls: anyone with the right tools can potentially see what you are doing. Public Wi-Fi is an open ecosystem where the rules of trust break down entirely and understanding the specific attack vectors that flourish on these networks is the first and most essential step toward meaningful protection. When you connect to a public Wi‑Fi network, your device joins a shared space with everyone else in that location. If the network is not properly secured, it becomes easier for someone else on the same network to see what you are doing online. In 2026, hackers use "Man-in-the-Middle" (MitM) attacks which is arguably the most dangerous and pervasive threat on public Wi-Fi networks. The concept is deceptively simple: an attacker positions themselves — technically speaking — between your device and the network's access point to intercept the data flowing between your device and the router and very packet of data you send or receive passes through the attacker's system first.

Without encryption they can capture login credentials, private messages, or credit card info, often by setting up a fake network with a name like "Free_Airport_WiFi" that looks legitimate but is actually a trap. These are often called “evil twin” hotspots, and they can be used to capture your login details, redirect you to fake websites, or distribute malware onto your device. In some cases, attackers use these fake networks to distribute spyware or a specific kind of keylogger called DarkHotel that reports keystrokes to the hackers who particularly target unsecured Wi-Fi at hotels. Once downloaded this this of spyware track every keystroke entered and save the data in a file so that malicious users can identify and exploit your personal information such as credit card information, log in credentials from all the personal platforms or even the company’s network in order to steal confidential information. After a certain number of recorded keystrokes, DarkHotel deletes itself from the device to avoid detection. The best protection against keylogging, or any other type of attack, is education about how the attacks occur: it is fundamental to check that emails and websites are from a legitimate source and to never user public Wi-Fi for any activity involving sensitive personal, financial, or confidential information.

Recent reports from consumer‑security organizations and financial institutions explain that a large share of people still use public Wi‑Fi for sensitive tasks such as online banking, shopping, or account logins, even though these networks are often unencrypted and easy to spy on. Studies show that Wi‑Fi is one of the most frequent attack surfaces for data theft, especially when people reuse passwords or do not check whether a website uses a secure HTTPS connection. In a family context, this is particularly risky because children tend to use devices in public places, and their accounts are sometimes less protected than adults’: a game profile, a school portal, or a social media account can become a doorway for someone who wants to steal information or gain access to more. Public Wi‑Fi networks are not all the same: some are genuinely secure and managed by the venue, while others are open, unencrypted, or even fake.

To protect your family’s privacy in these situations, there are two main defences. The first is to avoid sensitive tasks (like banking) on public networks. The second, and more modern solution, is using a VPN (Virtual Private Network). For everyday users, a VPN is simply a software application that you download and install directly onto your smartphone, tablet, or laptop from an official app store or a trusted provider's website. Once installed and activated, it offers a simple way to reduce some of these risks by establishing a secure tunnel between your device and internet so that even if someone intercepts your connection, all they will see is scrambled, unreadable code. When you turn on a VPN, your data travels through an encrypted channel to a server operated by the VPN provider, and then to the internet; this makes it much harder for someone in the same café or hotel to see which sites you visit or what information.

Modern VPN services are designed to be easy to use, often with a single button you can turn it on your phone or tablet. They are especially useful when travelling, studying in a library, or using Wi‑Fi in a hotel or train, where you cannot be sure about the network’s security. However, a VPN is not a magic button that makes everything safe. It cannot protect you from phishing, social engineering, or from clicking on suspicious links. It also cannot compensate for an outdated device or software: if your phone or apps or computer software is not updated, you are still exposed to other vulnerabilities, even if the connection is encrypted. In practice, a VPN should be used as one layer of protection, alongside habits like using strong, unique passwords, avoiding sensitive logins on public Wi‑Fi, and checking that the networks you use are truly official. Furthermore, it is vital to know how to react in real-time: if you ever suspect that your connection has been compromised or that you are actively under attack—which usually manifests as sudden slowdown of your device, unexpected security warnings, or strange page redirects—your very first reflex must be to immediately disconnect from the Wi-Fi network or switch off your device's wireless connection entirely, instantly cutting off the hacker's visibility.

Nowadays, a VPN is no longer just a tool for tech experts; it is a fundamental travel essential for any family that wants to stay connected safely while on the move.

💡 Why is it important to understand public Wi‑Fi and VPNs?

Understanding public Wi‑Fi and VPNs helps families move from “I connected to the Wi‑Fi here without thinking” to “I know when it is risky and when it is safer.”

One of the most important reasons to understand the usage of VPNs and public Wi-Fi is "Anonymity and Integrity." A VPN hides your IP address and encrypts your traffic, making it nearly impossible for hackers or even the Wi-Fi provider to track your online behaviour. For a family, this means you can check your emails or browse the web at a train station with the same level of security you have in your own living room.

Signs that you are using Wi-Fi safely

You are practicing good digital hygiene if your devices are set to "Ask to Join Networks" rather than connecting automatically. You know you are protected when your VPN app shows a "Connected" status with a lock icon before you open your browser. Most importantly, you recognize that "Free" Wi-Fi often comes with a hidden privacy cost and you choose to use your mobile data hotspot for sensitive transactions instead.

Note: Since a modern household uses a mix of different devices, you actively check these steps across your family's ecosystem: toggling "Ask to Join Networks" under the Wi-Fi settings on iOS, disabling "Connect to public networks automatically" within Android’s network preferences, and ensuring the "Connect automatically" box is completely unchecked on Windows and macOS laptops for any unfamiliar hotspot.

👨‍👩‍👧 Example from everyday life

During a family holiday, Marco needed to check the balance on his travel card while waiting at a crowded bus station. Instead of joining the "City_Guest_WiFi," which required no password and felt suspicious, he turned on the family VPN on his phone first. This ensured that his bank login details were wrapped in encryption, protecting his money from anyone else lurking on that same public connection.

📝 Activity: The "Hotspot Check"

Open the Wi-Fi settings on your phone right now while you are in a public place. Count how many "Open" networks (those without a padlock icon) you can see. Remind your children that an open network is like a public conversation—anyone can listen in. Practice turning on your VPN or using your "Mobile Hotspot" as a safer alternative together.

Before turning that hotspot on, take a moment to open its settings together and check the password. It is important to know that when your hotspot is turned off, it is completely invisible and safe from outside attacks. Even when active, cracking its password does not grant a hacker access to your phone’s internal photos, chats, or personal data. However, leaving the default factory password active creates an easy entry point for automated guessing tools. Once inside your hotspot, a stranger can quickly drain your monthly cellular data or, more dangerously, intercept the internet traffic of your children's tablets and laptops connected to that same network. Taking thirty seconds to change the default key to a unique, custom password completely neutralizes this boundary risk before you share your connection.

Attention: Forget the Network

Once you leave a public place, tell your device to "Forget this Network." You can find this option right inside your Wi-Fi settings: on an iPhone or iPad, tap the small "i" icon next to the network name to see the command; on Android devices, tap the gear icon or long-press the connection name to select "Forget" or "Remove"; and on Windows or Mac laptops, open your known networks list within the network settings to clear it. This prevents your phone from automatically reconnecting to that same Wi-Fi (or a fake one with the same name) the next time you are nearby, closing a potential "backdoor" into your device.

3.4 Privacy on the Internet, in the Cloud and on Connected Home Devices

Our digital lives are no longer confined to a single computer screen; they flow seamlessly between the websites we browse, the cloud servers storing our digital data, documents and memories, which serve as remote, internet-based storage networks that hold data on external servers removing the bind of a particular physical device, and the smart objects populating our homes.

The term "cloud" may sound technical, and for many families, cloud services operate almost invisibly in the background of daily life. Photos, videos, contacts, documents, and even device settings are often synchronised automatically across multiple devices linked to the same Google, Apple, Microsoft, or similar online account, meaning information can be stored on remote servers without requiring any active action from the user. This is why many people only become aware they are using cloud storage when they receive a notification that their available space is running low or when a new device instantly displays years of photos and files from a previous one. In many cases, cloud storage is not something families actively choose to use every day; it is simply enabled during the setup of a device and continues operating automatically in the background. Every time a family saves photos to an online backup service, synchronises files between devices, or stores documents in a cloud account, copies of that information are managed on external systems that can often be accessed from multiple locations and devices. While this provides convenience and protection against data loss, it also means that personal information is no longer stored exclusively within the home.

Nowadays, protecting your family means managing an interconnected ecosystem where internet privacy, cloud storage, and home devices constantly overlap: every website we visit, every application on our smartphone, and every smart object in our homes represents a potential data pipeline to the outside world, creating a continuous trail of tracking cookies, browser histories, and online account profiles. This boundary becomes especially critical when we look at cloud storage and modern photo applications. Most families use automated cloud backups, which simply means your device automatically saves a copy of your photos to the internet, to ensure they never lose precious family memories if the phone breaks or gets lost; however, cloud storage is often misunderstood because many people assume that their photos and files exist only on the device where they were created. In reality, cloud platforms continuously synchronise information across servers, smartphones, tablets, and computers linked to the same account. As a result, deleting a file from one device does not always guarantee that it has been removed from backups, shared folders, archived copies, or other synchronised locations. Families should therefore periodically review their cloud accounts, check which devices are connected, verify who has access to shared albums or folders, and remove information that is no longer needed. These controls can usually be found in the account, privacy, or storage settings associated with the cloud service being used. In any case, you can always choose to disconnect entirely or manage them with extreme granularity, as modern platforms like OneDrive, iCloud, Google Drive, and Dropbox offer precise configuration options. If you want to completely sever the link between your local device and the cloud, you can choose to un-link or log out of the account. This action immediately stops the machine from actively communicating with remote servers without deleting any of the files already stored in the cloud. From a security standpoint, this ensures that if a physical device is ever lost, stolen, or compromised, it cannot be used as an open backdoor to access the family's entire historical archive.

Furthermore, families are not forced to save every single file to the cloud and can utilize selective synchronization or files-on-demand features. Through selective synchronization, parents can adjust cloud preferences to only sync specific folders, such as a work directory, while leaving large personal folders exclusively on the website server to save local storage space. By right-clicking any file or folder, users can explicitly dictate its behaviour: choosing an option like 'always keep on this device' ensures the file is saved both locally and online with automatic updates active, represented by a green checkmark icon, while choosing 'free up space' removes the local copy entirely, turning it into a cloud icon that downloads instantly only when double-clicked.

Finally, it is entirely possible to leave the cloud service active and vigilant to access shared files without allowing it to automatically hoard personal documents. By default, operating systems often automatically clone local system folders like Desktop, Documents, and Pictures directly into the cloud. To block this intrusive behaviour in OneDrive, parents can open the backup settings, select manage backup, and turn off the toggles for these primary folders, which forces the software to only sync files that are manually dragged into the specific OneDrive folder. For Mac users, a similar boundary is established by navigating to iCloud Drive settings and disabling the automatic backup option for the Desktop and Documents folders, ensuring the family remains in absolute control of what leaves the physical machine. Strategically dividing data—using the cloud strictly for non-sensitive material like school assignments, while keeping intimate family photographs, work projects and financial records strictly on local, encrypted hard drives—drastically shrinks the family's digital attack surface, guaranteeing that a single cloud server breach cannot compromise their entire private life.

In recent years, this cloud-based privacy risk has expanded into a highly delicate frontier: the widespread adoption of generative Artificial Intelligence tools and chatbots. When family members interact with these AI systems—whether a teenager is pasting a school essay for feedback, a parent is uploading a financial document for analysis, or a child is sharing personal stories with an AI companion—they are often unknowingly triggering severe data leakage. It is crucial for parents to understand that these platforms do not operate as closed, private diaries. In standard free AI models, every prompt typed, document uploaded, or image shared is processed and stored on external servers to be utilized as raw material for training future algorithmic models. Furthermore, these conversations are routinely subjected to human review, meaning that real human engineers and third-party contractors read through dialogue transcripts to evaluate performance, completely stripping away the anonymity of the interaction. While paid subscription tiers or enterprise models sometimes offer advanced privacy toggles that allow users to opt-out of data training, free AI models inherently monetize user inputs. This structural architecture means that sensitive family anecdotes, proprietary work data, or identifiable details about a child's life are vulnerable to data exfiltration via server breaches, or worse, can be accidentally regurgitated to other users globally through algorithmic errors.

While incredibly convenient, this creates an immense privacy risk because modern digital photos contain hidden metadata—including the exact date, time, and geographic coordinates of where the picture was taken. Additionally, tech companies use advanced facial recognition algorithms on these cloud servers to scan, categorize, and profile your children's faces as they grow. Because cloud accounts often contain years of family photographs, personal documents, contact information, school records, and location histories, they have become one of the most attractive targets for cybercriminals. Protecting a cloud account should therefore be considered just as important as protecting online banking or email accounts. If a family cloud account uses a weak password or lacks two-factor authentication, a hacker doesn't just gain access to a random file; they gain a chronological, geotagged visual diary of your family’s entire life, school locations, and daily routines.

Yet, this invisible data trail does not remain confined to remote internet servers; it actively crosses our thresholds and takes physical shape right inside our domestic sanctuary.

Our homes are populated with “smart” objects: Smart TVs, voice-controlled assistants, security cameras, and even connected appliances. Most of us enjoy the convenience of these devices in our homes, but we rarely stop to think about what they are “listening” to or “seeing.”

In 2026, the "Smart Home" is not just a technological home, but an ecosystem that requires active privacy management to prevent private conversations or children's habits from becoming a commodity. Many of these devices are connected to the internet, can record sound, track viewing habits, or store information about what we say and how we use them. In fact, modern smart devices often gather data to improve voice recognition, offer recommendations, or personalise content, but the same features can also expose private conversations, search habits, or even the times when the family is at home or away.

Official European cybersecurity assessments reveal that many smart entertainment devices lack robust security, often relying on weak authentication models like basic 4-digit PINs that are easily compromised. Furthermore, manufacturers frequently discontinue critical software and firmware updates after just 3 to 5 years, leaving older but fully functional home devices permanently exposed as the weakest link in the family network. A major factor highlighted by European research is that the primary smart device business model has increasingly shifted toward generating new revenue streams through data monetization rather than focusing on user privacy. This environment creates a multi-layered ecosystem of third-party data controllers—including equipment manufacturers, OS developers, and application platform providers—all collecting and potentially exchanging percentages of revenue based on your family's personal data.

When this technological infrastructure enters the children's bedrooms through Baby Monitors and Smart Toys (connected dolls, interactive games, or robotic stencils), the structural vulnerabilities become acute. European safety audits and case studies highlighted by cybersecurity agencies reveal that many mass-market smart toys utilize unencrypted Bluetooth or Wi-Fi local connections. This design flaw allows remote third parties within physical proximity to intercept audio streams or establish direct communication with the child without any prior authentication challenge. Furthermore, the back-end cloud databases where children's voice recordings and profile data are processed frequently suffer from inadequate structural protection, presenting clear vectors for data exfiltration that violate baseline GDPR (General Data Protection Regulation) mandates.

In the European context, this is not just a matter of convenience: under the GDPR, this information can count as personal data, so manufacturers and service providers are expected to follow principles such as data minimisation, transparency, and privacy by design and by default. To explain it simply, data minimisation means that companies are legally forbidden from hoarding your information; they are required to collect only the absolute minimum amount of data necessary to make their specific service work, and nothing more. If a smart toy needs an internet connection just to download updates, it has no legal right to collect your child's voice recordings or location history.

Far from being just a dry set of rules, the GDPR establishes strict guardrails that grant families powerful, actionable rights. It allows you, as a parent, to demand full access to any tech company or toy manufacturer's database to see exactly what information they have gathered about your children. It gives you the "right to be forgotten," meaning you can legally force these companies to permanently delete your family's stored voice snippets, profile data, or behavioural history from their servers. Finally, it gives you the right to object to data processing, allowing you to legally shut down their ability to track your lifestyle habits or trade percentages of revenue based on your family's personal life, giving you total ownership over your domestic privacy.

Security researchers and investigative reports have demonstrated that several mass‑market smart home devices, including smart fridges, can reveal detailed patterns of behaviour, such as when a household is likely to be empty, simply by analysing appliance usage data. In controlled tests, attacks on poorly secured smart‑home devices have shown how information from a connected fridge or similar appliance can be used to infer when a family is away, information that could be attractive to a burglar or malicious actor: for example, a smart speaker might store snippets of normal conversation; a connected TV might log what you watch and when you watch it; a smart fridge or other smart‑appliance might reveal when you leave the house or during which hours the kitchen is used.

For families, this means that privacy settings on home devices are not just about turning off a microphone but about understanding what each device is allowed to do. Smart TVs often ask for permission to collect viewing habits, voice assistants collect audio to improve recognition, and smart‑home hubs store lists of connected devices and schedules. If these permissions are not reviewed, everything from children’s bedtime routines to parents’ work calls can become part of a detailed profile of your family life. In practical terms, this is exactly where European privacy rules matter: if a device asks for more data than it needs, or keeps data longer than necessary, that may conflict with GDPR principles even if the device still “works” normally.

📘 Step-by-Step: How to Unlink Your Devices from the Cloud

  • Windows Users (OneDrive): Open your OneDrive settings, navigate to the Account tab, and select the option to Unlink this PC.
  • Mac and iPhone Users (iCloud): Access your System Settings, click on your Apple ID name at the very top, and choose Sign Out.
  • Google Drive Users (Desktop): Open the application's internal Preferences menu (usually found via the gear icon) and select Disconnect account

💡 Why is it important to audit your privacy settings?

The primary reason is "Passive Data Collection” as modern applications and smart device collects data passively and silently. As highlighted by European Union impact studies, users generally accept default privacy settings, unknowingly allowing third-party services to track and profile their daily viewership and family habits. Because modern smart devices are equipped with specialized sensors like integrated microphones and facial-recognition cameras to facilitate voice and gesture controls, they actively capture, filter, and store surrounding audio and images right inside the domestic environment. Limiting these settings across your internet browsers, cloud photo apps, and home devices drastically reduces your family's "attack surface: the less data that leaves your home and enters the cloud, the less information is available for hackers or data brokers to build detailed profiles on your children or your daily routines.

👨‍👩‍👧 Example from everyday life

A family just bought a brand-new Smart TV for their living room. Instead of simply plugging it in and jumping straight to their favourite shows, they decide to spend ten minutes reviewing the privacy settings during the initial setup. They discovered that the TV was pre-configured to automatically record and share their viewing habits with third-party advertisers. Together they turned off the "Automatic Content Recognition" feature and disabled the integrated voice control microphone when not actively in use.

By taking these quick steps, your family’s private weekend conversations and late-night movie choices remain strictly confidential, safely shielded from automated tracking and commercial profiling.

📝 Activity: The "Device Mute" Walk

Walk around the house with your children and identify every device that has a microphone or a camera.

  1. Check if there is a light or signal indicating when they are active.
  2. Go into the settings of each device and look for "Privacy" or "Shared Data".
  3. Turn off the "Improve service by sending usage statistics" feature.

This exercise teaches children that we have the power to decide what our objects can "say" about us to the outside world.

Attention: Physical covers and hardware switches

For cameras integrated into laptops, Smart TVs, or baby monitors, do not rely on software alone. A simple physical cover (a sliding webcam cover or even a small piece of dark tape) is the only way to be 100% sure no one is watching. For connected toys, look for physical hardware switches that completely disconnect the internal battery or cut the power supply to the microphone module when the toy is not in active use.

3.5 Recognizing secure websites (HTTPS vs. HTTP)

Every day, we browse dozens of websites to read news, check school updates, play online games, or make purchases without thinking too much about how the connection works. However, the infrastructure connecting a home device to a web server can vary significantly in its level of security. What matters is that not every website protects data in the same way, and the address bar gives us an important clue: understanding the technical distinction between HTTP (Hypertext Transfer Protocol) and HTTPS (Hypertext Transfer Protocol Secure) is the first step in establishing a baseline for safe data transmission, preventing sensitive information from being exposed in transit.

A website that starts with HTTP does not encrypt the connection, which means information can be easier to intercept or modify while it is moving across the internet. When a browser connects to a legacy HTTP website, the data is exchanged in "plain text." This means that any entity positioned along the network pathway—such as an attacker on a public Wi-Fi router, an internet service provider, or an intermediate data controller—can view, intercept, or even modify the content of the transmission. In the context of European data privacy legislation, utilizing unencrypted HTTP connections for pages that handle authentication credentials, credit card details, or personal identifiers constitutes a major structural vulnerability that fails to meet basic standards for secure data processing.

On the other hand, a website that uses HTTPS does encrypt the connection between the browser and the website, making it harder for others on the network to read what is being sent. HTTPS implements a cryptographic layer known as Transport Layer Security (TLS). This protocol ensures that all communication between the user's browser and the web server is thoroughly encrypted.

However, a critical distinction must be made: encryption does not automatically equal honesty. This is where many people misunderstand the meaning of the padlock icon. The padlock means that the connection is encrypted, but it does not prove that the website itself is genuine, trustworthy, or safe in every sense. A fake shop, a phishing page, or a scam website can still use HTTPS if the attacker has set up a secure connection for their own fraudulent site. In other words, HTTPS protects the path between the user and the site, but it does not automatically guarantee that the site behind it is honest, well managed, or respectful of your data. It also does not stop the website from collecting information that the user willingly enters, such as names, email addresses, or payment details. In 2026, cybercriminals can easily obtain legitimate HTTPS certificates for fraudulent or phishing websites within seconds. Therefore, while HTTPS guarantees that the data layer between the device and the server is encrypted and protected against local eavesdroppers, it does not verify whether the destination company itself is trustworthy or malicious. For that reason, families need to look beyond the padlock. A site that asks for passwords, payment information, or school-related data should use HTTPS, but the presence of HTTPS alone should never be treated as a final sign of safety. It is still important to check the full web address, the spelling of the domain name, and whether the page looks consistent with the service it claims to be. If a browser warning appears, or if the site address looks slightly different from the official one, that is a reason to stop and verify before continuing. This distinction is especially important in a European context, where secure communication is encouraged, but where data protection also depends on transparency, lawful processing, and responsible handling of personal information by the service itself.

💡 Why is it important to check the protocol?

The primary technical reason is "Data Confidentiality and Server Authentication." Encryption transforms legible data into scrambled code, ensuring that even if a cybercriminal intercepts the transmission, the information remains mathematically unreadable. Furthermore, modern HTTPS implementation includes a validation mechanism: it verifies that the website actually belongs to the organization it claims to represent. For families, this prevents basic "spoofing" attacks, where a malicious actor replicates the visual appearance of a legitimate school portal or bank login page to harvest credentials.

Signs of a secure browsing connection

A secure connection is visually indicated in modern browsers by a padlock icon located to the left of the website address (URL). Clicking this icon allows users to inspect the digital certificate, verifying the identity of the domain owner and the issuing Certificate Authority. A safe browsing habit also involves checking that the URL explicitly begins with https:// rather than http://. Crucially, safe browsing requires looking past the padlock icon to verify the exact spelling of the domain name (e.g., checking for most subtle alterations like paypa1.com instead of paypal.com where the final ‘l’ is replaced by a 1), as a perfectly encrypted connection to an illegitimate server remains a severe threat. Additionally, up-to-date web browsers actively support privacy by default by displaying prominent, full-screen warnings before loading unencrypted HTTP pages that prompt for input.

👨‍👩‍👧 Example from everyday life

At 8:30 PM, twelve-year-old kid rushed his mother to download a school file he forgot about. Searching on her phone, the mother clicked a link, but her browser displayed a "Not Private" warning. Despite the kid urging her to ignore it due to a lack of time, she noticed the unsafe http:// prefix. Instead of proceeding, she typed the official address directly into the bar, reaching the secure https:// portal and protecting his son's login credentials.

📝 Activity: The Padlock Inspection

Gather the family around a computer or tablet and open three websites you use frequently—such as a favourite online store, a local news site, and a video streaming platform.

  1. Instruct your children to locate the padlock icon next to the URL on each site.
  2. Click the padlock together and read the certificate information to see who officially owns the domain.
  3. Look for an older website that still uses HTTP and observe how the browser flags it as insecure. This quick exercise trains children to automatically look for structural security indicators before typing any username or password.

Attention: Let Technology Double-Check the Domain

Because human eyes can easily miss tiny spelling variations in a domain name, only in the case you have to fill in your personal credentials or information in a form, you can consider using a reliable Password Manager on family devices because a password manager acts as an excellent second line of defence as its automated systems will refuse to auto-fill your saved credentials if the domain name changes even by a single character, instantly alerting your children that they might be on a sophisticated phishing site.

Don’t forget to always double-check because also a technology tool can make mistakes. For any other scenario keep your attention high!

Community updates

If you would like to share any updates to this part of the e-learning, feel free to let us know!