Privacy By The Numbers
Cookies
Data Retention
Social Engineering
Privacy By Design
100

This percentage of Americans say they often click “agree” without reading privacy policies.

What is 56%?

100

These small text files stored on a user’s device when accessing a website are called this.

What are cookies?

100

Personal data should not be kept longer than necessary, a concept known as this.

What is limited retention?

100

This type of social engineering attack uses fake emails, calls, or texts to trick victims into revealing sensitive information.

What is phishing?

100

This proactive approach integrates privacy safeguards during the design phase of a product or system.

What is Privacy by Design?

200

As of 2025, this many countries have enacted national data privacy laws.

What is 144 countries?

200

These cookies are essential for a website to function properly.

What are strictly necessary cookies?

200

This U.S. law requires financial institutions to maintain certain data retention periods.

What is the Gramm-Leach-Bliley Act (GLBA)?

200

Attackers often impersonate someone in power to exploit this human tendency.

What is authority?

200

This EU regulation mandates “data protection by design and by default.”

What is GDPR?

300

According to Cisco, this percentage of organizations say customers would not buy from them if they failed to protect data.

What is 94%?

300

Cookies that remain after closing the browser session are called this.

What are persistent cookies?

300

Regular deletion of outdated data reduces this type of risk and potential penalties.

What is compliance risk (or fines)?

300

This attack involves compromising a website frequently visited by a target group rather than attacking individuals directly.

What is a watering hole attack?

300

Limiting the amount of personal data collected to only what is necessary is called this principle.

What is data minimization?

400

In 2024, this many individuals’ protected health information was exposed or stolen.

What is 276,775,457?

400

Cookies may collect what type of data?

What is personal data?

400

When creating a retention policy, you should first document this about the data processing activity.

What is the purpose?

400

One way to reduce the success of social engineering is to enable this multi-step login security measure.

What is multi-factor authentication?

500

About this percentage of Americans believe privacy policies are ineffective at explaining how companies use data.

What is 61%?

500

Websites serving targeted ads must provide this functionality to users regarding ad targeting.

What is the ability to opt out?

500

Instead of deleting data, companies may render it unidentifiable through this process.

What is anonymization?

500

AI-driven impersonation of voices and faces is known as this.

What is deepfaking?