Making sense of our connected world

Why data protection doesn’t protect data, but people
Clicking through cookie banners, wading through terms and conditions, managing your consent settings: anyone who spends time online knows how tiresome data protection can feel. Yet what looks like a personal chore is actually a means of moving through the internet on your own terms. This piece explains why the term “data protection” is something of a misnomer, and why the main responsibility for making it work doesn’t rest with users alone.
Every time we go online, we leave behind data that reveals something about who we are and what we like. At first glance, this might seem harmless enough; friends and acquaintances know plenty about us too. But when this data is used to target advertising or shape what we see on a platform, the consequences can be very real. We might never see certain job adverts because our data doesn’t match the intended audience. In online shops, we might be shown a different price to someone else, simply because we’ve been sorted into a different income bracket.
Take Jonas, for example. He lives in a part of town where rents are high, and his IP address, the internet’s equivalent of a postcode, gives that away. He browses on a new iPhone and has never once clicked on a discount code. The shop puts two and two together: affluent, not particularly price-sensitive customer. Next time Jonas buys the same product, he pays more than someone browsing from an older device in a cheaper neighbourhood. He never even notices. Or he ends up buying things he never really wanted, nudged along by adverts tailored just for him.
To keep effects like these to a minimum, we’re expected, or even required, to think about data protection every single day: agreeing to or declining the use of our data, checking settings, reading terms and conditions, ticking boxes. All of this can be rather tedious, but it matters, because it’s how we retain some say over what happens to the data collected about us.
What’s actually being protected
So what does data protection actually protect? Is it really about data? No. Which is precisely why the term is a bit of a misnomer. What it’s really about is protecting people from the consequences of how their data is used, not protecting the data itself. If we’re honest about what we mean, we should really be talking about user protection rather than data protection.
Jonas’s IP address, sitting somewhere in a database, is, on its own, nothing more than a number. It causes him no harm by itself. Harm, or indeed benefit, only arises from what’s done with that information, for instance when his IP address is combined with other details about him. This shift in perspective is more than a semantic quibble: it makes clear who ought to be protected, and who bears the responsibility for that protection.
The myth of personal responsibility
The endless string of decisions we’re asked to make each day, decisions that determine what our data can and can’t be used for, creates the impression that we, as internet users, are personally responsible for preventing harm (Guagnin, Feldhusen & Thor, 2026). But doing so properly would require us to understand, in technical detail, exactly how our data is processed, so that we could spot the sources of potential harm. And that’s something no user can genuinely check.
There are three reasons for this. First, we simply have no access to the internal systems of the platforms we use every day. Second, these processes are far too complex and abstract to follow in any detail; some are so intricate that even the companies running them can only make sense of them with considerable effort. Third, reconstructing the entire journey our data takes would, quite simply, take too long (Pohle & Lukat, 2026; Rost, 2018).
We’re handed small, fiddly levers, privacy settings being the obvious example, but their effect is limited. It’s rather like climate change: as an individual, you can make a difference by flying less or shopping more thoughtfully, but the levers that really move the needle sit with policymakers and with those who process your data in the first place. The good news is that there’s a powerful tool available here too: data protection law itself.
Who’s actually responsible
So who does carry the main responsibility, if not users? The General Data Protection Regulation (GDPR) refers to the companies or individuals who process our data as “controllers” (Art. 4(7) GDPR), and not without reason. They’re the ones designing the systems, deciding what data gets used for what. And they’re the ones making money from processing data about you. That combination of design power and financial interest gives them far more sway than any individual user could ever have, which is exactly why the main responsibility for minimising harm to you falls on them. The law sets out concrete obligations: controllers must explain clearly what data they collect and why (Art. 12–14 GDPR); they must obtain your consent before collecting and using your data (Art. 6 GDPR); and they must design their systems in a way that keeps potential harm to users to a minimum (Art. 32 GDPR).
Traffic rules, not airbags
Think of data flows as being rather like traffic. Nobody would suggest that road safety is the sole responsibility of pedestrians. Everyone on the road shares a duty to prevent harm, through careful driving, consideration for others, and avoiding unnecessary risk (Pohle & Lukat, 2026). Road signs, too, tell us where particular rules apply and who has the right of way. All of this exists for one reason: to prevent harm before it happens, rather than patch it up afterwards. The GDPR and the Digital Services Act work on exactly the same principle: they set out what may and may not be done with data.
The state’s role in enforcement
Rules alone aren’t enough; they need to be enforced. To stop them existing only on paper, Germany has seventeen independent data protection authorities: one for each federal state, plus one at national level. If you suspect a platform is processing your data unlawfully, you can raise the matter with them free of charge and without needing a lawyer (Art. 77 GDPR). They take complaints, investigate breaches, and issue fines where warranted. But for this work to be genuinely effective, these authorities need adequate staff and funding, and that, in practice, is often where things fall short.
What you can still do
Does this mean there’s nothing left for us to do? Not quite. We choose which services to use, and when to consent to our data being used, or not. We can adjust our settings and withdraw consent when we choose to. The decisions we make as users complement the responsibility held by companies and the state, but they don’t replace it. So while we’re not solely responsible for effective data protection, informed choices still allow us to protect ourselves to some degree, provided we understand where our own influence ends and others’ responsibility begins. That’s precisely where our research comes in.
The toolbox for user protection
In our project, Sicher im Datenverkehr (“Safe in Data Traffic”), we’re studying how personalisation works online, and weighing up its benefits against its risks. The difference between feeling entirely at the mercy of a system, and knowing there are rules, rights and bodies in place to protect you, is enormous. Recognising that difference is what makes clear that we can act with genuine agency over how our data is used. You’ll soon be able to find out exactly how, in our forthcoming toolbox on personalised advertising online. Because, in the end, good data protection isn’t about protecting data. It’s about protecting the people behind it.
Literature
European Parliament and Council of the European Union. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). Official Journal of the European Union, L 119. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32016R0679
European Parliament and Council of the European Union. (2022). Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act). Official Journal of the European Union, L 277. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32022R2065
Guagnin, D., Feldhusen, G., & Thor, L. (2026). Datenschutz-Risikokommunikation zwischen Surveillance und Personalisierung: Einwilligung oder Selbstbegrenzung? In Guagnin, D. & Pohle, J. (eds.) Risikonarrative im Feld Privacy, Surveillance und Datenschutz. Nomos, Baden-Baden.
Pohle, J., & Lukat, M. (2026). Vollkörper-Airbags für Fußgänger:innen? – Zur Nutzung von Analogien in der Risikokommunikation im Datenschutz, oder: Wie mit guten Vergleichen über schlechte Lösungen aufgeklärt werden kann. In Guagnin, D. & Pohle, J. (eds.) Risikonarrative im Feld Privacy, Surveillance und Datenschutz. Nomos, Baden-Baden.
Rost, M. (2018). Risiken im Datenschutz. vorgänge – Zeitschrift für Bürgerrechte und Gesellschaftspolitik, 57(2), 79–92.
This post represents the view of the author and does not necessarily represent the view of the institute itself. For more information about the topics of these articles and associated research projects, please contact info@hiig.de.

You will receive our latest blog articles once a month in a newsletter.
Featured Topics
Can AI strengthen democracy? A data collection on AI projects aiming to serve democratic processes
This article introduces a dataset of 98 AI projects claiming to serve democracy, built to help researchers test these claims.
Between accusations of censorship and platform power: What the Digital Services Act actually regulates
The DSA is increasingly attacked as "censorship law". This article argues: Its core purpose is to protect freedom of expression online.
Tick-box democracy: What a polling booth reveals about our personal beliefs
We invited Berliners to share their feelings and opinions about democracy in Germany. Find the results here.



