logo
|
Log In
LeadArise

Sign up to stay in touch with us

Contact
Data PrivacyImprintTerms And Conditions
Visit our LinkedIn pageVisit our Instagram page

© leadarise, 2026

Data PrivacyImprintTerms And Conditions

© leadarise, 2026

Visit our LinkedIn pageVisit our Instagram page
Data PrivacyImprintTerms And Conditions
  1. Insights
  2. Lena-Carlotta Hartlieb

Insights

Digital Visibility - a double edged sword

Protecting one's digital footprint is becoming a matter of discipline

When it comes to data protection, there’s no such thing as “set it and forget it”

We often have detailed guidelines, processes, and protocols in place to protect our customers’ personal data and our company data from malicious attacks. But what about us as individuals?

This is especially true for people in leadership roles—whether in politics, academia, business, or even in private life as board members of organizations: Today, more than ever, we are in the public eye and leave an ever-growing digital footprint.

In the context of social media, where it’s all about likes, followers, and impressions, the pressure to be seen is mounting. This also comes with an obligation to draw a clear line for oneself regarding which data is considered private and should under no circumstances be made public.

Today, I’m speaking with Lena-Carlotta Hartlieb, a criminologist and security consultant specializing in OSINT analysis, about precisely this pressure. She outlines clear strategies that help navigate the balance between digital visibility and privacy protection.


With every post on social media, we become a bit more visible and at the same time more vulnerable. And this doesn’t just affect me, but also people in my private environment. Why should we understand how visible we are digitally?

In the digital space, it’s less about whether data is being managed, and more about who takes responsibility for it. If I don’t take care of it myself, someone else will. Absolute security is unrealistic, because you can never fully control all your data.

That’s why the focus shouldn’t be on perfect protection, but on consciously managing uncertainty: knowing which information about me is public and being prepared in case it is used.


Before this conversation, you analyzed my public digital presence and there were quite a few eye-opening moments for me. To set the context: when data about me is collected and analyzed online, this is done using publicly accessible methods and tools. Not through hacking, but with tools that essentially anyone could use. Is that correct?

First of all, it’s important to understand that the digital space is fundamentally designed not for privacy, but for visibility and public exposure.

Even if you configure services to be as privacy-friendly (and user-friendly) as possible, they are still built to present and position us. That’s something to always keep in mind.

Beyond that, the biggest vulnerability is clearly careless handling of one’s own data. Many people unintentionally disclose private information on social networks, putting themselves at risk without any active attack or advanced technical means being required.

In many cases, no specialized hacking or exceptional skills are needed, because much of the information is already easily accessible and the tools to gather it are relatively easy to obtain or learn.

We did a small experiment beforehand where you applied your analysis tools and methods to me. I found it fascinating to understand how I appear in the digital space both as a private individual and in connection with leadarise, and what traces I’ve already left online. In short, parts of the result felt quite “spooky”. Especially realizing that very old images or videos of me, combined with current ones, create a very clear overall picture.

We shouldn’t forget that the digital space is not only enormous, making it easy to lose track, but that data, or fragments of data, are almost always stored.

This makes it relatively easy to collect and analyze information.

What makes the digital space so complex isn’t just its scale, but the fact that data persists, even when we’ve long forgotten about it. Nothing disappears on its own, so I have to actively ensure that data about me is deleted. Even though it’s a common assumption that individual data gets lost in the sheer volume, there will always be people who search for it specifically.

So I just set all my accounts and profiles to private.

Even that tells me something as a malicious actor: namely, that this person values privacy highly. That alone is already usable information.

To make the risk more tangible, could you give a concrete example?

A good example is a Google account, which is extremely convenient because it connects many services - from email to logins across numerous platforms.

This convenience simplifies everyday life, but it also means that a large amount of information converges in one central place. Even seemingly harmless activities, like a well-intentioned café review, are linked to this account and provide contextual clues about locations, habits, and social situations.

Most people don’t want their private home address to be publicly available online. But once someone has your Google email address, certain services can be used to identify which accounts are linked to it. Is the Google Calendar public, for example? Can I see scheduled appointments? This happens more often than one might think.

Even without publicly sharing your name or address, recurring locations, timestamps (“my first coffee in the morning”), or phrasing (“just a five-minute walk to the best matcha in town”) can reveal your approximate place of residence.

If such an account falls into the wrong hands, through a data leak or targeted searching, it’s not just emails that are affected, but an entire usage profile: interests, movement patterns, even family structures. Many of these data points are generated unconsciously in everyday life, but can still be highly valuable to malicious actors.


I’m not always the source of information about myself. What about situations like photos taken at events: how quickly do you appear in someone else’s post without being asked?

It’s important to distinguish clearly between the public-professional space and the private space.

The public-professional space is easier to manage, because visibility is often intentional and even beneficial, especially in semi-public roles like that of a managing director.

Visibility does not automatically mean insecurity. What matters is how informed you are and how consciously you manage that visibility. The better your overview, the better you can manage the associated risks.

This includes regularly checking where you appear, where content is shared, in what context it appears, and how it is perceived, whether through simple tools like name alerts or professional analyses by external providers.

At the same time, you decide how precise the information in your own posts is. You can create something like “background noise”, sharing without revealing meaningful details. For example, you could say you like to go for a walk when you’re stuck, without specifying exactly where. That way, you control your visibility while managing your digital security.

And in the private space?

The private sphere is more difficult to manage, because people in your close environment rarely assume malicious intent.

At the same time, this is where the most sensitive data exists. That’s why it makes sense to establish a clear family strategy: how do we present ourselves digitally? What do we share? Which services do we use?

Even if data is only temporarily visible (for example via “status” features), it can still be saved. So you need to be clear about what you’re comfortable with. And if you don’t want your face online, you need to communicate that clearly and others should respect it.

There are services that show where you are registered online, and these should be checked regularly as part of active data hygiene. In short: if you no longer use something, delete it.

In our experiment, you showed me that a volunteer role from over 10 years ago still publicly lists my email address and phone number. I simply assumed I wouldn’t need to actively take care of deleting that. What concrete strategy would you recommend that anyone can implement quickly?

The first step is to ask yourself: which data do I want to keep private, and which data am I comfortable sharing online? Then sit down and write out: “Where do I have accounts?”

Let me guess, that’s already where most people fail.

Exactly. Most people estimate they have five to ten accounts.

In reality, it’s often more than 30. Many services are no longer actively used, but the data is still stored. So you need to go through all services, apps, and platforms (including inactive ones) and review their privacy settings.

What does that mean in concrete terms?

First, I create a realistic overview of where my data is stored.

Then I review what information is saved: usernames, passwords, and personal data such as date of birth or address.

For social networks, I also check the general settings: visibility of my profile and personal information, and how much contact from strangers is allowed.

And this process should be repeated regularly, because updates can reset these settings.

So active data management means regularly reviewing the services I use, consciously and critically.

Exactly. I personally aim to minimize how much private information I share, while many services are designed for maximum connectivity. These are fundamentally opposing interests.

One final question: What gives you confidence that the digital world is moving toward greater personal security?

I would answer that in two parts.

First, from a legal perspective, we are on a positive path toward a safer digital environment - not fast enough, but in the right direction.

Second, it’s the younger generation. They grow up with a different level of digital literacy and can often intuitively distinguish, for example, between AI-generated and real content. In fact, parents and grandparents can learn a lot from them. That’s why working with young people in the context of digital media is so rewarding: they already approach it with a level of critical thinking that many adults lack.

Conclusion

Any digital visibility also increases our vulnerability—both for ourselves and for those around us. In the digital realm, therefore, it is less about perfect security and more about responsibility: Those who do not actively manage their data are leaving that responsibility to others. Absolute control is unrealistic; what matters is a conscious and active approach to dealing with uncertainties.


The interview shows that digital risks usually do not arise from hacking, but from everyday convenience and negligent data management. The digital space is designed for public visibility, not privacy. Even privacy-friendly settings do little to change this. Certain services aggregate enormous amounts of personal information, from which movement patterns, interests, and social relationships can be derived over time - often unconsciously.


Visibility is not inherently problematic; in a professional context, in particular, it can be useful. However, this requires active management of one’s own digital presence. In the private sphere, clear boundaries, agreements, and regular data hygiene are essential. Data protection is not a one-time project, but an ongoing process and a skill that younger generations, in particular, already possess as a matter of course.


Links

  • Linked-In Lena-Carlotta Hartlieb
  • Nexus
  • Publication
Lena-Carlotta Hartlieb

Facts

Name: Lena-Carlotta Hartlieb
Titel: Criminologist and security consultant
Passion: Cybersecurity, criminology, and flora and fauna
Mission: I focus on the risks of digital visibility and how easily publicly available information can lead to real-world threats. Using OSINT analysis, I help people whose professional activities or personal commitments involve increased digital visibility—and who are actively engaged in the digital space—to identify risks and specifically reduce their digital attack surface. My goal is to enable visibility without compromising security and self-determination.