DAC8 is in force: your 2026 data is already being collected. And on 9 July the EU extended Chat Control until 2028.

Field manual · updated

Digital self-defense

As you read this page, every transaction you make on a regulated exchange is being recorded in a file with your name on it: in 2027 that file will be handed to the tax authorities and shared automatically across 27 countries. That is not a hypothesis — it is DAC8, in force since 1 January. And privacy can't be "recovered" when you need it: you either build it before, or you don't have it.

This manual is the path to defend what can still be defended: messages, browsing, phone, money. All legal, all sourced. The first two levels are free below — you can put them into practice tonight. The full 7-level path is in the PDF guide (Italian + English).

Italian + English PDFs · instant download · every fact verified at the source

What else is already tracked today (and why it won’t reverse)

And crypto is only the latest piece. Your bank account is already transparent (balances and movements sit in registries available to the tax authorities), cross-border payments have been reported by payment providers since 2024, non-encrypted chats will remain scannable until 2028 under the Chat Control extension, and your call and message records — who you contact, when, from where — are retained for years, while Brussels drafts new rules to retain even more traffic data, VPNs included. The direction is one-way and it doesn't reverse: every year one more piece of your private life becomes a data point — collected, stored, queryable — without anyone asking your permission.

There is one more thing the laws don't say but the blockchain does: every link between your identity and your wallets is permanent. It cannot be deleted, it doesn't expire, it can't be negotiated. What you link today stays linked ten years from now, under any government and any future law.

Why now — and what actually changed

The context in five minutes, no panic and no fake news.

5 min · read

In 2026 two European laws shifted the balance between you and whoever watches you. They are worth understanding for what they actually say, not for how they trend on social media.

DAC8 is real: since 1 January 2026 every regulated EU exchange and crypto service (CASP) collects — and from 2027 reports to the tax authorities — your transactions. It is automatic exchange of tax information, exactly as already happens for bank accounts. Using crypto is not illegal; the era of the exchange as a blind spot is over.

Chat Control is the misunderstood part. On 9 July 2026 the European Parliament did not impose scanning of your messages: it only extended until 2028 the voluntary scanning of *non*-encrypted chats, with end-to-end communications excluded. The hard version — mandatory client-side scanning — is still under negotiation (trilogue, next stage September 2026), and mandatory scanning was removed from the Council's November 2025 position. In plain terms: end-to-end encryption still protects you today, and it is worth adopting now, before the framework changes.

This manual does not teach you to hide from the law. It teaches you to exercise a right: to decide who reads your messages, who sees your browsing and who knows your money moves. We start from the simplest step and climb to the most important one.

Your threat model in three questions

Before installing anything, answer: who you want protection from (spam and data brokers? an app reselling your data? an ex? a targeted adversary?), what you want to protect (your messages, your location, your assets) and how much friction you can accept. Privacy is not an on/off switch: it is a series of proportionate choices. A password manager is for everyone; routing everything through Tor on a dedicated phone is for few. Levelling up only where you genuinely need it is what makes a setup sustainable — and therefore real.

Field note Rule of thumb: privacy you don't use doesn't exist. Signal used every day beats a fortress abandoned after a week.

Sources for this level (3)

The foundations that apply to everyone

Passwords, second factor, aliases, DNS: 90% of the benefit for 10% of the effort.

30 min · one-off

No encrypted tool saves you if you reuse the same password everywhere or if your email is known across half the internet. This level is the non-negotiable base: do it once and it holds for years. It is also the level with the best effort-to-result ratio, so don't skip it to rush to the wallets.

A password manager, and different passwords everywhere

A single password leaked in a data breach can open all your accounts if you reuse it. A password manager generates and remembers a unique password per site, so a breach stays contained. Choose between an open-source, audited option and a 100% offline one if you want no cloud at all.

  • Bitwarden ↗ Open source · cloud

    Open source with recurring third-party audits (Cure53) and SOC 2; syncs across devices, generous free tier.

  • KeePassXC ↗ Offline · local

    Encrypted .kdbx database on your own disk, no server: version 2.7.9 is CSPN-certified by France's ANSSI. Maximum control, zero cloud.

Second factor: prefer apps (or a hardware key) over SMS

SMS codes are vulnerable to SIM swapping: if someone re-registers your number, they receive your codes. Use a TOTP app or, for your most important accounts, a FIDO2 hardware key. It is the same principle as self-custody: you hold the key, not a middleman.

Field note Turn on 2FA on your email first: it's the key that unlocks the reset of everything else.

Stop giving out your real email: use aliases

Every site you give your email to is a potential leak point (breach, spam, cross-site tracking that links your activity). An alias service creates a disposable forwarding address per service: if one gets resold or breached, you disable it without touching your real inbox.

  • SimpleLogin ↗ Open source

    Open-source forwarding aliases, acquired by Proton in 2022; you can also reply from the alias while keeping your real address hidden.

  • addy.io ↗ Open source · self-host

    Unlimited aliases, open source and self-hostable if you want to run the infrastructure yourself.

Encrypt your DNS: your ISP stops seeing every site you open

Even over HTTPS, by default your ISP sees the name of every site you visit through plaintext DNS queries. An encrypted DNS (DoH/DoT) closes that gap and can block trackers and malicious domains upstream.

  • Quad9 ↗ No-log · Switzerland

    Zurich nonprofit: does not log your IP, blocks malicious domains, supports DoT/DoH/DoQ. Swiss law extended to all users.

  • NextDNS ↗ Configurable

    Fully customizable encrypted DNS: tailored blocklists and per-device profiles. More control, with optional analytics you can turn off.

Sources for this level (3)

Encrypted messaging — the direct defense against Chat Control

From the choice for everyone to those who won't even leave a phone number.

Cover of the “Digital self-defense” PDF guide

The full guide · PDF

The manual continues in the full guide

The entire path, from level 02 onward, with comparison tables, a 30-day action plan, mistakes to avoid and every fact verified at the source:

  • 02 Encrypted messaging — the direct defense against Chat Control
  • 03 Browsing without leaving a trail
  • 04 Phone and identity — the most neglected level
  • 05 Sovereign money — taking back custody
  • 06 Spending privately — and putting it all together
  • 7 levels, from simplest to most important — a path, not a link dump
  • Italian and English PDFs, both included
  • Side-by-side tool tables (apps, VPNs, wallets, cards)
  • 30-day action plan, week by week
  • Every regulatory fact verified at the source as of July 2026
  • Instant download after purchase
Get the full guide — €20.00

Instant download · secure Payhip checkout · IT + EN included

Before you buy

What’s in it beyond the free part?

Above you read the context and foundations for free. The guide contains the 5 operational levels that matter most: encrypted messaging, anonymous browsing, phone and SIM, self-custody money and private spending — with concrete steps, tables and the 30-day plan.

Is it updated to the new rules (DAC8, Chat Control)?

Yes. It is written after DAC8 came into force and after the EU Chat Control vote of 9 July 2026, with every fact verified against official sources. No scaremongering or myths: just what the rules actually say and what you can do.

In what format and language do I get it?

Two PDFs, Italian and English, downloadable right after payment. Secure checkout handled by Payhip.

Is it all legal?

Yes. Privacy is a right: the guide teaches you to protect your data while staying compliant. It is not a manual to evade taxes or hide income — that is a crime, and we say so plainly.

Get the full guide — €20.00

This manual is information, not legal or tax advice. Privacy is a right; tax evasion and the use of anonymous tools for illegal activity are crimes. promp.it verifies data against the listed sources: if you spot something outdated, let us know.