Netflix collects detailed viewing behaviour, device fingerprints, and advertising data — including interests inferred by third-party ad companies from your activity across the internet — to serve behavioural ads on its ad-supported tier. Controls are reasonably accessible, but retention timelines are vague, Do Not Track is ignored, and the breadth of the ad-tech ecosystem is larger than you might expect from a subscription service.
No known public data breaches
Netflix does not appear in the Have I Been Pwned database of publicly disclosed data breaches.