It is important to point out that the quality of the data is not important. There is no such thing as dangerous vs harmless data, because that quality completely depends on the context.
So I usually give a context in which "harmless" data can be misused to build trust for scamming schemes (something, that most people, that do not care about data privacy, fear a lot as real threat). I look, for example, in the fb-timeline of my counterpart and immediately come up with a story, how I, as a stranger with scamming intentions, would ring their doorbell and tell some story why I need to enter the house or collect some money or the like, making myself believable with the information I collected from the social media sites. In the same way I describe how I would draft a spear phishing mail, pretending to be some member of the inner circle by using public information of that circle.
Finally I point them to the contradiction, that they ask their neighbour to empty the mailbox during their vacation, so nobody can see they are away, but then they provide a live-coverage of their trip in social media. Once they get the picture, that the burglar might not be walking down the streets looking for overflowing mailboxes but rather investigate his potential victims on facebook, they start to reconsider the "I have nothing to hide"-opinion.
The trick is to set the topic into a context that is comprehensible and likely. People can often not imagine how their average lives could be interesting for corporates and governments - it is a perceived unlikelyness on a deeper level: not only do they believe that corporates and governments would not misuse privacy data, they cannot even see why such a misuse could be of any value. In their perception, there is no misuse, because there is no reason for misuse.