Privacy audit checklist: a step-by-step personal review with time estimates

Monitoring / awareness. Updated 2026-09-13. About 6 minutes to read.

Start with your main email account, because whoever controls it can reset the password on almost everything else you own.

A privacy audit is a planned check of where your personal information is exposed and which accounts could be taken over. Done once properly, it takes about five to six hours spread across a week. After that, a lighter version every three to six months keeps you ahead of new breaches and relisted broker profiles.

The steps below are in priority order. The first five protect your accounts, which is where real damage happens. The rest reduce what strangers can find about you. Each step shows a realistic time and the free tools on this site that do the checking for you.

Before you start: gather these five things (10 minutes)

  • A list of every email address you have used in the last ten years, including old work, university and internet provider addresses.
  • Every phone number linked to your accounts, including old numbers you no longer use.
  • Access to your password manager, or a notebook if you do not have one yet.
  • Your phone, because most account checkups need a code or an approval.
  • A simple log, a note or spreadsheet with columns for the step, what you found, what you fixed and the date. The log is what makes next year's audit quick.

Part 1: lock down your accounts (about 2.5 hours)

  1. Breach exposure, 15 minutes. Run each email address through the free email breach check. Note every breach that included passwords, phone numbers or identity numbers. Then subscribe each address to Have I Been Pwned notifications so future breaches reach you without another audit.
  2. Password reuse, 45 to 60 minutes. Test your most important passwords with the password checker, which checks whether a password already appears in breach lists without sending it anywhere. Replace any password that is leaked or used on more than one site, starting with email, banking and any shop that stores your card. Use the password generator or your password manager to create new ones.
  3. Email account, 20 minutes. Turn on two-factor authentication, using an authenticator app or passkey rather than text messages where possible. Check the recovery phone number and backup email are still yours. In Gmail, open Settings, See all settings, then Forwarding and POP/IMAP and Filters and Blocked Addresses. In Outlook.com, open Settings, Mail, then Forwarding and Rules. Delete any forwarding address or rule you did not create.
  4. Platform checkups, 30 minutes. Run Google's Security Checkup at myaccount.google.com/security-checkup and remove old devices and third-party apps. On an iPhone with iOS 16 or later, open Settings, Privacy and Security, Safety Check, then Manage Sharing and Access. For Microsoft, open account.microsoft.com/security and review sign-in activity. For Facebook and Instagram, open Accounts Center, Password and security, Where you're logged in.
  5. Phone number, 15 minutes. Ask your mobile carrier for a port-out PIN, number lock or SIM swap protection, and take the phone exposure audit to see where your number is published and which accounts use it for recovery.

A forwarding rule you did not create is a sign someone has already been inside your email. Change the password, sign out of all sessions, and check your bank and shopping accounts for password reset emails before you carry on with the audit.

Part 2: reduce what strangers can find (about 2.5 hours)

  1. Search yourself, 20 minutes. In a private browser window, search your full name in quotes with your city, then your mobile number, personal email and home address. Note every result that shows contact details.
  2. Google Results about you, 10 minutes. Open myactivity.google.com/results-about-you, add your phone number, home address and email, and turn on alerts. Request removal of results that show them. Google will not remove results from government sites or news outlets.
  3. People-search sites, 60 to 90 minutes for the first pass. Use the free data broker opt-out tracker to work through the sites that matter in your country, starting with any listing that shows your address next to your phone number. Record the date you submitted each one.
  4. Social media visibility, 20 minutes. Set old posts to friends only, hide your friends list, turn off search by phone number and email, and remove your birth date and employer from public view.
  5. App permissions and ad tracking, 20 minutes. On iPhone, open Settings, Privacy and Security, App Privacy Report. On most Android phones, open Settings, Security and privacy, then Privacy dashboard. Remove location, contacts, microphone and photo access from apps that do not need them, and reset your advertising ID.

Part 3: close old doors (about 1 hour)

  1. Search your email inboxes for words such as welcome, verify your account and confirm your email to find accounts you forgot. Delete the ones you no longer use through each site's account settings, and write down any that refuse to delete.
  2. Remove saved cards from shops you rarely use.
  3. Freeze or ban your credit file. In the US, freezes are free at Equifax, Experian and TransUnion. In Australia, request a credit ban with each bureau if you suspect fraud. In the UK, where there is no consumer freeze, check your statutory credit reports and consider Cifas Protective Registration if you are at risk. In Canada, ask Equifax and TransUnion about a fraud alert or a provincial security freeze.
  4. Practise on a real suspicious message. Paste the next odd text or email into the scam message checker and any link into the phishing link checker, so checking becomes a habit before you click.

Turn the audit into a routine

Most of the audit only needs doing once. What drifts is broker listings, which come back as sites import new public records, and passwords on accounts you create during the year. Put two reminders in your calendar: one every 90 days to search your name and number again and check your opt-out log, and one each year to repeat Part 1.

If you want a quick measure of progress, take the privacy score quiz before you start and again when you finish. It will show which gaps are left and which fixes matter most for your situation.

Opting out of a people-search site does not delete the public records it used. That is why listings often reappear, and why the 90 day re-check matters more than doing a perfect first pass.

Frequently asked questions

How often should I do a privacy audit?

Do the full audit once, then repeat Part 1 every year and the people-search check every 90 days. Also rerun the account steps after any breach notification, a lost phone, or the end of a relationship where the other person knew your passwords or had your devices.

What is the fastest way to check whether my accounts are compromised?

Check your email address against breach data, then look at the signed-in devices and recent security activity for your email, Apple or Google, and Microsoft accounts. Unknown devices, unexpected password reset emails or new forwarding rules are signs of a compromise.

Should I delete old accounts or just change the passwords?

Delete them where you can. A dormant account still holds your data and can still be breached. Change the password first so a compromised account cannot block the deletion, then delete it from the account settings.

What is Apple Safety Check for?

Safety Check on iPhone, under Settings, Privacy and Security, lets you see and stop what you share with other people and apps. Manage Sharing and Access walks through it step by step. Emergency Reset stops all sharing at once and is meant for situations where your personal safety is at risk.

Do I need to pay for a service to do this?

No. Every step in this checklist can be done for free. Paid removal services save time on the people-search step, which is the most repetitive part, but they cannot fix passwords, email rules or account security for you.

Tools that help

Related guides

Sources