Digital Safety & Privacy

Online Privacy Checklist: Reduce Exposure Without Breaking Your Life

Focus on the accounts, data, people, and harms that matter most instead of trying to disappear from the internet in one afternoon.

What this guide helps you do

Create a practical, prioritized personal online-privacy review.

Privacy is control over context, not perfect secrecy. Start with sensitive accounts, identity and location data, communications, financial information, family exposure, and plausible threats. Secure access first, reduce unnecessary collection and sharing, then establish a recurring review.

Build a personal data map

List key account categories, devices, browsers, apps, cloud storage, public profiles, data brokers, shared family services, work boundaries, and physical records. For each, ask what it holds, who can see it, what resets it, how it earns money, and what harm misuse could cause.

Prioritize high-value privacy controls

  • Unique credentials, multi-factor authentication, and safe recovery for email and finance
  • Device lock, updates, encryption defaults, notification privacy, and backups
  • App, browser, location, microphone, camera, contacts, and photo permissions
  • Social audience, search visibility, tagging, old posts, and connected apps
  • Optional profile fields, ad personalization, data export, history, and deletion
  • Data-broker exposure, breach monitoring, family plan, and trusted recovery contact

Choose changes by consequence

DataPotential harmPriority control
Recovery email and phoneAccount takeoverStrong authentication and carrier protection
Live location and routinePhysical safety or stalkingLimit audience and background access
Old unused accountsBreach and impersonation surfaceExport needed data and delete

Run a privacy reset

  1. Secure primary accounts and devices.
  2. Review public search results and profiles.
  3. Remove unnecessary permissions and connected apps.
  4. Reduce stored history and optional collection.
  5. Close unused accounts through official settings.
  6. Schedule quarterly and post-incident reviews.

Avoid privacy products that overpromise

  • Installing an unknown “cleaner” with broad access
  • Assuming private browsing makes activity anonymous
  • Deleting an account before saving needed records
  • Publishing removal requests that reveal more personal data

Keep a privacy decision register

Record service, data category, purpose, audience, permissions, recovery route, export date, deletion or opt-out request, confirmation, remaining copies, and next review. Store it securely and avoid centralizing more sensitive detail than the plan needs.

Continue with the next decision

Review browser collection and site permissions. The browser is a major junction for accounts, trackers, downloads, and permissions.

Reduce public and broker exposure. Removal needs prioritization, verification, and periodic rechecking.

Sources and further reading

Primary and contextual sources used to verify definitions or give readers a relevant next resource.

  • NIST Privacy Framework Primary voluntary framework for identifying and managing privacy risk; useful as a conceptual reference beyond organizations.
IE

Prepared and reviewed by

Infortified Editorial Team

Research-led guides with explicit scope, source checks where facts require them, and an independence review before publication.

Search Infortified

Find a practical answer

Start typing to search all guides.

Open full search