Create a practical, prioritized personal online-privacy review.
Privacy is control over context, not perfect secrecy. Start with sensitive accounts, identity and location data, communications, financial information, family exposure, and plausible threats. Secure access first, reduce unnecessary collection and sharing, then establish a recurring review.
Build a personal data map
List key account categories, devices, browsers, apps, cloud storage, public profiles, data brokers, shared family services, work boundaries, and physical records. For each, ask what it holds, who can see it, what resets it, how it earns money, and what harm misuse could cause.
Prioritize high-value privacy controls
- Unique credentials, multi-factor authentication, and safe recovery for email and finance
- Device lock, updates, encryption defaults, notification privacy, and backups
- App, browser, location, microphone, camera, contacts, and photo permissions
- Social audience, search visibility, tagging, old posts, and connected apps
- Optional profile fields, ad personalization, data export, history, and deletion
- Data-broker exposure, breach monitoring, family plan, and trusted recovery contact
Choose changes by consequence
| Data | Potential harm | Priority control |
|---|---|---|
| Recovery email and phone | Account takeover | Strong authentication and carrier protection |
| Live location and routine | Physical safety or stalking | Limit audience and background access |
| Old unused accounts | Breach and impersonation surface | Export needed data and delete |
Run a privacy reset
- Secure primary accounts and devices.
- Review public search results and profiles.
- Remove unnecessary permissions and connected apps.
- Reduce stored history and optional collection.
- Close unused accounts through official settings.
- Schedule quarterly and post-incident reviews.
Avoid privacy products that overpromise
- Installing an unknown “cleaner” with broad access
- Assuming private browsing makes activity anonymous
- Deleting an account before saving needed records
- Publishing removal requests that reveal more personal data
Keep a privacy decision register
Record service, data category, purpose, audience, permissions, recovery route, export date, deletion or opt-out request, confirmation, remaining copies, and next review. Store it securely and avoid centralizing more sensitive detail than the plan needs.
Continue with the next decision
Sources and further reading
Primary and contextual sources used to verify definitions or give readers a relevant next resource.
- NIST Privacy Framework Primary voluntary framework for identifying and managing privacy risk; useful as a conceptual reference beyond organizations.