facebook-pixel

How to Do a Personal Data Audit: A Complete Step-by-Step Guide

L
Lunyb Security Team
··10 min read

Most people have no idea how much personal information they've scattered across the internet over the past decade. Old forum accounts, forgotten newsletter signups, shopping profiles, cloud photo backups, and dozens of apps you tried once and never opened again — all of them are still holding pieces of your identity. A personal data audit is the process of finding, reviewing, and cleaning up that trail so you can regain control of your privacy.

This guide walks you through exactly how to do a personal data audit, what tools to use, and how to build habits that keep your digital footprint small going forward.

What Is a Personal Data Audit?

A personal data audit is a structured review of all the personal information you have shared online, the accounts that hold it, and the third parties that can access it. The goal is to answer three simple questions: What data exists about me? Where does it live? Who can see or sell it?

Think of it like a financial audit, but instead of tracking money, you're tracking data — email addresses, phone numbers, home addresses, payment details, browsing history, location logs, biometric data, and behavioral profiles built by advertisers.

Why You Should Do One at Least Once a Year

  • Data breaches are constant. Even careful users end up in breach dumps because of company mistakes.
  • Old accounts are attack surfaces. Forgotten accounts often use weak, reused passwords.
  • Ad profiles compound over time. Every unaudited year adds more behavioral data to your file.
  • Regulations give you rights. Laws like GDPR, CCPA, and similar frameworks let you request deletion — but only if you know where your data is.

Step 1: Build a Master Inventory of Your Accounts

You cannot audit what you cannot see. The first step is to create a complete list of every online account tied to your identity. This is often the most eye-opening part of the process — most people discover they have 150 to 400 accounts.

How to Find Every Account You've Ever Created

  1. Search your primary email inbox for keywords like "welcome", "confirm your email", "verify your account", "your new account", and "subscription".
  2. Check your password manager (or your browser's saved passwords) and export the list.
  3. Review "Sign in with Google/Apple/Facebook" connected apps in your account settings.
  4. Check your phone for installed apps that required registration.
  5. Search old email addresses — including that Hotmail account from high school.

Put everything into a simple spreadsheet with columns for: Service name, email used, category, sensitivity level, last used, action to take.

Step 2: Check Which Accounts Have Been Breached

Once you have your inventory, cross-reference it with known data breaches. This tells you which accounts are already compromised and need immediate password changes.

Free Tools for Breach Checking

Tool What It Checks Cost
Have I Been Pwned Email addresses and phone numbers against known breaches Free
Firefox Monitor Email breach monitoring with alerts Free
Google Password Checkup Passwords saved in Chrome against breach databases Free
Apple Password Monitoring iCloud Keychain passwords for reuse and breaches Free (built-in)

For every account flagged as breached: change the password immediately, enable two-factor authentication, and mark it in your spreadsheet for a deeper review.

Step 3: Map What Personal Data Each Account Holds

Not every account is equally sensitive. A trivia game app knowing your nickname is not the same as a tax service holding your government ID. Categorize each account by sensitivity so you know where to focus.

Suggested Sensitivity Tiers

  • Critical: Banking, government, healthcare, primary email, password manager.
  • High: Cloud storage, work accounts, social media with private messages, shopping sites with saved cards.
  • Medium: Newsletters, forums, streaming services, loyalty programs.
  • Low: One-off signups, throwaway trials, abandoned apps.

For critical and high-tier accounts, log in and review exactly what data is stored: saved addresses, payment methods, uploaded documents, biometric data, and connected devices. Delete anything you don't actively need.

Step 4: Audit Your Browser and Device Privacy Settings

Your browser and phone are the two biggest leakers of personal data in your daily life. They collect location, browsing history, contacts, microphone access, and more.

Browser Audit Checklist

  1. Review site permissions — revoke camera, microphone, and location access from sites that don't need it.
  2. Clear third-party cookies and switch to strict tracking protection.
  3. Enable DNS over HTTPS (DoH) to encrypt DNS lookups.
  4. Install a reputable content blocker such as uBlock Origin.
  5. Turn off ad personalization in your Google, Microsoft, and Apple accounts.
  6. Review installed extensions — remove any you don't recognize or use.

Phone Audit Checklist

  1. Open Settings > Privacy and review permissions per category (Location, Microphone, Contacts, Photos).
  2. Turn location off for apps that shouldn't have it (games, flashlights, most utilities).
  3. Disable advertising ID or reset it regularly.
  4. Review Bluetooth-paired devices and remove old ones.
  5. Uninstall apps you haven't used in 90+ days.

Step 5: Audit Your Social Media Footprint

Social platforms are treasure chests of personal data — both what you post and what platforms infer about you. A proper audit means reviewing both.

What to Review on Each Platform

  • Profile visibility: Set profiles to private or friends-only where possible.
  • Old posts: Bulk-delete or archive content older than a few years.
  • Tagged photos: Untag yourself from anything you don't want indexed.
  • Connected apps: Revoke third-party apps that no longer need access.
  • Ad preferences: Reset advertising interest categories and turn off off-platform tracking.
  • Download your data: Use each platform's data export tool to see exactly what they hold about you.

Downloading your data archive from Facebook, Google, Instagram, or TikTok is often shocking — it includes years of location pings, search queries, and inferred interests. This is your best evidence for deciding what to delete.

Step 6: Deal With Data Brokers

Data brokers are companies that collect and sell your personal information — usually without you ever hearing of them. They pull from public records, loyalty programs, and shady sources to build detailed dossiers.

How to Remove Yourself From Data Broker Sites

  1. Search your name in a private browser window along with your city.
  2. Identify broker sites that list your address, phone, relatives, or age.
  3. Submit opt-out requests using each broker's removal form.
  4. Use automated services like DeleteMe, Kanary, or Optery if manual removal is too tedious.
  5. Send GDPR/CCPA deletion requests if you're covered by those laws — they are legally binding.

Set a calendar reminder to redo broker removals every six months, since many brokers repopulate your data from fresh sources.

Step 7: Clean Up Links, Sharing, and Public Exposure

Beyond accounts, you likely have a scatter of public-facing links: shared Google Docs, Dropbox folders, old Bio pages, and QR codes on printed material. These can leak information you forgot you exposed.

Go through your cloud storage and revoke "anyone with the link" sharing on files that no longer need it. If you use link shorteners to share content publicly, consider switching to a privacy-respecting one like Lunyb, which doesn't build advertising profiles from your click data. If you want a deeper look at how it stacks up against alternatives, read our honest Lunyb review or our 2026 buyer's guide to URL shorteners.

Step 8: Exercise Your Data Rights

Depending on where you live, you have legal rights to see, correct, and delete data companies hold about you. Use them.

Common Data Rights You Can Exercise

  • Right to access: Request a copy of all data a company holds.
  • Right to deletion: Demand that data be erased ("right to be forgotten").
  • Right to correction: Fix inaccurate information.
  • Right to portability: Get your data in a machine-readable format.
  • Right to opt out of sale: Prevent your data from being sold to third parties.

Most companies have a privacy request form linked from their privacy policy. When submitting a request, mention the applicable law (GDPR, CCPA, LGPD, PIPEDA, etc.) — responses are usually much faster.

Step 9: Strengthen the Accounts You Keep

After the cleanup, harden what remains. This is the last mile of the audit and the one that pays off every day afterward.

Security Hardening Checklist

  1. Move every account to a password manager with unique, long passwords.
  2. Turn on two-factor authentication — prefer app-based or hardware keys over SMS.
  3. Set up recovery contacts and backup codes, then store them offline.
  4. Use email aliases or a masked-email service for new signups.
  5. Consider virtual card numbers for online purchases to isolate merchants.
  6. Review login history on critical accounts monthly.

Step 10: Set Up an Ongoing Maintenance Routine

A one-time audit is powerful, but data exposure is a moving target. Build a lightweight routine so you never have to do a full audit from scratch again.

Frequency Task
Weekly Review any new signups; delete accounts you tried but won't keep.
Monthly Check breach alerts; review social media privacy changes.
Quarterly Audit app permissions on your phone and browser.
Every 6 months Redo data broker removals; review connected apps on all major platforms.
Yearly Full personal data audit using this guide.

Common Mistakes to Avoid During a Personal Data Audit

  • Deleting accounts by just abandoning them. Actually go through the deletion process — abandoned accounts still hold your data.
  • Ignoring old email addresses. Your teenage inbox is often the recovery email for accounts you forgot exist.
  • Skipping the boring services. Loyalty programs and utility apps often hold surprisingly rich personal profiles.
  • Not saving your work. Keep your audit spreadsheet — it becomes the foundation for every future audit.
  • Trusting "private" browser modes to protect you. Private browsing hides history locally but does nothing to stop tracking at the network level.

FAQ: Personal Data Audits

How long does a personal data audit take?

Plan for 4 to 10 hours total, spread over a week or two. Doing it in short sessions (one platform per evening) is far more sustainable than trying to marathon it. The first audit is the longest — subsequent yearly audits usually take 1 to 2 hours if you keep good records.

Do I need paid tools to do a personal data audit?

No. You can complete a thorough audit using only free tools: Have I Been Pwned, your browser's built-in password checker, platform data-download features, and a plain spreadsheet. Paid services like data broker removal tools are convenient but not required.

What should I do with old accounts I don't want anymore?

Formally delete them rather than just walking away. Log in, remove any stored payment methods and personal details first, then use the account deletion option in settings. Sites like JustDeleteMe can point you to the deletion page for hundreds of services.

Can I recover data I've deleted during the audit?

Usually not, which is why you should download a copy of anything sentimental (photos, messages, documents) before deleting accounts. Most platforms offer a data export tool in account settings — use it before hitting delete.

Is a personal data audit really worth doing?

Yes. Beyond privacy, an audit dramatically reduces your risk of identity theft, account takeovers, and phishing. It also cuts down on spam and unwanted marketing, and it gives you a clear map of your digital life — which is genuinely useful when something goes wrong and you need to act fast.

Final Thoughts

A personal data audit isn't glamorous, but it's one of the highest-impact things you can do for your privacy and security. The exercise reveals just how much information you've handed over — often unintentionally — and gives you a concrete plan to take it back. Do it once thoroughly, keep your spreadsheet, and future audits become quick maintenance rather than massive projects.

Start with Step 1 today: open your primary inbox, search for "welcome", and start building your list. Everything else follows from there.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles