Personal data — your name, address, date of birth, financial records, health information, login credentials, and the hundreds of other details you share with services, employers, and institutions — is the raw material for identity theft, targeted fraud, data broker profiles, and surveillance advertising. Most people share far more of it than they need to and take far fewer steps to protect their personal data from the companies, attackers, and aggregators that want it. For a broader walkthrough, our Complete Guide to Security and Privacy is a good next read.
Data breaches exposing personal records occur daily, identity theft costs victims thousands of dollars and hundreds of hours to recover from, and personal information shared with one company is routinely sold and licensed to dozens of others without your awareness. A deliberate, category-by-category approach — rather than assuming services handle your data responsibly — is the only approach that produces meaningful results.
Start with data minimisation — share less in the first place
The most effective protection is sharing less personal data before it ever enters a company’s systems. Every piece you provide is a liability — it can be breached, sold, or misused, and it persists long after you stop using the service.
When signing up for any online service, distinguish between mandatory and optional fields. Mandatory fields (usually marked with an asterisk) are required to complete registration; optional fields serve the platform’s data collection interests more than your needs. Skip all optional fields: middle name, phone number when not needed for 2FA, home address when not needed for delivery, date of birth when not needed for verified age confirmation.
Phone numbers specifically: your mobile carrier number is a high-value piece of personal data because it can be used for SIM swapping, appears in data broker profiles linked to your real identity, and enables targeted marketing calls. Use a VoIP number (Google Voice in the US is free; MySudo offers more separation) for all non-essential registrations. The VoIP number forwards calls and texts normally while keeping your real carrier number private.
Managing personal data already held by third parties
Three categories of third-party data holding require active management:
Data broker profiles: companies that compile and sell your personal data without a direct relationship with you. Submit opt-out requests to the major brokers (Spokeo, Whitepages, Intelius, BeenVerified, Radaris) and use an automated removal service like DeleteMe or Privacy Bee for the long tail of smaller brokers and the quarterly re-submissions required as profiles repopulate. Our dedicated guide on stopping data brokers provides the complete opt-out process for each major broker.
Old unused accounts: every forgotten account still holds the email address, password hash, and profile information you provided at signup — and is just as exposed in a breach as an active account. Search your email inbox for “Welcome to” subject lines to inventory every service you’ve registered with. Use JustDeleteMe (justdeleteme.xyz) as a reference for each service’s deletion process. Prioritise accounts at services that appeared in Have I Been Pwned breach notifications.
Cloud services: review privacy and data access settings on every actively-used cloud service. Check which third-party applications have OAuth access to your Google, Microsoft, and Apple accounts — and revoke any that are inactive or have broader permissions than their function justifies. These third-party connections are frequently granted once and never reviewed again, accumulating into a significant shadow data-sharing network.
The step-by-step protection plan
- Audit your existing exposure. Search your full name on Google and on major people-search sites. Check your email addresses at haveibeenpwned.com. Review your Google account’s data holdings at myactivity.google.com and myaccount.google.com/data-and-privacy. This tells you what exists and prioritises where to focus first.
- Change passwords and enable 2FA everywhere. Any breached credential is an open door to the account’s personal data. Change passwords for all breached accounts immediately using your password manager’s generator. Enable 2FA using an authenticator app on all accounts holding personal data.
- Submit data broker opt-out requests. Start with Spokeo, Whitepages, Intelius, BeenVerified, and Radaris. Set calendar reminders to resubmit every 90 days.
- Delete unused accounts. Prioritise accounts at breached services, then accounts unused for more than two years. Use guest checkout for future one-time purchases rather than creating new accounts.
- Switch to email aliases for new signups. Install SimpleLogin or AnonAddy and use a unique alias for every new service registration going forward. Your real email address stops accumulating in new databases from this point.
- Review privacy settings on all active services. Check data sharing settings on social media, cloud storage, email, and shopping accounts. Disable data sharing for advertising and opt out of behavioural profiling.
- Place a credit freeze at all three bureaus. Equifax, Experian, and TransUnion — free, reversible, and the most powerful action available against new-account financial fraud. Also sign up for free credit monitoring through each bureau’s service.
- Use a password manager for all credentials. Every account gets a unique generated password in the encrypted vault — protects personal data from credential stuffing when any single service is breached.
Step 5 — switching to email aliases — is the one change that most durably protects personal data going forward because it creates structural separation between your real identity and the services you use. Breaches, data sales, and marketing list sharing all affect only the alias (which you can disable instantly) rather than your primary address, which continues accumulating in other databases you don’t want affected.
Device-level personal data protection
- Enable full-disk encryption on all devices that hold personal data — BitLocker (Windows 11 Pro/Enterprise), FileVault (macOS), or Device Encryption (Windows 11 Home). A stolen or lost device with encryption enabled exposes nothing. Our guide on encrypting files on Windows 11 covers the setup process.
- Use a password manager rather than browser storage for credentials. Browser-stored passwords, autofill data (name, address, card number), and browsing history represent a high-value target for malware that specifically exfiltrates browser data — browser profiles are among the most frequently targeted data categories by infostealers.
- Disable browser autofill for addresses and payment cards. Browser autofill can submit data to hidden form fields on sites designed to capture it. Use the password manager’s form-fill feature instead, which requires active selection.
- Review app permissions quarterly on all mobile devices — location, microphone, camera, contacts. Each permission is an ongoing data collection channel. Revoke access from apps that don’t have a clear functional need.
Legal rights to protect personal data
Depending on where you live, you have legal rights that go beyond voluntary opt-outs:
- EU and UK (GDPR): right to access, correct, and delete personal data held by any organisation, with mandatory 30-day response. The most comprehensive rights globally.
- California (CCPA/CPRA): right to know what data is held, request deletion, and opt out of the sale of personal information.
- Virginia, Colorado, Texas, and other US states: comparable privacy laws with deletion rights for residents.
Exercising these rights begins with submitting a Subject Access Request (SAR) to any organisation you want to audit. Follow up with an Erasure Request (under GDPR Article 17 or equivalent state law) to request deletion. Include “Article 17 GDPR Erasure Request” or “CCPA Deletion Request” in the subject line — this signals legal familiarity and typically accelerates response. Organisations that don’t respond within the legal timeframe can be reported to the relevant data protection authority (ICO in the UK; national DPAs in EU member states; FTC for CCPA violations in the US).
Legal rights provide the mechanism to remove data that already exists and to hold organisations accountable for misuse. They don’t prevent the initial collection of data you willingly provided — which is why data minimisation and alias usage are the practices that complement the legal rights framework rather than replacing it. Together: provide less, use aliases, delete what’s no longer needed, and exercise legal rights for data held without ongoing legitimate purpose.
Our guides on protecting social media privacy, reducing your digital footprint, and protecting your online identity cover the complementary practices across each specific channel where personal data is collected and shared. For a current reference on which US states have enacted consumer data privacy laws with personal data deletion rights, the IAPP’s US state privacy legislation tracker maintains an updated map of enacted and pending laws.
Personal data and AI-assisted fraud
A growing threat that highlights why active personal data protection matters: AI-assisted fraud. Attackers now use large language models to craft hyper-personalised phishing emails based on scraped personal data — your employer, recent purchases, family members’ names, and current events relevant to your location. The more personal data exists in publicly accessible sources, the more convincing and targeted these AI-generated attacks become.
The connection between data minimisation and phishing resistance is direct: less data in circulation means less ammunition for attackers building personalised attack campaigns. Removing your data from data broker profiles, locking down social media, and using aliases for registrations directly reduces the fuel available for AI-assisted fraud targeting you specifically. This makes the seemingly abstract privacy practice of data minimisation a concrete fraud-resistance measure — one that becomes more valuable rather than less as AI-assisted fraud tools become more sophisticated.
The personal data exposure risk by category
| Data category | Where it typically ends up | Main risks | Priority protection action |
| Email address | Data brokers, marketing lists, breach databases | Phishing target; credential stuffing vector | Use email aliases for all non-essential signups |
| Mobile phone number | Data brokers, marketing databases, breach databases | SIM swap; smishing; robocalls | Use VoIP number for non-essential registrations |
| Home address | Public records, data brokers, merchant records | Doxxing; targeted physical mail scams; identity fraud | Data broker opt-outs; PO box for non-essential use |
| Date of birth | Data brokers, account registration databases | Identity verification bypass; fraud | Provide approximate DOB to non-essential services |
| Payment card details | Merchant databases, breach databases | Fraudulent purchases | Virtual card numbers; credit cards over debit |
| Login credentials | Breach databases; sold on criminal markets | Credential stuffing; account takeover | Unique generated passwords + 2FA on all accounts |
| SSN/National ID | Public records (partial); employer records; financial institutions | Credit fraud; tax fraud; government impersonation | Credit freeze; share only where legally required |
| Health information | Health provider records; insurance databases; wellness apps | Insurance discrimination; targeted fraud; breach exposure | Review what wellness apps share; use HSA/insurance accounts cautiously |
| Browsing/purchase history | Advertising networks; data brokers; retail databases | Targeted manipulation; profiling for fraud | Browser tracking protection; data minimisation with retailers |
The table shows why a category-by-category approach matters — the right action for protecting email addresses is different from the right action for protecting your SSN, and both are different from the right action for protecting browsing history. A single privacy setting or a single tool doesn’t cover all categories simultaneously. The layered approach throughout this guide addresses each category with the most appropriate available control.
Protecting personal data is ultimately about reducing the surface area of information that can be used against you — whether by identity thieves, data brokers, targeted advertisers, or social engineering attackers. The specific controls vary by data type, but the underlying principle is consistent: provide the minimum necessary, review what exists, delete what’s no longer needed, and enforce your legal rights for what remains in systems without your active consent to keep it there. That consistent application, across every category and every service, is what personal data protection looks like in practice. Related: Biometric Data Privacy.






