UK tech experts · info@vividrepairs.co.uk
Vivid Repairs

ZeroYour rights, used

The Personal Privacy Audit: Find Out What the Internet Knows About You

14 min readLast verified 21 July 2026

In short

Most people have a much larger digital footprint than they realise, spread across search results, people-search directories, platform activity logs, old accounts, and data breaches. This guide walks you through a structured afternoon audit covering all of those areas, using official tools and UK-specific resources. The goal isn't to alarm you. Most findings are fixable, and knowing what's out there is the only way to start fixing it.

Why audit yourself: you cannot lock down what you have not seen

There's a particular kind of unease that comes from not knowing. You've probably wondered, at some point, what a stranger could find out about you with a few minutes and a search engine. The answer is often more than you'd expect, and less than you fear. But wondering isn't the same as knowing.

A personal privacy audit is simply the act of looking. You go through the places your data lives, one by one, and you see what's actually there. Not what you assume is there. Not what a headline told you might be there. What is actually, specifically, findable about you right now.

The reason this matters under UK law is worth understanding briefly. The UK GDPR gives you a set of rights over your personal data: the right to access it, the right to have inaccurate data corrected, and in certain circumstances the right to have it erased. The Information Commissioner's Office explains these rights clearly. But exercising them requires knowing where your data sits in the first place. Rights you don't know to use are rights that don't help you.

This guide is structured as a working checklist. You don't need any technical background. You need a couple of hours, a notepad (physical or digital, your choice), and a willingness to look at what you find without catastrophising about it. Most findings are fixable. That is entirely the point of looking.

Search yourself like a stranger would

The first thing a curious stranger, a prospective employer, an ex-partner, or anyone else with your name would do is search for you. So start there.

Open a browser in private or incognito mode. This matters because your regular browser is personalised to you, and you want to see results the way someone who isn't you would see them. Then run these searches in turn, noting anything that surprises you:

  • Your full name in quotation marks
  • Your full name plus your town or city
  • Your full name plus your current or most recent employer
  • Your full name plus your job title
  • Any old usernames you've used online, especially ones you used across multiple platforms
  • Your email address in quotation marks
  • Your mobile number in quotation marks

Do this on Google, and then repeat the most important searches on Bing. The results differ more than most people expect.

What are you looking for? Anything you didn't knowingly make public. Old forum posts. Cached versions of profiles you deleted. Your address appearing in a local news story or a planning application. A LinkedIn profile that's more detailed than you remembered. Images that appear in reverse image search (drag a photo of yourself into Google Images and see what comes back).

Old usernames deserve particular attention. If you used the same handle on a gaming forum in 2009 and on a now-deleted social media account, those posts may still be indexed. Researchers studying online identity have documented how usernames create unexpected threads between accounts people consider entirely separate. A username you used casually years ago might connect your real name to opinions, locations, or communities you'd rather not have linked.

Write down every result that concerns you. Don't act on anything yet. You're mapping first.

  • Run all searches in a private browser window, not your regular one
  • Search your name, town, employer, old usernames, email address, and phone number separately
  • Try a reverse image search on your most-used profile photo
  • Note every surprising result without trying to fix anything yet

The UK people-search sites and the open electoral register

Search engines are just the start. There's a category of website, sometimes called people-search sites or data broker directories, that specifically aggregates personal information and presents it in profile form. In the UK, these include sites that compile names, addresses, phone numbers, and sometimes age ranges or household information. They're legal to operate, which surprises many people.

The reason these sites have your details is worth understanding. How data brokers collect and sell personal information is a layered process involving public records, commercial data purchases, and web scraping. The open electoral register is one significant source.

Here's how the electoral register works in the UK. When you register to vote, your details go onto the full electoral register, which is used for elections and has strict access controls. But there's also an opt-out version called the open register (sometimes called the edited register). Unless you specifically opted out when you registered, your name and address appear on the open register, which can be bought by commercial organisations including data brokers, credit reference agencies, and direct marketing companies.

To check your status: contact your local Electoral Registration Office (find yours via gov.uk) and ask whether you're on the open register. If you are and you'd prefer not to be, you can opt out. This won't affect your ability to vote. The ICO has a clear explanation of how the electoral register works and what your options are.

For the people-search sites themselves: search for your name on the main UK-facing ones (a search for "UK people search" will surface them quickly). When you find a profile that's yours, look for their removal or opt-out process. Under UK GDPR, you have the right to request erasure in many circumstances. The ICO's guidance on the right to erasure explains when this applies. Some sites comply readily. Others require persistence. Note which ones have your data and what they show, then submit removal requests one by one.

This step takes longer than the others, but it's one of the highest-impact things you can do. A profile on a people-search site is findable by anyone, forever, until you remove it.

  • Contact your local Electoral Registration Office to check your open register status and opt out if you prefer
  • Search for your name on UK people-search directories and note what each one shows
  • Submit erasure requests to any site holding information you didn't knowingly make public

Open your own file: Google, Meta and Amazon activity tools

The data held by the platforms you use daily is a different category entirely. It's not scraped from public records. It's data you generated yourself, through every search, every click, every scroll. The platforms are legally required to let you see it, and their tools for doing so are more detailed than most people realise.

Understanding what the major platforms actually collect about you is useful context before you open these files, because what you find may be more granular than you expect.

Google

Go to myactivity.google.com while signed into your Google account. What you'll see is a timestamped log of your activity across Google's services: every search, every YouTube video watched, every Maps query, every voice search if you've used Google Assistant. The default view goes back years.

Then visit adssettings.google.com. This shows you the profile Google has built for targeting purposes: inferred age range, interests, and demographic categories. Some of these will be accurate. Some will be wrong in ways that are almost funny. The point isn't whether they're right. It's that this profile exists and influences what you see.

You can delete activity in bulk or set auto-delete periods. You can also download everything via Google Takeout, which produces an archive of your data across all Google services. The archive can be large. You don't need to download it for this audit, but knowing it exists is useful.

Meta (Facebook and Instagram)

The most revealing Meta tool for this audit is the off-Facebook activity page, now found within the Meta Accounts Centre. This shows you a list of businesses and websites that have sent information about you to Meta, even when you weren't using Facebook or Instagram. It's the tracking pixel system: when you visit a website that has Meta's code embedded, that visit is reported back.

The list is often startling. Charities, NHS-adjacent services, news sites, retailers, government-adjacent portals. These organisations have, whether deliberately or by default, shared data about your visits with Meta. You can clear this history and disconnect future off-platform tracking, though doing so doesn't delete the data Meta already holds and doesn't stop the tracking entirely, it just breaks the link to your account.

Also check your ad preferences within the Accounts Centre. Meta's inferred interest categories and the "advertisers with your contact info" section (which shows businesses that have uploaded your email or phone number to target you) are both worth reviewing.

Amazon

In your Amazon account, under "Browsing History" you can see every product page you've viewed. Under "Order History" you have a complete record of every purchase. Neither of these is surprising, but the volume often is. Amazon also holds Alexa voice recordings if you use an Echo device, accessible and deletable via the Alexa app or the Alexa Privacy settings page.

The practical takeaway from this section isn't necessarily to delete everything. It's to know what's there, and to adjust the settings that feel disproportionate to you. Turning off activity logging where the option exists, clearing histories you don't need, and reviewing ad profiles are all reasonable steps that don't require you to delete your accounts.

Old accounts, forgotten apps and third-party permissions

Most people have significantly more online accounts than they think they do. An account you created in 2015 for a service you used twice still holds your data. If that service is later acquired, breached, or simply sold its user database to a data broker, that data is out in the world under your name.

The best starting point for finding old accounts is your email inbox. Search for phrases like "welcome to", "confirm your email", "you've successfully registered", and "activate your account". Go back as far as your inbox allows. The results will almost certainly include services you'd completely forgotten about.

For each one you find, ask: is this account still active? Does it hold information I care about? If not, log in and delete the account properly. Not just unsubscribe from emails. Delete the account, which removes your data from their systems (or should, under UK GDPR). If you can't log in because you've forgotten the password, use the password reset flow to regain access, then delete.

Third-party app permissions are a separate but related issue. These are the connections you've granted to external apps and services to access your accounts. "Sign in with Google" or "Sign in with Facebook" creates a persistent permission that the third-party app retains until you revoke it.

To review these:

  • Google: go to myaccount.google.com/permissions
  • Facebook: check Apps and Websites in your Settings
  • Apple: go to Settings, then your Apple ID, then Password and Security, then Apps Using Apple ID

Remove any app you don't recognise or no longer use. An old app with permission to read your contacts or calendar is a low-level but persistent risk. It costs you nothing to revoke it.

An account you created years ago and never think about still holds your data. If that service is later breached or sold, that data travels under your name, attached to an email address and possibly a password you still use elsewhere.

Breach exposure: checking your email addresses

Data breaches happen constantly. A company's database is stolen, and the stolen data, which typically includes email addresses and hashed or plaintext passwords, circulates online. The question isn't really whether any of your email addresses have appeared in a breach. For most people who've been online for more than a few years, the answer is yes. The question is which ones, and what was exposed.

Breach notification services exist specifically to answer this. They collect information about known breaches and let you check whether a given email address appears in them. The category of tool is well-established, and the National Cyber Security Centre has endorsed the use of such services for exactly this purpose. You're looking for a service that checks your address against a database of known breaches and tells you which breach it appeared in and what data was included (email only, or email plus password, or email plus other personal details).

Check every email address you use or have used, including old ones you've largely abandoned. An address you stopped using in 2012 may have appeared in a breach since then, and if you still use the same password anywhere, that's a live risk.

What to do with what you find: if an address appears in a breach that included passwords, change that password everywhere you used it. This is exactly the scenario where a password manager (a tool that generates and stores unique passwords for every account) earns its keep. The category is well worth understanding: a password manager means you never reuse a password, which is the single most effective thing most people can do to reduce breach-related risk. The NCSC has guidance on password managers that explains how they work and what to look for.

If a breach included data beyond just your email and password, such as your address, phone number, or payment card details, note that. It doesn't require immediate action beyond changing the password, but it's relevant context for your risk list at the end.

  • Check every email address you use or have used through a breach notification service
  • Change passwords for any account where the breach included password data
  • If you reuse passwords across accounts, start moving to unique passwords using a password manager
  • Note any breaches that exposed more than just your email address

Your credit file: the audit step people skip

Most people think of their credit file as something you check before applying for a mortgage. It's that, but it's also a detailed record of your financial identity, and it's worth reviewing from a privacy perspective for reasons that have nothing to do with your credit score.

In the UK, the three main credit reference agencies are Experian, Equifax, and TransUnion. Under UK GDPR, you're entitled to a free statutory credit report from each of them. Each agency may hold slightly different information, so checking all three is worthwhile.

What you're looking for in a privacy audit context:

  • Accounts you don't recognise. A credit account in your name that you didn't open is a serious red flag for identity fraud.
  • Addresses listed against your name that you didn't live at or didn't associate with credit. These can end up on your file through data errors or, in fraud cases, through someone using your identity.
  • Hard searches (credit checks) you don't remember authorising. A hard search means someone applied for credit using your details.
  • Financial associations with people you're no longer connected to. A joint account or joint mortgage from years ago may still link your credit file to an ex-partner's.

If you find anything you don't recognise, the first step is to raise a dispute with the credit reference agency directly. They're legally obliged to investigate. The ICO's guidance covers your rights in relation to credit reference agencies in detail.

Even if everything looks correct, reviewing your credit file annually is a reasonable habit. It's one of the few places where identity fraud leaves a clear, documented trace before it causes serious damage.

Access your statutory reports directly through each agency's website. Be aware that all three agencies also offer paid subscription services. You're not obliged to sign up for anything to access your free statutory report, though the sign-up flows are sometimes designed to make this less obvious than it should be.

Turning findings into a three-item action list

By this point you have a notepad full of findings. Some will be minor. Some will have surprised you. A few may have genuinely concerned you. The worst thing you can do now is try to fix everything simultaneously, because that leads to overwhelm and inaction.

Instead, sort what you found into three rough categories:

Immediate risks. Things that represent an active or near-term threat. A reused password that appeared in a breach. A credit account you don't recognise. An app permission you can't explain that has access to your contacts or messages. These go to the top of your list.

Exposure you want to reduce. Things that aren't urgent but are worth addressing. Your presence on people-search sites. Being on the open electoral register. Old accounts you've forgotten about. Platform activity logs that are more detailed than you're comfortable with. These can be worked through over the coming weeks.

Things to monitor. Findings that don't require action right now but that you want to keep an eye on. An email address that appeared in a breach involving only email addresses (no passwords). A search result that's public information but that you'd rather wasn't prominent. These go on a list you revisit in six months.

From these categories, pick your three most important items. Not ten. Three. Write them down as specific actions: "Remove my profile from [site name] by submitting their erasure form", "Change the password on my [account] and set up two-factor authentication", "Contact the Electoral Registration Office to opt out of the open register".

Three specific actions, done, are worth more than fifteen vague intentions.

A few things worth keeping in mind as you close this audit. The goal was never to disappear from the internet. That's neither realistic nor, for most people, desirable. The goal was to understand your actual footprint, identify the parts of it you didn't choose, and make informed decisions about what to do. You've done that now. The feeling of having looked, and found it manageable, is the point.

Privacy isn't a destination you reach. It's a set of habits you build gradually. Running this audit once a year, or after any significant life change (a new job, a move, the end of a relationship), keeps your footprint in a shape you've chosen rather than one that accumulated without your attention.

The ICO's Your Data Matters hub is a reliable ongoing resource for understanding your rights as they develop. The NCSC's Top Tips for Staying Secure Online covers the technical hygiene side in plain language. Neither will alarm you unnecessarily. Both are worth bookmarking.

Last verified 21 July 2026. Settings move and companies change their terms, so every Vivid Zero guide is re-checked on a schedule and corrected the moment it drifts.

Questions people ask

How do I find out what information is publicly available about me online?
Start by searching your full name in a private browser window, combined with your town, employer, and any old usernames. Also check UK people-search and directory sites, which aggregate public records including the open electoral register. Your email address and phone number in quotation marks can surface additional results you might not expect.
How do I remove myself from UK people-search websites?
Most UK people-search sites have an opt-out or removal request process, usually found in their privacy policy or a dedicated "remove my data" page. Under UK GDPR, you have the right to request erasure of your personal data in many circumstances, and the ICO's guidance on the right to erasure explains when this applies. Some sites comply quickly; others require a follow-up. Keep a record of each request you submit.
What is the open electoral register and should I opt out?
The open register (also called the edited register) is a version of the UK electoral roll that can be purchased by commercial organisations, including data brokers and marketing companies. You're included by default unless you opted out when registering to vote. Opting out has no effect on your right to vote. Contact your local Electoral Registration Office to check your status and opt out if you prefer.
How do I check if my email address has been in a data breach?
Breach notification services let you enter an email address and check it against databases of known breaches. The National Cyber Security Centre endorses using this category of tool. Check every email address you use or have used, including old ones. If a breach included password data, change that password everywhere you used it and consider moving to a password manager so you're not reusing passwords in future.
How do I see what Google knows about me?
Go to myactivity.google.com while signed in to see a timestamped log of your searches, YouTube history, Maps queries, and more. Visit adssettings.google.com to see the demographic and interest profile Google uses for ad targeting. You can delete activity in bulk, set auto-delete periods, and adjust what Google records going forward, all from within those pages.
What is the Meta off-Facebook activity tool and what does it show?
The off-Facebook activity tool, found in the Meta Accounts Centre, shows a list of businesses and websites that have sent data about your activity to Meta via tracking pixels, even when you weren't using Facebook or Instagram. The list often includes retailers, news sites, charities, and other organisations you wouldn't necessarily expect. You can clear the history and disconnect future off-platform tracking, though this doesn't delete the underlying data Meta already holds.
Why should I check my credit file as part of a privacy audit?
Your credit file holds a record of every credit account opened in your name, every address associated with your financial identity, and every hard search made against your details. Reviewing it can reveal accounts you didn't open (a sign of identity fraud), addresses you don't recognise, or financial links to people you're no longer connected to. UK residents are entitled to a free statutory credit report from each of the three main credit reference agencies: Experian, Equifax, and TransUnion.
How do I find and delete old accounts I've forgotten about?
Search your email inbox for phrases like "welcome to", "confirm your email", and "activate your account", going back as far as possible. Each result that surfaces a forgotten service is a potential account to review and delete. Deleting properly (not just unsubscribing from emails) removes your data from that organisation's systems, which is your right under UK GDPR. If you can't remember the password, use the reset flow to regain access before deleting.

← All Vivid Zero guides