Why Structure Your Privacy Audit This Way

Thinking about your online privacy as a single sprawling problem is overwhelming. Breaking it into discrete "rooms" — accounts, devices, browsers, and apps — mirrors how your data actually flows: each category has its own exposure points, its own settings, and its own fixes.

If you're new to the underlying concepts, the starter's overview on digital privacy explains what data is collected and why it matters before you dive in. This checklist assumes basic familiarity and focuses on action.

Work through each section in one sitting or spread it across an evening. The goal isn't perfection — it's closing the gaps that leave you most exposed. Items marked must address high-probability risks; should items meaningfully reduce your exposure; nice-to-have items are worthwhile refinements for those who want to go further.

Required

Password Manager

Generates and securely stores unique passwords for every account, eliminating the need to reuse credentials.

Required

Authenticator App

Provides time-based one-time codes for two-factor authentication, which is more secure than SMS-based 2FA.

Required

Have I Been Pwned (haveibeenpwned.com)

Free public service that checks whether your email addresses appear in known data breach databases.

Required

Browser Privacy Settings Panel

Built into every major browser; used to manage tracking protection, permissions, and stored site data.

Required

Device Permission Settings

Your phone or computer's system settings for reviewing and revoking app-level access to location, camera, microphone, and contacts.

Optional

Notebook or Spreadsheet

Track which accounts, devices, and apps you've reviewed and flag items that need a follow-up action.

The Checklist: Room by Room

Work through each group below in order. The accounts room typically takes the longest, especially if you haven't audited passwords recently. For a deeper dive into why reused passwords cause so much damage, see why password reuse is still the biggest privacy hole.

Room 1: Accounts & Passwords

Install and configure a reputable password manager to generate and store unique passwords for every account. Must
Change any reused or weak passwords, starting with email, banking, and social media accounts. Must
Enable two-factor authentication (2FA) on every account that supports it, prioritizing email and financial services. Must
Delete or formally close accounts you no longer use — dormant accounts can be breached without your awareness. Should
Check haveibeenpwned.com to see whether your email addresses appear in known data breaches. Should
Remove saved payment methods from retail accounts you rarely use. Nice to have

Room 2: Devices

Confirm that your operating system and all installed apps are set to update automatically. Must
Enable full-disk encryption on laptops and computers (BitLocker on Windows, FileVault on macOS). Must
Set a strong lock-screen PIN or passphrase — and a short auto-lock timeout — on every mobile device. Must
Review which devices are logged into your primary accounts (Google, Apple ID, Microsoft) and remove any you no longer recognize or own. Should
Turn off Bluetooth and Wi-Fi when not actively in use in public spaces. Nice to have

Room 3: Browsers

Audit browser extensions and remove any you didn't install deliberately or no longer need. Must
Review browser permissions — especially camera, microphone, and location — and revoke access for sites that don't require it. Must
Enable enhanced tracking protection or equivalent in your browser's privacy settings. Should
Clear stored cookies and site data periodically, especially for sites you visited only once. Should
Consider using a privacy-focused DNS resolver (such as those offered by Cloudflare or your router's admin settings) to reduce DNS-level tracking. Nice to have

Room 4: Apps & Permissions

Open your phone's settings and review location permissions for every app — set to "while using" or "never" unless always-on access is genuinely required. Must
Revoke microphone and camera access from any app that has no clear reason to need it. Must
Delete apps you haven't opened in three months or more. Should
Review contact and calendar access — these permissions expose data about people other than yourself. Should
Check whether apps are set to share data with third-party advertising networks via their in-app privacy settings. Nice to have
Opt out of personalized advertising through your device's platform-level ad settings (iOS Privacy > Tracking; Android Privacy > Ads). Nice to have

Email Is the Master Key to Your Accounts

Your primary email account controls password resets for virtually every other service you use. If it's compromised, an attacker can access banking, social media, and cloud storage without needing any other credentials. Prioritize a unique, strong password and two-factor authentication on email above everything else on this checklist.

Once you've worked through your browser settings, consider pairing this audit with the detailed guidance in locking down your browser privacy settings. For apps specifically, privacy red flags hidden in app permissions explains which permission types are most commonly abused.

Don't Trust Browser-Saved Passwords as Your Only Solution

Browsers offer to save passwords as a convenience feature, but they vary significantly in how securely those credentials are stored and synced. If your browser account or device is compromised, saved passwords can be exposed. A dedicated password manager with strong encryption provides meaningfully better protection and works across all your devices and browsers.

If you use smart home devices, be aware that the privacy considerations there are distinct from phone and browser settings — privacy trade-offs in smart home devices gives a balanced overview of what you're giving up for convenience.

Making the Audit a Habit

A one-time audit closes the gaps that exist today, but new apps, platform policy changes, and account drift mean the picture shifts over time. Building a short quarterly check into your routine — reviewing newly installed apps, confirming two-factor authentication is still active, and culling unused accounts — keeps your exposure manageable without requiring hours of work each time.

The weekly screen-time audit framework offers a complementary structure: while that guide focuses on usage habits, the same regular-review mindset applies directly to privacy. When you sign up for a new service, protecting your privacy when joining a new online platform is a quick pre-registration checklist worth running first.

Privacy is not a destination. Each step you complete today reduces the surface area available to data brokers, advertisers, and bad actors — and each future review keeps that surface area small.