Skip to content

How to audit your public-data exposure

Audit your own public exposure across search, brokers, profiles, images and records; prioritise harm and build a safe removal and monitoring queue.

Quick answer

Quick answer to How to audit your public-data exposure

Audit only yourself or someone who authorised you. From a safe device and a minimally personalised browser, inventory non-sensitive identifiers you control, search names and exact contact details, inspect your public profiles, images, broker previews and relevant official records, then log each verified source, exposure category, risk, controller and next action. Secure active account incidents first, remove information from its source where possible, and monitor only the identifiers and sites that produced meaningful risk.

  • A useful exposure audit is consent-based, source-specific and prioritised by harm – not a hunt for every available fact.
  • Do not search stolen data, trigger account recovery, buy another person's report or create a new master file of unnecessary sensitive details.
  • Classify each finding by source, controller, accuracy, access, risk and remedy before requesting removal.

Topics: Privacy audit · Public data · Data brokers · Exposure monitoring

A public-data exposure audit is a self-search with a defined scope, a safety plan and a written record. Its purpose is not to discover everything anyone could know about you. It is to find the public paths that create the most risk, identify the source behind each one and turn the results into a prioritised removal or security queue.

Audit only yourself, a dependent you are authorised to help or a consenting participant. Do not use password-reset flows, leaked credentials, paid reports about someone else or deceptive contact to 'test' what can be found.

Decide whether it is safe to search now

Searching, changing accounts or submitting removals can create browser history, email confirmations, account alerts and changes an abusive person may notice. If you suspect a partner, stalker, employer or family member monitors your device or accounts, do not start by clearing history or changing everything. Use a safer device and account, and make a plan with a qualified advocate. The FTC warns that abrupt device changes can alert an abuser using stalkerware and increase danger.

For an ordinary self-audit, use a browser profile that is not signed into your usual search or social accounts. This does not make you anonymous; it simply reduces personalisation so the findings better resemble what another person might see.

Build a private identifier inventory

Write the identifiers you are willing to test in a private working file:

  • current name, former names, common misspellings and professional name
  • current and old cities or regions
  • phone numbers and email addresses you control
  • stable usernames and personal domains
  • public profile URLs
  • one or two photos already published by you
  • business names, licences or public roles that genuinely relate to you

Do not add highly sensitive identifiers merely to make the audit 'complete'. A Medicare number, driver licence number, passport number, full date of birth, recovery answer or unpublished home address should not be typed into ordinary search engines or broker sites.

Search in layers

Start broad, then use exact identifiers. Record the result before moving to the next layer.

1. Name and context

Search your full name in quotes, then combine it with a city, employer, school, profession or username. Repeat with former names and common variants. Check the first several result pages, image results and document results where available.

Do not assume a matching name is you. Open the source and confirm several independent details. A namesake's address or court record belongs in neither your exposure file nor your removal request.

2. Exact contact identifiers

Search each phone number in several normal formats and each email address in quotes. Search the email's local part as a username only when it is distinctive. These queries often find old profiles, cached contact pages, PDFs, repositories, mailing-list archives and broker listings.

The fact that an email appears in a breach-notification index is a security signal, not permission to obtain or search the underlying stolen data. Check only addresses you control through a reputable notification service, and never seek passwords or breach contents.

3. Usernames and profiles

Search exact usernames and inspect profiles you recognise. Look for public biography fields, contact buttons, friend or follower visibility, location tags, old posts and links that connect accounts. Review the platform's own privacy settings while signed in; a public search cannot reveal every audience setting.

4. Images

Use a photo you already publish to find copies and old profile pages. The goal is to locate your own public reuse, not to identify strangers in photographs. Record the containing page as well as the image URL.

5. People-search and data-broker sites

Search a small set of major services for your own record by name, phone or address. The FTC explains that people-search sites can combine public records, public social profiles and commercial broker data into reports containing addresses, relatives, contact details, employment and legal records. Partial previews alone can be sensitive.

Do not purchase a report merely to remove a visible listing. Record the public profile URL and use the site's official opt-out or privacy route. A broker may blend two people into one file, so verify the record without adopting incorrect details as your own.

6. Official and professional records

Check the government or professional sources that are reasonably likely to hold a public record about you: a business registry, licensing board, property record, court portal or campaign filing, for example. Search engines and brokers are projections of these sources; removing a projection may not change the original record.

If you own or are purchasing a motor vehicle, a Personal Property Securities Register (PPSR) search uses the Vehicle Identification Number (VIN) or chassis number to reveal whether the vehicle has a registered security interest (money owing), written-off status or stolen status (except Tasmania). The search costs AU$2 online or AU$7 by phone and should be conducted on the day of purchase or the day before. The PPSR does not disclose the vehicle owner's identity, the amount of finance owing, odometer readings or outstanding fines, and NEVDIS data (written-off and stolen records from state agencies) may not always be available or up-to-date. If buying a car registered in Tasmania, a separate search on the Transport Tasmania website is required. Buyers from licensed motor vehicle dealers are generally protected from repossession even if a security interest was registered, though a search is still recommended.

Do not assume a public office can lawfully delete a record. Look for its current correction, confidentiality, address-protection or safety process. Eligibility depends on the jurisdiction and record type.

Record findings without building a new privacy risk

Use a compact exposure register:

FieldExample of what to capture
Finding'Old phone number on conference PDF'
Exact locationSource URL and search-result URL
CategoryContact, location, family, account, image, financial, legal
AccuracyCorrect, stale, mixed with a namesake or unknown
Source typeYour account, publisher, public record, broker, search index
AccessFree preview, account-only, paywalled or search snippet
RiskLikelihood × impact, with a short reason
ControllerWho can actually edit or suppress it
Next actionSecure, correct, delete, opt out, de-index or monitor
EvidenceRequest ID and last checked date – not a copy of every sensitive field

Encrypt or otherwise protect the file, restrict who can see it and delete raw screenshots when they are no longer needed. A beautifully complete spreadsheet of every address and account can become more dangerous than the individual pages it documents.

Prioritise by harm, not by result count

Use four practical tiers:

  1. Immediate: current home location, threats, active account takeover, confidential credentials, financial identifiers or a child's sensitive information.
  2. High: a current phone or personal email tied to an address, relatives, work schedule or other information useful for impersonation or stalking.
  3. Routine: old contact details, broker profiles, exposed audience settings and accurate but unnecessarily public biographies.
  4. Observe: harmless mentions, genuine namesakes, lawful public records you cannot change and results with too little evidence to classify.

Secure accounts before seeking cosmetic cleanup. If your email account is compromised, removing the address from search results does not stop the attacker from reading password-reset messages.

Turn the audit into an action queue

For each real finding, choose the controller and remedy:

  • Your account: change the audience, delete the field or post, and review linked apps and sessions.
  • A publisher: request correction, redaction or deletion at the source.
  • A data broker: use its official opt-out or privacy request.
  • A search engine: request policy removal or refresh only after choosing the correct category.
  • A public body: use the record-specific correction or confidentiality path if one exists.
  • An active security incident: secure the email, carrier, financial and recovery accounts before continuing the audit.

Under Australian privacy law, individuals have the right to request correction of personal information held by an organisation or agency if it is inaccurate, out of date, incomplete, irrelevant or misleading. The entity must respond within a reasonable period (generally 30 days). There is no charge for requesting or obtaining correction. If correction is refused, you may request that a statement be associated with the information noting the claimed inaccuracy. You also have a general right to access personal information held about you; a request must be responded to within 30 days. Requesting access is free, though organisations may charge a non-excessive fee for providing access. Agencies cannot charge for providing access.

To lodge a privacy complaint with the Office of the Australian Information Commissioner (OAIC), you must first complain to the organisation or agency directly. If there is no response within 30 days or the response is unsatisfactory, a complaint may be lodged with the OAIC. Complaints about electricity, gas, water providers (in ACT, NSW, QLD, SA, VIC, WA), financial service providers or Victorian public transport may be required to go to an approved external dispute resolution scheme before the OAIC.

Then verify the result from the source outward. A 'request submitted' email is not proof of removal.

Monitor a small, meaningful set

Google's Results about you can monitor supported contact information in Google Search and notify you of new matches. It does not monitor every search engine, broker, social network, archive or source database.

Create reminders around the identifiers and sites that produced actual risk, not every page you visited. A quarterly check is a reasonable starting point for ordinary exposure; people facing an active safety threat need a plan made with appropriate support, not a generic schedule.

Continue with how to remove personal information from search results, or use the phone and email response plan if the audit reveals an active incident.

Continue reading