A public-data exposure audit is a self-search with a defined scope, a safety plan and a written record. Its purpose is not to discover everything anyone could know about you. It is to find the public paths that create the most risk, identify the source behind each one and turn the results into a prioritised removal or security queue.
Audit only yourself, a dependent you are authorised to help or a consenting participant. Do not use password-reset flows, leaked credentials, paid reports about someone else or deceptive contact to 'test' what can be found.
Decide whether it is safe to search now
Searching, changing accounts or submitting removals can create browser history, email confirmations, account alerts and changes an abusive person may notice. If you suspect a partner, stalker, employer or family member monitors your device or accounts, do not start by clearing history or changing everything. Use a safer device and account, and make a plan with a qualified advocate. The FTC warns that abrupt device changes can alert an abuser using stalkerware and increase danger.
For an ordinary self-audit, use a browser profile that is not signed into your usual search or social accounts. This does not make you anonymous; it simply reduces personalisation so the findings better resemble what another person might see.
Build a private identifier inventory
Write the identifiers you are willing to test in a private working file:
- current name, former names, common misspellings and professional name
- current and old cities or regions
- phone numbers and email addresses you control
- stable usernames and personal domains
- public profile URLs
- one or two photos already published by you
- business names, licences or public roles that genuinely relate to you
Do not add highly sensitive identifiers merely to make the audit 'complete'. A National Insurance number, passport number, full date of birth, recovery answer or unpublished home address should not be typed into ordinary search engines or broker sites.
Search in layers
Start broad, then use exact identifiers. Record the result before moving to the next layer.
1. Name and context
Search your full name in quotes, then combine it with a city, employer, school, profession or username. Repeat with former names and common variants. Check the first several result pages, image results and document results where available.
Do not assume a matching name is you. Open the source and confirm several independent details. A namesake's address or court record belongs in neither your exposure file nor your removal request.
2. Exact contact identifiers
Search each phone number in several normal formats and each email address in quotes. Search the email's local part as a username only when it is distinctive. These queries often find old profiles, cached contact pages, PDFs, repositories, mailing-list archives and broker listings.
The fact that an email appears in a breach-notification index is a security signal, not permission to obtain or search the underlying stolen data. Check only addresses you control through a reputable notification service, and never seek passwords or breach contents.
3. Usernames and profiles
Search exact usernames and inspect profiles you recognise. Look for public biography fields, contact buttons, friend or follower visibility, location tags, old posts and links that connect accounts. Review the platform's own privacy settings whilst signed in; a public search cannot reveal every audience setting.
4. Images
Use a photo you already publish to find copies and old profile pages. The goal is to locate your own public reuse, not to identify strangers in photographs. Record the containing page as well as the image URL.
5. People-search and data-broker sites
Search a small set of major services for your own record by name, phone or address. The FTC explains that people-search sites can combine public records, public social profiles and commercial broker data into reports containing addresses, relatives, contact details, employment and legal records. Partial previews alone can be sensitive.
Do not purchase a report merely to remove a visible listing. Record the public profile URL and use the site's official opt-out or privacy route. A broker may blend two people into one file, so verify the record without adopting incorrect details as your own.
6. Official and professional records
Check the government or professional sources that are reasonably likely to hold a public record about you: a business registry, licensing board, property record, court portal or campaign filing, for example. Search engines and brokers are projections of these sources; removing a projection may not change the original record.
Do not assume a public office can lawfully delete a record. Look for its current correction, confidentiality, address-protection or safety process. Eligibility depends on the jurisdiction and record type.
In the United Kingdom, you can check a vehicle's MOT history online using its registration number (number plate). For cars, motorcycles and vans, results are available for tests done since 2005; for HGVs, trailers, buses and coaches, since 2018. The service shows whether the vehicle passed or failed, recorded mileage, when the next MOT is due and, for tests in England, Scotland or Wales, what parts failed and where each test was done (requiring the 11-digit V5C log book number). DVLA's online vehicle enquiry service allows you to check details including vehicle tax status and expiry, SORN status, MOT expiry date, date of first registration, last V5C issue date, year of manufacture, type approval category, weight, engine size, fuel type and emissions data. The service requires the vehicle's registration number. To request information about the current or previous registered keeper of a vehicle, you must write to DVLA; the online vehicle enquiry service does not provide registered keeper identity information.
Record findings without building a new privacy risk
Use a compact exposure register:
| Field | Example of what to capture |
|---|---|
| Finding | 'Old phone number on conference PDF' |
| Exact location | Source URL and search-result URL |
| Category | Contact, location, family, account, image, financial, legal |
| Accuracy | Correct, stale, mixed with a namesake or unknown |
| Source type | Your account, publisher, public record, broker, search index |
| Access | Free preview, account-only, paywalled or search snippet |
| Risk | Likelihood × impact, with a short reason |
| Controller | Who can actually edit or suppress it |
| Next action | Secure, correct, delete, opt out, de-index or monitor |
| Evidence | Request ID and last checked date – not a copy of every sensitive field |
Encrypt or otherwise protect the file, restrict who can see it and delete raw screenshots when they are no longer needed. A beautifully complete spreadsheet of every address and account can become more dangerous than the individual pages it documents.
Prioritise by harm, not by result count
Use four practical tiers:
- Immediate: current home location, threats, active account takeover, confidential credentials, financial identifiers or a child's sensitive information.
- High: a current phone or personal email tied to an address, relatives, work schedule or other information useful for impersonation or stalking.
- Routine: old contact details, broker profiles, exposed audience settings and accurate but unnecessarily public biographies.
- Observe: harmless mentions, genuine namesakes, lawful public records you cannot change and results with too little evidence to classify.
Secure accounts before seeking cosmetic cleanup. If your email account is compromised, removing the address from search results does not stop the attacker from reading password-reset messages.
Turn the audit into an action queue
For each real finding, choose the controller and remedy:
- Your account: change the audience, delete the field or post and review linked apps and sessions.
- A publisher: request correction, redaction or deletion at the source.
- A data broker: use its official opt-out or privacy request.
- A search engine: request policy removal or refresh only after choosing the correct category.
- A public body: use the record-specific correction or confidentiality path if one exists.
- An active security incident: secure the email, carrier, financial and recovery accounts before continuing the audit.
Then verify the result from the source outward. A 'request submitted' email is not proof of removal.
Monitor a small, meaningful set
Google's Results about you can monitor supported contact information in Google Search and notify you of new matches. It does not monitor every search engine, broker, social network, archive or source database.
Create reminders around the identifiers and sites that produced actual risk, not every page you visited. A quarterly check is a reasonable starting point for ordinary exposure; people facing an active safety threat need a plan made with appropriate support, not a generic schedule.
If you receive a suspicious text message, forward it to 7726 (free of charge) so your mobile provider can investigate and potentially block the number. If you receive a suspicious call, hang up and do not call back, especially numbers beginning 070, 076, 084, 087, 090, 091 or 118, which can be premium-rate. If you think you have lost money or been hacked because of an online scam or fraud in England or Wales, contact Report Fraud online or call 0300 123 2040. In Scotland, report the crime to Police Scotland. Forward suspicious emails to report@phishing.gov.uk for investigation by the National Cyber Security Centre. Scammers use 'number spoofing' to make calls appear from trusted numbers on your caller ID, so displayed caller ID cannot be trusted to verify caller identity. Do not give personal details such as bank details, PIN, passwords or National Insurance number to unexpected callers.
Under Article 17 of the UK GDPR, individuals have the right to have personal data erased (also known as 'the right to be forgotten'). The right applies in certain circumstances, including when the data is no longer necessary for its original purpose, when consent is withdrawn or when processing is based on legitimate interests and the individual objects with no overriding legitimate interest. Requests can be made verbally or in writing. Organisations must respond to erasure requests without undue delay and within one month of receipt. They must inform any recipients if they erase data that has been shared. The right to erasure does not apply if the organisation is required by law to process the data, and organisations can refuse manifestly unfounded or excessive requests.
Continue with how to remove personal information from search results, or use the phone and email response plan if the audit reveals an active incident.