How to audit your public-data exposure

Audit your own public exposure across search, brokers, profiles, images, and records; prioritize harm and build a safe removal and monitoring queue.

Lena OrtizUpdated 9 min read

Quick answer

Quick answer to How to audit your public-data exposure

Audit only yourself or someone who authorized you. From a safe device and a minimally personalized browser, inventory non-sensitive identifiers you control, search names and exact contact details, inspect your public profiles, images, broker previews, and relevant official records, then log each verified source, exposure category, risk, controller, and next action. Secure active account incidents first, remove information from its source where possible, and monitor only the identifiers and sites that produced meaningful risk.

  • A useful exposure audit is consent-based, source-specific, and prioritized by harm—not a hunt for every available fact.
  • Do not search stolen data, trigger account recovery, buy another person's report, or create a new master file of unnecessary sensitive details.
  • Classify each finding by source, controller, accuracy, access, risk, and remedy before requesting removal.

Topics: Privacy audit · Public data · Data brokers · Exposure monitoring

A public-data exposure audit is a self-search with a defined scope, a safety plan, and a written record. Its purpose is not to discover everything anyone could know about you. It is to find the public paths that create the most risk, identify the source behind each one, and turn the results into a prioritized removal or security queue.

Audit only yourself, a dependent you are authorized to help, or a consenting participant. Do not use password-reset flows, leaked credentials, paid reports about someone else, or deceptive contact to “test” what can be found.

Decide whether it is safe to search now

Searching, changing accounts, or submitting removals can create browser history, email confirmations, account alerts, and changes an abusive person may notice. If you suspect a partner, stalker, employer, or family member monitors your device or accounts, do not start by clearing history or changing everything. Use a safer device and account, and make a plan with a qualified advocate. The FTC warns that abrupt device changes can alert an abuser using stalkerware and increase danger.

For an ordinary self-audit, use a browser profile that is not signed into your usual search or social accounts. This does not make you anonymous; it simply reduces personalization so the findings better resemble what another person might see.

Build a private identifier inventory

Write the identifiers you are willing to test in a private working file:

  • current name, former names, common misspellings, and professional name
  • current and old cities or regions
  • phone numbers and email addresses you control
  • stable usernames and personal domains
  • public profile URLs
  • one or two photos already published by you
  • business names, licenses, or public roles that genuinely relate to you

Do not add highly sensitive identifiers merely to make the audit “complete.” A Social Security number, passport number, full date of birth, recovery answer, or unpublished home address should not be typed into ordinary search engines or broker sites.

Search in layers

Start broad, then use exact identifiers. Record the result before moving to the next layer.

1. Name and context

Search your full name in quotes, then combine it with a city, employer, school, profession, or username. Repeat with former names and common variants. Check the first several result pages, image results, and document results where available.

Do not assume a matching name is you. Open the source and confirm several independent details. A namesake's address or court record belongs in neither your exposure file nor your removal request.

2. Exact contact identifiers

Search each phone number in several normal formats and each email address in quotes. Search the email's local part as a username only when it is distinctive. These queries often find old profiles, cached contact pages, PDFs, repositories, mailing-list archives, and broker listings.

The fact that an email appears in a breach-notification index is a security signal, not permission to obtain or search the underlying stolen data. Check only addresses you control through a reputable notification service, and never seek passwords or breach contents.

3. Usernames and profiles

Search exact usernames and inspect profiles you recognize. Look for public biography fields, contact buttons, friend or follower visibility, location tags, old posts, and links that connect accounts. Review the platform's own privacy settings while signed in; a public search cannot reveal every audience setting.

4. Images

Use a photo you already publish to find copies and old profile pages. The goal is to locate your own public reuse, not to identify strangers in photographs. Record the containing page as well as the image URL.

5. People-search and data-broker sites

Search a small set of major services for your own record by name, phone, or address. The FTC explains that people-search sites can combine public records, public social profiles, and commercial broker data into reports containing addresses, relatives, contact details, employment, and legal records. Partial previews alone can be sensitive.

Do not purchase a report merely to remove a visible listing. Record the public profile URL and use the site's official opt-out or privacy route. A broker may blend two people into one file, so verify the record without adopting incorrect details as your own.

6. Official and professional records

Check the government or professional sources that are reasonably likely to hold a public record about you: a business registry, licensing board, property record, court portal, or campaign filing, for example. Search engines and brokers are projections of these sources; removing a projection may not change the original record.

Do not assume a public office can lawfully delete a record. Look for its current correction, confidentiality, address-protection, or safety process. Eligibility depends on the jurisdiction and record type.

Record findings without building a new privacy risk

Use a compact exposure register:

| Field | Example of what to capture | | --- | --- | | Finding | “Old phone number on conference PDF” | | Exact location | Source URL and search-result URL | | Category | Contact, location, family, account, image, financial, legal | | Accuracy | Correct, stale, mixed with a namesake, or unknown | | Source type | Your account, publisher, public record, broker, search index | | Access | Free preview, account-only, paywalled, or search snippet | | Risk | Likelihood × impact, with a short reason | | Controller | Who can actually edit or suppress it | | Next action | Secure, correct, delete, opt out, de-index, or monitor | | Evidence | Request ID and last checked date—not a copy of every sensitive field |

Encrypt or otherwise protect the file, restrict who can see it, and delete raw screenshots when they are no longer needed. A beautifully complete spreadsheet of every address and account can become more dangerous than the individual pages it documents.

Prioritize by harm, not by result count

Use four practical tiers:

  1. Immediate: current home location, threats, active account takeover, confidential credentials, financial identifiers, or a child's sensitive information.
  2. High: a current phone or personal email tied to an address, relatives, work schedule, or other information useful for impersonation or stalking.
  3. Routine: old contact details, broker profiles, exposed audience settings, and accurate but unnecessarily public biographies.
  4. Observe: harmless mentions, genuine namesakes, lawful public records you cannot change, and results with too little evidence to classify.

Secure accounts before seeking cosmetic cleanup. If your email account is compromised, removing the address from search results does not stop the attacker from reading password-reset messages.

Turn the audit into an action queue

For each real finding, choose the controller and remedy:

  • Your account: change the audience, delete the field or post, and review linked apps and sessions.
  • A publisher: request correction, redaction, or deletion at the source.
  • A data broker: use its official opt-out or privacy request.
  • A search engine: request policy removal or refresh only after choosing the correct category.
  • A public body: use the record-specific correction or confidentiality path if one exists.
  • An active security incident: secure the email, carrier, financial, and recovery accounts before continuing the audit.

Then verify the result from the source outward. A “request submitted” email is not proof of removal.

Monitor a small, meaningful set

Google's Results about you can monitor supported contact information in Google Search and notify you of new matches. It does not monitor every search engine, broker, social network, archive, or source database.

Create reminders around the identifiers and sites that produced actual risk, not every page you visited. A quarterly check is a reasonable starting point for ordinary exposure; people facing an active safety threat need a plan made with appropriate support, not a generic schedule.

Continue with how to remove personal information from search results, or use the phone and email response plan if the audit reveals an active incident.

Continue reading