Tech Explained

Personal Data Security Audit: A Step-by-Step Self-Check

Share
Person reviewing personal data security settings on a laptop with a checklist nearby.

Key Takeaways

Most data vulnerabilities stem from weak passwords, reused credentials, or outdated app permissions.
A self-audit takes under an hour and requires no special software or technical knowledge.
Reviewing privacy settings regularly is as important as reviewing account passwords.
Old, unused accounts are a common entry point for unauthorized access.
Two-factor authentication dramatically reduces the risk of account compromise.
30–60 min

Summary

22 items · 30–60 minutes

Why You Need a Personal Data Security Audit

Most people assume a breach happens to someone else — until it happens to them. The reality is that unauthorized access to personal accounts rarely involves sophisticated hacking. More often, it exploits something preventable: a recycled password, an app granted too many permissions, or an old account left open and forgotten.

A personal data security audit is a structured self-check. It doesn't require technical expertise — just focused attention and about an hour of your time. Think of it the way you might think of checking your smoke detectors or reviewing your bank statements: a routine precaution that catches problems early.

Before you start, it helps to understand what you're protecting. Every login, search, and app interaction leaves traces — your digital footprint is larger than most people realize, and reducing unnecessary exposure is one of the most effective things you can do.

Passwords and Login Credentials

Identify every account that uses a password you also use elsewhere and update each to a unique passphrase or randomly generated password. Must
Enable a reputable password manager to generate, store, and autofill strong credentials so you don't have to memorize them. Must
Check whether any of your email addresses appear in known data breaches using a service such as Have I Been Pwned (haveibeenpwned.com). Must
Update the master password or PIN for any password manager or device keychain you use. Should

Two-Factor Authentication (2FA)

Enable two-factor authentication — which requires a second verification step beyond your password — on all financial, email, and social media accounts. Must
Switch from SMS-based 2FA to an authenticator app (such as any TOTP-compatible app) wherever the service allows it, as text messages can be intercepted. Should
Save or print backup codes provided by services during 2FA setup and store them in a secure offline location. Should

App Permissions and Connected Services

Open your phone's settings and review which apps have access to your location, microphone, camera, and contacts — revoke any that don't require it to function. Must
Check third-party apps connected to your Google, Apple, or Microsoft account and remove any you no longer use or don't recognize. Must
Review which apps have permission to read or send email on your behalf and remove access for any you didn't intentionally authorize. Should
Change location-sharing settings from 'Always' to 'While Using' for any app that doesn't require background location to work. Should

Old and Unused Accounts

List every online account you've created over the years and close or delete any you no longer actively use. Must
Search your email inbox for registration confirmation messages to surface accounts you may have forgotten. Should
Use a service's official data deletion or account closure option rather than simply uninstalling its app, which leaves the account active. Must

Device Security

Confirm that automatic software and security updates are enabled on every device you use — phones, tablets, computers, and routers. Must
Set a strong screen lock (PIN, password, or biometric) on all mobile devices, and verify that auto-lock activates after no more than two minutes of inactivity. Must
Verify that full-disk encryption is enabled on your laptop or desktop computer (FileVault on macOS, BitLocker on Windows). Should
Check that your home Wi-Fi router uses WPA2 or WPA3 encryption and change the default admin password if you haven't already. Must

Privacy Settings and Data Sharing

Review the privacy settings on social media platforms and limit who can see your posts, contact information, and friend or follower lists. Should
Opt out of ad personalization and data-sharing settings within major platforms where the option is available in account settings. Nice to have
Review your browser's saved autofill data — including stored credit card numbers and addresses — and remove anything you don't want kept there. Should

Tools You'll Need to Run This Audit

You don't need to install anything special. The tools below are either built into your devices or freely available through your existing accounts. Gather access to all of them before you begin so you can move through the checklist without interruption.

Required

Have I Been Pwned (haveibeenpwned.com)

Check whether your email address has appeared in any publicly known data breaches.

Required

Password manager

Generate and securely store unique, strong passwords for every account you hold.

Required

Authenticator app (any TOTP-compatible app)

Generate time-based one-time codes for two-factor authentication as a more secure alternative to SMS.

Required

Your device's system settings

Review and manage app permissions, screen lock, encryption, and software update status.

Optional

Email inbox search

Search for account registration emails to surface old or forgotten online accounts.

How to Act on What You Find

Running the audit is only useful if you follow through. When you discover an issue — a reused password, an app with location access you didn't knowingly grant, an account you forgot existed — address it the same day rather than adding it to a mental to-do list.

Don't Defer Issues You Discover

It's tempting to note a problem and plan to fix it later. In practice, deferred security tasks rarely get done. If you find a reused password or an app with excessive permissions during this audit, address it before moving to the next item. A partial audit that results in real changes is far more valuable than a complete audit that results in none.

Breach Notifications Require Immediate Action

If a service notifies you that your account was part of a data breach, treat it as urgent rather than informational. Change the password for that account immediately, update it everywhere you reused the same password, and check whether 2FA was enabled. Delays increase the window of exposure significantly.

For account security habits you want to carry forward after this audit, see our companion guide on keeping your accounts safe across every app you use. For a deeper look at the specific settings that most apps default to without your awareness, privacy settings that are easy to overlook on everyday apps is a useful next read.

Finally, be alert to social engineering attempts that can render even strong security habits ineffective. Understanding how phishing attacks are constructed and how to spot them is a practical complement to everything in this checklist.

Plan to repeat this audit every three to six months — or immediately after any suspected account compromise or data breach notification.

Tech Explained Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Tech Explained Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.