Technology & Gadgets

Your Annual Digital Privacy Audit

Laptop, smartphone, notebook and pen arranged on a clean white desk from above

Key Takeaways

  • Most privacy vulnerabilities come from forgotten accounts, weak passwords, and unchecked app permissions.
  • A once-a-year audit is enough for most people to stay meaningfully ahead of common risks.
  • Two-factor authentication is one of the highest-impact steps you can take today.
  • Reviewing connected apps and third-party access is often overlooked but highly effective.
  • Device and browser privacy settings drift over time and need periodic re-evaluation.
45–90 min

Summary

22 items · 45–90 minutes

Why a Privacy Audit Is Worth Your Time

Your digital footprint grows quietly. Every new account you create, every app you grant location access, every browser extension you install adds another surface area that can be exploited — or simply left unattended. Over a year, the average person accumulates dozens of forgotten logins, stale permissions, and outdated recovery settings without realising it.

A structured annual audit takes less than two hours and systematically closes those gaps. It's not about paranoia — it's about maintenance, the same way you'd review a financial account or change a smoke detector battery. If you're new to thinking about privacy in these terms, our foundational guide to online privacy covers the key concepts and why they matter before you start.

This checklist is organised into logical phases so you can work through it section by section, check items off as you go, and return to anything that needs more attention later.

Required

Password Manager

Stores, generates, and audits passwords across all your accounts so you don't rely on memory or reuse.

Required

Authenticator App

Generates time-based one-time codes for two-factor authentication, more secure than SMS codes.

Required

Data Breach Notification Service

Checks whether your email addresses have appeared in known data breaches so you can act quickly.

Optional

Spreadsheet or Checklist App

Tracks your audit progress and notes any follow-up actions that need more time to complete.

The Full Annual Audit Checklist

Work through each group in order. Some items take seconds; others — like reviewing connected apps — may take a few minutes per platform. Don't skip the groups that feel tedious; they're often where the most meaningful exposure lives.

Passwords & Authentication

Audit your password manager (or browser-saved passwords) and replace any duplicated or weak passwords with unique, randomly generated ones. Must
Enable two-factor authentication (2FA) on every account that supports it, prioritising email, banking, and social platforms. Must
Review your 2FA methods and replace SMS-based codes with an authenticator app where possible, as SMS can be intercepted. Should
Download and store 2FA backup codes in a secure, offline location in case you lose access to your primary 2FA device. Should
Update the email address and phone number on recovery options to ensure they are current and accounts you still control. Must

Account Access & Connected Apps

Visit the security settings of your primary email, social media, and cloud storage accounts and revoke access for any apps you no longer use. Must
Check for active sessions — most account security pages list every device and location logged in — and sign out of any you don't recognise. Must
Search for dormant or forgotten accounts using your email address and close any you no longer need, reducing your exposure if that service is breached. Should
Review which apps use 'Sign in with Google' or 'Sign in with Apple' and remove any you no longer actively use. Should

Device & App Permissions

Open your phone's privacy settings and audit location access — set all non-essential apps to 'Never' or 'While Using' rather than 'Always'. Must
Review microphone and camera permissions on your phone and computer, revoking access for any app that doesn't have an obvious need. Must
Check contact, calendar, and photo library access on mobile apps and restrict any app that doesn't genuinely require it. Should
Uninstall apps you haven't used in the past six months — idle apps still hold permissions and may receive data in the background. Should

Browser & Email Settings

Review and remove browser extensions you no longer use, since extensions can read page content and transmit data. Must
Clear stored cookies and site data, then review which sites have persistent exceptions for notifications, location, or camera access. Should
Check your email's filter rules and forwarding settings — attackers who gain brief access often set up silent forwarding that persists after the password is changed. Must
Unsubscribe from marketing lists you no longer want to reduce your email address's exposure and the volume of phishing opportunity. Nice to have

Data Exposure & Breach Checks

Check your email addresses against a reputable data breach notification service to see if your credentials have appeared in known leaks. Must
If any accounts show up in breach results, change those passwords immediately and check whether the same password was reused elsewhere. Must
Search your own name on major search engines to understand what personal information is publicly indexed and whether any of it concerns you. Nice to have

Email Forwarding Is a Silent Threat

One of the most overlooked post-breach attack vectors is silent email forwarding. If an attacker gained access to your email account — even briefly — they may have created a forwarding rule that sends copies of your incoming mail to an address they control. Changing your password stops their login, but it does not remove forwarding rules they've already set. Always verify your email's filters and forwarding settings during every audit.

For a deeper look at the settings behind the items in the device and browser sections, our guide on what device privacy settings actually mean explains each toggle in plain language. And if public networks are part of your routine, see public Wi-Fi habits that put your data at risk for habits worth changing.

After the Audit: Building a Sustainable Habit

Running this checklist once is useful. Running it every year — on the same calendar date — is what keeps your privacy posture consistently strong. Pick a recurring date that's easy to remember: your birthday, the start of a new year, or the anniversary of a major tech event.

Between audits, a few lightweight habits carry most of the ongoing weight. Understanding why passwords alone aren't sufficient protection anymore is a good place to start — our article on why strong passwords alone are no longer enough explains why layering defences matters. For day-to-day browsing, privacy-conscious browsing habits offers grounded practices that fit into your existing routine without major disruption.

If you encounter unfamiliar terms during your audit — fingerprinting, metadata, end-to-end encryption — our plain-language privacy glossary is a quick reference worth bookmarking.

Don't Rely on Breach Checks Alone

Breach notification services only index leaks that have been publicly disclosed. Many breaches are sold privately or discovered months after the fact — so a 'clean' result doesn't guarantee your credentials haven't been exposed. Treat breach checks as a useful signal, not a certificate of safety. Maintaining unique passwords per account means any single leak has limited impact regardless of when it surfaces.

Technology & Gadgets Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Technology & Gadgets Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.