Key Takeaways
- Most privacy vulnerabilities come from forgotten accounts, weak passwords, and unchecked app permissions.
- A once-a-year audit is enough for most people to stay meaningfully ahead of common risks.
- Two-factor authentication is one of the highest-impact steps you can take today.
- Reviewing connected apps and third-party access is often overlooked but highly effective.
- Device and browser privacy settings drift over time and need periodic re-evaluation.
Summary
22 items · 45–90 minutes
Why a Privacy Audit Is Worth Your Time
Your digital footprint grows quietly. Every new account you create, every app you grant location access, every browser extension you install adds another surface area that can be exploited — or simply left unattended. Over a year, the average person accumulates dozens of forgotten logins, stale permissions, and outdated recovery settings without realising it.
A structured annual audit takes less than two hours and systematically closes those gaps. It's not about paranoia — it's about maintenance, the same way you'd review a financial account or change a smoke detector battery. If you're new to thinking about privacy in these terms, our foundational guide to online privacy covers the key concepts and why they matter before you start.
This checklist is organised into logical phases so you can work through it section by section, check items off as you go, and return to anything that needs more attention later.
Password Manager
Stores, generates, and audits passwords across all your accounts so you don't rely on memory or reuse.
Authenticator App
Generates time-based one-time codes for two-factor authentication, more secure than SMS codes.
Data Breach Notification Service
Checks whether your email addresses have appeared in known data breaches so you can act quickly.
Spreadsheet or Checklist App
Tracks your audit progress and notes any follow-up actions that need more time to complete.
The Full Annual Audit Checklist
Work through each group in order. Some items take seconds; others — like reviewing connected apps — may take a few minutes per platform. Don't skip the groups that feel tedious; they're often where the most meaningful exposure lives.
Passwords & Authentication
Account Access & Connected Apps
Device & App Permissions
Browser & Email Settings
Data Exposure & Breach Checks
Email Forwarding Is a Silent Threat
One of the most overlooked post-breach attack vectors is silent email forwarding. If an attacker gained access to your email account — even briefly — they may have created a forwarding rule that sends copies of your incoming mail to an address they control. Changing your password stops their login, but it does not remove forwarding rules they've already set. Always verify your email's filters and forwarding settings during every audit.
For a deeper look at the settings behind the items in the device and browser sections, our guide on what device privacy settings actually mean explains each toggle in plain language. And if public networks are part of your routine, see public Wi-Fi habits that put your data at risk for habits worth changing.
After the Audit: Building a Sustainable Habit
Running this checklist once is useful. Running it every year — on the same calendar date — is what keeps your privacy posture consistently strong. Pick a recurring date that's easy to remember: your birthday, the start of a new year, or the anniversary of a major tech event.
Between audits, a few lightweight habits carry most of the ongoing weight. Understanding why passwords alone aren't sufficient protection anymore is a good place to start — our article on why strong passwords alone are no longer enough explains why layering defences matters. For day-to-day browsing, privacy-conscious browsing habits offers grounded practices that fit into your existing routine without major disruption.
If you encounter unfamiliar terms during your audit — fingerprinting, metadata, end-to-end encryption — our plain-language privacy glossary is a quick reference worth bookmarking.
Don't Rely on Breach Checks Alone
Breach notification services only index leaks that have been publicly disclosed. Many breaches are sold privately or discovered months after the fact — so a 'clean' result doesn't guarantee your credentials haven't been exposed. Treat breach checks as a useful signal, not a certificate of safety. Maintaining unique passwords per account means any single leak has limited impact regardless of when it surfaces.
