Why Do an Annual Privacy Checkup?
Privacy settings change. Apps update permissions. New data breaches occur. Services you forgot about still hold your data. An annual checkup catches privacy drift before it becomes a problem.
Set a calendar reminder and run through this checklist once a year (or quarterly if you handle sensitive data).
Minute 1-5: Account Security Audit
Check for Breaches
- Visit haveibeenpwned.com
- Enter ALL your email addresses
- For any new breaches: change the password, enable 2FA
Password Manager Health
- Open your password manager's health/audit report
- Fix reused passwords (most critical)
- Fix weak passwords
- Remove accounts you no longer use
2FA Audit
- Review which accounts have 2FA enabled
- Enable 2FA on any accounts that support it but don't have it
- Migrate SMS 2FA to authenticator app where possible
- Verify backup codes are still accessible
Minute 5-10: App & Permission Audit
Phone Permissions
- iOS: Settings > Privacy & Security — review each category (Location, Camera, Microphone, Photos)
- Android: Settings > Privacy > Permission manager
- Revoke permissions for apps that don't need them
- Delete apps you haven't used in 6+ months
Connected Apps
- Google: myaccount.google.com/permissions — revoke old apps
- Apple: Settings > [Name] > Sign-In & Security > Sign In with Apple
- Facebook: Settings > Apps and Websites — remove everything unused
- GitHub: Settings > Applications > Authorized OAuth Apps
- Microsoft: account.microsoft.com/privacy
Browser Extensions
- Review installed extensions
- Remove anything you don't actively use
- Target: 3-5 extensions maximum
Minute 10-15: Data Broker Opt-Out
Data brokers collect and sell your personal information. Opt out annually:
- Google yourself — see what's publicly available
- Common brokers to opt out of:
- Spokeo, WhitePages, BeenVerified, Intelius, PeopleFinder
- Use justdelete.me for direct links to account deletion pages
- Automated services: DeleteMe ($129/year) handles opt-outs for you
- Google Search: Request removal of personal info via Google's removal tool
Minute 15-20: Network & Device Audit
VPN Check
- Verify VPN is installed and auto-connect is enabled
- Run a DNS leak test (dnsleaktest.com)
- Check kill switch is active
- Verify you're on the latest VPN app version
Device Security
- Check OS is up to date
- Verify disk encryption is enabled (BitLocker/FileVault)
- Verify Find My Device is active
- Check auto-lock is set to 2 minutes or less
- Review Bluetooth and Wi-Fi connections — forget old networks
Router
- Check router firmware is updated
- Verify Wi-Fi encryption is WPA3 or WPA2-AES
- Review connected devices — remove unknowns
- Verify admin password isn't default
After the Checkup
Schedule your next checkup (set a calendar reminder for 12 months).
Document any changes you made so you can track your privacy posture over time.
Related Guides
10 Secure Browsing Habits Every Remote Worker Should Build (2026)
Simple daily habits that dramatically reduce your risk. HTTPS checking, URL verification, download safety, and more.
Sarah ChenSecure Job Searching: Protect Your Privacy While Looking for Work (2026)
Job searching exposes your personal data to recruiters, job boards, and potential scammers. How to search safely while protecting your identity.
Sarah ChenVPN for Accountants & CPAs: Protect Financial Client Data (2026)
Accountants handle the most sensitive financial data. VPN setup for tax season security, client portal access, and IRS compliance.
Sarah ChenWas this guide helpful?
Advertisement
Ready to Get Protected?
Take the next step in securing your remote work setup.