Skip to main content
Security Guide

Annual Privacy Checkup: 20-Minute Audit for Your Digital Life (2026)

A step-by-step annual privacy audit. Check your accounts, permissions, data broker listings, and security settings in 20 minutes.

Sarah Chen — Lead Security Editor
Sarah Chen·CISSPCompTIA Security+·Lead Security Editor
Updated
Sarah Chen — Lead Security Editor
Sarah ChenCISSPCompTIA Security+

Lead Security Editor · San Francisco, CA

Updated Editorial policy
Editor's picks

Our Recommended VPNs

Chosen after real-world testing across speed, privacy, and streaming. Each ranking is independent — we buy every VPN at retail and test it ourselves.

EDITOR'S PICK
NordVPN logo
Best Overall
NordVPN
4.8/ 5

Fastest speeds, audited no-logs, 6000+ servers

Audited no-logs policyThreat Protection blocks malware10 devices per account30-day money-back guarantee
Save 74%
was $12.99/mo
$3.39/mo
Get NordVPN
30-day money-back guarantee
Read full NordVPN review
Surfshark logo
Best for Unlimited Devices
Surfshark
4.6/ 5

Unlimited devices, CleanWeb blocker, 100+ countries

Unlimited simultaneous devicesCleanWeb ad & malware blockerRAM-only server network30-day money-back guarantee
Save 87%
was $15.45/mo
$1.99/mo
Get Surfshark
30-day money-back guarantee
Read full Surfshark review
Proton VPN logo
Best for Privacy
Proton VPN
4.5/ 5

Swiss privacy laws, open-source, free tier

Swiss jurisdiction (no data laws)Open-source and auditedSecure Core multi-hopFree tier available forever
50% off
was $9.99/mo
$4.99/mo
Get Proton VPN
30-day money-back guarantee
Read full Proton VPN review
FastestVPN logo
Best Budget
FastestVPN
4.2/ 5

Lifetime plans, 10 devices, ad blocker

Lifetime deal available10 devices per accountBuilt-in ad blockerNo-logs policy
Save 89%
was $10/mo
$1.11/mo
Get FastestVPN
30-day money-back guarantee
Read full FastestVPN review

We earn a commission when you click “Get” buttons, at no extra cost to you. Read our affiliate disclosure

3 min read

Why Do an Annual Privacy Checkup?

Privacy settings change. Apps update permissions. New data breaches occur. Services you forgot about still hold your data. An annual checkup catches privacy drift before it becomes a problem.

Set a calendar reminder and run through this checklist once a year (or quarterly if you handle sensitive data).

Minute 1-5: Account Security Audit

Check for Breaches

  1. Visit haveibeenpwned.com
  2. Enter ALL your email addresses
  3. For any new breaches: change the password, enable 2FA

Password Manager Health

  1. Open your password manager's health/audit report
  2. Fix reused passwords (most critical)
  3. Fix weak passwords
  4. Remove accounts you no longer use

2FA Audit

  1. Review which accounts have 2FA enabled
  2. Enable 2FA on any accounts that support it but don't have it
  3. Migrate SMS 2FA to authenticator app where possible
  4. Verify backup codes are still accessible

Minute 5-10: App & Permission Audit

Phone Permissions

  1. iOS: Settings > Privacy & Security — review each category (Location, Camera, Microphone, Photos)
  2. Android: Settings > Privacy > Permission manager
  3. Revoke permissions for apps that don't need them
  4. Delete apps you haven't used in 6+ months

Connected Apps

  1. Google: myaccount.google.com/permissions — revoke old apps
  2. Apple: Settings > [Name] > Sign-In & Security > Sign In with Apple
  3. Facebook: Settings > Apps and Websites — remove everything unused
  4. GitHub: Settings > Applications > Authorized OAuth Apps
  5. Microsoft: account.microsoft.com/privacy

Browser Extensions

  1. Review installed extensions
  2. Remove anything you don't actively use
  3. Target: 3-5 extensions maximum

Minute 10-15: Data Broker Opt-Out

Data brokers collect and sell your personal information. Opt out annually:

  1. Google yourself — see what's publicly available
  2. Common brokers to opt out of:
    • Spokeo, WhitePages, BeenVerified, Intelius, PeopleFinder
    • Use justdelete.me for direct links to account deletion pages
  3. Automated services: DeleteMe ($129/year) handles opt-outs for you
  4. Google Search: Request removal of personal info via Google's removal tool

Minute 15-20: Network & Device Audit

VPN Check

  1. Verify VPN is installed and auto-connect is enabled
  2. Run a DNS leak test (dnsleaktest.com)
  3. Check kill switch is active
  4. Verify you're on the latest VPN app version

Device Security

  1. Check OS is up to date
  2. Verify disk encryption is enabled (BitLocker/FileVault)
  3. Verify Find My Device is active
  4. Check auto-lock is set to 2 minutes or less
  5. Review Bluetooth and Wi-Fi connections — forget old networks

Router

  1. Check router firmware is updated
  2. Verify Wi-Fi encryption is WPA3 or WPA2-AES
  3. Review connected devices — remove unknowns
  4. Verify admin password isn't default

After the Checkup

Schedule your next checkup (set a calendar reminder for 12 months).

Document any changes you made so you can track your privacy posture over time.

Found this helpful?

Share it with someone who needs it

Continue learning

Related Guides