Online privacy is best protected by using several layers of protection. This guide covers 10 steps, from securing your email and banking accounts to removing your details from people-search websites. It draws on guidance from the FTC, CISA, NIST, Apple, Android and Google, including CISA's September 2024 phishing tip sheet.

  1. Secure your email, banking and recovery accounts with unique passwords or passkeys.
  2. Turn on multifactor authentication.
  3. Keep your devices, apps and browser updated.
  4. Review app permissions and location access.
  5. Limit advertising and cross-site tracking.
  6. Share less personal information publicly.
  7. Treat unexpected links, attachments and urgent messages as suspicious.
  8. Secure your home Wi-Fi and use public networks carefully.
  9. Remove your information from people-search and data-broker websites.
  10. Act quickly after a breach or suspected account takeover.

Online privacy and online security are related, but they are not the same. Privacy controls how much information companies, apps and websites collect about you. Security helps prevent criminals from accessing information that is already online.

Online Privacy Protection at a Glance

Priority What to do Why it matters
Highest Secure your email, banking and primary accounts These accounts can expose or reset other accounts
Highest Use passkeys, security keys or an authenticator app These methods provide stronger protection than a password alone
High Install automatic software updates Updates often fix security weaknesses
High Review app permissions and location access Apps may not need ongoing access to sensitive data
High Avoid unexpected links and attachments Phishing can steal passwords and personal information
Medium Use browser tracking protection It reduces cross-site tracking and profiling
Medium Remove your information from people-search sites It limits public access to addresses, phone numbers and relatives
Situational Use private browsing or a VPN for the right purpose These tools have specific benefits but do not make you anonymous

1. Protect Your Email, Banking and Recovery Accounts First

Start with the accounts that contain the most sensitive information:

  • Primary email
  • Online banking and payment services
  • Cloud storage
  • Government and tax accounts
  • Mobile phone account
  • Social media accounts
  • Password manager

Your primary email account needs particular attention because it may be used to reset passwords for other services. The Federal Trade Commission recommends strong, unique passwords and two-factor authentication for accounts containing personal and financial information.

Use a Password Manager or Passkeys

Use a password manager to generate and store a different password for every account. If you create a password yourself, make it long and unique. The FTC recommends aiming for at least 15 characters, while CISA recommends long, random and unique passwords.

Choose a passkey or physical security key when a service supports one. Passkeys use a device-based cryptographic credential instead of a reusable password. NIST says passkeys can resist common forms of phishing-based password theft, and CISA identifies FIDO security keys and passkeys as phishing-resistant authentication methods.

Turn on Multifactor Authentication

Use the strongest available MFA method in this order:

  1. Passkey or physical security key
  2. Authenticator app
  3. Number-matching push notification
  4. SMS or email verification code

SMS and email codes are better than no MFA, but CISA describes security keys as the strongest option and text or email codes as weaker alternatives.

Never share a verification code with someone who contacts you unexpectedly. Legitimate support staff should not need you to read an MFA code to them.

2. Keep Every Device and App Updated

Turn on automatic updates for:

  • Operating systems
  • Web browsers
  • Mobile apps
  • Password managers
  • Security software
  • Home routers, where supported

Software updates often include patches for vulnerabilities that criminals could exploit. The FTC and CISA both recommend installing updates promptly or enabling automatic updates.

Protect the device itself with a strong screen lock, biometric authentication and automatic locking. Do not leave an unlocked phone or computer unattended, especially if it contains saved passwords, email or financial information.

3. Review App Permissions and Location Access

Many apps request access to information they do not need for their core function. Review permissions for:

  • Location
  • Camera
  • Microphone
  • Contacts
  • Photos
  • Calendar
  • Bluetooth
  • Local network
  • Health or fitness data

On iPhone, go to Settings > Privacy & Security to review location, tracking and app permissions. You can turn off Precise Location or allow an app to access your location only while you are using it.

On Android, use Settings > Security & Privacy > Privacy dashboard or Permission manager to see which apps accessed sensitive permissions and when. Android also lets you limit location access to "only while using the app" or "ask every time."

Delete apps you no longer use. An unused app may still retain account access, permissions or stored personal information.

4. Reduce Advertising and Cross-Site Tracking

Websites and apps may collect information about your browsing, interests, device and activity across services. To reduce tracking:

  • Enable your browser's tracking protection.
  • Block or limit third-party cookies.
  • Reject unnecessary advertising and analytics consent.
  • Disable personalised advertising where appropriate.
  • Turn off app tracking requests on iPhone.
  • Review advertising privacy settings on Android.
  • Use separate browser profiles for work, personal browsing and sensitive activities.

Safari includes protections against cross-site tracking. Firefox includes Enhanced Tracking Protection and Total Cookie Protection. These features reduce the ability of third-party trackers to follow you between websites.

On iPhone, App Tracking Transparency lets you prevent apps from tracking activity across other companies' apps and websites. On Android, advertising privacy controls can limit ad topics, app-suggested ads and ad measurement.

Private Browsing Is Not Anonymity

Private or Incognito mode mainly prevents browsing history, cookies and form data from being retained on your device after the session ends. It does not prevent websites, your employer, school or internet service provider from observing activity.

Use private browsing on a shared computer, but do not treat it as a complete privacy tool.

5. Share Less Personal Information

Before submitting information online, ask whether the service genuinely needs it.

Avoid posting these details publicly:

  • Home address
  • Personal phone number
  • Full date of birth
  • Travel dates and live location
  • Government identification numbers
  • Financial information
  • Security-question answers
  • Photos showing documents, tickets or visible addresses

Make social media accounts private where practical. Limit who can see older posts and remove followers you do not know.

Do not use real information for security-question answers when a service lets you create your own answers. Treat those answers like additional passwords.

Use email aliases or a secondary email address for newsletters, shopping sites and services that do not need your primary address.

6. Recognise Phishing and Impersonation Scams

Phishing messages try to make you click a link, open an attachment or reveal personal information. Common warning signs include:

  • Unexpected account alerts
  • Urgent threats or deadlines
  • Requests for passwords or verification codes
  • Unusual sender addresses
  • Shortened or mismatched links
  • Unexpected attachments
  • Offers that seem too good to be true

Do not use the link or phone number in a suspicious message. Open the company's official app or type its known website address yourself. CISA recommends verifying the sender and reporting suspicious messages instead of responding to them.

A website can use HTTPS and still be a scam. HTTPS encrypts the connection to the site, but it does not prove that the website operator is trustworthy.

7. Secure Your Home Wi-Fi and Use Public Networks Carefully

For your home network:

  • Change the router's default administrator password.
  • Use WPA2 or WPA3 encryption.
  • Install router firmware updates.
  • Use a separate guest network for visitors and smart-home devices.
  • Disable remote administration unless you need it.

On public Wi-Fi, use websites and apps that encrypt traffic. Check for HTTPS, and avoid entering sensitive information into unfamiliar websites.

The FTC says public Wi-Fi is usually safer than it was in the past because most websites use encryption. Fake websites can still steal information that you submit, however.

8. Remove Your Information From People-Search Websites

People-search websites and data brokers can compile information from public records, social media and other commercial sources. Reports may include addresses, phone numbers, relatives, employment history and property records.

To reduce your exposure:

  1. Search for your name, phone number and address.
  2. Find each site's opt-out or removal process.
  3. Submit the request using the site's instructions.
  4. Repeat the process on other people-search websites.
  5. Check again periodically because information can reappear.

Opting out does not remove information from public government records. Your details may also appear in another person's report.

The FTC warns that paid removal services differ in how many websites they cover and how often they rescan for new listings.

9. Back Up Important Data

Back up photos, documents, contacts and other important files to a trusted backup service or external drive. Keep at least one backup separate from your main device.

Backups do not stop tracking or account theft. They can reduce the damage caused by device loss, malware or ransomware. The FTC includes backups among its basic recommendations for protecting computers and phones.

10. Act Quickly After a Breach or Hacked Account

If an account may have been compromised:

  1. Change the password immediately.
  2. Change the same or similar password anywhere else it was used.
  3. Sign out of other sessions and devices.
  4. Turn on MFA.
  5. Check recovery email addresses and phone numbers.
  6. Review email forwarding rules and recent account activity.
  7. Contact your bank if financial information may be exposed.
  8. Visit IdentityTheft.gov if someone is using your identity.

If your Social Security number or other identity information was exposed, a free credit freeze can make it harder for someone to open new credit accounts in your name. The FTC says credit freezes are free, do not affect your credit score and can be placed with Equifax, Experian and TransUnion.

The Most Important Privacy Actions to Take Today

If you only have 30 minutes, start here:

  1. Secure your email account with a unique password and MFA.
  2. Turn on automatic updates for your phone, computer and browser.
  3. Review location, camera and microphone permissions.
  4. Enable browser tracking protection and disable unnecessary ad personalisation.
  5. Search for your name and phone number on people-search websites, then submit removal requests.

These steps will not make you anonymous. They reduce the amount of information available about you, make account takeover harder and give phishing messages fewer opportunities to work.