Online privacy is your ability to control how your personal information is collected, used, stored, shared and inferred when you use the internet. It covers information you provide directly, such as your name and email address, and data created by your activity, including browsing history, location, device details and purchasing behaviour. The data lifecycle has 6 stages, from collection through deletion or access. A 2021 Federal Trade Commission guide also explains that companies may collect information about people's habits, activities and locations, then share it with other companies or data brokers.
Online privacy does not mean complete anonymity. It means having clear information about data practices and some control over what happens to information about you.
Online Privacy at a Glance
| Question | Answer |
|---|---|
| What does online privacy protect? | Personal information, online activity, communications, location, account details and digital profiles |
| Who can affect it? | Websites, apps, advertisers, data brokers, internet providers, employers and other organisations |
| What is the main risk? | Information may be collected, combined, shared or used in ways you did not expect |
| Is privacy the same as security? | No. Security protects information from unauthorised access. Privacy concerns how information is collected and used |
| Can online privacy be guaranteed? | No, but you can reduce unnecessary collection, tracking and exposure |
What Information is Covered by Online Privacy?
Online privacy covers more than passwords and credit card numbers. It can include:
- Your name, email address, phone number and postal address
- Login details and account identifiers
- Browsing history, searches and clicks
- IP address, device information and approximate location
- Photos, videos, messages and documents
- Purchases, payment details and shopping habits
- Health, biometric, employment and financial information
- Information inferred about your interests, behaviour or relationships
A website or app may combine several types of information to build a profile about you. For example, a shopping app could combine your searches, location, purchases and device information to personalise advertising or recommendations.
The FTC says companies may collect information about people's habits, tastes, activities and locations. They may also share that information with other companies or data brokers.
How Does Online Privacy Work?
Online privacy depends on what happens to personal information throughout its lifecycle:
- Collection: A website, app or device gathers information about you.
- Storage: The organisation keeps that information in databases or cloud systems.
- Processing: Software analyses the information to provide services, personalise content or make decisions.
- Sharing: The organisation may disclose information to service providers, advertisers, affiliates, authorities or data brokers.
- Retention: The organisation keeps the information for a set period, which may be longer than users expect.
- Deletion or access: Depending on the service and applicable law, you may be able to view, correct or delete some information.
Privacy can be affected even when nobody breaks into a system. An organisation might protect its databases from hackers while collecting more information than necessary or using it in ways that surprise users.
NIST distinguishes privacy risk from cybersecurity risk because privacy problems can result from the intentional collection, processing and sharing of information, not only from data breaches.
What is the Difference Between Online Privacy and Online Security?
Online security protects information and systems from unauthorised access, damage or theft. Online privacy governs how information about people is collected, used and shared.
The two concepts overlap, but they address different questions.
| Online privacy | Online security |
|---|---|
| Controls how personal data is collected and used | Protects data from hacking and unauthorised access |
| Concerns consent, transparency and data minimisation | Concerns passwords, encryption, access controls and malware protection |
| Asks, "Should this organisation collect and use this information?" | Asks, "Can an unauthorised person access this information?" |
| Can be violated through excessive or unexpected data use | Can be violated through a breach or account takeover |
For example, an app may have strong security but request continuous location access when it only needs location occasionally. That is a privacy problem even if no hacker obtains the location data.
Why Does Online Privacy Matter?
Online privacy matters because personal information can affect your safety, finances, reputation, autonomy and ability to make independent choices.
Poor privacy practices can contribute to:
- Identity theft and account fraud
- Targeted scams and phishing
- Unwanted advertising and persistent tracking
- Exposure of sensitive location or relationship information
- Discrimination based on inferred characteristics
- Harassment, stalking or doxxing
- Manipulative content or pricing
- Loss of control over personal photos, messages or documents
A data breach is only one type of privacy risk. Harm can also occur when information is inaccurate, kept longer than necessary, combined with other datasets or used for a purpose the individual did not reasonably expect.
NIST identifies privacy risks involving personal autonomy, dignity, emotional distress and loss of trust, including situations where information was disclosed with some form of authorisation.
What are Common Examples of Online Privacy Risks?
Cookies and Online Tracking
Cookies and similar technologies can remember logins, measure behaviour and track activity across websites. Some tracking supports useful features. Other tracking helps build advertising profiles.
Mobile App Permissions
An app may request access to your contacts, camera, microphone, files or location. The key questions are whether the permission is necessary, how often the app uses it and who receives the resulting data.
Data Brokers
Data brokers collect information from public records, commercial sources and online activity. They may combine those records into profiles and provide the profiles to other businesses.
Social Media Oversharing
Public posts can reveal your home location, daily routine, family relationships, travel plans or workplace. Another person may copy or archive content even after you delete it.
Connected Devices
Smart speakers, televisions, watches, cameras, cars and home appliances can generate information about behaviour, movement and usage. Privacy depends on the device settings, the manufacturer's data practices and the organisations receiving the data.
Privacy Policies
A privacy policy explains how a service says it collects, uses, shares and retains information. These policies can be long, so focus on the sections covering:
- Data collection
- Third parties
- Advertising
- Retention
- Deletion
- User choices
The FTC recommends checking a website's privacy policy or terms before deciding whether to use a service.
How Can You Protect Your Online Privacy?
No single tool provides complete privacy. A practical approach combines safer account habits, limited sharing and regular checks of app, browser and device settings.
1. Share Less Personal Information
Do not provide optional information simply because a form requests it. Avoid publicly posting your address, travel plans, identification documents, workplace details or real-time location.
2. Review App Permissions
Check which apps can access your location, camera, microphone, contacts, photos and files. Disable permissions you do not need. Where available, choose one-time or limited location access.
3. Use Strong Passwords and Multifactor Authentication
Use a different password for every important account. A password manager can help create and store unique passwords.
Enable multifactor authentication for email, banking, social media and other accounts containing sensitive information.
4. Adjust Browser and Device Privacy Settings
Review cookie controls, advertising settings, location access, microphone permissions and tracking preferences. These controls may reduce data collection, although they cannot prevent every form of tracking.
5. Limit Targeted Advertising and Data Broker Exposure
Use available opt-out tools for targeted advertising and data broker listings. The options vary by service and location.
The FTC identifies advertising controls and data broker opt-outs as practical privacy measures.
6. Secure Your Accounts and Devices
Keep operating systems, browsers and apps updated. Use a screen lock, install software from reputable sources and avoid entering sensitive information on suspicious websites or through unexpected links.
7. Use Secure Connections Carefully
When shopping or banking, check that the site uses HTTPS. HTTPS helps protect information while it travels between your browser and the website. It does not stop the website from collecting information about your visit.
CISA recommends using HTTPS sites for sensitive online activities.
8. Delete Unused Accounts and Old Data
Unused accounts can retain personal information and become targets if the service is breached. Delete accounts you no longer need. Remove old posts, files and connected devices where practical.
Does Private Browsing Protect Your Online Privacy?
Private browsing mainly limits what your browser stores on your device. It does not make you anonymous online.
Private or incognito browsing may prevent the browser from retaining some local history, cookies or form data after the session ends. Websites, internet providers, employers, schools and other network operators may still be able to observe or log activity, depending on the connection and service.
A virtual private network, or VPN, can change which network sees your connection and can encrypt traffic between your device and the VPN server. It does not prevent the websites or apps you use from collecting information. It also shifts trust to the VPN provider.
Privacy tools reduce particular types of exposure. They do not provide complete anonymity.
What is the Simplest Definition of Online Privacy?
Online privacy is the right and practical ability to decide what personal information you reveal online, who can access it, how it is used and how long it is kept.
For individuals, protecting online privacy means limiting unnecessary data collection, checking permissions, reviewing important privacy settings and choosing services that explain their data practices clearly.
Organisations also have responsibility for managing privacy risks through appropriate collection, use, sharing, retention and protection practices. NIST's Privacy Framework helps organisations identify and manage those risks.