Everyday Privacy
The Beginner's Privacy Checklist (Start Here)
The short version
If you have never thought about your digital privacy, do these seven things in order: check what has already leaked, fix your passwords, turn on two-factor authentication, freeze your credit, lock down your social profiles, join the Do Not Call Registry, and opt out of the biggest data brokers. Every step is free. Start with your email account - it is the master key to everything else - and work down the list one evening at a time.
Why a checklist beats scattered advice
Privacy advice usually arrives as a hundred disconnected tips, so most people do none of them. A short, ordered checklist works better: a handful of high-value moves block most of the real-world harm, and doing them in priority order means every step you finish actually matters.
The stakes are not hypothetical. In 2025 the FTC received about 3 million fraud reports from consumers, who reported a record $15.9 billion in losses - up from $12.5 billion the year before. Most of these scams start with exposed personal data: a leaked password, a public phone number, a profile page listing your address and relatives.
| Year | Fraud reports to the FTC | Reported losses |
|---|---|---|
| 2024 | 2.6 million | $12.5 billion |
| 2025 | 3 million | $15.9 billion |
Source: Federal Trade Commission Consumer Sentinel data, as announced in the FTC's 2025 and 2026 press releases.
You cannot make yourself un-scammable, but you can make yourself a much harder target. That is the entire goal of this list.
Step 1: See what is already exposed
Before fixing anything, find out where you stand. Two things are worth checking: whether your email address has appeared in a known data breach, and which people-search sites publish a profile about you. Both checks are free and take about five minutes.
For breaches, the standard reference is Have I Been Pwned, which currently indexes more than 17.7 billion breached accounts from over 1,000 breached websites. If your email shows up, the breach entry lists what leaked - passwords, phone numbers, addresses - which tells you exactly what to fix first. Our explainer on checking your email against breach data walks through reading those results.
RedactZero's free exposure scan combines both checks: it runs your email against known breaches, looks up a username across public profiles, and lists the data brokers most likely to publish a profile on a US adult. Nothing you scan is stored.
Step 2: Fix your passwords
Reused passwords are the single biggest fixable risk most people have. When one site leaks your password, attackers try that same email-and-password pair everywhere else - banking, email, shopping. A password manager ends this by generating a different strong password for every account, so one breach stays one breach.
Do not try to fix every account in one sitting. Install a reputable password manager, then change passwords on your five most important accounts first: your main email, your bank, your phone carrier, and any account that stores a card number. Work through the long tail over the following weeks as you log in to things naturally.
If you want the full reasoning and setup steps, we cover both tools in our no-nonsense guide to password managers and 2FA.
Step 3: Turn on two-factor authentication
Two-factor authentication (2FA) means a stolen password alone is no longer enough to take over your account. Microsoft's security research found that multi-factor authentication can block over 99.9 percent of automated account compromise attacks - the best return on effort in consumer security.
Turn it on for your email first, then banking, then your phone carrier account. An authenticator app is stronger than text-message codes, because SMS codes can be intercepted if someone hijacks your phone number - but SMS 2FA still beats no 2FA. Most major sites bury the setting under "Security" in account settings, and it takes about two minutes per account.
Step 4: Freeze your credit at all three bureaus
A credit freeze blocks anyone from opening a new credit account in your name, which shuts down the most damaging form of identity theft. Under US federal law, freezing and unfreezing your credit file is free at all three national bureaus: Equifax, Experian, and TransUnion.
You need to place the freeze with each bureau separately, online or by phone. The freeze does not stop you from using your existing cards or accounts - it only blocks new credit checks. When you do want to apply for a loan or card, you lift the freeze; bureaus are required to lift it within one hour for online and phone requests, so it is a minor inconvenience, not a lockout.
If you have already seen suspicious activity, a freeze is step one of a longer response - our checklist on what to do after a data breach covers the rest.
Step 5: Lock down social profiles and delete old accounts
Your public social profiles feed scammers the raw material for convincing phishing and impersonation: birthday, hometown, employer, family names. Set each profile so that only people you accept can see your posts and friend list, and strip your public bio down to what a stranger genuinely needs to see.
Then deal with the accounts you forgot about. Every dormant account from 2012 is a little package of your personal data waiting to appear in the next breach. Search your email inbox for "welcome" and "verify your account" to find old sign-ups, and delete the ones you no longer use.
While you are at it, search your own name in Google and see what comes up - our guide to removing personal info from Google Search covers what you can do about results you do not like.
Step 6: Join the Do Not Call Registry - then cut the source
The National Do Not Call Registry is free, run by the FTC, and takes one minute at donotcall.gov. It stops calls from most legitimate telemarketers. What it does not do is stop scammers, who ignore the registry entirely - so treat it as one layer, not a solution.
The deeper fix is shrinking the number of companies that sell your phone number in the first place. People-search sites and data brokers publish phone numbers openly, and lead-generation databases pass them to whoever pays. That is why the next step on this checklist matters for your phone as much as your privacy. For a layered plan, see our post on stopping spam calls and texts.
Step 7: Opt out of the biggest data brokers
People-search sites like Spokeo and Whitepages publish your name, age, addresses, phone numbers, and relatives where anyone can find them. Every major site has a free opt-out, usually a short form plus an email confirmation, and most verified requests process within 24 to 72 hours.
Start with the sites that rank highest when you search your own name. We keep free, step-by-step opt-out guides for the major brokers, each verified and dated - the Spokeo and Whitepages guides are good first targets because those two are so widely indexed.
Two things to know before you start. First, if you live in California, the state's free DROP platform can send one deletion request to more than 500 registered brokers at once - see our California DROP guide. Second, removals do not stick forever: brokers re-ingest public records constantly, and listings commonly reappear within three to six months. Put a re-check reminder on your calendar every three months and re-file whatever came back.
Not sure where to start?
Run a free exposure scan to see which breaches include your email and which data brokers likely list you - no account, nothing stored. It gives you a personal version of step 1 in about a minute.
Frequently asked questions
What is the single most important privacy step for a beginner?
Securing your main email account with a strong, unique password and two-factor authentication. Your email is the reset button for every other account you own, so protecting it does more than any other single step on this list.
Do I need to pay for anything on this checklist?
No. Breach checks, credit freezes, the Do Not Call Registry, and every major data broker opt-out are free. Good free password managers exist too. Paid tools can save time, but nothing on this checklist requires spending money.
How long does the whole checklist take?
Plan for a few hours spread over a week or two, not one sitting. The breach check takes minutes; moving passwords into a manager is the slowest part. Doing one step per evening is a realistic pace that actually gets finished.
Do I have to lift a credit freeze to apply for a loan?
Yes. A freeze blocks lenders from pulling your credit file, so you must lift it - temporarily or permanently - before applying for new credit. Bureaus must lift a freeze within one hour for online or phone requests, so it is a small chore.
Does the Do Not Call Registry stop scam calls?
No. The registry stops calls from most legitimate telemarketers, but scammers ignore it. To cut scam calls you also need to shrink the number of places that sell your phone number, which mostly means opting out of data brokers.
Is two-factor authentication really worth the hassle?
Yes. Microsoft's security research found that multi-factor authentication can block over 99.9 percent of account compromise attacks. A few extra seconds at login is one of the best trades in all of security.
Why does my data broker listing come back after I opt out?
Data brokers continually re-ingest public records and buy data from each other, so removed listings often reappear within three to six months. Removal works, but it is maintenance - re-check your name every few months and re-file.
What should I do first if my email shows up in a breach?
Change the password on the breached site immediately, and on any other site where you reused that password. Then turn on two-factor authentication for the account. Watch for phishing emails that reference the breached service.
Sources: Federal Trade Commission Consumer Sentinel press releases (2025 fraud data announced 2026; 2024 data announced 2025); USAGov on free credit freezes and the National Do Not Call Registry; Have I Been Pwned (breach counts as of August 2026); Microsoft Security research on multi-factor authentication; California Privacy Protection Agency (DROP). Data broker opt-out and relisting behavior reflects the brokers' own published opt-out processes.