Data privacy is not a product you buy or a setting you flip once. It is a continuous practice—a set of habits, tools, and decisions that you apply to every account, device, and message. This guide walks you through the core actions you can take today, organized by the three stages where privacy is won or lost: before you share, while you store, and when you communicate.
The single most effective privacy technique is to never collect the data in the first place. Every field you fill, every permission you grant, every optional checkbox you leave unchecked is a data point that can be leaked, sold, or subpoenaed.
1. Log into each online account (email, social media, shopping, banking).
2. Go to “Privacy Settings” or “Data & Personalization.”
3. Download your data archive (GDPR/CCPA give you this right) and review what the company holds.
4. Delete any stored payment methods, saved addresses, or browsing history that you no longer need.
5. For accounts you rarely use, export what you want, then delete the account entirely.
When a website asks for your birthdate, ask yourself:Does this service need my exact birthdate, or just to know I’m over 18?If the latter, enter a fake but consistent date (e.g., Jan 1, 1990) and store that in your password manager’s notes.
For phone numbers, use a secondary VoIP number (Google Voice, MySudo) for non-essential signups.
For email addresses, use a plus-alias (yourname+shopping@gmail.com) or a dedicated alias service (SimpleLogin, DuckDuckGo Email Protection). This lets you track which company sold your address and block it later.
Install a browser extension like Privacy Badger or uBlock Origin that blocks tracking scripts by default.
When a cookie banner appears, click “Reject” or “Manage Settings” and turn off all toggles except “Strictly Necessary.”
Use a browser with strong built-in tracking protection (Firefox with Enhanced Tracking Protection set to “Strict,” or Brave). Data privacy fails most often when your files, photos, and documents sit in unencrypted cloud storage or on a device you no longer control.
On your computer: Enable full-disk encryption. On Windows, use BitLocker; on macOS, turn on FileVault. This means that if your laptop is stolen, the hard drive is a brick without your password.
On your phone: Ensure the device lock is a strong PIN (not a pattern) and enable “Erase Data After 10 Failed Attempts.”
For cloud backups: If you use Google Drive, iCloud, or Dropbox, enable “Client-Side Encryption” where available. For true zero-knowledge storage, switch to a provider like Proton Drive or Tresorit—they cannot read your files even if compelled by a court.
1. Choose a reputable manager (Bitwarden, 1Password, KeePassXC).
2. Generate a unique, 16+ character password for every account.
3. Enable two-factor authentication (2FA) on the password manager itself.
4. Store your recovery codes in a physical safe or a sealed envelope—never in the same cloud account you’re protecting.
Keep an external SSD for offline backups, but encrypt it with VeraCrypt before copying files.
For sensitive documents (scans of IDs, tax returns), do not upload them to a general cloud at all. Store them on the encrypted drive only. Your messages, emails, and calls travel through servers you do not control. The goal is to ensure that even if those servers are hacked, the content is unreadable.
Use Signal or WhatsApp for personal chats. Both use the Signal Protocol, which means only the recipient can decrypt the message.
Crucial step: Verify safety numbers (Signal) or encryption codes (WhatsApp) with your contacts when you first meet or after a long gap. Do this in person or via a separate channel (e.g., a phone call). This prevents a man-in-the-middle attack.
Disable cloud backups for these apps, or if you must back up, encrypt the backup with a passphrase that you do not store online.
For sensitive emails, use a service like ProtonMail or Tuta (both have built-in E2E encryption).
If you must stay on Gmail or Outlook, install a browser extension like FlowCrypt (for PGP). However, note that PGP requires both parties to manage keys—a hassle but effective.
Practical tip: Never send credit card numbers, passport scans, or medical records via email. Instead, share them via a secure file transfer like Send (by Firefox) or Proton Drive’s password-protected link, then share the password via a separate channel (e.g., SMS or a phone call).
Use Signal for voice calls—it offers end-to-end encryption by default.
For video conferencing, avoid services that record without consent. Use Jitsi Meet (open-source) or Zoom with “End-to-End Encryption” enabled (requires you to turn it on in settings and set a passcode).
Be aware of metadata: even if the call content is encrypted, the fact that you called a certain person at a certain time is visible to your phone carrier. To hide that, use a VPN on your phone (see below). These are the small, repeatable actions that keep your privacy posture strong.
A VPN encrypts your internet traffic from your device to a server, hiding your IP address and content from your ISP.
Do not use free VPNs—they monetize your data. Use a paid, no-logs provider like Mullvad or ProtonVPN.
Turn on the VPN when using public Wi-Fi (airports, cafés) and when you want to hide your browsing history from your ISP.
Important: A VPN does not make you anonymous. Websites still see your traffic after the VPN server. Use it for encryption, not invisibility.
1. Review your app permissions on your phone. Revoke location, microphone, and camera access for any app that doesn’t strictly need it.
2. Check your Google Account “Security Checkup” and Facebook “Off-Facebook Activity.” Clear all ad-tracking history.
3. Delete old emails with sensitive content (bank statements, medical results) after you’ve downloaded them to your encrypted drive.
4. Rotate the passwords for your most critical accounts (email, banking, password manager) every 90 days.
Create a dedicated browser profile (Firefox or Chrome) used only for online shopping and social media.
Disable all extensions in this profile except a script blocker.
This isolates your shopping history from your work and personal browsing, making it harder for trackers to build a unified profile.
Do not rely on “Incognito Mode.” It only prevents local history, not tracking by websites, your ISP, or your employer.
Avoid using your real phone number for 2FA. If you can, use an authenticator app (Aegis, Google Authenticator) or a hardware key (YubiKey) instead. SMS 2FA is vulnerable to SIM-swapping attacks.
Beware of “free” services that ask for extensive data. If a weather app wants your contacts and location, that is a red flag. Uninstall it.
Do not post photos with location metadata. Turn off GPS tagging in your camera settings, or strip EXIF data before uploading (use a tool like ExifTool).
Never reuse a password across sites. A data breach on one site gives attackers the keys to your email, bank, and social accounts. To put it all together, follow this sequence every time you acquire a new device or start a new account:
1. Encrypt the device (BitLocker/FileVault).
2. Install a password manager and generate a master password of at least 20 characters.
3. Use a VPN