Online privacy checklist

Online privacy checklist

Elena Ross
April 5, 2026· Updated April 27, 2026· 4 min read

This online privacy checklist is not about turning you into a security expert. It is about using 30 minutes to close the most common data exposure points: reused passwords, missing MFA, overbroad app permissions, browser tracking, public Wi-Fi, and old accounts. The FTC and CISA both treat strong passwords, multi-factor authentication, software updates, and phishing awareness as personal security basics.[1][2]

If you only have time for one high-impact cleanup, follow the order below. For the bigger picture, read the digital privacy guide.

Online privacy checklist step 1: lock down your main email in 0-5 minutes

Your main email is the recovery entry point for most accounts. Give it a unique strong password first, then enable MFA. Prefer an authenticator app, passkey, or hardware security key.

If your main email is taken over, an attacker can reset passwords for banking, social media, shopping, and cloud storage. Do not start with a small app. Start with email.

5-10 minutes: fix reused passwords

Open your password manager or browser password check tool and find reused, weak, and leaked passwords. NIST's digital identity guidance also emphasizes that compromised passwords should not keep being used.[3]

Prioritize these accounts:

  • Email;
  • Apple ID / Google account;
  • Payments and banking;
  • Cloud storage;
  • Social media;
  • Work accounts.

10-15 minutes: clean up app permissions

Start with location, photos, contacts, microphone, camera, and local network access. Change unnecessary "always allow" permissions to "allow while using" or "ask."

If you have not used an app for three months, delete it. Permission management is not only about toggles; removing unused access points is cleaner. For details, read the app permission risks checklist.


15-20 minutes: reduce browser tracking

Check your browser settings:

  • Block third-party cookies;
  • Delete extensions you do not use;
  • Enable HTTPS-Only mode;
  • Turn off unnecessary ad personalization;
  • Clear site data you no longer need;
  • Use a more privacy-focused search tool for sensitive searches.

The browser is where a lot of website tracking happens. Incognito mode is not invisibility; it mainly reduces local history. For the boundaries, read is private browsing really private?.

20-25 minutes: reduce public Wi-Fi risk

Turn off automatic connection to open networks. In hotels, airports, coffee shops, and malls, connect to a VPN before logging in to email, payments, work systems, or cloud storage.

A VPN cannot identify phishing websites for you, but it can reduce the connection details visible to the local network and ISP. For more, read about public Wi-Fi risks.

25-30 minutes: delete old accounts and old authorizations

Search your inbox for phrases like "welcome," "verification code," and "reset password" to find services you no longer use. Delete old accounts, revoke third-party sign-in grants, and clean up public profiles and old cloud links.

Old accounts are troublesome because you forget them, but they may still store your email address, phone number, birthday, address, or order history.

Review these 5 things every month

ItemFrequencyGoal
Password breach alertsMonthlyFind reused and leaked passwords
App permissionsMonthlyRemove overbroad access
Browser extensionsMonthlyDelete suspicious extensions
Old accountsQuarterlyReduce long-term exposure
Router and system updatesMonthlyPatch known vulnerabilities

Summary

  • The online privacy checklist order is: main email, passwords, MFA, permissions, browser, network, old accounts.
  • Protect high-value accounts first instead of spending energy on low-risk settings.
  • VPNs, password managers, MFA, and permission cleanup complement each other.
  • Thirty minutes cannot solve every privacy issue, but it can sharply reduce common risks.

FAQ

Is 30 minutes really enough?

It is enough for the first high-impact cleanup. Deep account deletion and data broker removals may take longer.

Which account should I protect first?

Your main email. It is usually the password reset entry point for other accounts.

Is SMS MFA acceptable?

SMS is better than nothing, but authenticator apps, passkeys, or hardware security keys are better for core accounts.

Should I keep my VPN on all the time?

Use it on public Wi-Fi, in hotels, at airports, and on untrusted networks. On a trusted home network, you can decide based on your needs.

Do I need to buy many tools for privacy cleanup?

No. Start with built-in system settings, a password manager, MFA, and browser privacy options. That already gives you a strong return.


Disclaimer: This article provides general privacy guidance and does not guarantee complete anonymity or removal of all data collection.

AethoVPN can handle the network path in “Online privacy checklist”, but not its non-network requirements.

Sources

[1]FTC — How to protect your privacy online: https://consumer.ftc.gov/articles/how-protect-your-privacy-online [2]CISA — Secure Our World: https://www.cisa.gov/secure-our-world [3]NIST — Digital Identity Guidelines, SP 800-63B: https://pages.nist.gov/800-63-3/sp800-63b.html

Sources checked 8 May 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

Online privacy checklist | AethoVPN