Summary. Highest value first.
Part 1 — The two hours (do this before anything else)
Freeze credit — free, and the single most effective anti-fraud step:
- Equifax
- Experian
- TransUnion
Freeze the specialty agencies — where account fraud actually happens, and almost nobody freezes them:
- Check and bank account screening service
- Telecom and utility payment database
- Insurance claims history database
- Employment and tenant screening agencies that offer freezes
Lock the mobile account — this defeats SIM swapping:
- Port-out PIN or account passcode added
- Asked what is required to port the number or change the SIM; strongest option selected
- Confirmed who else is authorized on the account
Secure the email account — it is the master key to everything:
- Unique, long password in a password manager
- Two-factor with an authenticator app or hardware key — not text messages
- Recovery email, recovery phone, and trusted contacts reviewed and updated
- Connected apps reviewed; unused ones removed
- Active sessions and trusted devices reviewed; unfamiliar ones signed out
Then:
- Password manager set up; unique passwords for financial, email, and personal-data accounts
- Two-factor on financial, email, social, cloud storage, and the carrier account
- Screen lock and full-disk encryption on every device
- App permissions reviewed — location, contacts, microphone, camera, photos; location set to "while using" or off
- Ad identifier turned off or reset
- Location history reviewed; stored history deleted if unwanted
- Pre-screened credit offers opted out of
- National do-not-call registration
Part 2 — Access audit (who already has the keys)
Family or group location sharing
Shared cloud photo libraries and albums
Shared cloud storage and documents
Recovery and trusted contacts on every account
Mobile plan owner — can see call and text metadata, often location
Smart home administrators — door logs, camera history, assistant history
Vehicle telematics and connected car apps
Streaming and subscription profiles
Shared financial accounts and authorized users
Password manager shared vaults
Old devices given away or still held by someone
Work devices and work profiles on personal phones
Anyone who knows a password you have not changed
Everything that should not be there, removed
STOP — one exception: if a current or former partner who has been abusive may be monitoring you, do not change anything yet. Go to Part 6 first.
Part 3 — Find and remove yourself
Find:
- Full name searched in two or more engines
- Name + city, name + former city, name + employer
- Images tab checked
- Phone number and email address searched
- Family members' names searched — their profiles often list your address
- Everything screenshotted with URL and date BEFORE removal
Remove:
- Opted out of each people-search site found
- Spreadsheet kept: site · opt-out URL · date submitted · confirmation · re-check date
- State data broker registry checked — the closest thing to a complete target list
- Statutory deletion and opt-out requests sent if your state has a comprehensive privacy law
- Search engine removal requests for contact info, government ID numbers, financial account numbers, medical records, non-consensual intimate imagery
- Re-check calendared for six months — profiles come back; that is expected
If safety is the concern:
- State address confidentiality program enrolled — a substitute address addresses the source, not just the republication
- PO box or commercial mail address for anything that becomes public
- Family members asked to lock down their profiles
- Own posts audited for home, routine, workplace, children's school
- Photo location metadata checked
Part 4 — Get and fix your consumer reports
Pull all of them:
- Three nationwide credit reports
- Tenant screening reports — the ones that decide housing
- Employment screening report
- Check and bank account screening report
- Insurance claims history report
- Medical information exchange report
- Utility and telecom payment report
- Gig platform screening report
- Full file disclosure requested, not a score — should show sources and recipients
Read for:
- Accounts, addresses, or employers that are not yours — a mixed file with a similar name is the most common serious error
- Eviction filings that were dismissed or belong to someone else
- Criminal records that should have aged off — 15 U.S.C. § 1681c
- Duplicate accounts
- Wrong balances, dates, statuses
- Inquiries you did not authorize — 15 U.S.C. § 1681b limits who may obtain a report
Dispute:
- In writing to the agency, under 15 U.S.C. § 1681i
- Each item identified, reason stated, proof attached
- Also disputed directly with the furnisher
- Sent certified, return receipt; everything kept
- Written result received within the reinvestigation period
- If not corrected: disputed again with new evidence · complaint to the federal consumer financial regulator · lawyer consulted (the statute provides attorney's fees)
If denied housing, employment, credit, or insurance:
- Asked which company provided the report — you are entitled to know
- Free copy obtained
- For employment: standalone written disclosure and authorization were required beforehand, and a pre-adverse action notice with a copy of the report was required before rejection — absence of either is itself a violation
- Disputed, then decision-maker asked to reconsider with the corrected report
Part 5 — Send the requests that carry deadlines
- Determined whether your state has a comprehensive privacy law
To companies that matter:
- Right to know / access
- Right to delete
- Right to correct
- Opt out of sale and of sharing for targeted advertising
- Limit use of sensitive personal information, where available
- Universal opt-out signal enabled in the browser, where your state requires it be honored
Other access requests:
- Federal agency records — access and amendment under 5 U.S.C. § 552a; request under both the Privacy Act and the freedom of information statute
- Personnel file from your employer, where state law provides it
- Medical records — complete designated record set, not a summary
- Education records, and directory information opted out of for your children
- Financial privacy sharing opt-out from the annual notice (16 C.F.R. Part 313)
- Telecom customer information restrictions with your carrier (47 U.S.C. § 222)
What makes them work:
- Specific scope — "all records" invites refusal for overbreadth
- Identity verified exactly as instructed — most refusals are verification failures
- Statutory deadline stated
- Sent with proof; logged
- Second request sent when the deadline passes, referencing the first
Part 6 — If someone may be monitoring you
If there is ANY history of violence, threats, or control:
- Domestic violence advocate contacted BEFORE changing anything — abrupt loss of access can escalate danger
- Research and calls made from a device the person has never accessed
- Documented before removing — screenshots of sharing settings, account access, and messages showing knowledge they should not have
- Technology safety program asked about — specialized ones exist and are free
- Protective order considered — most states expressly cover electronic harassment and stalking
If there is no safety concern, in this order:
- Email password and every recovery method first
- Unintended trusted and recovery contacts removed
- Family and location sharing disabled
- Moved to your own mobile account with a port-out PIN
- Cloud photo libraries and storage unshared
- Smart home and vehicle app administrators removed
- Financial credentials changed; authorized users removed
- Signed out of all sessions everywhere
Devices:
- Unfamiliar apps, profiles, and device management or configuration profiles checked for
- Battery and data usage checked for unexplained consumption
- Operating system updated — updates commonly remove monitoring software
- Factory reset considered after documenting, and not restored from a backup that may carry the software
- Vehicle checked for tracking devices
- Smart home devices, cameras, and shared displays checked
Part 7 — Breach and identity theft
Breach notice:
- What data was involved read carefully — the response differs by data type
- Credit frozen at all three bureaus
- Specialty agencies frozen
- Password changed there and anywhere reused
- Two-factor turned on there
- Offered monitoring accepted, but not treated as a substitute for a freeze
- Alert set for targeted phishing referencing the breach
Identity theft:
- Identity theft report filed with the federal trade regulator — needed for the next step
- Police report filed
- Fraudulent items disputed with each agency
- BLOCK PROVISION INVOKED — an agency must block information resulting from identity theft when given an identity theft report. Stronger than an ordinary dispute and rarely used
- Each affected creditor notified in writing; fraud-related records requested
- Medical identity theft checked via explanation-of-benefit statements
- Tax identity theft — filed early; identity protection PIN considered
- Criminal identity theft — an arrest in your name requires a separate court remedy
- Log kept of every call, letter, and reference number
Part 8 — Complain
- Federal trade regulator — deceptive practices, data security, identity theft reporting
- Federal consumer financial regulator — consumer reporting agencies, furnishers, financial institutions. Routed with a response deadline; responses are substantive
- Federal communications regulator — telecom privacy, unwanted calls
- State attorney general — state privacy law and unfair practices
- State insurance, banking, or utility regulator for licensed entities
- Health privacy enforcement office for covered entities
- The agency itself on a Privacy Act refusal — internal appeal, then federal court
Complaint format:
- One page, chronological, factual
- What you asked for, when, and how
- What they did or failed to do
- The statutory provision named — moves it out of the general queue
- What you want
- Numbered attachments
- Reference number kept
Part 9 — Situations with their own rules
Moving:
- Address change filed; commercial-use opt-out of the forwarding database asked about
- Financial institutions updated directly
- People-search audit re-run three months after the move
- Credit reports re-checked for addresses that are not yours
Divorce or separation:
- Access audit run, in the safe order
- Shared vaults, authorized users, subscriptions, insurance portals, and the mortgage or lease account included
- Attorney communications moved to an account the former partner never accessed
Job searching:
- Employment screening report pulled BEFORE applying
- Own name searched as an employer would
- Social profiles reviewed as a stranger sees them
Renting:
- Tenant screening reports pulled BEFORE applying
- If denied: company identified, free copy obtained, errors disputed, landlord asked to reconsider
A death in the family:
- Death certificate sent to each bureau; deceased alert requested
- Financial institutions, insurers, and agencies notified
- Online accounts closed or memorialized
- Pre-screened offers opted out of in the decedent's name
- Full date of birth and mother's maiden name kept out of the obituary — those are authentication answers
Children:
- Credit freeze requested for each minor child — free everywhere, and it prevents the fraud typically discovered at 18
- Directory information opted out of at school
- Posts reviewed for school name, uniform, routine, location metadata
- School device and learning platform privacy settings reviewed
Older adults:
- Credit and specialty agencies frozen
- Do-not-call registered
- Account alerts set for large or unusual transactions
- Trusted contact designated at financial institutions — lets the institution reach someone about suspected exploitation without giving account authority
- Power of attorney reviewed for who holds it and what it authorizes
Part 10 — Maintenance
Monthly (5 minutes):
- Financial alerts and unusual activity reviewed
- Unexpected mail watched for — mail is still how identity theft is discovered
Every six months (1 hour):
- Own name searched; images tab checked
- People-search opt-outs redone; spreadsheet updated
- App permissions reviewed
- Connected apps and active sessions reviewed
- Family sharing, location sharing, shared albums reviewed
- Smart home and vehicle administrators checked
- Ad identifier reset
Annually (2 hours):
- All consumer reports pulled — credit plus tenant, employment, check, insurance, medical
- Freezes verified still in place
- Recovery methods and trusted contacts updated everywhere
- Financial privacy notice read; sharing opt-out re-exercised
- Mobile port-out PIN confirmed
- High-value passwords updated
- Public posts from the last year reviewed
- State privacy law requests re-sent to the brokers that matter
- State data broker registry checked for new entrants
Full audit after: a move · a breach involving your SSN · a separation · a job change · a death in the family · any denial of housing, employment, credit, or insurance · any sign someone knows what they should not
- One page kept with: what is frozen and when · mobile PIN status · people-search spreadsheet · request log · last audit dates
Related documents
- Personal Privacy: Data Brokers, Surveillance, and Your Rights Over Your Own Information
- Protecting Your Personal Information
- Privacy Toolkit
- Scams, Fraud, and Elder Financial Exploitation
- Debt Collection and the FDCPA
Educational only, not legal advice. Privacy law is a patchwork of federal sectoral statutes (18 U.S.C. § 2510, 18 U.S.C. § 2701, 15 U.S.C. § 6801, 15 U.S.C. § 1681 and following) and rapidly changing state laws. If someone violent may be monitoring you, contact a domestic violence advocate before changing settings.