Summary. Highest-value first, then the paperwork.


Step 1 — The two hours that matter most

Do this before writing a single letter.

Freeze your credit — free, and the single most effective step against new-account identity theft:

  • Equifax
  • Experian
  • TransUnion

Then freeze the specialty agencies, which almost nobody does and which is where account fraud actually happens:

  • Check and bank account screening services
  • Telecom and utility payment databases
  • Insurance claims history database
  • Employment and tenant screening agencies that offer freezes

Lock the mobile account — this is what defeats SIM swapping:

  • Call your carrier and add a port-out PIN or account passcode
  • Ask what is required to port your number or change the SIM, and require the strongest option
  • Confirm who else is authorized on the account

Secure the email account, which is the master key to everything:

  • Unique, long password, in a password manager
  • Two-factor authentication with an authenticator app or hardware key — not text messages
  • Review and update recovery email, recovery phone, and trusted contacts
  • Review connected apps and remove what you do not use
  • Review active sessions and trusted devices; sign out of anything unfamiliar

Then the rest:

  • Password manager set up; unique passwords for financial, email, and any account holding personal data
  • Two-factor on financial, email, social, cloud storage, and your phone carrier account
  • Screen lock and full-disk encryption on every device
  • App permissions reviewed — location, contacts, microphone, camera, photos. Set location to "while using" or off
  • Ad identifier turned off or reset
  • Location history reviewed and deleted if you do not want it kept
  • Opt out of pre-screened credit offers
  • Register on the national do-not-call list

Two hours. No lawyers, no letters, and more protection than everything that follows.


Step 2 — Audit who already has access

The most serious exposures are usually people, not companies.

Work through this list and write down what you find:

  • Family or group location sharing — who can see you
  • Shared cloud photo libraries and albums
  • Shared cloud storage and document access
  • Recovery contacts and trusted contacts on your accounts
  • Who owns your mobile plan — a plan owner can see call and text metadata and often location
  • Smart home administrators — door logs, camera history, voice assistant history
  • Vehicle telematics and connected car apps
  • Streaming and subscription profiles, which reveal viewing and location
  • Shared financial accounts and authorized users
  • Password manager shared vaults
  • Old devices you gave away or that someone still holds
  • Work devices and work profiles on personal phones
  • Anyone who knows a password you have not changed

Then remove what should not be there.

One critical exception: if you are concerned that a former or current partner who has been abusive is monitoring you, do not change anything yet. Go to Step 6 first. Abrupt changes can escalate danger, and there is a safer sequence.


Step 3 — Find yourself, then remove yourself

Find out what is public:

  • Search your full name in more than one search engine
  • Search name plus city, name plus former city, and name plus employer
  • Check the images tab
  • Search your phone number and your email address
  • Search a spouse's or family member's name — their profiles often list your address
  • Screenshot everything before removing it, with the URL and date visible

Then remove:

  • Opt out of each people-search site you found. Most have a process; it is usually buried in the footer
  • Keep a spreadsheet: site name, opt-out URL, date submitted, confirmation received, date to re-check
  • Check whether your state has a data broker registry — it is the closest thing to a complete target list
  • If your state has a comprehensive privacy law, send statutory deletion and opt-out requests, which carry response deadlines
  • Search engine removal requests for personal contact information, government ID numbers, financial account numbers, medical records, and non-consensual intimate imagery
  • Calendar a re-check every six months — profiles come back, and that is expected, not a failure

If personal safety is the concern:

  • Enroll in your state's address confidentiality program if it has one — a substitute address for public records is far stronger than opting out site by site, because it addresses the source
  • Consider a post office box or commercial mail address for anything that becomes public
  • Ask family members to lock down their profiles
  • Review what your own posts reveal about your home, routine, workplace, and children's school

And consider a removal service if the time cost is prohibitive — evaluating it on which sites it covers, whether it re-checks, and what it does with the data you give it.


Step 4 — Get and fix your consumer reports

This is the highest-value legal step in this guide.

Get them:

  • All three nationwide credit reports
  • Tenant screening reports — the ones that decide housing
  • Employment screening report
  • Check and bank account screening report
  • Insurance claims history report
  • Medical information exchange report
  • Utility and telecom payment report
  • Gig platform screening report, if you drive or deliver
  • Request the full file disclosure, not a score — it should show sources and who received reports

Read them for:

  • Accounts, addresses, or employers that are not yours — a mixed file with someone of a similar name is the most common serious error
  • Eviction filings that were dismissed, or that belong to someone else
  • Criminal records that should have aged off — 15 U.S.C. § 1681c generally bars reporting arrest records not resulting in conviction after the applicable period
  • Duplicate accounts
  • Balances, dates, and statuses that are wrong
  • Inquiries you did not authorize15 U.S.C. § 1681b limits who may obtain a report

Dispute what is wrong:

  • In writing, to the agency, under 15 U.S.C. § 1681i
  • Identify each item, state why it is wrong, and attach the proof
  • Also dispute directly with the furnisher — the creditor, landlord, or court records vendor
  • Send certified with return receipt, and keep everything
  • Expect a written result within the reinvestigation period
  • If it is not corrected, dispute again with new evidence, complain to the federal consumer financial regulator, and consider a lawyer — this statute provides attorney's fees, which is why these cases are taken on contingency

If you were denied housing, employment, credit, or insurance:

  • Ask which company provided the report — you are entitled to know
  • Get a free copy
  • For employment, you should have received a pre-adverse action notice with the report and a summary of rightsif you did not, that is itself a violation
  • Dispute, then ask the decision-maker to reconsider with the corrected report

Step 5 — Send the requests that carry deadlines

Find out first whether your state has a comprehensive privacy law. If it does, your requests are legal obligations rather than customer service tickets.

The requests to send, to companies that matter to you:

  • Right to know / access — what they collected, from where, why, and who they shared it with
  • Right to delete
  • Right to correct
  • Opt out of sale and of sharing for targeted advertising
  • Limit use of sensitive personal information, where your state provides it
  • Universal opt-out signal enabled in your browser, where your state requires it to be honored

Where to send them: the address, email, or webform in the company's privacy policy — which the law generally requires to be provided.

Other access requests worth making:

  • Federal agency records under 5 U.S.C. § 552a — access and amendment of records that are inaccurate, irrelevant, untimely, or incomplete. Request under both the Privacy Act and the freedom of information statute
  • Personnel file from your employer, where your state provides the right
  • Medical records — the complete designated record set, not a summary
  • Education records, and opt out of directory information disclosure for your children
  • Financial privacy sharing opt-out described in the annual notice you have been throwing away, under the framework at 16 C.F.R. Part 313
  • Telecom customer information restrictions with your carrier, under 47 U.S.C. § 222

What makes a request work:

  • Be specific — "all records" is often refused as overbroad
  • Verify your identity as required — most refusals are verification failures, not denials
  • State the statutory deadline
  • Send with proof and log it
  • Follow up in writing when the deadline passes

Step 6 — If someone may be monitoring you

Safety first. This is the one place where moving fast is wrong.

If there is any history of violence, threats, or controlling behavior:

  • Contact a domestic violence advocate before changing anything — abrupt loss of access can escalate danger, and advocates plan the sequence
  • Use a device the other person has never had access to for research and calls — a library computer, a friend's phone
  • Document before removing — screenshots of location sharing, account access, messages showing knowledge they should not have
  • Ask about a technology safety program; specialized ones exist and are free
  • Consider a protective order — most states now expressly cover electronic harassment and stalking

If there is no safety concern, work through the access map from Step 2, in this order:

  • Email password and every recovery method first — it is the key to the rest
  • Remove trusted and recovery contacts you did not intend
  • Disable family and location sharing
  • Move to your own mobile account with a port-out PIN
  • Unshare cloud photo libraries and storage
  • Remove smart home and vehicle app administrators
  • Change financial account credentials and remove authorized users
  • Sign out of all sessions on every account

On devices:

  • Check for unfamiliar applications and profiles, and for device management or configuration profiles you did not install
  • Check battery and data usage for unexplained consumption
  • Update the operating system — updates commonly remove monitoring software
  • Consider a factory reset after documenting, and do not restore from a backup that may contain the software
  • Check vehicles for tracking devices
  • Check smart home devices, cameras, and shared displays

Step 7 — Breach and identity theft response

When a breach notice arrives:

  • Read what data was involved — the response differs for an email address versus a Social Security number
  • Freeze credit at all three bureaus if not already
  • Freeze the specialty agencies
  • Change the password for that service and anywhere you reused it
  • Turn on two-factor there
  • Take the offered monitoring, but do not treat it as a substitute for a freeze
  • Watch for targeted phishing that references the breach

If identity theft has occurred:

  • File an identity theft report with the federal trade regulator — you need it for the next step
  • File a police report
  • Dispute fraudulent items with each agency
  • Use the block provision — an agency must block information resulting from identity theft when you provide an identity theft report. This is stronger than an ordinary dispute and it is rarely invoked
  • Notify each affected creditor in writing and request fraud-related records
  • Check for medical identity theft in explanation-of-benefit statements
  • Check for tax identity theft; file early and consider an identity protection PIN
  • Check for criminal identity theft — someone arrested using your name — which requires a different remedy through the court
  • Keep a log of every call, letter, and reference number

Step 8 — Complain effectively

Complaints work here, because the enforcement bodies are active.

  • Federal trade regulator — deceptive privacy practices, data security, identity theft reporting
  • Federal consumer financial regulator — consumer reporting agencies, furnishers, financial institutions. Complaints get routed with a response deadline and the responses are frequently substantive
  • Federal communications regulator — telecom privacy, unwanted calls
  • State attorney general — the state privacy law and the unfair practices statute
  • State insurance, banking, or utility regulator for licensed entities
  • Health privacy enforcement office for covered entities
  • The agency itself, on a Privacy Act refusal — internal appeal, then federal court

Write it in one page:

  • Chronological and factual
  • What you asked for, when, and how
  • What they did or failed to do
  • The statutory provision, if you can name it — this moves a complaint out of the general queue
  • What you want
  • Numbered attachments
  • Keep the reference number — it is leverage in every later conversation

A worked case: Priya Ramanathan, one Saturday and six letters

Priya, 38, a hospital pharmacist, gets a breach notice from a former employer's benefits administrator. Social Security numbers were involved.

Saturday morning, two hours.

She freezes credit at all three bureaus. Twenty minutes total, all online, no cost.

She calls her mobile carrier and adds a port-out PIN. Eight minutes on hold, ninety seconds of actual conversation.

She changes her email password, sets up an authenticator app, and reviews her recovery settings — and finds a recovery phone number belonging to an ex-roommate from 2019. She removes it.

She reviews connected apps on her main accounts and removes fourteen she has not used in years, including a photo editor from 2017 with access to her cloud storage.

She sets up a password manager and changes passwords for her bank, her brokerage, her email, and her health portal.

She turns on two-factor everywhere it is offered.

Saturday afternoon, one hour.

She searches her own name. Seven people-search profiles, listing her current address, three prior addresses, her mother's name, and a phone number from 2015 that she still uses.

She screenshots all seven with URLs and dates, then opts out of each and logs them in a spreadsheet with a re-check date of six months out.

She checks her state — it has a comprehensive privacy law. She sends statutory deletion requests to the four largest brokers, referencing the statute and noting the response deadline.

Sunday, ninety minutes.

She pulls her three credit reports. Clean.

Then she pulls the reports almost nobody pulls: the check screening service, the insurance claims database, the medical information exchange, and the two largest tenant screening companies.

The tenant screening report has a problem. It lists an eviction filing from 2021 in a neighboring county. She has never lived there and has never been evicted. The record belongs to a P. Ramanathan with a different first name.

She would never have found this. She is not moving. But she will move eventually, and this would have cost her an apartment.

She disputes it in writing under 15 U.S.C. § 1681i, attaching her driver's license, her lease history for the relevant period, and the county docket printout showing the other person's full name. Certified mail, return receipt.

She also disputes directly with the court records vendor that furnished the item.

Thirty-one days later: deleted.

Six weeks later, the re-check. Two of the seven people-search profiles are back, and one new one has appeared. She opts out again. This is normal.

Total investment: about five hours, spread over two weekends, and $0.

What it produced: new-account fraud blocked at every bureau, SIM swapping defeated, a stranger's recovery access removed, fourteen dormant app permissions revoked, seven public profiles removed, and an eviction record that was not hers deleted before it ever cost her a home.

The last one is the point. She had no idea it was there. Nobody checks the reports that decide housing until after they have been denied.


Where people go wrong

Buying monitoring instead of freezing. Monitoring tells you after it happened. A freeze prevents it. The freeze is free; the monitoring usually is not.

Freezing only the three credit bureaus. Account fraud runs through the specialty agencies — check screening, telecom, and utility databases — and almost nobody freezes those.

Using text messages for two-factor. Better than nothing, defeated by SIM swapping. An authenticator app or a hardware key is the real protection, and the port-out PIN is what closes the remaining gap.

Reusing passwords. The single largest cause of account compromise. One breach becomes twelve.

Never checking the reports that actually decide things. Credit reports are the ones people pull. Tenant and employment screening reports are the ones that cost people housing and jobs, and they contain errors at meaningful rates.

Not asking which company provided a background check after a denial. You are entitled to know, and to a free copy. Without asking, the error travels with you.

Disputing by phone. No record, no proof, no deadline you can enforce. Dispute in writing, certified.

Disputing only with the agency and not the furnisher. Do both.

Treating an opt-out as permanent. Profiles return. Calendar the re-check.

Ignoring the annual financial privacy notice, which describes a sharing opt-out that exists precisely because nobody reads it.

Leaving old access in place — an ex's recovery phone number, a former roommate on the phone plan, a photo library shared with someone who moved out three years ago.

Acting fast when a violent partner may be monitoring. This is the one situation where speed is dangerous. Document first, get an advocate, plan the sequence.

Removing evidence before screenshotting it. In a harassment or doxxing situation, removal destroys the proof you will need.


The requests, and how to word them so they work

Three practical rules govern every request in this guide.

Rule one: verify your identity the way they ask. The most common reason a request is refused is not a substantive denial — it is that the requester did not complete identity verification. Read the verification instructions and follow them exactly. If they ask for a specific form, use it.

Rule two: be specific about scope. "Send me everything you have" invites a refusal for overbreadth or a useless summary. "All personal information you have collected about me from 1 January 2020 to the present, including the categories of sources, the business or commercial purpose for collecting it, and the categories of third parties to whom you have disclosed it" does not.

Rule three: state the deadline and create proof. Name the statutory response period. Send certified, or use a portal that generates a confirmation. Log the date, the method, and the confirmation number.

Then track it:

REQUEST LOG
COMPANY          TYPE        SENT      METHOD/CONF     DUE       RESULT
______________   know        ________  ____________   ________  ________
______________   delete      ________  ____________   ________  ________
______________   opt out     ________  ____________   ________  ________
______________   dispute     ________  ____________   ________  ________

What to do when the deadline passes:

Send a second request referencing the first, with the date and confirmation number, and stating that the statutory period has elapsed.

Then complain, naming the provision and attaching both letters. For a company subject to your state privacy law, complain to the state attorney general. For a consumer reporting agency or a financial institution, complain to the federal consumer financial regulator — those complaints carry a response deadline and produce substantive answers.

And note when a failure to respond is itself actionable. Several statutes make it so, and saying so in the second letter changes how it is handled.


Situations that need their own approach

Moving. A move generates a burst of public records — a new address on voter rolls, licenses, utility accounts, and property records — and repopulates every people-search profile you cleaned up.

  • File the address change with the postal service, but know the forwarding database feeds commercial data products; an opt-out of that commercial use exists — ask
  • Update the address with your financial institutions directly rather than relying on forwarding
  • Re-run the people-search audit three months after the move, when the new address has propagated
  • Re-check your credit reports for addresses that are not yours

Divorce or separation. The access audit in Step 2 becomes urgent, and the order matters — see Step 6.

  • Add: shared password vaults, joint account authorized users, shared subscriptions, shared insurance portals, and the mortgage or lease account
  • Add: your attorney's communications — use an email account your former partner has never had access to
  • Consider whether any device was a gift that you now use but that is registered to their account

Job searching. Employers run background checks, and errors are found at the worst possible moment.

  • Pull your employment screening report before applying, not after a denial
  • Search your own name as an employer would
  • Review social profiles as a stranger sees them
  • Know your rights: a standalone written disclosure and written authorization before a report is obtained, and a pre-adverse action notice with a copy of the report before you are rejected — so you can dispute the error before losing the job

Renting. Same logic, higher stakes, worse data quality.

  • Pull tenant screening reports before applying
  • If denied, ask which company and get the free copy
  • Check for eviction filings that were dismissed, that belong to someone else, or that should have aged off
  • Ask the landlord to reconsider once the record is corrected

A death in the family. Deceased people are targets for identity theft, and estates are not monitored.

  • Send a copy of the death certificate to each credit bureau and request a deceased alert
  • Notify financial institutions, insurers, and government agencies
  • Close or memorialize online accounts
  • Opt out of pre-screened offers in the decedent's name
  • Do not publish the full date of birth and mother's maiden name in the obituary — those are authentication answers

Children. A child's credit file should not exist, and if it does, that is the signal.

  • Request a credit freeze for each minor child — free in every state, and it prevents the fraud that is typically discovered at age 18
  • Opt out of directory information disclosure at school
  • Review what you post about them — school name, uniform, routine, and location metadata
  • Review the privacy settings of school-issued devices and learning platforms

Older adults. The exposure is different and the stakes are higher.

  • Freeze credit and specialty agencies
  • Register on the do-not-call list
  • Set up account alerts for large or unusual transactions
  • Discuss a trusted contact designation with financial institutions — many offer one, and it lets the institution reach someone when it suspects exploitation without giving that person account authority
  • Review who has power of attorney and what it authorizes

What to do when a company simply will not fix it

There is a ladder, and each rung is more effective than the one below.

Rung one: the written dispute or request, with proof of delivery.

Rung two: the second written request, referencing the first by date and confirmation number, stating the elapsed statutory period, and naming the provision.

Rung three: escalate inside the company. Ask for the privacy officer, the compliance department, or the executive customer relations team by name. A letter to the general counsel's office at corporate headquarters is answered more often than people expect.

Rung four: the regulator complaint. For consumer reporting and financial services, the federal consumer financial regulator — complaints are routed with a response deadline and the responses are substantive. For deceptive practices and data security, the federal trade regulator. For your state privacy law and unfair practices, the state attorney general. For a licensed entity, its licensing regulator.

Rung five: a demand letter from a lawyer. For consumer reporting violations this is inexpensive, because the statute provides attorney's fees for willful violations, which is why consumer lawyers take these on contingency.

Rung six: suit. Available and worth evaluating where a private right of action exists:

  • Consumer reporting — actual damages; statutory and punitive damages plus fees for willful violations
  • Interception and stored communications — civil remedies
  • Automated call and text restrictions — statutory damages per violation
  • One state's biometric statute — a private right of action that has driven substantial litigation
  • Certain state breach provisions

Where a private right of action does not exist — which is the case for most comprehensive state privacy laws — the attorney general complaint is the enforcement mechanism, and volume matters. A well-written complaint is not futile; it is how enforcement priorities get set.

Finding a lawyer: consumer law referral panels, the state bar's consumer section, legal aid for lower-income households, and law school consumer clinics. Ask specifically whether they handle consumer reporting cases — it is a distinct practice, and the ones who do it take cases on contingency because of the fee provision.


The maintenance schedule

Privacy is not a project you finish. It is a short recurring task.

Monthly, five minutes:

  • Review financial account alerts and any unusual activity
  • Check for unexpected mail — a card you did not order, a bill from a company you do not use, a notice about an account you did not open. Mail is still how identity theft is discovered

Every six months, one hour:

  • Search your own name in two engines, plus name-and-city and the images tab
  • Re-opt-out of people-search sites that reappeared; update the spreadsheet
  • Review app permissions on every device — new apps accumulate permissions
  • Review connected apps and active sessions on your main accounts
  • Review who is on family sharing, location sharing, and shared albums
  • Check smart home and vehicle app administrators
  • Reset the advertising identifier

Annually, two hours:

  • Pull all consumer reports — three credit bureaus plus tenant screening, employment screening, check screening, insurance claims, and medical information
  • Verify freezes are still in place at all of them
  • Review and update recovery methods and trusted contacts on every important account
  • Read the financial privacy notice and re-exercise the sharing opt-out
  • Confirm the mobile account port-out PIN is still set
  • Update passwords for the highest-value accounts
  • Review what you have posted publicly in the last year
  • Re-run the state privacy law requests to the brokers that matter most
  • Check the state data broker registry for new entrants

After any of these events, run the full audit:

  • A move
  • A breach notice involving your Social Security number
  • A separation or divorce
  • A job change
  • A death in the family
  • Any denial of housing, employment, credit, or insurance
  • Any indication someone knows something they should not

And keep one page with: which bureaus and agencies are frozen and when · your mobile PIN status · the people-search spreadsheet · your request log · and the dates of your last audits. The page is what makes this take an hour instead of an afternoon.


Reasonable expectations

A closing note, because privacy advice often oversells what is achievable.

You cannot become invisible, and services that promise it are selling something. Public records are public. Court filings, property deeds, professional licenses, and voter registrations exist and will keep existing. What you can do is reduce the surface, correct what is wrong, and control who gets to make decisions about you based on bad data.

Rank the work honestly:

Highest value, lowest cost: credit freezes at the three bureaus and the specialty agencies · a mobile port-out PIN · unique passwords with a manager · two-factor with an app or key · and pulling the tenant and employment screening reports before you need them.

High value, moderate cost: the access audit · the people-search removal and its six-month repeat · state privacy law requests · and correcting any consumer report error you find.

Situational but critical: the address confidentiality program, if safety is the issue. The domestic violence technology safety consultation, if a partner may be monitoring you. In those cases, these are the whole answer, and everything else is secondary.

Lower value than the marketing suggests: paid credit monitoring, which reports after the fact rather than preventing · "dark web scanning," which tells you what a freeze already protects you from · and removal services, which are useful for time savings but not for anything you cannot do yourself.

And the thing worth keeping in mind: most of the harm in this area does not come from a shadowy broker. It comes from an error in a screening report that costs someone a home, a reused password that opens twelve accounts, an ex who was never removed as a recovery contact, and a phone number that could be ported away because nobody set a PIN.

Those four are all fixable this week.


Frequently asked questions

What is the single best thing I can do? Freeze your credit at all three bureaus. Free, fast, and the most effective step against new-account fraud. Then freeze the specialty agencies.

How do I stop SIM swapping? Add a port-out PIN to your mobile account and use an authenticator app rather than text messages for two-factor.

How do I get off people-search sites? Opt out site by site, use your state privacy law's deletion right, check the state data broker registry, and repeat every six months.

I lost an apartment over a background check. Ask which company provided it, get a free copy, and dispute the errors. Dismissed evictions and wrong-person records are common.

How do I know if my state has a privacy law? Search your state's attorney general site for "consumer privacy." If it does, your requests carry deadlines.

Can I see what the government has on me? For federal agencies, yes — access and amendment under the Privacy Act. Request under both it and the freedom of information statute.

I think my partner is tracking me. Talk to a domestic violence advocate before changing anything. Use a device they have never touched to get help.

Is my health app covered by health privacy law? Usually not. Federal health privacy rules cover plans, providers, and clearinghouses — not most apps.

Does removal from search remove it from the internet? No — but search is how people find things, so it matters practically.

Nobody is responding to my request. Complain to the state attorney general and, for financial and consumer reporting matters, to the federal consumer financial regulator — those complaints get answers.


Related documents

Educational only, not legal advice. Privacy law varies substantially by state and changes rapidly. If you are being monitored by someone who has been violent toward you, contact a domestic violence advocate before altering device or account settings.