← all articles

How to remove your personal data from the web

Search your own name right now and you’ll probably find your home address, phone number, age, relatives, and maybe even a satellite photo of your house, all sitting on a site you never signed up for. Data brokers like Spokeo, Whitepages, and BeenVerified scrape public records, purchase histories, and social profiles, then repackage that into a profile they sell to anyone with a credit card. None of this required your consent.

This guide is for anyone who wants their exposure down, not necessarily to zero (that’s not realistic if you’ve ever owned property, registered to vote, or had a phone bill), but down to the point where a random person googling your name doesn’t get your address on the first page. I wrote this from doing it for myself and for a few family members here in Singapore and abroad, so it covers both US-heavy data broker mechanics and what actually applies if you’re outside the US.

By the end you’ll have pulled yourself off the major broker sites, filed a Google removal request for anything sensitive still ranking, and set up a recurring check so this doesn’t quietly creep back in three months from now, because it will if you don’t check.

what you need

  • a dedicated email alias for opt-out correspondence, separate from your main inbox (a free Gmail/Proton account works fine)
  • a password manager (Bitwarden or 1Password) to store the login and confirmation details for each opt-out
  • a free Have I Been Pwned account to check which of your emails/passwords have leaked in known breaches
  • a Google account, for the “results about you” removal tool
  • 3-5 hours for the initial manual sweep across roughly 15-20 broker sites
  • optional but recommended: a paid removal service subscription, DeleteMe runs about $129/year for one person, Incogni is closer to $90/year billed annually
  • a spreadsheet or note doc to track which sites you’ve submitted to and when, because you will lose track otherwise
  • your government ID on hand, a small number of US brokers require ID verification before honoring a removal request

step by step

1. map your exposure

Search your full name in quotes, plus a second identifier like your city or employer, in Google. Then run every email you use through Have I Been Pwned to see what’s already leaked.

"Xavier Fok" "Singapore" -site:linkedin.com
site:spokeo.com "Xavier Fok"
site:whitepages.com "Xavier Fok"

Expected output: a list of URLs, broker profile pages, old forum posts, breach records, social profiles, that make up your current footprint. Write every URL down in your tracker before you do anything else.

If it breaks: a common name returns mostly noise. Add a middle initial, a former employer, or a street/neighborhood name to narrow it down.

2. set up a clean operating base

Create the dedicated email alias and get your password manager running before you touch a single opt-out form. Every broker site will send a confirmation link, and you want those going somewhere you’ll actually check, not buried in your main inbox.

Expected output: one inbox you check weekly, holding nothing but opt-out confirmations, and a password manager entry per site you submit to.

If it breaks: some brokers reject “+” style aliases ([email protected]) outright. If a form errors out on the alias, use a fully separate free account instead.

3. remove yourself from the major people-search sites manually

Work through the big ones first since they feed most of the “free background check” traffic: Spokeo, Whitepages, BeenVerified, MyLife, Radaris, Intelius, USSearch, FastPeopleSearch, and TruePeopleSearch. Each has a self-serve opt-out page, usually findable by searching “[site name] opt out.”

If a broker has no visible form, email them directly and cite the relevant law if you have standing to:

Subject: Data removal request

To whom it may concern,

I am requesting removal of my personal information from your database,
including my name, address, phone number, and any associated records.
[If a California resident: This request is made under the California
Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq.]

Please confirm removal in writing within the timeframe required by law.

[Your name]

Expected output: confirmation emails within 24 hours to 2 weeks, and your profile disappearing from search results within roughly 30 days.

If it breaks: California’s Attorney General maintains a public data broker registry listing every broker required to register in the state, useful if a site you found isn’t on your list yet.

4. automate the long tail with a paid removal service

Manually opting out of the top 10 sites gets you maybe 20% of the way there. The rest is a long tail of smaller, obscure brokers that resurface constantly. This is what DeleteMe and Incogni are for, both submit removal requests across their broker lists (DeleteMe covers more sites but costs more) and resubmit automatically when your data reappears.

Expected output: a quarterly report showing what was found and what got removed.

If it breaks: neither service touches everything, some brokers require court orders or ID verification they can’t do on your behalf. Check the vendor’s published coverage list before paying so you know what you’re actually getting. If you’re curious how people are starting to use AI agents to automate this kind of repetitive web-form work, aitoolgazette.com/blog/ has been tracking that space.

5. clean up social media and legacy accounts

Old forum accounts, a Myspace profile from 2007, a public Facebook page with your full birthdate, these all feed broker scrapers too. Go through everything, lock down privacy settings on what you keep, and fully delete (not just deactivate) what you don’t use.

Expected output: fewer personal-profile results on the first two pages of a search for your name.

If it breaks: deactivating an account often isn’t the same as deleting it, most platforms hold the data for 30-90 days and it can still surface in search caches during that window. Use the actual account-deletion flow, not deactivation.

6. request removal from Google search results directly

Google will delist certain personal results, phone numbers, home addresses, ID numbers, and images of signatures, from search even if the source page stays live. Use their removal request tool under Search Help.

Expected output: Google reviews the request within a few days and, if it qualifies, the page stops showing in search results for your name.

If it breaks: Google delists, it doesn’t delete. The source page is still live at its original URL, you still need to get it removed at the site itself (back to step 3) if you want it gone entirely.

7. handle public records and jurisdiction-specific limits

Voter rolls, property deeds, and court records are statutory public record in most US states and generally can’t be scrubbed on request, though some states run address confidentiality programs for people with documented safety concerns. If you’re in the EU or UK, GDPR’s right to erasure gives you real leverage, email the data controller directly and most brokers with an EU presence have to respond within 30 days. If you’re in Singapore, the Personal Data Protection Commission handles private-sector data complaints, but it doesn’t cover government-held public records.

Expected output: broker-held data comes down, statutory public records generally don’t.

If it breaks: if a broker ignores a GDPR erasure request past 30 days, you can file a complaint with your national data protection authority, that alone tends to get a response fast.

8. set up recurring monitoring

Set a Google Alert for your full name, keep Have I Been Pwned monitoring active on your emails, and put a recurring 90-day reminder on your calendar to redo the manual broker sweep. Brokers rescrape public records on a rolling basis, so removed listings do come back.

Expected output: you catch reappearances within a quarter instead of finding out a year later when someone mentions it.

If it breaks: if the same broker keeps repopulating your listing within weeks of removal, that’s a repeat offender, flag it specifically with your paid removal service or file a direct complaint rather than resubmitting manually every time.

common pitfalls

  • Treating it as one-time. A sweep you do once and never repeat decays within months as brokers rescrape public records. Set the recurring reminder in step 8 or it doesn’t stick.
  • Using your real contact info on opt-out forms. Submitting your actual phone number to “verify” a removal request just hands a data broker a fresh, confirmed data point. Use the alias.
  • Confusing Google delisting with deletion. Getting a result removed from Google search doesn’t touch the source page. If the broker still has your data, it’ll resurface eventually through a different query.
  • Not checking confirmation emails. Several brokers require you to click a confirmation link within 24-48 hours or the request silently expires. Check the dedicated inbox weekly during the initial sweep.
  • Ignoring cached and archived copies. The Wayback Machine and Google’s cache can keep old versions of a profile page visible even after the live page is taken down. Worth a separate check if the content was ever high-profile enough to be crawled.

scaling this

Doing it for yourself (1x) is a spreadsheet and a weekend afternoon. Doing it for a household (10x), spouse, kids, aging parents, doesn’t need new tooling, just separate tabs in your tracker and separate alias inboxes per person; the bottleneck is time, not process. Most paid services (DeleteMe, Incogni) sell family plans at this scale that are cheaper per person than buying individual licenses.

Running it as a side service for friends or small clients (100x) changes the risk profile more than the workflow. You’re now handling other people’s PII, so a spreadsheet stops being adequate, you need a proper case tracker with access controls, and you need explicit written authorization from each person before submitting removal requests on their behalf (several US states require this for third-party CCPA requests).

Turning it into an actual business (1000x) is a different problem entirely. The bottleneck stops being manual submission and becomes compliance: CCPA authorized-agent documentation, GDPR data processing agreements if you’re touching EU subjects’ data, and probably a direct API or reseller relationship with a removal vendor instead of clicking through forms yourself. This is a real, valid niche, but it’s a compliance business first and a privacy-tools business second.

where to go next

If you haven’t already, check whether your accounts show up in any known breaches over on how to check if your accounts were in a breach, it’s the fastest way to find leaked passwords tied to the same email addresses you just cleaned up. From there, how to lock down your Google account covers hardening the account you’ll be using for the removal requests in step 6. And if browser fingerprinting rather than data brokers is your bigger concern, see how to browse without being fingerprinted. More tutorials like these live on the blog index.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-07-20.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →