Technology
A Realist's Guide to Digital Privacy
Online privacy is not about becoming invisible; it is about control. This guide offers 15 practical, no-nonsense steps to reduce your data exposure and secure your digital life against trackers, scammers, and data brokers.

In summary
Forget the goal of total online anonymity. This guide provides a realistic framework for improving your digital privacy with 15 actionable tips. They are grouped by effort, from fifteen-minute fixes like enabling 2FA to ongoing habits like spotting phishing and exercising your data rights. You can make it much harder for companies and criminals to track and exploit your personal information. It starts with understanding the real threats and taking methodical, concrete steps to counter them.
Fifteen-Minute Fixes
Improving your privacy does not require a week-long technical retreat. Some of the most effective actions take less time than brewing coffee. Start here.
1. Check if your data is already loose
Your first step is reconnaissance. See what is already out there. Use a free, respected service like Have I Been Pwned to check if your email address or phone number has appeared in any known data breaches. This is not a cause for panic. It is a to-do list.
If your credentials for a service were exposed, go change that password immediately. If you reused that password anywhere else—a common and dangerous mistake—change it there, too. This check gives you a clear, prioritized list of accounts that need immediate attention.
2. Enable proper two-factor authentication
A password alone is a weak lock. Two-factor authentication (2FA) adds a second lock, requiring both something you know (your password) and something you have (your phone or a hardware key). Turn it on for every important account: your primary email, your bank, and your social media.
Not all 2FA is equal. Avoid using SMS (text messages) for your second factor if possible, as it is vulnerable to SIM-swapping attacks. Government agencies like the UK's National Cyber Security Centre (NCSC) and the US Cybersecurity and Infrastructure Security Agency (CISA) recommend using an authenticator app (like Google Authenticator or Authy) or, for maximum security, a physical hardware key (like a YubiKey).
3. Review your main social media privacy settings
The default settings on social media platforms are designed for maximum sharing, not maximum privacy. Go into the privacy and security settings of Facebook, Instagram, X (formerly Twitter), and any other network you use. Limit who can see your posts to “Friends” instead of “Public.” Restrict who can find you using your email or phone number. Turn off location history. This is your data. You decide who sees it.
4. Cull your phone's app permissions
That free game does not need access to your contacts. Your flashlight app does not need your location. Modern mobile operating systems (iOS and Android) offer granular control over what data each app can access. Go to your phone’s privacy settings and start revoking permissions.
Be ruthless. If an app’s function does not logically require access to your microphone, camera, location, or contacts, turn it off. The app will ask again if it truly needs it for a specific task, giving you a chance to grant temporary permission.
5. Install a browser tracker blocker
Every time you load a website, dozens of third-party companies you have never heard of are likely tracking your activity to build a profile for targeted advertising. You can stop most of this by installing a browser extension. Tools like the Electronic Frontier Foundation's Privacy Badger or uBlock Origin actively identify and block these trackers from loading, which makes your browsing more private and often faster.
An Evening's Work
With the quick wins handled, dedicate a single evening to setting up a more robust privacy foundation. These steps require more focus but offer a disproportionately large return on your security and peace of mind.
6. Stop remembering passwords. Start managing them.
This is the single most important change you can make. The human brain is not built to create and remember dozens of unique, complex passwords. A password manager is a secure, encrypted vault that does it for you. You remember one strong master password, and it generates and stores long, random passwords for every site you use.
When creating a new password or your master password, use a passphrase. Instead of `Jk5^b$9!pL`, use a memorable but long string of unrelated words like `yellow-stapler-runs-quickly`. It is far easier for you to remember and exponentially harder for a computer to brute-force.
7. Start adopting passkeys
Passwords are a flawed legacy technology. Passkeys are their replacement. A passkey uses your device (phone or computer) and its biometric security (fingerprint or face scan) to log you into a website or app. There is no password to be stolen in a data breach or given away in a phishing attack. The cryptographic key never leaves your device.
Major platforms like Google, Apple, and Microsoft are pushing this standard. When a service offers you the option to create a passkey, take it. This technology is a massive step forward for security and makes phishing nearly impossible for the protected account.
8. Update everything. Now.
Those annoying update notifications are not just about new features; they contain critical security patches. Running outdated software is like leaving your front door unlocked. Set aside time to update your computer’s operating system, your phone’s OS, your web browser, and all your most-used applications. Better yet, enable automatic updates wherever the option exists. This is fundamental digital hygiene.
9. Switch to a private search engine
Your search history is an intimate log of your thoughts, fears, and plans. Using a search engine like Google means feeding that log directly into one of the world's largest advertising profiles. Switch your browser’s default search engine to one that does not track you, such as DuckDuckGo, Startpage, or Brave Search. The results are high-quality, and your curiosity remains your own.
10. Change your device's DNS resolver
The Domain Name System (DNS) is the internet’s phone book, translating human-readable domain names (like novapedia.com) into machine-readable IP addresses. Your Internet Service Provider (ISP) usually handles this, logging every site you visit. You can switch to a third-party DNS resolver that prioritizes privacy and may even block malicious sites. By better understanding the internet's core components, as described in an article on a web request's long journey, you can identify points to bolster your privacy.
Services like Cloudflare (1.1.1.1) and Quad9 (9.9.9.9) offer free, fast, and privacy-focused DNS. Changing this setting on your router covers every device on your network, or you can change it on individual devices. It is a slightly technical but powerful step.
Ongoing Habits for the Long Haul
Privacy is not a one-time setup. It is a practice. Integrating these habits into your digital life will maintain your defenses over time.
11. Learn to spot a phish
The most sophisticated security can be defeated by a single, ill-advised click. Phishing—fraudulent attempts to trick you into revealing sensitive information—is a constant threat. Learn the signs: a sense of extreme urgency, an unfamiliar sender address pretending to be a known contact, spelling and grammar mistakes, and requests to click a link or download an attachment. For a deeper look at this and other dangers, it is worth reading about common cybersecurity threats and how to stay safe.
Be skeptical. If your bank emails you unexpectedly about a problem with your account, do not click the link. Go to your bank’s website directly by typing the address into your browser. This simple habit neutralizes the entire attack.
12. Think before you share
The most significant source of data leakage is often you. Every piece of information you post online—your child's school, your vacation dates, your political opinions, your new car—is collected, indexed, and stored. Forever. It can be used by advertisers, data brokers, future employers, and even large language models, as data scraped from the public web is a primary training source for systems like ChatGPT.
Before you post, pause. Ask yourself: who needs to see this? What is the worst-case scenario if this information becomes public? Adjust your audience or, better yet, just do not post it. A little self-censorship goes a long way.
13. Exercise your legal data rights
Regulations like Europe’s GDPR and California’s CCPA grant you legal rights over your data. These include the right to access the data a company holds on you and the right to request its deletion. The UK's Information Commissioner's Office (ICO) provides clear guidance on these rights. While companies do not always make it easy, you can send formal requests to services you no longer use to have your account and associated data wiped. It is tedious but powerful.
14. Start the data broker opt-out process
Data brokers are companies that exist solely to buy and sell your personal information: your address, age, income, interests, and more. Removing your information from these services is a frustrating, manual process of visiting each broker's site and navigating its opt-out procedure. Paid services can do this for you, but you can also do it yourself if you have the patience. Starting with the biggest brokers can significantly reduce your public data profile.
15. Freeze your credit reports
This is less about browsing privacy and more about protecting you from the financial consequences of identity theft. In the US, you can place a free security freeze on your credit files with the three major bureaus (Equifax, Experian, and TransUnion). A freeze prevents anyone from opening a new line of credit in your name. You can temporarily lift the freeze when you need to apply for a loan or credit card. This is one of the most effective ways to stop identity thieves in their tracks.
Things You Can Probably Stop Worrying About
Some privacy advice is outdated or misdirected. Your energy is better spent on the tips above than on these common but less impactful concerns.
Using public Wi-Fi is not the threat it once was. In the past, open networks were a serious risk, but today the vast majority of web traffic is encrypted with HTTPS. This means that even if you are on a coffee shop’s network, the operator cannot see the content of your traffic to secure sites. The bigger risk on public Wi-Fi is someone physically looking over your shoulder.
A Virtual Private Network (VPN) is not a magic invisibility cloak. A VPN is a useful tool that encrypts your traffic and hides it from your local network operator and your ISP. It does not make you anonymous to the websites you visit. If you log in to Google with a VPN, Google still knows it is you. Furthermore, the VPN provider itself can see your traffic, so choosing a reputable, no-logs provider is essential. Use a VPN for specific purposes, but do not mistake it for total privacy.
Obsessively deleting your cookies is a losing battle. While cookies are one method of tracking, modern techniques like browser fingerprinting are far more sophisticated and do not rely on them. A good tracker-blocking extension, as mentioned in tip #5, is a more effective and less labor-intensive defense than manually clearing cookies.
Finally, forget about achieving total anonymity. Disappearing from the internet is a full-time job for spies and dissidents, not a realistic goal for the average person. The objective is practical harm reduction: making yourself a difficult and unappealing target for the vast, automated systems of surveillance capitalism and for common criminals.
Key takeaways
- Use a password manager and enable two-factor authentication (via app or hardware key) on all important accounts.
- Adopt new technologies like passkeys where available, as they are inherently resistant to phishing.
- Install a browser-based tracker blocker and switch to a private search engine to limit third-party data collection.
- Understand the limits of tools like VPNs and Incognito mode; they are not magic bullets for privacy.
- Regularly review app permissions, update your software promptly, and be mindful of what you share on social media.
- Exercise your legal rights under GDPR/CCPA to request and delete your data from companies and data brokers.
Frequently asked questions
Is a VPN still worth it, then?
Yes, for specific uses. A VPN is valuable for hiding your web traffic from your Internet Service Provider or an untrusted network operator (like at a hotel or airport). It is also effective for bypassing geographic content restrictions. Just understand its limitations: it does not make you anonymous to the websites you log into, and you are trusting the VPN provider with your data. Choose a reputable one with a strict no-logs policy.
Are password managers safe? What if they get hacked?
Reputable password managers are designed with a 'zero-knowledge' architecture. They are heavily encrypted using your master password, which the company never sees. Even if their servers were breached, your data would remain a scrambled, useless mess to the attackers. The risk of using weak or reused passwords across multiple sites is exponentially greater than the risk of a top-tier password manager being compromised in a meaningful way. It is a massive security upgrade.
What is the difference between a passphrase and a password?
Functionally, nothing. A passphrase is just a modern method for creating a very strong password. Instead of a hard-to-remember string of random characters like `9#kG&vP!4`, a passphrase consists of several unrelated words, like `enormous-coffee-planet-ladder`. This makes it vastly easier for a human to remember and type, but its length makes it exceptionally difficult for a computer to guess through brute-force attacks.
Will these steps make me 100% private and secure?
No. Nothing will. The goal is not to achieve an impossible state of perfect privacy but to practice effective harm reduction. By following these steps, you significantly reduce your digital footprint and your 'attack surface.' You make yourself a much more difficult and less profitable target for advertisers, data brokers, scammers, and low-level criminals, who will simply move on to easier targets. It is about control and resilience, not invisibility.
Is Incognito or Private Browsing mode enough for privacy?
Absolutely not. Its only function is to prevent your browser from saving your history, cookies, and site data on your local device for that session. It does not hide your activity from your Internet Service Provider, your employer (if on a work network), or the websites you visit. It is useful for hiding your activity from other people who use the same computer, but it provides no real privacy from outside observers.
I got an email saying I'm in a data breach and I need to pay to fix it. Is it real?
This is almost certainly a scam. Criminals use fear to extort money. Never pay. Instead, independently verify the claim by using a free, trusted service like Have I Been Pwned. If your email was part of a legitimate breach for a specific service, go to that service's website directly (do not use any links in the email) and change your password. Then, change that same password on any other site where you might have reused it.
Keep reading on Novapedia
- common cybersecurity threats and how to stay safe
For a deeper look at this and other dangers, it is worth reading about common cybersecurity threats and how to stay safe.
- systems like ChatGPT
It can be used by advertisers, data brokers, future employers, and even large language models, as data scraped from the public web is a primary training source for systems like ChatGPT.
- a web request's long journey
By better understanding the internet's core components, as described in an article on a web request's long journey, you can identify points to bolster your privacy.
Further reading
Authoritative external sources for readers who want the primary material.
- Top tips for staying secure online — National Cyber Security Centre (UK)
- Cyber Essentials — Cybersecurity and Infrastructure Security Agency (USA)
- Surveillance Self-Defense — Electronic Frontier Foundation
- Your data matters — Information Commissioner's Office (UK)
- Identity Theft: A Recovery Plan — Federal Trade Commission (USA)