GeneratePass
Privacy 14 min read

Online Privacy Checklist: 50 Steps to Protect Your Digital Life

By GeneratePass Developers | Published: July 08, 2026 | Last Updated: July 08, 2026

Why You Need a Privacy Checklist

Online privacy is not a single setting you toggle. It is a collection of dozens of small decisions across your accounts, devices, browsers, and networks. Most people address privacy reactively — they change a setting after a breach, install an extension after hearing about a tracking scandal, or review their social media privacy after a negative experience.

The problem with reactive privacy management is that by the time you act, your data has already been exposed. A proactive approach — systematically working through a comprehensive checklist — is far more effective.

This article provides 50 actionable steps organized into six categories. Each step includes a clear explanation of why it matters and how to implement it. Work through the checklist at your own pace, but start with the critical items today.


Account Security (Steps 1-10)

Your accounts are the primary targets for attackers. Securing them is the foundation of online privacy.

Step 1: Use a password manager

A password manager generates, stores, and autofills unique passwords for every account. You memorize one master password; the manager handles the rest. Choose a reputable, audited manager with zero-knowledge encryption.

Step 2: Generate unique passwords for every account

No two accounts should share a password. Use our Password Generator to create cryptographically secure random passwords for each account. A 16-character random password with mixed character types provides excellent protection.

Step 3: Enable two-factor authentication (2FA)

Enable 2FA on every account that supports it. Prioritize email, banking, cloud storage, and social media. Use authenticator apps (Google Authenticator, Authy) or hardware keys (YubiKey). Avoid SMS-based 2FA.

Step 4: Use a strong master password

Your password manager’s master password is the key to your entire digital life. Make it at least 16 characters, completely random, and never used anywhere else. Generate and check its entropy with our Entropy Calculator.

Step 5: Set up account recovery options

Configure backup email addresses and phone numbers for account recovery. Store recovery codes in your password manager. Without recovery options, a locked account may be permanently lost.

Step 6: Review connected apps and services

Audit which third-party applications have access to your accounts. Remove access for apps you no longer use. Check Google, Facebook, Twitter, and GitHub account settings regularly.

Step 7: Use email aliases

Create separate email aliases for different purposes (shopping, social media, banking). This limits the impact of a breach at any single service and makes it easier to identify which service leaked your email.

Step 8: Disable password hints

Security questions and password hints provide attackers with useful information. If forced to set hints, use nonsensical answers stored in your password manager.

Step 9: Set up breach monitoring

Enable automatic breach notifications. Use our Breach Checker to monitor your credentials against known data breaches. Your password manager may also offer built-in breach monitoring.

Step 10: Audit passwords quarterly

Every three months, review your password manager’s security audit. Replace weak, reused, or old passwords with newly generated ones.


Browser Privacy Settings (Steps 11-20)

Your browser is your primary interface with the internet. Proper configuration dramatically improves your privacy.

Step 11: Update your browser

Enable automatic updates. An outdated browser is one of the most common attack vectors. Every update contains critical security patches.

Step 12: Block third-party cookies

Third-party cookies are the primary mechanism for cross-site tracking. Block them in your browser settings. Some sites may break; add exceptions for trusted sites that require cookies to function.

Step 13: Enable DNS-over-HTTPS

DNS-over-HTTPS (DoH) encrypts your DNS queries, preventing your ISP and network operators from seeing which websites you visit. Enable it in your browser settings and choose a trusted resolver like Cloudflare (1.1.1.1) or Google (8.8.8.8).

Step 14: Install a content blocker

uBlock Origin is the gold standard for content blocking. It blocks malicious ads, tracking scripts, and fingerprinting attempts. It is open source, lightweight, and highly effective.

Step 15: Disable browser telemetry

Most browsers send usage data to their vendors. While some telemetry is anonymous, reducing it minimizes your data exposure. Check your browser’s privacy settings and disable non-essential telemetry.

Step 16: Enable “Do Not Track”

While not universally honored, the “Do Not Track” signal expresses your preference not to be tracked. Enable it in your browser settings.

Step 17: Clear cookies on exit

Configure your browser to delete cookies and site data when you close the browser. This prevents persistent tracking across sessions.

Step 18: Use private browsing for sensitive activities

Use incognito or private browsing mode when accessing sensitive accounts or searching for private information. Remember that this does not make you anonymous — combine it with other measures.

Step 19: Review and limit extensions

Audit your browser extensions regularly. Remove any you do not actively use. Each extension is a potential attack vector. Verify that installed extensions are from reputable developers.

Step 20: Bookmark important sites

Access important sites (banking, email) through bookmarks rather than clicking links. This prevents accidentally visiting phishing sites with similar-looking URLs.


Social Media Privacy (Steps 21-30)

Social media platforms collect vast amounts of data about you and expose it to advertisers, data brokers, and sometimes the public.

Step 21: Review privacy settings on every platform

Each social media platform has its own privacy settings. Review and tighten them:

  • Facebook: Settings → Privacy → restrict who can see your posts, friend list, and profile information
  • Instagram: Settings → Privacy → set account to private, restrict story viewing
  • Twitter/X: Settings → Privacy and Safety → protect your tweets, disable location
  • LinkedIn: Settings → Visibility → limit profile visibility

Step 22: Limit personal information on profiles

Remove or hide your phone number, physical address, date of birth, and relationship status from public profiles. This information is used for identity theft and social engineering attacks.

Step 23: Disable location tagging

Turn off location services for social media apps. Never tag your real-time location in posts — it tells attackers when your home is empty.

Step 24: Review tagged photos and posts

Configure your social media accounts to require your approval before tags appear on your profile. Review and remove unwanted tags.

Step 25: Limit app permissions

Social media apps often request excessive permissions (contacts, camera, microphone, location). Revoke permissions that are not necessary for the app’s core functionality.

Step 26: Disable facial recognition

If your social media platform offers facial recognition, disable it. This prevents the platform from automatically identifying you in photos posted by others.

Step 27: Review ad preferences

Most social media platforms allow you to view and manage ad targeting preferences. While you cannot eliminate targeted advertising entirely, you can limit the data used for targeting.

Step 28: Remove old posts

Periodically review and delete old posts that contain personal information, location data, or other sensitive content. Many platforms offer tools to bulk-delete or archive old posts.

Step 29: Separate personal and professional accounts

Use different email addresses and accounts for personal social media and professional networking. This limits cross-platform data correlation.

Step 30: Be cautious about quizzes and surveys

Personality quizzes, “which [X] are you” games, and surveys are often designed to harvest personal information for social engineering attacks. Avoid them.


Email Security (Steps 31-35)

Email is the master key to your digital life. If an attacker controls your email, they can reset passwords for every other account.

Step 31: Use a secure email provider

Consider using a privacy-focused email provider (ProtonMail, Tutanota) that offers end-to-end encryption and does not scan your emails for advertising purposes.

Step 32: Enable 2FA on email accounts

Your email account is the most important account to protect with 2FA. If an attacker gains access to your email, they can reset passwords for all your other accounts.

Step 33: Use email aliases for sign-ups

Never give your primary email address to websites you do not trust. Use email aliases (SimpleLogin, Apple’s Hide My Email) for sign-ups and newsletters.

Step 34: Be cautious with attachments

Never open attachments from unknown senders. Even attachments from known senders should be treated cautiously if the email is unexpected. Verify with the sender through a different channel.

Step 35: Set up email forwarding rules

Periodically check your email settings for unauthorized forwarding rules. Attackers sometimes set up rules to silently forward copies of your emails to their own addresses.


Device Security (Steps 36-42)

Your devices store your data and provide access to your accounts. Securing them is essential.

Step 36: Enable full-disk encryption

Enable FileVault (macOS), BitLocker (Windows), or LUKS (Linux) to encrypt your entire hard drive. If your device is stolen, the data remains protected.

Step 37: Set a strong device password/PIN

Use a strong password or PIN for device login. Avoid simple PINs like 1234 or 0000. Enable biometric authentication (fingerprint, face recognition) for convenience alongside a strong backup PIN.

Step 38: Enable remote wipe

Enable Find My iPhone, Find My Device (Android), or similar features that allow you to remotely wipe your device if it is lost or stolen.

Step 39: Keep your operating system updated

Enable automatic OS updates. Operating system updates contain critical security patches for vulnerabilities that could be exploited to compromise your device.

Step 40: Install reputable security software

Use your operating system’s built-in security tools (Windows Defender, macOS XProtect) or a reputable third-party security suite. Keep it updated.

Step 41: Disable auto-connect to Wi-Fi

Disable your device’s tendency to automatically connect to available Wi-Fi networks. Manually connect only to networks you trust.

Step 42: Review app permissions regularly

Audit the permissions granted to installed apps. Revoke permissions that are not necessary for the app’s functionality. Pay special attention to apps with access to your camera, microphone, contacts, and location.


Network Privacy (Steps 43-50)

Your network connection is the pipe through which all your data flows. Securing it protects everything else.

Step 43: Use a VPN on public networks

Always use a VPN when connected to public Wi-Fi. A VPN encrypts your traffic, preventing eavesdropping and man-in-the-middle attacks. Choose a reputable, paid VPN with an audited no-logs policy.

Step 44: Secure your home Wi-Fi

Change your router’s default password. Use WPA3 encryption (or WPA2 if WPA3 is not available). Create a strong Wi-Fi password. Disable WPS (Wi-Fi Protected Setup), which has known vulnerabilities.

Step 45: Update your router firmware

Router firmware often contains security vulnerabilities. Check for updates regularly and enable automatic updates if available. An outdated router firmware can compromise every device on your network.

Step 46: Create a guest network

Set up a separate guest network for visitors and IoT devices (smart TVs, cameras, thermostats). This isolates your main network from potentially compromised devices.

Step 47: Disable UPnP

Universal Plug and Play (UPnP) automatically opens ports on your router, which can be exploited by attackers. Disable it and manually configure port forwarding only when necessary.

Step 48: Use encrypted DNS

Configure your router or devices to use encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) to prevent DNS-based tracking and manipulation.

Step 49: Monitor network devices

Regularly review the list of devices connected to your network. Remove any unrecognized devices. Many routers provide a device list in their admin interface.

Step 50: Consider a Pi-hole or DNS filter

A Pi-hole or similar DNS filter blocks ads and trackers at the network level, protecting every device on your network without requiring individual configurations.


Complete Privacy Checklist

#StepCategoryPriority
1Use a password managerAccount SecurityCritical
2Unique passwords for every accountAccount SecurityCritical
3Enable 2FA on all accountsAccount SecurityCritical
4Strong master password (16+ chars)Account SecurityCritical
5Set up account recovery optionsAccount SecurityHigh
6Review connected appsAccount SecurityMedium
7Use email aliasesAccount SecurityHigh
8Disable password hintsAccount SecurityMedium
9Set up breach monitoringAccount SecurityHigh
10Audit passwords quarterlyAccount SecurityMedium
11Update browser automaticallyBrowser PrivacyCritical
12Block third-party cookiesBrowser PrivacyHigh
13Enable DNS-over-HTTPSBrowser PrivacyHigh
14Install content blockerBrowser PrivacyHigh
15Disable browser telemetryBrowser PrivacyMedium
16Enable “Do Not Track”Browser PrivacyLow
17Clear cookies on exitBrowser PrivacyHigh
18Use private browsing for sensitive tasksBrowser PrivacyMedium
19Review extensions quarterlyBrowser PrivacyHigh
20Bookmark important sitesBrowser PrivacyMedium
21Review social media privacy settingsSocial MediaHigh
22Limit profile informationSocial MediaHigh
23Disable location taggingSocial MediaHigh
24Review tagged photosSocial MediaMedium
25Limit app permissionsSocial MediaHigh
26Disable facial recognitionSocial MediaMedium
27Review ad preferencesSocial MediaLow
28Remove old postsSocial MediaMedium
29Separate personal/professional accountsSocial MediaMedium
30Avoid quizzes and surveysSocial MediaMedium
31Use secure email providerEmail SecurityHigh
32Enable 2FA on emailEmail SecurityCritical
33Use email aliases for sign-upsEmail SecurityHigh
34Be cautious with attachmentsEmail SecurityHigh
35Check email forwarding rulesEmail SecurityMedium
36Enable full-disk encryptionDevice SecurityHigh
37Strong device password/PINDevice SecurityHigh
38Enable remote wipeDevice SecurityHigh
39Keep OS updatedDevice SecurityCritical
40Install security softwareDevice SecurityMedium
41Disable auto Wi-Fi connectDevice SecurityMedium
42Review app permissionsDevice SecurityMedium
43Use VPN on public networksNetwork PrivacyHigh
44Secure home Wi-Fi (WPA3)Network PrivacyHigh
45Update router firmwareNetwork PrivacyHigh
46Create guest networkNetwork PrivacyMedium
47Disable UPnPNetwork PrivacyMedium
48Use encrypted DNSNetwork PrivacyHigh
49Monitor network devicesNetwork PrivacyMedium
50Consider DNS filterNetwork PrivacyLow

Frequently Asked Questions

Where should I start if this list feels overwhelming? Start with the critical priority items: unique passwords with a password manager, 2FA on email and banking, browser updates, and blocking third-care cookies. These four steps alone dramatically improve your security. Then work through the high-priority items at your own pace.
Do I need to do all 50 steps? Not necessarily. The checklist is comprehensive — some steps matter more than others depending on your threat model. A journalist or activist needs stronger protections than a casual internet user. Focus on the critical and high-priority items first, then add medium and low items based on your personal risk level.
How often should I revisit this checklist? We recommend a full review every 6 months. Privacy settings change, new threats emerge, and your own circumstances evolve. Set a calendar reminder to revisit the checklist twice a year.
Will these steps make me completely anonymous online? No. True anonymity requires extreme measures (Tor, burner devices, Tails OS) that are impractical for most people. This checklist focuses on practical privacy — reducing your exposure, limiting tracking, and protecting your accounts — rather than complete anonymity.
Are these steps enough to protect against all threats? No security measure provides absolute protection. This checklist addresses the most common and impactful threats. For maximum security, combine these steps with ongoing security awareness, cautious online behavior, and prompt response to breach notifications. Generate tools like our [Password Generator](/password-generator) and [Breach Checker](/breach-checker) help you maintain strong security practices.

References

  1. Electronic Frontier Foundation. “Surveillance Self-Defense: Tools and Tactics for Protecting Your Privacy.” https://ssd.eff.org/
  2. National Institute of Standards and Technology (NIST). “Privacy Framework.” https://www.nist.gov/privacy-framework
  3. Privacy Rights Clearinghouse. “Privacy Tips and Tools.” https://privacyrights.org/
  4. Mozilla Foundation. “Privacy Not Included: Buyer’s Guide.” https://foundation.mozilla.org/privacynotincluded/
  5. Center for Internet Security. “CIS Controls v8.1.” https://www.cisecurity.org/controls
  6. Privacy International. “Guide to Online Privacy.” https://privacyinternational.org/

About the Author

The GeneratePass Editorial Team builds privacy-first security tools that run entirely in your browser. Every tool on GeneratePass processes data locally — nothing is ever sent to a server. Visit generatepass.me to try our free Password Generator, Entropy Calculator, and Breach Checker.

GeneratePass Developers

Verified Author

Security researchers, cryptography engineers, and software developers dedicated to making browser-based cryptographic tools accessible and secure. We write guides with a focus on local execution, zero-trust patterns, and client-side data sovereignty.

Focus: Cryptography Standard: zero-trust