Personal information is part of everyday online life.
You may provide information when creating an account, buying something, joining a class, using an application, sharing a photograph or contacting another person.
Some information genuinely needs to be shared for a service to work.
Other information may be unnecessary.
Protecting personal information means understanding what information identifies you, deciding when sharing is necessary and reducing access when it is not.
What is personal information?
Personal information is information that can identify you, help locate you or reveal something specific about you.
Examples can include:
- your full name
- home address
- telephone number
- email address
- date of birth
- school or workplace
- current or regular locations
- photographs and videos
- account usernames
- financial information
- identity document details
Some information may not identify you by itself but can become identifying when combined with other information.
Small details can add up
Imagine that one public profile shows your first name.
Another post shows your school.
A photograph shows the street near your home.
A birthday post reveals your age.
Each detail may appear ordinary on its own.
Together, they can reveal much more about you.
Not all personal information has the same sensitivity
Some information deserves particularly careful protection.
Examples include:
- passwords and passphrases
- authentication and recovery codes
- bank and payment details
- identity document numbers
- account recovery information
- private health information
- information that reveals exactly where you live or regularly travel
A useful rule is to think about the harm that could occur if the information reached the wrong person.
Share information for a reason
Before entering personal information into a website, application or form, ask:
Why does this service need this information?
If you can understand the reason and trust the service, sharing may be appropriate.
If the request seems unrelated to what you are trying to do, investigate before providing it.
Do not fill every optional field automatically
Online profiles and forms often contain optional fields.
You do not have to publish information simply because a box exists for it.
Consider whether the service genuinely needs:
- your full birth date
- telephone number
- home address
- school
- workplace
- relationship information
- other personal details
If the information is optional and provides no useful benefit to you, leaving it blank may reduce unnecessary exposure.
Verify who is asking
A request for personal information can look professional and still be fraudulent.
Scammers may pretend to represent:
- a bank
- a delivery company
- a government agency
- a school
- an employer
- a technology company
- a social media service
Do not rely only on the name or logo in a message.
Unexpected requests deserve extra caution
Be especially careful when someone unexpectedly asks for:
- a password
- an authentication code
- a payment card number
- bank information
- identity document details
- a photograph of an identity document
- account recovery information
Instead of using the contact details in the unexpected message, find the organization's official website or application independently.
A verification code is personal security information
A login or recovery code can give another person access to an account.
Do not send it to someone who contacts you unexpectedly.
If you receive a code when you are not attempting to sign in, treat it as a warning that someone may be trying to access your account.
Protect your online accounts
Your accounts contain personal information and can also provide access to other services.
Protect them with:
- unique passwords or passphrases where passwords are used
- a reputable password manager when appropriate
- multi factor authentication
- current recovery information
Review Password Managers Explained Clearly for help managing unique passwords.
Review Multi Factor Authentication: What It Does and Why It Helps for stronger account protection.
Your email account deserves special protection
Your main email account may contain years of personal information.
It may also be used to reset passwords for many other accounts.
If someone gains access to your email, they may be able to discover which services you use and attempt to reset other accounts.
Use a unique credential and additional authentication where available.
Protect the devices that hold your information
Phones, tablets and computers can contain:
- messages
- photographs
- saved account sessions
- contacts
- documents
- payment applications
- location history
Protect your devices with a screen lock and current software updates.
Configure them to lock automatically when they are not being used.
Install software updates
Updates often fix security weaknesses that could otherwise be used to access a device or its information.
Keep current:
- the operating system
- web browsers
- applications
- security software where used
Automatic updates can make this easier when your device supports them.
Download applications from trusted sources
A malicious application can try to collect information from your device.
Use the official application store or another source recommended by the device or software provider.
Be cautious when a website asks you to install an unfamiliar application outside the normal process.
Review application permissions
Applications may request access to features such as:
- camera
- microphone
- contacts
- photographs
- location
- files
- notifications
Some permissions are necessary for a feature to work.
Others may not be needed for the way you use the application.
Review permissions and remove access that no longer serves a purpose.
Permission should match purpose
A map application may have a clear reason to request location while you are navigating.
A simple calculator may not have an obvious reason to request your contacts.
When a permission seems unrelated to the application's function, investigate before allowing it.
Review permissions again later
You may have approved a permission months ago and forgotten about it.
Device settings usually provide a way to review which applications can access sensitive features.
A later HubEgg lesson will guide you through reviewing mobile application permissions.
Control location sharing
Your location can reveal where you live, study, work, shop or spend time.
Applications may use location for useful features, but access should match your needs.
Consider whether location should be available:
- all the time
- only while using the application
- only once
- not at all
The choices available depend on your device and application.
Photographs can reveal personal information
Before sharing an image, look beyond the main subject.
A photograph may reveal:
- a house number
- street name
- school uniform
- vehicle registration details
- workplace badge
- identity document
- computer screen
- letter or parcel label
Check the background before publishing.
Documents deserve extra care
Do not casually upload or send photographs of identity documents.
If a trusted service genuinely needs a document for verification, use its official process and understand why the document is required.
Avoid leaving unnecessary document copies in shared folders, messaging conversations or public cloud links.
Be careful with screenshots
A screenshot can accidentally reveal more than the information you intended to show.
It might contain:
- another person's message
- an email address
- an account number
- a browser tab title
- a notification
- a verification code
Review the entire image before sharing it.
Think about other people's privacy too
Personal information does not have to belong to you.
Before sharing someone else's:
- telephone number
- address
- photograph
- private conversation
- location
- school or work information
consider whether that person agreed to the sharing.
Social media can reveal information over time
One post may not reveal very much.
Years of posts can create a detailed picture of your routines, relationships, locations and interests.
Review Safe Social Media Habits for Everyday Users for more guidance.
Review privacy settings
Websites and applications often provide controls over:
- who can see your profile
- who can find you
- who can message you
- what information appears publicly
- whether activity is personalized or tracked
- whether location is shared
Review these controls periodically because services and settings can change.
Understand that websites and applications collect data
Online services may collect information about how you use them.
This can include information that you deliberately provide and information generated by your activity.
Before giving an unfamiliar service significant personal information, consider reviewing its privacy information and reputation.
A privacy policy is useful but does not make every service trustworthy
A service may publish a privacy policy because it is required to explain its practices.
That does not mean you should automatically provide every piece of information it requests.
You should still consider whether you trust the organization and whether the information is necessary.
Be cautious with online quizzes and surveys
Some quizzes ask for information about:
- family members
- pets
- birthdays
- schools
- first cars
- favourite places
The activity may be harmless, but the information can still add to your public profile.
You do not need to answer every question simply because it appears entertaining.
Be careful with public usernames
A username used across many services can make it easier to connect separate profiles.
That may be convenient, but it can also make your activity easier to link together.
For accounts where privacy matters, consider whether the public username reveals more than necessary.
Use secure payment processes
When buying online, enter payment information only through the genuine seller or payment service you intended to use.
Be suspicious if a seller suddenly asks you to move payment to an unusual channel or send financial information through ordinary messages.
Investigate unfamiliar sellers independently before paying them.
Do not store payment details everywhere for convenience
Some services offer to remember payment information.
This can be convenient, but it also means another account or company stores information connected to your payments.
Decide whether the convenience is useful and protect any account that stores payment information.
Public networks still require normal caution
Modern websites and applications commonly encrypt connections, but using a public network does not make every website or application trustworthy.
Continue to verify the service you are using.
Avoid ignoring browser security warnings simply because you need to finish a task quickly.
Do not disable security warnings casually
If your browser or device warns that a connection, certificate, application or download may be unsafe, investigate the warning.
Do not automatically bypass it just to continue.
Phishing is designed to collect personal information
A phishing message may try to obtain:
- login credentials
- payment information
- identity details
- verification codes
- contact information
Review How to Recognize Phishing Messages for signs of suspicious requests.
Use independent verification
If a message says your account, payment or identity needs urgent attention, do not depend on the link or telephone number in that message.
Open the organization's official website or application yourself.
This separates your verification process from the contact that may be fraudulent.
What is identity theft?
Identity theft occurs when someone uses personal or financial information without permission to impersonate another person or obtain something in that person's name.
Stolen information can be used for fraudulent accounts, purchases or other forms of impersonation.
Protecting personal information reduces opportunities for misuse, although no individual can eliminate every risk.
Watch for warning signs of misuse
Possible warning signs can include:
- account login alerts you do not recognize
- password resets you did not request
- transactions you did not make
- new accounts you did not create
- messages sent from your account without your knowledge
- changes to recovery information
Investigate unexpected activity promptly.
If personal information has been exposed
The correct response depends on what information was exposed.
For example, if a password was exposed, change that credential wherever it was used and make every affected account unique.
If an account was compromised, follow the provider's official recovery process and review authentication methods and sessions.
If financial information was involved, contact the relevant financial provider using its official channel.
A data breach does not always expose the same information
When an organization reports a breach, find out what categories of information were involved.
A breach involving an email address may require different action from one involving passwords, payment information or identity documents.
Follow the organization's official notice and trusted government guidance relevant to the information involved.
Be cautious after a breach
Scammers may use information from a real breach to create convincing follow up messages.
A message that knows your name or email address is not automatically genuine.
Verify breach related instructions using the organization's official website or another trusted source.
Delete information you no longer need
Keeping unnecessary copies of sensitive information creates more places where it must be protected.
Review old:
- downloads
- screenshots
- shared folders
- cloud files
- documents
- unused accounts
Remove information you no longer need when it is safe and appropriate to do so.
Before selling or giving away a device
A phone, tablet or computer may contain personal information even after you stop using it.
Follow the device manufacturer's official instructions for signing out, removing accounts and securely erasing or resetting the device before transferring it to another person.
Do not forget backups
If a device contains important files, make sure necessary information is safely backed up before erasing the device.
Protect backups because they can contain the same sensitive information as the original device.
Children and teenagers may need help deciding what to share
Younger users may encounter forms, games or messages asking for information they do not understand.
When unsure, ask a trusted adult before sharing information that identifies you, reveals your location or gives access to an account.
A useful rule for everyone
When a request for personal information appears, ask three questions:
- Who is asking?
- Why do they need it?
- What could happen if this information reached someone else?
If the answers are unclear, do not rush.
Personal information protection checklist
Review these habits:
- I avoid publishing unnecessary personal details.
- I verify unexpected requests for sensitive information independently.
- My important accounts use unique credentials and additional authentication.
- My devices are locked and updated.
- I review application permissions.
- I control location sharing.
- I check photographs and screenshots before sharing them.
- I review privacy settings on important services.
- I avoid sharing passwords and verification codes.
- I investigate unusual account or financial activity quickly.
- I remove unnecessary sensitive files and unused access where appropriate.
The main idea
Protecting personal information does not mean never sharing anything online.
It means sharing deliberately.
Know what information identifies you, provide it only when there is a clear reason and verify who is asking before sharing sensitive details.
Protect the accounts and devices that hold your information, review application permissions and privacy settings and be cautious with messages designed to make you act quickly.
Small privacy habits repeated consistently can greatly reduce unnecessary exposure.
Continue learning
Review Complete Guide to Staying Safe Online for the wider Digital Safety framework.
Review Safe Social Media Habits for Everyday Users for privacy and sharing on social platforms.
Review How to Recognize Phishing Messages for suspicious requests for information.