Personal data exposure
In plain terms
What you publish yourself without gauging what it reveals: a photo where an address can be read, a document with a visible number, a profile that answers your security questions.
Definition
Personal data exposure refers to the unintentional availability of information about you through your own posts and settings. Unlike the other fiches in this family, there's no intrusion or third-party collector at the start: the data is provided, and the problem comes from what it enables once read by someone looking for it.
How it works
The gap lies in the intent of the reader. You post a vacation photo; an attentive reader sees that the home is empty, the make of the car, and the street name in the background. You post a photo of a ticket, a package, or an official document; the number is legible. You answer a quiz asking for your first pet's name, your city of birth, and your mother's maiden name — exactly the account-recovery questions many services use. You leave your job title, employer, and colleagues on a professional profile, which is enough to build a credible message in your name. None of this is a mistake, which is exactly why it isn't visible in the moment: the post makes sense in its context, and has an entirely different use outside it.
Warning signs
- Posts showing a legible document, ticket, badge, or license plate
- Photos where the background identifies the home, school, or workplace
- Quizzes and chain posts asking for information that doubles as security-question answers
- Public profile showing full date of birth, address, phone number
- Real-time posting of an extended absence from home
- Old accounts still online, with settings never revisited
How to verify
Look at your profiles logged out, in a private browsing window: that's what a stranger sees, which the logged-in view never shows. Search your name and phone number in a search engine, and your photos with a reverse image search. Do the exercise on your old accounts, which are usually the most open because no one revisits their settings.
What to do
Set default visibility to your contacts rather than the public. Remove from profiles anything that answers a security question. Before posting an image, look at what it contains beyond its subject. Post about an absence after you're back rather than during it. Close accounts you no longer use, instead of leaving them as they are.
If it already happened
Remove what can be removed and change the security questions whose answers had become public — replacing a true answer with an arbitrary one saved in a password manager is safer here than an accurate answer. For content posted by others, ask the platform for removal, then the person. If the exposure is used to harm you or to locate you, the doxxing and cyberstalking/harassment fiches cover that situation, and the response isn't the same.
Frequently asked questions
- Do you have to delete everything from your social media?
- No, and that's not where most of the work happens. Two settings do the bulk of it: default visibility restricted to your contacts, and removing whatever serves as an answer to a security question. The rest comes down to paying attention at the moment you post.
- How do I remove information that's already been published?
- You can remove it at the source and ask search engines to de-index it. On copies made in the meantime, no one can do anything, which is exactly why checking before you publish is more effective than any after-the-fact step.
Related attacks
Official sources
This article is part of the Data and digital identity family. Last updated: 2026-09-03.