Can you really delete yourself from the Internet?

No.

I want to give you that answer straight away, because almost everything written on this subject buries it under a listicle, and the burying is where the harm happens. People go looking for a door marked “erase me,” they pay someone to walk them through it, and they come out the other side believing they are gone. They are not gone. They are slightly less visible, temporarily, and they have stopped watching.

That is worse than knowing the truth. So let me tell you the truth, and then let me tell you what to do about it, because the honest answer is not a counsel of despair. It’s the beginning of a much better defence than the one you were sold.

First, understand that “you” are not in one place

The reason deletion fails is that there is no single “you” on the internet to delete. There are at least six of you, and each obeys different physics.

There is the you held by data brokers and people-search sites, the ones that assemble your name, age, address history, relatives, and phone number into a profile and sell it. In the United States alone there are well over seven hundred of these. This is the version of you that is, in principle, deletable.

There is the you sitting in breach dumps. Once your details have been stolen and traded, they are out. Permanently. No law reaches them, no service removes them, and the people holding them are not accepting deletion requests.

There is the you in public records: the electoral roll, property records, court filings, company registers. Much of this is deliberately public by statute. You cannot delete it, because the state has decided it should be visible, and the brokers know it, which is why public records are the wellspring that feeds the entire industry.

There is the you in archives and caches, the Wayback Machine, search engine snapshots, screenshots on other people’s hard drives. There is the you on platforms, which you can mostly control. And there is the you in other people’s content, the photograph you’re tagged in, the blog post that names you, the local newspaper story from 2009. That version belongs to someone else.

Any honest conversation about deletion has to start here, because most of those categories are not deletable at all, and the industry that sells you deletion is only ever addressing the first one.

What actually happens when you try

Here is where the evidence gets uncomfortable, and I would rather you were uncomfortable now than complacent later.

Consumer Reports ran the most rigorous study I know of on this. They took thirty-two volunteers, signed them up to seven different removal services, and tracked thirteen people-search sites over four months to see what actually disappeared. Across all the services, of the personal profiles they found, roughly thirty-five percent were gone after four months. Not ninety. Thirty-five.

The spread was enormous. The two best services cleared around sixty-five to sixty-eight percent. The two worst cleared four percent and six percent. Read that again: people were paying an annual subscription for a service that removed four records in every hundred.

Then there is the finding that should reframe the whole market. The researchers ran a control group where they did the opt-outs manually themselves. Doing it by hand achieved seventy percent, better than every paid service tested. And these were trained privacy professionals who, by their own account, built custom automation to speed the work along. So the honest reading is not “do it yourself, it’s better.” It’s this: even experts, with tooling, working carefully, could only reach seventy percent. Nothing reaches a hundred. Nothing comes close.

Two more details from that study have stayed with me. The cheapest service tested, at twenty dollars a year, performed second best, beating one costing over two hundred. Price tells you almost nothing about performance. And the volunteers in New York had slightly more of their data removed than the volunteers in California, despite California having by far the tougher privacy law at the time. Regulation, at that point, was not yet biting.

And this is before we get to the re-adding. Brokers reacquire. They buy fresh feeds from the same public records, and your profile grows back like a weed through a paving stone.

Removal is not a purchase. It is a subscription, and the reason it is a subscription is that it does not stay done. That is not a flaw in the business model. That is the business model.

Troy Hunt, who runs Have I Been Pwned and has watched more stolen data pass through his hands than almost anyone alive, made the point most sharply when he was asked about these services. Scrubbing yourself from the brokers who obey the law achieves relatively little, and the operators causing the genuine harm are entirely beyond your reach. You are tidying the shop window while the back door stands open.

An industry with a conflict problem

I would not be doing my job if I recommended these services without telling you what the industry looks like from the inside.

In 2024 the security journalist Brian Krebs published an investigation into Onerep, a well-known data removal company. He established that its founder had created dozens of people-search sites over the years, and still held an ownership stake in one, an active data broker selling background reports on people. The company that would charge you to remove your data was run by a man who had built the machinery that published it. Mozilla had bundled Onerep into its Monitor service; it announced it would wind the partnership down, and then, remarkably, kept promoting the service for well over a year before finally ending it.

Krebs’s observation on this was the one worth remembering: creating and spreading the same disease your medicine is designed to cure may be deeply unethical, but in the United States it is not illegal. Neither, for that matter, is collecting and selling data on people who never agreed to it.

It goes further. When you opt out of at least one major people-search site, it has been documented that the site pushes you toward an affiliate link for a removal service, so both parties earn from the same transaction. Your removal is a lead-generation event.

And when you go looking for guidance, be aware that the review ecosystem is largely captured. Search for a comparison of these services and you will find “independent” reviews published on the blog of a direct competitor, glowing awards cited by the company that won them, and affiliate links in nearly every roundup. Even one of the vendors openly warns that most online reviews cannot be trusted because they are written by paid affiliates. When a vendor tells you not to trust vendor reviews, believe them.

So should you use one? Yes, with your eyes open

Despite all of that, I do think these services are worth paying for, provided you understand precisely what you are buying.

You are not buying deletion. You are buying time, and a lowered signal.

Doing this by hand across hundreds of brokers, every quarter, forever, is a part-time job. Paying twenty to a couple of hundred pounds a year to have most of it done for you is a rational trade.

If you’re choosing one, this is how I would vet it.

  • Check who owns it, and what else they own. This is the first question, not the last. Look for a company with no ties, present or historical, to any data broker or people-search operation. Ask the question explicitly; the good ones answer it plainly.
  • Discount the coverage numbers. A service advertising eight hundred and fifty brokers may only automate removals from a fraction of those, with the rest requiring “custom” requests you have to initiate. Ask how many are covered automatically, and whether requests are resubmitted on a recurring schedule, because the resubmission is the entire point.
  • Demand proof, not status. The better services provide before-and-after screenshots of your removed listings. “Request submitted” is not a result. A dashboard full of green ticks is not evidence.
  • Ignore the price signal. As the Consumer Reports data shows, the cheapest option may outperform the premium one. Start with a free scan, which most reputable services offer, and judge from what they actually find.
  • If your role makes you a target, buy the enterprise tier. Judges, executives, journalists, social workers, anyone in a public-facing or high-risk role should look at the business services, which assign a human specialist rather than an automated queue. This is attack-surface management, and it should be a company expense, not a personal one.

The law is arriving, and it changes the arithmetic

Here is the genuinely new development, and it is the first thing in a decade that gives me real hope.

California’s Delete Act created a single, state-run platform called DROP, where a resident makes one verified request and every registered data broker must delete their information. It opened to consumers on the first of January this year, and by the time it launched it had over two hundred thousand registrants. From the first of August, in three weeks’ time, brokers are legally obliged to check it every forty-five days and act. Failure to comply costs two hundred dollars per request, per day.

The provision that matters most, and which almost no coverage mentions, is the requirement that brokers maintain suppression lists to ensure the data is not simply re-collected and re-sold. That is the first serious legal attack on the weed-through-the-paving-stone problem. One click, six hundred brokers, and an obligation to keep you deleted.

Temper it with three caveats. It applies only to California residents. It binds only registered brokers, and the operators doing the worst harm are exactly the ones who never registered. And it exempts information that is publicly available from the government, along with data governed by credit, health, and financial regulation. So the wellspring keeps flowing.

In the UK and Europe, the right to erasure under GDPR is real but heavily qualified, and it does not touch lawful public records. The so-called right to be forgotten delists a page from a search engine; it does not delete the page. The link disappears. The thing remains.

The part that actually works: don’t be there in the first place

Deletion is expensive, partial, and permanent work. Prevention is cheap, total, and one-off. Every hour spent on the first would have been better spent on the second, ten years earlier. Since you can’t go back, start now, because the profile the brokers build in 2030 is being assembled from what you hand over this year.

Treat every form as a future broker record. The loyalty card does not need your date of birth. The retailer does not need your mobile number. The competition entry is a data-collection exercise with a prize attached. Give the minimum that the transaction actually requires, and lie cheerfully wherever no law compels the truth.

Segment your identities. One email address for people who know you, another for commerce, and, ideally, a unique alias per service, which most modern mail providers now offer for free. When an alias starts receiving spam you know precisely who sold you.

Guard your phone number like a password, because it is one. It’s the anchor for SIM-swap attacks and the recovery route into most of your accounts. Use a secondary or masked number for retail, deliveries, and sign-ups.

Close the taps at the source. In the UK, opt out of the open electoral register, which councils are permitted to sell to anyone; the full register still serves its legal purpose, but the commercial copy stops. If you’re a company director, apply to suppress your home address at Companies House. In the US, opt out of pre-screened credit offers, which shuts down one of the largest legal data flows into the broker ecosystem, and freeze your credit while you’re there.

Understand that the danger is the join, not the fact. Your employer is not sensitive. Your town is not sensitive. Your mother’s maiden name, your dog, your birthday, the school you attended: none of these, alone, matter much. Assembled into one profile, they are a spear-phishing brief and an account-recovery answer sheet. Audit your social media for the combination, not the individual posts.

And never accept a free scan from a company you haven’t vetted. You have just handed a stranger a verified, current, structured record of exactly who you are and where you live. Read that sentence twice before you type your name into the box.

Why this is a security problem, not a vanity one

I want to close by moving this out of the privacy box, because filing it there is why most people never bother.

When someone runs a social engineering attack against you, the first phase is reconnaissance. The fake IT helpdesk that calls you knows where you work. The spear phish that lands in your inbox names your manager. The SIM swap succeeds because the operator’s security question was your date of birth and your old address, and both were on a people-search site for a fiver.

Your broker footprint is not a privacy inconvenience. It is the raw material of the attack against you, and it’s sitting on a public shelf, indexed and searchable, waiting for someone with a motive.

Which gives you the right way to think about the whole problem. You are never going to reach zero. Chasing zero will exhaust you and it will fail. What you can do is make yourself more expensive to research than the next person on the list, and keep doing it, because the weeds grow back and always will.

So, can you ever really delete yourself from the internet? No. Deletion is a verb, not a destination. You cannot delete yourself; you can only keep deleting yourself, and get better at not leaving the trail in the first place.

Anyone selling you the noun is selling you something else.

Newsletter Form

Subscribe to our newsletter

Curated insights on AI's impact on information security and cyber warfare - real-world use cases and the critical skills your organization needs to stay ahead.


Related Articles

Responses