You have discovered a breach through a service notification, Have I Been Pwned or the breach section of your Data Knight report. This seven-day plan helps you organise the response: secure your accounts, check where your information appears and request erasure where possible.
Do not wait for a scheduled day to deal with an urgent risk. Change a compromised or reused password immediately. Contact your bank immediately if payment details are being misused. The timetable is a way to organise the remaining work, not a reason to postpone account security.
Why a breach may extend beyond the affected site
An exposed email address, password, phone number or address can be copied and combined with other information.
| Stage | What may happen |
|---|---|
| Exposure | A website, app or database discloses personal information |
| Circulation | Files are copied, exchanged or sold |
| Enrichment | Records are linked with directories, forms or public profiles |
| Broker exposure | Brokers may separately hold profiles built from public or commercial sources |
| Misuse | Contact details can support scams, impersonation or unwanted messages |
This does not mean that every breach feeds a broker or that a broker holding your details obtained them illegally. Those connections require evidence. It does mean that changing one password will not remove contact information published elsewhere.
A useful response combines immediate account security with reducing unnecessary public and commercial exposure. Read more about personal data resale and spam after a breach.
Day 1: confirm and prioritise
Goal: understand which information and accounts are affected.
- Identify the service involved and the reported data categories: email, password, phone number, financial information or other sensitive details.
- Confirm a notification through the service's official website or app. Do not follow an unexpected message's login link.
- Prioritise email, banking, important social accounts and any account where a compromised password was reused.
- Use the breach-checking guide and a free scan to review supported sources of exposure.
A result in a breach database does not automatically mean that your current password is known. Equally, no match does not rule out an incident that the database does not cover.
Days 2–3: complete your account security checks
Goal: close access routes and check for signs of misuse. Carry out urgent password changes on day 1; use these days to finish the wider review.
| Action | Why it helps |
|---|---|
| Set unique passwords for affected and reused credentials | Prevent one exposed password from opening several accounts |
| Enable two-factor authentication where available | Add protection beyond a password |
| Revoke unfamiliar sessions and devices | Remove existing access where the service supports it |
| Review recovery details and reset notifications | Spot changes or attempts you did not authorise |
Two-factor authentication reduces risk but does not make an account immune to phishing or stolen sessions. Review the account itself, not only its password.
If a password is exposed, follow the immediate leaked-password checklist. Avoid changing only a digit and reusing that new variation across several services.
Days 4–5: map brokers and public web exposure
Goal: identify organisations and pages that still display or hold your details.
A Data Knight scan separates three areas:
- Breaches: supported records of known incidents.
- Public web: indexed pages, directories and other public mentions.
- Brokers: sources that collect or aggregate personal profiles. See how data brokers work.
Review possible matches before acting. A name match is not always your profile, and the scan is not exhaustive.
Prioritise information that creates a practical problem: a personal phone number, home address, old employer detail or unwanted people-search profile. You do not have to remove everything. Decide which sources you want to keep and which you want to address.
Days 6–7: request erasure
Goal: reduce data held by identified organisations where you can exercise your rights.
The right to erasure under Article 17 GDPR applies when its conditions are met. Some records must or may be retained under an applicable exception.
- Identify the target organisation and the specific page, profile or identifier concerned.
- Send a clear request stating what you want erased. An erasure request and a marketing objection are different rights; use the one that fits.
- Keep the request and its sending date. The usual response deadline is one month, with extensions possible under the GDPR's conditions.
- Review the response and follow up where needed. See broker follow-ups and CNIL complaints.
You can manage requests yourself or use Remove my data. After the scan, choose your targets and authorise the requests before they are sent. The service helps with sending and tracking; it cannot guarantee every recipient will erase every record.
What this plan cannot solve
| Realistic objective | Limit |
|---|---|
| Reduce broker profiles and unnecessary public exposure | It cannot guarantee that no organisation will collect data again |
| Strengthen accounts with unique passwords, 2FA and session checks | It cannot make all account compromise impossible |
| Exercise GDPR rights where applicable | Identification, lawful retention and enforcement can complicate a request |
| Respond to a past breach | It cannot retrieve every copy already stolen or circulated |
The GDPR can apply to certain organisations outside the EU too; scope is not determined solely by server location. Practical enforcement may still be difficult.
The aim is to reduce the ways someone could misuse your accounts and personal details, while keeping a clear record of what you have done.
Quick FAQ
Do I have to wait seven days before requesting broker removal? No. Start a request as soon as you have identified the correct target and information. Deal with compromised accounts immediately, regardless of the timetable.
Does every breach involve data brokers? No. A breach and a broker profile can exist independently. Check each source on its own evidence rather than assuming a direct connection.
Is Data Knight free? The scan is free. Sending and tracking erasure requests through Remove my data is part of the paid offer, if you choose to delegate that work.
Summary
| Day | Priority |
|---|---|
| 1 | Confirm the incident, secure compromised accounts immediately and review exposure |
| 2–3 | Finish password, 2FA, session and recovery-detail checks |
| 4–5 | Review public pages and broker sources |
| 6–7 | Send appropriate erasure requests and keep a record for follow-up |
Start a free scan to review supported breaches, public web mentions and broker sources. Then choose removal targets and track their responses.
Read next: Checking for a breach, personal data resale, spam after a breach and removing broker profiles.



