Your digital footprint is the collection of traces associated with you online: pages mentioning you, profiles held by data brokers, accounts exposed in breaches and search engine results. This guide connects the useful concepts with practical action under the GDPR. It provides general information rather than individual legal advice.
1. Why call it a footprint?
A footprint assessment goes beyond a Google search for your name. It generally brings together:
- the open web, including websites, directories and articles;
- broker databases that aggregate or resell personal information;
- known data breaches, including incidents recorded by services such as Have I Been Pwned;
- where relevant to the service and your choices, social networks and other sources.
The objective is to understand your exposure and act where possible, not to promise complete disappearance. Some processing has a lawful basis. We already explain what a digital footprint is and how to remove your traces online. This guide connects that overview with the legal framework and practical process.
2. GDPR and the right to erasure
The EU regulation gives individuals the right to request erasure in specified circumstances, for example where data is no longer necessary, consent is withdrawn and no other basis applies, a qualifying objection is made, or processing is unlawful. Erasure differs from search engine delisting: one concerns the information held by the organisation, while the other concerns a link's visibility in search results. Read GDPR Article 17 and the right to be forgotten and delisting for the distinctions.
In France, the CNIL is the data protection authority for complaints within its remit. Organisations generally have one month to respond, with extensions possible in specified cases. Google's separate personal content removal policies, covering certain sensitive information and doxxing, follow another process: see removing personal information from Google results.
3. Data brokers and the open web
Data brokers often aggregate information from public sources or partners. Our broker guide explains their role and the available options, including opt-outs and access requests. On the open web, mentions may appear in directories, news articles, forums and professional sites. Contact the site operator or data protection officer identified in the legal notice or privacy policy.
For public registers and directories, removal options depend on the legal framework. Read public registers and erasure.
4. Data breaches: what can you do?
A breach can expose credentials or other personal information in a known security incident. It cannot be erased in the same way as a broker listing. The priority is to reduce risk with unique passwords, multi-factor authentication and attention to phishing. Our data breach guide explains the steps. Data Knight includes known breaches in the free report, alongside other parts of your footprint.
5. A practical process with Data Knight
For a structured approach:
- Start a free scan: review the public web, relevant brokers and known breaches through Analyse my data.
- Understand the scan: read about the three sources.
- Understand removal requests: authorisation, emails, forms and tracking are explained in our method.
- Review the plans: one-off removal or an Always-on Protection subscription, on the pricing page.
- When you are ready to act after reviewing the report, start the removal process.
The process uses targeted requests and tracks their sending status. Each recipient remains responsible for handling the request under the applicable rules.
Namesakes and protection over time
Two issues often arise after the first report:
- Namesakes: a result may concern another person with the same name. Data Knight lets you exclude it with “This isn't me” to avoid an inappropriate request. See handling namesakes.
- Reappearance: information can return on a website or broker listing. Always-on Protection provides ongoing monitoring and follow-ups. Read the dedicated page. A subscription is not required to start a first removal cycle.
6. Limits and good practice
- Removal is not guaranteed for every source. Each organisation must consider its obligations and the applicable law.
- Comparisons with third-party services should remain factual and substantiated, without unsupported disparaging claims.
- For an individual dispute, employment matter or other situation requiring legal advice, consult a qualified professional.
In summary: identify your footprint, distinguish erasure, delisting and breach response, then take targeted action. Start with the free report and our method.
See also: Remove your traces online · GDPR Article 17 · Remove data broker information · Check whether your data leaked



