Search Yourself Online: What a Stranger Finds About You

Search yourself online the way a stranger would: how to run the lookup properly, who aggregates the pieces, and what US opt-outs and GDPR requests actually achieve.

A plain framed mirror leaning against a bare wall in a dim room, returning nothing but the empty space and the glow of a single warm lamp

Someone types your name into a search box. A hiring manager, a neighbour, a buyer from a classifieds site, an ex-colleague with a grudge. What comes back in the next thirty seconds is outside your control, and most people have never looked. When you search yourself online properly, the findings are rarely dramatic. It is small stuff: a club committee listing from 2014, a business imprint, an old race result, a photo from a company charity run.

The interesting part is what happens when those fragments get laid side by side. The club listing gives a town, the imprint gives a street address, the photo gives an approximate age, the forum handle gives twenty years of posting history. None of it is worth mentioning on its own. Assembled, it is enough to pass a call centre security check or to write a phishing email that does not read like one.

This piece reverses the direction of the question. Instead of asking what others are allowed to know about you, you go and look at what they actually get, using the same tools they would. In intelligence work that is called defensive reconnaissance: mapping your own attack surface before somebody else does.

Running the search on yourself

The first pass costs nothing but half an hour. What matters is doing it methodically, and not just typing your name once and shrugging at the result.

Log out before you start. A signed-in search returns a result tuned to you, which is not what a stranger sees. A private window is the minimum, a different search engine than your usual one is better.

Use quotation marks. "First Last" searches the phrase itself, where an unquoted query hunts two loose words that may sit paragraphs apart. Then start appending qualifiers that narrow the field: town, employer, club, university, hobby. These are precisely the combinations somebody uses when they are looking for you and not for your namesake.

Cover the variants. Maiden name, hyphenated name, initial instead of first name, common misspellings. Add old usernames and email addresses, because a handle you picked at sixteen tends to be attached to more accounts than you remember and can be traced across forums for years.

A plain glass magnifier with a dark metal rim lying flat on a dark table over scattered blank paper scraps that appear larger and closer together beneath the lens
Under the lens the scraps move closer together. That is the entire trick.

Reverse image search is the part people skip. A profile photo uploaded to a job board in 2016 can be sitting somewhere entirely different today. Google Images and TinEye find identical and lightly edited copies of a file. Face search services such as PimEyes go further and match the face rather than the file, which is useful for checking on yourself and unpleasant in somebody else’s hands. That service is legally contested, since matching faces means processing biometric data under Art. 9 GDPR and several European data protection authorities have taken action against it. Both belong in an honest picture of the situation.

Do not stop at search engines. The internal search of the social networks finds profiles that Google never indexed, either because they carry a noindex or because they sit behind a login. An account you have not opened in years is still sitting there with a photo, a friends list and posts from a time when nobody thought much about privacy settings. Professional networks are worse in one specific way: a complete career history with dates and locations lets somebody narrow down where you live with fairly little effort.

Then the aggregators. In the US this is where the search gets uncomfortable, because the consumer-facing people search sites are large, well indexed and cheap. Spokeo, BeenVerified, Whitepages, Intelius, Radaris and a long tail of smaller operators assemble listings from voter files, property records, court filings, marriage and divorce records, phone directories and purchased marketing data. A typical free preview will confirm your age range, current city, previous addresses and the names of relatives, with the rest behind a subscription. In Europe the equivalent layer is thinner and rests more on directories, company registers, association pages and press archives, but the mechanism is identical.

Who collects this, and why it pays

People search sites rarely create new information. They crawl what is already open and file it under a name. That is the business, and that is also the risk.

Many fine warmly lit threads running in from the dark edges of the frame and drawing together into a single dense knot in the centre
Individually the threads are barely visible. The knot holds.

A concrete case makes this clearer than any list. Suppose someone finds your name in a sports club match report, a photo from the club’s summer party, an old business imprint from a side venture you closed years ago, and a phone directory entry. The report gives the town, the imprint gives the street, the directory gives the number, the photo gives an approximate age, and the club itself gives a conversational hook that manufactures trust. That is enough to place a phone call that sounds personal, which is exactly why it works. Not one of those four sources was a mistake.

A town in a club report interests nobody. A birth date in a public notice, on its own, likewise. An old email address in a forum profile, the same. Put those three under one record and someone has the answers to the standard verification questions of most support lines. Aggregation is the actual event here, not publication.

Behind the consumer sites sits the larger data broker market, which buys, enriches and resells profiles to insurers, employers, collections agencies and advertisers. It became visible enough that several US states now require brokers to register: California, Oregon, Texas and Vermont maintain registries. California went furthest with the Delete Act, whose Delete Request and Opt-Out Platform launched in January 2026, with registered brokers required to start processing requests through it from August 2026. One submission reaches hundreds of brokers, which is a genuine improvement, and it is limited to California residents.

Europe took the other route. There is no single opt-out platform, but every person has an enforceable right to know and an enforceable right to have data erased, and those rights apply to any company processing data about people in the EU regardless of where the company sits. The trade-off is obvious: the US approach is one form for many brokers, the European approach is many letters with much stronger teeth behind each one.

How much of your shadow the search engines themselves keep is a separate matter, and we wrote it up separately in what Google knows about you.

Doing something about it: access first, erasure second

Two instruments matter here, and the order in which you use them decides how much of your effort is wasted.

A right of access request comes first. Under Art. 15 GDPR you can require any controller to confirm whether it processes data about you and, if so, to tell you what it holds, why, from which source, to whom it has been disclosed and for how long it is kept, along with a copy of the data. It is free unless the request is manifestly unfounded or excessive, in which case Art. 12(5) lets the controller charge a reasonable fee. It is informal, and addressed to the contact named in the imprint or privacy policy. The answer is due without undue delay and at the latest within one month, with a single extension of two further months available for complex or numerous requests provided you are told within the first month. In the US the equivalent under California law is the right to know, which most large brokers now handle through a web form.

The valuable field in that answer is the source. When an aggregator tells you where your address came from, you have identified the upstream record you actually need to deal with. Skip this step and you spend weeks deleting copies while the original keeps feeding new ones.

Erasure comes second. Art. 17 GDPR gives you the right to have data deleted, among other reasons when it is no longer necessary for the purpose, when you withdrew consent, when the processing was unlawful, or when you objected under Art. 21 and no overriding legitimate grounds remain. One paragraph deserves more attention than it gets: under Art. 17(2), a controller that has made the data public must take reasonable steps to inform other controllers that you have requested erasure of links to and copies of that data. That is the lever against duplication.

A hand reaching in dim warm light for the top blank sheet of a thick stack of identical dark sheets on a table
One sheet fewer. The stack stays where it is.

Two practical points, because they save time. Send the request from an address the controller can match to your record, otherwise it may ask for additional identifying details under Art. 12(6) and the exchange starts over. The reverse also holds: a controller demanding a copy of your ID when the link is already obvious is asking for more than it is entitled to. And keep a note of when you sent what. If the matter ever reaches a supervisory authority, the first question there is when you contacted the controller.

The request itself needs no legal language. Your name, any former names, the exact URL or record, a reference to Art. 17 GDPR, a fourteen-day deadline and a request for written confirmation. If a controller ignores you, a complaint to the competent supervisory authority is free and surprisingly effective.

Delisting is not deletion. This is where most of the confusion lives. Through Google’s right to be forgotten form you ask for a result to stop appearing in searches for your name. The page itself stays online, stays reachable by direct link and stays visible in other engines. Google assesses whether the material is inaccurate, irrelevant, or outdated against the public interest in keeping it findable, which is why requests about public figures and current reporting mostly fail. For a private address, phone number or email address showing up in results, the Results About You tool is the narrower and faster route: you register the details once and Google reports and offers to remove new matches. Neither touches the source.

RouteActs onHandled byOutcome
Access request, Art. 15 GDPRthe recordthe service operatoryou learn what exists and where it came from
Erasure, Art. 17 GDPRthe sourcethe site operatorthe entry is removed
Objection, Art. 21 GDPRthe processingthe service operatoroften the fastest route with aggregators
US broker opt-outone listingthe brokerlisting removed, records may regenerate
California DROP platformmany brokersstate platformone request reaches registered brokers
Search delistingfindabilitythe search engineresult gone, page stays
Complaintunresponsive operatorssupervisory authorityfree, frequently effective

The sensible sequence falls out of the table. Ask first so you know the source, then remove or object at the source, and use delisting for whatever cannot be switched off.

Where this runs out

The uncomfortable section, which belongs in any honest treatment of the subject.

A dark stone floor under fine warm dust with one circular patch swept clean and the brush set down beside it
The swept circle is real. It just does not stay clean on its own.

Removal is an event, not a state. A deleted listing may already have been copied, cached, archived or resold, and people search sites in particular regenerate entries when the underlying public records refresh. Some listings come back within months because the upstream source was never addressed. That is why the access request goes first and why the list is worth revisiting twice a year.

Some records are meant to be public. Company registers, court filings, property records and professional licences exist to be findable, and press coverage is protected by freedom of expression, which Art. 17(3) explicitly preserves. Running a business generally carries a disclosure obligation. You will not remove these, though you can sometimes change what they contain, for instance by using a registered business address instead of your home.

An empty result proves nothing. Your search covers one language, one spelling and the open web. Material in closed groups, and anything that gets traded after a breach instead of published, does not show up. The other half of that question, whether your credentials are already circulating, has its own answer: data breach check covers the tools for it.

And looking at yourself changes nothing by itself. It makes the picture visible. The value comes from what you do next, in that order: build the list, request access, remove at the source, delist the rest.

What sticks

Most people who run this exercise for the first time get a surprise in an unexpected place. The embarrassing thing from university has long since fallen out of the index. What is sitting there instead is a home address in a directory entry that came bundled with a phone line fifteen years ago, agreed to without a second thought.

That is the real message of the topic, and it is a reasonably good one. The bulk of what a stranger finds comes from entries that can be switched off, dormant profiles nobody needs, and forms filled out more generously than necessary. The remainder can at least be made harder to reach.

After that it is a habit. Twice a year, the same pass, a quarter of an hour, with last time’s list next to you. And if the exercise turns up material you want gone from your own devices as well as from the web, the thorough end of the chain is covered in how to really delete data.

Frequently asked questions

Are people search sites legal?
In the United States, publishing information from public records is generally lawful, and the people search industry is built on exactly that. Several states now require data brokers to register, and California, Oregon, Texas and Vermont maintain public registries. In the EU the same activity is permitted only where a legal basis holds, usually the legitimate interest test in Art. 6(1)(f) GDPR, which has to be weighed against your rights and which you can challenge. What is illegal everywhere is the use: stalking, harassment and identity fraud do not become lawful because the data was easy to obtain.
How do I search for myself properly?
Log out first, or use a private window, because a signed-in search shows you a personalised result rather than what a stranger sees. Put your full name in quotation marks so the engine looks for the phrase instead of two separate words, then add a city, employer, club or university to surface the results that otherwise sit on page five. Repeat with maiden names, nicknames, misspellings and old email addresses, and finish with a reverse image search on any photo you have used publicly.
What is a data broker?
A company that collects, combines and sells personal information about people it has no relationship with. The raw material comes from public records, marketing lists, loyalty programmes, tracking and purchased feeds. Consumer-facing people search sites are the visible surface of this market, while the larger part sells to insurers, employers, debt collectors and advertisers. The economic value is not in any single record but in the linkage between records.
Do people search opt-outs actually work?
Individually yes, collectively only with maintenance. Most large US sites run an opt-out page that removes a listing within days or weeks, and California residents can now use a single state platform to reach hundreds of registered brokers at once. The catch is that listings regenerate when the underlying public records are refreshed, so a removal is an event rather than a permanent state. Plan on rechecking twice a year.
What does the Google removal form actually do?
It removes a result from searches for your name, not the page itself. The source stays online, remains reachable by direct link and remains visible to other search engines. Google weighs whether the information is inaccurate, irrelevant or outdated against any public interest in keeping it findable. For a private address, phone number or email address appearing in results, the Results About You tool is the more direct route.
How do I get data deleted under GDPR?
Write to the controller named in the site imprint or privacy policy, in text form, no lawyer required. State your name, identify the exact URL or record, and invoke Art. 17 GDPR. The response is due without undue delay and at the latest within one month, extendable once by two further months for complex or numerous requests if you are told within the first month. If nothing happens, a complaint to the competent supervisory authority costs nothing and works more often than people expect.
What is the difference between a people search site and a credit bureau?
A people search site scrapes and bundles openly available sources and sells access to anyone who types in a name. A credit bureau processes reported contract and payment data, discloses it to businesses with a legitimate interest, and operates under its own sector rules including a correction procedure. A first copy of your data is free from any controller under Art. 15 GDPR, not just from a credit bureau. Both hold personal data about you, but the sources, the recipients and the correction routes are different.
Can I make myself unfindable?
Not completely, not once you have signed a contract, registered a business or appeared in a public record. The realistic goal is different: reduce the volume and break the links between the fragments. Delete dormant profiles, remove your address from club pages and old CVs, opt out of directories, and keep your professional and private identities on separate email addresses. What remains is loose material rather than a profile, and that distinction is the whole point.