Annual Online Safety Audit: Everything Worth Reviewing at Least Once a Year
A practical checklist covering passwords, app permissions, account recovery options, and privacy settings you should review every year.

Photo: ReadersChronicle.com | Your Comprehensive Learning Destination editorial
—— In This Article
Key Takeaways
- Reused or weak passwords remain the most common entry point for unauthorized account access.
- App permissions and account recovery options accumulate silently — they need a deliberate annual review.
- Privacy settings on social platforms and devices are frequently reset or changed by software updates.
- Two-factor authentication (2FA) is one of the highest-impact protections you can enable on any account.
- Old, unused accounts you have forgotten about can still expose your personal data if breached.
Why a Yearly Review Actually Matters
Most people set up their accounts and devices once and never look back. But your digital footprint changes constantly — you download new apps, share new information, and create new accounts throughout the year. Meanwhile, the security landscape shifts too: apps update their permission requests, platforms quietly revise their privacy defaults, and breach databases grow.
Think of this audit the same way you think about annual checkups for your home or your finances. Just as a seasonal home maintenance checklist catches small problems before they become expensive ones, a yearly online safety review catches digital vulnerabilities before they become serious incidents. It is also a natural companion to an annual savings and debt review — both reward the habit of deliberately pausing to assess your situation.
This checklist is designed for everyday users, not IT professionals. Work through it at your own pace — most people complete it in under an hour.
Password Manager
Stores unique passwords for every account and flags weak or reused credentials during your audit.
Authenticator App
Generates time-based one-time codes for two-factor authentication, more secure than SMS codes.
Breach Notification Service
Checks whether your email address appears in known data breaches so you know which accounts to prioritize.
Encrypted Note or Offline Document
Stores backup 2FA recovery codes safely outside your primary devices.
The Full Audit Checklist
Work through each group below. Pay particular attention to the must items — these represent the protections with the highest real-world impact for the broadest range of people.
Passwords and Authentication
Account Recovery Options
App Permissions and Connected Accounts
Privacy Settings
Dormant and Forgotten Accounts
Device and Software Hygiene
Breach Exposure Requires Immediate Action
If a breach notification service shows that your email address has appeared in a known data breach, treat it as urgent — change the password on the affected account immediately, then check whether you reused that password anywhere else. Do not wait until your next annual audit. A compromised password that remains active is an open door.
If you have recently purchased or set up a new phone, tablet, or computer, the foundational steps in our guide to locking down a new device should be completed before you run through this annual audit. The two work together — the device guide covers one-time setup steps while this audit covers ongoing review habits.
If you have children or teenagers in your household, consider pairing this audit with a review of children's screen safety and privacy risks — their accounts and devices deserve their own dedicated review.
Don't Lock Yourself Out During the Audit
Before changing recovery options or revoking 2FA methods, make sure you have your backup codes downloaded and stored somewhere accessible. Changing a recovery phone number or email without first saving your backup codes can lock you out of your own account. Proceed methodically, one account at a time.
