# AI Prompts for a Personal Privacy and Digital Footprint Audit

> Source: <https://www.narracomm.com/ai-prompts-for-a-personal-privacy-and-digital-footprint-audit/>
> Published: 2026-07-31 05:21:09+00:00

# AI Prompts for a Personal Privacy and Digital Footprint Audit

**Short answer:** For a visibly wealthy household, an exposed home address isn’t a marketing nuisance — it’s a

**physical security** issue. Security practitioners now describe the home as a primary target for digital-to-physical threat escalation, where public information about address, routine and household composition is used to plan intrusions and social engineering. The good news is that 2026 changed the tooling:

**California’s DROP platform**, live since January, lets residents send

**one deletion request that reaches every registered data broker in the state**. The prompts below structure a self-audit, sequence your removals, and — the part almost nobody covers — map the exposure of everyone

*around*you.

**TL;DR — Key Takeaways**

**Your privacy is set by the least careful person in your household**— family, staff, assistants. Their footprint is usually larger than yours.** Use statutory levers before manual opt-outs.**California’s DROP (live 1 Jan 2026) reaches every registered broker in one request.** Sequence by risk, not by ease.**Records revealing address, routine or household composition first. Email addresses last.** Removal is maintenance, not a project.**Public records repopulate broker databases. Plan quarterly re-checks.** The durable win is verification protocols**— making sure information an outsider could plausibly know can’t authenticate a request.

**✔ Best for**

Visible business owners, recently liquid founders, family principals, and anyone whose wealth, role or transaction has become publicly searchable.

**✕ Skip if**

You’re facing an active threat, stalking or harassment situation — that needs law enforcement and a specialist protection firm now, not a self-audit.

**✔ What this guide is — and deliberately isn’t.** Every prompt here is

**strictly self-directed and defensive**. They work from information

*you*already know is exposed about

*yourself and your own household*, and they help you organise removal, sequence it by risk, and build protective protocols.

This guide contains **no techniques for locating information about other people** — no search methodology, no investigative operators, no third-party lookup instructions. That’s a deliberate design constraint, not an oversight. If you need an adversarial assessment of your exposure, commission a professional risk assessment from a licensed security firm under a proper engagement — that’s the appropriate route, and they operate within a legal and ethical framework this guide can’t substitute for.

**On this page**

## Why does this matter more when you’re wealthy?

**Because the consequence changes category.** For most people, an exposed home address means junk mail and nuisance calls. For a visibly wealthy household, the same record supports a different set of risks: targeted intrusion, social engineering of staff, extortion attempts, and fraud that uses accurate personal detail to establish credibility.

Security practitioners describe the home as the primary target for **digital-to-physical threat escalation** — where an online footprint is used to map an estate, establish routine, and time an approach. Demand reflects it: ASIS research found **42% of organisations reporting significantly more emphasis on executive protection** than 18 months earlier.

**The liquidity event problem.** Exposure often spikes at precisely the moment wealth becomes real. A business sale generates press coverage, corporate register changes, property purchases and a visible lifestyle shift — all in a compressed window, all publicly searchable. If you’ve recently sold a business or are about to, this audit is more urgent than it was twelve months ago.

## The four exposure categories

**Audit by category rather than by platform.** Platform-by-platform checklists miss the point — what matters is what a given record *reveals*, not where it sits.

**Category 1**

**Identity & contact** Name variants, addresses, phone, email, DOB, relatives listed

**Category 2**

**Property & financial** Ownership records, corporate registers, filings, transactions

**Category 3**

**Movement & routine** Location tags, check-ins, schedules, gym, school, travel

**Category 4**

**Household & associates** Family, staff, assistants — usually the largest gap

Most privacy advice covers category 1 and stops. But **categories 3 and 4 carry the physical risk**. An address alone tells someone where you live; an address combined with a routine tells them when you’re not there, and a household map tells them who else has access.

## Your 2026 deletion rights (and what changed)

**January 2026 materially changed what’s possible in California, and it’s worth using before any manual work.** The Deletion Request and Opt-Out Platform (DROP), operated by the California Privacy Protection Agency under the Delete Act, lets residents submit **one request that reaches every data broker registered in the state** — the first centralised deletion system of its kind in the US.

| Lever | Who it covers | What to know |
|---|---|---|
California DROP |
California residents | Free, state-operated, live since 1 Jan 2026. One submission reaches all registered brokers. Brokers must check the platform every 45 days and process requests, with penalties reported at $200 per request per day for non-compliance. Start here if eligible. |
CCPA / CPRA deletion rights |
California residents | Individual requests to businesses holding your data, including those not registered as brokers. |
GDPR Article 17 |
EU / UK residents | Right to erasure. Broad, enforceable, and applies to organisations processing your data regardless of where they’re based. |
Other US state laws |
Varies by state | A growing patchwork with differing scope and mechanisms. Check your own state — the landscape is moving quickly. |
Individual broker opt-outs |
Everyone | Still necessary for anything outside statutory coverage. Slowest route — do it after the centralised levers. |

Privacy law is jurisdiction-specific and changing fast. Verify what currently applies where *you* are resident before relying on any mechanism described here — and note that a right existing doesn’t mean compliance is automatic.

### Get the Privacy Audit Checklist

The full four-category audit worksheet, the removal sequencing tracker, the household exposure map, request templates, and a quarterly re-check schedule. Free.

## Prompt 1: The exposure inventory

**You supply what you already know; the prompt organises it and finds the gaps in your own knowledge.** This isn’t a search tool — it’s a structuring tool, and the useful output is the list of things you *haven’t* checked.

```
## ABOUT MY SITUATION
Visibility level: [e.g. named in press / company director /
recently sold a business / not publicly known]
Jurisdiction(s): [WHERE YOU'RE RESIDENT — determines rights]
Household: [WHO LIVES THERE — roles, not names]
Staff/associates: [PA, HOUSEKEEPER, DRIVER, ETC. — roles only]

## WHAT I ALREADY KNOW IS PUBLIC ABOUT ME
[List what you're already aware of. Don't research it —
just write what you know. Include: press mentions, company
filings, property records, professional profiles, social
accounts, anything you've published.]

## WHAT I'VE ALREADY DONE
[Any opt-outs, privacy settings, removals already actioned]

## YOUR TASK
Help me structure a self-audit. Do NOT attempt to search for
or infer information about me — work only from what I've
supplied.

A. CATEGORISE what I've listed into: identity & contact ·
   property & financial · movement & routine · household
   & associates.

B. THE GAPS IN MY OWN KNOWLEDGE — based on my situation,
   what categories of record would typically exist that I
   haven't mentioned? Give me a checklist of things to go
   and verify about MYSELF. Frame each as "check whether X
   exists for you", not as a research method.

C. RISK-RANK what I've listed. Which items reveal:
   - Where I live
   - When I'm not there
   - Who else has access to my household
   Those three rank above everything else.

D. THE COMPOUNDING PROBLEM — which items are individually
   harmless but revealing in combination? Explain the
   combination rather than demonstrating it.

E. WHAT I CANNOT REMOVE — which items are likely permanent
   public record? For each, what's the mitigation, since
   removal isn't available?

F. MY FIRST FIVE ACTIONS, ranked by risk reduction per hour
   of effort.

Rules:
- Work only from what I've told you. Do not speculate about
  what might exist about me specifically.
- Do not provide methods for locating information about any
  person, including me.
- Flag anything that warrants a professional risk assessment
  rather than self-audit.
```

## Prompt 2: The removal sequence

**Sequence by risk reduction, not by what’s easiest.** Most people start with the quickest opt-outs and never reach the records that actually matter.

```
MY INVENTORY: [PASTE OUTPUT FROM PROMPT 1]
MY JURISDICTION: [FOR DETERMINING RIGHTS]
TIME I CAN COMMIT: [HOURS PER WEEK, REALISTICALLY]

Build my removal plan.

1. STATUTORY FIRST — which centralised or legal mechanisms
   apply to me given my jurisdiction? These go before any
   manual work. Note what each does and doesn't cover.

2. THE SEQUENCE — order everything by risk reduction per
   unit of effort. Address and routine exposure first;
   historic employment and email last.

3. THE SOURCE PROBLEM — for each item, note whether removal
   is durable or whether it will repopulate from an
   underlying public source. If it repopulates, removal
   alone is wasted effort — say so and address the source.

4. THE TRACKER — give me a table structure to log: item ·
   holder · date requested · method · response due · status ·
   re-check date.

5. REALISTIC TIMELINE given my available hours. Don't
   present this as a weekend project.

6. WHAT TO DELEGATE vs do myself — noting that anything
   delegated means sharing the exact data I'm protecting.
   Flag the trade-off explicitly.

Do not include any technique for locating records about a
person. Work from my list only.
```

## Prompt 3: The household exposure map

**This is the section that distinguishes a serious audit from a consumer checklist.** A principal can be meticulous and still be fully exposed through a teenager’s location tags, an assistant’s public professional profile, or a staff member’s employer listing.

```
MY HOUSEHOLD & CIRCLE (roles, not names):
[e.g. spouse — active on two social platforms
 teenager — posts frequently, location tags on
 PA — public professional profile naming employer
 housekeeper — listed employer on a jobs profile
 driver — check-ins at regular locations
 adult child — property enthusiast, posts about family home]

WHAT I KNOW ABOUT THEIR HABITS:
[Only what you actually know. Don't investigate them —
this is a conversation starter, not surveillance.]

Map the household exposure.

A. EXPOSURE BY ROLE — for each role, what categories of
   information does someone in that position typically
   make public without realising the aggregate effect?
   Describe categories, not techniques.

B. WHAT THEIR EXPOSURE REVEALS ABOUT ME — specifically:
   location, routine, household composition, travel
   patterns, staff changes.

C. THE CONVERSATION — for each person, how do I raise this
   without being controlling or alarming? Give me an actual
   script. This is the part that usually fails: the
   principal issues an edict, the family ignores it.

D. WHAT'S REASONABLE TO ASK — distinguish between:
   - Non-negotiable (genuine security implications)
   - Worth asking (meaningful reduction, modest cost)
   - Not worth the relationship friction
   Be honest about the third category. Privacy demands
   that make family life miserable get abandoned.

E. STAFF PROTOCOLS — for employed household staff, what
   belongs in an employment agreement or handbook rather
   than a personal request? Note that employment terms
   need proper drafting.

F. THE TEENAGER PROBLEM — practical, non-authoritarian
   approaches for family members who reasonably want a
   normal social life.

Rules:
- Do not suggest monitoring, tracking or covertly reviewing
  anyone's accounts. This is about conversations and
  agreements, not surveillance of family or staff.
- Do not provide methods for finding anyone's information.
```

**A line worth holding.** Covertly monitoring family members’ or employees’ accounts is corrosive, frequently counterproductive, and in an employment context can carry legal consequences. The effective approach is agreement, not surveillance — and a household that understands

*why*complies far better than one that’s been policed.

## Prompt 4: Draft your deletion requests

```
Draft a data deletion request.

Recipient type: [DATA BROKER / BUSINESS / PLATFORM]
My jurisdiction: [DETERMINES WHICH RIGHT APPLIES]
What I'm asking them to delete: [CATEGORY, NOT THE ACTUAL
DATA — e.g. "residential address records"]
Prior contact: [FIRST REQUEST / FOLLOW-UP / ESCALATION]

Write:
1. THE REQUEST — citing the applicable statutory right for
   my jurisdiction, stating clearly what I'm requesting,
   and specifying the response deadline the law provides.
2. THE MINIMUM IDENTIFYING INFORMATION they legitimately
   need — and flag anything they might request that exceeds
   what's necessary, since over-disclosure to a broker is
   self-defeating.
3. THE FOLLOW-UP for non-response, referencing the deadline.
4. THE ESCALATION — which regulator handles complaints in
   my jurisdiction, and what to include.

Keep it short and formal. No emotion, no explanation of why.
Flag any point where I should take legal advice rather than
send a template.
```

## A real household map, run in full

A founder eighteen months post-exit, now publicly associated with the sale. Roles only — no identifying detail.

```
Visibility: named in trade press re: the acquisition.
Director of two companies. Property purchased post-exit.
HOUSEHOLD: spouse (moderate social use, mostly private) ·
two teenagers (active, location tags on) · adult child at
university (public, posts about visits home).
STAFF: PA (public professional profile, names me as
employer) · housekeeper three days/week · gardener monthly.
HABITS I KNOW ABOUT: teenagers post from home and school.
PA lists my company on her profile. We use the same
restaurant most Fridays and the family mentions it.
```

**A. Exposure by role**

| Role | Typical exposure category | What it reveals about the principal |
|---|---|---|
Teenagers |
Location-tagged posts from home and school; consistent timing | Home location, school location, term-time routine, when the house is occupied |
PA |
Employer named on a public professional profile | Confirms the principal-assistant link — the entry point for most social engineering attempts |
Adult child |
Posts about visits home, family occasions | Confirms property, family composition, and predictable gathering dates |
Household staff |
Employer listed on jobs profiles; regular schedules | Household composition, when staff are present, when the property is unattended |
The Friday restaurant |
Family mentions a consistent weekly pattern | Reliable routine — the single most useful piece of information for anyone planning an approach |

**B. What this reveals in aggregate**

Individually these are unremarkable. Together they establish: where you live, where your children are during the day, when your house is empty, who works for you, and where your family reliably is on a Friday evening. **None of that came from your own footprint.** You could delete every record about yourself and this map would remain intact.

**C. The conversations — scripts**

*Teenagers:* “I’m not asking you to stop posting, and I’m not going to check your accounts. One thing only: turn off location tagging. Here’s why it matters more for us than for your friends — [specific, honest reason]. Everything else is your call.”

*PA:* “Would you mind changing your profile to a general description rather than naming the company? It’s the link between us that creates the risk, and it’s the thing people use when they call pretending to be me.”

*Adult child:* “Post whatever you like about visits — just not in real time. A week later is completely fine and changes the risk entirely.”

**D. What’s reasonable to ask**

**Non-negotiable:** location tagging off for anyone posting from home; PA’s profile de-linked; no real-time posting of the family’s whereabouts.**Worth asking:** vary the Friday pattern occasionally; staff avoid naming the household on jobs profiles.**Not worth the friction:** asking teenagers to stop posting, going private across the board, or restricting who your adult child tells about family life. These get abandoned within a month and cost you goodwill you’ll need for the requests that matter.

**F. The teenager problem**

Location tagging is the single highest-value change and the easiest to accept, because it costs them almost nothing socially. Lead with that one and let the rest go. An agreement they actually keep beats a policy they resent — and a teenager who understands the reason will often self-police far better than one who’s been given rules.

**Note the finding:** the principal’s own footprint was reasonably well managed. The exposure was entirely in the household — which is the normal result, and the reason a personal-only audit gives false comfort.

## Level-up: the verification protocol

This is the part almost nobody builds, and it’s the highest-value output of the whole audit. Some information about you **cannot be removed** — corporate filings, press coverage, property records in open registers. Accepting that, the question becomes: *what protocol makes that information useless to someone who tries to weaponise it?*

The answer is verification. If an outsider can plausibly know it, it must never be sufficient to authenticate a request.

```
WHAT'S PERMANENTLY PUBLIC ABOUT ME (from my audit):
[List the categories you cannot remove — e.g. company
filings, press coverage of a transaction, property register
entries, professional history, charity trusteeships]

WHO CAN ACT ON MY BEHALF:
[Roles who might receive instructions purporting to come
from you — PA, bookkeeper, household manager, family]

WHAT THEY CAN AUTHORISE:
[Payments, access, information disclosure, travel booking,
deliveries, contractor entry]

Build verification protocols. The goal: ensure that
information an outsider could plausibly obtain is NEVER
sufficient to authenticate a request.

A. THE AUTHENTICATION AUDIT — for each thing my people can
   authorise, what would they currently accept as proof
   it's really me? Identify where that proof consists of
   information that is publicly available.

B. THE PROTOCOL — for each category of request, define:
   - What must ALWAYS be verified out-of-band, on a known
     number, initiated by them calling me
   - What can never be actioned on a first request
   - Who has authority to refuse, and explicit cover for
     doing so

C. THE CALLBACK RULE — write the actual rule for household
   and office. Keep it short enough to be remembered under
   pressure, when someone sounds urgent and authoritative.

D. URGENCY AS A SIGNAL — script how staff should respond
   when a request is framed as time-critical. Manufactured
   urgency is the common thread in these attempts, so the
   protocol must survive it.

E. THE PERMISSION TO SAY NO — draft the standing instruction
   that no one will ever be criticised for delaying a
   request to verify it, including one that turns out to be
   genuinely from me. Without this, protocols fail.

F. THE QUARTERLY TEST — how to check the protocol is
   actually being followed, without deceiving my own staff.

Output as a one-page household protocol I can share.
```

**Why section E carries the whole thing:** protocols fail because a staff member fears looking obstructive or foolish for questioning the principal. Explicit, standing, advance permission to delay *any* request — including genuine ones — is what makes the rest operable. Without it you have a document; with it you have a behaviour.

**Section F matters too.** Test the protocol, but don’t do it by deceiving your own staff with a fake request — that damages trust and makes people less likely to escalate honestly. Test by asking openly what they’d do in a described scenario.

## Why removal is maintenance, not a project

**Broker records repopulate.** Data is sourced from public records, corporate registers, property filings, court documents and commercial datasets that keep producing new entries. Delete a record today and the same underlying source may recreate it next quarter.

**Initial pass — weeks 1–4**

Statutory mechanisms first, then the highest-risk manual removals. Set up the tracker at the same time, not afterwards.

**Household — weeks 2–8**

The conversations and agreements. Slower than the technical work and more durable, because it stops new exposure being created.

**Protocols — weeks 4–8**

Verification rules for household and office. This is the piece that protects you against what you couldn’t remove.

**Quarterly re-check — ongoing**

Re-submit where records returned, re-check new brokers, revisit household habits. Expect this permanently.

One security provider estimates a family’s exposure can be meaningfully reduced within about 90 days of concerted effort. Treat vendor figures as directional rather than independent research — but the shape is right: the first quarter delivers most of the gain, and after that it’s maintenance.

## What AI cannot do here

| Don’t use it for | Why |
|---|---|
Finding what’s public about you |
Models can’t reliably search live records and will produce confident, wrong answers. Check sources yourself, or commission a professional assessment. |
Researching any other person |
Out of scope by design, including household members. Use conversations and agreements, not investigation. |
Storing your exposure inventory |
Don’t paste a consolidated list of your addresses, routines and household details into a consumer AI tool. Use categories and roles, as the prompts above do. |
Legal interpretation of your rights |
Privacy law varies by jurisdiction and changes fast. Use AI to draft; verify the right actually applies to you. |
An active threat situation |
Stalking, harassment or credible threats need law enforcement and a licensed protection firm immediately. Not a self-audit. |

## Which model for which task?

Any tier · request drafting

Enterprise tier · anything personal

Use a **reasoning-tier model** for the household map and verification protocol — both reward careful analysis of how separate pieces combine. Request drafting works on any tier. Most importantly: for anything involving personal detail, prefer a **business or enterprise tier with a data processing agreement**, and follow the prompts’ convention of describing *roles and categories* rather than names and addresses. Don’t let a privacy audit become a privacy incident.

Privacy law and platform settings change frequently. We re-verify on each review — confirm current rights in your jurisdiction before relying on anything here.

## Frequently asked questions

### How do I remove my personal information from the internet?

Work in three layers. First use any centralised statutory deletion mechanism available in your jurisdiction, such as California’s Deletion Request and Opt-Out Platform which launched in January 2026 and lets residents submit one request reaching every registered data broker in the state. Second, submit individual opt-outs to brokers not covered by that mechanism. Third, address the sources that repopulate broker records, including public records, social accounts and information published by other people about you. Removal without addressing sources means records return.

### What is California’s DROP platform?

DROP is the Deletion Request and Opt-Out Platform operated by the California Privacy Protection Agency, launched on 1 January 2026 under the Delete Act. It allows California residents to submit a single deletion request that reaches every data broker registered in the state, and is the first centralised deletion system of its kind in the United States. Registered brokers are required to check the platform every 45 days and process outstanding requests, with penalties for non-compliance.

### Why does digital privacy matter more for wealthy individuals?

Because the risk is physical rather than commercial. Security practitioners describe the home as a primary target for digital-to-physical threat escalation, where publicly available information about address, routine and household composition is used to plan intrusions or social engineering. For most people an exposed address means unwanted marketing. For a visibly wealthy household it changes the threat model.

### Can AI find what information is public about me?

No, and it shouldn’t be used to try. A language model can’t reliably search live records, and prompting one to compile information about a person is both unreliable and inappropriate. What AI does well in this context is organise an audit you conduct yourself: structuring what you already know is exposed, sequencing removals by risk, drafting deletion requests, and designing household verification protocols.

### How long does it take to remove data from brokers?

Expect an initial cycle of several weeks to a few months, and treat it as ongoing rather than one-off. Statutory mechanisms operate on defined processing cycles, individual broker opt-outs vary widely in response time, and records commonly repopulate from public sources. A realistic approach is an intensive initial pass followed by quarterly re-checks.

### Does removing data from brokers actually work?

It reduces exposure rather than eliminating it. Broker records can be removed and statutory rights make this enforceable in some jurisdictions, but information sourced from public records, court filings, corporate registers and other people’s social accounts will persist and can repopulate broker databases. Removal is therefore maintenance, and the durable gains come from reducing what enters the system in the first place.

### What is the biggest privacy mistake wealthy households make?

Securing the principal while ignoring everyone connected to them. A teenager’s location-tagged posts, an assistant’s public calendar habits, a staff member’s employer listing on a professional network, or a family member’s property enthusiasm can each disclose more than the principal’s own footprint. A household’s privacy is effectively set by its least careful member.

### Should I use a paid data removal service?

They can save considerable time on the repetitive opt-out work, and for high-exposure households the ongoing monitoring is often worth the cost. Assess them on which brokers they actually cover, whether they re-check and re-submit, and how they handle the data you must give them to work — since you’re supplying a service with precisely the information you’re trying to protect. They don’t address exposure from public records, your own accounts or other people’s posts.

### Download: The Privacy Audit Checklist

The four-category audit worksheet, removal sequencing tracker, household exposure map with conversation scripts, deletion request templates, the one-page verification protocol, and a quarterly re-check schedule.

Enter your email and we’ll send the checklist plus occasional updates when deletion rights change. Unsubscribe anytime.

**Written by the Narracomm team**

Narracomm is a communications and content strategy team that helps business owners, operators, and founders use AI to produce clear, credible, high-performing work. [This guide would benefit from a named reviewer with security or privacy credentials — a licensed protection professional, CIPP-certified privacy practitioner, or data protection solicitor — given the jurisdictional and personal-safety content.]

## Sources & further reading

[California Privacy Protection Agency — Data broker registry and DROP](https://cppa.ca.gov/data_brokers/)[Byte Back — California’s DROP platform is live (2026)](https://www.bytebacklaw.com/2026/02/californias-deletion-request-and-opt-out-platform-drop-is-live/)[Crowell & Moring — CPPA data broker strike force and Delete Act enforcement](https://www.crowell.com/en/insights/client-alerts/california-privacy-agency-launches-data-broker-strike-force-amid-delete-act-crackdown)[Troutman — Analysing the California Delete Act regulations](https://www.troutmanprivacy.com/2025/12/analyzing-the-california-delete-act-regulations/)[Security Magazine — The rising tide of executive protection (ASIS data)](https://www.securitymagazine.com/articles/102199-the-rising-tide-of-executive-protection-corporations-ramp-up-security-in-an-era-of-heightened-threats)[Crisis24 — Digital executive protection and the cybersecurity gap around executives](https://finance.yahoo.com/technology/ai/articles/crisis24-launches-digital-executive-protection-130000038.html)[GDPR Article 17 — Right to erasure](https://gdpr-info.eu/art-17-gdpr/)

**On scope:** this guide is deliberately limited to defensive self-audit. It contains no methodology for locating information about other people. If you require an adversarial assessment of your exposure, engage a licensed security or investigations firm under a formal engagement — that work belongs within a professional legal and ethical framework.

Last reviewed and updated: **July 25, 2026** · Deletion rights and platform details verified on this date. Privacy law is moving quickly — confirm current rights in your jurisdiction. Next review due within 14 days. **This guide is general information, not legal or security advice.**
