Is Updating Online PII Enough?

Hypothetical: you’ve got some online account, one that does provide you with meaningful value. You’d like to continue using the service in some way

Unfortunately, you made it before you were privacy conscious. The account contains some sensitive PII: name, address, phone number. God forbid, maybe even a birthdate

There are two options: (1) update the account with fake PII, continue using it, or (2) delete the account, remake a fresh one with anonymous PII

You could err on the side of caution & pursue option 2, but thats a decision based on fear alone. You don’t want to take a drastic action - full account deletion - unless you have a good reason to believe the historic PII is still associated with your account, even after it’s been updated.

How do you proceed? I havent been able to find much in the way of quantifying this threat, beyond the point that jurisdictional privacy laws may be a factor to consider

1 Like

It’s not. Not today with how bad things have gotten online. I would still go with option 2 here. But what you can do is leave that account be but delete any info you can or want to. And still make a new account to use that going forward with fake info.

But without more info on any particulars, its hard to conclusively recommend something/the right move(s).

Check the privacy policy of whatever service you are doing this on. If they explicitly say that they keep the history of your PII, it’s obviously better to delete that and create a new account. If they are vague about it, like “We keep ‘certain’ data for ‘legal purposes’” or whatever, ask their support team what this certain data is. This all depends on if you trust that their privacy policy is enforced and that their support staff is knowledgeable enough to answer it truthfully.

1 Like

For what it’s worth, yeah I would delete

This was a discussion I had with a coworker yesterday, who challenged me to provide receipts. They suggested that a company retaining deleted PII after an update would be just as likely to do so after account deletion, rendering the whole ordeal moot

Well, its not impossible but they do want to comply with the law so if it doesn’t delete as they would need to, they’d be in trouble. And such news always comes out sooner or later.

Best to still delete so you’re doing the right thing.

Your friends will not respect this decision, as it has happened to me.

If it is so important, just continue using and scrub out pictures and posts from the past. Be more conscious on what you post in the future. For example, if you go and move out to a new residence, dont post that. What matters is reachability and the connections that you have.

I have to go through about 500 accounts to delete or remake… In my todo.

There’s no way to really answer your question as it’s all based on trust.

There is also a hypothetical situation where a company could keep logs on your past account even if you delete it.

If you want to be really cautious, then delete and recreate. It also depend what you’re talking about. If it’s a social media account or an online store, the implications are not the same.