Your Forgotten Online Accounts Are a Privacy Risk — Here Is What to Do About Them

Your Forgotten Online Accounts Are a Privacy Risk — Here Is What to Do About Them

Photo by Quino Al on Unsplash

TL;DR

  • Every account you have ever created — even ones you forgot years ago — still stores your personal data on a company's servers.
  • Abandoned accounts are prime targets when companies get breached, and the data they hold can be used for credential stuffing, identity fraud and phishing.
  • India's new DPDP Act (in effect from November 2025) gives you the legal right to request access to your data and ask for its erasure.
  • The fix is simple: find old accounts, close them properly, review app permissions and check what your phone number and email address are exposing online.

The Accounts You Forgot Are Not Forgotten by Anyone Else

Think back to every app you downloaded, every shopping site you tried once, every forum you signed up for to read a single thread. Each of those registrations handed over at least your email address and often your mobile number, name and sometimes your address or payment details.

Those accounts do not disappear when you stop using them. The data sits in company databases, unmonitored, often under a weak or reused password — exactly the kind of target that makes data breaches so damaging. As one security guide puts it, abandoned accounts are "privacy time bombs" because each one holds your personal information in a database that could be breached at any time.

For Indian users especially, this risk is compounding. Mobile numbers are tied to Aadhaar, bank accounts, UPI IDs and dozens of apps. A phone number exposed from one forgotten account does not stay isolated — it connects to a web of other services and can be used by scammers for targeted fraud, impersonation calls and phishing messages.

Why Old Accounts Are Riskier Than You Think

1. They Are Breached Just Like Active Ones

When a company is hacked, every account in their database gets exposed — active or not. If your account exists, your data goes with it. An old registration on a now-defunct e-commerce site or a gaming platform you used in college could appear in a data breach today with your phone number, email and possibly a password you still use somewhere else.

2. Credential Stuffing Starts With Weak Old Passwords

Old accounts are easy targets precisely because they tend to use older, weaker passwords. Once attackers get hold of those credentials from a breach, they test them automatically across banking apps, email services and social media — a technique known as credential stuffing. One forgotten account can therefore put your active accounts at serious risk.

3. Forgotten Apps Keep Collecting Data in the Background

Unused apps on your phone do not necessarily go quiet. App permissions granted at installation — access to contacts, location, storage, microphone — often remain active even after you stop using the app. Over time, forgotten apps can quietly build a profile of your behaviour without you noticing, creating unnecessary privacy risks. Outdated apps also stop receiving security patches, leaving known vulnerabilities open for attackers to exploit.

4. Your Phone Number Can Get Recycled

Indian telecom operators reassign inactive mobile numbers to new subscribers after a period of dormancy. If your old number is still tied to an app account or a UPI ID, the person now using that number could inadvertently inherit access routes to your services — a genuine fraud risk that is easy to overlook.

5. Old Accounts Expose More Than You Remember

Old accounts can expose location history, purchase records, social connections and recycled usernames that still link back to you. A stale profile on a matrimonial or dating platform may contain photos, relationship preferences and personal contact details you shared years ago and completely forgot about.

What Your Rights Are Under India's DPDP Act

India's Digital Personal Data Protection Act, 2023 (DPDP Act) came into effect in phases from November 13, 2025, when the Ministry of Electronics and Information Technology officially notified the implementing DPDP Rules, 2025. This is a meaningful shift in individual privacy rights in India.

As a data principal — the individual to whom personal data relates — you now have formal rights under the Act, including:

  • Right to Access (Section 11): You can request a summary of what personal data a company holds about you and what they are doing with it.
  • Right to Correction and Erasure (Section 12): You can ask companies to correct inaccurate data or erase data that is no longer needed.
  • Right to Withdraw Consent: Consent under the DPDP Act must be specific, informed and unambiguous, and you can withdraw it at any time — this withdrawal does not affect processing that already happened.
  • Right to Grievance Redressal (Section 13): You can raise a complaint directly with a company, and if unresolved, escalate to the Data Protection Board of India.
  • Right to Nominate (Section 14): You can nominate another person to exercise your data rights in the event of death or incapacity.

Practically, the Act also requires companies to erase your personal data once the purpose for which it was collected is served — or once you have not engaged with the service within the applicable retention period. For large social media platforms and e-commerce entities, the DPDP Rules specify a default retention period of three years from the last login or transaction, after which erasure is required unless you actively engage.

These rights are meaningful, but they only work if you actually exercise them. Most people never do, which is why personal data from forgotten accounts continues to circulate long after the account was last used.

How to Find and Close Forgotten Accounts

Step 1 — Search Your Email Inbox

Search your email for phrases like "welcome to", "verify your email", "your account" and "confirm your registration". These will surface most of the services you signed up for, including ones you have completely forgotten. Check older email addresses too — especially ones you used before switching providers.

Step 2 — Check Saved Passwords in Your Browser

Your browser's password manager often holds a record of every site you have logged into. Go to your browser settings and open the saved passwords section. The list is usually much longer than people expect.

Step 3 — Review Social Login Connections

Many apps allow you to log in using your Google, Facebook or Apple account. Those connections are listed in your social account settings under "Apps and Permissions" or "Third-Party Access". Review and revoke access for any app you no longer use.

Step 4 — Close Accounts, Not Just the App

Uninstalling an app from your phone does not close your account or delete your data. You need to actively request account deletion through the app settings, the company's website or by emailing their support team. Under India's DPDP Act, companies are now obligated to process such erasure requests. Keep a record of what you requested and when.

Step 5 — Review App Permissions on Your Phone

Go to your phone's Settings > Apps > Permissions to see which apps currently have access to your location, contacts, microphone and camera. Revoke permissions for any app you do not actively use and uninstall apps you no longer need.

Step 6 — Check What Your Phone Number and Email Are Exposing

Even after closing accounts, your phone number and email address may already appear in data breach records, directory listings or other open-web sources. Running a digital exposure check helps you understand what is already out there — so you know where your cleanup efforts should focus first.

You can check your phone number and email address across multiple sources with a Scan My Shadow digital exposure scan. The report shows you where your details have turned up online so you have a clear picture of your current exposure before you start cleaning up.

A Simple Priority List: Which Accounts to Close First

Not all forgotten accounts carry the same risk. Prioritise closing accounts that:

  • Are still accessible with an old or reused password
  • Contain your real name, phone number, home address or financial details
  • Are linked to your primary email or social media account
  • Belong to services that have suffered data breaches in the past
  • Held payment card or UPI-linked information
  • Include photos or personal details you no longer want publicly associated with you

Accounts with no personal details — for example, an anonymous forum account with a fake username and no linked email — carry much lower risk and can be deprioritised.

After the Cleanup: Keeping Your Digital Footprint Small Going Forward

  • Use a separate email address for trials, one-off registrations and anything you do not plan to use long-term.
  • Avoid using your primary mobile number for app registrations that do not genuinely need it.
  • Set a reminder every six months to review your installed apps and saved passwords.
  • Use strong, unique passwords for every account — a password manager makes this practical.
  • Do not sign in with Google or Facebook unless you are prepared to manage that connection long-term.
  • Periodically re-scan your exposure to catch new places your details may have appeared since your last check.

If you want to understand your current digital exposure before or after a cleanup, Scan My Shadow produces a plain-language report showing where your phone number and email address have been found across breach databases and open-web sources. There is no app to download and no technical knowledge required.

Frequently Asked Questions

If I delete an app from my phone, is my account and data also deleted?

No. Uninstalling an app removes it from your device but leaves your account and all your personal data on the company's servers. To remove your data, you need to actively delete your account through the app, the company's website or a written request to their support team. Under India's DPDP Act, companies are required to process valid erasure requests.

Can an old account I forgot about actually cause harm today?

Yes. If the company behind that old account suffers a data breach, your details — email, phone number, password — get exposed. Attackers can use those credentials in automated attacks against your active accounts elsewhere. Even without a breach, the account may still be accessible to anyone who requests a password reset to your email.

What does the DPDP Act mean for my right to erase old data in India?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (effective from November 13, 2025), Indian residents have a formal right to request erasure of personal data that is no longer needed for the purpose it was collected. Companies operating in India are required to respond to these requests. You can also file a complaint with the Data Protection Board of India if a company does not comply.

How do I find accounts I have completely forgotten about?

Search your email inbox for phrases like "welcome to", "verify your email" and "your account". Check saved passwords in your browser and review third-party app connections in your Google, Facebook and Apple account settings. Running a check on your email address through a data breach tool can also surface services you signed up for that later suffered a breach.

My phone number was registered with a service I closed years ago. Can it still be exposed?

Yes. Closing an account reduces future risk but does not erase data that was already collected before closure, shared with third parties or included in a breach that happened while the account was active. A digital exposure scan can help you see whether your phone number is still appearing in breach databases or open-web sources even after you have closed the underlying account.

Find Out What Your Phone Number and Email Are Exposing Right Now

Before you start closing old accounts, it helps to know what has already been exposed. Scan My Shadow checks your phone number and email address across breach databases and open-web sources and sends you a plain-language report — no app to download, no technical knowledge needed, and no subscription required.

Run your free digital exposure scan at Scan My Shadow →

Comments

Popular posts from this blog

UPI Fraud Prevention in India: Complete Guide to Protect Your Digital Payments in 2024

Children’s Data and the DPDP Act: What Parents Should Know

Digital Arrest Scams Rise 200% in India: New AI-Powered Cyber Threats Target Professionals in 2026