Step-by-Step Guide to Removing Personal Data from Search Engines, Databases and Social Networks
The article opens by describing how entering a phone number in quotes, followed by formatted variants such as 8 (999) 123-45-67, and old email addresses quickly reveals scattered personal data across the internet. The guide is structured as a checklist rather than theory, supplying exact buttons to click, wording for letters, statutory deadlines, and escalation procedures when requests are refused.
Plan on seven steps and calendar
The recommended sequence begins with an audit to build a list of URLs, followed by contacting the original source, then search engines, social networks, phone directories, maps, and finally archives. The first week is allocated to auditing and sending letters, weeks two and three to waiting plus social media and directory work, week four to search engine requests, and month two to complaints with Roskomnadzor for non-responsive operators.
Step 1. 20-minute audit
Users are instructed to create a spreadsheet tracking every URL, the personal data displayed, the recipient contacted, date sent, and reply received. Search queries should include full name variations, maiden names, city combinations, four phone formats, every historical email address, and old forum nicknames. The same queries must be run in both Yandex and Google, including image search. Additional checks cover Have I Been Pwned for breach history, caller-ID apps, the Roskomnadzor register of personal-data operators, and email inboxes for forgotten registrations.
Step 2. Source site and letter template
Contact details are located in “Contacts”, “About us”, privacy policies, or WHOIS records. Letters should be sent via email, web form, and messenger simultaneously. The template cites 152-FZ, lists exact URLs and data fields, demands cessation of processing and deletion within statutory timeframes, and warns of escalation to Roskomnadzor. Screenshots of every page and message are required for later complaints.
Step 3. Search engines Yandex and Google
Yandex accepts 10.3-law requests through its feedback form and processes them within ten working days. Google offers both the Russian legal route and its global “Results about you” tool, which now covers passport and driver-license numbers. Quick removal of already-deleted pages is available via the three-dot menu. The right to be forgotten applies only to name-based queries; direct links remain accessible.
Step 4. Social networks, messengers, old accounts
Visibility settings for phone numbers, birth dates, and indexing must be disabled first. Accounts should be fully deleted rather than deactivated. When login access is lost, the same 152-FZ request applies. Photographs published without consent can be removed under Article 152.1 of the Civil Code except in cases of public interest or paid posing.
Step 5–7. Phone numbers, directories, archives
Old listings on classifieds, food-delivery profiles, and review sites are removed through account settings or support tickets. Map services such as 2GIS require identity verification. Web-archive removal requests go to info@archive.org and succeed only with copyright or proven-harm arguments. Leaked databases cannot be erased; mitigation relies on changing numbers, using separate registration emails, enabling two-factor authentication, and activating credit self-bans via Gosuslugi.
Roskomnadzor and courts
Complaints are filed when operators ignore deadlines, refuse without legal basis, or lack contact information. The regulator has 30 days to respond and may issue orders or restrict access. Court action remains a last resort with lower practical impact due to modest fines.
Maintenance and realistic expectations
A full audit should be repeated after one month and then quarterly. The realistic goal is clearing the first page of search results for phone, address, and daily routine data rather than total disappearance from the internet.
Related articles
Building Prizrak: How a Developer Created a Federated Messenger That Masks All Traffic as Legitimate HTTPS
A developer created Prizrak, a federated messenger with end-to-end encryption where all traffic, including calls, is indistinguishable from ordinary HTTPS connections. The project addresses three common limitations of existing messengers: centralized control points, mandatory phone numbers, and detectable encrypted traffic. It uses real TLS 1.3 handshakes to actual domains, multi-port listening, and a hidden token mechanism inside the encrypted channel. When servers cannot reach each other directly, messages are delivered through a network of storage nodes modeled after Ceph's RADOS system. Voice and video calls run on a native media stack with custom STUN-like functionality and careful UDP buffer sizing to avoid packet truncation. An integrated two-hop VPN reuses the same stealth transport while keeping messenger traffic outside the tunnel.
GrapheneOS Setup Guide: Configuring Pixel Phones for Corporate Surveillance-Free Daily Use
This comprehensive engineering guide explains how to deploy GrapheneOS on supported Google Pixel devices to eliminate corporate telemetry collection. It follows three core principles: rejecting proprietary ecosystems, applying Zero Trust through cryptography and open-source audits, and enforcing strict compartmentalization via isolated user profiles. The tutorial covers official installation via the Web Installer, basic owner profile hardening with PIN shuffling and automatic reboot, and the use of Obtainium for direct FOSS app management from GitHub repositories. Detailed recommendations include privacy-focused tools such as KeePassDX, Aegis Authenticator, AmneziaVPN, Signal, and Fossify applications, along with VPN kill-switch configuration. Regional profiles are created for sandboxed Google Play, Aurora Store, RuStore, and Huawei AppGallery to safely run banking, marketplace, and social apps without cross-profile tracking.
Following the White Rabbit: Developer Builds Custom Rust VPN PAYPHONE Using QUIC and Obfuscation to Evade Detection
A Russian developer has released PAYPHONE, an experimental IPv4 VPN written entirely in Rust that uses QUIC datagrams and optional TLS-over-TCP transport with custom obfuscation. The project aims to provide an alternative to AmneziaWG and Xray/VLESS+REALITY stacks that are commonly used to bypass Russian internet filtering. The article details the full packet path from TUN interface through a 16-byte PAYPHONE header, session management with Ed25519 tokens, and multiple post-launch bugs including MTU miscalculations, self-routing loops on macOS, and timer lifetime issues in Tokio. Key technical choices include RFC 9221 datagram support to avoid head-of-line blocking for multiplexed TCP flows and token-bucket rate limiting tied to subscription tokens. The author also describes route monitoring every 400 ms and interface-bound sockets to prevent the tunnel from swallowing its own control traffic.
WhatsApp Introduces Parental Controls for Teen Privacy Settings
WhatsApp, owned by Meta (recognized as an extremist organization and banned in Russia), has rolled out new parental control tools for family accounts. Parents can manage privacy settings, group participation, channel access, status visibility, and Meta AI usage for teens, but cannot read personal messages due to end-to-end encryption. All controls are voluntary and require joint setup with the teenager, protected by a single PIN code that prevents easy reversal of restrictions. Notifications alert parents when teens join or leave groups or when group sizes change significantly. Separate options cover channel usage, viewable statuses, and audience controls for teen posts. Meta AI access can be set to a standard 13+ mode or a stricter Limited Content mode with undisclosed restrictions. The company plans to expand these features gradually based on family feedback while maintaining encryption protections.