Step-by-Step Guide to Removing Personal Data from Search Engines, Databases and Social Networks
The article opens by describing how entering a phone number in quotes, followed by formatted variants such as 8 (999) 123-45-67, and old email addresses quickly reveals scattered personal data across the internet. The guide is structured as a checklist rather than theory, supplying exact buttons to click, wording for letters, statutory deadlines, and escalation procedures when requests are refused.
Plan on seven steps and calendar
The recommended sequence begins with an audit to build a list of URLs, followed by contacting the original source, then search engines, social networks, phone directories, maps, and finally archives. The first week is allocated to auditing and sending letters, weeks two and three to waiting plus social media and directory work, week four to search engine requests, and month two to complaints with Roskomnadzor for non-responsive operators.
Step 1. 20-minute audit
Users are instructed to create a spreadsheet tracking every URL, the personal data displayed, the recipient contacted, date sent, and reply received. Search queries should include full name variations, maiden names, city combinations, four phone formats, every historical email address, and old forum nicknames. The same queries must be run in both Yandex and Google, including image search. Additional checks cover Have I Been Pwned for breach history, caller-ID apps, the Roskomnadzor register of personal-data operators, and email inboxes for forgotten registrations.
Step 2. Source site and letter template
Contact details are located in “Contacts”, “About us”, privacy policies, or WHOIS records. Letters should be sent via email, web form, and messenger simultaneously. The template cites 152-FZ, lists exact URLs and data fields, demands cessation of processing and deletion within statutory timeframes, and warns of escalation to Roskomnadzor. Screenshots of every page and message are required for later complaints.
Step 3. Search engines Yandex and Google
Yandex accepts 10.3-law requests through its feedback form and processes them within ten working days. Google offers both the Russian legal route and its global “Results about you” tool, which now covers passport and driver-license numbers. Quick removal of already-deleted pages is available via the three-dot menu. The right to be forgotten applies only to name-based queries; direct links remain accessible.
Step 4. Social networks, messengers, old accounts
Visibility settings for phone numbers, birth dates, and indexing must be disabled first. Accounts should be fully deleted rather than deactivated. When login access is lost, the same 152-FZ request applies. Photographs published without consent can be removed under Article 152.1 of the Civil Code except in cases of public interest or paid posing.
Step 5–7. Phone numbers, directories, archives
Old listings on classifieds, food-delivery profiles, and review sites are removed through account settings or support tickets. Map services such as 2GIS require identity verification. Web-archive removal requests go to info@archive.org and succeed only with copyright or proven-harm arguments. Leaked databases cannot be erased; mitigation relies on changing numbers, using separate registration emails, enabling two-factor authentication, and activating credit self-bans via Gosuslugi.
Roskomnadzor and courts
Complaints are filed when operators ignore deadlines, refuse without legal basis, or lack contact information. The regulator has 30 days to respond and may issue orders or restrict access. Court action remains a last resort with lower practical impact due to modest fines.
Maintenance and realistic expectations
A full audit should be repeated after one month and then quarterly. The realistic goal is clearing the first page of search results for phone, address, and daily routine data rather than total disappearance from the internet.
Related articles
Amnezia VPN Survives Coordinated Russian Censorship Campaign Targeting AmneziaWG Protocol Fingerprints
Amnezia VPN has published a detailed post-mortem on the multi-wave blocking campaign conducted by Russian authorities against its Amnezia Free and Amnezia Premium services during June and July. The company describes a shift from simple protocol blocking to sophisticated fingerprinting of AmneziaWG traffic combined with infrastructure DDoS attacks and automated IP-subnet blacklisting. Engineers closed multiple detection vectors including zero-length UDP packets, fixed-size keepalive messages, handshake timing patterns, and nonce zero bytes. The incident forced accelerated migration to AmneziaWG 2.0, discontinuation of legacy client support, and development of AmneziaWG 3.0 while expanding VLESS infrastructure as a backup. Self-hosted users largely avoided direct protocol blocks but still faced subnet-level restrictions. The report highlights how Roskomnadzor now applies cumulative scoring across multiple traffic features rather than single definitive markers.
Data Masking: 8 Critical Questions Businesses and Developers Ask About Protecting Sensitive Data
Garda expert Dmitry Larin addresses common challenges in data masking during a recent webinar titled 'Data Masking: Battle of Opinions'. The discussion covers why masking remains essential even when encryption is deployed, how to preserve application functionality after anonymization, and the performance trade-offs of processing large databases such as 5 TB PostgreSQL instances. Different masking types including static, dynamic, selective, and streaming are explained with specific use cases for DevOps pipelines, external contractors, and BI systems. The article also examines why machine learning alone is insufficient for discovering personal data and why custom scripts fail at scale across heterogeneous environments like PostgreSQL and Oracle. Practical recommendations include combining masking with encryption, using deterministic transformations for deduplication, and separating replication from masking tasks to avoid production impact.
MAX Desktop Client Tested for VPN Detection on Windows, No Tracking Signs Found
A Habra user named Slava_B conducted an experiment on September 8, 2026, to determine whether the MAX desktop client on Windows could detect or route traffic through a VPN configured at the router level. The setup used a Keenetic router that directed Russian resources directly while sending other connections via an OpenConnect tunnel to a European VPS, with no VPN client or virtual adapter present in Windows itself. Monitoring tools including Process Monitor, Wireshark, TCPView, and tcpdump revealed that MAX.exe and MAX-service.exe processes communicate locally and connect to MAX/ONEME infrastructure along with AppTracer services. The application repeatedly accessed MachineGuid, computer name, proxy settings, device IDs, and microphone/camera information, though these reads may support diagnostics and anti-fraud functions. No connections appeared on the VPN interface, and the client did not attempt to reach IP-checking services, Telegram, or WhatsApp. The researcher noted that TLS traffic was not decrypted, so actual transmission of identifiers could not be confirmed, and results apply only to this router-based configuration.
PII-Guard: Open-Source Detector for Personal Data in Russian Text
Andrey Ivanov, an NLP researcher at red_mad_robot, has released PII-Guard, an open-source system that detects and masks personal data in Russian text before it reaches language models. The tool combines rule-based checks with a fine-tuned ruBert-base NER model to handle names, addresses, phones, passports, INN, SNILS, bank cards and other entities. It replaces detected PII with structured XML-like tags that preserve grammatical information such as gender and entity ID, allowing models to generate coherent responses that are later restored with real values. The hybrid pipeline first applies normalization, pattern matching, Luhn and weighted checksum validation, and context windows with positive and negative keywords, then merges results with model predictions via an arbitration module. Evaluation on four public datasets, including Hivetrace, alexen2 and alrosait, shows PII-Guard outperforming other open solutions on both strict span matching and type-overlap micro-F1 metrics. The project, including datasets and code, is available on GitHub and aims to reduce leakage risks while maintaining downstream model utility.