Digital footprint

How to delete old accounts

Every old account you never use is still a live copy of your personal details sitting on someone else's server. This guide covers what to delete first, how to get it removed, and your rights as an Australian when a company makes it difficult.

Last updated: 31 May 2026Independent guidance, Australia-first

The short answer

Every old account you never use is still a live copy of your personal details sitting on someone else's server, and if you have reused a password, it is also a way into your other accounts. To delete them properly: first find every account linked to your email, then work through them in order of risk, starting with accounts already caught in a breach, then anything holding payment or ID details, then everything else. Look for a genuine “delete account” option rather than “deactivate”, and where none exists, send a written deletion request. Businesses covered by the Privacy Act 1988 must take reasonable steps to destroy or de-identify personal information they no longer need, though the Act does not cover every business, with a long-standing exemption for many smaller operators. Some accounts cannot be deleted immediately due to record-keeping laws, so ask for a timeline instead.

In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and get a prioritised plan of what to do after a breach or a life change.

Australian & independentThird-party security assessmentSources cited

Key takeaways

  • A dormant account holds the same data as an active one, and nobody is watching it.
  • Reused passwords turn one old breach into a way into your current accounts.
  • Delete in order of risk: breached accounts, then payment or ID details, then the rest.
  • Deactivate is not delete, the company keeps your data either way.
  • APP 11.2 requires organisations to destroy or de-identify personal information they no longer need.

Why it matters

Why old accounts are a breach liability

An account you have not logged into in three years does not feel like a risk. But from a data-exposure standpoint, it is identical to a live one. The company still holds your email, likely a password, and often your name, date of birth, address or payment details. None of that disappears because you stopped using the service.

Two things make old accounts worse than most people assume. First, reused passwords turn one old breach into many new problems: if a forgotten account gets breached and you used the same password on your email or banking, attackers can try that combination elsewhere (credential stuffing). Second, dormant accounts are rarely monitored, by you or the company, so a breach at a service you closed years ago can go unnoticed indefinitely, especially if the business itself has stopped actively maintaining security.

The fix is simple: fewer accounts holding your data means fewer places it can leak from. For what to do when a service you still use gets breached, see what to do if your email is in a data breach.

Step 1

Find them before you delete them

You cannot clean up an inventory you do not have. Before deleting anything, build a list using the methods in our find accounts linked to your email guide: inbox searches for welcome and confirmation emails, your password manager's saved logins, the connected apps pages inside Google, Apple and Microsoft, and a free breach check against your email address.

Put everything into one list with columns for service name, whether it holds payment or ID details, whether it has shown up in a known breach, and last used date. That is what turns “I should clean this up” into an actual to-do list, and the difference between deleting old accounts online in an afternoon versus never getting around to it.

Check my exposure, free

In The Event Of runs a free email check against known breaches and maps the accounts linked to your email in one pass. No credit card required.

Check my exposure free

Step 2

Deletion order of attack: what to close first

Once you have your list, do not start alphabetically, start with risk. This order gets the highest-exposure accounts closed first, in case you run out of time or motivation partway through.

  1. Accounts confirmed in a known data breach (do this first). Assume attackers already have whatever that service stored. Change the password immediately if reused elsewhere, then delete the account if you do not need it. See what to do if your email is in a data breach for full response steps.
  2. Accounts holding payment details or government ID. Old shopping accounts with a saved card, or anything that asked for a driver's licence or Medicare number, carry the most damage potential if breached later.
  3. Accounts with a reused password. Even without a confirmed breach, sharing a password with your email or banking is a standing risk. Delete it, or change the password to something unique first.
  4. Everything else you do not use. Old forums, one-off signups, apps you tried once. Lower individual risk, but each is still a copy of your data sitting somewhere unwatched.
  5. Accounts you are unsure about. Secure them with a unique password and multi-factor authentication rather than leaving them as-is, and revisit at your next review.

Step 3

How to delete unused accounts: the actual steps

Time estimate: 5 to 15 minutes per account, once you know where to look.

  1. Log in and go to account or privacy settings.Most services bury deletion under Settings › Account or Privacy, not the main profile page.
  2. Look for “delete account”, not “deactivate” or “log out”. Deactivating just hides your profile while the company keeps your data. Deletion is what actually triggers removal.
  3. Check for a direct link first.Community-maintained directories like Just Delete Me list the deletion-page URL for hundreds of common services, saving you a hunt through settings menus. Always confirm you are on the company's own site before entering login details.
  4. Confirm and check your inbox. Most services send a confirmation email, sometimes with a grace period (often 14 to 30 days) before deletion is final. Do not log back in during that window, since it can cancel the deletion.
  5. If there is no visible delete option, send a written request using the template below instead of giving up.

Step 4

Delete all accounts associated with your email: a systematic sweep

If your goal is closing out everything tied to one email address, before switching to a new one, or after a breach made you want a clean slate, treat it as a project, not a single sitting. Work from your inventory list, not memory, and batch by platform type such as shopping sites, old subscriptions and forum accounts, rather than jumping between different settings menus. Note the closure date against each entry, then re-run a breach check afterwards. It will not erase historical breach records, but it confirms whether closed accounts still show up anywhere and flags anything new.

Gmail

Delete all accounts associated with your Gmail address

If Gmail is the login for most of what you use, Google's own tools make the sweep faster than doing it blind. Go to myaccount.google.com › Security › Third-party apps & services to see every app connected via “Sign in with Google”, when you last used it, and what data it can access. Revoke anything you do not recognise. That revokes the connection but does not always delete the account on the third party's side, so you will usually still need to visit that service directly to finish the job.

Google Takeout(takeout.google.com) lets you export your account activity first if you want a record. Finally, repeat the inbox-search steps (“welcome”, “verify your email”, “receipt”) inside Gmail specifically to catch accounts that do not use Google sign-in but still list your Gmail address as the contact.

Your rights

Your deletion rights in Australia: the Privacy Act, not the right to be forgotten

Australia does not have a direct, GDPR-style “right to erasure” that lets you demand deletion of any data at any time. What you do have, under the Privacy Act 1988 and the Australian Privacy Principles (APPs), is narrower but still useful. APP 11.2 requires an organisation to take reasonable steps to destroy or de-identify personal information it no longer needs for any purpose it was collected for, and is not required by law to retain. This is the strongest lever for a deletion request, since you are asking the business to meet an obligation it already has. APP 12 and APP 13 add a right to request access to, and correction of, the personal information an organisation holds about you.

Most reasonable Australian businesses will action a clear, written deletion request even without a codified “right to be forgotten”, because ignoring it creates compliance risk for them. If a business refuses without a lawful reason, you can escalate to the Office of the Australian Information Commissioner (OAIC), which oversees the Privacy Act and the Notifiable Data Breaches scheme.

Template

Template deletion-request email

Copy this, adjust the bracketed sections, and send it to the company's privacy or support email address.

Subject: Request to delete my personal information — [your name / account email]

Hi [Company name],

I'm requesting that you delete the personal information you hold on me under my account associated with [your email address], in line with your obligations under Australian Privacy Principle 11.2 of the Privacy Act 1988 to destroy or de-identify personal information you no longer need.

Please confirm:

  1. That my account and associated personal information have been deleted (not just deactivated),
  2. Any information you're required to retain for legal, financial or regulatory reasons, and for how long, and
  3. The date this will be completed.

I would appreciate a response within 30 days.

Thanks,

[Your name]

Limits

When deletion is not possible: dormant account and retention policies

Sometimes a business genuinely cannot delete everything you ask for straight away, and it is not stonewalling, it is a real constraint. Tax, banking and some healthcare records often must be kept for a set number of years regardless of your request, commonly five to seven years for financial records, depending on the record type and applicable law. Some services also hold an inactive account in a dormant or archived state for a fixed period before permanent deletion, in case of disputes or fraud investigations. And deletion from live systems does not always mean immediate deletion from backups, which are typically purged on their own rolling schedule.

Ask for the specific retention period

If a company cites one of these, ask for the specific retention period and what happens at the end of it. That is a reasonable, verifiable answer. A vague “we can't delete that” without a reason is not, and is worth escalating to the OAIC.

Shortcuts

Where to find brand-specific deletion steps

Some of the largest platforms bury deletion behind non-obvious menus, multi-step confirmations or retention quirks. For direct deletion links to hundreds of services, JustDeleteMe is a useful free directory. The general steps above apply to every service either way, and the higher-leverage move is usually knowing which accounts to delete first, which is what mapping your footprint tells you. For a broader clean-up plan, see our digital footprint checklist and best digital footprint management tools (Australia).

Using In The Event Of

How In The Event Of helps

In The Event Of is built around turning scattered account records into a single map. You can connect a supported inbox (Gmail or Outlook) so it can scan for account-related metadata, sender addresses, subject lines and timestamps rather than the body of your emails, or add services manually. It then organises what it finds into a digital footprint, highlights breach exposure, and gives you guided steps for each account, so you can see which forgotten services are worth closing first. You stay in control of every change.

FAQ

Frequently asked questions

Does deleting an account remove it from a breach that already happened?
No. If your email and password were already exposed, deleting the account now does not undo that, and the data may already be circulating. Deletion stops future liability. For the breach itself, change any reused passwords and follow the steps in our data breach response guide.
What is the difference between deactivating and deleting an account?
Deactivating hides your profile while the company keeps your data, usually so you can reactivate later with everything intact. Deleting removes your personal information from active systems. Always look specifically for delete, because deactivate does not reduce your exposure.
Can an Australian company legally refuse to delete my account?
Yes, in limited cases, if it must legally retain certain records such as tax, financial or some healthcare data, or if the information is still needed for an active, lawful purpose. Under APP 11.2 it should still destroy or de-identify data once that need ends. An unexplained refusal is worth raising with the OAIC.
Is it safe to use a site like Just Delete Me to find deletion links?
Generally yes for finding the right settings page faster, since these are community-maintained directories of official deletion URLs rather than tools that access your accounts. Confirm you have landed on the company's genuine site before entering login details, and treat the difficulty rating as a guide, not a guarantee.
How do I find every account tied to my email before I start deleting?
Use inbox searches, your password manager's saved logins, the connected-apps pages in Google, Apple and Microsoft, and a free breach check. Full steps are in our guide on how to find accounts linked to your email. Build one list first so you are working from a plan, not memory.
Should I delete accounts linked to a breach even if I never got a notification?
Yes, run your own breach check rather than waiting for one, since not every affected company notifies promptly, or at all. If your email turns up in a breach for a service you no longer use, that is a priority-one deletion candidate regardless.

Disclaimer: This guide is general information about Australian privacy law, not legal advice. Retention rules and platform deletion steps change, so check the linked official sources for the current position. This guide is general information only and is not legal, financial, or security advice. It is based on publicly available sources at the time of writing and may not reflect the most recent developments. In The Event Of Pty Ltd (ABN 38 687 352 647) is an independent Australian company and is not affiliated with the third-party services named in this guide.