Digital footprint
How to delete old accounts
Every old account you never use is still a live copy of your personal details sitting on someone else's server. This guide covers what to delete first, how to get it removed, and your rights as an Australian when a company makes it difficult.
The short answer
In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and get a prioritised plan of what to do after a breach or a life change.
Key takeaways
- A dormant account holds the same data as an active one, and nobody is watching it.
- Reused passwords turn one old breach into a way into your current accounts.
- Delete in order of risk: breached accounts, then payment or ID details, then the rest.
- Deactivate is not delete, the company keeps your data either way.
- APP 11.2 requires organisations to destroy or de-identify personal information they no longer need.
Why it matters
Why old accounts are a breach liability
An account you have not logged into in three years does not feel like a risk. But from a data-exposure standpoint, it is identical to a live one. The company still holds your email, likely a password, and often your name, date of birth, address or payment details. None of that disappears because you stopped using the service.
Two things make old accounts worse than most people assume. First, reused passwords turn one old breach into many new problems: if a forgotten account gets breached and you used the same password on your email or banking, attackers can try that combination elsewhere (credential stuffing). Second, dormant accounts are rarely monitored, by you or the company, so a breach at a service you closed years ago can go unnoticed indefinitely, especially if the business itself has stopped actively maintaining security.
The fix is simple: fewer accounts holding your data means fewer places it can leak from. For what to do when a service you still use gets breached, see what to do if your email is in a data breach.
Step 1
Find them before you delete them
You cannot clean up an inventory you do not have. Before deleting anything, build a list using the methods in our find accounts linked to your email guide: inbox searches for welcome and confirmation emails, your password manager's saved logins, the connected apps pages inside Google, Apple and Microsoft, and a free breach check against your email address.
Put everything into one list with columns for service name, whether it holds payment or ID details, whether it has shown up in a known breach, and last used date. That is what turns “I should clean this up” into an actual to-do list, and the difference between deleting old accounts online in an afternoon versus never getting around to it.
Check my exposure, free
In The Event Of runs a free email check against known breaches and maps the accounts linked to your email in one pass. No credit card required.
Step 2
Deletion order of attack: what to close first
Once you have your list, do not start alphabetically, start with risk. This order gets the highest-exposure accounts closed first, in case you run out of time or motivation partway through.
- Accounts confirmed in a known data breach (do this first). Assume attackers already have whatever that service stored. Change the password immediately if reused elsewhere, then delete the account if you do not need it. See what to do if your email is in a data breach for full response steps.
- Accounts holding payment details or government ID. Old shopping accounts with a saved card, or anything that asked for a driver's licence or Medicare number, carry the most damage potential if breached later.
- Accounts with a reused password. Even without a confirmed breach, sharing a password with your email or banking is a standing risk. Delete it, or change the password to something unique first.
- Everything else you do not use. Old forums, one-off signups, apps you tried once. Lower individual risk, but each is still a copy of your data sitting somewhere unwatched.
- Accounts you are unsure about. Secure them with a unique password and multi-factor authentication rather than leaving them as-is, and revisit at your next review.
Step 3
How to delete unused accounts: the actual steps
Time estimate: 5 to 15 minutes per account, once you know where to look.
- Log in and go to account or privacy settings.Most services bury deletion under Settings › Account or Privacy, not the main profile page.
- Look for “delete account”, not “deactivate” or “log out”. Deactivating just hides your profile while the company keeps your data. Deletion is what actually triggers removal.
- Check for a direct link first.Community-maintained directories like Just Delete Me list the deletion-page URL for hundreds of common services, saving you a hunt through settings menus. Always confirm you are on the company's own site before entering login details.
- Confirm and check your inbox. Most services send a confirmation email, sometimes with a grace period (often 14 to 30 days) before deletion is final. Do not log back in during that window, since it can cancel the deletion.
- If there is no visible delete option, send a written request using the template below instead of giving up.
Step 4
Delete all accounts associated with your email: a systematic sweep
If your goal is closing out everything tied to one email address, before switching to a new one, or after a breach made you want a clean slate, treat it as a project, not a single sitting. Work from your inventory list, not memory, and batch by platform type such as shopping sites, old subscriptions and forum accounts, rather than jumping between different settings menus. Note the closure date against each entry, then re-run a breach check afterwards. It will not erase historical breach records, but it confirms whether closed accounts still show up anywhere and flags anything new.
Gmail
Delete all accounts associated with your Gmail address
If Gmail is the login for most of what you use, Google's own tools make the sweep faster than doing it blind. Go to myaccount.google.com › Security › Third-party apps & services to see every app connected via “Sign in with Google”, when you last used it, and what data it can access. Revoke anything you do not recognise. That revokes the connection but does not always delete the account on the third party's side, so you will usually still need to visit that service directly to finish the job.
Google Takeout(takeout.google.com) lets you export your account activity first if you want a record. Finally, repeat the inbox-search steps (“welcome”, “verify your email”, “receipt”) inside Gmail specifically to catch accounts that do not use Google sign-in but still list your Gmail address as the contact.
Your rights
Your deletion rights in Australia: the Privacy Act, not the right to be forgotten
Australia does not have a direct, GDPR-style “right to erasure” that lets you demand deletion of any data at any time. What you do have, under the Privacy Act 1988 and the Australian Privacy Principles (APPs), is narrower but still useful. APP 11.2 requires an organisation to take reasonable steps to destroy or de-identify personal information it no longer needs for any purpose it was collected for, and is not required by law to retain. This is the strongest lever for a deletion request, since you are asking the business to meet an obligation it already has. APP 12 and APP 13 add a right to request access to, and correction of, the personal information an organisation holds about you.
Most reasonable Australian businesses will action a clear, written deletion request even without a codified “right to be forgotten”, because ignoring it creates compliance risk for them. If a business refuses without a lawful reason, you can escalate to the Office of the Australian Information Commissioner (OAIC), which oversees the Privacy Act and the Notifiable Data Breaches scheme.
Template
Template deletion-request email
Copy this, adjust the bracketed sections, and send it to the company's privacy or support email address.
Subject: Request to delete my personal information — [your name / account email]
Hi [Company name],
I'm requesting that you delete the personal information you hold on me under my account associated with [your email address], in line with your obligations under Australian Privacy Principle 11.2 of the Privacy Act 1988 to destroy or de-identify personal information you no longer need.
Please confirm:
- That my account and associated personal information have been deleted (not just deactivated),
- Any information you're required to retain for legal, financial or regulatory reasons, and for how long, and
- The date this will be completed.
I would appreciate a response within 30 days.
Thanks,
[Your name]
Limits
When deletion is not possible: dormant account and retention policies
Sometimes a business genuinely cannot delete everything you ask for straight away, and it is not stonewalling, it is a real constraint. Tax, banking and some healthcare records often must be kept for a set number of years regardless of your request, commonly five to seven years for financial records, depending on the record type and applicable law. Some services also hold an inactive account in a dormant or archived state for a fixed period before permanent deletion, in case of disputes or fraud investigations. And deletion from live systems does not always mean immediate deletion from backups, which are typically purged on their own rolling schedule.
Ask for the specific retention period
Shortcuts
Where to find brand-specific deletion steps
Some of the largest platforms bury deletion behind non-obvious menus, multi-step confirmations or retention quirks. For direct deletion links to hundreds of services, JustDeleteMe is a useful free directory. The general steps above apply to every service either way, and the higher-leverage move is usually knowing which accounts to delete first, which is what mapping your footprint tells you. For a broader clean-up plan, see our digital footprint checklist and best digital footprint management tools (Australia).
Using In The Event Of
How In The Event Of helps
In The Event Of is built around turning scattered account records into a single map. You can connect a supported inbox (Gmail or Outlook) so it can scan for account-related metadata, sender addresses, subject lines and timestamps rather than the body of your emails, or add services manually. It then organises what it finds into a digital footprint, highlights breach exposure, and gives you guided steps for each account, so you can see which forgotten services are worth closing first. You stay in control of every change.
FAQ
Frequently asked questions
Does deleting an account remove it from a breach that already happened?
What is the difference between deactivating and deleting an account?
Can an Australian company legally refuse to delete my account?
Is it safe to use a site like Just Delete Me to find deletion links?
How do I find every account tied to my email before I start deleting?
Should I delete accounts linked to a breach even if I never got a notification?
Sources
Where this information comes from
- OAIC, Chapter 11: APP 11 Security of personal information
- OAIC, Australian Privacy Principles quick reference
- OAIC, About the Notifiable Data Breaches scheme
- Google Account Help, Manage connections between your Google Account and third-party apps & services
- IDCARE, Identity and cyber support fact sheets
- Scamwatch, Report a scam
Related guides
Email in a data breach
Data breaches
Best footprint tools (AU)
Tools & comparisons
Find accounts linked to your email
Digital footprint
Incogni vs DeleteMe (AU)
Tools & comparisons
MyFitnessPal breach timeline
Data breaches
Find accounts linked to your phone
Digital footprint
Have I Been Pwned explained
Data breaches
Remove personal info (AU)
Digital footprint
Digital footprint checklist
Digital footprint
Password manager vs breach monitor
Tools & comparisons
Secure your email after a breach
Account security
What data companies store
Digital footprint
Moving house address checklist
Life admin
Disclaimer: This guide is general information about Australian privacy law, not legal advice. Retention rules and platform deletion steps change, so check the linked official sources for the current position. This guide is general information only and is not legal, financial, or security advice. It is based on publicly available sources at the time of writing and may not reflect the most recent developments. In The Event Of Pty Ltd (ABN 38 687 352 647) is an independent Australian company and is not affiliated with the third-party services named in this guide.