The Privacy Dashboard That Made You Feel Safe While Your Home Address Stayed Online

Practical Advice

The Privacy Dashboard That Made You Feel Safe While Your Home Address Stayed Online

I want to talk about something the privacy removal industry does not mention in its marketing: the gap between what a service measures and what actually constitutes your risk.

This is not primarily a criticism of the services. It is a description of what dashboards do. They measure what they can reach. They show you what they addressed. They do not show you what they were never designed to address.

For UK SMB directors, that unmeasured territory may be where most of your actual risk lives.

What a Dashboard Actually Measures

A typical data removal service dashboard shows:

  • Number of brokers scanned
  • Number of profiles found
  • Number of removals submitted or confirmed
  • A summary score or percentage indicating overall privacy health
  • Trend lines showing improvement over time

All of that data is about broker and people-search site exposure. It is the data the service has access to and can take action on.

It does not show your Companies House address exposure. It does not show your open electoral register status. It does not show what your LinkedIn profile reveals about your organisational structure. It does not show what your job adverts say about your technology stack. It does not show whether your email fails DMARC checks. It does not show whether an old VPN portal from 2019 is still accessible from the internet.

A score of 85 out of 100 on a broker removal dashboard is a score on that specific domain. It says nothing about the broader landscape. And for a UK director, the broader landscape is where the attacker’s most valuable information often comes from.

The Upstream Blind Spot

The most fundamental limitation of any removal service is that it cannot address upstream public sources.

If your home address appears in a Companies House filing, that is a public register entry. A data broker may have copied it. The removal service can ask the broker to delete the copy. The Companies House source continues to exist until you take action through official channels.

If your name appears on the open electoral register because you never opted out, that register is commercially licensed. A data broker may have used it. The removal service can ask the broker to delete their derived product. The electoral register entry continues to exist until you opt out with your local council.

The broker copy is downstream of the original source. Removing the copy while the source continues is a temporary state. The broker’s next database refresh cycle may republish you from the same source you never fixed.

A removal service that does not explain this distinction clearly is not providing the information you need to make a good decision about risk.

How to Run the Gap Test

After subscribing to any removal service, or before subscribing to evaluate whether it will help:

Run the two-hour search described in Week 1’s Thursday guide. Search your name and address as an attacker would. Document every result in the first three pages.

For each result, identify which category it belongs to: Companies House or official record, electoral register or derived product, LinkedIn or social platform, job board or careers site, press archive or news coverage, domain or technical record, broker or people-search site.

Now check whether the service’s documented automated coverage includes the specific sources in your top results. Not in general. Specifically.

If your top three results are a Companies House address listing, an electoral register derived people-search entry, and a LinkedIn profile, a broker removal service addresses none of them directly.

If your top results are two or three specific people-search sites that are in the service’s documented broker list, a subscription may provide practical value.

The gap test tells you whether the service solves your specific problem before you pay.

The Correct Priority Order

For UK directors, the correct priority order for exposure reduction is not to start with a subscription service. It is:

First, fix Companies House records. Address suppression if applicable. Update service addresses.

Second, opt out of the open electoral register.

Third, clean LinkedIn and job adverts of unnecessary organisational and technical detail.

Fourth, check domain records, DMARC configuration, and old technical portals.

Fifth, submit priority erasure requests to the broker and people-search sites that appear in your own search results.

Only after those five steps should you evaluate whether a subscription service adds coverage you have not already addressed yourself. The service fills in what you have not covered. It is not a substitute for the steps that precede it.

The Identity Documentation Risk

One more gap that dashboards do not show.

Exercising data removal rights, whether personally or through a service, often requires identity verification. A service that submits removal requests on your behalf may do so by providing your personal details to the brokers it contacts.

That is a reasonable operational approach. The broker needs to identify whose data to remove. But it means you are providing your name, address, email, date of birth, and potentially other identifiers to the service, which then transmits them to a list of data brokers.

Most services will state that they do not sell or misuse this data. The better ones, like Incogni as verified by Deloitte, have third-party confirmation of their data handling practices. But the flow of data from you to the service to the brokers is a real data sharing event that you should understand before you agree to it.

How to Turn This Into a Competitive Advantage

For MSPs and advisers, the false confidence risk is a client education opportunity. Most clients who have subscribed to a removal service have not run the gap test. Walking them through it and showing them what remains unaddressed is a concrete, demonstrable value add.

For business owners, a documented gap test, showing what exposures you assessed, what was in scope for a service and what was not, and what direct action you took for out-of-scope sources, is a governance record that demonstrates active management rather than purchased assumption.

How to Sell This to Your Board

The false confidence argument lands clearly at board level because it translates to risk management language boards understand.

A control that covers part of a risk and implies it covers all of it is a control with an undisclosed residual risk. The board should understand precisely what any data removal service covers and what it does not. That boundary should be in your risk register, with the uncovered areas assigned to alternative controls.

A subscription service with clearly documented scope plus direct action on the out-of-scope areas is a coherent control. A subscription service as a substitute for thinking about the full scope is a liability dressed as assurance.

What to Do This Week

  1. Run the gap test on your current exposure or any service you are considering.
  2. Document which results fall into which categories and whether the service addresses them.
  3. Fix every upstream source before evaluating whether a subscription adds coverage.
  4. If you already subscribe to a removal service, run a fresh search to confirm which exposures remain and whether they are in scope.
  5. Add the documented scope of any removal service to your risk register alongside the residual exposures and the alternative controls for those.
SourceArticle
Companies HouseRemove your home address from the Companies House register
ICOElectoral register opt-out
ICOYour right to get your data deleted
NCSCEmail security and anti-spoofing
NordVPNIncogni vs DeleteMe comparison
GOV.UKCyber Security Breaches Survey 2025/2026

Filed under

  • smb-security
  • uk-business
  • data-protection
  • vendor-risk
  • business-risk
  • compliance-failure
  • executive-security