What this protects, and what it doesn't
Protects
- Against a live doxxing or coordinated exposure, by attacking it on several fronts at once instead of one slow request at a time.
- Against search engines keeping your name tied to the exposed pages: the removal forms can delist them for name searches even while the pages stay up.
- Against EU-based sites and data brokers that re-publish the data: erasure and an objection can force them to take it down or stop processing it.
Does not protect
- This is general information, not legal advice. If you are in danger, treat it as an emergency and contact your local police or emergency services first.
- Erasure and de-indexing do not delete copies other people already hold: screenshots, re-uploads, archives, scraped databases and messages already sent are out of reach.
- They do not touch sites outside the EU that ignore the GDPR, or anonymous hosts in uncooperative jurisdictions. Search-engine removal only hides a page from results; the page itself stays online at its source.
- There is no guaranteed timeline. The GDPR gives controllers up to one month (extendable), search engines and platforms set their own pace, and a supervisory authority can take far longer. Marking a request urgent does not create a binding deadline.
- It does not make you anonymous or undo the exposure. Treat it as damage control, run in parallel with changing exposed logins, phone numbers and routines.
Prerequisites
- A threat model and some help: at Level 3 you should not do this alone. Line up an ally, your employer or security team, and, where you can, a lawyer or a digital-rights or victim-support organisation.
- A secure device and a dedicated email address for the requests, so replies do not get lost and you do not hand hostile sites a personal address.
- A tracking list: each site or platform, the URL, what was exposed, the channel used, the date sent, and every reply.
- Only the identity details each recipient actually needs to find your record; never send a full ID scan to a site that only needs a name and a URL.
Step by step
-
First hour: preserve evidence and secure what is exposed
Before anything is taken down, capture the evidence. Screenshot each page with its full URL and the date and time visible, and save the links. You will need this for every removal request and for any complaint or police report, and takedowns destroy it.
Then act on what the exposure enables. If your home address is public, think about physical safety. If a phone number or email is out, expect phishing, SIM-swap attempts and account-takeover tries: change passwords on the exposed accounts, turn on phishing-resistant two-factor authentication, and warn anyone named alongside you (an exposed colleague Alice Example at Example Corp may be targeted too).
If anyone is threatened or in danger, contact your local police or emergency services. A police reference number also helps later removal and escalation requests.
-
Report to the platform or host where the data sits (usually fastest)
The quickest takedown is almost always from the platform, forum or host that is showing the data, not from a court or a regulator. Most large platforms have a dedicated reporting path for the sharing of private information, threats and harassment, which is faster than their general support.
- Find the site's own abuse, safety or "report" channel and report each post for exposing private information and, where it applies, for threats or harassment. Quote the specific data exposed and your evidence.
- If the site will not act, report the host instead. Finding the host, and sending it a notice, is covered in a dedicated guide you can follow in parallel.
- Keep the ticket or case numbers on your tracking list; you will need them if you escalate.
Treat this as the front line: it can remove the source in hours, which de-indexing and erasure cannot.
-
Ask search engines to remove the pages from results
While the pages are still up, cut the link between your name and the search results. This does not delete the page; it stops it surfacing when someone searches for you. Use two kinds of form on each major engine.
- Google, personal information / doxxing removal. Google's own policy lets you ask to remove results that expose contact details or that dox you with an intent to harm. Start from Google's Report a problem / remove personal information process.
- Google, European privacy request. Separately, under European data protection law you can ask Google to delist results for searches of your name. See Google's Right to be Forgotten overview and its linked web form.
- Bing / Microsoft. Report the results through Microsoft's privacy FAQ, which links to the Bing "Report a concern" web form, and, if you live in the EU, file the separate European right-to-be-forgotten request. Microsoft notes these go to different teams, so send both if both apply.
Removal applies to name searches and, for the European forms, to the relevant country versions of the engine. The page stays online elsewhere, so this runs alongside the takedown and erasure steps, not instead of them.
-
EU/EEA: send erasure and objection requests, marked urgent
For any EU/EEA site, forum operator or data broker that holds or re-publishes the data, send a right to erasure request and, where relevant, an objection. You can send them together.
- Erasure (Art. 17). Ask the controller to delete your personal data. Doxxing content will usually have no lawful basis and the data is no longer needed, which are grounds under Art. 17(1); where it was processed on a legitimate-interest basis, a successful objection is itself a ground (Art. 17(1)(c)). Use the GDPR request generator with the right to erasure.
- Objection (Art. 21). Where processing rests on legitimate interests or a public-interest task, you can object on grounds relating to your particular situation; the controller must then stop unless it shows compelling legitimate grounds that override your interests. Use the generator with the right to object.
Say in the request that it is urgent and why (safety, ongoing harm), and ask for confirmation once done. Be realistic: the controller still has up to one month to respond, extendable by two months for complex requests, and erasure has exceptions, for example data a controller must keep by law or that is covered by freedom of expression (Art. 17(3)). Urgency does not shorten the legal deadline; it is the platform and search-engine routes that move in hours.
-
Shut down the data brokers that amplify the exposure
Doxxers routinely pull home addresses, phone numbers and relatives from people-search sites and data brokers. If your details are circulating, assume several brokers carry them and that leaving them live lets the dox be rebuilt.
- Search for your name, address and number, and note every broker and people-search site with a profile.
- Send each one an erasure request (and an objection to any marketing use), the same way as above.
- Use the opt-out pages on people-search sites as well, since many act on those faster than on a formal letter.
The routine, non-emergency version of this, including how to find brokers and track replies, is in the Level 1 guide Remove yourself from data brokers. Here you are doing it at speed and in parallel with everything else.
-
Escalate to a supervisory authority
If an EU/EEA controller ignores you, refuses without a valid reason, or misses the deadline, lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work or where the infringement happened (Art. 77).
- Find your national authority on the EDPB list of members.
- Attach your evidence, the requests you sent and their dates, and any replies, and flag the safety risk so it is handled as a priority.
Be realistic about speed. A complaint is not a fast takedown. The GDPR does contain an urgency procedure (Art. 66): in exceptional circumstances a supervisory authority can adopt provisional measures on its own territory for up to three months, and can ask the European Data Protection Board for an urgent opinion or binding decision, to be adopted within two weeks. That mechanism is for authorities to use between themselves, not a button you press, but it is the legal basis an authority can act on quickly, so name the urgency when you complain.
-
Monitor for re-uploads and keep records
Exposed data comes back: it is re-uploaded, mirrored or re-scraped. Set up name and number alerts, re-run the searches from the de-indexing and broker steps every few weeks, and re-file removals when copies reappear.
Keep your evidence and your tracking list intact even after the pages are gone, in case of a later complaint, police report or legal claim. And look after yourself: doxxing is designed to frighten, so lean on your allies and on victim-support services rather than handling it alone.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Deleting or reporting the content before screenshotting it with its URL and timestamp, which destroys the evidence you need for complaints and police reports.
- Relying only on a GDPR erasure letter and waiting a month, while the platform abuse channel could have removed the source in hours.
- Confusing de-indexing with deletion: a search-engine removal hides a page from name searches but leaves it online, so the source still has to be taken down.
- Sending one request and stopping. A dox is multi-front; the host, the search engines, the brokers and the regulator are separate routes that run at the same time.
- Over-sharing identity documents with hostile or unknown sites instead of the minimum each recipient needs to find your record.
- Trying to handle a Level 3, safety-critical situation entirely alone instead of involving police, an employer, a lawyer or a support organisation.
Going further
Close the holes the dox used. A phone number found through a broker is the start of many SIM-swap attacks, so read Defend against SIM swaps and number theft. Then revisit your threat model: a public exposure changes who your adversaries are and what they can reach, so your plan should change with it. If the exposure is tied to your work or a public role, your employer or a press-freedom or digital-rights organisation may have faster takedown contacts than you do alone.