Section: Technology & AI Author: V Reading Length: ~27 min Sources and further reading: 22 items Topics: digital footprint, GDPR, OSINT, cookies, data brokers, public registers, deindexing SEO / Working Title: What is a digital footprint and what does it reveal about a person?
What is a digital footprint and what does it reveal about a person? The question sounds simple until we notice that we are not compiling one resume. A cookie is not consent to everything. Deindexing is not deleting a page. IMEI is not an account and an account is not message content. And the American list of data brokers is not a Czech file. The following text maps the daily footprint under GDPR. It is not court evidence, a forensic chain, or a guide to framing a stranger.
1. Two namesakes, one bar, four different tracks
Let's imagine an ordinary lunch at the office. Someone enters their name into a search engine and finds an old race result, an online profile, a company listing and an article about a person with the same name. A colleague will say that the Internet knows everything. The accountant will argue that it is enough to write a GDPR application and it will be gone. The lawyer will remind the cadastre and ARES. The marketer will add US broker data catalogs and a number that looks like a definitive market map.
At first glance, it's a privacy dispute. In fact, each describes a different layer. A colleague mixes a visible selection of links with a biography. The accountant confuses the right against one administrator for the deletion of the entire website. The lawyer talks about the legal publicity of recorded facts. The marketer transfers the American registration regime to Europe, where there is no such unified public catalog. Therefore, everyone can be partially right and the sentence "the internet knows everything" still wrong.
So the first distinction is not whether the trace exists. It exists. It says which track, with whom, at what time and to what conclusion it may serve. A custom comment trace is not the same as a browser cookie. The entry in the commercial register is not the same as the contents of the box. And the search result by name is not proof that all displayed records belong to the same person.
2. The daily footprint has at least six layers
The single word "trace" covers several things. Some are public, others lie with a specific administrator. We create some on purpose, others arise as a side record of traffic. Some have legal significance, others are just a technical connection point. If we don't distinguish between them, we start to read character from cookies and private life from the cadastre.
Six layers of everyday footprint:
- Conscious Disclosure: profiles, comments, photos, public bios, reviews and posts. CZSO in VŠIT 2025 states that 15.7% of social network users aged 16+ in private households had a fully public profile and posts; it is a self-declaration of network users, not an audit of all their accounts [1].
- Account and Telemetry: history with Google, Apple, Microsoft, social networks or applications. It's a rich picture of behaviour in one administrator. It is not public just because it exists.
- Device and Network Identifiers: IMEI, IMSI, advertising ID, IP address, cookies or fingerprint. The GDPR reminds that online identifiers can, in conjunction with other data, identify a person [3]. But they are not a biography in themselves.
- Commercial Aggregation: data brokers, advertising profiles, people-search services and marketing segments. Their record can be both useful for targeting and dangerous for fraud. She is not a registrar.
- Legal publicity: public registers, document collections, real estate cadastre, official boards. They have the weight of a written fact. They have no weight to anything one does outside of writing.
- Copies, caches and backups: search engine snippets, forwarded emails, downloaded documents, web archives or saved images. The author may not control them.
The forensic chain does not enter here. Device security, image copy, procedural applicability and evidence in proceedings belong to a different series. This is a common trace that one encounters when using accounts, websites and public records. It's not a minor topic. It's a different topic.
That is why the question "where am I everywhere" is misleading. A person is not spread over the Internet in the same way that text is spread over a page. One service has an account, the second an advertising segment, the third a billing contact, the fourth a public record, and the fifth just a technical identifier. You can't start a custom track map by fitting everything into one list. It starts with a layer table: what I've posted, what the account manager has, what the browser holds, what's in the registry, what might be at a broker and what is a copy outside the original context.
A digital footprint is not a biography. It is a set of tracks with different weights.
— Jiný Kontext
3. The best map is the one whose gap you carry
We are not looking for an all-knowing image of man at the trail. We are looking for a map that admits its gaps. A good map will tell what it sees, what it doesn't see, who the record belongs to, who manages it, and why it can't be used to make a stronger conclusion. A bad map lumps everything into one person and adds certainty where there is only similarity.
| A kind of failure | What does he look like? | How to test | What will limit the damage |
|---|---|---|---|
| Swap layers | Cookie or IMEI reads like a CV | Separate identifier, account, content and index | Map of administrators and data types |
| Confusion of rights | Deindexing is pretending to delete the site | Distinguish between source page and search engine | First the resource manager, then the search engine |
| Geography confusion | 750 brokers from the USA will be transferred to the Czech Republic | Name the state, register and period | Do not port US number to EU |
| Publicity confusion | Cadastre or ARES is taken as "everything about a person" | To ask what fact the record records | To hold on to a registered role or property |
| Population swap | A visible profile will pass itself off as a universal status | Indicate the population and the unit of statistics | Read the CZSO as a self-report, not as a forensic file |
This is reasonable, but incomplete if the map ends with a list of finds. Every finding needs weight. A public profile can be genuine and still be old. The register entry can be accurate and still only talk about a function in the company. A cookie can connect visits, but it doesn't tell who sat at a shared computer. Therefore, the track is not evaluated according to the number of items. It is evaluated according to which question it can handle without switching to assumptions.
A good map also has a date. Not because everything disappears quickly, but because different layers age differently. Cookie settings can be changed with one click. A profile on the network can remain visible for years, even if the author has not used it for a long time. A register entry may have a legal history. A broker's segment may be derived from an old purchase. Without the date, the map becomes a mixture of the present and the past that looks like a portrait of today.
4. Track is not a biography. And there is no judgement
A biography has a plot, author, timeline, and responsibility for selection. A digital footprint has records. Some are accurate, some are outdated. Some arose from your will, others from the operation of the service. Some are related to you, another name tag, a business account, a family device, or a shared address. That's not a detail. It is the line between orientation and erroneous conclusion.
A trace is also not a judgment. Court evidence must go through other questions: who obtained it, how it was secured, whether it has been altered, how it relates to the alleged event, and whether it can be used procedurally. An everyday track does not have such a chain. It can be a guide for self-cleaning accounts, for a request to administrators or for better privacy settings. It should not appear as the definitive truth about a person.
This does not mean that the clue is worthless. It follows that he has to stay in his weight. When we find an old photograph, we know that a copy of the image exists somewhere. We don't know if he expresses his approval today. When we find a company record, we know something about a legal role at a particular time. We do not know anything about the state of health, the household or daily movements.
The biggest mistake doesn't come from one bad item. It is formed from correct items connected by a wrong sentence. The name fits, the field fits, the city fits, the photo looks similar. But it does not follow that it is the same person. Shared Wi-Fi, a family tablet, or a business phone can create a technical record that, if read casually, feels more personal than it should. A digital trail therefore needs a denominator: who is the subject, who is the administrator and how do we know the recordit belongs to him.
5. IMEI is not an account. Account is not content
The IMEI identifies the device, more precisely the mobile equipment in the network according to GSMA rules [14]. It's not an account with Google, Apple or a social network. And the account is not automatically the content of messages, photos and documents. In everyday speech, three words merge into the phrase "the mobile knows everything about you". Technically and legally, these are three different tracks.
The device can be corporate, shared or sold. An account can be logged in on multiple devices. Content can be stored with another administrator, in a backup, in an application with end-to-end encryption, or just locally. So, when checking one's own track, one should not ask what "the phone knows". It should ask which identifiers the device has, which accounts are logged in, and where the content resides.
This distinction is practical. Resetting your advertising ID will not change your account history. Logging out of the account will not delete the public comment. Changing the phone does not cancel the profile with the service. One change may be correct, but only for its own layer. Anyone who passes it off as cleaning the entire track is selling peace without support.
The opposite fallacy also applies. When a person finds a long list of app permissions on their phone, it doesn't mean that every app has read every piece of content. Authorization is an option in a certain mode, not an automatic log of everything that happened. Still, it's a good place to clean up. For a custom track, we ask: which app has access to location, photos, contacts, or microphone, and whether it matches the function I'm using it for. The answer doesn't have to be big toshe was helpful.
6. Cookie is not agreeable to everything
A cookie is a small technical record. It can hold login, cart, language, analytics or advertising. The GDPR states in Recital 30 that online identifiers such as IP address, cookies or RFID can, in conjunction with other data, identify a natural person [3]. Directive 2002/58/EC in Article 5(3) makes the storage or access of information in the terminal subject to consent, except for what is necessary for the service requested by the user [4].
In guidelines 2/2023, the EDPB interprets the technical scope of this rule more broadly than just traditional cookies; also aims at similar technologies of access to information in the device [5]. This does not mean that every cookie is the same. This means that a technical detail in a browser can be personal data if it is combined with other data and serves to distinguish a person.
The CZSO in VŠIT 2025 states that 43 % of persons aged 16+ in the Czech Republic indicated that they had changed their cookie settings; for the age group 16 to 34 it was 62 %, for people 75+ 7 % [1]. The number measures self-report of setting change, not the legal quality of consent and not the actual number of trackers. However, it shows that part of the population no longer takes the cookie bar as a mere background of the website.
What needs to be tested
It's easy to start with your own browser. Which sites are exempt? Which extension blocks or allows tracking? Which services hold logins? This is not an audit of someone else's computer. It's a proprietary layer control that has different rules than an account, phone, or public registry.
7. Deindexing is not deletion
The right to be forgotten is often abbreviated to "I've been deleted from Google" in common parlance. But the decision of the Court of Justice of the EU in the case of Google Spain and the subsequent practice aim at search results by name, not at the automatic disappearance of the source page [8]. The later case of Google v. CNIL rejected the obligation of global deindexing as a general rule of EU law [9].
The EDPB distinguishes between the role of the search engine and the role of the source content publisher in the guidelines on the right to be forgotten for search engines [7]. That's the crux of the matter. The link may disappear from European name searches, while the page remains at the original address. Anyone who knows the URL can find it. Another search engine may display it differently. The archive or copy can live on.
A study by the Google team between May 2014 and May 2019 indicates that Google de-indexed 44.5% of requested URLs in Right to Be Forgotten requests [10]. This is a historical window of one service and one type of request. It doesn't measure the erasure of the internet, it doesn't say anything about every request today, and there's no promise of a result at all. It only shows the difference between the request, the search result and the source content.
Deindexing deletes the link by name. Does not delete the page. And article 15 will show one administrator, not the internet.
— Jiný Kontext
8. The public register is not all about the person
The public register is strong precisely because it is narrow. Act No. 304/2013 Coll. edits public registers of legal entities and natural persons and records of recorded facts [15]. Justice and ARES help to verify a business, role, registration or connection to a business [17] [18]. They are not diaries of private life.
Similarly, the real estate register records rights to real estate. § 52 of the Cadastral Act regulates access to the cadastre [16]. The practical weight of the entry refers to the land, building, unit or right. It is not a telephone directory of residents and should not be used to build a "name, address, contact" procedure about a stranger.
For one's own track, public records have a different meaning. A person can check whether his company, role or real estate corresponds to reality, whether there is an old document somewhere and whether the recorded fact is still true. This is the control of one's own legal image. It's not a search for someone else's privacy.
9. The American catalog of brokers is not the Czech OSINT
In an analysis published in 2025, the Privacy Rights Clearinghouse says it found 750 unique groups of data brokers registered in at least one of five US state registries as of early April 2025 [22]. This number is useful if we know what it is measuring. It is the floor of registrations in the USA, not the number of data brokers in the Czech Republic and not the number of profiles about Czech residents.
In the European Union, the data broker is governed by the GDPR as another controller of personal data. That's a strong rule of thumb, but it's not a single, public catalog of all companies that trade in data. Whoever translates the American number into the Czech sentence "there are 750 brokers about you" is producing an accurate number for the wrong population.
In its App Tracking Transparency documentation, Apple lists data sharing with data brokers as one of the tracking purposes for which apps request permission [13]. This is useful for understanding your own device and applications. It is not a list of companies that have a record of you. Again: the track exists, but its weight depends on the layer, administrator and geography.
10. One request of Article 17 does not delete the copies
Article 17 GDPR regulates the right to erasure under specified conditions [3]. It's not a magic button. If the controller has disclosed the data, paragraph 2 talks about reasonable steps to inform other controllers processing that data. It doesn't say that one email will physically destroy all caches, screenshots, downloads and forwarded copies.
The deadline is also specific. Article 12(3) of the GDPR states that the controller shall provide information on the measures taken without undue delay and in any case within one month of receiving the request; depending on the complexity and number of applications, the deadline can be extended by up to another two months [3]. This is a deadline for the administrator to respond, not a promise of complete disappearance of the trace.
CZSO states in VŠIT 2025 that 21.2% of persons aged 16+ in the Czech Republic filed a request to delete data previously provided on the Internet, i.e. 1 838.7 thousand persons; the data has a broad definition and also includes situations such as unsubscribing from the newsletter [1]. The number measures people's behaviour, not the success of the deletion and not the extent of the copies. The precision of statistics must not mask the limitations of what it actually counts.
11. Sixty-three percent of networks are not a complete profile
Social media is the most visible part of a digital footprint, and that's why it's tempting to overdo it. CZSO in VŠIT 2025 reports the use of social networks by 63.2% of persons aged 16+ in private households in the Czech Republic, i.e. by 5 492.6 thousand persons [1]. In 2020 it was 54 % and in 2009 it was 5 % [1]. This measures the prevalence of use, not the complete profile of each person.
The same source states that 15.7% of social network users, i.e. 863.9 thousand people, had a fully public profile and posts; 79.6% at least sometimes set privacy and 4.7 % did not know the setting [1]. It's about self-declaration. We do not know from it whether the service profiles a person for advertising, whether someone downloaded a copy or whether the namesake is mixed up in the search results.
The age group looks even different. For persons 75+, the CZSO reports the use of social networks at 9.4% [1]. So a digital footprint is common, but not universal in the same way for everyone. Anyone who says "everyone has a public profile" is missing the population. Whoever says "elderly people don't have a digital footprint" misses bills, official records, operators, family devices and copies.
12. Article 15 will show the picture with one administrator. Not the whole track
The right of access according to Article 15 of the GDPR gives a person the possibility to ask a specific controller whether and how it processes his personal data [3]. In instructions 01/2022, the EDPB explains how the controller has the right to access [6]. This is a powerful tool. However, it is not a legal "excerpt of the digital footprint of a citizen of the Czech Republic".
When you ask for an operator, you will get an image of the operator. When you ask for a social network, you get an image of the social network. When you download data from your own account via Google Takeout, you get an export with Google [11]. Each statement has its own structure, time range, exceptions and administrator. Only their comparison shows the map. It's not about the internet either.
CZSO in VŠIT 2025 states that refusal of personal data for advertising purposes at least once every three months was reported by 58.2% of persons aged 16+ in the Czech Republic, i.e. 5 060.2 thousand persons [1]. The security validation of the data entry page reported 45.6%, while the chapter text talks a rounded 46 % [1]. 52 % reported changing access to device location [1]. All these numbers speak about the behaviour of people. They don't say exactly what individual administrators think of them.
13. Six months with the operator is a different layer than a cookie
The Act on Electronic Communications in § 97 paragraph 3 works with the retention of operational and location data for a period of 6 months [19]. This is network metadata, not the content of the communication. This is a different layer than a cookie in a browser, an advertising ID on a phone or a profile on a social network.
The Supreme Court, in a press release on decision 30 Cdo 2556/2025 of January 8, 2026, concluded on the illegality of widespread retention of electronic communication data in relation to EU law [20]. This text does not make it an article about data retention or police location. It only uses it as a boundary: the same person can have cookies, a public profile, an account with the platform and network metadata with the operator. Each layer has a different purpose and mode.
A practical error arises when network metadata is added to the general sentence "the phone knows everything". Metadata is not content. Even the content is not always with the operator. And the legal obligation of retention is not the user's consent to advertising tracking. The rules of one layer cannot be derived from another.
14. Conscious disclosure and broker differ in weight, not just visibility
The public profile is striking. A broker's record may be hidden. This leads to the conclusion that the former is less serious and the latter always more accurate. But visibility and weight are not the same thing. A public profile can include a real name and photo, but also irony, old jobs or namesakes. A broker's record may be extensive but duplicative, derivative and misattributed.
Neither layer is a matrix. A profile is a statement in the service environment. A broker's segment is a business hypothesis over resources that must be known. In both cases, it must ask about the origin, update, administrator and repair option. It does not follow that they are the same. It follows that they lie in different ways.
This means double work for your own track. The public layer can often be cleaned up directly: old profiles, post visibility, photos, captions, account links. The hidden commercial layer can only be addressed against a specific administrator, if we know it, or via platform settings, consents, advertising preferences and rights according to the GDPR. The feeling that there is a catalog somewhere is not enough.
15. Copy survives author. Recital 27 is a different file
The digital footprint does not die the moment the author deletes the post. Someone could have cited it, downloaded it, forwarded it, or backed it up. The search engine may have had a snippet. The app may have created a preview. The admin could hold the log. This durability is not always bad will. It is a feature of a distributed environment where data is replicated for speed, backups, integrations, and human convenience.
The GDPR states in Recital 27 that it does not apply to personal data of deceased persons, while Member States may set rules for the processing of such data [3]. That's a boundary, not an invitation to turn. The digital legacy of accounts after death is another text. Suffice it to say here that a copy can survive the author's original intent as well as his control over the account.
Therefore, it is more cautious to talk about a reduction in visibility than an absolute erasure. Changing the settings, asking the administrator, deindexing and deleting the account may be the right steps. They are not the same step and do not have the same result. Cleaning up the trail is a gradual work with layers, not a one-time cleaning of the Internet.
The copy also changes the addressee of the request. An administrator can be requested for the original service. The search result can be solved with the search engine. A post that has been taken over by someone else is already a new admin or a new context. This is inconvenient but accurate. One request to the wrong place can rightfully be handled without result, because the addressee does not control the layer that bothers the person. That's why a "who can change it" column is written on the map before each step.
16. A map of your own footprint will say more than the sentence that the Internet knows everything
The practical test is supposed to be the defense of the reader. Not a search for a stranger. The goal is to find out which layers of the custom footprint exist, where they are managed, and what flows from them. As soon as the test turns into composing someone else's address, phone or privacy, it has ceased to be hygiene and has become a risk.
Three tests of own tracks
The first test is the conscious layer. In the private window, look for your name and your e-mail, that is, the data you enter yourself. Sort results by "me", "nameholder", "index", "news" and "foreign content". It's not a file. It's a list of visible hits and misses.
The second test is account and browser. Download data from your own account using Google Takeout or a similar export for the service you use [11]. In addition, check the cookies, website permissions and advertising settings in your own browser. Compare what is public and what can only be seen by the account administrator.
The third test is device and content. Find advertising ID, app permissions and logged in accounts on your phone. Separate device identifier, account and communication content. Resetting the identifier is not deleting messages. Logging out of the account is not deletion of the public page. Each step belongs to its own layer.
The result of the test should not be a feeling of guilt. It's supposed to be a work list. Four columns are enough for each item: layer, manager, visibility and possible step. The public profile has a different step than the old index document. A browser cookie has a different step than account history. Someone else's copy has a different step than the post you still hold in your own account. Such a table is less impressive than the sentence "the Internet knows everything". However, it is usable.
What needs to be tested for Article 15
Choose two administrators that you know: for example, your own operator and one platform. Request access pursuant to Article 15 GDPR and observe the one-month deadline with a possible extension pursuant to Article 12(3) [3]. Read the answer as a single admin image, not a complete track.
Before requesting deletion and deindexing
First find the source. If there is a problem with the page, write to the page administrator. As for the search result by name, solve the search engine; Google offers tools for this, including the Results about you service [12]. The historical 44.5% deindexed URLs at Google between 2014 and 2019 is not a promise. It is a reminder that the outcome of the request depends on the right, the content and the administrator [10].
The same rule applies to public records. In the case of one's own company or one's own real estate, it is first verified whether the recorded fact is correct and up-to-date. If so, it's not a bug just because it's public. If not, the correction is handled according to the registration rules. This test is not done on a stranger. This article is not a manual for compiling someone's address from official traces.
17. The question is not what the internet knows about you. It says which layer carries which conclusion
A digital footprint is not one vault, one profile or one judgement. It is a set of records that are created by different managers and serve different purposes. Some are public. Some are only visible after logging in. Some are technical. Some have legal effect. Some are copies that are no longer controlled by the author.
The hidden cost is not just the loss of privacy. It is a biography made up of disparate traces. When the cookie is read as character, the register as privacy, and the American list of brokers as Czech reality, an image emerges that seems accurate because it has many items. However, item accuracy is not inference accuracy.
The same caution applies within a family or company. One laptop is used by several people. One phone can be a business phone. One address can serve an entire household. A single role in the registry can survive the actual work in the project. The digital footprint is therefore not just a matter of privacy. It's a matter of attribution. If you don't know who the record belongs to and why it was created, you shouldn't use it as a strong sentence.
Therefore, the right question is not: "What does the Internet know about me?" The right question is, "Which layer of the trail bears which conclusion, who maintains it, and how can I verify or fix it myself?" At that moment, vague panic becomes a map. She is not perfect. But it is accurate enough so that one does not chase the entire Internet and start piecing together a strange life from other people's clues.
Such a map also has a second value. It teaches to inhibit one's own interpretation. Once a person distinguishes between an account, a cookie, a register, and a copy, it becomes easier to apply the same distinction to a public debate, a newspaper text, or a corporate decision. The digital footprint then does not act as a fog in which it is possible to claim anything. It becomes a limited recordset. Some require repair. Some just require lower visibility. And some mainly require the sentence: it does not follow from thiswhat it wants to tell us.
Related texts in this series
- On the web, series A digital footprint is not a judgment — court evidence. This text is a daily GDPR/OSINT map.
- What can Google find out about you from a single name?
- What does your mobile phone know about you?
