The Ultimate Facebook Privacy and Security Checklist

Prepare for hacks and data breaches. Here are all the steps you need to follow to lock your Facebook profile and control your privacy.

When social media started gaining traction in the early 2000s, privacy was less of a concern due to the limitations of social media platforms, and perhaps because fewer people had access to the internet. Nowadays, thanks to security breaches and data leaks, we are all very aware that our digital privacy is volatile.

With the vast amount of information available on your Facebook profile, it’s important to protect your privacy from identity theft, hackers, and people who might want to access your account. By limiting the personal data accessible to others, you can protect yourself and those around you.

To help you, we’ve put together a checklist of steps you can take to lock down your Facebook profile. We’ve separated them by the different sections found in Facebook’s settings page.

FREE DOWNLOAD: This cheat sheet is available as a downloadable PDF from our distribution partner, TradePub. You will need to fill out a short form to access it for the first time only. Download the ultimate Facebook privacy and security checklist cheat sheet.

  • Under the Security and Login tab, check the box Where you are logged in section to identify the devices you have connected to Facebook. If you see a browser or device you don’t recognize, select it. three points next and choose Sign out. If you notice anything suspicious, select Not you?.
  • If you think someone might have access to your Facebook, go to Login section of Security and connectionthen select Change password. You need to create a hard-to-guess passphrase that is different from the ones you had before (include upper and lowercase letters, numbers, and special characters).
  • Don’t want to save your login information? If someone else has access to your computer or devices, you can choose not to save your login information by changing the Save your login information option. Here you can delete an account or delete information saved on other devices.
  • To further strengthen your security, you can add two-factor authentication to your Facebook account. You can use an authenticator app, receive an SMS message or a security key when you log in from an unrecognized browser or device.
  • Be informed of any unrecognized Facebook connection attempt by the option of Receive alerts on unrecognized connections under the Implementing additional security section.

USE VIDEO OF THE DAY

  • You must ensure that the visibility of your current and future publications corresponds to your expectations. You can do this by visiting the Privacy tab and navigating to Your activity. Future posts can be set to public, friends, friends except, only me, or specific friends.
  • The activity section also lets you review any posts or pictures you’ve been tagged in. You can accept or reject tags by displaying the Activity Log.
  • If you’d rather people not see any of your old posts on Facebook, you can choose to limit the audience of old posts on your timeline. This means that any previous public posts or those you’ve shared with friends of friends will be restricted to your friends only.
  • Privacy doesn’t just stop with your own information. You can limit the audience that sees the people, pages, and lists you follow. The same options apply here as for future releases.
  • Locking your Facebook security can prevent people from finding you, but you can adjust the settings in the How people can find and contact you section. Here you can allow everyone to send you friend requests, or only friends of friends.
  • If people can’t find you through Facebook search using your name, they might be able to find you using the email address or phone number you provided when you signed up. You can remove this option by selecting Just meor limit it to friends or friends of friends.
  • To ensure that your Facebook profile cannot be found via search engines, select Nope under the Would you like search engines outside of Facebook to link to your profile section.
  • Don’t want to be harassed by strangers via Facebook Messenger? You can decide whether chats are received or filtered on message requests by adjusting your Potential Connections and The other people in the How do you receive message requests settings.


  • While you can view your tagged posts and photos elsewhere, you can adjust the global settings for them under the Profile & Tagging tab. Here you can decide who can post on your profile.
  • Once someone posts something, posts to your profile by other people (friends, friends of friends, friends except, specific friends, and everyone) may be viewable. Be sure to set the audience to decide who can see other people’s posts on your profile.
  • If you want to further customize your profile settings, you can hide comments containing certain words from your profile by adding words, phrases or emojis. This means that comments containing these words will only remain visible to those who wrote them and their friends.
  • Allowing friends to tag you in photos or messages can be managed in the markup section. Here you can limit who sees posts you’re tagged in, as well as the post’s audience.
  • Not sure if you’re happy with what you’ve been tagged in? You can see the posts you’re tagged in or the tags people add to your posts under the tab Revision section.


  • The Public Posts tab in Facebook settings lets you decide who can follow you (including your posts, stories, and reels). This information may be shared publicly or only with your friends.
  • Once you’ve published a post, you can adjust the audience who can comment on your posts. However, it should be noted that if you limit this to friends, their friends may still be able to comment.
  • Some information on Facebook is always public, such as your cover photos, profile photos, and featured photos. You can manage who can like or comment on them, including the public, friends of friends, or friends only.
  • If you’ve commented or been tagged in a public group post that’s then shared outside of Facebook, you can turn off previews so that your username and profile picture don’t show. This can be done by the Off-Facebook previews option.


  • Adding people to your restricted list on Facebook via the Blocking tab means that they will remain your friends on Facebook, but will not be able to see only the posts you share with your friends.
  • If you want to block a Facebook user from seeing your timeline, tagging you, adding you as a friend, or even having a conversation with you, you can add them to your blocked list.
  • To block someone from your Facebook and Facebook Messenger, you can add them to your Block messages listing. You will also need to make sure to block their profile on Facebook.
  • Harmful applications for which you do not want to receive notifications? By using the Block app invites and Block apps options, you can stop certain people from being invited to apps or stop notifications from specific apps altogether.

6. Quick Tips

  • To make sure your privacy settings are up to date, you need to run Facebook’s privacy control under Settings and Privacy. This is a quick overview of your existing settings for who can see what you share, how people find you, and more.
  • Below general settings, you must ensure that your name and contact details are correct. If you lose access to your account and need to prove your identity, you will need to be able to confirm your details.
  • Don’t want Facebook to know where you are? Check the Location and disable location history for your mobile devices.


Be Aware of Facebook Privacy

By cleaning up old messages, being careful who sees your photos, and limiting access to your personal data, you can create a secure online presence on Facebook and other social media. It’s worth revisiting these settings periodically to make sure everything is as locked down as you want it to be.

About Marion Browning

Check Also

How LogonBox Authenticator Makes Windows Login More Secure

Introduction As organizations strive to improve security, they often overlook their most critical network asset: …