
Your business data doubles as a map to your front door. I didn't think about this until a routine background check on a prospective client turned into me staring at my own home address on a data broker site, right next to my wife's maiden name and a list of relatives going back two generations. As a self-employed consultant, digital privacy wasn't something I'd budgeted time for. The tools running my day-to-day business turned out to be doing the opposite of protecting me.
Quick disclosure before we go further, because I'd want to know this before reading anyone's product opinions: this piece includes affiliate links, and if you sign up through one, I earn a commission at no extra cost to you. I only write about tools I've actually paid for and used myself — starting with the Proton bundle I moved my entire business onto after that search result knocked the wind out of me.
Why My Business Email Became a Data Security Problem
Freelancing erases the line between business and personal fast. My business email tied back to my domain, the domain tied back to my registration, and the registration tied back to my home address — a paper trail that never existed when I had an employer's IT department standing between me and the open internet. It's the same mechanism as junk mail, just scaled up: once one list has your address, it sells to the next list, and the next, until deleting the original source barely matters anymore.
My first fix was embarrassingly low-effort. I set up Google Alerts on my own name, figuring I'd get pinged the moment a broker re-listed me and could act fast. Months went by and the alerts turned up nothing useful — broker databases don't publish to news feeds or crawlers, so I was watching the wrong door entirely while my actual listings sat untouched. That's when I stopped trying to catch problems after the fact and looked instead at what was generating them: one stock email account doing double duty as both my client-facing tool and my personal identity, resting on one basic layer of data security most people never think to question.
Migrating My Domain to Encrypted Email Without Losing Clients
Once I decided to consolidate, I moved my whole professional stack onto the Proton bundle — mail, VPN, drive, and calendar under one login instead of four separate accounts with four separate leaks. Nobody advertises how unglamorous the actual migration is. Pointing a business domain at an encrypted email provider means editing MX records in your DNS settings yourself, which is less like flipping a switch and more like rerouting the post office one form at a time.
DNS propagation isn't instant, and depending on your TTL settings there's a window — could be an hour, could be closer to a full day — where mail can bounce or land somewhere you're not watching. I scheduled my cutover for a quiet Friday afternoon specifically so a stray client message wouldn't vanish into that gap during a busy Tuesday instead. It still felt uncomfortably exposed watching the inbox go silent while the new records took hold. Once they did, the quiet stuck around for a different reason: no more "helpful" scanning of my invoices to suggest accounting software I already use.
What Makes Swiss Jurisdiction Genuinely Different
People roll their eyes at "Swiss-based" the same way they roll their eyes at anything that sounds like a marketing badge. For a consultant handling client NDAs, though, it's less about the badge and more about who can legally ask for what. Switzerland sits outside the intelligence-sharing arrangements that make it easy for US authorities to compel a US-based provider to hand over data. Proton's zero-access encryption pushes that further — the company itself can't read the contents of my inbox, so there's nothing to hand over even if someone came asking. It turns what would otherwise be a promise buried in a privacy policy into something closer to a structural fact.
The HIPAA Gap Standard Plans Don't Cover
Where this gets complicated is for consultants working anywhere near medical or legal clients. Standard Proton plans, solid as they are, don't include what HIPAA-adjacent work actually requires — a business associate agreement and the kind of administrative audit trail that only shows up on the higher business tiers. I found that out by reading the fine print rather than the marketing page, which is generally where the real limitations of any privacy tool tend to live.
There's also a strange social side to this nobody warns you about. Explaining end-to-end encryption to a client who just wants their PDF signed makes me feel like the office's designated tinfoil-hat guy some days. They don't want to hear about keys or ciphers — they want confirmation their file is safe, and a tool that handles the encryption quietly in the background lets me look competent instead of paranoid. If you're dealing with older accounts and legacy listings instead of new leaks, Why Personal Data Keeps Reappearing on Broker Sites After a Removal covers why a broker you thought was handled shows back up on its own schedule — a pattern that has nothing to do with your email provider and everything to do with how those sites resell data to each other.
Running Yubikeys, RoboForm, and a Removal Service in the Same Week
My desk — a corner of a converted spare bedroom in the 1990s brick ranch we live in, here in South Austin — has a whiteboard on the door where I track which brokers are clear, pending, or re-listed, color-coded in dots because a spreadsheet never held my attention the same way. A printed timeline of past reappearances is taped up beside it, and a Yubikey hangs off a lanyard clipped to my monitor bezel so I stop losing it in laptop-bag chaos. Gemma Tull, who shares a desk block with me at a coworking space nearby, is the one who'll tell you exactly how many clicks a given opt-out form takes — fourteen, she says, for one broker's account-deletion flow, counted the week she found her new neighborhood listed under her own name before she'd told half her friends she'd moved.
The manual route Gemma and I both started on works — I ran my first opt-out batch past midnight once, nothing but the router lights across the room blinking back at me for company — but it stops scaling past a broker or two before the hours pile up, which is really the whole case for paying someone else to file requests on repeat instead of doing it site by site yourself. Logins are a separate problem, and I still lean on RoboForm, mostly on their family plan because it covers up to five accounts at a better per-person cost than the alternatives I compared. Pairing a password manager with a hardware key like the Yubikey only works if the second factor lives somewhere a phished login page can't reach, which a physical key does and a text-message code doesn't. RoboForm's form-fill engine is also, oddly, one of the few that survives contact with government tax portals, which is most of why it made my list of best password managers for small business owners.
Proton handles new mail. It does nothing about the accounts and profiles that existed before I ever signed up, which is a separate job I hand to DeleteMe and, more recently, Incogni. DeleteMe's family coverage runs up to four people and reaches into the harder sites — Radaris was the one that kept re-listing my old apartment address every few months no matter how many times it came down, and their quarterly report is the first place I actually saw that pattern laid out instead of just suspecting it. Incogni covers a narrower list of brokers but files its requests under CCPA and GDPR language that carries real legal weight, and its dashboard is where I keep score — neither service chases the exact same slice of what is honestly a much longer roster of people-search sites than most people assume exists. Somewhere around week seven of tracking that dashboard, completed removals finally outnumbered the pending ones. Small milestone, but the first six weeks had made it look like the list only grew in one direction.
None of this touches what happens to the laptop itself once I'm done with it — wiping a drive before reselling old hardware is its own problem, and a different category of tool entirely from anything that talks to data brokers. A VPN, running quietly while I work from that same coffee shop, doesn't do a thing about listings that were already public before I opened the app either; it protects the connection in front of me, not the paper trail behind me. And if a client of mine ever got caught in a breach on someone else's system, the response isn't emailing them from Proton — it's rotating passwords and re-checking recovery methods everywhere that login got reused, a conversation that comes up more often than I'd like.
One Lesson From Two Years of Patching My Own Leaks
Two years into treating my own privacy like an actual maintenance job instead of a one-time cleanup, the biggest shift isn't any single tool — it's realizing none of them are supposed to work alone. Proton keeps new information from leaking into the system in the first place. DeleteMe and Incogni clean up what already escaped before I started paying attention. RoboForm and the Yubikey make sure the accounts holding all of this can't be walked into with a guessed password. Cut any one of those out and the other two just cover a smaller gap instead of closing it. If you're self-employed and only doing one of these things, that's the actual lesson: pick the piece that matches the leak you actually have, not the one with the best homepage.