Exposing identifying information, usually without consent and with harmful or intimidating context.
Doxxing
Finding, combining or publishing personal or identifying information about someone without permission, commonly to expose, intimidate, silence or enable harassment.
UK law & digital life
In brief
Public fragments can become dangerous when aggregated and directed at a target.
Doxxing may combine details that were individually public—such as a username, workplace, photograph, event attendance or property record—to reveal a private identity, address or routine. The label is descriptive rather than a single UK offence; harassment, stalking, threats, communications, data-protection or other law may apply to the actual conduct.
Information and traces available about a person across accounts, services and public records.
Using another person's identity or details for deception, accounts, goods or services.
Patterns of unwanted conduct that may include publication, monitoring, contact or recruited harassment.
Aggregation and kink-specific exposure
A scene name, distinctive image, retailer review and public social profile may be linked through reused usernames, backgrounds or metadata. Disclosure can expose sexual orientation, kink interests, employment or home life even without publishing an address.
Outing or threatening to out someone can cause discrimination and physical risk. Community disagreement does not justify publishing identifying information.
Risk reduction
Use separate identifiers and contact details where appropriate, review image backgrounds and metadata, restrict location sharing and audit what a search reveals. Privacy settings reduce casual access but cannot remove copied or archived information.
Two-step verification and unique passwords protect accounts, while trusted contacts and an incident plan can help if disclosure occurs. Avoid implying that a victim caused abuse by leaving traces online.
Legal distinctions
There is no universal rule that every publication of personal information is criminal. Context, intent, repetition, threats, reasonable conduct, data-controller status and UK jurisdiction affect possible offences or civil remedies.
An organisation posting personal data may have UK GDPR duties even where a person acting purely personally falls outside parts of data-protection law. Harassment or communications law can still apply.
Responding to exposure
Preserve URLs, timestamps, account names and threats without amplifying the personal data. Report the content to platforms, alert people who need to manage physical or workplace safety, and consider police or specialist advice.
If immediate danger is credible, call emergency services. Changing passwords, securing recovery accounts and asking search engines or data brokers for removal may limit further spread but cannot guarantee erasure.
Non-graphic examples
What the umbrella may include
- Linking a scene name to a workplace through reused usernames.
- Publishing a home address to encourage confrontation.
- Auditing photo backgrounds before posting.
- Saving a URL without reposting exposed details.
- Telling a venue discreetly about a credible safety threat.
Reviewed 30 August 2026
Keep exploring.
This detailed field note uses the best available evidence without treating one community sample as universal. Evidence limits and UK context are stated where relevant.
Prepared by The UK Kink Guide editorial team. Read the evidence and review methodology.
Found an error or important omission? See how to report a correction.
Explore all 268 entries