| [ Web Proxy ] |
| Viewing: https://joindeleteme.com/blog/what-are-data-brokers/ | [Back] [Original] |
Reading time: 19 minutes
Every week, your voicemail box fills up with spam. So does your email inbox. You receive strangely personalized scam and phishing texts. The website youre on knows a little too much about you.
One of the biggest reasons for all of that is data brokers.
According to estimates from a few years ago, there are at least 4,000 data brokers in operation today. Some well-known data brokers include Equifax, LexisNexis, and Oracle. As of 2026, there have been no official updates to that number, but privacy experts agree the industry has grown significantly.
The sheer volume of data these companies hold is unimaginable. An average data broker possesses over 1,000 points about a single individual according to CNBC, everything from their name and home address to family member information and net worth. Acxiom, a top data broker, recently revealed its Consumer List of more than 260 million individuals and 190 million households.
In most cases, anyone with a credit card can gain access to that data.
The good news is that many data brokers let you opt out of being included in their databases.
We discuss the exact processes for doing that below.
But first, what exactly are data brokers, where do they get your data, and what do they know about you? Perhaps most importantly, are they even legal? Read on to find out.
Data brokers (sometimes also called information brokers or people search sites) are companies that aggregate personally identifiable information from various sources to create individual profiles or listings.
They then sell these profiles to third parties, including advertisers, marketers, insurance companies, data mining corporations, financial institutions, government agencies, political consultants, and many other entities.
Some data brokers screen and monitor the individuals or organizations buying data from them.
For example, they may request to meet or speak with clients or ask them to fill out a credentialing questionnaire. However, few data brokers monitor the purchase or use of their products at all.
Depending on the type of data they collect and sell, data brokers typically fall within one of three categories:
Lets take a quick look at each one in turn. .
Find out which data brokers have your info
People search sites make it possible for anyone to find any other persons information online with just their name, or another identifier like a phone number or email.
Sometimes, you might be able to access that information for free. Other times, you may need to pay a small fee.
People search sites dont usually screen or monitor their clients. This means people can use them for more nefarious purposes, like finding information about someone to steal their identity, or for the purposes of stalking or doxxing.
Examples of a few of the most well-known people search sites include InfoTracer, Whitepages, and Spokeo.
B2B data brokers develop detailed consumer, employee, and/or business profiles to sell to other companies, usually either for marketing purposes or for background checks.
Thanks to these data brokers, cybercriminals can also get a detailed look at potential targets for the purposes of personalizing phishing campaigns and other attacks.
One of the most well-known examples of this type of data broker is National Public Data.
Big data brokers mostly consist of credit reporting and fraud prevention agencies. Examples include Equifax, Experian, and TransUnion.
These types of brokers are pretty much essential to how the modern financial world operates. For example, a lender might use a risk mitigation data broker to ensure that a person looking to open an account with them is indeed who they say they are.
Data brokers are not all bad. In fact, consumers can benefit from some of the purposes that big data brokers in particular collect their information for, like preventing fraud.
At the same time, data brokers, especially people search sites, increase certain risks for consumers. They also violate peoples privacy and make little to no effort to see that the information they sell doesnt end up in the wrong hands.
Due to a lack of regulation, theres no way to know where our personal data ends up or who uses it. This can lead to direct harm for individuals whose data is available through data brokers.
For example, information on a data broker website could lead to a rejection for a job or mortgage without a clear reason.
The exposed personal information of political officials and law enforcement can put them at direct risk of physical attacks, as demonstrated by the assassination of Representative Melissa Hortman. The FBI investigation revealed the suspects notebook listed the data brokers where he found her home address.
Data brokers can sell location data, political affiliations, and other personal data to the government, fueling federal surveillance.
Right now, its all legal. But that doesnt mean youre completely powerless. More on that later.
Due to the amount of personal data they collect and store, data brokers are prime targets for cybercriminals. A hack or a leak can expose sensitive information, including financial data and social security numbers.
This has happened before. Just a few years ago, Social Data, a data broker that scraped public social media profiles of companies, accidentally exposed 235 million social media accounts. More recently, the National Public Data breach of 2024 exposed millions of SSNs and has been called one of the largest data breaches of all time.
Acxiom, Epsilon, and Experian have been hacked.
One study estimated that just four recent data broker breaches resulted in nearly $21 billion lost to fraud, identity theft, and other harms.
As the information security professional Daniel Miessler wrote a few years ago, most people falsely believe that the real danger to their privacy comes from hackers in basements, when it actually comes from big companies with parking lots, coffee budgets, and health benefits for their employees.
In 2023, researchers tested whether 37 known data brokers would be willing to sell sensitive mental health data, including diagnoses and demographic information. The result? Eleven of the companies agreed, for prices as low as $275 per collection of 5,000 mental health records.
Under Californias new regulations, many data brokers are required to describe the types of data they provide and to what entities. Under that law, at least 33 data brokers reported that they sell personal information to foreign companies.
Some of those also admitted to selling personal data to AI developers for model training. Once personal info gets caught up in an AI training database, theres rarely any way to opt out or control where it goes next.
More on that later.
Recent research from the Joint Economic Committee showed many top data brokers deliberately prevent search engines from indexing opt-out pages as of 2026.
That means if you search [data broker name] opt-out in your browser, you will never find the page because the search engine hasnt categorized the page in its library. Its still possible to opt out if you have a direct link or can find the page through the main website, but data brokers will also make the site structure deliberately confusing so the page is harder to find.
This is another reason its often helpful to have a privacy service like DeleteMe on your side when you want to opt out. Our privacy advisors are very familiar with data brokers tactics and hidden web pages.
Although some data brokers claim that the sensitive data they collect, store and sell is anonymized, studies show that de-anonymizing data is relatively easy.
Many of the apps on your phone collect location data. A broker might sell a “nameless” log of GPS coordinates, but if that data begins and ends at your house every day, stopping at a specific daycare, and parking at a specific location for around eight hours, your name can be figured out.
AI is particularly good at aggregating enough personal information to deanonymize data and even identify the real person behind an online username with ease based on public posts and conversations.
This means you may not be as anonymous as you think online.
These five risks are just the beginning of the many harms data brokers can cause both online and offline.
The information on data brokers and people search sites also creates risk for businesses, in the form of executive threats, cybersecurity risks and other potential exploits.
Executives are often targeted by activists, disgruntled ex-employees, unhappy customers, and other threat actors.
Its not unusual for executives to be subject to harassment, doxxing, stalking, reputational attacks, and identity theft.
Threat actors do not have to go to significant lengths to find out an executives email address or where they live, because this information is easily findable on data brokers and people search sites.
We often find a higher degree of PII exposure for C-Suite executives (between 15% and 25%) compared to the average employee.
That said, other high-profile employees and board members, as well as high-risk professionals (law enforcement, journalists, etc.), are at an increased risk of personalized attacks from malicious individuals as well.
The personal data that exists about employees and executives on the open web can fuel sophisticated cyber threats like social engineering and make attack techniques like credential stuffing easier.
For example, if a threat actor can personalize a phishing email to a specific employee, their success rate will be much higher than if they were to send a generic message.
Learn more: OSINT: how cybercriminals use open source intelligence for social engineering
We know from ContiLeaks that ransomware groups use data brokers to find targets to spearphish and contacts they can name drop within emails to make them seem more believable.
Similarly, if a hacker knows enough information about an employee, they can more easily guess passwords and security questions for professional and even personal accounts, from which they can leapfrog into corporate networks.
They may also use what they find through publicly available sources to run a haveibeenpwned.com search for actual authentication credentials.
Learn more: The link between weak passwords, data breaches, and data brokers
Having multi-factor authentication (MFA) wont necessarily keep threat actors out. Many MFA solutions can be circumvented via SIM swap or phishing attacks.
Ultimately, exposed personal data increases your attackable surface. Protecting your systems starts with protecting your people.
AI companies like OpenAI, DeepSeek, Grok, and others have insisted that their tools do not share personally identifiable information or use it for training.
DeleteMes internal research has consistently shown LLMs do share personal information. With a few prompts, its possible for anyone to obtain home addresses and other personally identifiable information through many of the most popular chatbots.
Some LLMs will even link to data broker pages and share information from pages that are usually only accessible behind a paywall. This makes it theoretically easier for cybercriminals to reference multiple sites and put together complete profiles with the help of jailbroken AI chatbots or even tools built specifically for illicit activities like FraudGPT.
Many AI chatbots also train on the contents of everyday chat by default, so any personal information you share could potentially be sold to data brokers and other third parties.
Use with caution if at all and check your privacy settings.
Its not just marketers who want to better tailor their ads or long-lost friends who want to reconnect that use data brokers and people finder sites.
Other groups and people that use data brokers include:
Ultimately, data brokers will sell to whoever pays.
Data brokers use public records, commercial sources, and online tracking data to gather data about individuals.
Public records include census records, real estate records, DMVs, marriage certificate records, bankruptcy records, business listings, state professional and recreational license records, and voter registration records.
Commercial sources generally include purchase history from retailers, employment registration, credit information, membership data, loyalty card data, warranty registration, and subscriptions.
Online tracking data includes user data from social media profiles, web browser cookies, forum posts, mobile apps, web browsing activity, device data, metadata, and IP fingerprints.
Most of these sources provide only one or two data elements (i.e., a name or phone number) for any individual person. But by piecing them together and guessing the rest, data brokers can build a comprehensive picture of who you are.
For example, data brokers can guess whether you have any health conditions based on what you buy or search for online.
The majority of data brokers also obtain information from one another.
Data brokers know a lot about you, including your:
They may also know your medical history, interests, dating preferences, credit-driven data, real-time location data, Social Security number, and significant life events such as births, marriages, divorces, and deaths.
Many data brokers also put people into specific categories.
For example, if you have a dog, you might be placed within a Dog Owner category. If you are seeking treatment for bipolar disorder or severe anxiety or depression, you may be placed in a specific category that lets advertisers know how to target you. And so on.
Learn more: What exactly do data brokers know about you?
Its important to understand another issue we all face with data brokers: The data they sell may be wrong. Thats because data broker data sets are made up of two kinds of data:
Incorrect information on data broker websites can cause real harm to individuals.
The most jarring example is when a people search sites reports criminal record found for an individual, when the record is a dismissed traffic ticket or belongs to someone with the same or similar name.
In one incident, inaccurate data led to a background check platform confusing a prospective employee with a convicted murderer.
According to the NATO Strategic Communications Center of Excellence, only 50-60% of data broker information was accurate as of 2021. A 2024 study suggested that data brokers havent improved their accuracy at all in the past eight years. Very few data brokers allow individuals to correct inaccurate information.
Most people have no idea that the data broker industry exists, let alone that data brokers are selling their personal information. However, that doesnt make selling data illegal.
Because the information data brokers trade-in is publicly available, theyre not technically breaking the law in most cases.
Some states have passed legislation that restricts data brokers. Currently, 20 states have passed comprehensive consumer privacy laws. California and Vermont regulate data brokers and require that they register with the state.
Vermonts data broker privacy law (enacted in 2018, the first such law in the country) stipulates that data brokers must maintain minimum data security standards and be more transparent about the types of data they collect.
It also prohibits anyone from buying brokered personal data through fraudulent means or with the goal of fraud, harassment, stalking, or discrimination.
Similarly, the California Consumer Privacy Act sets down that consumers have the right to know what information is being collected about them and to whom its being sold to. Under this law, individuals have the right to opt-out or have their data deleted. The law also prohibits selling data about users under 16 years old.
Some state laws also prohibit the use of particular information, like voter registration records, for non-election and/or commercial purposes.
Theres no federal law protecting consumers right to control how information about them is being bought and sold.
However, federal regulations protect certain sensitive data:
Similarly, the Fair Credit Reporting Act (FCRA) applies to data brokers that sell consumer data to third parties that use it for particular, enumerated eligibility decisions, including employment and credit.
In the European Union, theres the General Data Protection Regulation (GDPR), a data privacy law that affects any organization collecting consumer information.
The GDPR stipulates that consumers must consent before their data is collected. Under the GDPR, consumers also have the right to ask organizations to delete any information organizations might have about them.
You can view a complete list of the current state consumer data privacy laws here.
If you are not in a state covered by a comprehensive consumer privacy law, you can still opt out, but data brokers are not required to comply with your request.
Some (but not all) data brokers and people search sites allow people to opt out of their databases.
You can opt out of data brokers yourself. Just be prepared to invest a lot of time in the process. And expect to do it regularly.
Data brokers dont make opting out easy. To remove your profile from a people finder site or data broker database, you might have to:
However, not all sites give users an option to opt out.
Some data brokers allow you to control your information but not delete it. And those that supposedly give you the option to opt out dont always honor your request.o opt out dont always honor your request.
Learn more: Our comprehensive data broker opt-out guides
Some data brokers also request that you submit additional personally identifiable information before they remove you from their database.
This can deter some people from requesting an opt-out. Thats particularly true if the service seems sketchy you dont want to give them any more personal information than they already have.
In most cases, you cant just opt out of a data broker site once. Because most data collection processes are automated, your profile will reappear as soon as the data broker receives information from another source.
Another thing to note is that just because you opt out of a data broker doesnt mean all traces of you will disappear from their database.
Your name and other information might still appear in another persons records (for example, your spouse, parent, etc.) For this reason, its a good idea to take the time to opt out family members from data broker sources too.
If you want the peace of mind that comes with having your personal information off of data brokers and people search sites, you can enlist the help of a professional opt-out service.
There are several data broker removal services to choose from. Some specialize in data broker removal, while others offer data removal as part of a larger offering (for example, online reputation).
Learn more: Best companies and tools to remove personal information from the internet
When choosing a data broker removal service, check their:
Because data brokers collect data from numerous online and offline sources, it is impossible to completely stop them from collecting your personal information.
That said, there are certain steps you can take to reduce your digital footprint and minimize the amount of information data brokers can find about you.
Start here:
Data brokers are a threat to our privacy, but were not totally helpless. Opt out of their databases and stay mindful of how and where you share your data to significantly improve your privacy.
Our privacy advisors:
Save 10% on any individual and
family privacy plan
with code: BLOG10
DeleteMe is our premium privacy service that removes you from more than 750 data brokers like Whitepages, Spokeo, BeenVerified, plus many more.
Save 10% on DeleteMe when you use the codeBLOG10.
Chat
DeleteMe is built and run by Abine, Inc.
The Online Privacy Company.
2026 Abine, Inc. All Rights Reserved.
Chat
DeleteMe is built and run by Abine, Inc.
The Online Privacy Company.
By Challenge
By Industry
2026 Abine, Inc. All Rights Reserved.
| Web Proxy Viewer | New URL | Original Page |