Data Brokers Know More About You Than Your Doctor. Here’s How to Disappear.

There is a file being maintained about you right now. It contains your home address, your previous addresses going back a decade, your approximate income, your political affiliation, your consumer debt level, the names of your relatives, your purchasing habits across dozens of retail categories, your estimated health conditions inferred from pharmacy data, and in some cases your precise geolocation history pulled from apps you downloaded years ago and never deleted. This file was not created with your consent. You cannot see it without requesting it. And it is being sold, right now, to anyone willing to pay — marketers, employers conducting background research, landlords, journalists, stalkers, and identity thieves, all pulling from the same commercial tap.

The entities maintaining this file are data brokers. In 2025, Privacy Rights Clearinghouse built a unified database of 750-plus data brokers by collecting and cross-referencing registration data from all five US state registries — and in the process identified hundreds of companies that had registered in one state but failed to register in others. Seven hundred and fifty companies, most of which you have never heard of, many of which you would not be able to name even if you spent an afternoon researching them. Acxiom. LexisNexis. Epsilon. BeenVerified. Whitepages. Spokeo. MyLife. These are the ones with brand recognition. Behind them is a long tail of smaller operators who resell the same data to less visible buyers.

The cognitive and professional stakes of this for knowledge workers are more specific than the generic “privacy is important” framing usually conveys. Your data broker profile influences background checks that affect your career. It feeds the risk-scoring models that affect your insurance premiums. It exposes the professionals who work with sensitive clients — attorneys, therapists, journalists, executives — to people who should not be able to find them. And it feeds the AI training datasets and personalisation engines that shape how algorithmic systems model you, often using inferences about your health, mental state, and financial vulnerability that are systematically wrong in ways you cannot see or correct. The file is not just a privacy inconvenience. It is an actively operating model of who you are, maintained by parties with commercial incentives to sell that model to buyers whose intentions you cannot verify.

This guide gives you the practical apparatus to start collapsing that file.

What Data Brokers Actually Know — and Where They Get It

The categories of data that appear in broker profiles are more intimate than most people assume until they see their own file. The California Privacy Protection Agency’s data broker registry requires each registered broker to disclose the categories of personal information it collects — and the list includes Social Security numbers, precise geolocation data, health information, browsing history, financial data, biometric identifiers, and information about children. Each of those categories carries specific risks that compound when combined. Precise geolocation plus home address plus daily routine equals a stalking resource. Health information plus financial data plus employment status equals a fraud-enablement package. SSN plus previous addresses plus relatives’ names equals identity theft infrastructure.

The sourcing is what makes the problem structurally difficult to solve. Data brokers compile from public records — court filings, property records, voter registration data, professional licences — which are by definition non-private and cannot be removed. They compile from data you voluntarily provided — retail loyalty programmes, app permissions, social media profiles, warranty registrations — which you consented to at some point without anticipating the secondary market. And they compile from other data brokers, buying and reselling profiles in a commercial chain that makes tracing your data’s origin practically impossible.

The FTC has studied the data broker industry extensively and found that nine data brokers alone — including the largest players — held 3,000 data segments on virtually every US consumer, and that these profiles are used for decisions including employment screening, housing, credit, and insurance, creating real and lasting economic consequences for individuals from data they cannot access or correct. The “consequences you cannot correct” framing is the one that most clearly establishes why this is not merely a preference issue for privacy enthusiasts. It is a systemic fairness problem with direct economic effects.

The Legal Landscape That Shifted in 2025–2026

The practical options available to you depend significantly on where you live, because data broker regulation has developed at the state level in the absence of comprehensive federal privacy legislation.

The most powerful single development in consumer data rights in 2026 is California’s DELETE Act and the platform it created. California’s centralised deletion platform — the Delete Request and Opt-Out Platform, or DROP — launched January 1, 2026, allowing California residents to submit a single deletion request that reaches every registered data broker in the state, free of charge; data brokers are required to process these requests within 45 days of retrieval, checking the DROP system at least every 45 days. If you are a California resident, this is the single most efficient first action available to you. One submission, managed by the California Privacy Protection Agency, rather than individual requests to hundreds of brokers.

If you are not in California, Texas, Vermont, and Oregon all have data broker registration requirements whose registries you can use to identify which brokers hold your data and what opt-out mechanisms they offer. The CPPA publishes the California data broker registry with details for every registered broker including business name, categories of personal data collected, and categories of entities to whom data is sold; similar registries in Texas, Vermont, and Oregon provide the same function for residents of those states.

The browser-level tool that most knowledge workers have not implemented is Global Privacy Control — a browser setting that sends an automated opt-out signal to every website you visit. Browser-level opt-out signals now carry legal weight in multiple states — California, Connecticut, Colorado, and others — meaning that a GPC-enabled browser communicates your opt-out preference automatically to participating data collectors, reducing the volume of new data being added to your profile even as you work to remove existing data. Firefox, DuckDuckGo Browser, and Brave have GPC enabled by default. Chrome requires a browser extension. The implementation takes under five minutes and is the highest-ROI passive privacy action available because it addresses the accumulation problem rather than only the remediation problem.

The Practical Removal Architecture: Doing It Systematically

Manual removal from data broker sites is not a single event. It is a process with a defined starting sequence, an ongoing maintenance component, and a realistic timeline measured in months rather than days. Understanding the architecture before you start prevents the discouragement of discovering, three weeks in, that the problem is larger than the first afternoon suggested.

Step One: Audit first, remove second. Before submitting any opt-out requests, run your name through the most prominent people-search databases — Spokeo, BeenVerified, Whitepages, MyLife, Intelius, and PeopleFinder. Screenshot every profile you find with your data. This gives you a baseline before you begin that documents what was there, confirms removals when they succeed, and reveals which brokers hold your data and in what format. Searching your name plus your city, and your name plus previous cities, surfaces profiles that a simple name search might miss. Cybernews’s February 2026 comprehensive opt-out guide recommends checking your state’s data broker registry as a structured starting point, using that list to identify the brokers operating in your jurisdiction rather than trying to identify brokers through general web searches.

Step Two: Submit California DROP if eligible, or start with the Tier 1 brokers. If you are a California resident, submit through DROP first — it handles the broadest scope of registered brokers in a single action. For everyone else, the priority order is the brokers whose profiles cause the most practical harm: Whitepages, Spokeo, BeenVerified, Intelius, and MyLife collectively are the most frequently used people-search databases and the ones most likely to appear in a simple name search by someone looking for you. Each has its own opt-out process — some require email verification, some require submitting a form, some require creating an account first. Budget two to four hours for these five.

Step Three: Enable Google’s Results About You. Google’s “Results About You” feature allows users to request removal of eligible search results containing their personal contact information — home address, phone number, and email address — directly from Google Search. This doesn’t remove data from the broker’s own database, but it removes the search-discoverable result that makes the data practically accessible to someone searching your name. For people in professional roles where their name is frequently searched, this adds a significant practical layer on top of the broker opt-out process.

Step Four: Set a quarterly maintenance calendar. The most important thing to understand about data broker removal is that it is not a problem you solve once. Even after opting out, your personal information can reappear online — meaning you must regularly check and resubmit requests; automated services like Incogni and DeleteMe handle ongoing monitoring and resubmission, at a cost of $100 to $300 per year, while manual maintenance requires quarterly checks of major brokers. A quarterly calendar reminder covering your top fifteen to twenty most prominent broker profiles is the minimum viable maintenance process. Automated services handle ongoing resubmission at scale — they are worth considering if your time cost for quarterly manual maintenance exceeds the subscription cost — but no automated service reaches every broker, particularly smaller regional operators, which is why the manual process cannot be entirely outsourced.

The AI dimension of data broker profiles is the one most directly relevant to knowledge workers navigating AI-augmented professional environments. The same profile data that data brokers sell to marketers and employers is feeding the commercial AI training datasets and personalisation models that shape how AI systems perceive and interact with you. The EFF’s research on location data brokers specifically documents how broker-sourced location data is being incorporated into AI targeting and inference systems, creating a feedback loop where your data broker profile influences your AI-mediated experience across search, advertising, and recommendation systems. Our exploration of what AI agents actually are and how they access and process your information is directly relevant here — the agents being built into professional software platforms are increasingly drawing on commercial data sources whose pipeline runs through the same broker ecosystem this guide addresses.

The cognitive exhaustion of managing digital privacy — the attention it consumes, the decision fatigue of dozens of opt-out processes, the uncertainty about whether removal was permanent — connects to the broader theme explored in why knowledge workers feel more exhausted than ever in the AI era. Privacy management is another form of cognitive labour that the digital environment has added to the professional’s plate without a corresponding reduction elsewhere. The tasks humans should never delegate to AI applies here too, with nuance: automated data removal services handle the repetitive submission work well, but the audit, the prioritisation, and the judgment about which exposures matter most for your specific professional risk profile are decisions only you can make.

Frequently Asked Questions

What is a data broker and why should I care about them?

A data broker is a company that collects personal information about individuals from public records, commercial databases, app permissions, loyalty programmes, social media, and other sources, then sells or licences that information to third parties. The California Privacy Protection Agency’s data broker registry — which covers brokers as defined by California’s DELETE Act — shows that registered brokers collect categories including Social Security numbers, precise geolocation, health information, browsing history, financial data, biometric identifiers, and information about children. These profiles are used in employment screening, housing decisions, credit and insurance pricing, and direct marketing — creating real economic consequences from data you did not knowingly disclose and may not be able to correct. The FTC has documented that nine major data brokers alone hold approximately 3,000 data segments on virtually every US consumer, making this a systemic privacy and financial risk rather than a niche concern.

What is California’s DROP platform and how do I use it?

DROP — the Delete Request and Opt-Out Platform — is a centralised deletion system created by California’s DELETE Act and launched January 1, 2026. It allows California residents to submit a single deletion request that reaches every data broker registered with the California Privacy Protection Agency, free of charge. Brokers are legally required to begin processing these requests by August 1, 2026, checking the DROP system at least every 45 days and processing requests within 45 days of retrieval. To use DROP, you must be a California resident, and you submit through the CPPA’s official platform at cppa.ca.gov. DROP is the most efficient single action available to California residents because it covers the full list of registered brokers without requiring individual submissions to each. For residents of other states, Texas, Vermont, and Oregon have data broker registration requirements with public registries that identify which brokers hold your data and what opt-out processes they offer.

How long does it take to remove my data from data brokers?

The manual opt-out process takes 10 to 20 or more hours for 100-plus brokers, and the timeline for individual removals varies by broker — some process requests within 24 hours, others take 30 to 45 days. CCPA-covered brokers are legally required to respond to consumer requests within 45 days in California. The more important timing point is that data removal is not permanent: even after a successful opt-out, your information can reappear in broker databases as they refresh from public records and other sources, typically within 3 to 6 months. This makes data broker removal an ongoing maintenance process rather than a one-time project. For practical management, focusing quarterly manual checks on the 15 to 20 most prominent brokers — Whitepages, Spokeo, BeenVerified, Intelius, MyLife, and similar people-search databases — is the minimum viable ongoing process. Automated services like DeleteMe and Incogni handle resubmissions at scale for a subscription fee but do not reach every broker, particularly smaller regional operators.

What is Global Privacy Control and how do I enable it?

Global Privacy Control (GPC) is a browser-level signal that automatically communicates your opt-out preference to every website you visit, telling them not to sell or share your personal data. GPC now carries legal weight in California, Connecticut, Colorado, and other states with comprehensive privacy laws — meaning websites covered by those laws are legally required to honour the signal. Firefox and the DuckDuckGo Browser have GPC enabled by default. Brave Browser enables it in the Privacy settings. Chrome users can install the Privacy Badger extension, which includes GPC support. The practical advantage of GPC is that it addresses the accumulation problem continuously — reducing the volume of new data being added to your profile even as you work to remove existing data through opt-out requests. Enabling GPC takes under five minutes and is the highest-ROI passive privacy action available to most users, complementing but not replacing the active broker opt-out process.

Should I use an automated data removal service or do it manually?

The honest answer is both, in different roles. Automated services like DeleteMe, Incogni, and Optery are most effective for maintaining removals from major, well-known brokers over time — they monitor for reappearance and resubmit opt-out requests automatically, which addresses the ongoing maintenance problem that makes fully manual management burdensome. They typically cost $100 to $300 per year. Their limitation is coverage: no automated service reaches every broker, particularly smaller regional operators, niche specialty brokers, and brokers that operate outside the service’s monitored list. The recommended approach is to use the California DROP platform if eligible plus manual opt-outs for the top 15 to 20 most prominent brokers first, then layer an automated service on top for ongoing maintenance of major brokers. This combination addresses both the immediate removal of your most visible profiles and the long-term management of reappearance at scale — without assuming that either approach alone is sufficient.

 

Conclusion

The uncomfortable reality about data brokers is that you cannot make them stop collecting data about you entirely — public records are public, commercial data flows are legal, and the infrastructure is too distributed to switch off from the consumer side. What you can do is systematically reduce your attack surface: collapse the most visible profiles, enable the browser-level signals that reduce new accumulation, use California’s DROP platform if available, and establish the quarterly maintenance rhythm that prevents the file from growing back to its current size.

State of Surveillance’s comprehensive 2026 data broker opt-out guide puts the goal precisely: the aim is not perfection but meaningful reduction — making you hard enough to find that the casual lookup, the background check run by a broker-aggregating service, and the AI personalisation system drawing on commercial data all return less of the intimate profile that exists today. Perfection is not available. Meaningful, sustained reduction is. And in a landscape where your data broker profile is increasingly the raw material for AI systems that model you, assess you, and make consequential decisions about you, the effort is proportionate to the stakes.

This article is for informational purposes only and does not constitute legal or financial advice. Data broker regulations and opt-out processes change frequently. Always verify current requirements directly with relevant state agencies and data broker platforms.

 

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *