Data Broker List 2026: 1,034 Brokers & Data Companies by Category
1,034 data brokers and data companies by category: people-search, marketing, B2B, and adtech, with each provider's request route and source date.
Industry counts vary because registries and researchers use different definitions and scopes. The EPIC data-broker overview is useful context, but it is not a universal count of every provider or a ranking of consumer risk. The practical starting point is the current, searchable OfflistMe directory, where each catalog record is separated from its source evidence and freshness status.
Quick Answer: Data brokers are commercial entities that may combine public records and commercial datasets to compile profiles on individuals. Start with providers where you can verify a relevant live profile, then expand based on your risk and the current catalog. Provider routes may be free; OfflistMe prepares first-party drafts for you to review, send or submit, verify, and follow up.
>
Key Statistics & Sourcing: Registry counts are scope-specific and change over time. The California Privacy Protection Agency's DROP guidance describes the platform's current registered-broker scope. Use the linked official registry or provider page for current counts; do not combine registries into a global total.
>
This guide covers what data brokers are, how they are categorized, how to choose a priority set, and how to use the live directory without treating a catalog record as proof of a personal profile or a completed removal.
Turn the broker list into a reviewable removal plan
Start with providers where you can verify a current listing or a matching route, choose the workflows you want to address, and review each draft before sending or submitting it yourself.
Use the right surface: the directory is the searchable customer-ready catalog; this article explains categories and prioritization; individual broker pages contain provider-specific route evidence and source dates.
Which data-broker list should you use?
- Search the full directory: compare the recorded route, source date, workflow fields, and evidence limits for a provider.
- Review the bounded Top 100 shortlist: start with a smaller, editorially selected group when you want prioritization rather than a census or universal risk ranking.
- Explore location-data providers: use the specialist guide when your concern is location or mobility data rather than a public people-search listing.
- Use this guide: understand categories, choose a priority set, and interpret what a catalog record does—and does not—prove.
These surfaces answer different questions. A link or catalog entry is not proof that a provider currently holds your information, that a request will be accepted, or that a related brand is covered by the same request.
Which surface answers which question?
| If you want to… | Use… | Keep in mind |
|---|---|---|
| Search the broadest current OfflistMe catalog | Data broker directory | It is a curated workflow catalog, not an official worldwide census or proof of a personal match. |
| Start with a bounded priority set | Top 100 shortlist | Inclusion and order are editorial starting points, not a universal risk ranking or coverage guarantee. |
| Understand categories, evidence limits, and prioritization | This guide | Examples and categories need current provider or official-source verification before submission. |
| Follow a provider-specific route | The linked provider profile or guide | A route for one legal entity, brand, or database may not cover related services. |
How this list is maintained
The catalog snapshot referenced here is dated September 20, 2026, and this guide was reviewed on September 24, 2026. The customer-ready catalog contains 1,034 recorded workflow profiles. The underlying research ledger contains dated observations and source-linked facts across a 1,052-record research universe, but a catalog record is not proof that a particular person appears on a provider, that a request will be accepted, or that deletion has completed.
The public broker evidence roadmap and evidence scorecard show the current source dates, route states, missing fields, and review boundaries. The freshness view is the right place to check whether a provider record needs re-review. To see how this catalog lines up against official government registries directly, the state registry crosswalk compares captured catalog matches against the California CPPA, Vermont Secretary of State, and SEC EDGAR records. Counts are snapshots of this research system, not a census of every company that could be described as a data broker.
How to verify a data-broker list before using it
A useful list should help you verify a provider, not ask you to trust an unexplained number of names or links. Before sending a request, use this five-part check:
- Confirm the exact entity and domain. A brand, parent company, processor, and public-record custodian can have different roles and request scopes.
- Read the current provider or regulator source. Check the privacy notice, request page, registry entry, or other named source instead of relying on a list description alone.
- Match the exposure. Look for a current profile, page, identifier, or other provider-supported match. Catalog inclusion does not prove that a provider has your information.
- Record the request boundary. Note whether the route addresses access, correction, deletion, sale/sharing, marketing preference, or another specific control. One request type is not a universal substitute for another.
- Preserve the follow-up evidence. Save the route, submission date, confirmation, response, and later source check. Treat a changed search result, sibling brand, or downstream copy as a separate verification question.
This process makes a list actionable while limiting unnecessary disclosure. It also separates three different facts: a provider is listed, a request was submitted, and a record later changed. Those facts should not be presented as interchangeable.
Key Takeaways
- Industry estimates use different definitions. Prioritize providers where you can verify relevant exposure, then use the current catalog to expand coverage; no universal percentage proves that one fixed number of opt-outs covers everyone.
- Five practical categories create different research and request paths: people-search, background checks, B2B and sales intelligence, marketing and audience data, and specialty or public-record services.
- Parent-company relationships are not outcome evidence: a shared owner, brand family, or route host does not prove that one request suppresses every related service. Verify each provider-specific listing and response separately.
- California's DROP platform is scope-specific: use the official CPPA DROP materials for current eligibility, registration, and processing details rather than repeating a static broker count.
- Downstream data flow is provider-specific: a request to one source may not change copies held by another provider. Treat every downstream listing as a separate verification target unless the provider documents shared suppression.
What Is a Data Broker?
A data broker is a business that collects personal information about consumers from various sources and sells that information to other companies, including when a consumer did not directly interact with the business. The California Privacy Protection Agency uses that definition for its California registry, but the legal scope and obligations depend on the provider, data type, business role, and jurisdiction. Read the CPPA definition and registry guidance before applying the label to a specific company.
California's Delete Request and Opt-out Platform (DROP) is now available to California residents. The official DROP guidance says one request can be sent to more than 600 registered data brokers, and that starting August 1, 2026, data brokers must access DROP at least once every 45 days to begin processing deletion requests. The CPPA registry page explains that California residents may use DROP for active data brokers. That scope is not a global broker count and does not replace provider-specific verification outside the platform.
The Five Practical Categories Used in This Guide
Category 1: People-Search Sites
These are the sites many consumers encounter first. They may aggregate public records and present searchable profiles, but the fields, price, login requirement, and matching process vary by provider.
Examples of people-search providers to investigate:
| Site | Recorded starting point — verify the current route |
|---|---|
| Whitepages | suppression requests |
| TruePeopleSearch | removal |
| FastPeopleSearch | removal |
| Spokeo | opt-out |
| Radaris | candidate privacy-control route; verify |
| AnyWho | official help page; opt-out route not directly exposed |
| USPhoneBook | opt-out |
| Nuwber | removal/link route; verify |
Category 2: Background Check Sites
These sites present themselves as background-check or people-search services. Their product scope, record types, audience, matching process, and request route vary by provider; review the current provider disclosure before relying on a category label.
| Site | Recorded starting point — verify the current route |
|---|---|
| BeenVerified | opt-out search |
| Intelius | PeopleConnect Suppression Center — public-report route; verify |
| TruthFinder | PeopleConnect Suppression Center — public-report route; verify |
| Instant Checkmate | PeopleConnect Suppression Center — public-report route; verify |
| PeopleFinders | opt-out |
| PeopleLooker | Dedicated route not confirmed; verify the provider's current privacy notice |
| AdvancedBackgroundChecks | Recorded route not independently verified; check the provider's current privacy notice |
| CyberBackgroundChecks | privacy page; dedicated removal route not confirmed |
| SmartBackgroundChecks | Dedicated route not confirmed; verify the provider's current privacy notice |
Category 3: B2B Data and Lead Generation
Some B2B data providers may offer professional contact data, work emails, direct dials, or job titles to sales, recruiting, or marketing users. Data sources and uses vary; check the provider's current privacy notice rather than assuming that every provider uses the same collection method or audience.
| Site | Recorded starting point — verify the current route |
|---|---|
| ZoomInfo | Trust Center privacy/removal |
| Apollo.io | remove profile |
| Lusha | request removal |
| RocketReach | privacy page; dedicated removal route not confirmed |
| Clearbit / HubSpot | Clearbit privacy request form |
| Cognism | remove my profile |
These links are starting points, not proof that a form is live, that it covers every product or affiliated brand, or that a request will be accepted. The current PeopleConnect Suppression Center describes public-report suppression for its named family, while its privacy center separately distinguishes suppression from user-data requests. Check the provider's current disclosure, scope, verification requirements, and response before submitting. A route that could not be independently confirmed remains an open catalog-review item.
Category 4: Marketing Data Aggregators
These providers may offer audience, marketing, risk, or other commercial-data products. Their visibility, data scope, and consumer request routes differ, so verify the provider's current description and rights process before applying this category.
Examples to investigate include Acxiom, Epsilon, Oracle Data Cloud, Experian Marketing Services, and LexisNexis Risk Solutions.
These companies publish different privacy-choice and rights routes. Open the provider's current privacy or rights page, confirm the request scope, and do not treat a marketing preference as proof of deletion from every product.
Category 5: Specialty Brokers
This category includes providers that readers may encounter in specific industries or use cases. The labels are discovery categories, not a current legal classification; verify each provider's own description and request route:
- Court-record and public-record providers: PublicRecordsNow, CourtRecords, Arrests.org
- Property and address providers: BlockShopper, PropertyShark
- Reverse-phone providers: WhoCalledMe, CallerSmart, NumLookup
- Political or voter-data providers: L2 Political, TargetSmart
- Healthcare and pharmaceutical data providers: IQVIA, Symphony Health
If a public-record or background-check result includes a mugshot, see how to get a mugshot removed from the internet for the separate source, provider, court, and search-result steps.
Why one global broker count is misleading
There is no single denominator that includes every registry, data supplier, people-search site, professional-data service, and downstream publisher. Registries use different legal definitions and reporting periods, while private providers may not expose a searchable consumer profile at all.
Use a layered priority instead:
- Verify the exposure first: start with providers where you can locate a current listing or where the provider publishes a matching route.
- Add context-specific providers: include background-check, public-record, marketing, B2B, location, or specialty services when they match your risk or profession.
- Treat related brands separately: a shared owner, data source, or route host does not prove shared suppression or a common request outcome.
The practical number of requests depends on the person, location, profession, and providers that actually hold or publish relevant information. A large catalog is useful for discovery; it is not a promise that every record is relevant to every person.
How Data Brokers Get Your Information
Understanding possible sources helps you investigate a listing, but a generic source category is not proof of how a particular provider obtained your information. Provider privacy notices, registry submissions, and request disclosures are stronger evidence.
Common source categories to investigate:
- Public and government records: property, court, business, licensing, or other records where the provider or regulator identifies them as a source.
- Commercial and transaction data: purchases, registrations, subscriptions, or other customer interactions disclosed by the provider.
- Online and device activity: browsing, app, location, advertising, or social information when the provider's notice documents that collection.
- Data supplied by other businesses: enrichment or licensing relationships that a provider explicitly names.
The CPPA registry lets readers inspect categories reported by registered California data brokers. Do not infer a specific source from a provider's name, category, or the fact that a profile exists.
How to Use Our Full Directory
Our live directory includes the 1,034 recorded workflow profiles we track, with route fields, source dates, evidence states, and missing-field boundaries. The page is revalidated on a documented cadence; use each profile's source date and provider page to judge currentness.
The directory is organized by category so you can prioritize. If your goal is public name-search visibility, begin with the people-search providers that actually appear in your results, then expand to background-check, public-record, marketing, or B2B providers relevant to your situation.
For a broader pass across the recorded workflow catalog, OfflistMe generates browser-local drafts for you to review and send or submit from your own channel. Provider verification and outcomes remain separate.
Frequently Asked Questions
How many data brokers do I actually need to opt out of?
There is no independently verified universal top-20 coverage percentage. The full recorded workflow catalog is broader, while a priority group can be a sensible starting point when it contains verified live profiles.
Do data brokers share data with each other?
Some providers state that they license, receive, or disclose data to other organizations, but the relationship and scope vary. Cite the provider or registry source for a specific relationship; opting out of one provider does not prove that every downstream copy changes.
How often is broker data updated?
Refresh schedules vary by provider and source. A listing can return after a provider receives new or republished data, so periodic re-checks are more reliable than a fixed interval.
Are data brokers regulated?
The answer depends on the provider, data type, business role, jurisdiction, and applicable exceptions. Credit-reporting activity can implicate the FCRA, while state privacy and data-broker laws apply within their own scopes. Use the controlling regulator or statute for a specific request instead of treating “data broker” as one legal category.
Is there one official list of every data broker?
No. Government registries and private research catalogs use different definitions, jurisdictions, inclusion rules, and update schedules. Use the current registry or provider source for the scope that matters, and treat an editorial list as a documented starting point rather than a universal census.
Does a data-broker list tell me which companies have my information?
No. A list identifies providers or workflows that may be relevant; it does not establish a current personal record. Search for a matching listing where the provider permits it, minimize the information you submit, and keep each provider's response separate.
Should I opt out of every provider on a data-broker list?
Not automatically. Start with providers where you can verify a relevant exposure or where your situation makes the category important, then expand by source freshness, risk context, and provider-specific route. A long list is a discovery tool, not an instruction to disclose information to every name on it.
What is the difference between a data-broker list and a data-broker directory?
A list may be an editorial or research overview; a directory is usually a searchable catalog with provider-level fields and routes. OfflistMe uses this guide for categories and prioritization, the directory for searchable workflow records, and individual profiles for provider-specific evidence and source dates.
Draft first-party requests for selected workflow profiles →
Tier 1 vs. Tier 2 vs. Tier 3 Brokers: The Priority Framework
Not all recorded workflow profiles in our directory deserve equal attention. Working through every provider alphabetically is inefficient and misses the point: the goal is to reduce verified privacy exposure, not hit an arbitrary count. This tiered framework prioritizes by context and evidence.
| Tier | Broker count | What they do | Why they matter | Examples |
|---|---|---|---|---|
| Tier 1: Verify first | A priority group | Publish consumer-facing profiles searchable by name or expose sensitive fields | Prioritize live results, safety risk, and search visibility; no universal harm or coverage percentage is asserted | WhitePages, Spokeo, Radaris, FastPeopleSearch, TruePeopleSearch, BeenVerified, Intelius |
| Tier 2: Context-specific review | A review group | Background-check aggregators, court-record publishers, professional directories | May matter for employment, housing, licensing, safety, or disputes; prioritize only when the context is relevant | TruthFinder, Instant Checkmate, CourtRecords.us, PublicRecordsNow |
| Tier 3: Structural or professional review | The remaining catalog | Marketing data, B2B lead generation, audience, identity-resolution, and specialty providers | Often requires provider- and jurisdiction-specific research rather than a generic people-search workflow | Acxiom, Epsilon, ZoomInfo, Apollo.io, LexisNexis |
How to use the tier framework:
If your goal is to reduce search visibility, start with the live results that expose the most sensitive information. Provider steps and time vary; use each current official route and preserve the submission record.
If your goal is to reduce advertising targeting, unsolicited offers, or professional-data exposure, Tier 3 requires separate provider-specific research and requests; a public people-search opt-out is not a substitute.
If you have professional exposure, business disputes, public role, professional licensing, Tier 2 is particularly important because it covers court record aggregators and professional directories that Tier 1 misses.
Why order matters:
Data flows can involve multiple providers, but a claimed source relationship must be supported by a provider or official source. Addressing one provider may not change copies held elsewhere. A practical sequence is: verify priority listings, submit provider-specific requests, then expand to other relevant sources.
Primary sources and verification
- California Privacy Protection Agency: DROP scope and eligibility
- California Privacy Protection Agency: data-broker information
- PeopleConnect Suppression Center
- PeopleConnect privacy center
- AnyWho Help / FAQ
- ZoomInfo: Your Privacy
- Apollo: remove your information
- Lusha: request removal
- Clearbit privacy policy and removal form
- Cognism: Contact Us and profile-removal link
- Every provider link in the directory should be opened and checked before submission; catalog inclusion is not proof of a live profile or completed removal.
How to Handle Parent Companies and Related Brands
Brand relationships can help explain why two providers show similar fields, but they do not prove shared ownership, shared suppression, or a common request outcome. Before treating related brands as one target, check the provider's current privacy notice, legal entity, request language, and confirmation scope.
Use this evidence order:
- Identify the legal operator or parent from a provider or official registry source.
- Check whether the current request route names the related brands or databases it covers.
- Save the submitted route and confirmation for the specific provider.
- Re-check each relevant listing separately; do not infer deletion from a sibling brand disappearing.
California residents should use the official CPPA DROP materials for the current platform scope and eligibility. A centralized route can reduce repeated work, but it does not remove the need to understand the request's scope or verify the resulting records.
Browse the source-backed broker directory →
Navigating the 2026 Data Broker Ecosystem
Data flows can involve compilers, search portals, professional-data vendors, and other providers. The relationship is not universal, so use provider and registry evidence before assigning a source or downstream relationship.
The Tiered Data broker Ecosystem:
- Compilers and data suppliers: providers that describe public-record, commercial, audience, identity, or professional-data inputs.
- Search and report portals: consumer-facing services that publish or sell searchable profiles or reports.
- Specialty and downstream providers: services with a narrower industry, location, public-record, or professional context.
The correct request target is the provider shown in the current listing. A request to a compiler or parent company may not update an independently operated search portal.
Related Guides
Understand your privacy rights
Where a privacy right is relevant, these plain-English explainers show what each law covers and what to verify before making a request.
Related Data Broker Removal Guides
Take back your privacy today
Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.
Review Provider RoutesFree to review provider routes · Optional one-time unlock from $9.00 · No subscription
