Skip to main content
Privacy Law & Rights
7 min read

FTC Data Broker Reports and Enforcement: What Consumers Can Verify (2026)

A source-bounded guide to the FTC's 2014 data-broker report, later location-data enforcement, and the privacy claims consumers can verify today.

Rahul Kandoriya
Written byRahul Kandoriya·Last updated August 25, 2026
FTC Data Broker Reports and Enforcement: What Consumers Can Verify (2026)
FTC Data Broker Reports and Enforcement: What Consumers Can Verify (2026)
Coverage scope: The OfflistMe catalog currently records 1,000+data-broker workflows. Paid access lets you select workflows at once; you review and send or submit the generated requests, while provider eligibility and outcomes remain outside OfflistMe's control.

The FTC's dedicated report Data Brokers: A Call for Transparency and Accountability was published in May 2014—not 2024. The Commission has also published later privacy research and brought enforcement actions involving specific data practices, including sensitive location data. This guide separates those sources so a historical report, an enforcement allegation, and a current legal requirement are not treated as the same thing.

Key Takeaways

  • The FTC's 2014 data-broker report examined practices reported by nine companies and made policy recommendations; it is historical evidence, not a current census of the market.
  • The report described concerns about transparency, consumer control, and the use of data from multiple sources. It did not make every claim about every broker or every individual consumer.
  • A federal report or recommendation does not itself create a new deletion right or a universal opt-out route. Current rights depend on the applicable statute, regulator, provider role, and facts.
  • Later FTC cases show that specific data practices can trigger enforcement under existing authority. For example, FTC orders involving X-Mode/Outlogic, Mobilewalla, and Gravy Analytics addressed sensitive location-data practices.
  • There is no evidence here for a blanket “all brokers are illegal” conclusion, a universal global broker count, or a claim that one request reaches every provider.

What the FTC's 2014 report actually is

The FTC's 2014 data-broker report examined information supplied by nine data brokers under the Commission's study authority. It discussed how brokers collect and combine information, how consumers may lack visibility into those practices, and policy options for improving transparency and control.

The report is useful historical context. It does not tell us what every broker does in 2026, whether a particular provider currently holds your information, or whether a request will succeed.

What the report supports

  • Data-broker practices can involve information from multiple sources and can create profiles more detailed than an individual source.
  • Consumers may have difficulty learning what information a broker holds or how it is shared.
  • Transparency, access, correction, and opt-out mechanisms were policy concerns identified by the Commission.
  • Policy recommendations are not the same as enacted legislation or an individual legal determination.

What it does not support

  • A universal count of data brokers or a current estimate of every broker's data inventory.
  • A conclusion that every broker sells every sensitive category described in a historical report.
  • A conclusion that a public record can never be collected or reused, or that every downstream use is lawful.
  • A guarantee that a request will be accepted, completed, or remain effective.

Do not use a long historical report as a substitute for the provider's current privacy notice, a current registry filing, the controlling statute, or a dated route observation.

Request Drafting

Exercise your statutory data deletion rights

Review source-aware privacy-rights request drafts directly in your browser. Send or submit each request yourself after checking the provider route and applicable law.

Start Free Statutory Opt-Out Free for selected workflows · No opt-out profile stored · No card needed

Recommendations are not a federal registry

The 2014 report discussed policy options such as greater transparency, consumer access, and stronger controls. A recommendation to create a federal registry or universal mechanism would not itself create that registry or mechanism. The United States should not be described as having a mandatory federal data-broker registry analogous to California's system based on this report.

For current California scope, use the California Privacy Protection Agency's Data Broker Registry and DROP guidance. Those state sources do not establish a global count or a federal registry.

For federal conduct, the FTC Act gives the Commission authority to address unfair or deceptive acts or practices. Other federal statutes may apply to particular sectors or activities. Whether a specific broker's practice violates a law requires a current, fact-specific analysis.


What this means for a consumer

The practical lesson is not that every person has every category of data in a broker file. It is that you should verify the specific provider and source rather than relying on a generic industry description.

  1. Search for the provider's current privacy, access, deletion, and opt-out route.
  2. Check whether a registry or provider notice identifies the data categories, recipients, or legal role relevant to the request.
  3. Use the right jurisdictional statute or regulator guidance; do not cite California law as though it applies universally.
  4. Keep the submitted request, date, route, confirmation, and re-check result. A reachable form is not evidence of acceptance or completion.

What later FTC enforcement shows

Later actions are separate from the 2014 report and should be described with their own procedural status:

  • In January 2024, the FTC announced proposed action against X-Mode Social and Outlogic concerning the sale or sharing of sensitive location data; the Commission finalized that order in April 2024.
  • In January 2025, the FTC finalized orders involving Gravy Analytics/Venntel and Mobilewalla concerning sensitive location-data practices.

These actions illustrate that the FTC can use existing authority against specific practices. They do not establish that every data broker engages in the same conduct, and they do not create a universal deletion right for every consumer.


What you can do now

Match the request to the law and provider

Start with the provider's own privacy or opt-out route. Then identify the law that may apply based on your location, the provider's role, the data involved, and any statutory exceptions. A deletion or opt-out request is not the same as a demand that an underlying government record be erased.

Build an evidence trail

Record the provider, profile or account URL, request route, date submitted, information supplied, response, and re-check date. Keep copies locally where possible. A catalog entry or reachable URL does not prove that the provider has your record or that a request succeeded.

Reduce optional collection

Review app permissions, advertising controls, browser settings, and account privacy options. These measures can reduce some future collection, but they do not recall copies already held by a broker or remove public records automatically.

For a provider-by-provider starting point, use the source-backed broker directory and its recorded evidence boundary. OfflistMe can generate request drafts for selected catalog profiles; you review and send them from your own channel.


How to read current FTC enforcement

An enforcement complaint, proposed order, and final order have different procedural meanings. A case involving one company is evidence about that case, not proof about the whole industry.

The FTC's January 2024 X-Mode/Outlogic action addressed allegations and proposed restrictions involving sensitive location data; the April 2024 final order finalized that matter. The FTC later finalized orders involving Gravy Analytics and Venntel and Mobilewalla. Read the individual order or case file for the exact covered conduct, definitions, remedies, and exceptions.

These cases show that sensitive location practices can receive scrutiny under existing authority. They do not prove that every provider collects location data, that every data category is unlawful, or that an individual can obtain deletion simply by citing an FTC case.


Frequently Asked Questions

Did the FTC publish a dedicated 2024 data-broker report?

The dedicated FTC report cited on this page is the May 2014 Data Brokers: A Call for Transparency and Accountability report. The FTC has published later research and enforcement materials, but a 2014 report should not be relabeled as a 2024 report.

Can I use the FTC report to demand that a data broker delete my information?

You can reference it as historical context, but it does not itself create a deletion right. Identify the applicable law or provider policy accurately and use the current provider route. Keep the request and response as evidence.

What is the FTC doing to enforce existing law against data brokers?

The FTC can use existing authority, including the FTC Act's prohibition on unfair or deceptive acts or practices, against specific conduct. The cited location-data cases are examples; they do not establish a universal rule for every provider or request.

Where can I read the primary sources?

Read the FTC's 2014 data-broker report, the FTC Act, and the individual X-Mode/Outlogic final-order material, Gravy Analytics/Venntel, or Mobilewalla materials.


What the FTC report does and does not establish

Report evidenceSupported conclusionAvoid claiming
Broker responses and recordsThe study documented large-scale collection practicesThat every broker has the same inventory
Described sensitive categoriesCertain data types can be used for invasive profilingThat every listed category belongs to every person
Opt-out observationsExisting mechanisms can be difficult to find or useThat one report proves every request fails
RecommendationsThe FTC identified policy gapsThat recommendations are already federal law

Related Guides

Take back your privacy today

Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.

Review Provider Routes

Free to review provider routes · Optional one-time unlock from $9.00 · No subscription