Skip to main content
Privacy Education
•11 min read

What Is a Data Broker? How They Get Your Info and How to Stop Them

A source-reviewed explanation of data brokers, people-search sites, public and commercial data sources, conditional privacy rights, and provider-specific removal options.

Rahul Kandoriya
Written byRahul Kandoriya·Last updated August 25, 2026
What Is a Data Broker? How They Get Your Info and How to Stop Them
What Is a Data Broker? How They Get Your Info and How to Stop Them
Coverage scope: The OfflistMe catalog currently records 1,000+data-broker workflows. Paid access lets you select workflows at once; you review and send or submit the generated requests, while provider eligibility and outcomes remain outside OfflistMe's control.

If a search for your name produces an address, phone number, relatives, or background details, the page may be a people-search site or another kind of information intermediary. A search result alone does not prove which company collected the information or how it got there.

The Federal Trade Commission describes data brokers as companies that collect consumer information from commercial, government, and other publicly available sources, often without a direct relationship with the people described. They may combine records, make inferences, and share or sell information for purposes such as marketing, fraud prevention, or other business uses. People-search sites are one type of data broker, but the term also covers businesses that do not publish a public name-search page.

There is no single universal definition, provider list, market-size figure, or deletion rule that applies to every company called a data broker. This guide separates what regulators have described, what a particular provider says it does, and what you can verify about your own records.

Key points

  • A data broker may combine information from public records, commercial sources, online activity, or other data suppliers. The exact sources vary by provider and jurisdiction.
  • People-search pages, marketing datasets, professional lead databases, identity-verification products, and fraud-prevention tools are different products even when they are all described as data brokerage.
  • A public record is not automatically inaccurate, unlawful, or removable. A broker copy can also be wrong, outdated, or matched to the wrong person.
  • Privacy rights depend on the person, the data, the business, the jurisdiction, and statutory exceptions. A general guide cannot promise deletion for everyone.
  • Opt-out work is provider-specific. Removing one page does not control a government record, another broker, a search index, or a copy held by a different organization.

What a data broker does

At a high level, a broker can receive or collect information, match it to an individual or household, enrich it with other data, and make a product or service available to a customer. Some businesses sell reports directly to consumers. Others provide data through an API, a marketing list, an identity product, an analytics service, or a risk tool that ordinary consumers never see.

Request Drafting

Tired of dealing with data exposure?

Choose relevant provider workflows, review the generated drafts in your browser, and send or submit each request yourself. Matching, eligibility, and provider requirements still need checking.

Review Removal Options Free for selected workflows · No opt-out profile stored · No card needed

The FTC's 2014 report found that data brokers studied by the agency collected information from many online and offline sources and that information could pass through multiple layers of brokers. That report is useful background, but it is not a current inventory of every company, practice, or product. Provider privacy notices, terms, regulatory filings, and current opt-out instructions should control a claim about a particular business.

Common categories

These categories overlap, and a company may operate more than one type of product:

CategoryDescription in this guide
People-search servicesName-search pages or reports that may combine public records with information from other data suppliers
Marketing and advertising data providersAudience segments, identifiers, inferred interests, or measurement products used by businesses; collection and sharing practices differ widely
Professional and business-contact databasesInformation about companies and professional contacts used for sales, recruiting, or business research; a business-contact record is not necessarily the same product as a consumer people-search profile
Identity, fraud, and risk providersData used to authenticate an applicant, prevent fraud, or assess a transaction; some products may fall under sector-specific rules, including the Fair Credit Reporting Act, depending on their purpose and use
Location and device-data providersData connected to devices or movement patterns; location data can be sensitive, and regulators have challenged particular collection or sale practices

The examples above are categories, not a certification that every named company belongs to one legal category in every context. A company can have multiple subsidiaries, products, data sources, and privacy routes.

Where broker information may come from

Government and public records

Public-record availability varies by record type, state, county, agency, access rules, and the person's status. Depending on local law and the particular record, a broker may find information from property records, court dockets, business registrations, professional-license records, or other government sources.

Do not assume that every record is public everywhere. Voter-record access, address fields, criminal-history information, marriage records, and business-registration details can be restricted, redacted, delayed, or subject to a special request process. A public record may also be legally available while a particular use, disclosure, or matching practice raises a separate issue.

If the source is a government database, an opt-out from a people-search site will not change the source record. Look for the agency's correction, confidentiality, address-shielding, sealing, expungement, or safety program when one exists and when you qualify.

Commercial and first-party sources

A provider may receive information from businesses, publishers, data suppliers, loyalty programs, surveys, warranty registrations, public websites, or other commercial relationships. Whether a specific retailer, app, lender, or manufacturer shares information with a broker depends on its notice, settings, contracts, applicable law, and the facts of the interaction.

Avoid treating a purchase, form submission, or app permission as proof that a particular broker has your data. Verify the source through the provider's privacy notice, the profile itself, an access request, or another reliable record.

Online and device-related information

Public profiles, web pages, cookies, advertising identifiers, app events, and location signals can be used in different data products. The scope can change with a person's settings, device, consent, browser controls, the provider's partners, and regional law. A reference to a tracking technology does not prove that a particular website sent your identity to a particular broker.

Sensitive location-data enforcement illustrates why the details matter. The FTC's actions involving Mobilewalla and Kochava addressed allegations and orders concerning particular practices, products, and consent requirements. Those cases support careful scrutiny of sensitive location data; they do not establish that every advertising or analytics provider collects or sells the same information.

Other data suppliers

A provider may license or purchase information from another provider. This can make it difficult to trace the first source or correct a record at its origin. It also means that one opt-out may not stop a later profile match made from a different source.

What a profile may contain

Depending on the product, a record may contain some combination of:

  • names, aliases, or approximate age;
  • current or historical addresses;
  • phone numbers or email addresses;
  • possible relatives, household links, or associates;
  • property, business, or professional information;
  • public court or government-record references;
  • social-profile links or public content;
  • inferred interests, demographic segments, or household characteristics; and
  • identifiers used to match records across systems.

This is not a universal profile template. A page can be incomplete or wrong, and two companies may show different results for the same person. Do not publish a sensitive value simply to demonstrate that a broker has it.

Who may use broker data

Potential customers and use cases differ by product. Examples can include advertising and measurement, business outreach, fraud prevention, identity verification, background research, or consumer-facing people searches. Whether a company may use a report for employment, housing, credit, or insurance decisions can trigger different legal requirements; a generic “data broker” label does not answer that question.

The Fair Credit Reporting Act is relevant to certain consumer reports and uses, but not every people-search page or marketing list is a consumer report under the FCRA. If a decision about credit, employment, housing, insurance, or another regulated transaction relied on information about you, ask the decision-maker which reporting company and legal process were involved.

The privacy risk is not limited to intentional misuse. A wrong match, exposed address, stale phone number, or inferred relationship can create unwanted contact, identity-theft risk, harassment, or an inaccurate decision. These are risk considerations, not proof that a particular broker caused a particular event.

What rights may apply

The United States does not have one general federal law that gives every person a universal deletion right against every data broker. Federal rules can apply by sector or product, and state privacy laws differ in scope, exemptions, definitions, and remedies.

California

The California Consumer Privacy Act overview explains rights that may apply to eligible California consumers, including deletion and choices about sale or sharing, subject to exceptions and verification. The California Delete Act also created a centralized deletion mechanism known as DROP. The California Privacy Protection Agency's current data-broker guidance explains the platform, registered-broker obligations, and the timing of access and processing rules. Check the live CPPA and privacy.ca.gov instructions before relying on the platform or a date.

DROP is not a guarantee that every company or every record will be removed. It is a legal mechanism with definitions, exemptions, verification rules, and processing requirements. If a broker denies a request, read the reason and appeal or use the route available under the law that applies to you.

Other U.S. states

Many states have enacted privacy laws with some combination of access, correction, deletion, sale or sharing opt-out, targeted-advertising opt-out, sensitive-data controls, appeals, or authorized-agent rules. Eligibility can depend on residency, thresholds, the business's role, the data type, and exceptions. Do not copy a California deadline or form into a request for a different state without checking that state's current law and the provider's instructions.

European and other jurisdictions

Article 17 of the EU General Data Protection Regulation can provide a right to be forgotten when the regulation applies, but the right has conditions and exceptions. A provider's location alone does not determine whether the GDPR applies. Identify the controller, legal basis, jurisdiction, verification route, and response or complaint options before making a legal conclusion.

A practical removal workflow

1. Identify the exact source

Record the page URL, provider name, profile name, visible fields, matching clues, and date checked. Avoid sending more information than the provider needs to locate the record. Do not assume a similarly named person is you.

2. Protect the source record where possible

If the exposure originates in a public agency, professional register, business filing, court record, social account, or website you control, review that source's own correction or privacy options. Source changes can reduce future republishing, but they do not automatically erase existing copies.

3. Use the provider's current route

Open the provider's current privacy or opt-out page from its own domain. Check whether it requires an email confirmation, profile URL, identity matching, a code, an authorized agent, or a limited request scope. Save confirmation details without exposing them in a public post.

4. Use a legal request only when it fits

If you qualify for a statutory right, state the applicable law accurately and answer the provider's verification questions. A voluntary opt-out can be available even when a statutory deletion right does not apply. Do not cite a law merely to make a request sound stronger.

5. Verify and follow up

Check the exact profile again after the provider's stated process. A missing page can reflect a temporary error or a different matching result. Recheck important exposures based on the provider response and your risk, not on a universal “every few months” promise.

OfflistMe provides a browser-local, user-reviewed way to examine recorded provider workflows and prepare drafts. You choose the provider routes, review the information, and send or submit requests yourself. Provider verification, eligibility, acceptance, timing, and downstream copies remain separate.

Frequently asked questions

Is every people-search site a data broker?

The FTC describes people-search sites as a type of data broker. Legal definitions can vary by statute and product, so use the provider's actual practices and the applicable law for a specific request.

Can a data broker sell my information legally?

Legality depends on the information, source, use, jurisdiction, notice, consent, contract, and exceptions. Public availability does not answer every legal question, and an opt-out right does not necessarily prohibit every business activity.

Can I remove a government record from a broker?

You may be able to remove or shield a broker copy without changing the underlying government record. For the source itself, look for the agency's correction, sealing, expungement, address-confidentiality, or safety procedure and verify that you qualify.

Why can a profile return after an opt-out?

A provider may receive a new source record, match a different record, update its database, or publish information supplied by another organization. A returning profile does not prove that the first request failed. Save the earlier confirmation and use the provider's current follow-up route.

Are data brokers the same as credit bureaus?

No. Credit reporting agencies operate under rules that can include the FCRA for covered consumer reports and uses. A company may also have separate marketing or identity products, but the legal analysis depends on the product and use rather than the company name alone.

Does one request remove my information everywhere?

No. A request is normally limited to the provider and scope identified in the request. Search engines, public agencies, other brokers, social platforms, archives, and downstream customers may have separate records and processes.

Official sources to start with

For a provider-by-provider workflow, review the complete data-broker opt-out guide and the people-search removal guide. The goal is a verifiable, source-specific request—not a promise that an entire internet profile can be erased in one step.

Take back your privacy today

Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.

Review Provider Routes

Free to review provider routes · Optional one-time unlock from $9.00 · No subscription