Data Broker Case Studies
Data-broker and personal-data exposure can create real safety risks. These documented, sourced cases involve stalking, murder, swatting, targeted harassment, or regulatory concern; each source states what is established and what remains uncertain. Each case ends with a practical privacy lesson rather than a promise that one removal request prevents harm.
Amy Boyer: the murder that put data brokers on trial
What happened
Liam Youens, who had been obsessed with Amy Lynn Boyer since high school, paid the online investigation service Docusearch for her Social Security number and then her workplace address. Docusearch obtained the work address through a pretextual ("pretexting") phone call. On October 15, 1999, Youens drove to Boyer’s workplace and fatally shot her as she left, then killed himself.
The role of data brokers
Boyer had no relationship with Docusearch and no way to know it was assembling and selling her identifying information. The broker sold her SSN and work location to a paying stranger without verifying his intent, the exact business model that people-search and data-broker services still run on.
What changed
In Remsburg v. Docusearch (2003), the New Hampshire Supreme Court recognized a duty of reasonable care in the circumstances before it because criminal misuse of sold personal data was foreseeable. Congress did not enact the original S. 2554 proposal as introduced, but it did enact a modified section titled "Amy Boyer’s Law" as section 635 of Public Law 106-553 in 2000; its text included exceptions and delayed application, so do not describe it as a blanket ban on all Social Security number use.
The removal lesson
The case shows why a broker-held work address or identifier can create safety risk when disclosed to a stranger. Removing a matching listing may reduce one lookup path, but it does not recall copies held elsewhere or establish that a threat actor used a particular source.
How to protect your personal information online →Sources: EPIC: Remsburg v. Docusearch (Amy Boyer case) · Remsburg v. Docusearch, 149 N.H. 148, 816 A.2d 1001 (N.H. 2003) · New Hampshire Supreme Court opinion: Remsburg v. Docusearch (Feb. 18, 2003) · Congressional Record: S. 2554, Amy Boyer’s Law (May 15, 2000) · Public Law 106-553, Appendix B, section 635: Amy Boyer’s Law
Location brokers tracked visits to clinics, shelters, and places of worship
What happened
The FTC brought actions involving Gravy Analytics / Venntel and X-Mode Social / Outlogic. The agency alleged that the companies collected or used precise location data and placed sensitive locations or audience segments at risk. The allegations, orders, and affected data differ by case; read the cited FTC materials rather than combining them into one universal model.
The role of data brokers
Precise location can reveal visits to places such as medical facilities, houses of worship, or shelters. An app or advertising SDK may be involved without the user having a direct relationship with the named data broker, but the collection path must be established for the specific case.
What changed
The FTC finalized orders in April 2024 for X-Mode Social / Outlogic and in January 2025 for Gravy Analytics / Venntel, prohibiting specified sales or uses of sensitive location data and requiring case-specific deletion or compliance steps. The complaints’ underlying allegations and the orders’ precise terms differ by case; they do not establish that every location-data company uses the same practice or that a phone setting removes historical data.
The removal lesson
Review app permissions, advertising controls, and the current privacy choices offered by the relevant app or platform. A device setting or broker request can address one layer of collection; it does not prove that every downstream copy or independent source changed.
Location data brokers explained →A judge’s home address, a murdered son, and Daniel’s Law
What happened
In July 2020, a disgruntled attorney posing as a delivery driver arrived at the New Jersey home of U.S. District Judge Esther Salas. He shot and killed her 20-year-old son, Daniel Anderl, and wounded her husband. The attacker had compiled a dossier on Judge Salas, including her home address, which was readily available online.
The role of data brokers
The attacker had access to the judge’s home address and other identifying information. The cited sources support the safety significance of exposed judicial information, but they do not establish that a particular people-search site supplied every item in the dossier.
What changed
New Jersey enacted Daniel’s Law for defined covered persons, covered information, and qualifying written requests; the current statute and amendments control its scope and timing. Congress later enacted the federal Daniel Anderl Judicial Security and Privacy Act for the federal judiciary, but that federal program is not the same as a nationwide self-service broker deadline.
The removal lesson
Address privacy is a legitimate safety concern. Covered people should use the current statute or program that applies to them; everyone else can review provider-specific suppression routes, source controls, and safety-planning resources without assuming Daniel’s Law applies.
What is Daniel's Law? →Sources: U.S. Courts: Daniel Anderl Judicial Security and Privacy Act overview · New Jersey Daniel’s Law (P.L. 2020, c. 125) · New Jersey framework (P.L. 2021, c. 371) · New Jersey amendment (P.L. 2023, c. 113) · Public Law 117-263, div. E, title LIX, subtitle D: Daniel Anderl Judicial Security and Privacy Act
The swatting epidemic runs on people-search addresses
What happened
Recent reporting and prosecutions describe swatting and doxxing incidents involving public officials, public figures, and other targets. The scale, source of the address, and legal consequences vary by case; the sources below provide context rather than a complete incident census.
The role of data brokers
A published address can make a target easier to locate, but it is not established that people-search sites supplied the address in every swatting case. Treat source-specific removal as one preventive measure alongside account security, platform reporting, and a safety plan.
What changed
States and federal prosecutors have used different criminal statutes and sentencing theories for swatting-related conduct. A legislative response or prosecution does not establish a universal address-removal duty for every publisher.
The removal lesson
If swatting or doxxing is a credible concern, document the threat, contact appropriate authorities or an advocate, and review the exact public listings and account controls involved. Removing a provider listing may reduce one lookup path but cannot undo information already obtained.
Remove your address and phone from data brokers →Targeting reproductive-health workers with broker data
What happened
Reporting in 2024 documented concerns that anti-abortion activists and harassers could use readily available personal information, including home addresses and phone numbers, to target reproductive-health-care workers. The source describes a safety risk; it does not establish one identical broker pipeline for every worker.
The role of data brokers
A published address or contact detail can make a worker easier to locate. The relevant source, publisher, and remedy must be checked for the specific person rather than inferred from the existence of a broker ecosystem.
What changed
The reporting contributed to calls for stronger address-confidentiality protections and source-specific privacy measures for health-care workers. It does not establish that a particular clinic or provider adopted a uniform data-removal program.
The removal lesson
For people facing a targeted safety risk, combine an advocate-informed safety plan with review of exact public listings, applicable address-confidentiality programs, and provider-specific opt-outs. No single measure is a universal safety solution.
Address Confidentiality Programs by state →Generate requests in under 60 seconds
Generate Your Opt-Out Requests
One-time from $9
