Data Broker Removal Checklist 2026 (Step-by-Step)
Six steps to find relevant listings, choose the right provider or legal route, retain evidence, verify each target, and set a risk-based follow-up plan. The catalog count describes recorded workflows, not proof that every provider has your data or that a request will succeed.
What this checklist covers
6
Steps
1,000+
Recorded workflows
Varies
Preparation time
Varies
Provider response time
Check route
Legal scope
Risk-based
Follow-up plan
Before you start · Varies by number of providers and matching profiles
Find your data footprint
- Google your full name in quotes ("First Last"), note relevant people-search results on the first page
- Search your name on Whitepages, Spokeo, and TruePeopleSearch directly
- Search variations: maiden name, middle name, previous addresses
- Note which brokers show your home address, phone number, relatives, or workplace
- Take a screenshot for before/after comparison after the provider's stated process and when your review plan calls for it
Start with providers where you can verify a matching listing. Use the directory to expand deliberately; catalog inclusion is not proof that a provider has your data.
Week 1 · Varies by provider and verification
Opt out of Tier 1 people-search sites
- Submit opt-out requests to: Whitepages, Spokeo, TruePeopleSearch, Nuwber, Radaris, FastPeopleSearch, PeekYou, USPhonebook, AnyWho
- Use the contact method the provider currently requests and keep the submission or confirmation evidence. Do not assume an email route removes the need for verification
- State only the privacy right that actually applies to your request, or use the provider's voluntary route without implying statutory coverage
- Check for a confirmation email according to the provider's current process, including spam or junk folders
- Re-check the exact listing after the provider's stated process or applicable legal response period
These are practical starting points selected for this checklist, but visibility, route, verification, and response time vary. Removing one listing does not prove that unrelated sites or source records changed.
Weeks 1–4 · Submission time and completion vary
Opt out of Tier 2 data aggregators
- Submit opt-out requests to: Intelius, BeenVerified, Acxiom, 6sense, LexisNexis, Equifax Marketing Services, PeopleFinder, Zabasearch
- Processing, verification, and route requirements vary; use the provider's current first-party instructions and do not assume a fixed disappearance date
- Some providers may request additional verification or use a different channel; submit only what the current route requires
- A relationship between a provider and another site must be confirmed from current first-party or official evidence; one request does not automatically cover a related brand
- A suppression request may not erase every underlying copy or prevent future matching; re-check the exact source when the provider's guidance or your risk plan calls for it
Treat each provider and related brand as a separate target unless the current request language clearly defines a shared scope.
When a legal or centralized route fits · Depends on the request, provider, jurisdiction, and verification
Use applicable legal or centralized routes carefully
- Review current California and Vermont registry entries and use the applicable official route; registration, eligibility, and request scope can change.
- For a covered California deletion request, the California Attorney General describes a 45-calendar-day response period and a possible notified 45-day extension; check the current official guidance and exceptions
- Keep the submission date, receipt or confirmation, verification record, and source of the legal deadline
- California residents can review the official DROP platform. Starting August 1, 2026, registered brokers must access DROP requests at least every 45 days, while status updates may take up to 90 days; check the live platform for current status and scope
- Do not assume a privacy law applies to a person or provider solely because the provider is a broker or is located in California; eligibility and exceptions depend on the request and facts
- If a provider does not respond, use the current provider, regulator, or complaint route that fits the jurisdiction and request; a deadline is not proof of deletion
California DROP and a provider-specific request are different routes. Confirm eligibility, scope, and current instructions before sending; neither route proves that unrelated copies or public records changed.
After the provider's stated process · Varies by number of providers and results
Verify removal actually happened
- Re-search your name directly on Whitepages, Spokeo, TruePeopleSearch, and Radaris
- Re-run your original Google search, check if the people-search pages still appear
- If a source page changed but an old search result remains, review Google's current eligible personal-information or outdated-content process. Do not rely on a fixed cache interval
- Use Google's current personal-information or outdated-content tool when the result fits its criteria; a search-result change does not delete the source page
- If the exact profile remains or the provider has not responded, preserve the evidence and use the provider's current follow-up or complaint route. Do not assume a reminder or re-submission will produce a particular result
- If the route allows a new request, document why you are resubmitting and follow the current provider instructions
- Document any non-compliant brokers (name, submission date, deadline date) for complaint filing
A page removed from a provider may remain in search results until the search engine re-crawls it. A stale result does not by itself prove that the provider rejected the request; check the source page and the provider response separately.
Ongoing · Set a reminder that fits the provider, source, and risk plan
Set your re-run schedule
- Choose a re-check interval based on the provider's stated process, the sensitivity of the exposure, and whether a new source event occurred; no universal 3- or 6-month schedule is established here
- Re-check after a move, name change, new public filing, job or business change, or another event that may create new source data when that is relevant to your situation
- Re-check sooner when a new listing appears or a provider confirms a changed scope
- For higher-risk situations, consider a documented safety plan and appropriate professional or local support; broker removal alone is not a guarantee of safety
- Use a one-time pass only when you choose to prepare another request batch; it does not create automatic monitoring
Data sources and provider refresh behavior vary. Treat recurring review as a risk-based maintenance decision, not a universal timetable or guarantee.
Check the current official route before sending
Use this page to organize the work, then confirm the live instructions for the specific provider, jurisdiction, and request. Official guidance controls when it differs from a checklist summary.
- California Attorney General CCPA guidance ↗ — review covered-business scope, exceptions, verification, and response-period rules for a California request.
- California Privacy Protection Agency FAQs ↗ — confirm current request-specific timing, scope, and exceptions.
- California DROP ↗ — review the official California resident platform, its current eligibility, participating-broker scope, and status instructions.
- OfflistMe source-backed directory → — use a recorded workflow as a research starting point, then verify the provider's live route and your matching listing.
Use a local request-draft workflow when it fits
OfflistMe lets you select recorded provider workflows and prepares privacy-rights-oriented request drafts in the browser. You review each destination and send or submit through the current provider route. Response timing, verification, eligibility, and any payment terms vary; the catalog count is not coverage or outcome proof. The product does not receive government ID.
Frequently asked questions
How long does it take to complete the data broker removal checklist?
Initial setup depends on the number of relevant providers and their verification steps. Using OfflistMe, you can prepare request drafts in your browser; you then review, send, and follow each provider's current process. Response time depends on the provider, request, and law that applies.
How often should I repeat the data broker removal checklist?
There is no universal interval. Re-check based on each provider's current process, the sensitivity of the exposure, new source events, and your risk plan. Keep a dated record; a calendar schedule is a planning choice, not a provider guarantee.
What is the fastest way to complete data broker removal?
OfflistMe can prepare request drafts for recorded workflows in your browser. You review each destination and send or submit through the current provider route; provider routes, verification, eligibility, and response times vary. This may reduce manual research, but it does not establish a universal completion time or guarantee a particular outcome.
