Privacy Glossary
Authoritative, plain-language definitions of the terms used in US and EU data-privacy law, data-broker opt-out processes, and personal-security practices. Updated June 2026.
1
192.com
The dominant UK people-search directory (~700 million records), compiled from the open electoral register, Companies House, and Land Registry data.
192.com is the UK's largest people-search and business-directory service, holding roughly 700 million residential and business records. It assembles its profiles from the open (edited) electoral register, Companies House director filings, HM Land Registry data, and birth/death/marriage records for England and Wales. You can remove yourself using 192.com's online removal-request page, which normally clears your electoral, Companies House, and phone-directory records from the platform within about 48 hours. To stop being re-listed, pair the 192.com removal with an open-register opt-out, otherwise your record returns when 192.com refreshes from the register.
Source: 192.com (sources & opt-out)
See also: Open Electoral Register, People-Search Site, Data Broker
A
Authorized Agent
A third party authorized by a consumer to make privacy requests on their behalf, as recognised under CCPA and similar state laws.
Under CCPA and many state privacy laws, consumers may designate an authorized agent to make privacy requests on their behalf. The agent must provide signed permission, and the business may verify the consumer's identity. Subscription data-removal services (DeleteMe, Incogni, OneRep) typically operate as authorized agents. First-party requests avoid the agent framework entirely.
See also: First-Party Request
Automated Decision-Making
Decisions made solely by algorithmic processing, without meaningful human involvement, that have significant effects on an individual.
Automated decision-making refers to decisions produced entirely by algorithms that materially affect an individual's employment, credit, insurance, housing, healthcare, or similar. Under GDPR Article 22, individuals have a right not to be subject to solely automated decisions (with exceptions). Minnesota's MCDPA allows a consumer to demand a human review of a solely automated decision. California is developing ADMT (Automated Decisionmaking Technology) regulations.
See also: Profiling
Address Confidentiality Program
A state-administered program that lets qualifying individuals use a substitute address for government records and mail.
An Address Confidentiality Program (ACP) lets qualifying individuals, typically survivors of domestic violence, sexual assault, stalking, trafficking, and in some states sexually exploited persons, reproductive-health providers, judges, and law enforcement, use a substitute address administered by the state. Mail is forwarded to the actual address confidentially. All 50 states have some form of ACP. Eligibility and coverage vary; ACP addresses are kept confidential in court records, motor-vehicle records, voter registration, and other government databases.
See also: Daniel's Law
Auskunftssperre
A German residents'-registry information block (§51 Bundesmeldegesetz) that fully hides your registered address where disclosure could endanger you.
An Auskunftssperre is a full information block on Germany's residents' registry (Melderegister) under §51 of the Bundesmeldegesetz (BMG). When granted, the registration authority will not disclose your registered address to third parties where doing so could endanger your life, health, freedom, or similar interests, the tool most relevant to stalking victims and at-risk professions. It is free, lasts two years, and is renewable. You apply at your local Bürgeramt/Meldeamt. The Auskunftssperre is the strongest of Germany's registry-suppression tools; for ordinary marketing suppression, the narrower Übermittlungssperre is used instead.
Source: §51 Bundesmeldegesetz (gesetze-im-internet)
See also: Übermittlungssperre, Melderegister, Address Confidentiality Program
B
Biometric Data
Measurements of physiological or behavioural characteristics used to identify an individual, including fingerprints, face geometry, voiceprints, and retina scans.
Biometric data includes both physiological identifiers (fingerprints, face geometry, iris/retina, DNA, voiceprint) and behavioural identifiers (gait, keystroke dynamics). Illinois's BIPA treats biometric data as specifically protected with a private right of action and statutory damages ($1,000-$5,000 per violation). Texas, Washington, and several other states also regulate biometric data. GDPR treats biometrics as special category data (Article 9).
See also: Sensitive Personal Information, BIPA
BIPA
Illinois Biometric Information Privacy Act, the most consequential US biometric-data law, featuring a private right of action with substantial statutory damages.
Illinois's Biometric Information Privacy Act (740 ILCS 14, 2008) requires written informed consent before collecting biometric identifiers and grants a private right of action for violations, with statutory damages of $1,000 per negligent violation or $5,000 per intentional violation. BIPA has produced nine-figure settlements including Facebook ($650M) and Clearview AI ($51.7M class settlement with Illinois residents).
See also: Biometric Data, Private Right of Action
Bloctel
France's national do-not-call register; telemarketers must screen their lists against it before calling.
Bloctel (bloctel.gouv.fr) is France's official telemarketing opt-out register. Once you enroll your numbers, companies are legally required to scrub their calling lists against Bloctel, re-checking at least monthly, before running prospecting campaigns; calling a registered consumer can draw CNIL or DGCCRF enforcement. Bloctel is the French counterpart to a national do-not-call list and the first step French residents take against unsolicited sales calls, complementing the absolute, free GDPR right to object to commercial prospecting at any time.
Source: Bloctel (official)
See also: Liste Rouge, Do Not Call Register (Australia), Opt-Out
BRP Geheimhouding
A Dutch confidentiality request that stops your municipality from sharing your residents-database details with certain third parties.
The BRP (Basisregistratie Personen) is the Dutch municipal residents' database. You cannot opt out of being registered, your gemeente (municipality) is legally obliged to record you, but you can request "geheimhouding" (confidentiality), which blocks the municipality from sharing your data with non-obligated third parties such as churches, sports associations, and other non-government bodies. Government bodies that are legally entitled to the data still receive it. Geheimhouding is the standard Dutch step for limiting downstream sharing of your registered details and is paired with KvK address shielding for residents who also run a business.
Source: Autoriteit Persoonsgegevens: privacy rights and the BRP
See also: KvK Address Shielding (Afschermen), Suppression List, Public Records
C
CCPA
California Consumer Privacy Act, the first comprehensive US state privacy law, granting California residents rights to know, delete, and opt out of the sale of their personal information.
The California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.), effective January 2020 and amended by the CPRA (effective January 2023), grants California residents the right to know what personal information businesses have collected, the right to delete that information, the right to opt out of the sale or sharing of personal information, and the right to correct inaccurate information. Data brokers must respond to verifiable deletion requests within 45 days, extendable once to 90 days. The California Privacy Protection Agency (CPPA) enforces CCPA alongside the AG.
Source: California Civil Code § 1798.100
See also: CPRA, GDPR, Data Subject Request (DSR), CCPA Delete Act
CPRA
California Privacy Rights Act, the 2020 voter-approved amendment to CCPA that created the California Privacy Protection Agency and added new consumer rights.
The California Privacy Rights Act (Prop 24, 2020) amended the CCPA effective January 2023. It added the right to correct inaccurate information, the right to limit the use of sensitive personal information, expanded the definition of "sale" to include "sharing," and created the California Privacy Protection Agency (CPPA) as an independent enforcement body. "CCPA/CPRA" is the combined current-state citation used in most legal and regulatory contexts.
See also: CCPA, Sensitive Personal Information
CCPA Delete Act
California SB 362, requires the California Privacy Protection Agency to build a universal deletion mechanism that propagates one request to all registered data brokers.
The California Data Broker Delete Act (SB 362, signed October 2023) requires the California Privacy Protection Agency to build and operate an accessible deletion mechanism. California consumers will be able to submit one request that automatically propagates to every broker on the state's Data Broker Registry. The mechanism (DROP) launches in 2026 per CPPA rulemaking. Once live, it dramatically reduces the per-broker work of California residents.
Source: California SB 362
See also: CCPA, Data Broker, DROP (Delete Request and Opt-out Platform)
Cure Period
A statutory grace period during which a business may remedy a privacy-law violation before enforcement action.
Most US state privacy laws originally included a 30-60 day cure period during which businesses could remedy alleged violations before the AG could fine them. Several states have now sunset these cure periods (California in 2023, Colorado and Connecticut in 2025). Texas and Indiana still have cure periods. The cure period affects how aggressively you should escalate a non-responsive broker, in cure-period states, expect the AG to require notice first.
See also: Private Right of Action
Controller
The entity that determines the purposes and means of processing personal data, as defined in GDPR and adopted by most US state privacy laws.
Under GDPR and most US state privacy laws (VCDPA, CPA, CTDPA, OCPA, TDPSA, NJDPA, etc.), a "controller" is the entity that determines why and how personal data is processed. Controllers bear the primary compliance burden. The counterpart is a "processor" (GDPR) or "service provider" (CCPA), which processes data on behalf of the controller. A data broker is typically both controller and processor depending on which data streams are considered.
See also: Processor
CPPA
California Privacy Protection Agency, the independent agency created by CPRA to enforce California privacy law and administer the Data Broker Registry.
The California Privacy Protection Agency (CPPA) is the independent US state privacy regulator. It enforces CCPA/CPRA alongside the AG, administers the California Data Broker Registry, and is building the statewide Delete Act universal deletion mechanism (DROP). Consumer complaints against specific data brokers should typically go to the CPPA rather than to the California AG.
Source: California Privacy Protection Agency
See also: CCPA, Data Broker Registry, CCPA Delete Act, DROP (Delete Request and Opt-out Platform)
Credit Header Data
The identifying portion of a credit report (name, aliases, addresses, SSN, phone, DOB), sold by credit bureaus largely outside FCRA deletion rights.
Credit header data is the top, non-financial section of a credit file: your name and past names, current and former addresses, Social Security number, date of birth, and phone numbers. Because it is not the "creditworthiness" portion of the report, bureaus have long sold credit header data to data brokers, identity-verification firms, and skip tracers without the full restrictions of the Fair Credit Reporting Act. It is a primary reason your address history is so widely available, and a focus of recent CFPB rulemaking aimed at bringing brokers under FCRA.
See also: Consumer Reporting Agency (CRA), Skip Tracing, Data Broker
Consumer Reporting Agency (CRA)
An entity that assembles consumer information into reports used for credit, employment, housing, or insurance decisions, regulated under the FCRA.
A consumer reporting agency (CRA) compiles "consumer reports", information bearing on creditworthiness, character, or reputation, used to make eligibility decisions about credit, jobs, housing, or insurance. The big three (Equifax, Experian, TransUnion) are CRAs, but so are many background-check companies. CRAs are regulated by the Fair Credit Reporting Act (FCRA), which gives you the right to access your report, dispute errors, and limit certain uses. Many people-search brokers carefully position themselves as non-CRAs to avoid FCRA, which is also why they must add disclaimers that their data can't be used for FCRA purposes.
See also: Credit Header Data, Data Broker
D
Data Broker
A company that collects personal information about consumers and sells, licenses, or shares that information with third parties.
A data broker aggregates personal information from public records, online activity, commercial transactions, and other sources, then sells, licenses, or shares that information. Major categories include people-search sites (Whitepages, Spokeo), background-check providers (BeenVerified, Intelius), B2B data providers (ZoomInfo, Apollo), and marketing-data aggregators (Acxiom, Epsilon). California, Vermont, Texas, and Oregon maintain public data-broker registries.
Source: California Data Broker Registry
See also: People-Search Site, CCPA, CCPA Delete Act
Data Subject Request (DSR)
A formal request from a consumer to a business to access, correct, delete, or port their personal data.
A data subject request (DSR) is the formal mechanism by which a consumer exercises their rights under a privacy law. Under GDPR these are called "data subject access requests" (DSAR); under CCPA they are called "verifiable consumer requests." DSRs typically require the consumer to identify themselves and specify the request type (access, delete, correct, port, opt-out). Businesses must respond within mandated timeframes (45 days under most US state laws, 30 days under GDPR).
See also: CCPA, GDPR, Data Subject Access Request (DSAR)
Data Subject Access Request (DSAR)
The GDPR term for a request by an individual to obtain a copy of the personal data an organization holds about them.
A data subject access request (DSAR) is the GDPR-specific form of a data subject request focused on access, the right to obtain confirmation that your data is being processed and a copy of it, along with information about its purpose, recipients, and retention. Controllers must usually respond within one month (extendable to three for complex requests) and generally cannot charge a fee. In US state law the rough equivalent is the CCPA "right to know." DSAR is often the first step before a deletion request, because it reveals what an organization actually holds.
See also: Data Subject Request (DSR), Right of Access, GDPR
Daniel's Law
A category of state statutes requiring data brokers to expedite removal of home address information for judges, prosecutors, law enforcement officers, and related family members.
Daniel's Law refers to statutes modelled on New Jersey's original law (P.L. 2020, c. 125), passed after the 2020 murder of Daniel Anderl at the home of his mother, federal Judge Esther Salas. The statute requires data brokers to remove home address information within 10 business days upon request from a covered person. California, Colorado, Maryland, and a growing number of states have Daniel's Law-equivalents. The federal Daniel Anderl Judicial Security and Privacy Act (2022) covers federal judges and court staff nationally.
See also: Data Broker, SWATting, Doxxing
DROP (Delete Request and Opt-out Platform)
California's state-run platform that lets a resident send one deletion request that every registered data broker must honor.
DROP (Delete Request and Opt-out Platform) is the mechanism the California Privacy Protection Agency built to deliver on the Delete Act. A verified California resident submits a single request through DROP, and every data broker on the state registry must check the platform at least once every 45 days and delete the matching person's data. Consumers can submit requests starting January 1, 2026, and brokers must begin processing them by August 1, 2026. DROP is the first true one-request-deletes-everywhere system in US law, though it covers only California residents and only registered brokers.
Source: California Privacy Protection Agency, DROP
See also: CCPA Delete Act, Data Broker Registry, CPPA
Data Broker Registry
A state-maintained public list of registered data brokers and their registration details.
Data broker registries exist in California (CPPA), Vermont (AG), Texas (SOS), and Oregon (AG). California's is the most comprehensive, with 500+ registered brokers. Registration requires brokers to disclose their identity, contact information, and whether they collect and sell specific categories of personal information. Failure to register carries per-day fines. California's registry feeds into the CCPA Delete Act universal deletion mechanism.
Source: California CPPA Data Broker Registry
See also: Data Broker, CCPA Delete Act
Data Breach
An unauthorised acquisition of personal information, typically triggering statutory notification requirements.
A data breach is an unauthorised acquisition, access, use, or disclosure of personal information. All 50 US states have breach-notification statutes with varying thresholds and deadlines (typically 30-90 days from discovery). Under GDPR, controllers must notify the supervisory authority within 72 hours. Some breaches trigger a private right of action. CCPA, for instance, allows individuals to sue for breaches of non-encrypted personal information.
Digital Footprint
The trail of data an individual generates through online activity, public records, and commercial transactions.
A digital footprint is the aggregate of data that identifies, locates, or profiles an individual, collected through browsing, purchases, social media, court filings, property records, employment records, and other sources. Reducing your digital footprint is the practical goal of data-broker opt-out, social-media hygiene, and cautious use of online services.
See also: Data Broker, Opt-Out
Doxxing
The act of publicly revealing personally identifying information about an individual, typically without consent and often as part of a harassment campaign.
Doxxing (sometimes spelled "doxing") is the public release of personally identifying information, home address, phone number, employer, family members, typically as a prelude to harassment, intimidation, or physical confrontation. Several states (California AB 1950, Texas, and others) have anti-doxxing statutes. Data-broker cleanup reduces the raw material available for doxxing campaigns.
See also: Data Broker, Daniel's Law, SWATting
Data Minimization
The principle that a business should collect, process, and retain only the personal data necessary for its specified purpose.
Data minimization is enshrined in GDPR Article 5(1)(c) and adopted in varying strength across US state privacy laws. Maryland's MODPA has the strongest US articulation: controllers must not collect or process personal data beyond what is "reasonably necessary and proportionate" to the specified purpose. Minimization reduces breach risk and compliance burden; lack of minimization is a common basis for enforcement action.
See also: GDPR, CPRA, Purpose Limitation
Data Broker Registration
A statutory requirement that data brokers register with the state, disclosing identity, data categories, and contact information.
California, Texas, Vermont, and Oregon require data brokers to register annually. California's CPPA maintains the most public and comprehensive registry, including over 500 brokers. Registration details include business name, contact information, data categories collected, whether the broker collects children's data, and (in some states) gross revenue from data sales. Failure to register triggers civil penalties per day of non-compliance.
See also: Data Broker Registry
Data Enrichment
Augmenting a record you already have (like an email) with additional attributes purchased or inferred from other sources.
Data enrichment (or "data append") takes a sparse record, say, an email address or a name and zip code, and fattens it with extra fields: phone number, home address, age, estimated income, household members, interests, and more. Brokers and marketing platforms sell enrichment as an API or batch service. Enrichment is how a single data point you hand over (an email at checkout) becomes a full profile, and why minimizing what you share matters even when it seems harmless.
See also: Identity Resolution, Data Broker, Profiling
Device Fingerprinting
Identifying a device by the unique combination of its settings and characteristics, without cookies or a stored ID.
Device fingerprinting derives a stable identifier from attributes your browser or device reveals, screen size, fonts, time zone, GPU, OS version, language, and dozens more, which together are usually unique enough to single you out. Because it needs no stored cookie or ID, fingerprinting survives cookie deletion and "private" browsing, making it a favored tracking method as cookies decline. It feeds identity resolution and is largely invisible to users; anti-fingerprinting features in browsers like Brave, Firefox, and Tor are the main defense.
See also: Mobile Advertising ID (MAID), Identity Resolution, Surveillance Advertising
Do Not Call Register (Australia)
Australia's national telemarketing opt-out list, run by ACMA, that registered numbers can use to block most unsolicited sales calls.
The Do Not Call Register (donotcall.gov.au) is Australia's national opt-out list for telemarketing and marketing faxes, administered by the Australian Communications and Media Authority (ACMA). Once you register your home or mobile number, most telemarketers are prohibited from calling it, and registration does not expire. It is the first practical step Australians take against unsolicited sales calls and complements the Privacy Act's APP 7 direct-marketing opt-out, which any organisation must honour on request.
Source: Do Not Call Register (Australia)
See also: Bloctel, Statutory Tort for Serious Invasions of Privacy, Opt-Out
F
First-Party Request
A deletion or access request sent directly by the consumer from their own email or identity, not through an intermediary.
A first-party request is one in which the consumer directly contacts the data broker or controller using their own email and identity, rather than using an agent or intermediary service. First-party requests avoid the verification overhead and possible rejection that third-party authorized agents sometimes face, and carry the strongest legal standing under CCPA and state laws. Tools like OfflistMe generate first-party request emails that the consumer sends from their own inbox.
See also: Authorized Agent, Zero-Data Architecture
G
GDPR
General Data Protection Regulation, the European Union's comprehensive data protection law governing personal data of EU/EEA residents.
The General Data Protection Regulation (Regulation EU 2016/679), effective May 2018, governs the processing of personal data of individuals in the EU and EEA. Key rights include access, rectification, erasure ("right to be forgotten," Article 17), restriction of processing, data portability, and the right to object. GDPR applies extraterritorially to any business processing EU residents' data. Violations carry fines up to 4% of global annual revenue or €20M, whichever is higher.
Source: Regulation (EU) 2016/679
See also: CCPA, Right to be Forgotten, Data Subject Request (DSR)
Global Privacy Control (GPC)
A browser and extension signal that communicates a user's intent to opt out of the sale or sharing of their personal information.
Global Privacy Control is an open standard browser signal that conveys opt-out preferences under CCPA and compliant state laws. Supported by Firefox, Brave, DuckDuckGo, and extensions for Chrome and Safari. Several states (CA, CO, CT, OR, NH, NJ) legally require businesses to honor GPC. Enabling GPC provides a passive, always-on opt-out layer that complements manual deletion requests.
See also: Universal Opt-Out Mechanism, Opt-Out
I
ID Verification
The process by which a data broker or controller confirms the identity of a consumer making a privacy request.
ID verification is how a business confirms the requester is the consumer whose data is at issue. CCPA requires verification to be proportionate to the sensitivity of the request, a deletion of publicly available name/address should not require a government ID. Some brokers request full ID uploads, which creates breach risk. OfflistMe's approach avoids ID upload by generating first-party requests the consumer sends from their own verified inbox.
See also: Verifiable Consumer Request, First-Party Request
Identity Resolution
The process of stitching together disparate records and identifiers to determine they all refer to the same person.
Identity resolution is the matching engine at the heart of every data broker: it decides that a cookie, a hashed email, a MAID, a home address, and a name all belong to one individual, then merges their data into a single profile. It uses both deterministic matching (shared exact identifiers like email) and probabilistic matching (statistical inference from overlapping signals). Identity resolution is why opting out at one broker doesn't clear you from the ecosystem: each broker resolves identity independently from its own sources.
See also: Data Enrichment, Shadow Profile, Data Broker
K
KvK Address Shielding (Afschermen)
The Dutch process of shielding your visiting/home address in the KvK trade register, available to all sole proprietors.
In the Netherlands, every business registers in the KvK (Kamer van Koophandel) Handelsregister, and for sole proprietorships (eenmanszaken) the visiting address is often the owner's home address, which became publicly searchable and resold. "Afschermen" (shielding) lets sole proprietors always hide that visiting address, provided they supply a separate public postal address instead; other entities can shield only on a proven threat, and officials' home addresses are protected by default. The key caveat: shielding at the KvK stops new disclosure but does not undo data already copied by online brokers, so it is paired with GDPR erasure requests. This is the Netherlands' single highest-intent privacy task.
Source: KvK, Shielding your business address
See also: BRP Geheimhouding, Public Records, Right to be Forgotten
L
Location Data Broker
A data broker specializing in precise geolocation data, often harvested from app SDKs and ad auctions, sold for targeting and analytics.
Location data brokers collect and sell precise movement data, frequently sourced from software development kits (SDKs) embedded in mobile apps and from real-time bidding ad exchanges. The FTC has brought a series of actions (Kochava, X-Mode/Outlogic, InMarket, Gravy Analytics/Venntel, Mobilewalla) alleging these brokers sold data that could trace individuals to reproductive-health clinics, places of worship, and domestic-violence shelters. Precise location is among the most sensitive data a broker can hold because it reveals where you live, work, worship, and seek care.
See also: Mobile Advertising ID (MAID), Real-Time Bidding (RTB), Sensitive Personal Information
Liste Rouge
A French "red list" service that removes your phone number from the universal telephone directory.
The liste rouge ("red list") is a free option you request from your French telecom operator to remove your phone number, and the associated name and address, from the universal directory (annuaire universel) and from directory-enquiry services. A related "liste orange" limits use of your details for marketing while keeping you findable. Requesting the liste rouge is the standard French step for taking your number out of public directories such as PagesBlanches/PagesJaunes, and it pairs with Bloctel (for telemarketing) and GDPR objection requests for a fuller removal.
Source: CNIL: file a complaint
See also: Bloctel, People-Search Site, Opt-Out
M
Mobile Advertising ID (MAID)
A resettable identifier assigned to a phone (Apple IDFA or Google AAID) that links app activity and location to a single device.
A Mobile Advertising ID (MAID), Apple's IDFA or Google's Advertising ID, is a unique string that advertisers and data brokers use to tie together a device's app usage, location pings, and ad interactions without using your name. Location-data brokers like the ones the FTC sued (X-Mode, Gravy Analytics, Mobilewalla) keyed their datasets on MAIDs harvested from apps and ad auctions. Because a MAID maps cleanly to a real person once cross-referenced, resetting it (or turning off ad tracking entirely) meaningfully degrades the profile brokers can build. On iOS, App Tracking Transparency lets you deny the IDFA per app.
See also: Real-Time Bidding (RTB), Location Data Broker, Device Fingerprinting
Melderegister
Germany's mandatory residents' registration database; third parties can request basic name-and-address data unless you file a registry block.
The Melderegister is Germany's residents' registration system under the Bundesmeldegesetz: every resident must register their address ("Anmeldung") at the local Bürgeramt. Because third parties can request "simple registry information" (einfache Melderegisterauskunft), name and current address, the registry itself acts as a quasi-broker feed. Residents control this with two tools: the Übermittlungssperre, which blocks specific disclosures (advertising, parties, churches), and the §51 Auskunftssperre, a full information block for people at risk. Understanding the Melderegister is essential to German data removal because it sits upstream of much address-trading.
Source: Bundesmeldegesetz (gesetze-im-internet)
See also: Übermittlungssperre, Auskunftssperre, Public Records
O
Opt-Out
A request that a business stop a specified processing activity, such as selling personal information or using it for targeted advertising.
Under CCPA, "opt-out" refers specifically to the right to direct a business to stop selling or sharing personal information. Under most newer state laws, separate opt-outs exist for sale, targeted advertising, and profiling. Opt-out is narrower than deletion: the business may retain data but must stop the specified activity. Universal opt-out mechanisms like Global Privacy Control (GPC) signal opt-out at the browser level.
See also: Universal Opt-Out Mechanism, Global Privacy Control (GPC)
Opt-In
Consent given before a specific processing activity occurs, required under GDPR and stricter state laws like Washington's MHMDA.
Opt-in consent means the consumer must affirmatively agree before a business may process or sell their personal data. GDPR requires opt-in consent for most processing involving sensitive data. Washington's MHMDA requires opt-in for the sale of consumer health data. Most US state privacy laws use an opt-out model by default, the business may process or sell data unless the consumer actively opts out.
See also: Opt-Out
Open Electoral Register
The "edited" version of the UK electoral roll that anyone, including marketers and people-search sites, can legally buy, and that you can opt out of.
The UK electoral register exists in two versions. The full register is restricted to elections, credit referencing, and law enforcement. The open (or "edited") register is sold to anyone who wants it, including marketing companies and people-search aggregators like 192.com, and it is the single biggest legal feed that keeps UK residents searchable online. You can opt out of the open register at any time, for free, by contacting your local council's Electoral Registration Office; opting out does not affect your right to vote. Removing yourself from the open register is the highest-leverage first step in any UK data-removal effort because it cuts off re-listing at the next monthly update.
Source: GOV.UK: Opt out of the open register
See also: 192.com, People-Search Site, Public Records
P
People-Search Site
A subtype of data broker that offers public-facing search of individuals by name, phone, address, or email.
People-search sites let anyone look up an individual by name or other identifier, returning aggregated records from public sources. Examples include Whitepages, Spokeo, TruePeopleSearch, FastPeopleSearch, BeenVerified, Nuwber, and Radaris. Unlike background-check providers, people-search results are typically free to view (with paid upsells for full reports). Each site is required under major US state privacy laws to honor deletion requests.
See also: Data Broker, Opt-Out
Profiling
Automated processing of personal data to evaluate, analyse, or predict characteristics of a person.
Profiling under GDPR (Article 22) and most US state privacy laws means automated processing that analyses or predicts an individual's work performance, economic situation, health, preferences, location, reliability, or behaviour. Several state laws (CO, CT, OR, NJ, MN) grant consumers an opt-out from profiling that produces legal or similarly significant effects. Minnesota's MCDPA has the strongest profiling rights, including a right to question automated decisions.
See also: Automated Decision-Making
Private Right of Action
The legal ability for a private individual (not just a government agency) to sue a business for a privacy violation.
A private right of action (PRA) lets individuals file lawsuits for statutory damages, rather than depending on government enforcement. In US privacy law, PRA exists in Illinois BIPA (biometric data), California CCPA (security breaches only), and Washington MHMDA (health data). Most comprehensive state laws (VCDPA, CPA, CTDPA, UCPA, OCPA, TDPSA, etc.) lack a PRA, enforcement is exclusively by the AG.
See also: BIPA, Cure Period
Processor
An entity that processes personal data on behalf of a controller, as defined under GDPR.
Under GDPR, a processor processes personal data on behalf of a controller pursuant to a data-processing agreement. Processors have narrower obligations than controllers but are directly liable for security and breach notification. Under CCPA the equivalent role is "service provider." Most US state privacy laws adopt the controller/processor distinction.
See also: Controller
Public Records
Government-maintained records that are open to public inspection by statute, including property records, court filings, voter rolls, and business registrations.
Public records are documents or information that governments must make available to the public by law. Examples include property assessor records, court filings (state and federal), voter registration data (varies by state), business entity filings, and driver's license records (redacted under federal DPPA). Data brokers scrape public records at scale to build individual profiles. Removal from data brokers does not remove the underlying government record, only the broker's aggregated copy.
See also: Data Broker, Skip Tracing
People Search Engine
Synonymous with people-search site, an online service that returns personal information about an individual based on name or other identifier.
Used interchangeably with "people-search site." Examples: Whitepages, Spokeo, TruePeopleSearch, FastPeopleSearch, BeenVerified, Nuwber, Radaris, Intelius, PeekYou. All are categorised as data brokers under US state privacy laws and are subject to deletion requests.
See also: People-Search Site, Data Broker
Purpose Limitation
The principle that personal data collected for one specified purpose should not be further processed for incompatible purposes.
Purpose limitation (GDPR Article 5(1)(b)) requires that personal data be collected for specified, explicit, and legitimate purposes and not further processed incompatibly. This restricts the common data-broker practice of acquiring data for one context and selling it into different contexts without renewed consent. Most US state privacy laws codify purpose limitation through data-use consent requirements.
See also: Data Minimization, GDPR
Pretexting
Obtaining someone's personal information by deception, posing as the person or as someone authorized to receive the data.
Pretexting is the use of a false identity or fabricated scenario to trick a person, business, or institution into handing over information they would not otherwise disclose, for example, calling a phone company while impersonating the account holder. It is how the Docusearch broker obtained Amy Boyer's workplace before her 1999 murder. The Gramm-Leach-Bliley Act (GLBA) criminalizes pretexting to obtain financial information, and the FTC treats it as a deceptive practice. Pretexting is the human-engineering counterpart to scraping: it fills gaps in a profile that public records can't.
See also: Data Broker, Skip Tracing
Q
Quebec Law 25
Quebec's private-sector privacy law, the strictest in Canada, with explicit-consent rules, data portability, and penalties up to CAD $10M or 2% of turnover.
Law 25 (formerly Bill 64) is Quebec's modernized private-sector privacy law, rolled out from 2022 through 2024. It is the strictest regime in Canada: it requires explicit consent for secondary uses, mandatory privacy officers, privacy impact assessments, breach reporting, and a data-portability right, and it carries administrative monetary penalties up to CAD $10 million or 2% of worldwide turnover. Because PIPEDA does not apply to intraprovincial activity in provinces with "substantially similar" laws, Quebec residents rely on Law 25 (enforced by the Commission d'accès à l'information) rather than PIPEDA for most local complaints, and it is effectively setting the national bar.
Source: Commission d'accès à l'information du Québec
See also: Private Right of Action, GDPR, Data Subject Request (DSR)
R
Right to be Forgotten
A right, rooted in GDPR Article 17, allowing individuals to request deletion of their personal data under specified conditions.
Under GDPR Article 17, the right to erasure ("right to be forgotten") lets EU/EEA residents demand that a controller erase personal data when, among other grounds, the data is no longer necessary, consent is withdrawn, or processing is unlawful. Similar rights exist in US state laws (CCPA right to delete, VCDPA, CPA, etc.) though worded differently. The term originates from EU caselaw (Google Spain v. AEPD, 2014).
Right of Access
The right of a consumer to obtain a copy of the personal information a business holds about them.
The right of access (also "right to know") lets consumers obtain a copy of the personal information a business holds about them, plus the source, purpose, and third parties with whom it is shared. Granted under CCPA, GDPR, and most comprehensive state privacy laws. Typical response window: 45 days (most US states), 30 days (GDPR). The right is distinct from the right to delete, you may exercise one without the other.
See also: Data Subject Request (DSR), Right to Delete, Data Subject Access Request (DSAR)
Right to Delete
The right of a consumer to demand that a business delete personal information it has collected about them.
The right to delete (also "right to erasure" under GDPR) lets consumers demand that a business delete their personal information. Granted under CCPA and every comprehensive US state privacy law. Certain exceptions apply, businesses may retain data necessary to complete a transaction, comply with legal obligations, detect security incidents, or exercise free speech. Data brokers typically must comply within 45 days under US state laws.
See also: Right of Access, Right to be Forgotten
Real-Time Bidding (RTB)
The automated auction that sells an ad slot in milliseconds as a page loads, broadcasting user data to many bidders in the process.
Real-time bidding (RTB) is the backbone of programmatic advertising: when you open a page or app, an auction broadcasts a "bid request", often including your approximate location, device, MAID, and inferred interests, to dozens or hundreds of potential advertisers so they can bid to show you an ad. Privacy regulators and researchers have flagged RTB as a mass data-leakage channel, because every bidder receives the data even if they don't win. Several FTC location-data cases traced their data supply back to RTB feeds. RTB is why data can flow to brokers from apps you trust.
See also: Targeted Advertising, Mobile Advertising ID (MAID), Surveillance Advertising
S
Sensitive Personal Information
A category of data under CCPA/CPRA that carries heightened protection, including SSN, precise geolocation, biometric data, and more.
Under CPRA, "sensitive personal information" includes government IDs (SSN, driver's license, passport), financial account credentials, precise geolocation, race, ethnicity, religion, union membership, contents of non-business communications, genetic data, biometric identifiers, health data, and sex-life or sexual orientation data. Consumers have a separate right to limit the use of SPI. Maryland's MODPA outright bans the sale of sensitive personal data.
See also: CPRA, Biometric Data
SWATting
A harassment tactic in which a false emergency report is made to draw armed police response to a target's home address.
SWATting is the practice of placing a hoax emergency call, typically reporting an active shooter, hostage situation, or similar, to trigger a heavily armed police response at a victim's home. The tactic depends on the attacker knowing the victim's home address, typically obtained through data brokers or public records. Several states now classify SWATting as a felony. Removing home-address information from data brokers is a primary defensive measure.
See also: Doxxing, Daniel's Law
Skip Tracing
The practice of locating a person's current whereabouts by piecing together data from many sources, originally to find debtors who "skipped" town.
Skip tracing combines public records, credit-header data, utility and phone records, social media, and broker databases to locate an individual, traditionally used by debt collectors, bail bondsmen, process servers, and private investigators. Modern skip-tracing tools are powered by data brokers and people-search aggregators. The same infrastructure that helps a process server find a defendant also helps a stalker find a victim, which is why removing yourself from people-search sites disrupts skip tracing aimed at you.
See also: People-Search Site, Public Records, Pretexting
Shadow Profile
A profile a company or broker builds about a person who never created an account or knowingly shared data with it.
A shadow profile is the dossier an entity compiles about someone with whom it has no direct relationship, assembled from other people's contact lists, third-party data purchases, tracking pixels on sites you visit, and public records. Data brokers are essentially shadow-profile machines: most people in their databases never signed up. Shadow profiles are why "I never gave them my data" is not a defense, and why deletion rights that apply regardless of a direct relationship (as under CCPA) matter.
See also: Identity Resolution, Data Broker, Digital Footprint
Surveillance Advertising
Advertising that relies on pervasive tracking and profiling of individuals across sites, apps, and the physical world.
Surveillance advertising (or "surveillance-based advertising") is the term privacy advocates use for the dominant ad model that depends on continuously tracking people, building behavioral profiles, and targeting them based on inferred traits. It is the economic engine that funds most data collection online and the demand side that makes data brokers profitable. Critics argue it is inherently privacy-hostile and have pushed for bans or strict limits; contextual advertising (targeting the content, not the person) is the leading privacy-preserving alternative.
See also: Targeted Advertising, Real-Time Bidding (RTB), Profiling
Suppression List
A list of people who have opted out, which a business is supposed to check so it doesn't re-add or re-contact them.
A suppression list (or "do-not-sell" / "do-not-contact" list) records the identifiers of people who exercised an opt-out, so the business can screen them out of future processing, marketing, or sale. Honest brokers use suppression lists to honor deletions persistently; the catch is that a suppression list must itself store some identifier about you to work. When data reappears after a successful opt-out, a failed or ignored suppression list is often the culprit, the broker re-ingested you from a fresh source without checking.
See also: Opt-Out, Identity Resolution, Data Broker
SCHUFA
Germany's dominant credit bureau, holding ~1.2 billion records on ~69 million people; you are entitled to one free data copy per year.
SCHUFA (Schutzgemeinschaft für allgemeine Kreditsicherung) is the leading German credit-reference agency, holding roughly 1.2 billion records on about 69 million people and 6.6 million companies and answering some 232 million inquiries a year. Companies need your consent to pull your SCHUFA score, and you are entitled to one free annual data copy ("Datenkopie nach Art. 15 DSGVO"), which lets you check, dispute, and request deletion of outdated entries. SCHUFA scoring is regulated under §31 BDSG and was constrained by a 2023 Court of Justice of the EU ruling limiting purely automated credit scoring.
Source: SCHUFA (free annual data copy)
See also: Consumer Reporting Agency (CRA), Credit Header Data, Automated Decision-Making
Statutory Tort for Serious Invasions of Privacy
Australia's new private right to sue for serious privacy invasions, in force since 2025, which also enables privacy class actions.
Introduced by the Privacy and Other Legislation Amendment Act 2024 (Royal Assent 10 December 2024) and in effect from 2025, this statutory tort lets individuals in Australia sue for serious invasions of privacy, whether intrusion upon seclusion or misuse of information, where the invasion is serious and the privacy interest outweighs competing public interests. It is significant because it opens the door to privacy class actions, a genuine private remedy that the Privacy Act 1988 previously lacked. It sits alongside tiered civil penalties (top tier up to AUD $50M / 30% of turnover) and stronger OAIC enforcement powers introduced in the same reform.
Source: New serious-invasion-of-privacy tort (National Law Review)
See also: Private Right of Action, Do Not Call Register (Australia)
T
Targeted Advertising
Displaying ads to a consumer based on personal data obtained from activity across other businesses, websites, or contexts.
Targeted advertising (also called "cross-context behavioral advertising" in CPRA) is advertising delivered based on data tracked across other businesses or contexts, as opposed to contextual advertising on a single site. CCPA/CPRA, VCDPA, CPA, CTDPA, OCPA, and most peer state laws grant consumers a separate opt-out from targeted advertising, typically honorable via GPC.
See also: Profiling, Universal Opt-Out Mechanism, Real-Time Bidding (RTB)
U
Universal Opt-Out Mechanism
A browser-level signal recognised as a legal opt-out of sale, sharing, and targeted advertising.
Universal opt-out mechanisms (UOOMs) let users express opt-out preferences once, at the browser level, rather than contacting each business individually. Global Privacy Control (GPC) is the most widely implemented UOOM. California, Colorado, Connecticut, Oregon, New Hampshire, New Jersey, and several other states legally require controllers to honor GPC as an opt-out signal.
Source: Global Privacy Control
See also: Global Privacy Control (GPC), Opt-Out
V
Verifiable Consumer Request
Under CCPA, a consumer request accompanied by information that allows the business to reasonably verify the consumer's identity.
A verifiable consumer request is required before a business must honor a deletion, access, or correction request under CCPA. Verification should be proportionate to the sensitivity of the request, for a deletion of publicly available data, minimal verification (email, zip code) is sufficient; for access to sensitive health data, stronger verification is expected. Businesses cannot require more verification than the original data collection involved.
See also: Data Subject Request (DSR)
Z
Zero-Data Architecture
A service design in which no user personally identifiable information is stored on the service provider's servers.
Zero-data architecture is a design pattern in which personally identifiable information (PII) is processed only in the user's browser or device, never transmitted to the service provider's servers. Applied to data-removal services, this means the provider does not hold names, addresses, or IDs of the users it serves. Advantages: no breach risk (nothing to breach), no account surface area, no subject-access complexity. OfflistMe is built on zero-data architecture.
See also: First-Party Request
Ü
Übermittlungssperre
A German registry opt-out that blocks specific disclosures of your address, such as to advertisers, political parties, churches, or for anniversary lists.
An Übermittlungssperre ("transmission block") is a targeted opt-out filed at your local Bürgeramt that stops Germany's residents' registry (Melderegister) from disclosing your data for particular purposes, most commonly advertising/address publishers, political parties ahead of elections, churches, and "age-anniversary" (Altersjubiläen) lists. Unlike the §51 Auskunftssperre, it does not require a safety threat and does not fully hide your address; it simply switches off the specified disclosure channels. It is the everyday tool German residents use to keep their registered address from feeding marketing and address-trading.
Source: Bundesmeldegesetz (gesetze-im-internet)
See also: Auskunftssperre, Melderegister, Suppression List
Put it to use
Opt out of 500+ brokers for $7
Now that you know the terms, exercise your rights. OfflistMe drafts CCPA/GDPR-compliant deletion emails you send from your own inbox.
Request Removal Now