Privacy research built from identifiable sources
This page documents the public registries, statutes, regulator databases, enforcement records, and survey sources used in OfflistMe research. Every published data point should link to its source, state the date or year it describes, and distinguish the original record from any OfflistMe-derived calculation.
Source first
Government and regulator records are preferred for legal, registry, breach, and enforcement claims.
No invented precision
If a source gives a range, estimate, or self-reported figure, the page preserves that qualification.
Derived data is labeled
Counts, joins, scores, and rankings created by OfflistMe are marked as derived and linked to their inputs.
Source-quality tiers
Tier 1: government, regulator, statutory, or official enforcement records.
Tier 2: peer-reviewed academic research and reproducible university research.
Tier 3: reputable nonprofit or survey research. These sources provide context and should not be presented as regulator findings.
Research source library
13 reviewed sources. The links below are the source of record for the stated scope.
| Source | Format / geography | Data / reuse | OfflistMe use / reliability |
|---|---|---|---|
| California Data Broker Registry California Privacy Protection Agency · Tier 1 The agency download is the source of record; OfflistMe normalization is derived data. | CSV and searchable web table California data brokers Annual registration cycle; agency updates may occur during the year Machine-readable: CSV download | Business identity, data categories, recipients, privacy-request information, and consumer-request metrics submitted by registrants Reuse: Use the agency record as source of record; label local normalization and joins as derived. | Registry explorer, category analysis, broker-alias reconciliation, and downloadable snapshots Reliability boundary: Official registry; registrant-submitted fields may be incomplete or stale. |
| Information for Data Brokers / DROP California Privacy Protection Agency · Tier 1 | Statute-linked HTML guidance California As implementation guidance changes Machine-readable: Not documented | Registration requirements, account requirements, access cadence, fees, and implementation instructions Reuse: Check the source terms and retain attribution. | DROP timeline, compliance explainer, and broker-facing implementation tracker Reliability boundary: Use only within the source scope and stated date. |
| Delete Act statutory text California Privacy Protection Agency · Tier 1 | PDF statutory text California When the statute or regulations change Machine-readable: Not documented | Legal duties, request-processing language, and statutory timelines Reuse: Check the source terms and retain attribution. | Primary legal citation for DROP and deletion-request claims Reliability boundary: Use only within the source scope and stated date. |
| HIPAA Breach Portal U.S. Department of Health and Human Services, Office for Civil Rights · Tier 1 The published list covers breaches affecting 500 or more individuals; do not generalize it to all breaches. | Searchable database United States Ongoing Machine-readable: Searchable web table; export availability should be checked before automation | Covered entity, state, entity type, individuals affected, submission date, breach type, and location of breached information Reuse: Link to the portal and preserve its 500-or-more-individual scope in every derived chart. | Health-breach explorer and category trend analysis Reliability boundary: Official required-reporting portal within HIPAA scope; not a census of all breaches. |
| Privacy and Security Enforcement Federal Trade Commission · Tier 1 | Case library and official releases United States Ongoing Machine-readable: Not documented | Case name, respondent, allegations, agency action, status, and official documents Reuse: Check the source terms and retain attribution. | Enforcement tracker with status and remedy fields Reliability boundary: Use only within the source scope and stated date. |
| Consumer Sentinel Network Data Book Federal Trade Commission · Tier 1 The FTC states these are consumer reports, not a population survey or verified incident census. | PDF, CSV archive, and interactive dashboard United States consumer reports Annual book; dashboard updates quarterly Machine-readable: CSV archive and interactive dashboard | Consumer reports about fraud, identity theft, and other consumer-protection topics, with category and geography fields Reuse: Do not convert reports into verified prevalence; retain the FTC report-count and contributor limitations. | Identity-theft and fraud context with explicit unverified-report limitations Reliability boundary: Official consumer-report dataset; reports are not verified incidents or a population survey. |
| FTC PADFAA data-broker guidance Federal Trade Commission · Tier 1 | Official press release United States As new enforcement or guidance is issued Machine-readable: Not documented | Sensitive-data categories, covered conduct, named warning-letter recipients, and stated penalty framework Reuse: Check the source terms and retain attribution. | Sensitive-data enforcement timeline and source-backed explainers Reliability boundary: Use only within the source scope and stated date. |
| Consumer reporting rulemaking materials Consumer Financial Protection Bureau · Tier 1 | Rulemaking materials and Federal Register links United States As rulemaking proceeds Machine-readable: Not documented | Proposed definitions, scope, consumer-reporting issues, and official policy documents Reuse: Check the source terms and retain attribution. | FCRA/data-broker boundary explainers and policy timeline Reliability boundary: Use only within the source scope and stated date. |
| NIST Privacy Framework National Institute of Standards and Technology · Tier 1 | Framework, XLSX, DOCX, and reference dataset Cross-sector, United States framework Versioned guidance; check the official page for updates Machine-readable: XLSX and reference dataset | Privacy-risk management functions, categories, subcategories, and implementation references Reuse: Use framework terminology with version/date; do not present a framework control as an empirical finding. | Privacy-risk vocabulary and organizational-control explainers; not evidence of consumer harm or broker compliance Reliability boundary: Official standards guidance, not a regulator finding about a specific company. |
| Cross-Sector Cybersecurity Performance Goals Cybersecurity and Infrastructure Security Agency · Tier 1 | Guidance and assessment materials U.S. critical-infrastructure sectors As CISA updates the goals Machine-readable: Not documented | Voluntary baseline cybersecurity practices and risk-reduction actions Reuse: Check the source terms and retain attribution. | Security-control context for breach and sensitive-data explainers; not a breach dataset Reliability boundary: Use only within the source scope and stated date. |
| EDPB Annual Report 2025 European Data Protection Board · Tier 1 | Annual PDF report and summary European Economic Area data-protection supervision Annual Machine-readable: Not documented | Board work, coordinated enforcement, guidance, opinions, and supervisory activity Reuse: Check the source terms and retain attribution. | GDPR enforcement and regulatory-timeline context; not a complete database of all national cases Reliability boundary: Use only within the source scope and stated date. |
| 2025 Internet Crime Report FBI Internet Crime Complaint Center · Tier 1 | Annual PDF report United States complaints reported to IC3 Annual Machine-readable: Not documented | Complaint counts, reported losses, crime categories, age groups, and selected emerging-threat categories Reuse: Check the source terms and retain attribution. | Fraud and identity-risk context; reported losses remain distinct from total losses Reliability boundary: Use only within the source scope and stated date. |
| How Americans View Data Privacy Pew Research Center · Tier 3 | Survey report United States adults Not fixed; use the stated survey date Machine-readable: Not documented | Consumer attitudes about data collection, control, and privacy concerns Reuse: Check the source terms and retain attribution. | Consumer-sentiment context, not evidence of broker behavior or legal compliance Reliability boundary: Use only within the source scope and stated date. |
How to read OfflistMe research
- Verified fact: directly stated by the linked source.
- Derived value: calculated by OfflistMe from one or more named sources.
- Observation: recorded during a documented audit and not automatically generalizable to the whole industry.
- Recommendation: an editorial or product decision, not a fact about the privacy industry.
Claim provenance ledger
These high-visibility claims are paired with a source and an explicit boundary. A derived value is not presented as an agency statistic.
| Claim | Status | Source | Boundary |
|---|---|---|---|
| Beginning August 1, 2026, covered data brokers must access the DROP mechanism at least once every 45 days. | verified | CPPA: Information for Data Brokers | The duty is subject to the Delete Act scope and limited exceptions; it is not a promise that every website is covered. |
| The CPPA operates a single-request deletion mechanism for California consumers. | verified | CPPA: Delete Act regulations and DROP materials | A single request does not establish deletion by every data holder or downstream recipient. |
| California registry counts on the Observatory are calculated from imported public records. | derived | CPPA California Data Broker Registry | The counts are OfflistMe-derived snapshot calculations, not agency-published totals or a current ownership match. |
| The HHS OCR portal is a source for published HIPAA breaches affecting 500 or more individuals. | verified | HHS OCR Breach Portal | It should not be presented as a census of all U.S. data breaches. |
| FTC enforcement rows on OfflistMe are selected official cases, not a complete enforcement census. | derived | FTC Privacy and Security Enforcement | Displayed totals are sums of the selected rows and should not be attributed to the FTC as agency totals. |
| No universal removal-effectiveness or reappearance rate is published by OfflistMe. | not published | OfflistMe methodology boundary | Until a documented, consented, reproducible study exists, avoid turning anecdotes or broker-stated timelines into an industry rate. |
Downloadable data hub
Each export is a convenience copy of a documented local snapshot or derived table. Check the linked source before reuse or republication.
