Skip to main content
OfflistMe Privacy Intelligence Lab • Source & Data Hub

Privacy Research & Open Data Repository

An open, reproducible research library providing evidence-bounded benchmarks, recorded entity mappings, state registry crosswalks, and machine-readable datasets across the captured broker catalog. Each material statistic must be read with its source, snapshot date, and denominator.

Key takeaways

This hub is an open, reproducible library of evidence-bounded benchmarks, recorded entity mappings, state registry crosswalks, and machine-readable datasets across the captured broker catalog. It is not proof of universal legal verification, current provider coverage, request acceptance, fulfillment, or deletion. Read each statistic with its source, snapshot date, denominator, and stated evidence boundary.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 21, 2026
Flagship Publications

Canonical Research Studies & Benchmarks

Global legal coverage control

195-state jurisdiction research ledger

See which jurisdictions have published research, which remain discovered-only, which official sources are attached, and why legal content is not promoted automatically. The matrix is a coverage boundary—not a claim of universal legal verification.

Open coverage ledger
Source-linked legal context

Start with the law that matches the data source

These explainers summarize different legal scopes. They are reference pages, not a determination that a particular provider or request is covered.

What is FCRA?

Federal privacy law explainer

What is GLBA?

Federal privacy law explainer

What is HIPAA?

Federal privacy law explainer

What is COPPA?

Federal privacy law explainer

What is FTC Act §5?

Federal privacy law explainer

What is the texas privacy law?

US state privacy law explainer

What is the virginia privacy law?

US state privacy law explainer

What is the colorado privacy law?

US state privacy law explainer

What is the connecticut privacy law?

US state privacy law explainer

What is the utah privacy law?

US state privacy law explainer

What is the oregon privacy law?

US state privacy law explainer

What is the tennessee privacy law?

US state privacy law explainer

What is the delaware privacy law?

US state privacy law explainer

What is the new-hampshire privacy law?

US state privacy law explainer

What is the new-jersey privacy law?

US state privacy law explainer

What is the maryland privacy law?

US state privacy law explainer

What is the minnesota privacy law?

US state privacy law explainer

What is the iowa privacy law?

US state privacy law explainer

What is the montana privacy law?

US state privacy law explainer

What is the indiana privacy law?

US state privacy law explainer

What is the nebraska privacy law?

US state privacy law explainer

What is the kentucky privacy law?

US state privacy law explainer

What is the rhode-island privacy law?

US state privacy law explainer

What is UK GDPR?

United Kingdom privacy law explainer

What is PIPEDA?

Canada privacy law explainer

What is LGPD?

Brazil privacy law explainer

What is DPDP Act?

India privacy law explainer

What is Privacy Act 1988?

Australia privacy law explainer

What is APPI?

Japan privacy law explainer

What is PIPL?

China privacy law explainer

What is Loi Informatique et Libertés?

France privacy law explainer

What is BDSG?

Germany privacy law explainer

What is Law 25.326?

Argentina privacy law explainer

What is RA 10173?

Philippines privacy law explainer

What is POPIA?

South Africa privacy law explainer

What is Malaysia PDPA?

Malaysia privacy law explainer

What is UAE PDPL?

United Arab Emirates privacy law explainer

What is Korea PIPA?

Republic of Korea privacy law explainer

What is UAVG?

Netherlands privacy law explainer

What is NDPA?

Nigeria privacy law explainer

What is PECA + Art. 14?

Pakistan privacy law explainer

What is Law 29733?

Peru privacy law explainer

What is PDPL?

Saudi Arabia privacy law explainer

What is Thai PDPA?

Thailand privacy law explainer

What is KVKK?

Türkiye privacy law explainer

What is Law No. 91/2025?

Viet Nam privacy law explainer

What is Poland GDPR + UODO Act?

Poland privacy law explainer

What is Portugal GDPR + Lei 58/2019?

Portugal privacy law explainer

What is Romania GDPR + Law 190/2018?

Romania privacy law explainer

What is Act No. 63 of 2026?

Bangladesh privacy law explainer

What is Law 21.719?

Chile privacy law explainer

What is Law 1581?

Colombia privacy law explainer

What is Law No. 151 of 2020?

Egypt privacy law explainer

What is UU PDP?

Indonesia privacy law explainer

What is Privacy Law 5741-1981?

Israel privacy law explainer

What is Law No. 94-V?

Kazakhstan privacy law explainer

What is LFPDPPP (2025)?

Mexico privacy law explainer

What is Law 124/2024?

Albania privacy law explainer

What is HO-49-N?

Armenia privacy law explainer

What is Law 998-IIIQ?

Azerbaijan privacy law explainer

What is Law 12/25?

Bosnia and Herzegovina privacy law explainer

What is Info tv. + GDPR?

Hungary privacy law explainer

What is Act No. 90/2018 + GDPR?

Iceland privacy law explainer

What is Data Protection Act 2020?

Jamaica privacy law explainer

What is Data Protection Act 2019?

Kenya privacy law explainer

What is Digital Code?

Kyrgyzstan privacy law explainer

What is PDL?

Latvia privacy law explainer

What is Law of 1 August 2018?

Luxembourg privacy law explainer

What is Chapter 586?

Malta privacy law explainer

What is Law no. 195/2024?

Republic of Moldova privacy law explainer

What is Law on Personal Data Protection?

Mongolia privacy law explainer

What is Law on Personal Data Protection?

Montenegro privacy law explainer

What is Law 09-08?

Morocco privacy law explainer

What is IKS?

Estonia privacy law explainer

What is Law No. 3144?

Georgia privacy law explainer

What is Act 843?

Ghana privacy law explainer

What is Law 4624/2019?

Greece privacy law explainer

What is Law 42/2020?

North Macedonia privacy law explainer

What is 152-FZ?

Russian Federation privacy law explainer

What is Law No. 2008-12?

Senegal privacy law explainer

What is Law 87/2018?

Serbia privacy law explainer

What is Act No. 18/2018 Coll.?

Slovakia privacy law explainer

What is ZVOP-2?

Slovenia privacy law explainer

What is PDPA?

Sri Lanka privacy law explainer

What is Organic Law No. 2004-63?

Tunisia privacy law explainer

What is Law No. 2297-VI?

Ukraine privacy law explainer

What is PDPA?

Bulgaria privacy law explainer

What is Act on the Implementation of the GDPR?

Croatia privacy law explainer

What is Law 125(I)/2018?

Cyprus privacy law explainer

What is Act No. 110/2019 Coll.?

Czechia privacy law explainer

What is DSG?

Austria privacy law explainer

What is Belgian Data Protection Act?

Belgium privacy law explainer

What is Databeskyttelsesloven?

Denmark privacy law explainer

What is Data Protection Act 1050/2018?

Finland privacy law explainer

What is Personal Data Act?

Norway privacy law explainer

What is Sectoral Privacy Protections?

Afghanistan privacy law explainer

What is Law No. 18-07 + Law No. 25-11?

Algeria privacy law explainer

What is LQPD?

Andorra privacy law explainer

What is Law No. 22/11?

Angola privacy law explainer

What is Data Protection Act 2013?

Antigua and Barbuda privacy law explainer

What is DPA 2003?

Bahamas privacy law explainer

What is Law No. 30 of 2018?

Bahrain privacy law explainer

What is Data Protection Act 2019-29?

Barbados privacy law explainer

What is Law No. 99-Z?

Belarus privacy law explainer

What is Data Protection Act 2021?

Belize privacy law explainer

What is Code du numérique, Book V?

Benin privacy law explainer

What is ICM Act 2018 + NDGF 2025?

Bhutan privacy law explainer

What is Art. 21(2), 25, 130–131 + Law 254?

Bolivia (Plurinational State of) privacy law explainer

What is Data Protection Act 2024?

Botswana privacy law explainer

What is PDPO 2025?

Brunei Darussalam privacy law explainer

What is Loi n°001-2021/AN?

Burkina Faso privacy law explainer

What is Law No. 1/03 of 2026?

Burundi privacy law explainer

What is Lei n.º 133/V/2001?

Cabo Verde privacy law explainer

What is Fragmented privacy framework?

Cambodia privacy law explainer

What is Law No. 2024/017?

Cameroon privacy law explainer

What is Law No. 24.001?

Central African Republic privacy law explainer

What is Ley 8968?

Costa Rica privacy law explainer

What is LOPDP?

Ecuador privacy law explainer

What is LPDP?

El Salvador privacy law explainer

What is Ley 172-13?

Dominican Republic privacy law explainer

What is GDPR + Data Protection Act?

Sweden privacy law explainer

What is Malawi DPA 2024?

Malawi privacy law explainer

What is Mali Law 2013-015?

Mali privacy law explainer

What is Mauritania Law 2017-020?

Mauritania privacy law explainer

What is Mauritius DPA 2017?

Mauritius privacy law explainer

What is Monaco Law 1.565?

Monaco privacy law explainer

What is Nepal Privacy Act 2075?

Nepal privacy law explainer

What is Oman PDPL?

Oman privacy law explainer

What is Panama Ley 81/2019?

Panama privacy law explainer

What is Paraguay Law 7593/2025?

Paraguay privacy law explainer

What is Qatar Law No. 13 of 2016?

Qatar privacy law explainer

What is Rwanda Law 058/2021?

Rwanda privacy law explainer

What is Saint Lucia DPA 2011?

Saint Lucia privacy law explainer

What is Togo Law 2019-014?

Togo privacy law explainer

What is Turkmenistan Law 519-V?

Turkmenistan privacy law explainer

What is Tanzania PDPA 2022?

United Republic of Tanzania privacy law explainer

What is Uruguay Ley 18.331?

Uruguay privacy law explainer

What is Vanuatu DPPA 2024?

Vanuatu privacy law explainer

What is Zimbabwe Cyber and Data Protection Act?

Zimbabwe privacy law explainer

What is Chad Law 007/PR/2015?

Chad privacy law explainer

What is Comoros Personal Data Law 2014?

Comoros privacy law explainer

What is Congo Law 29-2019?

Congo privacy law explainer

What is Côte d'Ivoire Law 2013-450?

Côte d'Ivoire privacy law explainer

What is Cuba Law 149/2022?

Cuba privacy law explainer

What is DPRK Information Law materials?

Democratic People's Republic of Korea privacy law explainer

What is DRC Digital Code 2023?

Democratic Republic of the Congo privacy law explainer

What is Djibouti Digital Code 2025?

Djibouti privacy law explainer

What is Equatorial Guinea Law 1/2016?

Equatorial Guinea privacy law explainer

What is Eswatini Data Protection Act 2022?

Eswatini privacy law explainer

What is Ethiopia Proclamation No. 1321/2024?

Ethiopia privacy law explainer

What is Fiji Privacy Framework?

Fiji privacy law explainer

What is Gabon Law 025/2023?

Gabon privacy law explainer

What is Grenada Data Protection Act 2023?

Grenada privacy law explainer

What is Guinea Law L/2016/037/AN?

Guinea privacy law explainer

What is Guyana Data Protection Act 2023?

Guyana privacy law explainer

What is Haiti 2018 Data Privacy Order?

Haiti privacy law explainer

What is Iran Electronic Commerce Act 2003?

Iran (Islamic Republic of) privacy law explainer

What is Jordan Personal Data Protection Law No. 24 of 2023?

Jordan privacy law explainer

What is Kiribati Data Protection Act 2025?

Kiribati privacy law explainer

What is Kuwait CITRA Decision 2024/26?

Kuwait privacy law explainer

What is Lao Law 25/NA?

Lao People's Democratic Republic privacy law explainer

What is Lebanon Law 81/2018?

Lebanon privacy law explainer

What is Lesotho Data Protection Act 2011?

Lesotho privacy law explainer

What is Liberia Data Protection Act 2024?

Liberia privacy law explainer

What is Libya Law No. 6 of 2022?

Libya privacy law explainer

What is Liechtenstein DSG 2026?

Liechtenstein privacy law explainer

What is Madagascar Law 2014-038?

Madagascar privacy law explainer

What is Marshall Islands PDPA 2025?

Marshall Islands privacy law explainer

What is Mozambique Privacy Framework?

Mozambique privacy law explainer

What is Myanmar Privacy and Security Law?

Myanmar privacy law explainer

What is Nicaragua Law No. 787?

Nicaragua privacy law explainer

What is Niger Law No. 2022-59?

Niger privacy law explainer

What is Saint Kitts and Nevis DPA No. 5 of 2018?

Saint Kitts and Nevis privacy law explainer

What is Saint Vincent and the Grenadines Privacy Act No. 18 of 2003?

Saint Vincent and the Grenadines privacy law explainer

What is San Marino Law No. 171/2018?

San Marino privacy law explainer

What is Lei n.º 03/2016?

Sao Tome and Principe privacy law explainer

What is Seychelles Data Protection Act 2023?

Seychelles privacy law explainer

What is Somalia Data Protection Act 2023?

Somalia privacy law explainer

What is Law No. 12 of 2024?

Syrian Arab Republic privacy law explainer

What is Law No. 1537?

Tajikistan privacy law explainer

What is Privacy Act 2025?

Tonga privacy law explainer

What is Trinidad and Tobago DPA 2011?

Trinidad and Tobago privacy law explainer

What is Uganda DPA 2019?

Uganda privacy law explainer

What is U.S. Privacy Law?

United States of America privacy law explainer

What is Law No. O‘RQ-547?

Uzbekistan privacy law explainer

What is Constitution Article 28?

Venezuela (Bolivarian Republic of) privacy law explainer

What is Law No. 13 of 2012?

Yemen privacy law explainer

What is Zambia Data Protection Act 2021?

Zambia privacy law explainer

What is Decree DCLVII?

Holy See privacy law explainer

What is Palestinian Data Protection Law (draft)?

State of Palestine privacy law explainer

What is CCPA?

California privacy law explainer

What is GDPR?

EU privacy law explainer

What is Daniel's Law?

Judicial privacy law explainer

Research to action

Move from research to a provider review

Use the evidence and legal context here to choose your next reading or review step. These links do not determine whether a provider accepts a request or whether a law applies.

Complete catalog evidence worklist

1,043-record broker research queue

Every record in the captured catalog is represented in a generated field-level evidence worklist. The queue identifies missing, stale, or uncertain fields for source review; it is not a verification certificate and does not imply that a request was sent, accepted, fulfilled, deleted, or legally required. User-authorized fields remain separately gated and must use minimized, preferably redacted records.

Open field assessment

1,043

catalog records represented

All captured records are included

177,832

open field tasks

Source and evidence work still queued

155,654

not-recorded states

No value is recorded in the snapshot

69

uncertainty states

Require conflict or ambiguity resolution

Open Access Research

Public Machine-Readable Datasets

Versioned, structured JSON datasets freely available under the Creative Commons Attribution 4.0 International (CC-BY 4.0) license.

entity-research-ledgerCaptured catalog

Broker profile records with 9-dimension Evidence Completeness Profiles, UNKNOWN field arrays, and primary citations.

broker-ownership-graphCaptured snapshot

Recorded parent labels and catalog-domain mappings; any SEC match requires separate current-source review.

broker-registry-crosswalkCrosswalk

Crosswalk linking captured broker records to the recorded California, Vermont, Oregon, Texas, and SEC evidence snapshots.

removal-friction-benchmarkBenchmark

Evidence-bounded friction fields with explicit sample sizes and UNKNOWN states where the source record is incomplete.

Knowledge-Base Snapshot

Live counts derived from the captured platform ledger and registry crosswalk snapshot.

Explore Observatory →

1,043

captured catalog records

Catalog snapshot from platforms.json and coverage artifacts

182,653

tracked evidence facts

Field-level evidence retained in the coverage layer

817

registry-profiled brokers

Profiles joined from captured registry sources

1,052

risk-adjusted research universe

Discovery and review universe; not customer-ready coverage

Frequently Asked Questions

What is the methodology behind this privacy research hub?

This hub organizes evidence-bounded benchmarks, recorded entity mappings, state registry crosswalks, and machine-readable datasets. Its claim provenance ledger pairs high-visibility claims with a source and explicit boundary, while material statistics should be read with their source, snapshot date, and denominator.

How should I read a denominator or snapshot number here?

A denominator identifies the set used for a statistic, and a snapshot date identifies when the captured data was observed. Counts on this page are bounded to the captured catalog, platform ledger, registry crosswalk, or stated sample; a derived value is not presented as an agency statistic and does not establish universal coverage.

What does the evidence status mean?

The page labels captured, source-linked material with explicit boundaries. The broker research queue identifies missing, stale, or uncertain fields for source review; it is not a verification certificate and does not imply that a request was sent, accepted, fulfilled, deleted, or legally required.

Does this research prove that a provider covers me or will remove my data?

No. The legal explainers are reference pages, not a determination that a particular provider or request is covered. The research queue and catalog describe evidence and workflow records, not request acceptance, fulfillment, deletion, or a universal legal result.

How often is the privacy research updated?

There is no single refresh interval promised for the whole hub. The source library lists each reviewed source update frequency, and this page carries a dated review marker. Treat the datasets as captured snapshots and read each statistic with its source, snapshot date, denominator, and stated scope.

Research Source Library

19 reviewed sources. The links below are the source of record for the stated scope.

SourceFormat / geographyData / reuseOfflistMe use / reliability
California Data Broker Registry

California Privacy Protection Agency · Tier 1

The agency download is the source of record; OfflistMe normalization is derived data.

CSV and searchable web table
California data brokers
Annual registration cycle; agency updates may occur during the year
Machine-readable: CSV download
Business identity, data categories, recipients, privacy-request information, and consumer-request metrics submitted by registrants

Reuse: Use the agency record as source of record; label local normalization and joins as derived.

Registry explorer, category analysis, broker-alias reconciliation, and downloadable snapshots

Reliability boundary: Official registry; registrant-submitted fields may be incomplete or stale.

Information for Data Brokers / DROP

California Privacy Protection Agency · Tier 1

Statute-linked HTML guidance
California
As implementation guidance changes
Machine-readable: Not documented
Registration requirements, account requirements, access cadence, fees, and implementation instructions

Reuse: Check the source terms and retain attribution.

DROP timeline, compliance explainer, and broker-facing implementation tracker

Reliability boundary: Use only within the source scope and stated date.

Delete Act statutory text

California Privacy Protection Agency · Tier 1

PDF statutory text
California
When the statute or regulations change
Machine-readable: Not documented
Legal duties, request-processing language, and statutory timelines

Reuse: Check the source terms and retain attribution.

Primary legal citation for DROP and deletion-request claims

Reliability boundary: Use only within the source scope and stated date.

HIPAA Breach Portal

U.S. Department of Health and Human Services, Office for Civil Rights · Tier 1

The published list covers breaches affecting 500 or more individuals; do not generalize it to all breaches.

Searchable database
United States
Ongoing
Machine-readable: Searchable web table; export availability should be checked before automation
Covered entity, state, entity type, individuals affected, submission date, breach type, and location of breached information

Reuse: Link to the portal and preserve its 500-or-more-individual scope in every derived chart.

Health-breach explorer and category trend analysis

Reliability boundary: Official required-reporting portal within HIPAA scope; not a census of all breaches.

Privacy and Security Enforcement

Federal Trade Commission · Tier 1

Case library and official releases
United States
Ongoing
Machine-readable: Not documented
Case name, respondent, allegations, agency action, status, and official documents

Reuse: Check the source terms and retain attribution.

Enforcement tracker with status and remedy fields

Reliability boundary: Use only within the source scope and stated date.

Consumer Sentinel Network Data Book

Federal Trade Commission · Tier 1

The FTC states these are consumer reports, not a population survey or verified incident census.

PDF, CSV archive, and interactive dashboard
United States consumer reports
Annual book; dashboard updates quarterly
Machine-readable: CSV archive and interactive dashboard
Consumer reports about fraud, identity theft, and other consumer-protection topics, with category and geography fields

Reuse: Do not convert reports into verified prevalence; retain the FTC report-count and contributor limitations.

Identity-theft and fraud context with explicit unverified-report limitations

Reliability boundary: Official consumer-report dataset; reports are not verified incidents or a population survey.

FTC PADFAA data-broker guidance

Federal Trade Commission · Tier 1

Official press release
United States
As new enforcement or guidance is issued
Machine-readable: Not documented
Sensitive-data categories, covered conduct, named warning-letter recipients, and stated penalty framework

Reuse: Check the source terms and retain attribution.

Sensitive-data enforcement timeline and source-backed explainers

Reliability boundary: Use only within the source scope and stated date.

Consumer reporting rulemaking materials

Consumer Financial Protection Bureau · Tier 1

The December 2024 Regulation V data-broker proposal was withdrawn on May 15, 2025; treat it as historical rulemaking material, not current law or a pending proposal.

Federal Register withdrawal notice and related materials
United States
As rulemaking or official interpretation changes
Machine-readable: Not documented
Withdrawal status, former proposed definitions, scope, consumer-reporting issues, and official policy documents

Reuse: Check the source terms and retain attribution.

FCRA/data-broker boundary explainers and policy timeline

Reliability boundary: Use only within the source scope and stated date.

NIST Privacy Framework

National Institute of Standards and Technology · Tier 1

Framework, XLSX, DOCX, and reference dataset
Cross-sector, United States framework
Versioned guidance; check the official page for updates
Machine-readable: XLSX and reference dataset
Privacy-risk management functions, categories, subcategories, and implementation references

Reuse: Use framework terminology with version/date; do not present a framework control as an empirical finding.

Privacy-risk vocabulary and organizational-control explainers; not evidence of consumer harm or broker compliance

Reliability boundary: Official standards guidance, not a regulator finding about a specific company.

Cross-Sector Cybersecurity Performance Goals

Cybersecurity and Infrastructure Security Agency · Tier 1

Guidance and assessment materials
U.S. critical-infrastructure sectors
As CISA updates the goals
Machine-readable: Not documented
Voluntary baseline cybersecurity practices and risk-reduction actions

Reuse: Check the source terms and retain attribution.

Security-control context for breach and sensitive-data explainers; not a breach dataset

Reliability boundary: Use only within the source scope and stated date.

EDPB Annual Report 2025

European Data Protection Board · Tier 1

Annual PDF report and summary
European Economic Area data-protection supervision
Annual
Machine-readable: Not documented
Board work, coordinated enforcement, guidance, opinions, and supervisory activity

Reuse: Check the source terms and retain attribution.

GDPR enforcement and regulatory-timeline context; not a complete database of all national cases

Reliability boundary: Use only within the source scope and stated date.

EDPB Data Subject Rights

European Data Protection Board · Tier 1

Official rights explainer
European Economic Area data-protection rights
As guidance and legal interpretation are updated
Machine-readable: Not documented
High-level descriptions of access, rectification, erasure, restriction, objection, portability, and automated-decision rights

Reuse: Check the source terms and retain attribution.

Rights vocabulary and source-linked explanations for EU broker-request workflows; check the applicable law and controller context for each request

Reliability boundary: Use only within the source scope and stated date.

EUR-Lex General Data Protection Regulation

European Union · Tier 1

Official regulation text
European Union
When the official consolidated text or applicable law changes
Machine-readable: Not documented
GDPR articles, rights, principles, legal bases, restrictions, and obligations

Reuse: Check the source terms and retain attribution.

Primary legal text for bounded GDPR explanations; preserve article, jurisdiction, exception, and controller-scope qualifiers

Reliability boundary: Use only within the source scope and stated date.

Vermont Data Broker Registry

Vermont Secretary of State · Tier 1

Searchable database and annual registration filings
Vermont / United States
Annual registration cycle
Machine-readable: Searchable web interface
Active/expired registrations, business names, opt-out mechanisms, credential collection disclosures, and security breach histories

Reuse: Preserve official registration status (ACTIVE vs EXPIRED/CANCELLED) and annual filing dates.

State registry reconciliation, breach cross-referencing, and multi-state compliance verification

Reliability boundary: Official state registry source; apply the current statute and filing record for legal interpretation.

Texas Data Broker Registry

Texas Secretary of State · Tier 1

Texas data-broker registration began under Chapter 509 and was redesignated as Chapter 510 effective September 1, 2025.

Official state registry database
Texas / United States
Annual registration cycle
Machine-readable: Searchable web registry
Registered data broker entities, primary contact information, opt-out URLs, and statutory compliance declarations

Reuse: Cite official registration status and statutory filing details.

Multi-state regulatory mapping and Texas Business & Commerce Code Chapter 510 compliance tracking (redesignated from Chapter 509 in 2025)

Reliability boundary: Official Texas Secretary of State filing information.

Oregon Data Broker Registry

Oregon Department of Consumer and Business Services (DCBS), Division of Financial Regulation (DFR) · Tier 1

Official registry page, verification site, and registration disclosures
Oregon / United States
Annual filing cycle
Machine-readable: Official web page and linked verification site
Registered entity names, consumer opt-out instructions, registration status, and published registration information

Reuse: Use the DFR/ DCBS page and linked verification record as the source of record; keep registration status separate from privacy-law eligibility or request outcomes.

Oregon data-broker registration context and multi-state source cross-verification

Reliability boundary: Official Oregon registry information under ORS 646A.593 and related rules.

SEC EDGAR Public Broker Filings

U.S. Securities and Exchange Commission · Tier 1

Covers public data corporations including LiveRamp, ZoomInfo, Experian, Equifax, TransUnion, Verisk, and RELX.

Electronic Data Gathering, Analysis, and Retrieval (EDGAR) 10-K, 10-Q, and 8-K filings
Public U.S. and foreign data brokers traded on U.S. exchanges
Quarterly and annual mandatory corporate disclosures
Machine-readable: XBRL and XML/JSON API
Audited revenues, segment descriptions, customer categories, risk disclosures, regulatory proceedings, and corporate subsidiary hierarchies

Reuse: Cite accession numbers, filing dates, and exact 10-K/10-Q report sections for financial and ownership claims.

Corporate parent resolution, public data broker economic profiles, and regulatory risk verification

Reliability boundary: Federal statutory filings backed by legal civil and criminal penalties for material misstatements.

2025 Internet Crime Report

FBI Internet Crime Complaint Center · Tier 1

Annual PDF report
United States complaints reported to IC3
Annual
Machine-readable: Not documented
Complaint counts, reported losses, crime categories, age groups, and selected emerging-threat categories

Reuse: Check the source terms and retain attribution.

Fraud and identity-risk context; reported losses remain distinct from total losses

Reliability boundary: Use only within the source scope and stated date.

How Americans View Data Privacy

Pew Research Center · Tier 3

Survey report
United States adults
Not fixed; use the stated survey date
Machine-readable: Not documented
Consumer attitudes about data collection, control, and privacy concerns

Reuse: Check the source terms and retain attribution.

Consumer-sentiment context, not evidence of broker behavior or legal compliance

Reliability boundary: Use only within the source scope and stated date.

Claim Provenance Ledger

These high-visibility claims are paired with a source and an explicit boundary. A derived value is not presented as an agency statistic.

ClaimStatusSourceBoundary
Beginning August 1, 2026, covered data brokers must access the DROP mechanism at least once every 45 days.verifiedCPPA: Information for Data BrokersThe duty is subject to the Delete Act scope and limited exceptions; it is not a promise that every website is covered.
The CPPA operates a single-request deletion mechanism for California consumers.verifiedCPPA: Delete Act regulations and DROP materialsA single request does not establish deletion by every data holder or downstream recipient.
California registry counts on the Observatory are calculated from imported public records.derivedCPPA California Data Broker RegistryThe counts are OfflistMe-derived snapshot calculations, not agency-published totals or a current ownership match.
The HHS OCR portal is a source for published HIPAA breaches affecting 500 or more individuals.verifiedHHS OCR Breach PortalIt should not be presented as a census of all U.S. data breaches.
FTC enforcement rows on OfflistMe are selected official cases, not a complete enforcement census.derivedFTC Privacy and Security EnforcementDisplayed totals are sums of the selected rows and should not be attributed to the FTC as agency totals.
No universal removal-effectiveness or reappearance rate is published by OfflistMe.not publishedOfflistMe methodology boundaryUntil a documented, consented, reproducible study exists, avoid turning anecdotes or broker-stated timelines into an industry rate.
Vermont, Texas, and Oregon registry counts are derived from official state agency filings.derivedVermont SOS, Texas AG, and Oregon DCBS Data Broker RegistriesRegistration totals represent official state snapshots normalized by OfflistMe, not combined multi-state legal entities.
SEC EDGAR provides a source for checking public-company filings and recorded parent relationships in the captured research.derivedU.S. Securities and Exchange Commission (EDGAR)An EDGAR match does not by itself establish current ownership, control, an exchange listing, a complete corporate hierarchy, or that a parent handles a privacy request for a brand.
Spain's Lista Robinson is an advertising-exclusion system that businesses conducting campaigns must consult, subject to customer and consent exceptions.verifiedAEPD: Publicidad no deseadaThe AEPD describes advertising-exclusion lists as free and voluntary, with customer and consent exceptions and an effectiveness delay; the list does not replace individual GDPR rights or remove source data.
Italy's Registro Pubblico delle Opposizioni (RPO) provides a free opt-out route for covered telemarketing and named postal advertising, with consent and continuing-contract exceptions.verifiedRegistro pubblico delle opposizioni: citizen FAQTelephone and postal RPO coverage differs; later consent, current or recently expired contracts, directory-source limits, and the registry's stated processing windows affect the result.
A UC Irvine university news report describes non-response and interface observations from a defined data-broker research cohort.observationUC Irvine: probe into state data brokersThe cited page is a university news report, not evidence by itself of peer review; findings describe the specific cohort and study period and must not be generalized to every broker.
National identity-fraud losses and consumer reports reflect separate methodologies across government and commercial research.verifiedFTC Consumer Sentinel, Javelin Strategy & Research, and FBI IC3FTC and FBI figures represent consumer complaints received, while Javelin figures are survey-based economic loss estimates; they measure different populations and should not be combined.
The current directory snapshot lists Address Confidentiality Programs in 44 US states and the District of Columbia.derivedMinnesota Secretary of State: Other States With Programs Like Safe At HomeThis is a dated directory snapshot of programs like the referenced Safe at Home model, not a complete legal determination of every address-protection or redaction route; eligibility and covered records remain state- and program-specific.