Privacy Research & Open Data Repository
An open, reproducible research library providing evidence-bounded benchmarks, recorded entity mappings, state registry crosswalks, and machine-readable datasets across the captured broker catalog. Each material statistic must be read with its source, snapshot date, and denominator.
Key takeaways
This hub is an open, reproducible library of evidence-bounded benchmarks, recorded entity mappings, state registry crosswalks, and machine-readable datasets across the captured broker catalog. It is not proof of universal legal verification, current provider coverage, request acceptance, fulfillment, or deletion. Read each statistic with its source, snapshot date, denominator, and stated evidence boundary.
Canonical Research Studies & Benchmarks
Data Broker Opt-Out Friction & Identity Barrier Benchmark
Evidence-gated audit of documented identity, workflow, and request-channel observations across the captured catalog.
Recorded Data Broker Parent Mapping
Evidence-gated mapping of recorded parent relationships; counts are limited to the captured ledger and cited source coverage.
Multi-State Data Broker Registry Crosswalk & Regulatory Discrepancies
Comparative matrix of captured catalog matches against California, Vermont, Oregon, Texas, and SEC evidence snapshots.
195-state jurisdiction research ledger
See which jurisdictions have published research, which remain discovered-only, which official sources are attached, and why legal content is not promoted automatically. The matrix is a coverage boundary—not a claim of universal legal verification.
Start with the law that matches the data source
These explainers summarize different legal scopes. They are reference pages, not a determination that a particular provider or request is covered.
What is FCRA?
Federal privacy law explainer
What is GLBA?
Federal privacy law explainer
What is HIPAA?
Federal privacy law explainer
What is COPPA?
Federal privacy law explainer
What is FTC Act §5?
Federal privacy law explainer
What is the texas privacy law?
US state privacy law explainer
What is the virginia privacy law?
US state privacy law explainer
What is the colorado privacy law?
US state privacy law explainer
What is the connecticut privacy law?
US state privacy law explainer
What is the utah privacy law?
US state privacy law explainer
What is the oregon privacy law?
US state privacy law explainer
What is the tennessee privacy law?
US state privacy law explainer
What is the delaware privacy law?
US state privacy law explainer
What is the new-hampshire privacy law?
US state privacy law explainer
What is the new-jersey privacy law?
US state privacy law explainer
What is the maryland privacy law?
US state privacy law explainer
What is the minnesota privacy law?
US state privacy law explainer
What is the iowa privacy law?
US state privacy law explainer
What is the montana privacy law?
US state privacy law explainer
What is the indiana privacy law?
US state privacy law explainer
What is the nebraska privacy law?
US state privacy law explainer
What is the kentucky privacy law?
US state privacy law explainer
What is the rhode-island privacy law?
US state privacy law explainer
What is UK GDPR?
United Kingdom privacy law explainer
What is PIPEDA?
Canada privacy law explainer
What is LGPD?
Brazil privacy law explainer
What is DPDP Act?
India privacy law explainer
What is Privacy Act 1988?
Australia privacy law explainer
What is APPI?
Japan privacy law explainer
What is PIPL?
China privacy law explainer
What is Loi Informatique et Libertés?
France privacy law explainer
What is BDSG?
Germany privacy law explainer
What is Law 25.326?
Argentina privacy law explainer
What is RA 10173?
Philippines privacy law explainer
What is POPIA?
South Africa privacy law explainer
What is Malaysia PDPA?
Malaysia privacy law explainer
What is UAE PDPL?
United Arab Emirates privacy law explainer
What is Korea PIPA?
Republic of Korea privacy law explainer
What is UAVG?
Netherlands privacy law explainer
What is NDPA?
Nigeria privacy law explainer
What is PECA + Art. 14?
Pakistan privacy law explainer
What is Law 29733?
Peru privacy law explainer
What is PDPL?
Saudi Arabia privacy law explainer
What is Thai PDPA?
Thailand privacy law explainer
What is KVKK?
Türkiye privacy law explainer
What is Law No. 91/2025?
Viet Nam privacy law explainer
What is Poland GDPR + UODO Act?
Poland privacy law explainer
What is Portugal GDPR + Lei 58/2019?
Portugal privacy law explainer
What is Romania GDPR + Law 190/2018?
Romania privacy law explainer
What is Act No. 63 of 2026?
Bangladesh privacy law explainer
What is Law 21.719?
Chile privacy law explainer
What is Law 1581?
Colombia privacy law explainer
What is Law No. 151 of 2020?
Egypt privacy law explainer
What is UU PDP?
Indonesia privacy law explainer
What is Privacy Law 5741-1981?
Israel privacy law explainer
What is Law No. 94-V?
Kazakhstan privacy law explainer
What is LFPDPPP (2025)?
Mexico privacy law explainer
What is Law 124/2024?
Albania privacy law explainer
What is HO-49-N?
Armenia privacy law explainer
What is Law 998-IIIQ?
Azerbaijan privacy law explainer
What is Law 12/25?
Bosnia and Herzegovina privacy law explainer
What is Info tv. + GDPR?
Hungary privacy law explainer
What is Act No. 90/2018 + GDPR?
Iceland privacy law explainer
What is Data Protection Act 2020?
Jamaica privacy law explainer
What is Data Protection Act 2019?
Kenya privacy law explainer
What is Digital Code?
Kyrgyzstan privacy law explainer
What is PDL?
Latvia privacy law explainer
What is Law of 1 August 2018?
Luxembourg privacy law explainer
What is Chapter 586?
Malta privacy law explainer
What is Law no. 195/2024?
Republic of Moldova privacy law explainer
What is Law on Personal Data Protection?
Mongolia privacy law explainer
What is Law on Personal Data Protection?
Montenegro privacy law explainer
What is Law 09-08?
Morocco privacy law explainer
What is IKS?
Estonia privacy law explainer
What is Law No. 3144?
Georgia privacy law explainer
What is Act 843?
Ghana privacy law explainer
What is Law 4624/2019?
Greece privacy law explainer
What is Law 42/2020?
North Macedonia privacy law explainer
What is 152-FZ?
Russian Federation privacy law explainer
What is Law No. 2008-12?
Senegal privacy law explainer
What is Law 87/2018?
Serbia privacy law explainer
What is Act No. 18/2018 Coll.?
Slovakia privacy law explainer
What is ZVOP-2?
Slovenia privacy law explainer
What is PDPA?
Sri Lanka privacy law explainer
What is Organic Law No. 2004-63?
Tunisia privacy law explainer
What is Law No. 2297-VI?
Ukraine privacy law explainer
What is PDPA?
Bulgaria privacy law explainer
What is Act on the Implementation of the GDPR?
Croatia privacy law explainer
What is Law 125(I)/2018?
Cyprus privacy law explainer
What is Act No. 110/2019 Coll.?
Czechia privacy law explainer
What is DSG?
Austria privacy law explainer
What is Belgian Data Protection Act?
Belgium privacy law explainer
What is Databeskyttelsesloven?
Denmark privacy law explainer
What is Data Protection Act 1050/2018?
Finland privacy law explainer
What is Personal Data Act?
Norway privacy law explainer
What is Sectoral Privacy Protections?
Afghanistan privacy law explainer
What is Law No. 18-07 + Law No. 25-11?
Algeria privacy law explainer
What is LQPD?
Andorra privacy law explainer
What is Law No. 22/11?
Angola privacy law explainer
What is Data Protection Act 2013?
Antigua and Barbuda privacy law explainer
What is DPA 2003?
Bahamas privacy law explainer
What is Law No. 30 of 2018?
Bahrain privacy law explainer
What is Data Protection Act 2019-29?
Barbados privacy law explainer
What is Law No. 99-Z?
Belarus privacy law explainer
What is Data Protection Act 2021?
Belize privacy law explainer
What is Code du numérique, Book V?
Benin privacy law explainer
What is ICM Act 2018 + NDGF 2025?
Bhutan privacy law explainer
What is Art. 21(2), 25, 130–131 + Law 254?
Bolivia (Plurinational State of) privacy law explainer
What is Data Protection Act 2024?
Botswana privacy law explainer
What is PDPO 2025?
Brunei Darussalam privacy law explainer
What is Loi n°001-2021/AN?
Burkina Faso privacy law explainer
What is Law No. 1/03 of 2026?
Burundi privacy law explainer
What is Lei n.º 133/V/2001?
Cabo Verde privacy law explainer
What is Fragmented privacy framework?
Cambodia privacy law explainer
What is Law No. 2024/017?
Cameroon privacy law explainer
What is Law No. 24.001?
Central African Republic privacy law explainer
What is Ley 8968?
Costa Rica privacy law explainer
What is LOPDP?
Ecuador privacy law explainer
What is LPDP?
El Salvador privacy law explainer
What is Ley 172-13?
Dominican Republic privacy law explainer
What is GDPR + Data Protection Act?
Sweden privacy law explainer
What is Malawi DPA 2024?
Malawi privacy law explainer
What is Mali Law 2013-015?
Mali privacy law explainer
What is Mauritania Law 2017-020?
Mauritania privacy law explainer
What is Mauritius DPA 2017?
Mauritius privacy law explainer
What is Monaco Law 1.565?
Monaco privacy law explainer
What is Nepal Privacy Act 2075?
Nepal privacy law explainer
What is Oman PDPL?
Oman privacy law explainer
What is Panama Ley 81/2019?
Panama privacy law explainer
What is Paraguay Law 7593/2025?
Paraguay privacy law explainer
What is Qatar Law No. 13 of 2016?
Qatar privacy law explainer
What is Rwanda Law 058/2021?
Rwanda privacy law explainer
What is Saint Lucia DPA 2011?
Saint Lucia privacy law explainer
What is Togo Law 2019-014?
Togo privacy law explainer
What is Turkmenistan Law 519-V?
Turkmenistan privacy law explainer
What is Tanzania PDPA 2022?
United Republic of Tanzania privacy law explainer
What is Uruguay Ley 18.331?
Uruguay privacy law explainer
What is Vanuatu DPPA 2024?
Vanuatu privacy law explainer
What is Zimbabwe Cyber and Data Protection Act?
Zimbabwe privacy law explainer
What is Chad Law 007/PR/2015?
Chad privacy law explainer
What is Comoros Personal Data Law 2014?
Comoros privacy law explainer
What is Congo Law 29-2019?
Congo privacy law explainer
What is Côte d'Ivoire Law 2013-450?
Côte d'Ivoire privacy law explainer
What is Cuba Law 149/2022?
Cuba privacy law explainer
What is DPRK Information Law materials?
Democratic People's Republic of Korea privacy law explainer
What is DRC Digital Code 2023?
Democratic Republic of the Congo privacy law explainer
What is Djibouti Digital Code 2025?
Djibouti privacy law explainer
What is Equatorial Guinea Law 1/2016?
Equatorial Guinea privacy law explainer
What is Eswatini Data Protection Act 2022?
Eswatini privacy law explainer
What is Ethiopia Proclamation No. 1321/2024?
Ethiopia privacy law explainer
What is Fiji Privacy Framework?
Fiji privacy law explainer
What is Gabon Law 025/2023?
Gabon privacy law explainer
What is Grenada Data Protection Act 2023?
Grenada privacy law explainer
What is Guinea Law L/2016/037/AN?
Guinea privacy law explainer
What is Guyana Data Protection Act 2023?
Guyana privacy law explainer
What is Haiti 2018 Data Privacy Order?
Haiti privacy law explainer
What is Iran Electronic Commerce Act 2003?
Iran (Islamic Republic of) privacy law explainer
What is Jordan Personal Data Protection Law No. 24 of 2023?
Jordan privacy law explainer
What is Kiribati Data Protection Act 2025?
Kiribati privacy law explainer
What is Kuwait CITRA Decision 2024/26?
Kuwait privacy law explainer
What is Lao Law 25/NA?
Lao People's Democratic Republic privacy law explainer
What is Lebanon Law 81/2018?
Lebanon privacy law explainer
What is Lesotho Data Protection Act 2011?
Lesotho privacy law explainer
What is Liberia Data Protection Act 2024?
Liberia privacy law explainer
What is Libya Law No. 6 of 2022?
Libya privacy law explainer
What is Liechtenstein DSG 2026?
Liechtenstein privacy law explainer
What is Madagascar Law 2014-038?
Madagascar privacy law explainer
What is Marshall Islands PDPA 2025?
Marshall Islands privacy law explainer
What is Mozambique Privacy Framework?
Mozambique privacy law explainer
What is Myanmar Privacy and Security Law?
Myanmar privacy law explainer
What is Nicaragua Law No. 787?
Nicaragua privacy law explainer
What is Niger Law No. 2022-59?
Niger privacy law explainer
What is Saint Kitts and Nevis DPA No. 5 of 2018?
Saint Kitts and Nevis privacy law explainer
What is Saint Vincent and the Grenadines Privacy Act No. 18 of 2003?
Saint Vincent and the Grenadines privacy law explainer
What is San Marino Law No. 171/2018?
San Marino privacy law explainer
What is Lei n.º 03/2016?
Sao Tome and Principe privacy law explainer
What is Seychelles Data Protection Act 2023?
Seychelles privacy law explainer
What is Somalia Data Protection Act 2023?
Somalia privacy law explainer
What is Law No. 12 of 2024?
Syrian Arab Republic privacy law explainer
What is Law No. 1537?
Tajikistan privacy law explainer
What is Privacy Act 2025?
Tonga privacy law explainer
What is Trinidad and Tobago DPA 2011?
Trinidad and Tobago privacy law explainer
What is Uganda DPA 2019?
Uganda privacy law explainer
What is U.S. Privacy Law?
United States of America privacy law explainer
What is Law No. O‘RQ-547?
Uzbekistan privacy law explainer
What is Constitution Article 28?
Venezuela (Bolivarian Republic of) privacy law explainer
What is Law No. 13 of 2012?
Yemen privacy law explainer
What is Zambia Data Protection Act 2021?
Zambia privacy law explainer
What is Decree DCLVII?
Holy See privacy law explainer
What is Palestinian Data Protection Law (draft)?
State of Palestine privacy law explainer
What is CCPA?
California privacy law explainer
What is GDPR?
EU privacy law explainer
What is Daniel's Law?
Judicial privacy law explainer
Move from research to a provider review
Use the evidence and legal context here to choose your next reading or review step. These links do not determine whether a provider accepts a request or whether a law applies.
1,043-record broker research queue
Every record in the captured catalog is represented in a generated field-level evidence worklist. The queue identifies missing, stale, or uncertain fields for source review; it is not a verification certificate and does not imply that a request was sent, accepted, fulfilled, deleted, or legally required. User-authorized fields remain separately gated and must use minimized, preferably redacted records.
1,043
catalog records represented
All captured records are included
177,832
open field tasks
Source and evidence work still queued
155,654
not-recorded states
No value is recorded in the snapshot
69
uncertainty states
Require conflict or ambiguity resolution
Public Machine-Readable Datasets
Versioned, structured JSON datasets freely available under the Creative Commons Attribution 4.0 International (CC-BY 4.0) license.
Broker profile records with 9-dimension Evidence Completeness Profiles, UNKNOWN field arrays, and primary citations.
Recorded parent labels and catalog-domain mappings; any SEC match requires separate current-source review.
Crosswalk linking captured broker records to the recorded California, Vermont, Oregon, Texas, and SEC evidence snapshots.
Knowledge-Base Snapshot
Live counts derived from the captured platform ledger and registry crosswalk snapshot.
1,043
captured catalog records
Catalog snapshot from platforms.json and coverage artifacts
182,653
tracked evidence facts
Field-level evidence retained in the coverage layer
817
registry-profiled brokers
Profiles joined from captured registry sources
1,052
risk-adjusted research universe
Discovery and review universe; not customer-ready coverage
Frequently Asked Questions
What is the methodology behind this privacy research hub?
This hub organizes evidence-bounded benchmarks, recorded entity mappings, state registry crosswalks, and machine-readable datasets. Its claim provenance ledger pairs high-visibility claims with a source and explicit boundary, while material statistics should be read with their source, snapshot date, and denominator.
How should I read a denominator or snapshot number here?
A denominator identifies the set used for a statistic, and a snapshot date identifies when the captured data was observed. Counts on this page are bounded to the captured catalog, platform ledger, registry crosswalk, or stated sample; a derived value is not presented as an agency statistic and does not establish universal coverage.
What does the evidence status mean?
The page labels captured, source-linked material with explicit boundaries. The broker research queue identifies missing, stale, or uncertain fields for source review; it is not a verification certificate and does not imply that a request was sent, accepted, fulfilled, deleted, or legally required.
Does this research prove that a provider covers me or will remove my data?
No. The legal explainers are reference pages, not a determination that a particular provider or request is covered. The research queue and catalog describe evidence and workflow records, not request acceptance, fulfillment, deletion, or a universal legal result.
How often is the privacy research updated?
There is no single refresh interval promised for the whole hub. The source library lists each reviewed source update frequency, and this page carries a dated review marker. Treat the datasets as captured snapshots and read each statistic with its source, snapshot date, denominator, and stated scope.
Research Source Library
19 reviewed sources. The links below are the source of record for the stated scope.
| Source | Format / geography | Data / reuse | OfflistMe use / reliability |
|---|---|---|---|
| California Data Broker Registry California Privacy Protection Agency · Tier 1 The agency download is the source of record; OfflistMe normalization is derived data. | CSV and searchable web table California data brokers Annual registration cycle; agency updates may occur during the year Machine-readable: CSV download | Business identity, data categories, recipients, privacy-request information, and consumer-request metrics submitted by registrants Reuse: Use the agency record as source of record; label local normalization and joins as derived. | Registry explorer, category analysis, broker-alias reconciliation, and downloadable snapshots Reliability boundary: Official registry; registrant-submitted fields may be incomplete or stale. |
| Information for Data Brokers / DROP California Privacy Protection Agency · Tier 1 | Statute-linked HTML guidance California As implementation guidance changes Machine-readable: Not documented | Registration requirements, account requirements, access cadence, fees, and implementation instructions Reuse: Check the source terms and retain attribution. | DROP timeline, compliance explainer, and broker-facing implementation tracker Reliability boundary: Use only within the source scope and stated date. |
| Delete Act statutory text California Privacy Protection Agency · Tier 1 | PDF statutory text California When the statute or regulations change Machine-readable: Not documented | Legal duties, request-processing language, and statutory timelines Reuse: Check the source terms and retain attribution. | Primary legal citation for DROP and deletion-request claims Reliability boundary: Use only within the source scope and stated date. |
| HIPAA Breach Portal U.S. Department of Health and Human Services, Office for Civil Rights · Tier 1 The published list covers breaches affecting 500 or more individuals; do not generalize it to all breaches. | Searchable database United States Ongoing Machine-readable: Searchable web table; export availability should be checked before automation | Covered entity, state, entity type, individuals affected, submission date, breach type, and location of breached information Reuse: Link to the portal and preserve its 500-or-more-individual scope in every derived chart. | Health-breach explorer and category trend analysis Reliability boundary: Official required-reporting portal within HIPAA scope; not a census of all breaches. |
| Privacy and Security Enforcement Federal Trade Commission · Tier 1 | Case library and official releases United States Ongoing Machine-readable: Not documented | Case name, respondent, allegations, agency action, status, and official documents Reuse: Check the source terms and retain attribution. | Enforcement tracker with status and remedy fields Reliability boundary: Use only within the source scope and stated date. |
| Consumer Sentinel Network Data Book Federal Trade Commission · Tier 1 The FTC states these are consumer reports, not a population survey or verified incident census. | PDF, CSV archive, and interactive dashboard United States consumer reports Annual book; dashboard updates quarterly Machine-readable: CSV archive and interactive dashboard | Consumer reports about fraud, identity theft, and other consumer-protection topics, with category and geography fields Reuse: Do not convert reports into verified prevalence; retain the FTC report-count and contributor limitations. | Identity-theft and fraud context with explicit unverified-report limitations Reliability boundary: Official consumer-report dataset; reports are not verified incidents or a population survey. |
| FTC PADFAA data-broker guidance Federal Trade Commission · Tier 1 | Official press release United States As new enforcement or guidance is issued Machine-readable: Not documented | Sensitive-data categories, covered conduct, named warning-letter recipients, and stated penalty framework Reuse: Check the source terms and retain attribution. | Sensitive-data enforcement timeline and source-backed explainers Reliability boundary: Use only within the source scope and stated date. |
| Consumer reporting rulemaking materials Consumer Financial Protection Bureau · Tier 1 The December 2024 Regulation V data-broker proposal was withdrawn on May 15, 2025; treat it as historical rulemaking material, not current law or a pending proposal. | Federal Register withdrawal notice and related materials United States As rulemaking or official interpretation changes Machine-readable: Not documented | Withdrawal status, former proposed definitions, scope, consumer-reporting issues, and official policy documents Reuse: Check the source terms and retain attribution. | FCRA/data-broker boundary explainers and policy timeline Reliability boundary: Use only within the source scope and stated date. |
| NIST Privacy Framework National Institute of Standards and Technology · Tier 1 | Framework, XLSX, DOCX, and reference dataset Cross-sector, United States framework Versioned guidance; check the official page for updates Machine-readable: XLSX and reference dataset | Privacy-risk management functions, categories, subcategories, and implementation references Reuse: Use framework terminology with version/date; do not present a framework control as an empirical finding. | Privacy-risk vocabulary and organizational-control explainers; not evidence of consumer harm or broker compliance Reliability boundary: Official standards guidance, not a regulator finding about a specific company. |
| Cross-Sector Cybersecurity Performance Goals Cybersecurity and Infrastructure Security Agency · Tier 1 | Guidance and assessment materials U.S. critical-infrastructure sectors As CISA updates the goals Machine-readable: Not documented | Voluntary baseline cybersecurity practices and risk-reduction actions Reuse: Check the source terms and retain attribution. | Security-control context for breach and sensitive-data explainers; not a breach dataset Reliability boundary: Use only within the source scope and stated date. |
| EDPB Annual Report 2025 European Data Protection Board · Tier 1 | Annual PDF report and summary European Economic Area data-protection supervision Annual Machine-readable: Not documented | Board work, coordinated enforcement, guidance, opinions, and supervisory activity Reuse: Check the source terms and retain attribution. | GDPR enforcement and regulatory-timeline context; not a complete database of all national cases Reliability boundary: Use only within the source scope and stated date. |
| EDPB Data Subject Rights European Data Protection Board · Tier 1 | Official rights explainer European Economic Area data-protection rights As guidance and legal interpretation are updated Machine-readable: Not documented | High-level descriptions of access, rectification, erasure, restriction, objection, portability, and automated-decision rights Reuse: Check the source terms and retain attribution. | Rights vocabulary and source-linked explanations for EU broker-request workflows; check the applicable law and controller context for each request Reliability boundary: Use only within the source scope and stated date. |
| EUR-Lex General Data Protection Regulation European Union · Tier 1 | Official regulation text European Union When the official consolidated text or applicable law changes Machine-readable: Not documented | GDPR articles, rights, principles, legal bases, restrictions, and obligations Reuse: Check the source terms and retain attribution. | Primary legal text for bounded GDPR explanations; preserve article, jurisdiction, exception, and controller-scope qualifiers Reliability boundary: Use only within the source scope and stated date. |
| Vermont Data Broker Registry Vermont Secretary of State · Tier 1 | Searchable database and annual registration filings Vermont / United States Annual registration cycle Machine-readable: Searchable web interface | Active/expired registrations, business names, opt-out mechanisms, credential collection disclosures, and security breach histories Reuse: Preserve official registration status (ACTIVE vs EXPIRED/CANCELLED) and annual filing dates. | State registry reconciliation, breach cross-referencing, and multi-state compliance verification Reliability boundary: Official state registry source; apply the current statute and filing record for legal interpretation. |
| Texas Data Broker Registry Texas Secretary of State · Tier 1 Texas data-broker registration began under Chapter 509 and was redesignated as Chapter 510 effective September 1, 2025. | Official state registry database Texas / United States Annual registration cycle Machine-readable: Searchable web registry | Registered data broker entities, primary contact information, opt-out URLs, and statutory compliance declarations Reuse: Cite official registration status and statutory filing details. | Multi-state regulatory mapping and Texas Business & Commerce Code Chapter 510 compliance tracking (redesignated from Chapter 509 in 2025) Reliability boundary: Official Texas Secretary of State filing information. |
| Oregon Data Broker Registry Oregon Department of Consumer and Business Services (DCBS), Division of Financial Regulation (DFR) · Tier 1 | Official registry page, verification site, and registration disclosures Oregon / United States Annual filing cycle Machine-readable: Official web page and linked verification site | Registered entity names, consumer opt-out instructions, registration status, and published registration information Reuse: Use the DFR/ DCBS page and linked verification record as the source of record; keep registration status separate from privacy-law eligibility or request outcomes. | Oregon data-broker registration context and multi-state source cross-verification Reliability boundary: Official Oregon registry information under ORS 646A.593 and related rules. |
| SEC EDGAR Public Broker Filings U.S. Securities and Exchange Commission · Tier 1 Covers public data corporations including LiveRamp, ZoomInfo, Experian, Equifax, TransUnion, Verisk, and RELX. | Electronic Data Gathering, Analysis, and Retrieval (EDGAR) 10-K, 10-Q, and 8-K filings Public U.S. and foreign data brokers traded on U.S. exchanges Quarterly and annual mandatory corporate disclosures Machine-readable: XBRL and XML/JSON API | Audited revenues, segment descriptions, customer categories, risk disclosures, regulatory proceedings, and corporate subsidiary hierarchies Reuse: Cite accession numbers, filing dates, and exact 10-K/10-Q report sections for financial and ownership claims. | Corporate parent resolution, public data broker economic profiles, and regulatory risk verification Reliability boundary: Federal statutory filings backed by legal civil and criminal penalties for material misstatements. |
| 2025 Internet Crime Report FBI Internet Crime Complaint Center · Tier 1 | Annual PDF report United States complaints reported to IC3 Annual Machine-readable: Not documented | Complaint counts, reported losses, crime categories, age groups, and selected emerging-threat categories Reuse: Check the source terms and retain attribution. | Fraud and identity-risk context; reported losses remain distinct from total losses Reliability boundary: Use only within the source scope and stated date. |
| How Americans View Data Privacy Pew Research Center · Tier 3 | Survey report United States adults Not fixed; use the stated survey date Machine-readable: Not documented | Consumer attitudes about data collection, control, and privacy concerns Reuse: Check the source terms and retain attribution. | Consumer-sentiment context, not evidence of broker behavior or legal compliance Reliability boundary: Use only within the source scope and stated date. |
Claim Provenance Ledger
These high-visibility claims are paired with a source and an explicit boundary. A derived value is not presented as an agency statistic.
| Claim | Status | Source | Boundary |
|---|---|---|---|
| Beginning August 1, 2026, covered data brokers must access the DROP mechanism at least once every 45 days. | verified | CPPA: Information for Data Brokers | The duty is subject to the Delete Act scope and limited exceptions; it is not a promise that every website is covered. |
| The CPPA operates a single-request deletion mechanism for California consumers. | verified | CPPA: Delete Act regulations and DROP materials | A single request does not establish deletion by every data holder or downstream recipient. |
| California registry counts on the Observatory are calculated from imported public records. | derived | CPPA California Data Broker Registry | The counts are OfflistMe-derived snapshot calculations, not agency-published totals or a current ownership match. |
| The HHS OCR portal is a source for published HIPAA breaches affecting 500 or more individuals. | verified | HHS OCR Breach Portal | It should not be presented as a census of all U.S. data breaches. |
| FTC enforcement rows on OfflistMe are selected official cases, not a complete enforcement census. | derived | FTC Privacy and Security Enforcement | Displayed totals are sums of the selected rows and should not be attributed to the FTC as agency totals. |
| No universal removal-effectiveness or reappearance rate is published by OfflistMe. | not published | OfflistMe methodology boundary | Until a documented, consented, reproducible study exists, avoid turning anecdotes or broker-stated timelines into an industry rate. |
| Vermont, Texas, and Oregon registry counts are derived from official state agency filings. | derived | Vermont SOS, Texas AG, and Oregon DCBS Data Broker Registries | Registration totals represent official state snapshots normalized by OfflistMe, not combined multi-state legal entities. |
| SEC EDGAR provides a source for checking public-company filings and recorded parent relationships in the captured research. | derived | U.S. Securities and Exchange Commission (EDGAR) | An EDGAR match does not by itself establish current ownership, control, an exchange listing, a complete corporate hierarchy, or that a parent handles a privacy request for a brand. |
| Spain's Lista Robinson is an advertising-exclusion system that businesses conducting campaigns must consult, subject to customer and consent exceptions. | verified | AEPD: Publicidad no deseada | The AEPD describes advertising-exclusion lists as free and voluntary, with customer and consent exceptions and an effectiveness delay; the list does not replace individual GDPR rights or remove source data. |
| Italy's Registro Pubblico delle Opposizioni (RPO) provides a free opt-out route for covered telemarketing and named postal advertising, with consent and continuing-contract exceptions. | verified | Registro pubblico delle opposizioni: citizen FAQ | Telephone and postal RPO coverage differs; later consent, current or recently expired contracts, directory-source limits, and the registry's stated processing windows affect the result. |
| A UC Irvine university news report describes non-response and interface observations from a defined data-broker research cohort. | observation | UC Irvine: probe into state data brokers | The cited page is a university news report, not evidence by itself of peer review; findings describe the specific cohort and study period and must not be generalized to every broker. |
| National identity-fraud losses and consumer reports reflect separate methodologies across government and commercial research. | verified | FTC Consumer Sentinel, Javelin Strategy & Research, and FBI IC3 | FTC and FBI figures represent consumer complaints received, while Javelin figures are survey-based economic loss estimates; they measure different populations and should not be combined. |
| The current directory snapshot lists Address Confidentiality Programs in 44 US states and the District of Columbia. | derived | Minnesota Secretary of State: Other States With Programs Like Safe At Home | This is a dated directory snapshot of programs like the referenced Safe at Home model, not a complete legal determination of every address-protection or redaction route; eligibility and covered records remain state- and program-specific. |
