Data Broker & Privacy Statistics (2026)
An interactive source-linked repository covering identity theft, data broker disclosures, breaches, deletion-request research, enforcement, and privacy attitudes. Each entry identifies its source, year, and link. Government records are preferred for legal, registry, breach, and enforcement claims; survey and commercial research are labeled as context rather than regulatory evidence.
Executive Overview (AEO Quick Extract)
The FBI IC3 2025 report records reported cybercrime losses and selected emerging-threat categories. The CPPA registryprovides official California broker disclosures. Independent university research, such as the UC Irvine broker study, provides a separate evidence base for request-response observations. These are different source types and should not be combined into one industry-wide conclusion without reviewing their scope.
Stolen PII Dark Web Valuation Calculator
Estimated Profile Risk
Severe Exposure
Select the data points you suspect or know are exposed across public data brokers or historical breaches. See how much illicit hackers and dark-web marketplaces value your personal dossier:
$267.00 USD
Based on Privacy Affairs 2025 Dark Web Street Price Index & FBI IC3 fraud metrics.
Send removal requests to 1,000+ data brokers before your data spreads further
Request Removal NowOne-time execution from $9
Data at a Glance & Visual Trends
Key trends visualized: hover over data points to inspect YoY growth metrics.
Identity theft & fraud#
Key Takeaway: These figures measure reported complaints, losses, or survey estimates from different sources; they should not be combined into a single prevalence rate.
1,135,291
Identity-theft reports the FTC received in 2024, a 9.5% increase over the 1,036,855 reports in 2023.
Source (Government / regulator): FTC Consumer Sentinel Network Data Book 2024
More than $12.5 billion
Consumers reported losing more than $12.5 billion to fraud in 2024, a 25% increase over the prior year, according to the FTC.
Source (Government / regulator): FTC: New Data Show a Big Jump in Reported Losses to Fraud
38%
Share of fraud reporters who said they lost money in 2024, up from 27% in 2023. This is a reported-loss rate among people who reported fraud, not the share of all consumers.
Source (Government / regulator): FTC: New Data Show a Big Jump in Reported Losses to Fraud
$27.3 billion
Traditional US identity-fraud losses in 2025, according to the Javelin Strategy 2026 Identity Fraud Study.
Source (Survey / industry / secondary): Javelin Strategy & Research, 2026 Identity Fraud Study
6.0 million
Number of account takeover victims in the US in 2025, representing an 18% increase year-over-year, per Javelin's 2026 Study.
Source (Survey / industry / secondary): Javelin Strategy & Research, 2026 Identity Fraud Study
$20.877 billion
Total losses reported to the FBI's Internet Crime Complaint Center (IC3) in 2025 across 1,008,597 complaints, a 26% year-over-year increase and a new record, beating the prior high of $16.6 billion set in 2024.
Source (Government / regulator): FBI Internet Crime Complaint Center, 2025 IC3 Annual Report
More than $893 million
Adjusted losses tied to 22,364 complaints containing a reference to artificial intelligence in 2025 exceeded $893 million, according to the FBI IC3.
Source (Government / regulator): FBI Internet Crime Complaint Center, 2025 IC3 Annual Report
$7.7 billion
Losses reported by victims over age 60 in 2025, up 59% from 2024; complaints in this age group rose 37%, per the FBI IC3.
Source (Government / regulator): FBI Internet Crime Complaint Center, 2025 IC3 Annual Report
43%
Share of surveyed U.S. adults who said they had submitted a robocall complaint to a state attorney general, the FTC, or the Do Not Call Registry in the prior 12 months, according to TNS survey data.
Source (Survey / industry / secondary): Transaction Network Services (TNS), 2025 Robocall Report
9%
Share of U.S. residents age 16 or older who experienced identity theft during the prior 12 months in 2021, according to the Bureau of Justice Statistics; this is not a lifetime estimate.
Source (Government / regulator): Bureau of Justice Statistics, Victims of Identity Theft, 2021
The data broker industry#
Key Takeaway: Registry counts are government or registry observations, while market-size figures are commercial estimates. Each card identifies which type of evidence it uses.
$315.66B to $448.32B
Estimated global data-broker market size of $315.66 billion in 2026, growing from $294.27 billion in 2025 to $448.32 billion by 2031 at a 7.27% CAGR.
Source (Survey / industry / secondary): Mordor Intelligence, Data Broker Market Size, Growth, Trends & Forecast Report 2031
Current scope
California residents may use DROP to submit one deletion request to all active data brokers within the platform’s current scope; the active list and eligibility can change, so check the live CPPA guidance.
Source (Government / regulator): California Privacy Protection Agency (CPPA) Data Broker Registry
Current registry
Texas requires data brokers to register with the Secretary of State under Business & Commerce Code Chapter 510; the filing officer states that registration does not imply approval or endorsement.
Source (Survey / industry / secondary): Texas Secretary of State, Data Broker FAQ
Current registry
Oregon publishes a data broker registry under its state registration requirements; the current list and qualifying exemptions should be checked before relying on a count.
Source (Government / regulator): Oregon Division of Financial Regulation (DFR) Data Broker Registry
August 1, 2026
Mandatory processing start date under the California Delete Act (SB 362): data brokers must access DROP at least once every 45 days and process deletion requests within the required timelines.
Source (Government / regulator): California Privacy Protection Agency (CalPrivacy), Processing DROP Requests
1 request → every broker
California's DROP (Delete Request and Opt-out Platform) lets residents send a single deletion request to all active data brokers, unless the consumer narrows the request; brokers are legally required to access DROP at least once every 45 days.
Source (Government / regulator): California Privacy Protection Agency (CalPrivacy), How DROP Works
$6,000
Annual registration fee for a data broker completing California registration in 2026, plus an associated third-party electronic-payment processing fee.
Source (Government / regulator): California Privacy Protection Agency (CalPrivacy), Account Creation, Fees, and Annual Registration
4,000+
Estimated number of data-broker companies operating worldwide, far more than any single state registry captures.
Source (Survey / industry / secondary): U.S. PIRG Education Fund analysis of the data-broker market
45 days (Connecticut)
Connecticut’s data privacy law generally requires a covered controller to respond to a consumer request within 45 days, subject to an allowed extension and scope rules; this is not a universal deadline for every state.
Source (Government / regulator): Connecticut Attorney General, The Connecticut Data Privacy Act
9 V.S.A. § 2446
Vermont statutory requirement mandating annual registration and privacy disclosures for commercial data brokers operating in the state.
Source (Government / regulator): Vermont Statutes Online, 9 V.S.A. § 2446
$300
Texas Secretary of State filing and renewal fee for a data-broker registration under Business & Commerce Code Chapter 510.
Source (Survey / industry / secondary): Texas Secretary of State, Data Broker FAQ
Breaches & exposure#
Key Takeaway: Breach totals depend on the reporting population, inclusion rules, and measurement period. Compare the linked source before using a figure as a benchmark.
3,152
Data compromises in the US in 2024, as reported retrospectively in the Identity Theft Resource Center’s 2025 Annual Data Breach Report.
Source (Survey / industry / secondary): Identity Theft Resource Center, 2025 Annual Data Breach Report
3,322
Record number of data compromises in the US in 2025, marking an all-time high, according to the Identity Theft Resource Center.
Source (Survey / industry / secondary): Identity Theft Resource Center, Annual Data Breach Report
75,000+
Publicly reported data-breach notifications compiled in the Privacy Rights Clearinghouse chronology since 2005; the database uses government-source notifications and notes that reporting and duplication practices vary.
Source (Survey / industry / secondary): Privacy Rights Clearinghouse Data Breach Chronology
$4.99 million
Global average cost of a data breach in IBM’s 2026 study, based on breaches experienced by 602 organizations from March 2025 through February 2026; the figure was 12% higher than the prior year and a record high in the report series.
Source (Survey / industry / secondary): IBM Newsroom, 2026 Cost of a Data Breach Study
147 million
People whose data was exposed in Equifax’s 2017 breach; the FTC says the global settlement included up to $425 million to help affected people. This credit-bureau settlement is not evidence of a data-broker count.
Source (Government / regulator): FTC: Equifax Data Breach Settlement
Dark web valuation & PII market#
Key Takeaway: Illicit-market price figures are estimates from the linked research or market source, not verified transaction records or a measure of every stolen identity.
$1–$6
Estimated dark-web price range for a U.S. Social Security Number in DeepStrike’s August 2025 pricing snapshot.
Source (Survey / industry / secondary): DeepStrike, Dark Web Data Pricing 2025
$70–$165
Estimated dark-web price range for a scanned U.S. driver’s license in DeepStrike’s August 2025 pricing snapshot.
Source (Survey / industry / secondary): DeepStrike, Dark Web Data Pricing 2025
$200–$1,000+
Estimated dark-web price range for an online bank login, highly dependent on account balance, in DeepStrike’s August 2025 pricing snapshot.
Source (Survey / industry / secondary): DeepStrike, Dark Web Data Pricing 2025
$20–$100+
Estimated dark-web price range for a U.S. Fullz package containing a name, Social Security Number, and date of birth in DeepStrike’s August 2025 pricing snapshot.
Source (Survey / industry / secondary): DeepStrike, Dark Web Data Pricing 2025
Request friction & efficacy#
Key Takeaway: Removal-response and efficacy figures are source-specific observations. They are not a universal success rate for every broker or request method.
43%
Share of the 543 California-registered brokers that did not respond to the UC Irvine study’s defined verifiable consumer request; the study described this as apparent noncompliance, not a court or regulator finding.
Source (Academic / research): UC Irvine: Probe into State Data Brokers (Bren School of ICS)
90.7%
Among respondents in the UC Irvine study’s defined sample, the share reported as replying within 45 days; this study result is not a universal broker-performance rate.
Source (Academic / research): UC Irvine: Consumer Beware! Exploring Data Brokers’ CCPA Compliance
32 DPAs
Number of European data protection authorities that participated in the EDPB’s 2025 coordinated enforcement action on the GDPR right to erasure; the action included fact-finding and formal investigations rather than a universal compliance rate.
Source (Government / regulator): European Data Protection Board, 2025 Coordinated Enforcement Framework report
45 days
California’s general response period for a covered, verifiable consumer request is 45 days, subject to permitted extensions, exceptions, and request-specific scope.
Source (Government / regulator): California Civil Code § 1798.130 (CCPA)
64%
Weighted share of California data brokers estimated by the study to have at least one interface feature that increased submission friction; the estimate was based on a stratified audit of 250 brokers and weighted to 522 registered brokers.
Source (Academic / research): Gueorguieva et al., “Privacy Without Remedy” (arXiv:2605.21376)
72%
Weighted share of California data brokers that the study classified as engaging in at least one behavior it considered a CCPA violation; this is an academic audit classification, not a regulator or court finding.
Source (Academic / research): Gueorguieva et al., “Privacy Without Remedy” (arXiv:2605.21376)
9.2%
Share of registered California data brokers that the study classified as fully complying with all six CCPA transparency reporting criteria it evaluated.
Source (Academic / research): Gueorguieva et al., “Privacy Without Remedy” (arXiv:2605.21376)
Enforcement#
Key Takeaway: The displayed penalties and enforcement outcomes are source-specific. Any aggregate shown elsewhere is a sum of listed rows, not a regulator-published total.
$16.5 million
FTC-finalized order requiring Avast to pay $16.5 million, expected to provide redress to consumers, and banning it from selling, disclosing, or licensing web-browsing data for advertising purposes.
Source (Government / regulator): FTC: FTC Finalizes Order with Avast
$200 / day / request
Daily statutory non-compliance penalty under California Civil Code § 1798.99.82 for failure to delete information as required by the Delete Act, plus agency investigative and administrative costs.
Source (Government / regulator): California Privacy Protection Agency: Data Broker Registry / Delete Act (effective 2026)
€6.31 billion
Total GDPR fines tracked by the GDPR Enforcement Tracker across 3,215 publicly known EU/EEA enforcement actions; the tracker includes UK GDPR fines and excludes non-GDPR fines.
Source (Publisher homepage / indirect): GDPR Enforcement Tracker
5
The FTC described the Gravy Analytics/Venntel action as its fifth action challenging the unfair handling of consumers’ sensitive location data; the release also names prior actions against Kochava, X-Mode, InMarket, and Mobilewalla.
Source (Government / regulator): FTC: Action Against Gravy Analytics and Venntel
Proposed order
The FTC announced a proposed order and settlement concerning Kochava on May 4, 2026. The proposal would restrict selling, sharing, or disclosing sensitive location data without affirmative express consent; the FTC case record should be checked before describing the matter as final.
Source (Government / regulator): FTC: proposed order and settlement concerning Kochava
$53,088 per violation
Civil penalties of up to $53,088 per violation that the FTC warned data brokers may face in an enforcement action for violating PADFAA’s restrictions on providing sensitive data to foreign adversaries.
Source (Government / regulator): Federal Trade Commission, PADFAA warning letters
$375,000
CCPA settlement California AG reached with DoorDash in 2024 for selling customer data via a marketing cooperative without required opt-out disclosures.
Source (Government / regulator): California Attorney General: DoorDash CCPA Settlement
$1.2 million
California's first public CCPA enforcement penalty against Sephora in 2022 for selling personal information and ignoring Global Privacy Control signals.
Source (Government / regulator): California Attorney General: Sephora Settlement
€20M / 4%
Maximum GDPR fine: the greater of €20 million or 4% of global annual turnover under Article 83.
Source (Government / regulator): Regulation (EU) 2016/679 (GDPR), Article 83
Consumer sentiment & privacy rights#
Key Takeaway: Survey results describe the sampled respondents and survey method; they should not be read as a universal measure of every consumer’s view.
73%
Share of U.S. adults who say they have little to no control over the personal data companies collect about them.
Source (Survey / industry / secondary): Pew Research Center: How Americans View Data Privacy
81%
Share of U.S. adults who feel very or somewhat concerned about how companies use the data they collect.
Source (Survey / industry / secondary): Pew Research Center: How Americans View Data Privacy
38%
Share of surveyed consumers classified by Cisco as “Privacy Actives,” a segment defined by privacy concern, willingness to act, and actions such as switching companies or providers over data practices.
Source (Survey / industry / secondary): Cisco 2024 Consumer Privacy Survey
75%
Share of surveyed consumers who said they would not purchase from an organization they do not trust with their data.
Source (Survey / industry / secondary): Cisco 2024 Consumer Privacy Survey
Global privacy laws#
Key Takeaway: Legal counts, registries, and rules change over time. Use the linked regulator or legislative source to verify the current position before relying on it.
€486.8 million
Total fines issued by France's CNIL in 2025; its annual summary reports 83 sanctions totaling €486,839,500 and cites €325M and €150M penalties against two major players.
Source (Survey / industry / secondary): CNIL: sanctions and corrective measures, 2025
69.1 million / 6.6 million
SCHUFA says it has creditworthiness information on 69.1 million natural persons and 6.6 million companies in Germany; its current business page does not state a total record count.
Source (Survey / industry / secondary): SCHUFA, Credit check of your customers & business partners
>700 million
192.com states that its database contains more than 700 million residential and business records across the UK; this is a provider claim, not an independent census or measure of current matching coverage.
Source (Survey / industry / secondary): 192.com About Us (provider claim)
1,205
Notifiable data breaches reported in Australia in 2025; OAIC says this was an 8% increase over 2024 and the highest annual total since the scheme began.
Source (Survey / industry / secondary): Office of the Australian Information Commissioner, 2025 NDB statistics
£12.7 million
Fine levied by the UK ICO against TikTok in 2023 for breaches involving children's personal data, including failing to use that data lawfully.
Source (Survey / industry / secondary): Information Commissioner's Office, TikTok enforcement action
AUD $50M / 3× benefit / 30%
Maximum civil penalty for a body corporate for a serious interference with privacy under Australia's Privacy Act 1988: the greatest of AUD $50 million, three times the benefit obtained, or 30% of adjusted turnover during the breach turnover period.
Source (Survey / industry / secondary): Australia Privacy Act 1988, section 13G
23 states
Number of US states with comprehensive consumer data privacy laws enacted as of mid-2026 (Vermont 23rd state in June 2026).
Source (Survey / industry / secondary): IAPP: Vermont becomes 23rd state to enact consumer privacy law
£17.5 million
Maximum PECR penalty for certain direct-marketing or spam-related infringements under the Data (Use and Access) Act 2025: £17.5 million or 4% of worldwide turnover for an undertaking, whichever is higher; the cap depends on the specific infringement.
Source (Government / regulator): Data (Use and Access) Act 2025, Explanatory Notes
CA$704 million
Reported fraud losses in Canada in 2025; the Canadian Anti-Fraud Centre says more than 112,000 reports were received and reported losses exceeded CA$704 million.
Source (Survey / industry / secondary): Canadian Anti-Fraud Centre, Fraud Prevention Month 2026
CA$7.11 million
Average cost of a data breach for Canadian organizations in IBM's 2026 report, a record high since the study began.
Source (Survey / industry / secondary): IBM Canada, Canada's Data Breach Costs Hit Record High
R$ 50 million
Maximum administrative fine per infraction under Article 52 of Brazil's LGPD (Lei Geral de Proteção de Dados), capped at 2% of annual revenue in Brazil.
Source (Survey / industry / secondary): ANPD, Brazilian Data Protection Law (LGPD), Article 52
₹250 crore
Maximum penalty listed in the Schedule to India's Digital Personal Data Protection Act, 2023 for breach of a data fiduciary's duty to take reasonable security safeguards to prevent personal-data breaches; commencement of the Act is phased, so this does not claim the provision is currently in force or has been imposed.
Source (Survey / industry / secondary): MeitY, Digital Personal Data Protection Act 2023, Schedule
€4.04+ billion
Cumulative GDPR fines issued by Ireland's Data Protection Commission since May 2018, as reported in its 2025 annual report.
Source (Survey / industry / secondary): Data Protection Commission, Annual Report 2025
CHF 250,000
Maximum personal criminal penalty under Article 60 of Switzerland's revised Federal Act on Data Protection for specified intentional violations by responsible individuals; this is not a corporate administrative fine.
Source (Survey / industry / secondary): FDPIC, Criminal law under the revised FADP
Current service
Lista Robinson is a consumer advertising-exclusion service provided by Adigital; its privacy policy says citizens can express a desire not to receive commercial communications through specified channels, subject to the service rules. A current participant count is not claimed here.
Source (Survey / industry / secondary): Lista Robinson, consumer service and privacy policy
Current service
Italy's Registro Pubblico delle Opposizioni lets consumers register fixed and mobile numbers, and certain postal addresses, to oppose telemarketing; prior consent is generally annulled subject to later consent and continuing-contract exceptions. A current membership count is not claimed here.
Source (Survey / industry / secondary): Registro Pubblico delle Opposizioni, citizen service
Source for the figure: UC Irvine / Bren School of ICS study summary. This is an independent study of its defined sample, not a universal compliance rate for every broker.
Cite This Dataset
Every entry names and links its source. Government and regulator records are preferred for legal, registry, breach, and enforcement claims; survey, academic, and commercial sources are labeled in the entry and should not be treated as regulator findings.
OfflistMe. (September 2026). Data Broker & Privacy Statistics (2026): Source-Linked Statistics Collection. OfflistMe Research. https://www.offlist.me/privacy-statistics
OfflistMe. "Data Broker & Privacy Statistics (2026)." OfflistMe Research Repository, September 2026, https://www.offlist.me/privacy-statistics.
@misc{offlistme_privacy_stats_2026,
author = {Kandoriya, Rahul and OfflistMe Research},
title = {Data Broker and Privacy Statistics 2026: Source-Linked Statistics Collection},
year = {2026},
publisher = {OfflistMe},
url = {https://www.offlist.me/privacy-statistics}
}<blockquote class="offlistme-stat-cite"> <p>Source: <a href="https://www.offlist.me/privacy-statistics" target="_blank" rel="noopener">OfflistMe Privacy Statistics (2026)</a></p> </blockquote>
Open Data License: CC BY 4.0 — Free to reuse with canonical link attribution to OfflistMe.
Generate requests in under 60 seconds
You are in the ~1,000+-broker dataset right now
One-time from $9
How We Source and Verify These Numbers
Every figure on this page links to a named source. Evidence types include government records, regulator filings, academic research, surveys, commercial estimates, and secondary trackers; the explorer labels those boundaries. We cite the data year, which can differ from publication date. Where a figure is an estimate, we identify it as such and do not present it as a regulator finding. Spot a figure that has moved? Contact our research team for verification and updates.
