Skip to main content
Interactive Reference Repository · Source-linked entries · Updated September 2026

Data Broker & Privacy Statistics (2026)

An interactive source-linked repository covering identity theft, data broker disclosures, breaches, deletion-request research, enforcement, and privacy attitudes. Each entry identifies its source, year, and link. Government records are preferred for legal, registry, breach, and enforcement claims; survey and commercial research are labeled as context rather than regulatory evidence.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

Executive Overview (AEO Quick Extract)

The FBI IC3 2025 report records reported cybercrime losses and selected emerging-threat categories. The CPPA registryprovides official California broker disclosures. Independent university research, such as the UC Irvine broker study, provides a separate evidence base for request-response observations. These are different source types and should not be combined into one industry-wide conclusion without reviewing their scope.

Selected PII items updated. Estimated total dark web dossier valuation is $267.00 USD. Risk level is Severe.
Interactive Privacy Tool

Stolen PII Dark Web Valuation Calculator

Estimated Profile Risk

Severe Exposure

Select the data points you suspect or know are exposed across public data brokers or historical breaches. See how much illicit hackers and dark-web marketplaces value your personal dossier:

Estimated Black-Market Dossier Value

$267.00 USD

Based on Privacy Affairs 2025 Dark Web Street Price Index & FBI IC3 fraud metrics.

Send removal requests to 1,000+ data brokers before your data spreads further

Request Removal Now
FREE

One-time execution from $9

Data at a Glance & Visual Trends

Key trends visualized: hover over data points to inspect YoY growth metrics.

Showing 66 of 66 statistics

Identity theft & fraud#

Key Takeaway: These figures measure reported complaints, losses, or survey estimates from different sources; they should not be combined into a single prevalence rate.

1,135,291

2024Identity theft & fraud

Identity-theft reports the FTC received in 2024, a 9.5% increase over the 1,036,855 reports in 2023.

Source (Government / regulator): FTC Consumer Sentinel Network Data Book 2024

More than $12.5 billion

2024Identity theft & fraud

Consumers reported losing more than $12.5 billion to fraud in 2024, a 25% increase over the prior year, according to the FTC.

Source (Government / regulator): FTC: New Data Show a Big Jump in Reported Losses to Fraud

38%

2024Identity theft & fraud

Share of fraud reporters who said they lost money in 2024, up from 27% in 2023. This is a reported-loss rate among people who reported fraud, not the share of all consumers.

Source (Government / regulator): FTC: New Data Show a Big Jump in Reported Losses to Fraud

$27.3 billion

2025Identity theft & fraud

Traditional US identity-fraud losses in 2025, according to the Javelin Strategy 2026 Identity Fraud Study.

Source (Survey / industry / secondary): Javelin Strategy & Research, 2026 Identity Fraud Study

6.0 million

2025Identity theft & fraud

Number of account takeover victims in the US in 2025, representing an 18% increase year-over-year, per Javelin's 2026 Study.

Source (Survey / industry / secondary): Javelin Strategy & Research, 2026 Identity Fraud Study

$20.877 billion

2025Identity theft & fraud

Total losses reported to the FBI's Internet Crime Complaint Center (IC3) in 2025 across 1,008,597 complaints, a 26% year-over-year increase and a new record, beating the prior high of $16.6 billion set in 2024.

Source (Government / regulator): FBI Internet Crime Complaint Center, 2025 IC3 Annual Report

More than $893 million

2025Identity theft & fraud

Adjusted losses tied to 22,364 complaints containing a reference to artificial intelligence in 2025 exceeded $893 million, according to the FBI IC3.

Source (Government / regulator): FBI Internet Crime Complaint Center, 2025 IC3 Annual Report

$7.7 billion

2025Identity theft & fraud

Losses reported by victims over age 60 in 2025, up 59% from 2024; complaints in this age group rose 37%, per the FBI IC3.

Source (Government / regulator): FBI Internet Crime Complaint Center, 2025 IC3 Annual Report

43%

2025Identity theft & fraud

Share of surveyed U.S. adults who said they had submitted a robocall complaint to a state attorney general, the FTC, or the Do Not Call Registry in the prior 12 months, according to TNS survey data.

Source (Survey / industry / secondary): Transaction Network Services (TNS), 2025 Robocall Report

9%

2021Identity theft & fraud

Share of U.S. residents age 16 or older who experienced identity theft during the prior 12 months in 2021, according to the Bureau of Justice Statistics; this is not a lifetime estimate.

Source (Government / regulator): Bureau of Justice Statistics, Victims of Identity Theft, 2021

The data broker industry#

Key Takeaway: Registry counts are government or registry observations, while market-size figures are commercial estimates. Each card identifies which type of evidence it uses.

$315.66B to $448.32B

2026The data broker industry

Estimated global data-broker market size of $315.66 billion in 2026, growing from $294.27 billion in 2025 to $448.32 billion by 2031 at a 7.27% CAGR.

Current scope

2026The data broker industry

California residents may use DROP to submit one deletion request to all active data brokers within the platform’s current scope; the active list and eligibility can change, so check the live CPPA guidance.

Source (Government / regulator): California Privacy Protection Agency (CPPA) Data Broker Registry

Current registry

2026The data broker industry

Texas requires data brokers to register with the Secretary of State under Business & Commerce Code Chapter 510; the filing officer states that registration does not imply approval or endorsement.

Source (Survey / industry / secondary): Texas Secretary of State, Data Broker FAQ

Current registry

2026The data broker industry

Oregon publishes a data broker registry under its state registration requirements; the current list and qualifying exemptions should be checked before relying on a count.

August 1, 2026

2026The data broker industry

Mandatory processing start date under the California Delete Act (SB 362): data brokers must access DROP at least once every 45 days and process deletion requests within the required timelines.

1 request → every broker

2026The data broker industry

California's DROP (Delete Request and Opt-out Platform) lets residents send a single deletion request to all active data brokers, unless the consumer narrows the request; brokers are legally required to access DROP at least once every 45 days.

$6,000

2026The data broker industry

Annual registration fee for a data broker completing California registration in 2026, plus an associated third-party electronic-payment processing fee.

4,000+

2024The data broker industry

Estimated number of data-broker companies operating worldwide, far more than any single state registry captures.

Source (Survey / industry / secondary): U.S. PIRG Education Fund analysis of the data-broker market

45 days (Connecticut)

2026The data broker industry

Connecticut’s data privacy law generally requires a covered controller to respond to a consumer request within 45 days, subject to an allowed extension and scope rules; this is not a universal deadline for every state.

Source (Government / regulator): Connecticut Attorney General, The Connecticut Data Privacy Act

9 V.S.A. § 2446

2026The data broker industry

Vermont statutory requirement mandating annual registration and privacy disclosures for commercial data brokers operating in the state.

Source (Government / regulator): Vermont Statutes Online, 9 V.S.A. § 2446

$300

2026The data broker industry

Texas Secretary of State filing and renewal fee for a data-broker registration under Business & Commerce Code Chapter 510.

Source (Survey / industry / secondary): Texas Secretary of State, Data Broker FAQ

Breaches & exposure#

Key Takeaway: Breach totals depend on the reporting population, inclusion rules, and measurement period. Compare the linked source before using a figure as a benchmark.

3,152

2024Breaches & exposure

Data compromises in the US in 2024, as reported retrospectively in the Identity Theft Resource Center’s 2025 Annual Data Breach Report.

Source (Survey / industry / secondary): Identity Theft Resource Center, 2025 Annual Data Breach Report

3,322

2025Breaches & exposure

Record number of data compromises in the US in 2025, marking an all-time high, according to the Identity Theft Resource Center.

Source (Survey / industry / secondary): Identity Theft Resource Center, Annual Data Breach Report

75,000+

2026Breaches & exposure

Publicly reported data-breach notifications compiled in the Privacy Rights Clearinghouse chronology since 2005; the database uses government-source notifications and notes that reporting and duplication practices vary.

Source (Survey / industry / secondary): Privacy Rights Clearinghouse Data Breach Chronology

$4.99 million

2025–2026Breaches & exposure

Global average cost of a data breach in IBM’s 2026 study, based on breaches experienced by 602 organizations from March 2025 through February 2026; the figure was 12% higher than the prior year and a record high in the report series.

Source (Survey / industry / secondary): IBM Newsroom, 2026 Cost of a Data Breach Study

147 million

2017Breaches & exposure

People whose data was exposed in Equifax’s 2017 breach; the FTC says the global settlement included up to $425 million to help affected people. This credit-bureau settlement is not evidence of a data-broker count.

Source (Government / regulator): FTC: Equifax Data Breach Settlement

Dark web valuation & PII market#

Key Takeaway: Illicit-market price figures are estimates from the linked research or market source, not verified transaction records or a measure of every stolen identity.

$1–$6

2025Dark web valuation & PII market

Estimated dark-web price range for a U.S. Social Security Number in DeepStrike’s August 2025 pricing snapshot.

Source (Survey / industry / secondary): DeepStrike, Dark Web Data Pricing 2025

$70–$165

2025Dark web valuation & PII market

Estimated dark-web price range for a scanned U.S. driver’s license in DeepStrike’s August 2025 pricing snapshot.

Source (Survey / industry / secondary): DeepStrike, Dark Web Data Pricing 2025

$200–$1,000+

2025Dark web valuation & PII market

Estimated dark-web price range for an online bank login, highly dependent on account balance, in DeepStrike’s August 2025 pricing snapshot.

Source (Survey / industry / secondary): DeepStrike, Dark Web Data Pricing 2025

$20–$100+

2025Dark web valuation & PII market

Estimated dark-web price range for a U.S. Fullz package containing a name, Social Security Number, and date of birth in DeepStrike’s August 2025 pricing snapshot.

Source (Survey / industry / secondary): DeepStrike, Dark Web Data Pricing 2025

Request friction & efficacy#

Key Takeaway: Removal-response and efficacy figures are source-specific observations. They are not a universal success rate for every broker or request method.

43%

2024–2025Request friction & efficacy

Share of the 543 California-registered brokers that did not respond to the UC Irvine study’s defined verifiable consumer request; the study described this as apparent noncompliance, not a court or regulator finding.

90.7%

2024–2025Request friction & efficacy

Among respondents in the UC Irvine study’s defined sample, the share reported as replying within 45 days; this study result is not a universal broker-performance rate.

32 DPAs

2025Request friction & efficacy

Number of European data protection authorities that participated in the EDPB’s 2025 coordinated enforcement action on the GDPR right to erasure; the action included fact-finding and formal investigations rather than a universal compliance rate.

45 days

2026Request friction & efficacy

California’s general response period for a covered, verifiable consumer request is 45 days, subject to permitted extensions, exceptions, and request-specific scope.

Source (Government / regulator): California Civil Code § 1798.130 (CCPA)

64%

2025Request friction & efficacy

Weighted share of California data brokers estimated by the study to have at least one interface feature that increased submission friction; the estimate was based on a stratified audit of 250 brokers and weighted to 522 registered brokers.

72%

2025Request friction & efficacy

Weighted share of California data brokers that the study classified as engaging in at least one behavior it considered a CCPA violation; this is an academic audit classification, not a regulator or court finding.

9.2%

2025Request friction & efficacy

Share of registered California data brokers that the study classified as fully complying with all six CCPA transparency reporting criteria it evaluated.

Enforcement#

Key Takeaway: The displayed penalties and enforcement outcomes are source-specific. Any aggregate shown elsewhere is a sum of listed rows, not a regulator-published total.

$16.5 million

2024Enforcement

FTC-finalized order requiring Avast to pay $16.5 million, expected to provide redress to consumers, and banning it from selling, disclosing, or licensing web-browsing data for advertising purposes.

Source (Government / regulator): FTC: FTC Finalizes Order with Avast

$200 / day / request

2026Enforcement

Daily statutory non-compliance penalty under California Civil Code § 1798.99.82 for failure to delete information as required by the Delete Act, plus agency investigative and administrative costs.

€6.31 billion

2026Enforcement

Total GDPR fines tracked by the GDPR Enforcement Tracker across 3,215 publicly known EU/EEA enforcement actions; the tracker includes UK GDPR fines and excludes non-GDPR fines.

Source (Publisher homepage / indirect): GDPR Enforcement Tracker

5

2024Enforcement

The FTC described the Gravy Analytics/Venntel action as its fifth action challenging the unfair handling of consumers’ sensitive location data; the release also names prior actions against Kochava, X-Mode, InMarket, and Mobilewalla.

Source (Government / regulator): FTC: Action Against Gravy Analytics and Venntel

Proposed order

2026Enforcement

The FTC announced a proposed order and settlement concerning Kochava on May 4, 2026. The proposal would restrict selling, sharing, or disclosing sensitive location data without affirmative express consent; the FTC case record should be checked before describing the matter as final.

Source (Government / regulator): FTC: proposed order and settlement concerning Kochava

$53,088 per violation

2026Enforcement

Civil penalties of up to $53,088 per violation that the FTC warned data brokers may face in an enforcement action for violating PADFAA’s restrictions on providing sensitive data to foreign adversaries.

Source (Government / regulator): Federal Trade Commission, PADFAA warning letters

$375,000

2024Enforcement

CCPA settlement California AG reached with DoorDash in 2024 for selling customer data via a marketing cooperative without required opt-out disclosures.

Source (Government / regulator): California Attorney General: DoorDash CCPA Settlement

$1.2 million

2022Enforcement

California's first public CCPA enforcement penalty against Sephora in 2022 for selling personal information and ignoring Global Privacy Control signals.

Source (Government / regulator): California Attorney General: Sephora Settlement

€20M / 4%

2018Enforcement

Maximum GDPR fine: the greater of €20 million or 4% of global annual turnover under Article 83.

Source (Government / regulator): Regulation (EU) 2016/679 (GDPR), Article 83

Consumer sentiment & privacy rights#

Key Takeaway: Survey results describe the sampled respondents and survey method; they should not be read as a universal measure of every consumer’s view.

73%

2023Consumer sentiment & privacy rights

Share of U.S. adults who say they have little to no control over the personal data companies collect about them.

Source (Survey / industry / secondary): Pew Research Center: How Americans View Data Privacy

81%

2023Consumer sentiment & privacy rights

Share of U.S. adults who feel very or somewhat concerned about how companies use the data they collect.

Source (Survey / industry / secondary): Pew Research Center: How Americans View Data Privacy

38%

2024Consumer sentiment & privacy rights

Share of surveyed consumers classified by Cisco as “Privacy Actives,” a segment defined by privacy concern, willingness to act, and actions such as switching companies or providers over data practices.

Source (Survey / industry / secondary): Cisco 2024 Consumer Privacy Survey

75%

2024Consumer sentiment & privacy rights

Share of surveyed consumers who said they would not purchase from an organization they do not trust with their data.

Source (Survey / industry / secondary): Cisco 2024 Consumer Privacy Survey

Global privacy laws#

Key Takeaway: Legal counts, registries, and rules change over time. Use the linked regulator or legislative source to verify the current position before relying on it.

€486.8 million

2025Global privacy laws

Total fines issued by France's CNIL in 2025; its annual summary reports 83 sanctions totaling €486,839,500 and cites €325M and €150M penalties against two major players.

Source (Survey / industry / secondary): CNIL: sanctions and corrective measures, 2025

69.1 million / 6.6 million

2026Global privacy laws

SCHUFA says it has creditworthiness information on 69.1 million natural persons and 6.6 million companies in Germany; its current business page does not state a total record count.

Source (Survey / industry / secondary): SCHUFA, Credit check of your customers & business partners

>700 million

2026Global privacy laws

192.com states that its database contains more than 700 million residential and business records across the UK; this is a provider claim, not an independent census or measure of current matching coverage.

Source (Survey / industry / secondary): 192.com About Us (provider claim)

1,205

2025Global privacy laws

Notifiable data breaches reported in Australia in 2025; OAIC says this was an 8% increase over 2024 and the highest annual total since the scheme began.

Source (Survey / industry / secondary): Office of the Australian Information Commissioner, 2025 NDB statistics

£12.7 million

2023Global privacy laws

Fine levied by the UK ICO against TikTok in 2023 for breaches involving children's personal data, including failing to use that data lawfully.

Source (Survey / industry / secondary): Information Commissioner's Office, TikTok enforcement action

AUD $50M / 3× benefit / 30%

2026Global privacy laws

Maximum civil penalty for a body corporate for a serious interference with privacy under Australia's Privacy Act 1988: the greatest of AUD $50 million, three times the benefit obtained, or 30% of adjusted turnover during the breach turnover period.

Source (Survey / industry / secondary): Australia Privacy Act 1988, section 13G

23 states

2026Global privacy laws

Number of US states with comprehensive consumer data privacy laws enacted as of mid-2026 (Vermont 23rd state in June 2026).

Source (Survey / industry / secondary): IAPP: Vermont becomes 23rd state to enact consumer privacy law

£17.5 million

2025Global privacy laws

Maximum PECR penalty for certain direct-marketing or spam-related infringements under the Data (Use and Access) Act 2025: £17.5 million or 4% of worldwide turnover for an undertaking, whichever is higher; the cap depends on the specific infringement.

Source (Government / regulator): Data (Use and Access) Act 2025, Explanatory Notes

CA$704 million

2025Global privacy laws

Reported fraud losses in Canada in 2025; the Canadian Anti-Fraud Centre says more than 112,000 reports were received and reported losses exceeded CA$704 million.

Source (Survey / industry / secondary): Canadian Anti-Fraud Centre, Fraud Prevention Month 2026

CA$7.11 million

2026Global privacy laws

Average cost of a data breach for Canadian organizations in IBM's 2026 report, a record high since the study began.

Source (Survey / industry / secondary): IBM Canada, Canada's Data Breach Costs Hit Record High

R$ 50 million

2026Global privacy laws

Maximum administrative fine per infraction under Article 52 of Brazil's LGPD (Lei Geral de Proteção de Dados), capped at 2% of annual revenue in Brazil.

Source (Survey / industry / secondary): ANPD, Brazilian Data Protection Law (LGPD), Article 52

₹250 crore

2023Global privacy laws

Maximum penalty listed in the Schedule to India's Digital Personal Data Protection Act, 2023 for breach of a data fiduciary's duty to take reasonable security safeguards to prevent personal-data breaches; commencement of the Act is phased, so this does not claim the provision is currently in force or has been imposed.

Source (Survey / industry / secondary): MeitY, Digital Personal Data Protection Act 2023, Schedule

€4.04+ billion

2025Global privacy laws

Cumulative GDPR fines issued by Ireland's Data Protection Commission since May 2018, as reported in its 2025 annual report.

Source (Survey / industry / secondary): Data Protection Commission, Annual Report 2025

CHF 250,000

2026Global privacy laws

Maximum personal criminal penalty under Article 60 of Switzerland's revised Federal Act on Data Protection for specified intentional violations by responsible individuals; this is not a corporate administrative fine.

Source (Survey / industry / secondary): FDPIC, Criminal law under the revised FADP

Current service

2026Global privacy laws

Lista Robinson is a consumer advertising-exclusion service provided by Adigital; its privacy policy says citizens can express a desire not to receive commercial communications through specified channels, subject to the service rules. A current participant count is not claimed here.

Source (Survey / industry / secondary): Lista Robinson, consumer service and privacy policy

Current service

2026Global privacy laws

Italy's Registro Pubblico delle Opposizioni lets consumers register fixed and mobile numbers, and certain postal addresses, to oppose telemarketing; prior consent is generally annulled subject to later consent and continuing-contract exceptions. A current membership count is not claimed here.

Source (Survey / industry / secondary): Registro Pubblico delle Opposizioni, citizen service

Outcome of sending a verified consumer access request to all 543 California-registered data brokers: 43% never responded, while 57% responded and 90.7% of responding brokers replied within the 45-day legal window.
When UC Irvine sent a verified consumer access request to every California-registered broker, the friction wasn't speed, it was the 43% that never answered at all.

Source for the figure: UC Irvine / Bren School of ICS study summary. This is an independent study of its defined sample, not a universal compliance rate for every broker.

Academic & Journalistic Attribution

Cite This Dataset

Updated September 2026

Every entry names and links its source. Government and regulator records are preferred for legal, registry, breach, and enforcement claims; survey, academic, and commercial sources are labeled in the entry and should not be treated as regulator findings.

APA Format
OfflistMe. (September 2026). Data Broker & Privacy Statistics (2026): Source-Linked Statistics Collection. OfflistMe Research. https://www.offlist.me/privacy-statistics
MLA Format
OfflistMe. "Data Broker & Privacy Statistics (2026)." OfflistMe Research Repository, September 2026, https://www.offlist.me/privacy-statistics.
BibTeX Format
@misc{offlistme_privacy_stats_2026,
  author = {Kandoriya, Rahul and OfflistMe Research},
  title = {Data Broker and Privacy Statistics 2026: Source-Linked Statistics Collection},
  year = {2026},
  publisher = {OfflistMe},
  url = {https://www.offlist.me/privacy-statistics}
}
EmbedHTML Format
<blockquote class="offlistme-stat-cite">
  <p>Source: <a href="https://www.offlist.me/privacy-statistics" target="_blank" rel="noopener">OfflistMe Privacy Statistics (2026)</a></p>
</blockquote>

Open Data License: CC BY 4.0 — Free to reuse with canonical link attribution to OfflistMe.

Generate requests in under 60 seconds

You are in the ~1,000+-broker dataset right now

The numbers above describe an industry built on your personal data. OfflistMe drafts user-reviewed privacy request drafts you send from your own inbox, one flat fee, no subscription.

One-time from $9

How We Source and Verify These Numbers

Every figure on this page links to a named source. Evidence types include government records, regulator filings, academic research, surveys, commercial estimates, and secondary trackers; the explorer labels those boundaries. We cite the data year, which can differ from publication date. Where a figure is an estimate, we identify it as such and do not present it as a regulator finding. Spot a figure that has moved? Contact our research team for verification and updates.

Related Privacy & Regulatory Resources