Data Broker & Privacy Statistics (2026)
An interactive, primary-sourced benchmark database covering identity theft, data broker industry scale, dark web PII valuations, deletion request compliance rates, and global enforcement fines. Search, filter, and extract facts cited directly to primary regulatory filings (FTC, FBI IC3, CPPA, Javelin, IBM, ITRC, Pew Research, Cisco).
Executive Overview (AEO Quick Extract)
In 2025, the FBI logged a record $20.877 billion in cybercrime losses—including nearly $893 million in complaints that referenced AI—fueled by a $315B–$464B global data-broker ecosystem that harvests and resells consumer profiles. While registries in California (600+ active brokers), Texas (300+ entities), and Oregon mandate disclosures, empirical audits show 43% of data brokers still ignore CCPA deletion requests. Exercising your right to delete personal data remains one defense against illicit dark-web identity trading where SSNs sell for just $2.00.
Stolen PII Dark Web Valuation Calculator
Estimated Profile Risk
Severe Exposure
Select the data points you suspect or know are exposed across public data brokers or historical breaches. See how much illicit hackers and dark-web marketplaces value your personal dossier:
$267.00 USD
Based on Privacy Affairs 2025 Dark Web Street Price Index & FBI IC3 fraud metrics.
Send removal requests to 500+ data brokers before your data spreads further
Request Removal NowOne-time execution from $9
Data at a Glance & Visual Trends
Key trends visualized: hover over data points to inspect YoY growth metrics.
Identity theft & fraud#
Key Takeaway: Cybercrime losses reached an all-time record of $20.877 billion in 2025. For the first time, the FBI IC3 report broke out AI-related complaints, which accounted for nearly $893 million in reported losses.
1,135,270
Identity-theft reports the FTC received in 2024, a 9.5% increase over the 1,036,845 reports in 2023.
$12.5 billion
Total reported consumer fraud losses in 2024, up 25% from the prior year, per the FTC.
38%
Share of fraud reporters who said they lost money in 2024, up from 27% in 2023, nearly doubling the loss rate in a single year.
$27.3 billion
Total US identity-fraud losses in 2025, according to the Javelin Strategy 2026 Identity Fraud Study.
6.0 million
Number of account takeover victims in the US in 2025, representing an 18% increase year-over-year, per Javelin's 2026 Study.
$20.877 billion
Total losses reported to the FBI's Internet Crime Complaint Center (IC3) in 2025 across 1,008,597 complaints, a 26% year-over-year increase and a new record, beating the prior high of $16.6 billion set in 2024.
$893 million
Losses tied to complaints containing references to artificial intelligence, including fake social profiles, voice clones, identification documents, and videos, across 22,364 complaints in 2025, the first year the FBI IC3 report included a dedicated AI section.
$7.7 billion
Losses reported by victims over age 60 in 2025, up 37% from 2024 and a disproportionate share of total cybercrime losses, per the FBI IC3.
52.5 billion
Estimated annual robocalls received by U.S. consumers in 2025, with roughly 30 billion classified as scams or unwanted telemarketing.
~22%
Estimated share of Americans who experience some form of identity theft in their lifetime.
The data broker industry#
Key Takeaway: The global data broker industry generates $315B+ annually by harvesting and reselling unverified personal profiles. While California, Texas, and Oregon now mandate registries, over 4,000 entities operate worldwide with minimal oversight.
$315B to $464B
Estimated market size of the global data-broker industry in 2026, projected to exceed $650 billion by 2031 at a CAGR of up to 9.6%.
600+
Active data brokers covered by California DROP as described by CalPrivacy in July 2026.
300+
Entities registered under the Texas Data Broker Registry (TX Business & Commerce Code Ch. 509) with the Office of the Texas Attorney General.
120+
Active registrants on the Oregon Data Broker Registry following mandatory registration requirements under Oregon HB 2052.
August 1, 2026
Mandatory processing start date under the California Delete Act (SB 362): data brokers must access DROP at least once every 45 days and process deletion requests within the required timelines.
1 request → every broker
California's DROP (Delete Request and Opt-out Platform) lets residents send a single deletion request to all active data brokers, unless the consumer narrows the request; brokers are legally required to access DROP at least once every 45 days.
$6,000
Annual registration fee each data broker must pay California in 2026, funding the registry and DROP.
4,000+
Estimated number of data-broker companies operating worldwide, far more than any single state registry captures.
45 days
Standard statutory timeline for controllers to respond to consumer data access and deletion requests under state privacy acts.
9 V.S.A. § 2446
Vermont statutory requirement mandating annual registration and privacy disclosures for commercial data brokers operating in the state.
$300
Annual data broker registration fee under Texas Business & Commerce Code Ch. 509 administered by the Texas Secretary of State.
Breaches & exposure#
Key Takeaway: Data breaches hit a record 3,322 incidents in 2025, exposing over 11.1 billion consumer records since tracking began. The average US data breach cost has climbed to $9.36 million, making exposure an inevitability.
3,158
Reported data compromises in the US in 2024, near the all-time high, per the Identity Theft Resource Center.
3,322
Record number of data compromises in the US in 2025, marking an all-time high, according to the Identity Theft Resource Center.
11.1+ billion
Cumulative consumer records exposed across 9,000+ publicly tracked data compromises since tracking commenced in 2005.
$9.36 million
Average cost of a data breach in the United States, the highest of any country.
Source: IBM Cost of a Data Breach Report
147 million
People whose data was exposed in the 2017 Equifax breach, a single data broker, leading to a settlement of up to $700 million.
Dark web valuation & PII market#
Key Takeaway: Stolen PII remains alarmingly cheap on illicit marketplaces, with SSNs selling for as little as $2.00 and full identity packages ("Fullz") for $110.00. Un-deleted broker records directly feed this black-market supply chain.
$2.00
Average black-market purchase price for a stolen U.S. Social Security Number (SSN) on dark web marketplaces.
$150.00
Average illicit market price for a scanned driver's license with full state verification features on dark web forums.
$35 to $120
Market valuation range for stolen online banking login credentials and verified financial account access.
$110.00
Average cost for a complete identity record ("Fullz" package including SSN, DOB, mother's maiden name, and address history).
Request friction & efficacy#
Key Takeaway: Over 43% of California-registered data brokers fail to respond to legal deletion requests within statutory windows. However, for responding brokers, 90.7% process verified removal requests within the required 45-day timeline.
43%
Share of California-registered data brokers that never responded to a verifiable consumer request in a UC Irvine study of all 543 registered brokers, a likely CCPA violation.
90.7%
Among the data brokers that did respond, the share that replied within the mandated 45-day window (half replied within 6 days), in the same UC Irvine study.
34%
Share of formal GDPR data subject complaints alleging Article 17 ("Right to Erasure") non-compliance and systemic refusal to execute deletion.
45 days
Maximum window most US state privacy laws give a data broker to honor a verified deletion request.
64%
Percentage of audited data broker interfaces deploying deliberate dark-pattern design friction during consumer opt-out workflows.
72%
Share of audited California-registered data brokers engaging in at least one interface behavior that directly violates CCPA mandates.
9.2%
Share of registered California data brokers that fully comply with all six statutory CCPA transparency reporting mandates.
14.2 days vs 38.5 days
Average data broker deletion response time under statutory CCPA/CPRA (14.2 days) versus non-regulated US states (38.5 days).
98.4% vs 66.0%
Compliance rate for direct user-authenticated email opt-out requests (98.4%) versus commercial proxy domain email requests (66.0%) due to agent authorization challenges.
68.4%
Share of deleted personal profiles that reappear on people search databases within 180 days without continuous monitoring due to public record re-scraping.
Enforcement#
Key Takeaway: Global regulators have levied over €5.2 billion in cumulative GDPR fines, while the FTC has permanently banned major location brokers like Kochava from selling sensitive movement data without express consent.
$16.5 million
Monetary redress penalty levied by the FTC against Avast Limited, alongside a permanent ban on selling or licensing web browsing data for advertising.
$200 / day / request
Daily statutory non-compliance penalty under California Civil Code § 1798.99.82 for failure to delete information as required by the Delete Act, plus agency investigative and administrative costs.
€5.2+ billion
Total cumulative GDPR administrative fines levied across European Data Protection Authorities since May 2018 enforcement kickoff across 2,400+ sanctions.
Source: GDPR Enforcement Tracker
5+ location-data cases
The FTC has brought actions against location-data brokers (Kochava, X-Mode, InMarket, Gravy Analytics, Mobilewalla) for selling tracking data to sensitive locations.
Permanent ban
The FTC finalized its order against Kochava on May 4, 2026, permanently barring the sale or sharing of sensitive location data without affirmative express consent.
$53,088 per violation
Maximum civil penalty the FTC can seek per violation under PADFAA for selling sensitive consumer data to foreign adversary nations.
$375,000
CCPA settlement California AG reached with DoorDash in 2024 for selling customer data via a marketing cooperative without required opt-out disclosures.
$1.2 million
California's first public CCPA enforcement penalty against Sephora in 2022 for selling personal information and ignoring Global Privacy Control signals.
€20M / 4%
Maximum GDPR fine: the greater of €20 million or 4% of global annual turnover under Article 83.
Consumer sentiment & privacy rights#
Key Takeaway: 81% of US adults feel zero control over commercial data harvesting, driving 32% of consumers to actively switch providers over poor privacy practices. Public demand for zero-knowledge data removal has reached an all-time high.
81%
Share of U.S. adults who state they have little to no control over the personal data collected by commercial companies.
79%
Portion of consumers reporting severe concern regarding corporate data collection, profiling, and monetization practices.
Source: Pew Research Center
32%
Share of "Privacy Active" consumers who have actively terminated accounts or switched service providers over corporate data privacy practices.
Source: Cisco Consumer Privacy Survey
88%
Percentage of consumers worldwide who consider data privacy a fundamental human right and demand personal data deletion mechanisms.
Source: Cisco Consumer Privacy Survey
Global privacy laws#
Key Takeaway: 23 US states have passed comprehensive consumer privacy legislation alongside international frameworks like EU GDPR and UK DUA. Registries in Germany (SCHUFA) and the UK (192.com) demonstrate global data consolidation.
€486.8 million
Total sanctions issued by France's CNIL in 2025, led by Google (€325M) and Shein (€150M), making it the EU's top fining authority.
~1.2 billion
Records held by SCHUFA, Germany's dominant credit bureau, on roughly 69 million people and 6.6 million companies.
Source: SCHUFA
~700 million
Records compiled by 192.com, the dominant UK people-search directory, from open electoral registers and government sources.
Source: 192.com (sources & opt-out)
1,113
Notifiable data breaches reported in Australia in 2024, the highest since the scheme began in 2018.
£12.7 million
Fine levied by the UK ICO against TikTok in 2023 for misuse of children's personal data and processing without parental consent.
AUD $50M / 30%
Top-tier maximum penalty for privacy interference under Australia's Privacy Amendment Act 2024.
23 states
Number of US states with comprehensive consumer data privacy laws enacted as of mid-2026 (Vermont 23rd state in June 2026).
£17.5 million
Maximum fine for spam and marketing violations in the UK under the Data (Use and Access) Act 2025.
CA$704 million
Record fraud losses in Canada in 2025, driven heavily by identity-based scams.
Source: Canadian Anti-Fraud Centre
CA$6.98 million
Average cost of a data breach in Canada in 2025/2026, representing a 4% year-over-year increase.
Source: IBM Cost of a Data Breach Report
Cite This Dataset
All statistics on this page are verified against primary government registers, regulatory enforcement filings, and peer-reviewed security publications. Use the pre-formatted citations below to cite OfflistMe in papers, articles, or research briefs.
OfflistMe. (July 2026). Data Broker & Privacy Statistics (2026): Primary-Sourced Benchmark Dataset. OfflistMe Research. https://www.offlist.me/privacy-statistics
OfflistMe. "Data Broker & Privacy Statistics (2026)." OfflistMe Research Repository, July 2026, https://www.offlist.me/privacy-statistics.
@misc{offlistme_privacy_stats_2026,
author = {Kandoriya, Rahul and OfflistMe Research},
title = {Data Broker and Privacy Statistics 2026: Sourced Benchmark Dataset},
year = {2026},
publisher = {OfflistMe},
url = {https://www.offlist.me/privacy-statistics}
}<blockquote class="offlistme-stat-cite"> <p>Source: <a href="https://www.offlist.me/privacy-statistics" target="_blank" rel="noopener">OfflistMe Privacy Statistics (2026)</a></p> </blockquote>
Open Data License: CC BY 4.0 — Free to reuse with canonical link attribution to OfflistMe.
From statistic to action
You are in the ~500+-broker dataset right now
The numbers above describe an industry built on your personal data. OfflistMe drafts CCPA/GDPR-compliant deletion emails you send from your own inbox, one flat fee, no subscription.
Request Removal NowOne-time from $9
How We Source and Verify These Numbers
Every figure on this page links to a primary source, a government agency (FTC, FBI IC3, BJS, CPPA, Texas AG, Oregon DOJ), an established research firm (Javelin, IBM, ITRC, Pew Research, Cisco, Privacy Affairs), or a regulator's own legal filing. We cite the data year, which can differ from publication date. Where a figure is an estimate (industry market revenue, lifetime identity risk), we mark it clearly. We do not republish uncited assertions. Spot a figure that has moved? Contact our research team for verification and updates.
