Skip to main content
Explainer · Source snapshot August 25, 2026

What Is a Data Broker?

A data broker is a company that may collect personal information from public records, online activity, commercial sources, or other providers, then sell, license, or share it with third parties. You may have no direct relationship with the provider. The exact data, purpose, recipient, and legal basis depend on the provider and jurisdiction.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 25, 2026

Canonical definition

A data broker is a legal term with jurisdiction-specific definitions. This working definition describes a business that collects and sells or shares consumer information with third parties without a direct consumer relationship; compare the applicable statute or registry definition before treating it as a legal classification. (Adapted for explanation from California Civil Code § 1798.99.80 and Vermont's data broker registry statute, 9 V.S.A. ch. 62, as in force on the review date; Vermont Act 138 (2026) changes parts of that chapter effective January 1, 2027.)

What Do Data Brokers Do?

Providers may collect information from public records, online activity, commercial transactions, and other providers. They may match fragments into profiles, add inferred details, and sell or license access for marketing, screening, risk, enrichment, or other business purposes; the actual products and practices must be checked provider by provider.

How does a data broker get your information?

Data brokers may collect personal information from three broad source categories. First, public and commercial sources: records, transactions, memberships, and other business-held information, where collection and reuse depend on the source and applicable law. Second, online services: websites, apps, advertising systems, and other services may generate activity, device, or location data under their own terms and permissions. Third, other data providers: a broker may license, purchase, or receive information from another company. A broker may then match fragments using identifiers such as phone numbers, email addresses, physical addresses, or device identifiers. California’s CCPA provides a deletion right for covered businesses, subject to verification and exceptions; GDPR Article 17 includes a right to erasure in specified circumstances and with exceptions. Read the underlying law before relying on a right in a particular case.

Think of a data broker as an information aggregator running four processes simultaneously:

  1. 1

    Collect

    Obtain information from public records, commercial sources, online services, and other data providers; the mix varies by broker and jurisdiction.

  2. 2

    Match

    Use identifiers such as email, phone, address, device ID, or cookie ID to link fragments into a consumer profile.

  3. 3

    Enrich

    Append additional attributes or inferences, such as estimated income, household characteristics, interests, or risk categories, where the provider offers them.

  4. 4

    Sell

    Offer the profile for sale: bulk lists for direct marketing, query access for background checks, per-record API calls for fraud detection, and segmented audiences for ad targeting.

Diagram of the data broker pipeline showing four stages: Collect (public records, app tracking, retailer lists, other brokers), Match (linking fragments by email, phone, address and device ID into one profile), Enrich (appending possible household, interest, income, or risk attributes), and Sell (bulk marketing lists, background-check query access, per-record API calls and ad-targeting segments).
The data broker pipeline: information may be collected, matched into a profile, enriched with additional attributes, and sold or licensed without a direct relationship between you and each provider.

The important thing to notice in this pipeline is that you may not be the customer. A broker may not need a direct account relationship with you to process information, but the exact collection and use depend on its business model, disclosures, and the law. A profile may reappear if a provider obtains new information or retains information under an applicable exception, which is why a single removal request may not be permanent. (We cover that cycle in detail in why your data keeps reappearing.)

What are the categories of data brokers?

Not every broker is the same. These are illustrative US categories and examples, not an exhaustive classification or endorsement:

CategoryExamplesPurpose
People-search sitesWhitepages, Spokeo, TruePeopleSearchPublic name/address lookup
Background-check providersBeenVerified, Intelius, CheckpeopleIdentity verification, employment screening
B2B sales dataZoomInfo, Apollo.io, LushaB2B prospecting, sales intelligence
Marketing data aggregatorsAcxiom, Epsilon, Experian MarketingAd targeting, audience segmentation
Credit-adjacentLexisNexis, TLOxpUnderwriting, fraud detection
Property and automotiveCoreLogic, Carfax, Realtor.comReal-estate and vehicle intelligence
Health data brokersIQVIA, Acxiom HealthPharmaceutical marketing
Location data brokersVeraset, SafegraphFoot-traffic and mobility data

Data broker vs. data processor: what is the difference?

These labels describe different questions. A data broker describes a business model or information role; a data processor or service provider describes how a company may handle information for another organization; and a first-party service collects information directly for its own product. A company can have more than one role across products or clients, so verify the relevant notice and jurisdiction.

Role or modelTypical relationshipWhat to verify
Data brokerMay collect, match, sell, license, or share information about people who are not direct customers.Sources, products, recipients, opt-out or deletion route, and the provider's legal scope.
Processor or service providerMay handle information on behalf of a client under defined instructions rather than operating an independent consumer database.Controller/client relationship, contract role, request channel, and whether the request reaches the client.
First-party serviceOften collects information directly when you create an account, buy something, visit a site, or use an app.Account controls, privacy notice, retention, sharing, and whether separate partners receive the data.
Public-record custodianA court, agency, or other public body may create or maintain an official record under its own rules.Correction, sealing, expungement, disclosure, and public-access procedures for that jurisdiction.

The practical consequence is that a request to one company may not reach a client, source agency, affiliate, or downstream copy. Record the exact entity, page, data category, and request route before treating a response as complete.

How do data brokers affect you?

Spam and unwanted contact

Contact information may be used for marketing or outreach.

Impersonation risk

Aggregated identifiers can make social-engineering attempts easier.

Stalking and harassment

Public-facing profiles can expose address or contact information.

Discriminatory targeting

Inferred or sensitive attributes can be used to segment audiences.

Screening and eligibility concerns

Inaccurate or incomplete records can affect decisions where they are used.

Loss of control

Information may circulate between providers beyond your direct visibility.

What legal rights do you have against data brokers?

Depending on where you live, the provider involved, and the applicable exemptions, you may have one or more of these rights in relation to personal-data processing:

  • Deletion or erasure

    Some laws provide a right to request deletion or erasure, but coverage, exemptions, verification, and the legal grounds differ.

  • Access

    Some laws allow you to ask what personal information a covered business holds or how it is used and shared.

  • Correction

    Some laws provide a right to correct inaccurate information; the scope and exceptions vary.

  • Opt out of sale or targeted advertising

    Several privacy laws provide opt-out rights, but the definitions of sale, sharing, targeting, and covered business differ.

  • Profiling and automated decisions

    Some jurisdictions provide specific rights around profiling or significant automated decisions; do not assume the right applies to every use.

  • Universal opt-out signals

    Some jurisdictions or covered businesses recognize browser-based signals such as Global Privacy Control under defined conditions.

Primary sources and limits

This guide explains common models; it does not determine whether a particular broker or request is lawful. For a specific claim, start with the underlying regulator, statute, registry filing, or provider disclosure.

Reviewed August 25, 2026. Laws, registries, and provider practices change; verify a time-sensitive issue against the current official source.

Generate requests in under 60 seconds

Generate request drafts for 1,009 US/global workflow profiles for $9

OfflistMe generates browser-local request drafts for selected catalog profiles. You review and send them from your own inbox; the directory shows recorded routes, source dates, and evidence limits. The 1,027-record research catalog is not a guarantee that a provider has your record or will complete a request.

FAQ

What is a data broker in simple terms?+

A data broker is a company that collects personal information from sources such as public records, commercial sources, websites, apps, or other brokers, then sells, licenses, or shares it with third parties. A consumer may not have a direct relationship with the broker.

How can I tell whether a company is a data broker?+

Check what the company says it collects, whose information it handles, whether it sells or licenses information to third parties, and whether it offers a consumer-facing lookup, audience, enrichment, screening, or identity product. A privacy notice, regulator registry filing, contract, or response to an access request is stronger evidence than the company name alone.

Are all data brokers the same?+

No. People-search, marketing, B2B, location, property, health, credit-adjacent, and screening providers can have different sources, customers, data fields, request routes, and legal obligations. Classify a specific provider from its documented products and practices rather than assuming that one opt-out or law covers every category.

How do data brokers get my information?+

Data may come from public records, commercial sources, online services, public websites, and other brokers. Which sources a particular broker uses is fact-specific; its privacy notice, registry filing, or response to an access request is stronger evidence than a generic industry assumption.

Are data brokers legal?+

There is no single yes-or-no rule for every business or activity. Data brokerage can be lawful, but a broker may also be subject to consumer-protection rules, privacy laws, sector-specific laws, registration requirements, and restrictions on how particular data is collected, used, or sold. California publishes a data-broker registry, and the FTC enforces the FTC Act against unfair or deceptive acts or practices. The answer depends on the jurisdiction and facts; this explainer is not legal advice.

How many data brokers are there?+

There is no universally authoritative global count. Registries use different legal definitions and reporting scopes, and many providers do not appear in a particular state registry. OfflistMe currently tracks 1,027 research records and separately labels 1,009 US/global workflow profiles, discovery records, and evidence gaps; that is our catalog scope, not a census of every global broker.

Can I remove myself from every data broker?+

You cannot assume that one request reaches every broker. California residents may use the California Privacy Protection Agency's DROP program within its defined scope; check the agency's current participation, processing, verification, and timing guidance before relying on it. Outside that scope, requests remain provider- and jurisdiction-specific. Coverage, identity verification, deadlines, and exceptions depend on the applicable law. OfflistMe can draft requests for selected catalog profiles; you review and send them from your own inbox.

What is the difference between a data broker and a people-search site?+

A people-search site is generally a consumer-facing type of data broker that offers lookup by identifiers such as a name, phone number, address, or email. Other broker categories may sell marketing, screening, property, location, or B2B data through business products rather than a public search page. Categories overlap, so classify a specific provider from its documented products and practices.

Why would a data broker have my information if I have never used their service?+

A lack of direct interaction with a broker does not rule out collection. A provider may obtain information from public records, commercial sources, online services, or other data providers, subject to the law and the provider's documented practices. That chain can move information between organizations without a separate account or consent interaction with each broker.

How much money do data brokers make from my data?+

The business model varies by provider. Some brokers license audience, contact, professional, risk, or identity data to businesses; others operate people-search products or provide enrichment and screening services. There is no single authoritative global revenue figure or universal per-record price: definitions, products, jurisdictions, and contract terms differ. Treat provider disclosures and official filings as the source of record for a specific claim.

Which federal laws regulate data brokers?

Different broker categories fall under different federal statutes. Here are the regimes that matter, and the gaps between them.

Related explainers