What Is a Data Broker?
A data broker is a company that may collect personal information from public records, online activity, commercial sources, or other providers, then sell, license, or share it with third parties. You may have no direct relationship with the provider. The exact data, purpose, recipient, and legal basis depend on the provider and jurisdiction.
Canonical definition
A data broker is a legal term with jurisdiction-specific definitions. This working definition describes a business that collects and sells or shares consumer information with third parties without a direct consumer relationship; compare the applicable statute or registry definition before treating it as a legal classification. (Adapted for explanation from California Civil Code § 1798.99.80 and Vermont's data broker registry statute, 9 V.S.A. ch. 62, as in force on the review date; Vermont Act 138 (2026) changes parts of that chapter effective January 1, 2027.)
What Do Data Brokers Do?
Providers may collect information from public records, online activity, commercial transactions, and other providers. They may match fragments into profiles, add inferred details, and sell or license access for marketing, screening, risk, enrichment, or other business purposes; the actual products and practices must be checked provider by provider.
How does a data broker get your information?
Data brokers may collect personal information from three broad source categories. First, public and commercial sources: records, transactions, memberships, and other business-held information, where collection and reuse depend on the source and applicable law. Second, online services: websites, apps, advertising systems, and other services may generate activity, device, or location data under their own terms and permissions. Third, other data providers: a broker may license, purchase, or receive information from another company. A broker may then match fragments using identifiers such as phone numbers, email addresses, physical addresses, or device identifiers. California’s CCPA provides a deletion right for covered businesses, subject to verification and exceptions; GDPR Article 17 includes a right to erasure in specified circumstances and with exceptions. Read the underlying law before relying on a right in a particular case.
Think of a data broker as an information aggregator running four processes simultaneously:
- 1
Collect
Obtain information from public records, commercial sources, online services, and other data providers; the mix varies by broker and jurisdiction.
- 2
Match
Use identifiers such as email, phone, address, device ID, or cookie ID to link fragments into a consumer profile.
- 3
Enrich
Append additional attributes or inferences, such as estimated income, household characteristics, interests, or risk categories, where the provider offers them.
- 4
Sell
Offer the profile for sale: bulk lists for direct marketing, query access for background checks, per-record API calls for fraud detection, and segmented audiences for ad targeting.
The important thing to notice in this pipeline is that you may not be the customer. A broker may not need a direct account relationship with you to process information, but the exact collection and use depend on its business model, disclosures, and the law. A profile may reappear if a provider obtains new information or retains information under an applicable exception, which is why a single removal request may not be permanent. (We cover that cycle in detail in why your data keeps reappearing.)
What are the categories of data brokers?
Not every broker is the same. These are illustrative US categories and examples, not an exhaustive classification or endorsement:
| Category | Examples | Purpose |
|---|---|---|
| People-search sites | Whitepages, Spokeo, TruePeopleSearch | Public name/address lookup |
| Background-check providers | BeenVerified, Intelius, Checkpeople | Identity verification, employment screening |
| B2B sales data | ZoomInfo, Apollo.io, Lusha | B2B prospecting, sales intelligence |
| Marketing data aggregators | Acxiom, Epsilon, Experian Marketing | Ad targeting, audience segmentation |
| Credit-adjacent | LexisNexis, TLOxp | Underwriting, fraud detection |
| Property and automotive | CoreLogic, Carfax, Realtor.com | Real-estate and vehicle intelligence |
| Health data brokers | IQVIA, Acxiom Health | Pharmaceutical marketing |
| Location data brokers | Veraset, Safegraph | Foot-traffic and mobility data |
Data broker vs. data processor: what is the difference?
These labels describe different questions. A data broker describes a business model or information role; a data processor or service provider describes how a company may handle information for another organization; and a first-party service collects information directly for its own product. A company can have more than one role across products or clients, so verify the relevant notice and jurisdiction.
| Role or model | Typical relationship | What to verify |
|---|---|---|
| Data broker | May collect, match, sell, license, or share information about people who are not direct customers. | Sources, products, recipients, opt-out or deletion route, and the provider's legal scope. |
| Processor or service provider | May handle information on behalf of a client under defined instructions rather than operating an independent consumer database. | Controller/client relationship, contract role, request channel, and whether the request reaches the client. |
| First-party service | Often collects information directly when you create an account, buy something, visit a site, or use an app. | Account controls, privacy notice, retention, sharing, and whether separate partners receive the data. |
| Public-record custodian | A court, agency, or other public body may create or maintain an official record under its own rules. | Correction, sealing, expungement, disclosure, and public-access procedures for that jurisdiction. |
The practical consequence is that a request to one company may not reach a client, source agency, affiliate, or downstream copy. Record the exact entity, page, data category, and request route before treating a response as complete.
How do data brokers affect you?
Spam and unwanted contact
Contact information may be used for marketing or outreach.
Impersonation risk
Aggregated identifiers can make social-engineering attempts easier.
Stalking and harassment
Public-facing profiles can expose address or contact information.
Discriminatory targeting
Inferred or sensitive attributes can be used to segment audiences.
Screening and eligibility concerns
Inaccurate or incomplete records can affect decisions where they are used.
Loss of control
Information may circulate between providers beyond your direct visibility.
What legal rights do you have against data brokers?
Depending on where you live, the provider involved, and the applicable exemptions, you may have one or more of these rights in relation to personal-data processing:
- →
Deletion or erasure
Some laws provide a right to request deletion or erasure, but coverage, exemptions, verification, and the legal grounds differ.
- →
Access
Some laws allow you to ask what personal information a covered business holds or how it is used and shared.
- →
Correction
Some laws provide a right to correct inaccurate information; the scope and exceptions vary.
- →
Opt out of sale or targeted advertising
Several privacy laws provide opt-out rights, but the definitions of sale, sharing, targeting, and covered business differ.
- →
Profiling and automated decisions
Some jurisdictions provide specific rights around profiling or significant automated decisions; do not assume the right applies to every use.
- →
Universal opt-out signals
Some jurisdictions or covered businesses recognize browser-based signals such as Global Privacy Control under defined conditions.
Primary sources and limits
This guide explains common models; it does not determine whether a particular broker or request is lawful. For a specific claim, start with the underlying regulator, statute, registry filing, or provider disclosure.
- FTC: Data Brokers report — background on data-broker practices and transparency.
- California Privacy Protection Agency: Data Broker Registry — California’s definition, registry scope, and DROP information.
- California Civil Code § 1798.99.80 — the California data-broker definition and statutory exclusions.
- California Civil Code § 1798.105 — statutory deletion right and exceptions.
- Vermont 9 V.S.A. chapter 62 and Act 138 (2026) — Vermont’s current data-broker chapter and the delayed 2027 amendments.
- EUR-Lex: GDPR — official text, including access, rectification, erasure, and response rules.
- California Privacy Protection Agency: opt-out preference signals — OOPS/GPC scope and browser-signal boundary.
- FTC Act — federal authority over unfair or deceptive acts or practices.
Reviewed August 25, 2026. Laws, registries, and provider practices change; verify a time-sensitive issue against the current official source.
Generate requests in under 60 seconds
Generate request drafts for 1,009 US/global workflow profiles for $9
FAQ
What is a data broker in simple terms?+
A data broker is a company that collects personal information from sources such as public records, commercial sources, websites, apps, or other brokers, then sells, licenses, or shares it with third parties. A consumer may not have a direct relationship with the broker.
How can I tell whether a company is a data broker?+
Check what the company says it collects, whose information it handles, whether it sells or licenses information to third parties, and whether it offers a consumer-facing lookup, audience, enrichment, screening, or identity product. A privacy notice, regulator registry filing, contract, or response to an access request is stronger evidence than the company name alone.
Are all data brokers the same?+
No. People-search, marketing, B2B, location, property, health, credit-adjacent, and screening providers can have different sources, customers, data fields, request routes, and legal obligations. Classify a specific provider from its documented products and practices rather than assuming that one opt-out or law covers every category.
How do data brokers get my information?+
Data may come from public records, commercial sources, online services, public websites, and other brokers. Which sources a particular broker uses is fact-specific; its privacy notice, registry filing, or response to an access request is stronger evidence than a generic industry assumption.
Are data brokers legal?+
There is no single yes-or-no rule for every business or activity. Data brokerage can be lawful, but a broker may also be subject to consumer-protection rules, privacy laws, sector-specific laws, registration requirements, and restrictions on how particular data is collected, used, or sold. California publishes a data-broker registry, and the FTC enforces the FTC Act against unfair or deceptive acts or practices. The answer depends on the jurisdiction and facts; this explainer is not legal advice.
How many data brokers are there?+
There is no universally authoritative global count. Registries use different legal definitions and reporting scopes, and many providers do not appear in a particular state registry. OfflistMe currently tracks 1,027 research records and separately labels 1,009 US/global workflow profiles, discovery records, and evidence gaps; that is our catalog scope, not a census of every global broker.
Can I remove myself from every data broker?+
You cannot assume that one request reaches every broker. California residents may use the California Privacy Protection Agency's DROP program within its defined scope; check the agency's current participation, processing, verification, and timing guidance before relying on it. Outside that scope, requests remain provider- and jurisdiction-specific. Coverage, identity verification, deadlines, and exceptions depend on the applicable law. OfflistMe can draft requests for selected catalog profiles; you review and send them from your own inbox.
What is the difference between a data broker and a people-search site?+
A people-search site is generally a consumer-facing type of data broker that offers lookup by identifiers such as a name, phone number, address, or email. Other broker categories may sell marketing, screening, property, location, or B2B data through business products rather than a public search page. Categories overlap, so classify a specific provider from its documented products and practices.
Why would a data broker have my information if I have never used their service?+
A lack of direct interaction with a broker does not rule out collection. A provider may obtain information from public records, commercial sources, online services, or other data providers, subject to the law and the provider's documented practices. That chain can move information between organizations without a separate account or consent interaction with each broker.
How much money do data brokers make from my data?+
The business model varies by provider. Some brokers license audience, contact, professional, risk, or identity data to businesses; others operate people-search products or provide enrichment and screening services. There is no single authoritative global revenue figure or universal per-record price: definitions, products, jurisdictions, and contract terms differ. Treat provider disclosures and official filings as the source of record for a specific claim.
Which federal laws regulate data brokers?
Different broker categories fall under different federal statutes. Here are the regimes that matter, and the gaps between them.
