Skip to main content

Data Brokers: Your Comprehensive Guide [2026 Update]

Data Brokers: Your Comprehensive Guide [2026 Update]

Laura Martisiute

February 3, 2023

Reading time: 19 minutes

img-databrokers

Every week, your voicemail box fills up with spam. So does your email inbox. You receive strangely personalized scam and phishing texts. The website you’re on knows a little too much about you. 

One of the biggest reasons for all of that is data brokers. 

According to estimates from a few years ago, there are at least 4,000 data brokers in operation today. Some well-known data brokers include Equifax, LexisNexis, and Oracle. As of 2026, there have been no official updates to that number, but privacy experts agree the industry has grown significantly. 

The sheer volume of data these companies hold is unimaginable. An average data broker possesses over 1,000 points about a single individual according to CNBC, everything from their name and home address to family member information and net worth. Acxiom, a top data broker, recently revealed its Consumer List of more than 260 million individuals and 190 million households. 

In most cases, anyone with a credit card can gain access to that data.

The good news is that many data brokers let you opt out of being included in their databases. 

We discuss the exact processes for doing that below. 

But first, what exactly are data brokers, where do they get your data, and what do they know about you? Perhaps most importantly, are they even legal? Read on to find out.

What are Data Brokers?

Data brokers (sometimes also called information brokers or people search sites) are companies that aggregate personally identifiable information from various sources to create individual profiles or listings. 

They then sell these profiles to third parties, including advertisers, marketers, insurance companies, data mining corporations, financial institutions, government agencies, political consultants, and many other entities. 

Some data brokers screen and monitor the individuals or organizations buying data from them. 

For example, they may request to meet or speak with clients or ask them to fill out a credentialing questionnaire. However, few data brokers monitor the purchase or use of their products at all. 

Depending on the type of data they collect and sell, data brokers typically fall within one of three categories:

  1. People search sites
  2. B2B data brokers
  3. “Big data” data brokers

Let’s take a quick look at each one in turn. . 

Get Your Free Scan Now

Find out which data brokers have your info

People search sites

People search sites make it possible for anyone to find any other person’s information online with just their name, or another identifier like a phone number or email. 

Sometimes, you might be able to access that information for free. Other times, you may need to pay a small fee. 

People search sites don’t usually screen or monitor their clients. This means people can use them for more nefarious purposes, like finding information about someone to steal their identity, or for the purposes of stalking or doxxing. 

Examples of a few of the most well-known people search sites include InfoTracer, Whitepages, and Spokeo. 

B2B data brokers

B2B data brokers develop detailed consumer, employee, and/or business profiles to sell to other companies, usually either for marketing purposes or for background checks. 

Thanks to these data brokers, cybercriminals can also get a detailed look at potential targets for the purposes of personalizing phishing campaigns and other attacks. 

One of the most well-known examples of this type of data broker is National Public Data. 

“Big data” brokers

“Big data” brokers mostly consist of credit reporting and fraud prevention agencies. Examples include Equifax, Experian, and TransUnion. 

These types of brokers are pretty much essential to how the modern financial world operates. For example, a lender might use a risk mitigation data broker to ensure that a person looking to open an account with them is indeed who they say they are.

The Problem with Data Brokers

Data brokers are not all bad. In fact, consumers can benefit from some of the purposes that “big data” brokers in particular collect their information for, like preventing fraud. 

At the same time, data brokers, especially people search sites, increase certain risks for consumers. They also violate people’s privacy and make little to no effort to see that the information they sell doesn’t end up in the wrong hands.

Problem #1: Data brokers are underregulated

Due to a lack of regulation, there’s no way to know where our personal data ends up or who uses it. This can lead to direct harm for individuals whose data is available through data brokers. 

For example, information on a data broker website could lead to a rejection for a job or mortgage without a clear reason. 

The exposed personal information of political officials and law enforcement can put them at direct risk of physical attacks, as demonstrated by the assassination of Representative Melissa Hortman. The FBI investigation revealed the suspect’s notebook listed the data brokers where he found her home address. 

Data brokers can sell location data, political affiliations, and other personal data to the government, fueling federal surveillance. 

Right now, it’s all legal. But that doesn’t mean you’re completely powerless. More on that later.

Problem #2: Data broker breaches  put millions of people at risk of identity theft and other harms

Due to the amount of personal data they collect and store, data brokers are prime targets for cybercriminals. A hack or a leak can expose sensitive information, including financial data and social security numbers.

list of data brokers with recent breaches

This has happened before. Just a few years ago, Social Data, a data broker that scraped public social media profiles of companies, accidentally exposed 235 million social media accounts. More recently, the National Public Data breach of 2024 exposed millions of SSNs and has been called one of the largest data breaches of all time. 

Acxiom, Epsilon, and Experian have been hacked. 

One study estimated that just four recent data broker breaches resulted in nearly $21 billion lost to fraud, identity theft, and other harms. 

As the information security professional Daniel Miessler wrote a few years ago, “most people falsely believe that the real danger to their privacy comes from hackers in basements, when it actually comes from big companies with parking lots, coffee budgets, and health benefits for their employees.”

Problem #3: Data brokers don’t care who they sell sensitive information to

In 2023, researchers tested whether 37 known data brokers would be willing to sell sensitive mental health data, including diagnoses and demographic information. The result? Eleven of the companies agreed, for prices as low as $275 per collection of 5,000 mental health records. 

Under California’s new regulations, many data brokers are required to describe the types of data they provide and to what entities. Under that law, at least 33 data brokers reported that they sell personal information to foreign companies. 

Some of those also admitted to selling personal data to AI developers for model training. Once personal info gets caught up in an AI training database, there’s rarely any way to opt out or control where it goes next. 

More on that later. 

Problem #4: Data brokers deliberately make it challenging to opt out

Recent research from the Joint Economic Committee showed many top data brokers deliberately prevent search engines from indexing opt-out pages as of 2026.

That means if you search “[data broker name] opt-out” in your browser, you will never find the page because the search engine hasn’t categorized the page in its library. It’s still possible to opt out if you have a direct link or can find the page through the main website, but data brokers will also make the site structure deliberately confusing so the page is harder to find. 

This is another reason it’s often helpful to have a privacy service like DeleteMe on your side when you want to opt out. Our privacy advisors are very familiar with data brokers’ tactics and hidden web pages.

Problem #5: Even de-anonymized data puts consumers at risk

Although some data brokers claim that the sensitive data they collect, store and sell is anonymized, studies show that de-anonymizing data is relatively easy. 

Many of the apps on your phone collect location data. A broker might sell a “nameless” log of GPS coordinates, but if that data begins and ends at your house every day, stopping at a specific daycare, and parking at a specific location for around eight hours, your name can be figured out. 

AI is particularly good at aggregating enough personal information to deanonymize data and even identify the real person behind an online username with ease based on public posts and conversations. 

This means you may not be as anonymous as you think online. 

These five risks are just the beginning of the many harms data brokers can cause both online and offline. 

The Impact of the Data Brokerage Industry On Business Cybersecurity

The information on data brokers and people search sites also creates risk for businesses, in the form of executive threats, cybersecurity risks and other potential exploits.

Executive threats

Executives are often targeted by activists, disgruntled ex-employees, unhappy customers, and other threat actors. 

It’s not unusual for executives to be subject to harassment, doxxing, stalking, reputational attacks, and identity theft. 

Threat actors do not have to go to significant lengths to find out an executive’s email address or where they live, because this information is easily findable on data brokers and people search sites. 

We often find a higher degree of PII exposure for C-Suite executives (between 15% and 25%) compared to the average employee. 

That said, other high-profile employees and board members, as well as high-risk professionals (law enforcement, journalists, etc.), are at an increased risk of personalized attacks from malicious individuals as well. 

Cybersecurity risks

The personal data that exists about employees and executives on the open web can fuel sophisticated cyber threats like social engineering and make attack techniques like credential stuffing easier. 

For example, if a threat actor can personalize a phishing email to a specific employee, their success rate will be much higher than if they were to send a generic message. 

Learn more: OSINT: how cybercriminals use open source intelligence for social engineering 

We know from ContiLeaks that ransomware groups use data brokers to find targets to spearphish and contacts they can “name drop” within emails to make them seem more believable. 

Data broker profile to answer what are data brokers

Similarly, if a hacker knows enough information about an employee, they can more easily guess passwords and security questions for professional and even personal accounts, from which they can leapfrog into corporate networks.

They may also use what they find through publicly available sources to run a haveibeenpwned.com search for actual authentication credentials.

Learn more: The link between weak passwords, data breaches, and data brokers

Having multi-factor authentication (MFA) won’t necessarily keep threat actors out. Many MFA solutions can be circumvented via SIM swap or phishing attacks. 

Ultimately, exposed personal data increases your attackable surface. Protecting your systems starts with protecting your people. 

How has AI changed the data broker market?

AI companies like OpenAI, DeepSeek, Grok, and others have insisted that their tools do not share personally identifiable information or use it for training. 

DeleteMe’s internal research has consistently shown LLMs do share personal information. With a few prompts, it’s possible for anyone to obtain home addresses and other personally identifiable information through many of the most popular chatbots. 

Some LLMs will even link to data broker pages and share information from pages that are usually only accessible behind a paywall. This makes it theoretically easier for cybercriminals to reference multiple sites and put together complete profiles with the help of jailbroken AI chatbots or even tools built specifically for illicit activities like FraudGPT. 

Many AI chatbots also train on the contents of everyday chat by default, so any personal information you share could potentially be sold to data brokers and other third parties. 

Use with caution if at all and check your privacy settings. 

What are data brokers doing with your data?

It’s not just marketers who want to better tailor their ads or long-lost friends who want to reconnect that use data brokers and people finder sites. 

Other groups and people that use data brokers include:

  • Law enforcement agencies
  • Educational institutions and financial aid providers
  • Employers/recruiters
  • Landlords
  • Politicians
  • Foreign governments/domestic terror organizations
  • Identity thieves 
  • Insurance agencies
  • Credit card companies
  • Scammers and other criminals
  • Big Tech companies
  • Retailers

Ultimately, data brokers will sell to whoever pays. 

How Do Data Brokers Get Data?

Data brokers use public records, commercial sources, and online tracking data to gather data about individuals. 

Public records include census records, real estate records, DMVs, marriage certificate records, bankruptcy records, business listings, state professional and recreational license records, and voter registration records. 

Commercial sources generally include purchase history from retailers, employment registration, credit information, membership data, loyalty card data, warranty registration, and subscriptions. 

Online tracking data includes user data from social media profiles, web browser cookies, forum posts, mobile apps, web browsing activity, device data, metadata, and IP fingerprints. 

Most of these sources provide only one or two data elements (i.e., a name or phone number) for any individual person. But by piecing them together and guessing the rest, data brokers can build a comprehensive picture of who you are. 

For example, data brokers can guess whether you have any health conditions based on what you buy or search for online.

The majority of data brokers also obtain information from one another.

What Do Data Brokers Know About You?

Data brokers know a lot about you, including your:

  • Name
  • Address
  • Phone number
  • Age
  • Gender
  • Ethnicity
  • Religion
  • Sexual orientation
  • Education level
  • Occupation
  • Net worth
  • Weight
  • Marital status
  • Presence of children
  • Political affiliations

They may also know your medical history, interests, dating preferences, credit-driven data, real-time location data, Social Security number, and significant life events such as births, marriages, divorces, and deaths.

Many data brokers also put people into specific categories. 

For example, if you have a dog, you might be placed within a “Dog Owner” category. If you are seeking treatment for bipolar disorder or severe anxiety or depression, you may be placed in a specific category that lets advertisers know how to target you. And so on.

Learn more: What exactly do data brokers know about you?

It’s important to understand another issue we all face with data brokers: The data they sell may be wrong. That’s because data broker data sets are made up of two kinds of data:

  1. Observed data. Genuine information about an individual. 
  2. Inferred data. Information that is deduced from observed data. For example, if you visit a website about treating high cholesterol, a data broker might assume that you suffer from high cholesterol, even though you might have looked up the information for a friend or family member.

Incorrect information on data broker websites can cause real harm to individuals. 

The most jarring example is when a people search sites reports “criminal record found” for an individual, when the record is a dismissed traffic ticket or belongs to someone with the same or similar name. 

In one incident, inaccurate data led to a background check platform confusing a prospective employee with a convicted murderer. 

According to the NATO Strategic Communications Center of Excellence, only 50-60% of data broker information was accurate as of 2021. A 2024 study suggested that data brokers haven’t improved their accuracy at all in the past eight years. Very few data brokers allow individuals to correct inaccurate information.

Most people have no idea that the data broker industry exists, let alone that data brokers are selling their personal information. However, that doesn’t make selling data illegal. 

Because the information data brokers trade-in is publicly available, they’re not technically breaking the law in most cases. 

Some states have passed legislation that restricts data brokers. Currently, 20 states have passed comprehensive consumer privacy laws. California and Vermont regulate data brokers and require that they register with the state.  

Vermont’s data broker privacy law (enacted in 2018, the first such law in the country) stipulates that data brokers must maintain minimum data security standards and be more transparent about the types of data they collect.

It also prohibits anyone from buying brokered personal data through fraudulent means or with the goal of fraud, harassment, stalking, or discrimination.  

Similarly, the California Consumer Privacy Act sets down that consumers have the right to know what information is being collected about them and to whom it’s being sold to. Under this law, individuals have the right to opt-out or have their data deleted. The law also prohibits selling data about users under 16 years old.  

Some state laws also prohibit the use of particular information, like voter registration records, for non-election and/or commercial purposes. 

There’s no federal law protecting consumers’ right to control how information about them is being bought and sold. 

However, federal regulations protect certain sensitive data:

  • The Health Insurance Portability and Accountability Act (HIPAA) protects your conversations with your doctor and your medical records. 
  • The federal Driver’s Privacy Protection Act (DPPA) forbids the disclosure of motor vehicle and driving record information, except for specific purposes, like insurance, fraud detection, and law enforcement. 

Similarly, the Fair Credit Reporting Act (FCRA) applies to data brokers that sell consumer data to third parties that use it for particular, enumerated eligibility decisions, including employment and credit. 

In the European Union, there’s the General Data Protection Regulation (GDPR), a data privacy law that affects any organization collecting consumer information.

The GDPR stipulates that consumers must consent before their data is collected. Under the GDPR, consumers also have the right to ask organizations to delete any information organizations might have about them.

You can view a complete list of the current state consumer data privacy laws here

If you are not in a state covered by a comprehensive consumer privacy law, you can still opt out, but data brokers are not required to comply with your request. 

How can you remove your information from data brokers?

Some (but not all) data brokers and people search sites allow people to opt out of their databases. 

DIY opt-outs

You can opt out of data brokers yourself. Just be prepared to invest a lot of time in the process. And expect to do it regularly. 

Data brokers don’t make opting out easy. To remove your profile from a people finder site or data broker database, you might have to: 

  • Fill out a lengthy online form.
  • Make your request via the phone.
  • Send an email.
  • Send information by mail.
  • Submit your request several times.  

However, not all sites give users an option to opt out. 

Some data brokers allow you to control your information but not delete it. And those that supposedly give you the option to opt out don’t always honor your request.o opt out don’t always honor your request. 

Learn more: Our comprehensive data broker opt-out guides

Some data brokers also request that you submit additional personally identifiable information before they remove you from their database. 

This can deter some people from requesting an opt-out. That’s particularly true if the service seems sketchy — you don’t want to give them any more personal information than they already have. 

Veripages removal email

In most cases, you can’t just opt out of a data broker site once. Because most data collection processes are automated, your profile will reappear as soon as the data broker receives information from another source.

Another thing to note is that just because you opt out of a data broker doesn’t mean all traces of you will disappear from their database. 

Your name and other information might still appear in another person’s records (for example, your spouse, parent, etc.) For this reason, it’s a good idea to take the time to opt out family members from data broker sources too.

Professional data broker removal services

If you want the peace of mind that comes with having your personal information off of data brokers and people search sites, you can enlist the help of a professional opt-out service. 

There are several data broker removal services to choose from. Some specialize in data broker removal, while others offer data removal as part of a larger offering (for example, online reputation). 

Learn more: Best companies and tools to remove personal information from the internet

When choosing a data broker removal service, check their:

  • Service availability: Does the service do removals for individuals based in the U.S. only, or do they also cover other countries? Depending on where you live, this can be very important.
  • Data removal scope: What kind of personal information does the service remove from data broker sources? Do they cover the biggest data brokers that show up on the first page of Google?
  • Company track record: Has the service been around long? What kind of reviews do they get? What’s their Better Business Bureau rating? 
  • Customer support: If you need help quickly, how easy are they to reach? 
  • Pricing and plans: How much does the service charge for personal data removal? Do they have family and business plans?

How to Stop Data Brokers from Collecting and Selling Your Data

Because data brokers collect data from numerous online and offline sources, it is impossible to completely stop them from collecting your personal information. 

That said, there are certain steps you can take to reduce your digital footprint and minimize the amount of information data brokers can find about you. 

Start here:

  • Don’t overshare on social media, online forums, blogs, and other online spaces. 
  • Use a private web browser.
  • Ditch Google for a privacy-focused search engine. 
  • Uninstall any apps you don’t actively use on your phone. 
  • Think twice before you sign up for a loyalty program. 

Data brokers are a threat to our privacy, but we’re not totally helpless. Opt out of their databases and stay mindful of how and where you share your data to significantly improve your privacy. 

SHARE THIS ARTICLE
Laura Martisiute is DeleteMe’s content marketing specialist. Her job is to help DeleteMe communicate vital privacy information to the people that need it. Since joining DeleteMe in 2020, Laura has…
Laura Martisiute is DeleteMe’s content marketing specialist. Her job is to help DeleteMe communicate vital privacy information to the people that need it. Since joining DeleteMe in 2020, Laura has…
Hundreds of companies collect and sell your private data online. DeleteMe removes it for you.

Our privacy advisors: 

  • Continuously find and remove your sensitive data online
  • Stop companies from selling your data – all year long
  • Have removed 35M+ records
    of personal data from the web
Special Offer

Save 10% on any individual and
family privacy plan
with code: BLOG10

Want more privacy
news?
Join Incognito, our monthly newsletter from DeleteMe that keeps you posted on all things privacy and security.
Icon mail and document

Don’t have the time?

DeleteMe is our premium privacy service that removes you from more than 750 data brokers like Whitepages, Spokeo, BeenVerified, plus many more.

Save 10% on DeleteMe when you use the code BLOG10.

Related Posts

Chainsaw on a stump for What the Hack data brokers episode

Data Brokers Are Working on Borrowed Time

The data broker business has always relied on consumer silence. That did not mean data brokers had consumer approval. 
Beau Friedlander
June 3, 2026
surveillance pricing at the grocery store

Surveillance Pricing: Why Personalized Pricing is a Lie

Ever go shopping for something, get distracted, only to come back later to find a totally different price and wonder if you had been hallucinating?
Sarah Huard
May 27, 2026
fake invitation scam

Threat Alert: How to Spot a Fake Invitation Scam

Fake invitation scams are a growing threat. Learn how to recognize them and how to protect yourself online.
Sarah Huard
May 26, 2026