Data Brokers: Who Is Selling Your Personal Information in 2026
Every time you sign up for a loyalty card, install a free app, or browse a news site, invisible companies are watching. They compile dossiers on your income, health, relationships, political views, and even your daily commute — then sell that information to the highest bidder. These companies are called data brokers, and they operate a $250+ billion global industry that most consumers have never heard of.
This guide explains exactly who these data brokers are, how they collect and sell your personal information, what risks it creates, and — most importantly — the concrete steps you can take right now to reduce your exposure.
What Are Data Brokers?
Data brokers are companies that collect, aggregate, analyze, and sell personal information about individuals — usually without the direct knowledge or explicit consent of those individuals. They act as middlemen in the global data economy, buying raw data from thousands of sources and repackaging it into detailed consumer profiles.
Unlike social media platforms, which collect data primarily to power their own advertising, data brokers exist purely to trade information. Their customers include advertisers, insurance companies, banks, political campaigns, employers, landlords, private investigators, law enforcement agencies, and even foreign governments.
The Three Main Types of Data Brokers
- Marketing and advertising brokers: Sell audience segments to advertisers (e.g., "single mothers earning over $60,000 who shop organic").
- Risk mitigation brokers: Provide fraud detection, identity verification, and background-check data to financial institutions and employers.
- People-search sites: Publish searchable profiles of ordinary citizens, often including addresses, phone numbers, relatives, and criminal records.
Who Are the Biggest Data Brokers Selling Personal Information?
The industry is dominated by a handful of massive players, along with thousands of smaller specialty firms. Most consumers have never heard their names, yet these companies likely have hundreds of data points on you.
| Company | Type | What They Sell | Estimated Profiles |
|---|---|---|---|
| Acxiom (LiveRamp) | Marketing | Consumer demographics, purchase history, lifestyle | 2.5 billion+ |
| Experian | Credit & Marketing | Credit data, income estimates, marketing segments | 1 billion+ |
| Equifax | Credit & Risk | Credit files, employment, income verification | 800 million+ |
| Oracle Data Cloud | Marketing | Digital advertising audiences, B2B contacts | 5 billion+ IDs |
| LexisNexis | Risk & Legal | Public records, court data, identity verification | 500 million+ |
| Spokeo, BeenVerified, Whitepages | People-search | Addresses, phone numbers, relatives, age | Billions (aggregated) |
| CoreLogic | Property | Real-estate ownership, mortgages, valuations | 4.5 billion property records |
Beyond these giants, the U.S. Federal Trade Commission estimates that 4,000 to 5,000 data brokers operate worldwide. Vermont and California maintain public registries — Vermont alone lists over 120 registered brokers, while California's registry contains nearly 500.
How Do Data Brokers Collect Your Personal Information?
Data brokers rarely collect information directly from you. Instead, they harvest it from an enormous web of sources, most of which you interact with every day without a second thought.
1. Public Records
Government-maintained records are a goldmine. These include voter registrations, property deeds, court filings, marriage and divorce records, business licenses, and professional certifications. All are legally accessible, and brokers scrape them at scale.
2. Commercial Sources
Retailers sell purchase histories. Magazine publishers sell subscriber lists. Loyalty programs sell shopping behavior. Warranty registrations, catalog orders, and charitable donations are all commodified.
3. Web Tracking and Cookies
Third-party tracking pixels, cookies, and advertising SDKs monitor your browsing across thousands of websites. Brokers pay to place these trackers or buy the resulting data from ad-tech networks.
4. Mobile Apps
Free apps — flashlights, weather, games, prayer apps, period trackers — often embed data-broker SDKs that transmit location coordinates, device IDs, and behavioral data every few seconds.
5. Social Media
Public posts, profile information, likes, and connections are scraped and cross-referenced with other data sources to enrich profiles.
6. Data Breaches and Leaks
When major breaches occur, leaked data circulates on the open web and dark web. Some brokers quietly incorporate this information into their datasets.
7. First-Party Sales
Companies you trust — banks, insurers, telecoms, even some healthcare providers — often sell or share "anonymized" data that brokers can re-identify using cross-referencing techniques.
What Personal Information Are They Actually Selling?
The scope is staggering. A single data-broker profile can contain hundreds — sometimes thousands — of individual data points.
- Identity: Full name, aliases, date of birth, Social Security or national ID numbers, driver's license.
- Contact information: Current and previous addresses, phone numbers, email addresses.
- Family and relationships: Spouse, children, relatives, roommates, neighbors.
- Financial: Estimated income, credit score bands, homeownership, mortgage balances, bankruptcies, investment behavior.
- Employment: Employer, job title, salary range, industry, tenure.
- Health inferences: Likely medical conditions, prescription categories, pregnancy status, mental-health signals.
- Behavioral: Shopping habits, brand preferences, hobbies, media consumption, political affiliation.
- Location: Home, work, gym, place of worship, travel patterns — often precise to a few meters.
- Digital identifiers: Device IDs, IP addresses, browser fingerprints, advertising IDs.
Investigations in 2023 and 2024 revealed brokers selling lists like "active-duty U.S. military personnel with financial vulnerabilities," "individuals with depression," and precise location trails of people who visited abortion clinics. These are not theoretical harms — they are on the market today.
Why This Matters: Real-World Risks
It's tempting to shrug and say "I have nothing to hide." But the aggregation of personal information creates concrete, measurable risks — even for people with completely ordinary lives.
Identity Theft and Fraud
Broker profiles give scammers the exact ingredients they need: your address, phone, birthdate, relatives' names, and employer. Social engineering attacks succeed because the caller already "knows" you.
Stalking and Physical Safety
People-search sites have been directly implicated in stalking, domestic violence, and even murder cases. A $5 subscription can reveal a victim's new address in seconds.
Discrimination
Employers, landlords, and insurers use broker data to make decisions about you — often illegally, and always without your ability to review or correct the underlying information.
Price Manipulation
"Personalized pricing" means two people see different prices for the same flight, insurance policy, or online product based on inferred willingness to pay.
Political Manipulation
Micro-targeted political ads — powered by broker segments like "persuadable suburban voter concerned about crime" — have reshaped elections around the world.
Foreign Intelligence Exploitation
Multiple U.S. and EU investigations have confirmed that hostile foreign governments purchase broker data on military personnel, government employees, and journalists.
How to Find Out What Data Brokers Have on You
Under laws like the EU's GDPR, California's CCPA/CPRA, and similar frameworks in Brazil, Canada, and the UK, you have a legal right to know what personal information a broker holds and to request its deletion.
- Search yourself on major people-search sites (Spokeo, BeenVerified, Whitepages, Radaris, Intelius, PeopleFinder). Use an incognito window.
- Check California's Data Broker Registry at oag.ca.gov — every registered broker must publish an opt-out link.
- Request your file from major aggregators like Acxiom, LexisNexis, and Experian using their subject-access request forms.
- Search your email address on breach-tracking services to see which datasets already include you.
- Review your mobile app permissions to identify which apps have location, contacts, and identifier access.
How to Remove Yourself from Data Broker Databases
Removal is possible but tedious. Each broker has its own opt-out process, and many require you to repeat the process every 6–12 months because your data gets re-added from fresh sources.
Manual Removal (Free but Time-Consuming)
- Visit each broker's opt-out or "do not sell my personal information" page.
- Submit the required verification (usually email, sometimes a photo ID with sensitive fields redacted).
- Wait 15–45 days for removal.
- Recheck every 3–6 months and resubmit as needed.
Realistically, covering the top 100+ brokers takes 40–60 hours of work.
Automated Removal Services
Services like DeleteMe, Kanary, Optery, and Incogni will submit removal requests on your behalf for an annual fee ($100–$250/year). They monitor for re-appearance and re-submit automatically. This is the pragmatic option for most people.
Legal Requests
Residents of the EU, UK, California, Colorado, Virginia, Connecticut, Utah, Texas, and a growing list of jurisdictions can file formal deletion requests with legal force behind them.
How to Reduce Future Data Collection
Removing existing data is only half the battle. If you don't change your habits, brokers will simply refill their databases within months.
1. Minimize What You Share
Skip loyalty programs that don't offer meaningful rewards. Give fake birthdates and secondary email addresses when websites don't legally need real ones. Never post your home address, workplace, or children's schools publicly.
2. Use Privacy-First Tools
Switch to a privacy-respecting browser (Brave, Firefox, or Safari with tracking prevention enabled). Use encrypted DNS resolvers like Cloudflare 1.1.1.1 or NextDNS. Install a reputable content blocker to shut down third-party trackers.
3. Compartmentalize Email Addresses
Use email aliasing services (SimpleLogin, Firefox Relay, Apple Hide My Email) so every website gets a unique address. When one leaks, you know exactly who sold or lost your data — and you can shut it down instantly.
4. Lock Down Your Phone
Reset your advertising identifier monthly, deny location access to apps that don't need it, and uninstall free apps that seem too eager for permissions.
5. Be Careful With Links
Shortened and tracking-laden links are a common vector for behavioral profiling. When you share URLs — for work, marketing, or social — use a privacy-conscious link platform like Lunyb, which lets you create clean, trackable short links without embedding third-party ad-tech trackers on your audience. You can read our honest Lunyb review or compare options in our 2026 URL shorteners buyer's guide to see how privacy-first shorteners differ from data-hungry alternatives.
6. Freeze Your Credit
In many countries, freezing your credit file with the major bureaus is free and dramatically reduces identity-theft risk. It also limits some risk-broker use cases.
The Regulatory Landscape in 2026
The regulatory environment is finally catching up with the data-broker industry — slowly.
- European Union (GDPR): Strongest global framework. Full rights to access, correct, delete, and object to processing.
- United States: No federal law yet, but 19+ states have passed comprehensive privacy laws. California's Delete Act (effective 2026) creates a one-stop deletion mechanism.
- United Kingdom: UK GDPR mirrors EU protections.
- Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act): Provide meaningful but narrower rights.
- FTC enforcement: Recent actions against X-Mode, Kochava, and Avast have signaled a harder U.S. stance on location-data sales.
Frequently Asked Questions
Is it legal for data brokers to sell my personal information?
In most jurisdictions, yes — provided the broker complies with applicable privacy laws. However, laws like GDPR, CCPA, and similar frameworks give you the right to opt out, request deletion, and in some cases sue for damages if your data is mishandled. Selling certain categories (health, precise location, children's data) is increasingly restricted.
How much money do data brokers make from my information?
Individually, your data is worth pennies — but at scale, the industry generates over $250 billion annually. A single detailed consumer profile might sell for $0.50 to $5, while specialty segments (like verified high-net-worth individuals or people with specific medical conditions) can command far higher prices.
Will opting out of data brokers stop all tracking?
No. Opting out reduces your exposure with brokers who honor the request, but new data is constantly generated. Combining opt-outs with tracker-blocking browsers, email aliases, minimized app permissions, and cautious information sharing produces the best long-term results.
Are people-search sites the same as data brokers?
People-search sites are a specific subcategory of data broker focused on selling access to individual profiles — typically to consumers, private investigators, and small businesses. The largest data brokers (Acxiom, LexisNexis, Experian) primarily serve corporate clients and don't offer a consumer-facing search interface, but they hold far more data.
How long does it take to remove myself from data broker databases?
Individual removals typically take 15–45 days. Covering the top 100+ brokers manually is a 40–60 hour project. Automated removal services can achieve broad coverage in 60–90 days, but ongoing monitoring is essential because your data is continuously re-added from public records, purchases, and app activity.
Final Thoughts
Data brokers thrive on obscurity. The less consumers know about them, the more freely they can trade in personal information. By understanding who they are, what they collect, and how the machinery works, you regain leverage. Combine deletion requests with better daily habits — privacy-respecting tools, minimal data sharing, and careful link and app choices — and you'll shrink your digital shadow substantially within a year.
You'll never disappear entirely from the data economy. But you can stop being one of its easiest targets.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Browser Fingerprinting: How Websites Track You Without Cookies
Browser fingerprinting lets websites track you across the web without cookies, using dozens of small device signals to build a unique ID. Learn how it works, what data gets collected, and the practical steps you can take to blend into the crowd and protect your privacy.
How to Do a Personal Data Audit: A Complete Step-by-Step Guide
A personal data audit reveals exactly what information about you exists online—and helps you take it back. This step-by-step guide walks you through mapping your digital footprint, checking for breaches, removing data broker profiles, and hardening the accounts you keep.
GDPR vs CCPA: Understanding Your Privacy Rights in 2026
GDPR and CCPA are the two most influential privacy laws in the world, but they take very different approaches. This guide compares scope, consumer rights, penalties, and compliance obligations — and explains how to exercise your rights or protect your business under both.
How to Protect Your Privacy Online in Australia: A 2026 Guide
A practical 2026 guide to protecting your privacy online in Australia. Covers Aussie privacy laws, common scams, secure browsing, encrypted messaging and step-by-step tips to reduce your digital footprint.