facebook-pixel

Data Brokers: Who Is Selling Your Personal Information in 2026

L
Lunyb Security Team
··10 min read

Every time you sign up for a loyalty card, install a free app, or browse a news site, someone is taking notes. That "someone" is often a data broker — a company that quietly assembles detailed profiles about you and sells them to advertisers, insurers, employers, political campaigns, and sometimes even scammers. The global data broker industry is now worth well over $300 billion, and most people have never heard of the companies profiting from their lives.

This guide explains exactly who data brokers are, what information they collect, how they sell it, and what you can do to reduce your exposure.

What Are Data Brokers?

A data broker is a business that collects personal information from public and private sources, aggregates it into detailed profiles, and sells or licenses that data to third parties. Unlike companies you interact with directly (like your bank or favorite retailer), data brokers usually have no relationship with you at all — yet they may know your income, health conditions, political leanings, and daily habits.

The industry includes household names like Acxiom, Experian, Epsilon, CoreLogic, LexisNexis, and Oracle Data Cloud, plus thousands of smaller firms specializing in niches such as location data, health data, or people-search services.

The Three Main Types of Data Brokers

  1. Marketing data brokers — Sell audience segments to advertisers (e.g., "new parents earning over $75K").
  2. Risk mitigation brokers — Supply data for fraud checks, insurance underwriting, and employment screening.
  3. People-search brokers — Publish searchable profiles online (Spokeo, BeenVerified, Whitepages, Radaris, and dozens more).

What Kind of Personal Information Do Data Brokers Sell?

The scope of collection is far broader than most people realize. A single broker profile can contain thousands of individual data points about one person.

Common Categories of Sold Data

  • Identity data: full name, aliases, date of birth, Social Security or national ID number, government-issued IDs.
  • Contact data: current and past home addresses, phone numbers, personal and work email addresses.
  • Financial data: estimated income, credit tier, homeownership status, mortgage amount, bankruptcies.
  • Demographic data: age, gender, ethnicity, religion, marital status, number of children, languages spoken.
  • Behavioral data: shopping habits, brands you buy, websites visited, apps installed, videos watched.
  • Location data: GPS pings from mobile apps showing where you live, work, worship, and travel.
  • Health data: inferred medical conditions, medications, pregnancy status, mental health signals.
  • Political and lifestyle data: party affiliation, likelihood to vote, gun ownership, dietary preferences.
  • Relationship data: names of relatives, roommates, neighbors, and known associates.

Investigations by journalists and researchers have shown that some brokers even sell lists categorized as "suffers from depression," "rape victims," or "financially vulnerable seniors" — with disturbing accuracy.

How Do Data Brokers Collect Your Information?

Data brokers rarely ask you for anything directly. Instead, they harvest information from a sprawling web of sources — most of which you"ve unknowingly consented to through terms of service you never read.

Primary Collection Sources

  1. Public records — Court filings, property deeds, marriage and divorce records, voter registration, business licenses.
  2. Commercial partners — Retailers, loyalty programs, magazine subscriptions, warranty registrations, and charities sell or share customer lists.
  3. Mobile apps and SDKs — Free apps often embed third-party software development kits that quietly transmit location, device ID, and usage data.
  4. Web tracking — Cookies, pixels, browser fingerprinting, and ad-tech networks follow you across sites.
  5. Social media scraping — Public posts, profile fields, likes, and connections are harvested at scale.
  6. Data breaches — Leaked databases circulate on the dark web and are folded into broker profiles.
  7. Surveys and sweepstakes — "Win a free iPad" forms are classic bait for enriching profiles.

Once collected, these fragments are matched to a persistent identifier (usually a hashed email address, phone number, or mobile advertising ID) and stitched together into a single dossier.

Who Buys This Data — and Why?

The buyers are more varied than you might expect. Below is a comparison of the major categories.

Buyer Type Primary Use Case Risk to Individuals
Advertisers & Marketers Targeted ads, audience modeling Manipulation, price discrimination
Insurance Companies Underwriting, premium setting Denied coverage, higher rates
Employers & Landlords Background checks Missed job or housing opportunities
Banks & Lenders Credit and fraud decisions Loan denials based on inferred data
Political Campaigns Voter targeting and persuasion Micro-targeted disinformation
Government & Law Enforcement Investigations, surveillance Warrantless access to sensitive data
Scammers & Fraudsters Phishing, identity theft, stalking Financial loss, physical harm

Perhaps the most troubling category is the last one. Because much broker data is available for as little as a few cents per record, criminals routinely buy it to craft convincing scams — targeting the elderly, the recently bereaved, or people whose profiles suggest financial distress.

The Real-World Harms of the Data Broker Industry

This isn't just an abstract privacy concern. The consequences of data brokers selling personal information are concrete and, in some cases, severe.

Documented Harms

  • Stalking and domestic violence — Abusers have used people-search sites to locate victims who moved to escape them.
  • Doxxing and harassment — Home addresses of journalists, judges, and public figures have been weaponized.
  • Discriminatory pricing — Studies have shown identical products offered at different prices based on inferred wealth or ZIP code.
  • Insurance and credit discrimination — Non-traditional data (like grocery purchases) has been used to raise premiums.
  • Immigration enforcement — Agencies have bought location data to bypass warrant requirements.
  • National security exposure — Foreign governments can purchase data on military personnel just like any other buyer.

The Legal Landscape: Weak Protection, Slow Progress

Regulation of data brokers varies dramatically by region, and enforcement is patchy even where laws exist.

Key Regulations Around the World

  • European Union (GDPR) — Requires a legal basis for processing, grants strong access and deletion rights. Brokers operating in the EU must respond to requests within 30 days.
  • United Kingdom (UK GDPR + DPA 2018) — Similar to EU rules, enforced by the ICO.
  • California (CCPA/CPRA) — Requires brokers to register with the state and honor opt-out requests. As of 2026, the DELETE Act allows Californians to remove themselves from all registered brokers with a single request.
  • Vermont, Texas, Oregon — Have their own broker registration laws.
  • Canada (PIPEDA) — Requires meaningful consent, though enforcement is limited.
  • Australia (Privacy Act reform) — Being expanded to cover broker-like practices.
  • United States (federal) — No comprehensive federal privacy law exists, though the FTC has taken enforcement action against specific brokers.

Most of the world still lacks meaningful oversight, meaning the burden of protecting your data falls largely on you.

How to Reduce Your Data Broker Footprint

You cannot fully disappear from broker databases, but you can dramatically shrink your profile with consistent effort.

Step-by-Step: Reclaim Your Privacy

  1. Opt out from major brokers directly. Start with the biggest: Acxiom, Epsilon, Oracle, LexisNexis, Spokeo, BeenVerified, Whitepages, Radaris, MyLife, Intelius, and PeopleFinder. Each has an opt-out form, though they are often deliberately hard to find.
  2. Use a removal service. Services like DeleteMe, Kanary, Optery, and Incogni automate removal requests across hundreds of brokers for a subscription fee.
  3. Submit legal deletion requests. If you live in the EU, UK, California, or another covered jurisdiction, use your statutory rights. A short template email citing GDPR Article 17 or CCPA Section 1798.105 is usually enough.
  4. Lock down your browser. Switch to a privacy-respecting browser (Brave, Firefox with strict tracking protection, or LibreWolf). Install uBlock Origin. Disable third-party cookies.
  5. Use encrypted DNS. Enable DNS-over-HTTPS with a privacy-focused resolver like Quad9 or Cloudflare 1.1.1.1 to prevent your ISP from logging every domain you visit.
  6. Reset your mobile advertising ID. On iOS, disable "Allow Apps to Request to Track." On Android, delete the Advertising ID entirely (Settings > Privacy > Ads).
  7. Audit app permissions. Revoke location, contacts, and microphone access for any app that doesn't strictly need them.
  8. Use email aliases. Services like SimpleLogin, Firefox Relay, and Apple's Hide My Email prevent brokers from linking accounts through a shared email address.
  9. Be careful what you share when shortening or sharing links. When you distribute links publicly, use a privacy-conscious shortener like Lunyb that doesn't monetize click data or build advertising profiles on visitors. See our honest review of Lunyb for details on how it handles user data.
  10. Freeze your credit. A credit freeze at all three bureaus (Equifax, Experian, TransUnion) prevents brokers from selling certain financial data and blocks most identity theft attempts.

Building Long-Term Privacy Habits

Removing yourself from broker databases is only useful if you stop feeding them new data. A few durable habits go a long way.

Habits That Compound Over Time

  • Read app permission prompts before tapping "Allow."
  • Refuse loyalty cards, or use a fake name and burner email.
  • Pay with cash for sensitive purchases when possible.
  • Skip "Sign in with Google/Facebook" — create dedicated accounts with aliased emails.
  • Review a different service's privacy settings every week — spread over a year, this covers nearly every account you own.
  • Choose vendors that publish clear privacy policies. Our 2026 URL shortener buyer's guide compares tools based partly on privacy practices, and our Rebrandly review takes a closer look at one popular option.

The Bigger Picture

The data broker industry thrives on invisibility. Most people never learn that their pregnancy was inferred from grocery purchases, or that their location was sold to a debt collector, or that their teenage child's mental health searches ended up in an advertising segment. Sunlight — through journalism, regulation, and personal action — is the only real disinfectant.

You will not opt out of surveillance capitalism in a single afternoon. But every broker you remove yourself from, every permission you revoke, and every privacy-respecting tool you choose weakens the machine. Multiplied across millions of people making the same choices, those small acts change the economics of the industry itself.

Frequently Asked Questions

Is it legal for data brokers to sell my personal information?

In most jurisdictions, yes — provided the broker complies with applicable laws. In the EU, UK, and California, brokers must have a legal basis for processing your data and honor your rights to access, correct, and delete it. In much of the United States and many other countries, however, there is no comprehensive law preventing the sale of most personal data, though sensitive categories (health, children's data, financial data) have specific protections.

How much is my personal data worth to data brokers?

Surprisingly little on a per-record basis. A basic identity record with contact information may sell for pennies. Enriched profiles with financial or health inferences can fetch a few dollars. Real-time location data on high-value targets can be worth significantly more. The industry is profitable because it operates at massive scale — billions of profiles bought and sold every day.

Can I completely remove myself from all data broker databases?

Realistically, no. There are thousands of brokers worldwide, new ones appear constantly, and data that has already been sold cannot be recalled from buyers. However, you can remove yourself from the largest and most visible brokers, which dramatically reduces the risk of doxxing, scam targeting, and casual lookups. Ongoing maintenance — either manually or through a removal service — is essential because brokers often re-add profiles from fresh public records.

How can I tell if my information is being sold?

Search your name in Google along with your city — people-search results usually appear on the first page. Check haveibeenpwned.com to see which breaches include your email. Some brokers, particularly those covered by California and EU law, must provide you a copy of your data upon request. Signs like sudden spam calls after buying a house, or hyper-targeted ads referencing something you never searched, often indicate broker activity.

Are removal services worth paying for?

For most people with busy lives, yes. Manually opting out of a few hundred brokers can take 40+ hours initially and requires quarterly follow-ups. Services like DeleteMe, Optery, and Incogni handle this for $100–$200 per year. If your budget is tight, focus manual effort on the top 15–20 brokers (which cover the majority of data circulation) and skip the long tail.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles