facebook-pixel

Data Brokers: Who Is Selling Your Personal Information in 2026

L
Lunyb Security Team
··10 min read

Every time you sign up for a loyalty card, install a free mobile app, or browse a news site, someone is quietly cataloging your behavior. That data rarely stays put. Instead, it flows into a massive, largely invisible industry known as data brokerage, where your habits, income, health conditions, and location history are packaged and sold to the highest bidder.

This guide breaks down exactly who these data brokers are, how they build shockingly detailed profiles on you, who buys the information, and what you can do to push back. Whether you're a casual internet user or a privacy-conscious professional, understanding this ecosystem is the first step to reclaiming control of your digital identity.

What Are Data Brokers?

Data brokers are companies that collect, aggregate, analyze, and sell personal information about consumers, usually without those consumers ever interacting with them directly. They operate behind the scenes, buying data from thousands of sources and reselling it to marketers, insurers, employers, political campaigns, and even government agencies.

The industry is worth an estimated $280 billion globally as of 2026, and it continues to grow. Some data brokers focus on marketing profiles, others specialize in risk assessment, fraud detection, or people-search services. What unites them is a business model built on turning your personal details into a tradable commodity.

Categories of Data Brokers

  • Marketing and advertising brokers: Build consumer profiles used for targeted ads and audience segmentation.
  • People-search sites: Aggregate public records and sell reports containing addresses, phone numbers, relatives, and criminal history.
  • Risk mitigation brokers: Sell data to banks, insurers, and landlords for background and creditworthiness assessments.
  • Health data brokers: Trade in de-identified (but often re-identifiable) medical and pharmacy information.
  • Location data brokers: Collect and sell precise GPS data harvested from smartphone apps.

How Data Brokers Collect Your Personal Information

Data brokers do not need to hack anyone. Most of the information they hold has been legally, if quietly, handed over through a web of everyday digital transactions. Understanding these collection channels helps explain why opting out is so difficult.

  1. Public records: Court filings, property deeds, voter registrations, marriage licenses, and business registrations are scraped and compiled.
  2. Website tracking: Cookies, tracking pixels, and fingerprinting scripts monitor your browsing across thousands of sites.
  3. Mobile apps: Free apps often bundle software development kits (SDKs) that quietly transmit your location, contacts, and usage patterns to third parties.
  4. Loyalty programs: Grocery, pharmacy, and retail rewards cards link your purchases to your identity and resell the data.
  5. Social media: Public posts, likes, and profile fields are scraped and combined with other datasets.
  6. Data partnerships: Brokers trade and buy datasets from each other, enriching profiles over time.
  7. Breached data: Some brokers ingest information exposed in security incidents, layering it with legally obtained records.

Who Buys Data From Brokers?

Data broker customers span nearly every industry. Some uses are relatively benign, like helping a bakery target ads to local coffee drinkers. Others raise serious ethical and legal concerns.

Buyer Type Typical Use Case Privacy Risk Level
Advertisers & Marketers Targeted campaigns, audience segmentation Medium
Insurance Companies Premium calculation, risk scoring High
Employers & Recruiters Background checks, candidate screening High
Financial Institutions Credit decisions, fraud detection High
Political Campaigns Voter targeting, microtargeted messaging High
Law Enforcement Location tracking, investigations Very High
Debt Collectors Skip tracing, locating individuals High
Scammers & Fraudsters Phishing, social engineering, identity theft Extreme

The Biggest Data Brokers You've Probably Never Heard Of

While Google and Meta dominate headlines, the largest pure-play data brokers operate with almost no consumer visibility. Here are some of the most influential players in 2026.

Acxiom (LiveRamp)

Acxiom claims to hold data on more than 2.5 billion consumers worldwide, with up to 11,000 data points per individual. Its parent company LiveRamp specializes in identity resolution, connecting your activity across devices, apps, and offline purchases.

Experian

Best known as a credit bureau, Experian also runs a major marketing services division that sells consumer segmentation data, income estimates, and lifestyle profiles.

Epsilon

Owned by Publicis Groupe, Epsilon manages loyalty program data for hundreds of major retailers and sells enriched consumer profiles to advertisers.

Oracle Data Cloud

Oracle aggregates data from more than 15 million websites and thousands of offline sources, feeding it into audience-targeting products used across the ad tech ecosystem.

CoreLogic

Specializes in property, mortgage, and tenant data, widely used by landlords, insurers, and real estate investors.

Spokeo, BeenVerified, and Whitepages

These consumer-facing people-search sites make broker data searchable by anyone with a credit card, exposing home addresses, relatives, and phone numbers.

Why This Matters: Real-World Consequences

The data broker industry is not just an abstract privacy concern. It has tangible, sometimes dangerous effects on everyday people.

  • Discriminatory pricing: Online retailers and insurers have been caught charging different prices based on inferred income or ZIP code.
  • Employment discrimination: Background reports that include inaccurate or outdated information can cost people jobs.
  • Stalking and harassment: People-search sites have been used repeatedly to locate victims of domestic abuse, journalists, and public officials.
  • Identity theft: Broker-held profiles give scammers the perfect raw material for convincing phishing attacks.
  • Health insurance surprises: Purchases of over-the-counter medications, gym memberships, or even certain groceries can influence risk scores.
  • Political manipulation: Microtargeted misinformation campaigns rely heavily on broker-supplied psychographic profiles.

What Laws Regulate Data Brokers?

Regulation is patchy, and enforcement varies widely by region. Here is a snapshot of the current legal landscape.

United States

There is no comprehensive federal privacy law, but several states have stepped in. California's CCPA and CPRA give residents the right to know what personal information is collected and to request deletion. Vermont, Texas, Oregon, and California require data brokers to register publicly. The FTC has increased enforcement actions against brokers that mishandle sensitive location and health data.

European Union

The GDPR gives EU residents strong rights, including access, correction, deletion, and objection to processing. Brokers must have a lawful basis for handling personal data, and fines for violations can reach 4% of global annual revenue.

United Kingdom

The UK GDPR and Data Protection Act 2018 mirror EU protections. The Information Commissioner's Office (ICO) has actively investigated ad tech and broker practices.

Canada, Australia, and Beyond

Canada's PIPEDA and Australia's Privacy Act provide baseline protections, and both countries are considering stronger reforms. Brazil's LGPD closely mirrors GDPR. Many other jurisdictions are following suit.

How to Reduce Your Data Broker Footprint

You cannot fully erase yourself from the data broker ecosystem, but you can meaningfully shrink your footprint. Here is a practical action plan.

1. Opt Out From Major Brokers Directly

Most large brokers have opt-out forms, though they are often buried. Start with Acxiom, LexisNexis, Epsilon, Oracle, Spokeo, BeenVerified, Whitepages, Radaris, and MyLife. Expect to repeat this process every 6 to 12 months, as brokers frequently repopulate profiles.

2. Use a Data Removal Service

Services like DeleteMe, Kanary, Optery, and Incogni will submit opt-out requests on your behalf across hundreds of brokers. Costs typically range from $75 to $250 per year.

3. Lock Down Your Browser

  • Switch to a privacy-focused browser like Brave, Firefox, or LibreWolf.
  • Install uBlock Origin to block trackers and ads.
  • Enable encrypted DNS (DNS over HTTPS) using providers such as Cloudflare 1.1.1.1 or Quad9.
  • Disable third-party cookies and use container tabs to isolate sessions.

4. Audit Your Mobile Apps

Review app permissions monthly. Revoke location, contacts, and background data access for anything that does not strictly need it. Prefer paid apps over free ones when possible, since ad-supported apps are the largest source of location data sold to brokers.

5. Minimize Loyalty Program Exposure

Use a dedicated email address for loyalty programs, or skip them entirely for low-value rewards. Consider whether the discount is worth handing over a lifetime of purchase history.

6. Protect Your Links and Shared URLs

When you share links publicly, on social media, or in newsletters, the destination and click patterns can be harvested by tracking-heavy shortening services. Using a privacy-respecting link shortener like Lunyb lets you share URLs without feeding another broker pipeline. You can read our transparent breakdown in this honest Lunyb review or compare options in our 2026 URL shortener buyer's guide.

7. Freeze Your Credit

Placing a free credit freeze with Equifax, Experian, and TransUnion prevents new accounts from being opened in your name and limits how your credit data is shared for pre-approved offers.

8. Use Email Aliases and Masked Phone Numbers

Services like SimpleLogin, Firefox Relay, and Apple's Hide My Email create disposable addresses. MySudo and Google Voice offer masked phone numbers. These break the identity graph brokers rely on.

9. Exercise Your Legal Rights

If you live in California, the EU, UK, Brazil, or a similar jurisdiction, submit formal data subject access requests (DSARs) and deletion requests. Regulators take patterns of non-compliance seriously.

The Future of Data Brokerage

The data broker industry is at an inflection point. Regulatory pressure is intensifying, particularly around location data, health information, and children's data. The FTC has signaled it will treat sensitive category data more strictly, and comprehensive federal privacy legislation in the US remains a live possibility.

At the same time, artificial intelligence is supercharging what brokers can infer from limited data. Machine learning models can now predict pregnancy, political views, sexual orientation, and mental health status from seemingly innocuous browsing patterns. This makes the case for aggressive personal privacy hygiene stronger than ever.

Expect to see continued growth in privacy-preserving technologies, decentralized identity systems, and consumer tools that give individuals meaningful control over their data. But the burden, for now, still falls largely on individuals to protect themselves.

Frequently Asked Questions

Is it legal for data brokers to sell my personal information?

In most jurisdictions, yes, provided the broker complies with applicable privacy laws. In the EU, UK, and states like California, brokers must have a lawful basis and honor consumer rights. In much of the US, however, selling personal data is largely unregulated at the federal level.

How do I find out what data brokers have on me?

You can submit access requests to major brokers directly, or use services like Optery and DeleteMe that scan hundreds of broker databases for your information. In the EU and UK, GDPR gives you a legal right to a full copy of your data within 30 days.

Will opting out actually remove my data permanently?

Not necessarily. Many brokers will delete your current record but repopulate it from new data sources within months. Continuous monitoring and repeated opt-outs, ideally through an automated removal service, are usually necessary to keep your footprint minimal.

Are free data broker opt-out services trustworthy?

Some are legitimate, but be cautious. A few "free" tools are actually run by data brokers themselves and use your opt-out request to verify and enrich their own records. Stick to well-reviewed services from established privacy organizations.

Do link shorteners sell my data to brokers?

Many mainstream link shorteners collect detailed click, device, and location data that can be shared with advertising partners or brokers. Privacy-focused alternatives like Lunyb minimize tracking and avoid selling analytics data. For a broader comparison, see our 2026 URL shortener guide or read our Rebrandly review for a competitor breakdown.

Take Back Control

The data broker industry thrives on invisibility. The more you know about who is collecting your information, who is buying it, and why, the better positioned you are to fight back. Start with a few opt-outs this week, tighten your browser and mobile app settings, and consider a paid removal service if your time is limited. Small, consistent steps compound into meaningful privacy over time.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles