Data Brokers: How They Collect, Sell, and Profile Your Data

Data brokers are companies that quietly assemble files on you from public records, store loyalty programs, app tracking, and buried data-sharing clauses, then sell those files to marketers, insurers, banks, employers, and other brokers. Understanding how data brokers collect and sell your personal information matters because most of them will never contact you, most Americans live in states that don’t require brokers to register, and the profiles are built and traded whether or not you know a specific company holds one on you.

Where the Information Comes From

Public records do most of the heavy lifting. Property deeds, marriage licenses, voter registrations, and court records are available through open-access government portals, and brokers use automated tools to pull them at scale. A single property record hands over your name, address, purchase price, and mortgage lender in one grab.

Commercial sources add spending behavior. Retailers share transaction data captured through loyalty cards. Banks and credit card issuers may sell aggregated transaction histories under the terms of their privacy notices. Those partnerships map your financial capacity and brand preferences across millions of purchases without anyone contacting you.

Digital tracking fills in daily habits. Web scraping tools pull from social media, public forums, and professional networking sites for interests, career updates, and social connections. Mobile apps collect GPS coordinates that reveal where you live, work, eat, and exercise. That location data gets packaged and resold through specialized exchanges with almost no consumer-facing transparency.

Cross-device linking connects your desktop browsing to your phone. Brokers run probabilistic matching against IP addresses, visited sites, and installed apps to decide which devices belong to the same person. Because mobile browsers carry more distinctive technical signatures, your phone often ties the whole profile together.

Indirect collection rounds it out. When you sign up for a free app or online service, the fine print often authorizes sharing your data with unnamed third-party partners. Those partners are frequently data brokers who merge what they get with data from other sources. By the time the profile is assembled, your information has traveled far from the place you first entered it.

What Ends Up in the Profile

Demographic data forms the skeleton: age, ethnicity, education level, marital status, estimated household income. These metrics slot you into market segments and predict life events like a move or a growing family.

Psychographic data captures what you believe and care about. Profiles often include inferred political leanings, religious interests, and charitable giving patterns, letting advertisers group people by mindset rather than zip code.

Behavioral data tracks what you actually do. Purchase histories, travel patterns, and recurring habits get logged. If you buy running shoes every six months or book flights to the same city quarterly, that pattern is in your file and available for sale.

Health Data Outside HIPAA

One category surprises most people. The federal HIPAA Privacy Rule only protects health data held by covered entities like doctors, hospitals, and health plans. Information you generate through fitness trackers, wellness apps, period-tracking software, and symptom searches generally falls outside HIPAA’s scope. Data brokers can legally buy and sell it, and many do. A profile might flag you as someone managing a chronic condition or tracking fertility based entirely on app data and search behavior that no medical privacy law covers.

Shadow Profiles

The most complete version of all this is what the industry calls a shadow profile. Linking algorithms match your email addresses, phone numbers, home addresses, and device identifiers across separate datasets, tying everything to a single identity. Even if you use different accounts for different purposes, the systems connect them. Shadow profiles exist even for people who have never directly handed information to a data broker.

Who Buys It

Marketing and advertising firms are the largest buyers. Detailed profiles let agencies place ads in front of the people most likely to convert at a given moment, lowering customer acquisition costs across nearly every commercial sector.

Insurance companies use broker data to sharpen risk models. Behavioral indicators and lifestyle data help predict claim likelihood more granularly than broad actuarial tables allow. Information about property maintenance habits or frequent travel can influence the premiums you get offered.

Financial institutions buy data for identity verification and fraud prevention. When you open a bank account, the institution compares what you provide against broker records. A mismatch flags potential identity theft or application fraud. This kind of check is a routine part of the customer verification protocols required of banks and lenders under federal regulation.

Employers and recruitment firms use broker services for background screening. Reports consolidate professional history, educational credentials, and public legal records into a single package, creating a paper trail showing due diligence in hiring.

What Federal Law Lets You Do

No single federal law comprehensively regulates the industry. A patchwork of statutes covers specific slices, and which one applies depends on what data a broker handles and how it gets used.

The Fair Credit Reporting Act

The FCRA, at 15 U.S.C. § 1681, is the oldest and most useful federal law here. It applies when a broker’s data is used for credit decisions, employment screening, insurance underwriting, or similar eligibility determinations. Any entity functioning as a consumer reporting agency must follow accuracy standards and give consumers specific rights.1Office of the Law Revision Counsel. 15 USC 1681 – Congressional Findings and Statement of Purpose

You can request all the information in your file from any consumer reporting agency, including the sources of that information and a list of everyone who pulled your report within the past year.2Office of the Law Revision Counsel. 15 USC 1681g – Disclosures to Consumers If you find errors, you can dispute them, and the agency must investigate and correct or delete inaccurate information within 30 days.3Office of the Law Revision Counsel. 15 USC 1681i – Procedure in Case of Disputed Accuracy Willful violations expose the broker to statutory damages between $100 and $1,000 per violation, plus punitive damages and attorney fees, even without proof of specific financial harm.4Office of the Law Revision Counsel. 15 USC 1681n – Civil Liability for Willful Noncompliance

The catch: the FCRA only applies when the data is collected or used for one of its designated purposes. Many brokers deliberately position themselves outside it by claiming they don’t sell “consumer reports” and aren’t “consumer reporting agencies.” A broker selling your data for targeted advertising rather than credit decisions can argue the FCRA doesn’t reach them.

The Gramm-Leach-Bliley Act

The GLBA, at 15 U.S.C. §§ 6801–6809, governs how financial institutions handle nonpublic personal information. It requires banks, lenders, and similar companies to explain their information-sharing practices and protect the confidentiality of customer data.5Office of the Law Revision Counsel. 15 USC Chapter 94 Subchapter I – Disclosure of Nonpublic Personal Information Before a financial institution shares your data with a nonaffiliated third party, it must disclose that it may do so, explain how to opt out, and give you a chance to block the sharing.6Office of the Law Revision Counsel. 15 USC 6802 – Obligations With Respect to Disclosures of Personal Information The opt-out is real but limited. It doesn’t apply when the institution shares data with a company performing services on its behalf, and many consumers never notice the annual privacy notices that carry the opt-out instructions.

The Protecting Americans’ Data From Foreign Adversaries Act

PADFAA, signed into law in 2024, is the first federal statute to define and regulate “data brokers” by name. It prohibits any data broker from selling, transferring, or providing access to personally identifiable sensitive data about Americans to North Korea, China, Russia, Iran, or any entity controlled by those countries.7Congress.gov. H.R.7520 – Protecting Americans Data from Foreign Adversaries Act of 2024 Covered categories include health, financial, genetic, biometric, and geolocation information, along with account login credentials and government identifiers like Social Security numbers. The FTC enforces the law, and violations can carry civil penalties of up to $53,088 per incident.8Federal Trade Commission. FTC Reminds Data Brokers of Their Obligations to Comply with PADFAA

PADFAA is narrow by design. It targets sales to specific foreign countries, not domestic sales, and its definition of “data broker” carves out companies that collect data directly from you, companies where data isn’t the primary product, and news organizations. It does not give you a personal right to sue or delete your data.

What State Law Lets You Do

Where federal law leaves gaps, a handful of states have stepped in. California, Vermont, Texas, and Oregon all require data brokers to register with a state agency. California’s framework is the most aggressive.

California’s Delete Act and the DROP System

California’s Delete Act, passed in 2023 as Senate Bill 362, requires every business meeting the definition of “data broker” to register annually with the California Privacy Protection Agency by January 31. A broker that fails to register faces administrative fines of $200 per day plus the unpaid registration fees.9California Legislative Information. SB 362 – The Delete Act

The centerpiece is the DELETE Request and Opt-out Platform, known as DROP. Since January 1, 2026, California residents can submit a single deletion request through DROP that reaches every registered data broker at once. Brokers are required to begin processing these requests on August 1, 2026, and must check the system at least once every 45 days after that.10California Privacy Protection Agency. About DROP and the Delete Act Once your data is deleted, brokers cannot sell or share new information about you unless you affirmatively ask them to.9California Legislative Information. SB 362 – The Delete Act

Separately, California’s Consumer Privacy Act requires businesses that sell personal information to post a “Do Not Sell My Personal Information” link on their websites, giving consumers a way to opt out company by company.11California Department of Justice. CCPA Opt-Out Icon

Other State Registries

Vermont was the first state to require data broker registration, launching its registry in 2019. Texas and Oregon followed with laws taking effect in 2024. Most Americans live in states where data brokers face no registration obligation at all, which limits how useful state law is if you don’t live in a covered state.

How to Get Your Data Removed

Removal is possible but tedious by design. A 2026 Congressional investigation found that many brokers hide opt-out pages from search engines, bury removal links inside privacy policies exceeding 9,000 words, and require consumers to navigate to third-party websites to submit requests.12U.S. Congress Joint Economic Committee. Opt-Out Obstacles: Concerning Practices by Registered Data Brokers and the Multi-Billion-Dollar Cost of Breaches

The self-service process generally works like this:

  • Identify which brokers have your data. Start with the largest people-search sites such as Spokeo, BeenVerified, Whitepages, and Intelius by searching your own name. California’s data broker registry lists every broker registered in the state and works as a useful starting index even for non-Californians.13California Privacy Protection Agency. Data Broker Registry
  • Submit opt-out requests individually. Each broker has its own removal process, usually a web form, and some require identity verification. Expect to repeat this across dozens of sites.
  • Follow up periodically. Brokers frequently re-acquire your data from the same public records and commercial sources that fed the original profile. A deletion today doesn’t guarantee you stay deleted six months from now.
  • Use California’s DROP system if you’re eligible. California residents can submit a single deletion request covering every registered broker through the state’s centralized platform.10California Privacy Protection Agency. About DROP and the Delete Act

Paid removal services handle the process for you. Annual subscriptions typically run from about $20 for basic coverage to $250 for services that monitor a larger number of broker sites. They automate the submissions and re-check periodically for reappearances. They save time, but even the best cannot guarantee complete removal. Brokers may repost information after it’s been taken down, and new brokers appear regularly.

The most effective long-term approach pairs active removal with limiting the data you generate going forward. Reviewing app permissions, declining loyalty programs, and using privacy-focused browser settings won’t undo what’s already out there, but they slow the rate at which new information flows into broker databases.