Who actually has your home address, your income bracket, your recent purchases, and a list of the apps on your phone — and how did they get all of it without you ever handing it over directly? The honest answer is a data broker, and if that’s a new term to you, it’s worth learning now: the industry that assembles and resells personal profiles has spent the past year getting real regulatory attention, and 2026 is the first year ordinary people have an actual tool to push back.
What a Data Broker Is
A data broker is a company that collects personal information from public records, purchase histories, apps, loyalty programs, and other brokers, then packages it into profiles and sells access to marketers, background-check services, and researchers. You’ve never signed up for most of these companies and never agreed to a specific privacy policy with them — that’s the defining feature of the business. Your data arrives secondhand, pulled together from dozens of smaller sources you interacted with for entirely different reasons.
This is a different threat model than the one covered in our guide to spotting phishing scams, where someone tricks you into handing over information directly. This is different — nobody needs to trick you at all — it just buys or scrapes what’s already sitting in public and semi-public sources and reassembles it into something far more detailed than any single piece on its own.
Why This Suddenly Matters More
This industry has operated with relatively little federal oversight for years, but that changed in a concrete way in early 2026. Under the Protecting Americans’ Data from Foreign Adversaries Act, brokers are barred from selling sensitive personal data — health, financial, genetic, biometric, geolocation, login credentials, and government ID numbers — to countries the law designates as foreign adversaries, including China, Russia, Iran, and North Korea. The FTC sent warning letters to 13 of them in February 2026, specifically flagging that some had been offering data tied to whether someone is a member of the US armed forces — exactly the kind of sensitive detail the law is meant to keep out of the wrong hands. Violations can carry civil penalties of more than $53,000 per infraction.
California’s New Opt-Out Tool
For years, opting out of them meant filing separate removal requests with dozens of companies individually, each with its own process and its own habit of re-listing you a few months later. California’s Delete Act changes that for state residents: the California Privacy Protection Agency’s DROP platform (Delete Request and Opt-out Platform) lets a California resident submit one deletion request that reaches every data broker registered in the state at once. Brokers had to create DROP accounts starting in January 2026, and as of August 1, 2026, they’re legally required to begin processing incoming deletion requests — at least once every 45 days going forward. A broker that skips registration or drags its feet on deletion requests faces fines of $200 per day, on top of investigation costs.
If you don’t live in California, DROP doesn’t cover you directly, but it’s worth watching: California privacy law has a track record of becoming the de facto national standard once large companies build compliance systems for it, the same way it did with cookie consent and the right to access your own data.
What You Can Do About It Right Now
Outside DROP, there’s no single button that removes you from every broker, but a few habits meaningfully cut down your exposure. Tighten the accounts brokers pull from in the first place — a password manager and two-factor authentication make it harder for anyone to break into the loyalty programs, retail accounts, and public-facing profiles that feed broker databases to begin with. Search your own name periodically to see what’s publicly indexed, since a lot of broker listings are built from exactly that kind of surface-level public data. And treat any site offering to “instantly reveal” someone’s personal information for a small fee with real skepticism — those consumer-facing lookup sites are usually a repackaged front for the same broker data described here, not an independent source.
FAQs
What information do data brokers typically have on me?
Commonly: your name, address history, phone number, age, estimated income, purchase habits, property records, and sometimes health or political interest categories inferred from your browsing and shopping activity. The exact profile varies widely by broker and data source.
Is it illegal for a company to sell my data to a data broker?
Not generally — most personal data trading is legal in the US outside specific categories like health records or data going to foreign adversaries under laws like PADFAA. This is different from many other countries, where broader data-protection laws restrict this kind of resale by default.
Does DROP work if I don’t live in California?
No, DROP is only available to California residents, since it’s a California state law. People outside California still have to contact individual brokers directly, though some brokers extend similar opt-out processes nationwide voluntarily.
Can a VPN stop brokers from collecting my information?
Only partially. A VPN can limit what your internet provider and some websites see about your browsing, as covered in our explainer on how VPNs work, but it doesn’t touch the public records, purchase histories, and app data that make up most of what brokers actually collect.
How often do data brokers update their profiles on me?
It varies by broker and data source, but profiles are generally refreshed whenever new public records or purchased datasets become available — which is also why opting out isn’t permanent. A broker that re-scrapes public records after a deletion request can end up re-listing you months later.











Discussion about this post