Data Brokers Explained: How They Get Your Information and What You Can Do

What brokers are, where they get their data, and which of the things you can do about it actually work.


A data broker is a company that collects personal information about people it has no direct relationship with, compiles it into profiles, and sells access to them. The data comes from public records, commercial transactions, online activity, and other brokers. Most of it is legal. You can ask brokers to delete what they hold — and in California a free state-run platform now does that in one request — but removal is ongoing rather than permanent, because brokers keep re-acquiring data from the same sources.

What brokers actually do

The business is aggregation. Any single fact about you is unremarkable: a property record, a magazine subscription, a change of address, a loyalty card purchase. Combined, they form a profile that can be sold to advertisers, insurers, employers, landlords, political campaigns and anyone else willing to pay.

A related category, people-search sites, publishes those profiles directly to the public — searchable by name, often showing addresses, relatives, ages and phone numbers, with more behind a payment.

Incogni's own description of the two, which is a fair summary: data brokers "scrape the internet for personal information," then "aggregate, often analyze, and then sell this data to third parties," while people-search sites "collect data, compile it into personal profiles, and either sell or publish those profiles online." Source: incogni.com. Checked: 2026-08-19.

Where the data comes from

  • Public records. Property deeds, voter registrations, court filings, business registrations, licences. Public by law and bulk-downloadable.
  • Commercial sources. Loyalty schemes, warranty cards, subscriptions, surveys, competitions. You supplied these, usually with a disclosure you didn't read.
  • Online activity. Advertising identifiers, app SDKs, tracking pixels, and location data sold on by app developers.
  • Other brokers. The industry trades internally, which is why removing yourself from one has limited effect on the others.
  • Breaches. Not a legitimate source, but leaked data circulates and doesn't always stay separate from legitimate datasets.

How your email address specifically gets there

Email is the industry's favourite join key — more stable than an address, more unique than a name, and easy to match across datasets. It arrives via companies you gave it to that share or sell it (which the FTC explicitly warns about), via scraping of anywhere you published it, and via breaches.

That join-key role is the strongest practical argument for using a different address per service: an address only one company holds is useless for matching you across datasets.

Is any of this legal?

Largely, yes — with a growing set of obligations attached, which varies sharply by jurisdiction.

California has gone furthest. Under the Delete Act, brokers must register annually with the California Privacy Protection Agency — the registration window is 1–31 January, and the 2026 fee is $6,000 plus processing. The Agency also built a deletion platform, DROP, and since 1 August 2026 registered brokers "must access the 'accessible deletion mechanism' at least once every 45 days and process consumer deletion requests." A first independent audit is due by 1 January 2028, then every three years. Source: California Privacy Protection Agency. Checked: 2026-08-19.

Vermont, Texas and Oregon also operate broker registries with their own requirements. In the EU and UK, the GDPR gives a right to erasure that applies to brokers as it does to anyone else. Elsewhere, protections range from partial to none.

A note on tone

It's worth resisting the framing that every broker is a criminal enterprise. Much of this industry does mundane work — address verification, fraud checks, credit decisioning — and some of it is legally required of banks and insurers. The reasonable objection isn't that the industry exists; it's that people have very little visibility into who holds what, and that the burden of correcting it falls on the individual.

What you can actually do

Ask them to delete it

Every broker with a legal obligation has an opt-out process. Doing it manually across hundreds of brokers is a serious time commitment, which is the market that removal services exist to serve.

If you're a California resident, use DROP first. It's free, state-run, and reaches every registered broker in one verified request.

Pay a service to do it

Incogni, DeleteMe and similar file requests on your behalf and repeat them. Incogni's Standard plan is $7.99/month or $95.88 billed yearly, covering "420+ data broker sites"; its site describes recurring waves roughly 10 days apart and around 14 days to initial resolution. Source: incogni.com/pricing. Checked: 2026-08-19. See Incogni alternatives for how the options compare.

Reduce what arrives in future

Removal addresses records that already exist. It does nothing about the data you generate next week. Reducing new collection means giving less away: fewer loyalty schemes, fewer competitions, WHOIS privacy on any domain you own, and a different email address per service so the join key stops working.

Why removed information comes back

Because brokers keep re-acquiring from the same upstream sources. A deletion request removes a record; the next time that broker ingests a public-records dump or buys a dataset from another broker, a matching record can reappear. This isn't necessarily bad faith — it's the structural consequence of aggregating continuously from sources you don't control.

California's rules attempt to address exactly this by requiring brokers to maintain suppression lists rather than simply deleting once. How well that works in practice is something to judge after the obligations have been in force for a while, not something to predict.

Removal or prevention?

They're different problems and most people have both to some degree:

  • Your name, address and phone are published on people-search sites. That's a removal problem. Aliases do nothing for it.
  • Companies you sign up with keep leaking your email. That's a prevention problem. Removal barely touches it, because the next signup recreates it.

Full treatment in data removal vs data prevention.

Sources

Part of the Data Brokers & Removal guides.

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading