Do the free routes first, in this order: search your own name to establish what's actually published; if you're a California resident, submit one request through the state's DROP platform; in the EU or UK, send GDPR erasure requests; and opt out manually at the specific brokers that list you. Only then consider paying a service, because by that point you'll know what gap is left rather than guessing.
Step 1 — Find out what's actually there
Skipping this is the most common mistake, and it's free to avoid.
- Search your full name in quotes, with your city or state.
- Repeat with your phone number and with a previous address.
- Open the people-search results and note which sites list you and what each shows.
- Write the list down with the date.
That's your baseline. Without it you have no way to judge whether anything you do afterwards worked, and you're left trusting whatever a service reports about itself.
A frequent outcome is that far less is published than expected — particularly for people who've never owned property and don't appear in voter files. If your baseline is nearly empty, you can stop here.
Step 2 — California: use DROP
If you're a California resident this is the highest-leverage free action available, and it takes one submission.
The California Privacy Protection Agency runs the Delete Request and Opt-Out Platform, where a single verifiable request reaches every data broker registered in the state. Since 1 August 2026, registered brokers must access it at least once every 45 days and process the deletion requests they find. Source: CPPA. Checked: 2026-08-19.
It reaches registered brokers only, and the processing obligation is new enough that its practical reach is still being established. It is nonetheless free, statutorily backed, and a single form. How it works.
Step 3 — EU and UK: erasure requests
The GDPR right to erasure applies to data brokers as it does to any other organisation. There's no consolidated portal, so it's per-broker, but the legal weight behind the request is real and it costs nothing but time.
Send it to the privacy or data protection contact named in the broker's privacy policy, state that you are exercising your right to erasure, and include enough detail to identify your records — typically name, email address, and any address they display.
Step 4 — Manual opt-outs at the brokers that list you
Work from your baseline list rather than from a generic "top 100 brokers" article. The sites showing your data are the ones worth your time.
The general pattern, which most of them follow:
- Find the opt-out, do-not-sell, or privacy page — usually linked in the footer.
- Search for your own listing and copy its URL.
- Submit the removal request with that URL.
- Confirm by email if they ask. Use an alias here, not your main address — you're handing an email address to a data broker, which is worth pausing on.
- Record what you submitted and when.
To remove your data you generally have to identify yourself to the broker, and some request more information than they already hold. Give the minimum needed to match the listing you found and nothing else. Never send a government ID unless there is a clear legal requirement and you trust the operator — and if the form asks for one to remove a listing that shows only your name and city, that's a reason to be suspicious rather than compliant.
Doing the top ten from your baseline is an evening's work and typically covers most of what a search actually surfaces.
Step 5 — Then decide about paying
Re-run your baseline search a month later. Whatever's still listed is the gap a paid service would be filling, and now you can price that decision honestly rather than buying against a vague worry.
Paid services are worth it when the baseline is large, when you're outside any free consolidated route, when there's a safety concern that makes speed matter, or when you'd simply rather buy the repetition than diarise it. The full decision, and how well they work.
What removal will not achieve
- It isn't permanent. Brokers re-ingest continuously from sources you can't be deleted from, so records reappear. This is structural, not misconduct. Why.
- Public records stay public. Property deeds, voter files and court filings are published by law.
- It doesn't touch companies you deal with directly. Your bank and your retailer are not brokers; removal unsubscribes you from nothing.
- Breach data can't be recalled. Once a dataset circulates, no request reaches everyone holding it.
- It doesn't stop future collection. Deletion is a snapshot; your next purchase or signup starts rebuilding.
The half that removal can't reach
Everything above deletes records that already exist. None of it affects the address you'll type into a checkout form next week — and email is precisely the field brokers most want, because it's the stable, unique key that lets them match records across datasets. Why email specifically.
Giving each company a different address breaks that. An address only one company holds matches nothing else, so it's near-worthless for aggregation, and if it does leak, the leak names its own source. That's free or nearly free and takes effect immediately, which makes it a reasonable thing to start alongside step 1 rather than after step 5.