6 mins read
European Data Broker Opt-Out & Removal Guide
GDPR Removal Guide for 85+ European Data Brokers (2026 Edition)
Protecting your personal information online is no longer optional. Thousands of organisations across Europe collect, analyse, license, and distribute personal data for advertising, marketing, credit assessment, fraud prevention, recruitment, and business intelligence. Many individuals have never interacted directly with these organisations, yet detailed profiles about them continue to circulate throughout the data broker ecosystem.
Fortunately, European privacy legislation provides some of the strongest legal protections in the world. Under the General Data Protection Regulation (GDPR), individuals have enforceable rights to access, correct, object to, restrict, and erase personal data held by organisations operating both inside and outside the European Economic Area when processing the personal data of EU residents.
This guide provides a comprehensive directory of more than 85 European and UK data brokers, advertising technology vendors, B2B intelligence providers, credit reference agencies, and regulated data intermediaries. Each listing includes verified privacy resources together with practical guidance on exercising your rights under the GDPR.
Unlike many commercial removal services that concentrate primarily on United States people-search websites, this guide focuses specifically on the European data broker landscape, where legal rights, regulatory obligations, and removal procedures differ significantly.
Throughout this guide you will find:
• Verified privacy and opt-out resources.
• GDPR-compliant removal procedures.
• Article 17 erasure guidance.
• Article 15 access request recommendations.
• Article 21 objection procedures.
• Information on suppression where deletion is not technically possible.
• Escalation guidance where organisations fail to comply within statutory deadlines.
The objective is simple: help individuals regain control of their personal information using legally enforceable rights rather than voluntary opt-out mechanisms.
Quick Start
If you simply want to begin removing your personal information, follow these steps.
Step 1 — Identify the organisations holding your data
Start with organisations most likely to process your information, including:
• Advertising technology companies
• Marketing data providers
• Business intelligence providers
• People-search websites
• Credit reference agencies
• Commercial data aggregators
Step 2 — Send an Article 17 GDPR erasure request
Use the template included later in this guide and send it directly to each organisation’s Data Protection Officer or designated privacy contact.
Step 3 — Record every request
Maintain a record including:
• Organisation name
• Date submitted
• Method of submission
• Reference number
• Statutory response deadline
• Outcome
A simple spreadsheet is usually sufficient.
Step 4 — Monitor the statutory deadline
Under Article 12(3) GDPR, controllers must normally respond within one month.
If additional time is required because of complexity, they must inform you before the original deadline expires.
Step 5 — Escalate where necessary
If an organisation ignores your request, refuses without lawful justification, or fails to comply with the GDPR, you may lodge a complaint with your national Data Protection Authority (DPA).
Complaints to European supervisory authorities are generally free of charge and may lead to regulatory investigations and enforcement action.
The GDPR establishes a comprehensive legal framework governing the processing of personal data throughout the European Union and, in many circumstances, beyond its borders.
Unlike many jurisdictions that rely primarily on voluntary opt-out systems, European law requires organisations to demonstrate a lawful basis before processing personal data.
Where organisations rely upon legitimate interests, they must demonstrate that those interests are not overridden by the rights and freedoms of the individual.
For many commercial data brokers, this balancing exercise has become increasingly subject to regulatory scrutiny.
Article 15 — Right of Access
You have the right to obtain confirmation that an organisation processes your personal data.
You may also request:
• Copies of all personal data held.
• Categories of personal data processed.
• Original data sources.
• Third-party recipients.
• Retention periods.
• Automated decision-making information where applicable.
Obtaining a copy of your data is often the best first step before requesting deletion.
Article 17 — Right to Erasure
Often referred to as the “Right to be Forgotten,” Article 17 allows individuals to request deletion of personal data where one or more statutory conditions apply.
Where erasure is justified, organisations must remove the personal data without undue delay and, where feasible, notify recipients with whom the data has been shared.
If complete deletion is technically impossible, organisations should explain the reasons and consider alternative measures such as suppression or restriction of processing.
Article 21 — Right to Object
Where processing relies upon legitimate interests, individuals have the right to object.
Following a valid objection, processing must cease unless the organisation demonstrates compelling legitimate grounds that override the individual’s interests, rights, and freedoms.
This provision is particularly relevant for commercial profiling and direct marketing.
Article 7(3) — Withdrawal of Consent
Where consent forms the legal basis for processing, consent may be withdrawn at any time.
Withdrawal should be as simple as giving consent and must not disadvantage the individual.
This is especially important within the online advertising ecosystem, where consent management platforms are commonly used.
Before You Begin
Successful data removal depends not only on legal rights but also on following a structured process.
Understand the Difference Between Deletion and Suppression
Many organisations distinguish between deleting personal data and suppressing future processing.
Deletion removes the active record from operational systems where legally possible.
Suppression retains only the minimum information necessary to prevent your data from being re-imported, re-marketed, or re-created through future data collection.
Where both options are available, requesting both deletion and suppression generally provides the strongest long-term protection.
Data broker removal is not permanent unless the upstream source is also controlled. Public records, new breach data, marketing resupplies, and broker-to-broker licensing can repopulate profiles.
Start your data broker removal and your FREE scan. Once your scan is complete, you’ll receive two complimentary reports:
• Data Broker & Internet Exposure Report
• Data Breach & Dark Web Report
Use a Dedicated Email Address
Avoid submitting requests using your primary email account whenever possible.
Creating a dedicated privacy email address or masked email alias reduces unnecessary exposure while allowing organisations to verify your request where appropriate.
Services such as Apple Hide My Email, SimpleLogin, Proton Pass aliases, or similar privacy tools may be useful.
Keep Detailed Records
Maintain evidence of every request you submit.
Recommended information includes:
• Organisation
• Date sent
• Email used
• Reference number
• Supporting documentation
• Expected response deadline
• Final outcome
This documentation becomes valuable if regulatory escalation becomes necessary.
Expect Data to Reappear
Many commercial data brokers continuously collect information from public records, business registries, advertising networks, social media, public websites, and third-party suppliers.
Consequently, a single successful removal does not guarantee permanent disappearance.
For this reason, privacy professionals generally recommend reviewing your online exposure every three to six months and submitting additional requests where new records appear.
Maintaining ongoing visibility into your digital footprint remains one of the most effective long-term privacy strategies.
Data broker removal is not permanent unless the upstream source is also controlled. Public records, new breach data, marketing resupplies, and broker-to-broker licensing can repopulate profiles.
Start your data broker removal and your FREE scan. Once your scan is complete, you’ll receive two complimentary reports:
• Data Broker & Internet Exposure Report
• Data Breach & Dark Web Report
GDPR Data Removal Request Template
A well-structured GDPR request is significantly more effective than a general email asking for deletion. Referencing the applicable legal provisions demonstrates that you understand your rights and reminds the organisation of its statutory obligations.
Where possible, send your request directly to the organisation’s Data Protection Officer (DPO) or designated privacy contact. Keep a copy of every email or submission confirmation, as it may be required if you later escalate the matter to a supervisory authority.
GDPR Article 17 Erasure Request
Subject: Request for Erasure of Personal Data under Articles 17 and 19 GDPR
Dear Data Protection Officer,
I am exercising my rights under the General Data Protection Regulation (EU) 2016/679.
Pursuant to Article 17 GDPR, I request the erasure of all personal data your organisation processes concerning me, including information collected directly, obtained from third parties, inferred through profiling, or generated through automated processing.
For identification purposes only, my details are:
• Full Name:
• Email Address:
• Postal Address (if applicable):
• Telephone Number (if applicable):
• Date of Birth (optional):
• Any additional identifiers relevant to your records:
Where my personal data has been disclosed to third parties, I also request, in accordance with Article 19 GDPR, that you notify those recipients of this erasure request unless doing so proves impossible or involves disproportionate effort.
If complete deletion is not technically or legally possible, I request that my personal data be permanently suppressed and no longer processed, disclosed, sold, licensed, profiled, or displayed for any commercial purpose.
Please confirm receipt of this request and provide written confirmation of completion within the statutory period established under Article 12(3) GDPR.
Should you require additional information solely for identity verification, please advise accordingly.
Kind regards,
[Full Name]
[Date]
Identity Verification
Many organisations will request proof of identity before processing an erasure request.
This is permitted under Article 12(6) GDPR where reasonable doubts exist regarding the identity of the requester. However, organisations should request only information that is necessary and proportionate to verify identity.
Where possible:
• Redact document numbers.
• Mask photographs if unnecessary.
• Hide financial information.
• Provide only the minimum information required.
Never provide more personal information than is necessary to verify your identity.
Manual vs Automated Data Broker Removal in Europe
Many commercial privacy services advertise automated removal from hundreds of data brokers. While these services can provide value in certain jurisdictions, their effectiveness within Europe is considerably more limited.
The United States and Europe operate fundamentally different data ecosystems.
Why Automation Works Better in the United States
Most US privacy services focus on consumer-facing people-search websites and public-record aggregators. These organisations typically provide standardised online opt-out forms, allowing automated systems to submit removal requests at scale.
Examples include:
• Whitepages
• Spokeo
• BeenVerified
• Intelius
• PeopleFinders
Since these organisations generally use similar removal procedures, automation can achieve reasonable coverage.
Why Europe Is Different
The European data broker ecosystem is significantly more fragmented.
Instead of large public people-search websites, Europe consists of several distinct categories of organisations, including:
• Advertising technology vendors.
• Real-Time Bidding (RTB) participants.
• Consent Management Platform vendors.
• Business intelligence providers.
• Credit reference agencies.
• Identity verification providers.
• Regulated Data Intermediaries under the Data Governance Act.
• Commercial marketing databases.
• Business information providers.
Each category operates under different legal obligations and frequently requires different removal procedures.
Some organisations provide dedicated privacy portals.
Others require formal email requests.
Certain organisations require an Article 15 access request before considering an Article 17 erasure request.
Others respond only to their appointed Data Protection Officer.
There is no single standard process.
GDPR Provides a Stronger Legal Framework
Although automation is more difficult within Europe, GDPR provides considerably stronger legal protections.
Individuals may rely upon statutory rights rather than voluntary company policies.
Depending upon the circumstances, individuals may exercise:
• Article 15 — Right of Access.
• Article 16 — Right to Rectification.
• Article 17 — Right to Erasure.
• Article 18 — Restriction of Processing.
• Article 21 — Right to Object.
• Article 77 — Right to lodge a complaint with a Supervisory Authority.
Failure to comply may expose organisations to regulatory investigation and administrative fines.
Deletion Is Not Always Permanent
Many data brokers continuously acquire information from multiple sources including:
• Public company registers.
• Electoral registers where permitted.
• Property databases.
• Court records.
• Social media.
• Marketing partners.
• Public websites.
• Commercial licensing agreements.
• Other data brokers.
For this reason, information that has been successfully removed may later reappear after a subsequent data refresh.
Privacy protection should therefore be viewed as an ongoing process rather than a one-time exercise.
Regular monitoring combined with periodic removal requests generally provides the most effective long-term protection.
How deleteme Can Help
Managing dozens of GDPR requests across multiple jurisdictions can become time-consuming, particularly when organisations use different verification procedures and legal requirements.
The deleteme privacy platform assists individuals and organisations by identifying where personal information is exposed, monitoring changes over time, and managing removal requests across a broad range of European and international data brokers.
Unlike many automated removal services that focus primarily on the United States, deleteme is designed to support both European and international privacy requirements, combining GDPR expertise with ongoing monitoring of digital exposure.
Whether you choose to submit requests yourself using this guide or use professional assistance, understanding your legal rights remains the foundation of effective privacy protection.
Start your data broker removal and your FREE scan. Once your scan is complete, you’ll receive two complimentary reports:
• Data Broker & Internet Exposure Report
• Data Breach & Dark Web Report
Part I — Marketing & AdTech Data Brokers
Understanding the European Advertising Data Ecosystem
Advertising technology (AdTech) companies represent one of the largest collectors of personal information in Europe. Unlike traditional data brokers that compile consumer profiles from public records or commercial databases, AdTech vendors build behavioural profiles by monitoring how individuals interact with websites, mobile applications, connected televisions, and digital advertising networks.
Every time a website loads advertisements, dozens—or sometimes hundreds—of advertising companies may receive information about the visitor. This information can include browser identifiers, IP addresses, approximate location, device characteristics, browsing behaviour, purchase interests, language preferences, and inferred demographic attributes.
Most users never interact directly with these companies, yet they continuously participate in the Real-Time Bidding (RTB) ecosystem, where advertising impressions are auctioned within milliseconds.
How AdTech Companies Collect Personal Data
Advertising companies collect information using various technologies, including:
• Browser cookies
• Mobile Advertising IDs (Apple IDFA and Google AAID)
• Device fingerprinting
• IP address analysis
• Consent Management Platforms (CMPs)
• Website analytics
• SDKs embedded within mobile applications
• Cross-device identity matching
• Server-to-server integrations
Many organisations combine information from multiple sources to create long-term behavioural profiles that can be licensed to advertisers, publishers, marketing agencies, and data partners.
Although much of this processing relies upon user consent obtained through cookie banners, some organisations also rely on legitimate interests under Article 6(1)(f) GDPR for specific processing activities. This legal basis remains subject to regulatory scrutiny and judicial interpretation across the European Union.
Your GDPR Rights Against Advertising Companies
Where an AdTech company processes your personal data, you may generally exercise several GDPR rights, depending on the legal basis relied upon.
Article 15 — Right of Access
Request:
• A copy of all personal data held.
• Categories of data processed.
• Data sources.
• Recipients of your information.
• Automated profiling information.
• Retention periods.
Article 17 — Right to Erasure
Where the legal requirements are satisfied, request deletion of:
• Advertising identifiers.
• Behavioural profiles.
• Device associations.
• Audience segmentation data.
• Marketing profiles.
• Historical tracking records.
Article 21 — Right to Object
If processing relies upon legitimate interests, you may object to profiling and direct marketing activities.
Unless the organisation demonstrates overriding legitimate grounds, processing should cease.
Withdrawal of Consent
Where consent was used to collect advertising identifiers, withdraw that consent using the same Consent Management Platform (CMP) whenever possible.
Withdrawing consent should prevent future collection but does not necessarily remove information already stored. A separate GDPR erasure request may still be required.
Recommended Removal Process
For advertising companies, the following order generally produces the best results.
Step 1
Withdraw advertising consent through the website’s Consent Management Platform.
Step 2
Submit an Article 15 GDPR access request to determine what personal information has already been collected.
Step 3
Submit an Article 17 erasure request requesting deletion of all behavioural profiles and associated identifiers.
Step 4
Where deletion is not legally or technically possible, request suppression so your identifiers cannot be reactivated or reused.
Step 5
Retain confirmation emails and monitor compliance within the statutory one-month response period under Article 12(3) GDPR.
Common Challenges
Advertising data is dynamic.
Profiles are rebuilt continuously as users browse the web, install applications, accept cookies, or interact with advertising networks.
As a result:
• Deleted identifiers may later be recreated.
• New browser cookies generate new identifiers.
• Mobile advertising IDs may change after device resets.
• Fresh consent creates new advertising profiles.
• Third-party partners may continue supplying information.
Privacy protection should therefore combine removal requests with ongoing privacy management.
Industry Frameworks
Many European AdTech companies participate in industry frameworks intended to manage advertising consent and transparency.
These include:
• IAB Europe Transparency & Consent Framework (TCF)
• Google Consent Mode
• OneTrust Consent Management Platform
• Didomi
• Usercentrics
• Cookiebot
• Quantcast Choice
Participation in these frameworks does not replace GDPR obligations. Individuals retain the right to exercise all applicable rights directly with each controller.
Special Case — Network-Level Advertising Identifiers (Utiq)
Traditional online advertising relies primarily on browser cookies or mobile advertising identifiers.
Utiq operates differently.
Developed by major European telecommunications providers, Utiq generates advertising identifiers at the network level rather than within the browser itself. These identifiers are linked to a customer’s mobile or broadband subscription and are designed to support personalised advertising while preserving a degree of pseudonymisation.
Because the identifier originates from the telecommunications network rather than the browser, deleting cookies alone does not remove it.
Individuals wishing to stop Utiq-based advertising should:
• Withdraw consent through the Utiq Consent Hub.
• Disable Utiq participation wherever offered by participating websites.
• Exercise their GDPR rights directly where appropriate.
• Continue declining future consent requests to prevent reactivation.
Marketing & AdTech Broker Directory
The organisations listed in this section participate in various aspects of the European digital advertising ecosystem. Some act as demand-side platforms (DSPs), others as supply-side platforms (SSPs), audience measurement providers, advertising exchanges, consent platform providers, or behavioural profiling companies.
For each organisation, this guide provides:
• Company name.
• Primary jurisdiction.
• Privacy or GDPR portal.
• Recommended removal method.
• Whether consent withdrawal alone is sufficient.
• Whether an Article 17 request is recommended.
• Whether suppression should also be requested.
• Practical observations where applicable.
The following directory begins with the largest and most influential European AdTech companies before moving to specialised advertising technology providers operating across the European Economic Area and the United Kingdom.
Start your data broker removal and your FREE scan. Once your scan is complete, you’ll receive two complimentary reports:
• Data Broker & Internet Exposure Report
• Data Breach & Dark Web Report
Marketing & AdTech Broker Directory
The organisations listed below participate in various parts of the European digital advertising ecosystem. While their business models differ, many collect, analyse, enrich, or distribute personal data for targeted advertising, audience measurement, attribution, fraud prevention, and programmatic advertising.
Some companies operate as data controllers, while others act as processors or joint controllers depending on the services they provide. Regardless of their role, individuals may exercise their GDPR rights where personal data is processed.
For each organisation below, this guide explains what the company does, the types of personal information typically processed, and the recommended approach for exercising your GDPR rights.
1. Criteo SA (France)
Business Overview
Criteo is one of Europe’s largest advertising technology companies, specialising in personalised advertising, commerce media, audience segmentation, and retargeting services. The company works with thousands of retailers, publishers, and advertising partners worldwide.
Personal Data Typically Processed
• Cookie identifiers
• Mobile advertising identifiers
• Device identifiers
• IP addresses
• Shopping behaviour
• Website activity
• Product interests
• Advertising interactions
• Approximate geolocation
Recommended GDPR Action
✔ Withdraw consent through your Consent Management Platform (CMP).
✔ Submit an Article 17 erasure request.
✔ Request deletion of behavioural profiles.
✔ Request suppression of future advertising identifiers.
Privacy Portal
https://www.criteo.com/privacy/
2. Ogury Ltd (United Kingdom / France)
Business Overview
Ogury provides privacy-focused mobile advertising, audience targeting, and advertising measurement technologies. The company primarily processes mobile device information for digital advertising campaigns.
Personal Data Typically Processed
• Mobile advertising IDs
• Device characteristics
• Browser information
• App usage
• Approximate location
• Consent preferences
Recommended GDPR Action
• Withdraw advertising consent.
• Request access to your advertising profile.
• Request deletion of all behavioural identifiers.
• Ask for suppression of future marketing use.
Privacy Centre
https://ogury.com/privacy-policy/
3. Sirdata (France)
Sirdata develops audience segmentation and advertising optimisation services for publishers and advertisers throughout Europe.
Typical information processed includes:
• Browser identifiers
• Cookies
• Website activity
• Audience interests
• Consent preferences
Recommended action:
• Withdraw consent.
• Submit an Article 21 objection.
• Follow with an Article 17 erasure request.
Privacy Portal
https://sirdata.com/en/privacy
4. Adikteev (France)
Adikteev specialises in mobile advertising and application retargeting.
Data processed commonly includes:
• Mobile identifiers
• Device IDs
• App engagement
• Advertising attribution
• Campaign performance metrics
Recommended removal:
• Remove consent.
• Submit an Article 17 request.
• Request deletion of advertising profiles.
Privacy Portal
https://www.adikteev.com/privacy
5. Jellyfish (France)
Jellyfish provides digital marketing, analytics, audience intelligence, advertising optimisation, and media buying services.
Depending upon the services delivered, personal information may include:
• Website analytics
• Marketing attribution
• Device identifiers
• Cookie identifiers
• Audience segmentation
Recommended approach:
• Request access.
• Object to profiling where applicable.
• Request deletion of marketing profiles.
6. ADventori SAS (France)
ADventori provides personalised advertising and dynamic creative optimisation technologies.
Typical processing:
• Device identifiers
• Advertising IDs
• Browser data
• Campaign interaction history
Recommended GDPR request:
• Article 15 Access
• Article 17 Erasure
• Suppression of future profiling
7. Adloox
Adloox provides advertising verification, fraud detection, and media quality assessment services.
Although fraud prevention may constitute a legitimate interest, individuals may still request:
• Confirmation of processing.
• Access to stored identifiers.
• Deletion where legally applicable.
• Restriction of unnecessary profiling.
8. Sublime
Sublime delivers premium advertising technology solutions across European publishers.
Typical information:
• Cookie identifiers
• Device data
• Browser information
• Advertising preferences
Recommended removal:
• Withdraw consent.
• Request deletion.
• Request suppression.
9. Roq.ad GmbH (Germany)
Roq.ad develops identity resolution technologies, customer data platforms, and audience analytics.
Data processed may include:
• Device identifiers
• Browsing activity
• Customer segmentation
• Marketing audiences
Recommended actions:
• Article 15 Access Request
• Article 17 Erasure
• Article 21 Objection
10. AdSpirit GmbH (Germany)
AdSpirit develops advertising servers used by publishers and advertising networks.
Although acting primarily as infrastructure, the platform may process:
• IP addresses
• Cookie identifiers
• Device information
• Advertising logs
Where personal data is retained, individuals may request access and deletion where applicable.
Practical Guidance
Many advertising companies receive your information indirectly rather than collecting it from you directly.
This means you may never have heard of the organisation before receiving a response to your GDPR request.
Do not assume that unfamiliar companies do not hold your information.
Advertising profiles are routinely exchanged between hundreds of advertising partners participating in programmatic advertising.
For this reason, deleting data from one company does not automatically remove your information from the wider advertising ecosystem.
Privacy protection is therefore most effective when requests are submitted across multiple organisations, combined with regular reviews of your browser consent settings, mobile advertising identifiers, and online privacy preferences.
Next Section
The following organisations will be covered in the next chapter:
• Admetrics GmbH
• Semasio GmbH
• Virtual Minds GmbH
• ShowHeroes SE
• Smartclip Europe
• Captify Technologies
• Sovrn
• Venatus
• Blis
• Fifty Technology
• MiQ
• LoopMe
• Dentsu UK
• Crimtan
• Genius Sports
• Yahoo EMEA
• Adform
• RTB House
• ETARGET
• BidTheatre
• Emerse
• TripleLift
• The Trade Desk
• Epsilon
• Magnite
• Madison Logic
• 33Across
• Eyeota
• DoubleVerify
• Quantcast
Each profile will include company background, data processed, GDPR removal strategy, privacy portal, legal considerations, and practical recommendations for exercising your rights.
Start your data broker removal and your FREE scan. Once your scan is complete, you’ll receive two complimentary reports:
• Data Broker & Internet Exposure Report
• Data Breach & Dark Web Report
Need help? Visit our Help Center.
More Privacy Tips





