Data Brokers in the United States: No Federal Privacy Law, 25 Major Brokers, and How to Opt Out

Data Brokers in the United States: No Federal Privacy Law, 25 Major Brokers, and How to Opt Out

Data Brokers in the United States: No Federal Privacy Law, 25 Major Brokers, and How to Opt Out

6 mins read

A deleteme briefing

The United States has no single, comprehensive federal privacy law. Unlike the European Union, where the GDPR gives individuals broad rights over how their personal data is collected, processed, and erased, the US still relies on a patchwork of sector-specific federal laws and state-by-state privacy statutes.

That gap has allowed a large data broker industry to develop. These companies collect, aggregate, enrich, and sell personal information about people who often have no direct relationship with them and may not even know they exist.

Data brokers build profiles from public records, commercial transactions, marketing lists, location signals, behavioural data, breach corpora, court filings, property records, and other open or semi-open sources. A single person may appear across many broker systems at once: as a people-search profile, a marketing segment, a credit-related record, a property record, a household profile, or a breach-linked identity.

This report explains what US law does and does not protect, how the state privacy patchwork works, which major brokers commonly hold US data, what practical opt-out steps exist, and where removal reaches its limit.

Why the US Has No Federal Privacy Law

The US privacy system is fragmented by design.

There is no federal equivalent of the GDPR. Instead, the US regulates specific categories of data through separate laws:

• HIPAA for certain health records;

• FCRA for credit and consumer reporting;

• COPPA for children’s data;

• GLBA for financial institutions;

• FERPA for education records.

These laws matter, but each applies only to a defined sector. A data broker holding general consumer profiles, addresses, relatives, phone numbers, purchase behaviour, inferred income, lifestyle signals, location data, or marketing segments, may fall outside those narrow federal regimes.

That is the central problem: data brokers often operate in the gaps between regulated sectors.

For deleteme clients, this means US exposure cannot be treated as one legal problem. It must be mapped by source type, broker category, state residency, use case, and whether the data is regulated, public, inferred, or commercially aggregated.

What Federal Law Actually Does

The FTC’s Role

In the absence of a comprehensive federal privacy statute, the Federal Trade Commission uses its authority against unfair or deceptive acts or practices to pursue some data broker abuses.

The FTC can act where a company lies about its data practices, misleads consumers, violates an existing order, or causes substantial harm that consumers cannot reasonably avoid. But the FTC is not a general-purpose deletion authority. It cannot simply order every broker to erase consumer profiles on request.

Where civil penalties are available under relevant FTC Act provisions, the current maximum listed in the eCFR is $53,088 for certain FTC Act violations assessed after January 17, 2025.

FTC enforcement has targeted data misuse and people-search practices in cases involving companies such as Spokeo, TruthFinder, Instant Checkmate, MyLife, Kochava, and BetterHelp. These cases show that the FTC can intervene, but only after a legal theory is available, not merely because a broker holds data that a person dislikes.

For individuals, FTC enforcement is important but indirect. It does not replace a structured opt-out, deletion, correction, or suppression strategy.

The FCRA: The Closest Federal Deletion Right

The Fair Credit Reporting Act is the strongest federal consumer-data regime in the US, but it is limited.

It applies to consumer reporting agencies that compile information used for credit, employment, housing, insurance, or similar eligibility decisions. Under the FCRA, consumers can request reports, dispute inaccurate information, place credit freezes, and require deletion of information that cannot be verified.

The key limitation is that most people-search sites and marketing brokers explicitly state that their data is not for FCRA purposes. That disclaimer is designed to keep them outside the strictest consumer reporting obligations.

For deleteme clients, this distinction matters. A credit bureau record, a background screening record, a people-search profile, and a marketing broker record may look similar to the individual, but they sit under different legal rules.

The State Patchwork

Because there is no comprehensive federal law, US privacy rights depend heavily on state residency.

California remains the most important state for data broker privacy. The California Consumer Privacy Act and California Privacy Rights Act give California residents rights to know, delete, correct, access, port, and opt out of certain sale or sharing of personal information. California also requires data brokers to register.

The biggest change is the California DELETE Act and the CPPA’s Delete Request and Opt-out Platform, known as DROP. The original report described this as “coming January 2026.” That should now be updated: the CPPA’s own site states that DROP is officially live, the regulations took effect on January 1, 2026, and data brokers must access DROP at least every 45 days starting August 1, 2026 to retrieve and process deletion requests.

This makes California the closest US equivalent to a centralized broker-deletion mechanism. It is still not the same as GDPR erasure. It applies to registered data brokers, includes exemptions, and does not erase public records themselves. But it materially changes the burden: a California resident can now submit one request through a state-hosted mechanism instead of contacting hundreds of brokers individually.

Other states, including Virginia, Colorado, Texas, Oregon, Connecticut, Indiana, Kentucky, Rhode Island, and others, have privacy laws with varying rights and thresholds. IAPP reported that Indiana, Kentucky, and Rhode Island comprehensive privacy laws became effective on January 1, 2026, adding to the state privacy patchwork.

For everyone outside stronger state regimes, opt-outs are often voluntary, inconsistent, and dependent on each broker’s own process.

The Key Difference from GDPR

The GDPR starts from a lawful-basis model: a company needs a lawful basis before processing personal data.

US privacy law is usually opt-out based: processing is often allowed unless the consumer objects, opts out, freezes, suppresses, or submits a deletion request under a state law that applies to them.

That structural difference matters. Under GDPR, the controller must justify the processing. Under most US frameworks, the individual must discover the broker, find the correct process, submit the request, verify identity, and repeat the process when records reappear.

This is why data broker removal in the US is not a one-time task. It is maintenance.

Why Breach Data Makes the Broker Problem Worse

US data broker exposure is intensified by repeated large-scale breaches.

Major breaches from 2020 to 2024 exposed names, addresses, Social Security numbers, dates of birth, phone numbers, driver’s licence numbers, medical data, insurance data, call records, and household relationships. The original report highlights major incidents involving T-Mobile, MOVEit, AT&T, Change Healthcare, and National Public Data.

The National Public Data breach is especially important because the company had no direct consumer relationship with many of the people whose records it held. That is the data broker problem in miniature: people cannot meaningfully protect themselves from companies they do not know exist.

Once breach data circulates in criminal forums, ordinary commercial opt-outs do not remove it. Opt-outs can reduce exposure across legitimate or semi-legitimate broker ecosystems, but they cannot pull copied breach data back from underground markets.

The 25 Major Data Brokers Holding US Data

The US broker ecosystem is broad. It includes people-search sites, marketing intelligence companies, credit bureaus, specialty reporting agencies, property data firms, insurance databases, employment verification systems, and identity-resolution platforms.

The original report identifies 25 major US-facing brokers and broker categories, including people-search platforms such as Spokeo, BeenVerified, Intelius, TruthFinder, Whitepages, PeopleFinders, MyLife, FastPeopleSearch, Radaris, Instant Checkmate, Pipl, Zabasearch, and USSearch.

It also identifies major aggregators and specialty data holders such as Acxiom/LiveRamp, Oracle Data Cloud, Epsilon, LexisNexis Risk Solutions, CoreLogic, Verisk/ISO, Equifax Workforce Solutions, Equifax, Experian, TransUnion, Clearview AI, and ChexSystems.

For deleteme, the important point is not just the list. It is the structure behind the list.

Some brokers publish searchable profiles. Others never show a public profile but still process and license data behind the scenes. Some respond to consumer opt-outs. Others only provide access or dispute rights under specific laws. Some data is removable. Some can only be corrected, suppressed, frozen, or limited. Some cannot realistically be removed at all.

Practical Opt-Out Toolkit

A strong US privacy cleanup usually starts with the highest-impact protective actions.

1. Freeze your credit files

A credit freeze is one of the most effective identity-theft prevention steps for US residents. It should be placed with the three major credit bureaus — Equifax, Experian, and TransUnion — and also considered for Innovis and ChexSystems.

A freeze does not remove broker data, but it helps prevent new credit from being opened in your name after sensitive identifiers have been exposed.

2. Opt out of pre-screened credit and insurance offers

Pre-screened credit and insurance offers are generated through credit bureau marketing systems. Opting out reduces one category of commercial data use and may reduce sensitive mail exposure.

3. Use browser-level opt-out signals

Global Privacy Control is increasingly important because some state laws require covered businesses to honour recognized opt-out preference signals. It does not solve the whole broker problem, but it is one of the few persistent privacy signals that follows a user across sites.

4. Submit broker-specific removals

People-search sites often require individual opt-out submissions. These can reduce visible exposure, but records may reappear when brokers refresh their sources.

5. Use state mechanisms where available

California residents should use DROP. Residents of other states should use applicable state privacy rights where available, including deletion, correction, access, sale opt-out, targeted advertising opt-out, and appeal rights.

6. Repeat the process

Data broker removal is not permanent unless the upstream source is also controlled. Public records, new breach data, marketing resupplies, and broker-to-broker licensing can repopulate profiles.

Start your data broker removal and your FREE scan. Once your scan is complete, you’ll receive two complimentary reports:

Data Broker & Internet Exposure Report

Data Breach & Dark Web Report

Even a thorough removal campaign has limits.

Public Records

Property deeds, court filings, voter records, corporate filings, professional licences, and some government records may be legally public.

Removing a broker profile does not erase the public source that fed it.

Criminal Breach Data

If data has already been copied into criminal markets, commercial opt-outs will not remove it.

The correct response is protective:

• Credential rotation

• MFA

• Credit freezes

• Monitoring

• Targeted risk reduction

B2B and Government-Facing Data

Some data streams used for fraud prevention, compliance, identity verification, insurance, law enforcement, or financial due diligence may not have ordinary consumer opt-out routes.

Offshore and Non-Compliant Operators

Some people-search sites operate outside practical enforcement reach.

They may honour requests voluntarily, inconsistently, or not at all.

Inferred Data

Adtech and marketing systems may infer income, interests, family status, life stage, health signals, political interests, or purchase intent without showing the person a neat public profile to remove.

What deleteme Does Differently

deleteme treats data broker removal as an investigation, not a checklist.

Automated tools can be useful for simple people-search removals, but they often stop at “request sent.” That is not the same as “record deleted.” The uploaded European comparison report makes the same distinction: dashboards may show a request has been submitted, while professional verification requires confirming broker by broker that the record is actually gone.

A deleteme engagement focuses on:

• identifying where the exposure actually sits;

• separating people-search profiles from upstream data sources;

• determining which legal route applies;

• submitting targeted removal, objection, correction, restriction, or suppression requests;

• escalating where brokers ignore valid requests;

• verifying outcomes rather than relying only on submission status;

• documenting what was removed, what remains, and why.

For ordinary exposure, DIY opt-outs may be enough. For executives, public leaders, founders, HNWIs, journalists, family offices, and people facing targeted harassment or social-engineering risk, one missed record can be the record that matters.

That is where analyst-led removal becomes a different service, not simply a more expensive subscription.

When to Use deleteme

Use deleteme when:

• your personal details appear across multiple broker sites;

• your home address or family links are visible;

• you have a professional or public profile;

• you are exposed through company records, filings, media, or litigation history;

• your identifiers appear in breach datasets;

• you are facing targeted contact, phishing, harassment, impersonation, or social engineering;

• you need a documented baseline before a new executive, public, legal, investment, or board role;

• you want verified removal rather than a dashboard that only confirms requests were sent.

deleteme can begin with a focused exposure review and then move into structured removal where appropriate.

Bottom Line

The US data broker system is not built for easy deletion.

There is no comprehensive federal privacy law. State rights vary. California now has the strongest centralized mechanism through DROP, but most Americans still rely on a combination of voluntary opt-outs, credit freezes, state privacy requests, browser signals, and repeated manual maintenance.

The practical answer is layered:

• First, reduce immediate risk through freezes and security controls.

• Second, remove visible people-search exposure.

• Third, challenge upstream broker records where possible.

• Fourth, verify what was actually removed.

• Fifth, repeat the process because broker data repopulates.

That is the purpose of deleteme: to turn a fragmented, repetitive, and deliberately difficult process into a structured removal and verification engagement.

Find Out What Is Visible About You

Start with a free deleteme Scan.

Send your email address and receive a concise two-page exposure summary within 48 hours.

No payment. No subscription. No obligation.

For deeper cases, deleteme can move from Scan to a full Digital Footprint Exposure or a verified data broker removal.

Take control of your data today.
Let’s get started!

Ready to take back control of your personal data on the dark web?
deleteme.com scans, detects, and helps remove your exposed information from high-risk sources fast, secure, and hassle-free.

Take control of your data today.
Let’s get started!

Ready to take back control of your personal data on the dark web?
deleteme.com scans, detects, and helps remove your exposed information from high-risk sources fast, secure, and hassle-free.

Take control of your data today.
Let’s get started!

Ready to take back control of your personal data on the dark web?
deleteme.com scans, detects, and helps remove your exposed information from high-risk sources

fast, secure, and hassle-free.

Need help? Visit our Help Center.