Direct Answer: Data brokers companies that collect and resell personal information are the primary source behind spam texts and unsolicited marketing calls. In the United States, no single federal law outright bans the sale of your phone number. In the UK and EU, passing your number to third-party marketers without explicit consent is a serious breach of data protection law. The rules you can use to fight back depend entirely on where you live.
Who is selling my phone number typically, several companies you have never heard of. You signed up for a loyalty card, filled out a “free quote” form, or downloaded a free app, and somewhere in the fine print your number was cleared for onward sale.
This article covers who these sellers are, what the law says in the US, UK, and EU, and what many people in this situation do next. For more context, see Can Companies Legally Sell Your Personal Data?.
The Short Version TL;DR
- Data brokers are the main culprits they collect your number from public records, apps, loyalty programs, and lead-generation sites, then sell it in bulk.
- In the US, selling phone numbers is broadly legal at the federal level. The TCPA restricts how companies can contact you not whether your number can be sold.
- In the UK and EU, sharing your number for marketing without valid consent breaches GDPR and PECR. Fines run into hundreds of thousands of pounds or euros.
- You can reduce spam by opting out of broker listings, registering with do-not-call registries, and sending deletion requests under applicable privacy law.
What “Who Is Selling My Phone Number” Means Under the Law
The data broker industry
A data broker is a company that collects personal information and sells it to third parties. Brokers pull your number from public records, mobile apps, loyalty programs, and lead-generation sites. They bundle it with your name, address, and browsing interests, then sell the package in bulk. Buyers range from legitimate marketers and political campaigns to fraudsters who access the same pipelines.
US law: the sale is broadly permitted, the contact is regulated
In the United States, no federal law prohibits the sale of your phone number. The TCPA (Telephone Consumer Protection Act, 1991) restricts how your number can be used, not whether it can be sold: companies sending automated marketing texts generally need prior express written consent.
For years, a loophole made that consent nearly meaningless a single checkbox on a lead-generation site could be shared across dozens of unrelated companies. The FCC tried to close this in December 2023 with a “one-to-one consent” rule. On January 24, 2025, the U.S. Court of Appeals for the Eleventh Circuit struck it down in Insurance Marketing Coalition v. FCC, ruling the FCC had exceeded its authority. The FCC declined to appeal. As of mid-2026, one disclosure form can still cover multiple sellers if the language is “clear and conspicuous” a low bar.
One real change did survive: since April 11, 2025, companies must honor opt-out requests by any reasonable means within 10 business days. TCPA violations carry fines of $500 to $1,500 per message. At the state level, California’s Delete Act (2023) building on the CCPA gives residents the right to submit a single deletion request covering all registered data brokers at once.
UK law: much stricter
In the United Kingdom, your phone number is personal data under UK GDPR and the Data Protection Act 2018. Sharing it for marketing without explicit consent violates the law.
The Privacy and Electronic Communications Regulations 2003 (PECR) add a second layer. Under PECR, sending unsolicited marketing texts without prior consent is unlawful, full stop. The ICO (Information Commissioner’s Office) enforces this actively: one firm that sent nearly 15 million texts without valid consent was fined £200,000. Under UK GDPR, individuals generally have the right to request erasure of their data from any company’s database. The company has one calendar month to comply.
EU law: GDPR in full
Inside the European Union, GDPR (2018) Regulation (EU) 2016/679 treats a phone number as personal data. Sharing it for marketing without explicit consent violates the law. The European Data Protection Board (EDPB) has consistently held that blanket tick-box disclosures do not meet GDPR’s consent standard.
Real-World Examples
The comparison-shopping form. You submit your number on an insurance comparison site. Buried in the consent checkbox is “I agree to be contacted by our marketing partners.” Under current US law, that disclosure if “clear and conspicuous” can cover dozens of companies you never named. Your number is now on multiple marketing lists, each of which may resell it further.
The app that tracks more than you expect. A free app shares your device identifiers and contact details with “analytics partners.” Some are data brokers. Your number ends up in a bulk dataset sold to telemarketers without you ever directly giving it to a marketing company.
The data breach pipeline. Your number was included in a breach at a retailer or loyalty platform. Stolen contact lists circulate on dark-web marketplaces. Once your number enters that ecosystem, it is difficult to trace to a single source and opt-out services cannot scrub data already moving through criminal networks.
What People in This Situation Typically Do
- Check if your number appears on data broker sites. Search your name on people-search platforms like Spokeo or WhitePages. If your number is publicly listed, it is available for bulk purchase.
- Register with do-not-call lists. In the US, register at donotcall.gov (FTC’s National Do Not Call Registry). This does not stop scammers but gives legal grounds to complain about telemarketers who ignore the list. In the UK, register with the Telephone Preference Service (TPS) at tpsonline.org.uk marketers must check this list before texting or calling.
- Submit opt-out requests to data brokers. Many brokers publish an opt-out page. The process is time-consuming but does reduce volume over weeks and months. California residents can submit a unified request through the state’s data broker registry under the Delete Act.
- Exercise deletion rights in the UK or EU. Under UK GDPR or EU GDPR, individuals generally have the right to ask any company to delete their personal data. Send a written request to any company whose texts you receive they have one month to act.
- Report violations. In the US, file with the FTC at reportfraud.ftc.gov or the FCC at consumercomplaints.fcc.gov. In the UK, report to the ICO at ico.org.uk/make-a-complaint.
- Consider legal action for repeated violations. If you received a high volume of automated texts without giving consent, the TCPA’s private right of action makes suits viable. Many consumer protection attorneys handle these cases on contingency.
Tools That Can Help
Managing data broker opt-outs by hand is time-consuming each broker has its own process, many require identity verification, and most re-list you after a few months. Automated removal services handle this continuously.
DeleteMe scans hundreds of data broker sites, submits removal requests on your behalf, and re-checks periodically to catch re-listing.
Incogni sends opt-out requests to a large list of brokers on an ongoing basis and provides a dashboard showing which requests are pending or completed.
Neither service guarantees removal from every list, but both significantly reduce the number of active brokers holding and reselling your data.
Related Articles
- How to Opt Out of Data Brokers 2026 Guide
- What Is GDPR and Why Should You Care?
- CCPA Explained: California’s Privacy Law
Frequently Asked Questions
Is it legal for a company to sell my phone number in the US? Generally, yes. No federal law bars the sale of phone numbers. The TCPA restricts how your number can be used for marketing automated texts typically require prior written consent but after the Eleventh Circuit struck down the FCC’s one-to-one consent rule in January 2025, the older, broader standard came back into effect. State laws in California, Texas, and Connecticut add some protection on top.
How did spam texters get my number if I never gave it to them directly? The most common route is a lead-generation website a comparison page or “free quote” form where buried consent language covered dozens of “marketing partners.” Your number also reaches brokers through mobile apps that share device identifiers with analytics companies, through public records, and through data breach pipelines where stolen contact lists are resold. Each transfer adds another link in a chain that can span many companies.
Does replying STOP actually work, or does it confirm my number is active? It depends on the sender. For legitimate businesses under TCPA rules, STOP should work: since April 2025, companies must honor opt-out requests within 10 business days. For scammers, replying to anything can confirm your number is live and make it more valuable to bad actors. If the message looks like a scam, do not reply forward it to 7726 (SPAM) to report it to your carrier.
Can I sue someone for sending me spam texts? Under the TCPA, individuals generally have the right to sue for $500 per violation, or up to $1,500 if the sender acted willfully per message, with no proof of financial harm required. The main obstacle is identifying the sender: anonymous senders require subpoenaing carrier records, which typically means filing a lawsuit first. Consumer protection attorneys who handle TCPA cases often work on contingency. In the UK, individuals may also claim compensation for distress under UK GDPR without needing to show financial loss.
The question of who is selling your phone number rarely has one answer it is typically a chain of data brokers, lead generators, and their downstream buyers. In the US, that chain operates largely within federal law, though consent and opt-out rules are real and enforceable. In the UK and EU, restrictions are tighter, and regulators actively fine companies that share data without proper consent. Knowing which framework applies to you is the starting point for action that actually works.
This article is for educational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. For advice specific to your situation, consult a qualified attorney.
Last Updated: July 2026
Sources & Further Reading
- FTC National Do Not Call Registry Official US opt-out registry for telemarketing calls and texts
- FCC Stop Unwanted Robocalls and Texts Federal rules on automated texts and calls and opt-out requirements
- ICO Electronic and Telephone Marketing Guidance UK regulator guidance on PECR and UK GDPR marketing rules
- EDPB Guidelines on Consent under GDPR EU-level guidance on valid consent standards
- FTC Report Fraud Report illegal robocalls and spam texts to the FTC

