How to Opt Out of Data Brokers Complete 2026 Guide

Photo of author
Author: admin
Published:

Direct Answer: Data brokers collect and sell personal information often without consent. In the US, individuals can submit opt-out requests directly to brokers, use California’s new DROP portal, or hire a removal service. In the EU and UK, GDPR Article 17 gives individuals a legally enforceable right to demand erasure. Opting out is free, but it takes time and regular follow-up.

How to opt out of data brokers is one of the most searched privacy questions in 2026 and for good reason. Right now, there are an estimated 4,000 or more data brokers operating in the United States alone. Many of them hold your name, home address, phone number, estimated income, political affiliation, and purchasing habits in a file you never agreed to create. If that sounds unsettling, the good news is that a growing number of laws now give people the power to request deletion and in some cases, a single click can reach hundreds of brokers at once. This guide breaks down the exact steps across three major jurisdictions: the US, the EU, and the UK. If a company has already sold your data without permission, you may also want to read about whether companies can legally sell your personal data.

The Short Version

  • Data brokers are companies that collect, package, and sell personal information to third parties usually without your knowledge or direct consent.
  • In the US, California’s new DELETE Act and its DROP portal let residents send a single deletion request to over 600 registered brokers. Other states offer deletion rights under their own privacy laws, though the process is broker-by-broker.
  • In the EU, GDPR Article 17 gives individuals a legally enforceable right to erasure. Brokers must respond within 30 days or face regulatory action.
  • In the UK, the UK GDPR and the Data Protection Act 2018 (amended by the Data Use and Access Act 2025) provide similar erasure rights enforced by the ICO.
  • Paid removal services like DeleteMe and Incogni can automate the process, but manual opt-outs are free.

What “Opting Out of Data Brokers” Actually Means Under the Law

Before getting into the steps, it helps to understand what a data broker actually is and what rights the law gives you.

A data broker is a business that collects personal information from public records, commercial transactions, social media, and other sources, then packages and sells that data to third parties. Unlike a bank or a hospital, data brokers typically have no direct relationship with the people whose information they trade. They operate largely in the background. Most people have never heard of the specific companies that hold their data.

The legal landscape around data broker removal varies dramatically depending on where you live.

United States

There is no single federal law that governs data brokers. Instead, a patchwork of state laws provides varying levels of protection.

California has gone the furthest. The California Consumer Privacy Act (CCPA, 2018) gave residents the right to ask businesses to delete their personal data and to opt out of the sale of that data. Then in 2023, the state passed the DELETE Act (Senate Bill 362), which directed the California Privacy Protection Agency (CalPrivacy) to build a centralized deletion tool.

That tool the Delete Request and Opt-Out Platform (DROP) went live on January 1, 2026. DROP lets any verified California resident submit a single request that reaches every registered data broker in the state. As of mid-2026, over 600 brokers are registered. Starting August 1, 2026, those brokers must begin processing deletion requests within 90 days and must check the platform at least every 45 days for new requests. Brokers that fail to comply face penalties of $200 per day.

CalPrivacy has already shown it takes enforcement seriously. In 2025, the agency fined multiple brokers for failing to register, including Accurate Append ($55,400) and National Public Data ($46,000). Background Alert was ordered to suspend operations until 2028 or pay a $50,000 penalty.

Beyond California, states including Colorado, Connecticut, Virginia, Oregon, and Indiana have passed privacy laws that include deletion and opt-out rights though none yet offer a centralized portal like DROP. Vermont and Oregon require data brokers to register with the state, which at least makes them visible to regulators.

European Union

The EU takes a fundamentally different approach. Under GDPR (2018), personal data processing is prohibited by default unless a lawful basis exists under Article 6. Data brokers operating in Europe cannot simply assume they have permission to collect and sell your information.

Article 17 commonly known as the right to erasure or the “right to be forgotten” gives individuals the right to request deletion of their personal data. Brokers must respond within 30 days. If they refuse without valid legal grounds, you can file a complaint with your national data protection authority (DPA) at no cost.

The European Data Protection Board (EDPB) made the right to erasure a key enforcement priority in 2025, and has continued coordinated enforcement actions into 2026 signaling that regulators are actively watching how controllers handle deletion requests.

There is an important distinction here: under GDPR, opting out of a data broker is not a favour it is a legal obligation the broker must follow. The burden of proof for justifying data retention falls on the company, not on you.

United Kingdom

The UK left the EU but kept its own version of the regulation the UK GDPR, enforced alongside the Data Protection Act 2018. The Data (Use and Access) Act 2025 (DUAA), which commenced on 5 February 2026, updated parts of the framework but left the core erasure right intact.

The Information Commissioner’s Office (ICO) handles complaints. UK residents have the same basic right to request erasure from data brokers, and the same 30-day response window applies.

One practical tool for UK residents: opting out of the Open Register (also called the edited electoral register). This public version of the electoral roll is sold to data brokers and marketing companies. Removing yourself from it cuts off a major source of personal data at the root. You can do this by contacting your local Electoral Registration Office.

Real-World Examples

Scenario 1: A job applicant gets rejected based on a background check

A hiring manager runs a background check using a people-search site. The report pulls up an old address associated with a former roommate’s criminal record. The applicant never knew this data existed online. Under CCPA, the applicant can request deletion from the people-search site. Under GDPR, they can demand erasure and correction of inaccurate records under Articles 16 and 17.

Scenario 2: A domestic abuse survivor finds their new address listed online

After relocating for safety reasons, a person discovers that Whitepages and similar sites have already published their new home address. Several US states have Address Confidentiality Programs that help in this situation, and most people-search brokers have expedited removal processes for safety-related cases. Under GDPR, the right to erasure applies without needing to prove a safety risk though citing one may speed the process.

Scenario 3: An EU resident discovers a US-based broker holds their data

A person in Germany finds their personal details on a US people-search site. Because GDPR applies to any company that processes EU residents’ data regardless of where the company is located they can send an Article 17 erasure request. If the broker ignores it, they can file a complaint with Germany’s federal data protection authority (BfDI) or their state-level authority.

What People in This Situation Typically Do

Here is a step-by-step approach many privacy advocates recommend for anyone wanting to stop data brokers from holding and selling their information.

Step 1: Find out where your data appears

Search your full name on major people-search sites like Spokeo, Whitepages, BeenVerified, and PeopleFinders. Run variations maiden names, old phone numbers, previous addresses. This gives you a picture of which brokers are most likely holding your records.

Step 2: Use a centralized tool if one is available

If you are a California resident, sign up for DROP at privacy.ca.gov/drop. Verification goes through the California Identity Gateway, and you can submit a single request to all registered brokers. Your data is hashed for privacy brokers receive coded identifiers, not your raw personal details.

If you live in the EU or UK, no centralized portal exists yet. However, you can use a copy-paste Article 17 erasure request template and send it to each broker individually. Your national DPA’s website will typically have a template or guidance.

Step 3: Submit opt-out requests directly to individual brokers

For US residents outside California (or for brokers not registered with DROP), this is still a manual process. Most major people-search sites have an opt-out page usually buried deep in their privacy policy. The process typically involves searching for your listing, verifying your identity (often by email or phone), and confirming the removal request.

Expect to spend 10–30 minutes per broker. With over 100 major US brokers, the full process can take many hours spread across several sessions.

Step 4: Set calendar reminders to re-check every 90–180 days

This is the part most people miss. Data brokers refresh their databases regularly by re-pulling from public records. An opt-out that worked in January may be undone by March. Most privacy professionals recommend checking back every three to six months to verify that your data has not reappeared.

Step 5: Reduce your data footprint going forward

Opting out of existing brokers is only half the equation. To remove personal data from the internet more permanently, consider these measures:

  • Enable the Global Privacy Control (GPC) signal in your browser. California, Colorado, and Connecticut legally require websites to honour it as a binding opt-out of data sale.
  • Limit what you share on social media profiles. Set them to private where possible.
  • Avoid filling out online quizzes, sweepstakes, and surveys these are common data-collection tools.
  • Use a privacy-focused browser or install an ad blocker that disables tracking cookies.
  • Check your cookie consent settings on websites you visit regularly. If you’re not sure how cookie laws work, this guide on cookie consent laws in 2026 covers the basics.

Step 6: Escalate if a broker ignores your request

In the US, file a complaint with the FTC (Federal Trade Commission) or your state attorney general’s office. In the EU, contact your national data protection authority. In the UK, file a complaint with the ICO. These agencies have the power to investigate and fine non-compliant brokers.

Under GDPR, fines for the most serious violations can reach €20 million or 4% of global annual revenue, whichever is higher. Under California’s DELETE Act, brokers face $200 per day in penalties for each unprocessed deletion request.

Tools That Can Help

For people who want to opt out of data selling but don’t have the time to do it manually, two paid services are worth mentioning.

DeleteMe scans major US people-search sites, submits removal requests on your behalf, and monitors for re-listing over time. Plans start at around $129 per year for individual coverage. DeleteMe publishes regular transparency reports showing how many records it removes making it one of the more established options in this space.

Incogni (from the team behind Surfshark) takes a similar approach but covers a wider range of data broker categories, including marketing databases and data aggregators beyond just people-search sites. Pricing is typically around $7–13 per month depending on the plan. As of mid-2025, Incogni reported processing over 245 million data removal requests across 420+ broker databases.

Neither service can guarantee complete removal no tool can, because data brokers continuously re-aggregate from public sources. But both significantly reduce the manual workload and provide ongoing monitoring that most individuals would not maintain on their own.

Free alternative: If you live in California, DROP is entirely free and state-administered. For EU and UK residents, submitting GDPR erasure requests is free by law brokers cannot charge for processing them.

Related Articles

Frequently Asked Questions

What is a data broker and how do they get my information?

A data broker is a company that collects personal information names, addresses, phone numbers, purchasing habits, and more from public records, commercial databases, social media, and online activity. They package this data into profiles and sell them to marketers, insurance companies, employers, and sometimes even law enforcement. Most data brokers operate without any direct relationship to the people whose data they hold.

Is it free to opt out of data brokers?

Yes, submitting opt-out and deletion requests is free in every major jurisdiction. California’s DROP portal charges nothing, and under both CCPA and GDPR, companies cannot charge consumers for processing deletion requests. Paid services like DeleteMe and Incogni charge for the convenience of automating the process across many brokers at once but the underlying right to request removal costs nothing to exercise.

How many data brokers have my information?

The FTC estimates there are over 4,000 data brokers operating in the US. California’s DROP portal has more than 600 registered. Globally, some estimates put the number above 5,000. For the average American adult, at least several dozen and possibly over a hundred brokers are likely to hold some form of personal information, from basic contact details to inferred data about income, health, and political leanings.

Does opting out of data brokers actually work?

It works, but it is not permanent. When you submit a deletion request, the broker is legally required to remove your data within the timeframe set by the applicable law (30 days under GDPR, 45–90 days under most US state laws). However, brokers re-pull from public records regularly sometimes every 60 to 180 days. This means your data can reappear after removal. That is why privacy experts recommend repeating opt-out requests every three to six months, or using a paid monitoring service.

Knowing how to opt out of data brokers is one of the most practical steps anyone can take to reclaim some control over their personal information online. The laws are getting stronger California’s DROP portal is a landmark development, and GDPR enforcement around erasure rights continues to tighten. But no single opt-out request is a permanent fix. The data broker industry is built on constant re-collection. Staying on top of removal requests, reducing your digital footprint, and knowing which laws protect you in your jurisdiction are all part of the long-term picture. If a broker has collected your data and refuses to delete it, the right to be forgotten is more than just a concept it is an enforceable legal right in much of the world.

This article is for educational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. For advice specific to your situation, consult a qualified attorney.

Sources & Further Reading

Written by Alex

Alex is the editorial pen name of Mohammed Ez-Zayady, a law student based in Morocco and the founder of Jovonk. The content is provided for educational purposes and does not constitute legal advice.

Leave a Comment