← Privacy Guides

EU / GDPR corner

Remove yourself from data brokers

Find out which companies collect and sell your personal data, ask them for a copy, then make them delete it and stop using it for marketing.

  • Low threat
  • Time 2 hours, then a check every few months
  • Difficulty Moderate
  • Last verified

What this protects, and what it doesn't

Protects

  • Against people-search sites that publish your address, phone number and relatives to anyone who pays.
  • Against your profile being sold on for targeted advertising and direct marketing.
  • Against attackers who use broker data to answer security questions or to impersonate you.

Does not protect

  • It does not remove data from public records, such as land or company registers.
  • Data can come back: brokers collect again from new sources, and new brokers appear. Plan to repeat the checks.
  • Outside the EU and California you may have no legal right to deletion. Many brokers offer a voluntary opt-out instead.
  • It does not remove what is already in the hands of the companies the broker sold to. Each one is a separate request.

Prerequisites

  • An email address you use only for these requests, so replies do not get lost and you do not hand brokers a new address.
  • A simple list or spreadsheet to track each request: company, date sent, right used, reply date.
  • Some ID details ready, but share only what a company needs to find your record.

Step by step

  1. Understand what data brokers are

    A data broker is a company that collects personal data about people it usually has no direct relationship with, combines it, and sells or shares it. People-search sites are a type of data broker: according to the FTC, they gather data from other brokers, public social media profiles and government records, compile reports and sell them to anyone willing to pay.

    Other brokers sell to advertisers, marketers, lenders or insurers. You rarely see them, which is why you have to go looking.

  2. Find out who holds your data

    1. Search the web for your full name with your town, your phone number and your email address. Note every people-search site that has a profile on you.
    2. Read the privacy notices of companies that send you marketing you did not ask for. In the EU they must say where they got your data from (GDPR Art. 14).
    3. Check the official data broker registry if your state or country publishes one. California publishes one: the Data Broker Registry of the California Privacy Protection Agency.
    4. Use the access requests in the next step: under GDPR Art. 15(1)(c) and (g), a company must tell you who it disclosed your data to and where it got the data, so each reply can lead you to the next broker.
  3. EU/EEA: ask for a copy of your data (right of access)

    Under GDPR Article 15 you can ask any company whether it processes your personal data and, if it does, get a copy plus the purposes, the recipients, how long it keeps it, and any available information about where it came from.

    1. Open the GDPR request generator with the right of access and fill in the company and your details.
    2. Send it to the contact in the company's privacy notice (often a privacy or data protection officer address).
    3. The company must answer without undue delay and at the latest within one month. It can extend that by two further months for complex requests, but must tell you within the first month (Art. 12(3)).
  4. EU/EEA: ask for deletion and object to marketing

    Once you know what a broker holds, send two requests. You can send them together.

    • Erasure (Art. 17). Ask the company to delete your data. One ground is that you object to direct marketing under Art. 21(2) (Art. 17(1)(c)); another is that the data was processed unlawfully (Art. 17(1)(d)). Use the generator with the right to erasure.
    • Objection to direct marketing (Art. 21(2) and (3)). You can object at any time to processing for direct marketing, including profiling linked to it, and you do not have to give a reason. Once you object, the company must stop using your data for that purpose. Use the generator with the right to object.

    Erasure has exceptions (Art. 17(3)), for example when the company must keep the data by law. The objection to direct marketing has no such balancing test: marketing use must stop.

  5. EU/EEA: complain to a data protection authority

    If a company does not answer within the deadline, refuses without a valid reason, or keeps marketing to you after you objected, you can lodge a complaint with a supervisory authority, in particular in the EU country where you live, work, or where the infringement took place (GDPR Art. 77). A company that refuses must tell you about that possibility (Art. 12(4)).

    1. Find your national authority on the EDPB list of members.
    2. Attach your request, the date you sent it, and any reply. Your tracking list makes this quick.
  6. Outside the EU: California DROP and opt-out pages

    If you are a California resident, the Delete Request and Opt-out Platform (DROP), run by the California Privacy Protection Agency under the Delete Act, lets you send one free request that tells every registered data broker (over 600) to delete your personal information and stop selling it.

    • DROP opened to consumers on January 1, 2026. Sign up at consumer.drop.privacy.ca.gov.
    • From August 1, 2026, data brokers must check DROP at least every 45 days and process the deletion requests. Status updates can take up to 90 days to appear.
    • Only California residents are eligible.

    Elsewhere, look for an opt-out page on each people-search site. The FTC notes that you can opt out site by site for free, that it takes time, and that paid removal services exist; if you pay one, check how many sites it covers and how often it checks again.

  7. Reset your advertising ID and limit app permissions

    Your phone has an advertising identifier that apps and ad networks use to link your activity into a profile. Cut that link:

    • Android: Settings, then Privacy, then Ads. Choose Delete advertising ID (apps then get only zeros) or Reset advertising ID. On older versions the path is Settings, Privacy, Advanced, Ads, with an Opt out of Ads Personalization switch.
    • iPhone and iPad: Settings, then Privacy & Security, then Tracking, and turn off Allow Apps to Request to Track. Every app is then treated as if you chose Ask App Not to Track, and its developer cannot access the advertising identifier.

    Then review app permissions on the same privacy screens: remove location, contacts, photos and microphone access from apps that do not need them, and prefer "while using the app" for location.

  8. Track replies and check again

    Record every request and reply. Every few months, repeat the searches from the second step. The FTC warns that your data can come back for sale on people-search sites when your public records change, so a profile that disappears may return.

Common mistakes

  • Sending more ID than the company needs to find you, such as a full passport scan to a site that only needs your name and email.
  • Using your main email address for requests, which can confirm it to a broker that did not have it.
  • Asking only for deletion: an access request first tells you where the data came from and who else has it.
  • Stopping after one round. Brokers collect again, so profiles come back.
  • Waiting for months without a reply instead of complaining to the data protection authority once the deadline has passed.

Going further

Reduce what new brokers can collect: use email aliases for sign-ups, keep your phone number off public profiles, and refuse cookie and tracking prompts. A phone number found through a broker is also the start of many SIM swap attacks, so read Defend against SIM swaps and number theft next.